DPDP-ready employee monitoring: a 2026 framework for evaluating any vendor
No employee monitoring vendor can honestly claim full DPDP certification yet. Here's exactly why, what "DPDP-ready" should mean instead, and a four-point framework to check any product against it - including ours.
If you run a consulting, accounting, or audit firm and you're evaluating employee monitoring or DLP software, you've probably already seen a vendor's homepage claim "DPDP compliant." Treat that claim with suspicion. It's not that the vendor is lying about their product necessarily - it's that the claim itself is premature, for every vendor, right now.
Why "DPDP compliant" isn't a real claim in 2026
The Digital Personal Data Protection Rules, 2025 were notified by MeitY on 14 November 2025 - but with three separate staged effective dates, not one:
| Phase | Effective date | What actually takes effect |
|---|---|---|
| I | 14 November 2025 | Data Protection Board of India is established and begins operating |
| II | 14 November 2026 | Consent-manager framework provisions |
| III | 13 May 2027 | The substantive compliance obligations - notice requirements, security safeguards, data-principal rights mechanics, breach reporting duties - that a "DPDP compliant" claim would actually need to be tested against |
Until Phase III lands, there is no regulator inspection regime and no accreditation body to certify a product against. A vendor claiming certified compliance today is describing a future state as if it were current. That's a marketing claim, not a legal one.
What's actually useful to ask instead: not "are you DPDP compliant," but "if the Phase III obligations were enforced today, would your product already do what they require, or would you be scrambling to build it?" That's what "DPDP-ready" should mean - and it's checkable right now, vendor by vendor.
The four-point DPDP-readiness framework
Strip the Act down to what actually matters for a monitoring or DLP product, and it comes down to four checkable things. Run any vendor - including us - through this list before you sign anything.
1. The legal basis is applied correctly, not bolted on
Section 7(i) treats employee monitoring for legitimate business purposes - safeguarding the employer from loss, protecting confidentiality and trade secrets - as a legitimate use that doesn't require consent as the operative legal basis. That's good, because consent extracted as a condition of employment from someone who can't realistically refuse it is weak anyway. But legitimate use isn't a free pass: notice, purpose limitation, security safeguards, and data-principal rights still apply. Check: does the product's default configuration reflect Section 7 correctly, or does it just slap a generic consent checkbox on the signup flow and call it a day?
2. Surveillance is off by default
The more intrusive a capability, the more it should require deliberate, reviewed activation - not ship pre-enabled and buried in a settings page. Screenshots, keystroke capture (where a vendor even offers it - see below), and webcam or microphone access are the highest-risk categories. Check: can you actually turn the product on for your firm without those toggles ever being touched, and does the vendor tell you what stays off unless you flip it?
3. Data-principal rights are a working workflow, not a policy PDF
The Act gives employees a real right to see, correct, and request erasure of their own data, plus a grievance mechanism. Check: is there an actual place an employee can go, today, in the product, to raise that request - or does the vendor's compliance story end at a privacy-policy page nobody in HR has ever operationalized?
4. The breach clock is a system, not a checklist
Section 6 requires notifying the Data Protection Board within 72 hours of becoming aware of a personal-data breach, with awareness meaning detection, not a completed investigation - and no minimum affected-user threshold. Check: if a breach happened at 11pm on a Friday, does the product actually start a timer and flag the deadline, or is "we have a process for that" something that lives in a compliance binder nobody has opened since the last audit?
Where consent actually still matters
Legitimate use under Section 7 covers the employment relationship itself. It does not cover unrelated processing - marketing employee data to a third party, for instance, or capturing categories of data that go beyond what's "relevant and reasonably necessary" for the stated purpose. A vendor that reads Section 7 as a blanket exemption to build whatever they want is misreading it. The purpose-limitation requirement is doing real work here, and it's worth asking a vendor to explain, specifically, why each category of data they collect is necessary for the employment purpose they're claiming.
What this looks like applied to Custelis
We built this framework because it's the one we hold ourselves to, not because we're the only vendor who can pass it - if another product genuinely passes all four points, that's a legitimate choice for a firm to make. Here's where we land on each:
- Legal basis: default configuration is built around Section 7 legitimate use, not a bolted-on consent banner - see the DPDP section of the product page.
- Surveillance off by default: screenshots are disabled until explicitly turned on, capped at 60/hour when active, exclusion zones supported; keylogging, password/credential capture, and webcam or microphone access are never implemented at all - enforced in code, not policy.
- Data-principal rights: every employee has a self-service transparency portal to raise access, correction, erasure, grievance, and nomination requests, tracked in an audited admin queue with an AI-assisted first draft a compliance officer reviews before anything is sent.
- Breach clock: recording a personal-data breach starts the 72-hour Data Protection Board clock automatically, flags it as the deadline approaches, and generates the Board-report payload.
None of that is a certification claim. It's what the product does today, and you can verify it in a demo rather than take our word for it.
See the four-point framework applied live
No credit card to start. Intrusive features stay off until your own DPIA is recorded.
Try for freeFrequently asked
Is any employee monitoring software DPDP compliant in 2026?
No. The DPDP Rules were notified on 14 November 2025 with three staged effective dates - Data Protection Board provisions from November 2025, consent-manager provisions from November 2026, and the substantive compliance obligations most vendors are judged on only from May 2027. Any vendor claiming full certified compliance today is describing a future state, not a current one. "DPDP-ready" - built and running today, ahead of the deadline - is the honest and useful claim.
Do employers need employee consent to monitor company devices under the DPDP Act?
Not as the primary legal basis. Section 7(i) of the DPDP Act treats processing for employment purposes - including safeguarding the employer from loss, corporate espionage, or breach of confidentiality - as a legitimate use that does not require consent. Consent obtained as a condition of employment is weak anyway, since an employee cannot realistically refuse it. What the Act does still require even under legitimate use is notice, purpose limitation, reasonable security safeguards, and a working data-principal-rights and grievance mechanism.
How fast does a company have to report a data breach under the DPDP Act?
Section 6 requires an immediate preliminary notification to the Data Protection Board of India as soon as the organization becomes aware of a personal data breach, followed by a detailed report within 72 hours covering cause, impact, and mitigation. Awareness means detection, not confirmation - the clock starts before an investigation is complete. There is no minimum-affected-users threshold.
Related reading
- Is employee monitoring legal in India? - the broader legal picture beyond DPDP specifically (Article 21, the IT Act, and where the boundaries actually sit).
- Custelis vs Teramind - how this framework plays out against a platform built around deeper, more intrusive capture by default.
- Employee monitoring for CA and audit firms - what this looks like applied to a professional-services risk profile specifically.
This page explains our understanding of the DPDP Act, 2023 and the DPDP Rules, 2025, and is not legal advice. Confirm applicability and compliance obligations for your organization with your own counsel.