What personal data is sensitive under DPDP and what are the rules?
Some personal data carries higher risk and requires stronger safeguards. Here is what counts as sensitive personal data under the DPDP Act.
What categories will likely be notified as sensitive under DPDP?
Based on the IT Act's SPDI Rules (which have operated since 2011) and the DPDP Act's framework, expected sensitive categories include: passwords; financial data (bank account, credit/debit card, financial credentials); health data (physical and mental health, medical history, prescriptions); biometric data (fingerprints, iris scans, facial geometry, voice); sexual orientation; religious beliefs; political opinions; caste or tribe; and genetic data. The government may add further categories by notification. Until the formal notification, treat these categories with the highest caution.
How does sensitive personal data under DPDP compare to GDPR?
GDPR's special category data covers similar ground: racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, sex life or sexual orientation. DPDP adds financial data and passwords — categories the GDPR does not treat as special. DPDP does not include trade union membership explicitly. The processing restrictions for special category data under GDPR (explicit consent or one of a narrow set of exceptions) are broadly comparable to the more rigorous standards expected for sensitive personal data processing under DPDP.
What additional safeguards apply to sensitive personal data?
Processing sensitive personal data under DPDP requires: explicit, informed, and specific consent (not bundled or implied); a clearly documented purpose; the most stringent security controls (encryption at rest and in transit, strict access controls, audit logging of every access); data minimisation (collect only what is strictly necessary for the specified purpose); prompt deletion after the purpose is served; and careful vendor management (DPAs must explicitly cover sensitive data and specify enhanced security obligations). For SDFs, DPIAs are mandated for large-scale processing of sensitive personal data.
How do Indian businesses commonly handle financial data — and where do they go wrong?
Financial data — bank account details, PAN, credit card numbers, UPI IDs — is widely collected by Indian companies but frequently mishandled. Common errors: storing bank account details in unencrypted spreadsheets for payroll; keeping credit card numbers in CRM notes fields; sending financial data over unencrypted email; retaining financial data for years beyond the statutory period; and sharing financial data with third parties (loan agents, insurance brokers) without specific consent. Each of these is a specific risk under both the IT Act and DPDP.
How do companies handle health data incorrectly under DPDP?
Health data is sensitive but frequently mishandled in corporate settings: health certificate fields in employee databases accessible to all HR staff; insurance claim data visible to line managers; pre-employment medical data retained after the employment decision is made; employee wellness programme data used for HR decisions; and health data collected in OHS systems shared with payroll for absence deductions. Audit every system that touches health data and implement role-based access so only the roles that strictly need health data for their function can see it.
What are the penalties for mishandling sensitive personal data?
Mishandling sensitive personal data — breach of security, unauthorised disclosure, failure to implement required safeguards — carries the highest penalties under the DPDP Act. The penalty for failure to implement adequate security safeguards resulting in a data breach is up to ₹250 crore. The penalty for failure to notify a breach to the Board is up to ₹200 crore. These are ceiling figures — the actual penalty will be determined by the Board based on the gravity of the violation, the harm caused, and whether it was wilful or negligent. The reputational consequence of a public enforcement action involving sensitive personal data breach is typically even larger than the financial penalty.
Frequently asked questions
Is health data collected through employee wellness apps sensitive personal data?
Yes. Health data collected through corporate wellness apps — step counts, sleep data, weight, health assessments, mental wellness scores — is health personal data and is likely to be notified as sensitive under DPDP. The corporate wellness app vendor is a Data Processor for this data. The app consent must be explicit and separate from the employment contract. Using wellness app data for any HR decision — performance management, insurance underwriting — is a misuse of sensitive personal data that requires explicit, separate consent.
Does caste data collected for SC/ST reservations processing count as sensitive personal data?
Caste information collected for statutory reservation purposes (for example, SC/ST certificates in government employment or bank loan applications under reservation schemes) is processed on a statutory compliance basis — the lawful basis is the statutory obligation, not consent. However, the data is still sensitive and must be: restricted to the personnel handling the statutory process; not used for any other purpose; protected with appropriate security; and deleted after the statutory process is complete. Do not retain caste certificates beyond the statutory purpose.
If we collect biometric data only for attendance and do not share it, do we need special consent?
Yes. Biometric data is sensitive personal data regardless of whether it is shared externally. The collection itself requires explicit consent — employees must be offered an alternative (PIN, card) if they do not wish to provide biometric data. The consent must specifically cover the biometric attendance purpose. Even if you never share the biometric data with anyone, the collection, storage, and processing requires: the enhanced security standards for sensitive data, explicit written consent, and a deletion schedule aligned to the employment period.
Audit your sensitive personal data handling
Niti Bharat's Sensitive Data Audit identifies every system that processes sensitive personal data in your organisation — financial, health, biometric — and benchmarks your safeguards against DPDP requirements.
Start Sensitive Data Audit