DPDP Act - buyer's guide

DPDP-ready employee monitoring: a 2026 framework for evaluating any vendor

No employee monitoring vendor can honestly claim full DPDP certification yet. Here's exactly why, what "DPDP-ready" should mean instead, and a four-point framework to check any product against it - including ours.

Published 24 August 2026 - Custelis, an Oris Intelligence product

If you run a consulting, accounting, or audit firm and you're evaluating employee monitoring or DLP software, you've probably already seen a vendor's homepage claim "DPDP compliant." Treat that claim with suspicion. It's not that the vendor is lying about their product necessarily - it's that the claim itself is premature, for every vendor, right now.

Why "DPDP compliant" isn't a real claim in 2026

The Digital Personal Data Protection Rules, 2025 were notified by MeitY on 14 November 2025 - but with three separate staged effective dates, not one:

PhaseEffective dateWhat actually takes effect
I14 November 2025Data Protection Board of India is established and begins operating
II14 November 2026Consent-manager framework provisions
III13 May 2027The substantive compliance obligations - notice requirements, security safeguards, data-principal rights mechanics, breach reporting duties - that a "DPDP compliant" claim would actually need to be tested against

Until Phase III lands, there is no regulator inspection regime and no accreditation body to certify a product against. A vendor claiming certified compliance today is describing a future state as if it were current. That's a marketing claim, not a legal one.

What's actually useful to ask instead: not "are you DPDP compliant," but "if the Phase III obligations were enforced today, would your product already do what they require, or would you be scrambling to build it?" That's what "DPDP-ready" should mean - and it's checkable right now, vendor by vendor.

The four-point DPDP-readiness framework

Strip the Act down to what actually matters for a monitoring or DLP product, and it comes down to four checkable things. Run any vendor - including us - through this list before you sign anything.

1. The legal basis is applied correctly, not bolted on

Section 7(i) treats employee monitoring for legitimate business purposes - safeguarding the employer from loss, protecting confidentiality and trade secrets - as a legitimate use that doesn't require consent as the operative legal basis. That's good, because consent extracted as a condition of employment from someone who can't realistically refuse it is weak anyway. But legitimate use isn't a free pass: notice, purpose limitation, security safeguards, and data-principal rights still apply. Check: does the product's default configuration reflect Section 7 correctly, or does it just slap a generic consent checkbox on the signup flow and call it a day?

2. Surveillance is off by default

The more intrusive a capability, the more it should require deliberate, reviewed activation - not ship pre-enabled and buried in a settings page. Screenshots, keystroke capture (where a vendor even offers it - see below), and webcam or microphone access are the highest-risk categories. Check: can you actually turn the product on for your firm without those toggles ever being touched, and does the vendor tell you what stays off unless you flip it?

3. Data-principal rights are a working workflow, not a policy PDF

The Act gives employees a real right to see, correct, and request erasure of their own data, plus a grievance mechanism. Check: is there an actual place an employee can go, today, in the product, to raise that request - or does the vendor's compliance story end at a privacy-policy page nobody in HR has ever operationalized?

4. The breach clock is a system, not a checklist

Section 6 requires notifying the Data Protection Board within 72 hours of becoming aware of a personal-data breach, with awareness meaning detection, not a completed investigation - and no minimum affected-user threshold. Check: if a breach happened at 11pm on a Friday, does the product actually start a timer and flag the deadline, or is "we have a process for that" something that lives in a compliance binder nobody has opened since the last audit?

Where consent actually still matters

Legitimate use under Section 7 covers the employment relationship itself. It does not cover unrelated processing - marketing employee data to a third party, for instance, or capturing categories of data that go beyond what's "relevant and reasonably necessary" for the stated purpose. A vendor that reads Section 7 as a blanket exemption to build whatever they want is misreading it. The purpose-limitation requirement is doing real work here, and it's worth asking a vendor to explain, specifically, why each category of data they collect is necessary for the employment purpose they're claiming.

What this looks like applied to Custelis

We built this framework because it's the one we hold ourselves to, not because we're the only vendor who can pass it - if another product genuinely passes all four points, that's a legitimate choice for a firm to make. Here's where we land on each:

None of that is a certification claim. It's what the product does today, and you can verify it in a demo rather than take our word for it.

See the four-point framework applied live

No credit card to start. Intrusive features stay off until your own DPIA is recorded.

Try for free

Frequently asked

Is any employee monitoring software DPDP compliant in 2026?

No. The DPDP Rules were notified on 14 November 2025 with three staged effective dates - Data Protection Board provisions from November 2025, consent-manager provisions from November 2026, and the substantive compliance obligations most vendors are judged on only from May 2027. Any vendor claiming full certified compliance today is describing a future state, not a current one. "DPDP-ready" - built and running today, ahead of the deadline - is the honest and useful claim.

Do employers need employee consent to monitor company devices under the DPDP Act?

Not as the primary legal basis. Section 7(i) of the DPDP Act treats processing for employment purposes - including safeguarding the employer from loss, corporate espionage, or breach of confidentiality - as a legitimate use that does not require consent. Consent obtained as a condition of employment is weak anyway, since an employee cannot realistically refuse it. What the Act does still require even under legitimate use is notice, purpose limitation, reasonable security safeguards, and a working data-principal-rights and grievance mechanism.

How fast does a company have to report a data breach under the DPDP Act?

Section 6 requires an immediate preliminary notification to the Data Protection Board of India as soon as the organization becomes aware of a personal data breach, followed by a detailed report within 72 hours covering cause, impact, and mitigation. Awareness means detection, not confirmation - the clock starts before an investigation is complete. There is no minimum-affected-users threshold.

Related reading

This page explains our understanding of the DPDP Act, 2023 and the DPDP Rules, 2025, and is not legal advice. Confirm applicability and compliance obligations for your organization with your own counsel.