top of page

The DPDP Act Double-Whammy: Why an Untrained Internal Committee Is Now a Two-Law Liability

  • reetika72
  • 4 days ago
  • 4 min read

Updated: 3 days ago

If your Internal Committee (IC) still treats a PoSH complaint as "just an HR matter," it is time for a hard reset. Since India's Digital Personal Data Protection (DPDP) Act, 2023 came into force with its Rules notified on November 14, 2025, and enforcement powers phasing in through 2026 and 2027, every PoSH complaint your IC handles is now also a data protection event. Handle it badly, and you are no longer looking at a single compliance failure. You are looking at two.


This is the DPDP Act double-whammy, and most organisations haven't updated their IC training to reflect it.


PoSH Data Is DPDP Data


The DPDP Act strictly regulates how "personal data" is collected, stored, shared, and disposed of and it draws no exception for HR or legal proceedings. Everything an Internal Committee touches during a Prevention of Sexual Harassment (PoSH) inquiry falls squarely within its scope:


  • The complainant's identity and statement

  • Witness testimonies and interview notes

  • The respondent's personal details and defence submissions

  • IC deliberation notes, draft findings, and the final inquiry report

  • Any medical, psychological, or corroborating evidence submitted


Under Section 16 of the PoSH Act, this information is already meant to stay confidential. But the DPDP Act adds an entirely separate, independently enforceable layer of obligation on top of that: as a "Data Fiduciary," your organisation must implement reasonable security safeguards for this data, use it only for the purpose it was collected, retain it no longer than necessary, and be able to demonstrate all of this if the Data Protection Board of India comes asking.


An IC that emails complaint documents without access controls, stores investigation notes in a shared drive open to the whole HR team, retains case files indefinitely "just in case," or lets details leak informally through the grapevine isn't just breaching PoSH confidentiality norms. It is very plausibly triggering a reportable personal data breach under the DPDP Act as a separate offence, investigated by a separate authority, with its own separate penalty.



Two Laws, Two Sets of Fines, One Untrained Committee


Here's where the "double" in double-whammy gets expensive.


A PoSH Act violation for example, a breach of confidentiality under Section 16, or failure to properly constitute or train the IC — is generally penalised under Section 26 of the PoSH Act, with fines of up to INR 50,000, escalating to license or registration cancellation on repeat offences.


The DPDP Act operates on an entirely different scale. Under its Schedule, a failure to implement reasonable security safeguards resulting in a personal data breach can attract penalties of up to INR 250 crore per instance. Breaches involving certain categories of data can carry separate, similarly severe ceilings. These are fixed-rupee penalties decided by the Data Protection Board, not percentage-of-turnover calculations — and they apply per incident, which means one poorly handled PoSH case with multiple lapses can compound exposure across categories.


Put plainly: your PoSH fine and your DPDP fine are not alternatives — they can both apply to the same underlying failure. A single mishandled complaint can leave your organisation defending itself in front of the Local/Internal Committee ecosystem and the Data Protection Board simultaneously, with the second exposure dwarfing the first by orders of magnitude.

And enforcement is no longer theoretical. With the DPDP Rules notified and the Data Protection Board's supervisory powers scaling up through the current transition period, "we didn't know the rules applied to HR" is not a defence that will age well.


Why "PoSH Training" Alone No Longer Covers You


Most existing IC training focuses on the PoSH Act in isolation: how to receive a complaint, how to conduct a fair inquiry, how to write a compliant report. That's necessary but it's no longer sufficient. A DPDP ready IC also needs to understand:


  • Data minimisation — collecting only what the inquiry actually requires, not everything that's offered

  • Access control — who on the IC, in HR, or in legal can see case files, and how that access is logged and restricted

  • Secure handling and storage — how complaint documents, statements, and evidence are stored, transmitted, and protected from unauthorised access

  • Retention and disposal — how long case records are kept after resolution, and how they're securely destroyed once that period lapses

  • Breach response protocol — what the IC and the organisation must do within the required timeline if sensitive case data is exposed, lost, or improperly shared.


Without training on these points, even a well-intentioned, procedurally sound IC can create a DPDP liability while trying to do its PoSH job correctly.


Close the Gap Before the Data Protection Board Does It For You


An untrained Internal Committee used to be a PoSH risk. Today, it's a PoSH risk and a data protection risk running in parallel — and the second one carries penalties that can dwarf the first. The fix isn't complicated, but it does require updating how ICs are trained: pairing safe, legally sound investigation frameworks with real data governance practices for sensitive personal data.


PoSH Expert Solutions helps organisations close exactly this gap — training Internal Committees to run PoSH inquiries that hold up under the PoSH Act and stay compliant under the DPDP Act, so one complaint never becomes two liabilities. [Get in touch] to schedule a DPDP-aligned IC training session before your next complaint tests your gaps for you.


FAQ


Does the DPDP Act actually apply to internal HR investigations like PoSH inquiries?

Yes. The DPDP Act applies to the processing of digital personal data broadly, and it does not carve out an exception for HR, legal, or disciplinary proceedings. Any personal data an IC collects, stores, or shares during a PoSH inquiry falls within the Act's scope.


Can a company be penalised under both the PoSH Act and the DPDP Act for the same incident?

Yes. The two statutes address different failures, PoSH confidentiality obligations versus data fiduciary obligations, and are enforced by different bodies. A single incident, such as a leaked complaint file, can trigger liability under both.


What is the single biggest DPDP mistake ICs make with PoSH data?

Over-retention and over-access are the most common: keeping case files indefinitely after resolution, and allowing more people than necessary to view sensitive statements and evidence.


Sources: Digital Personal Data Protection Act, 2023 and its Schedule of penalties; DPDP Rules, 2025 (notified November 14, 2025); Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013, Sections 16 and 26.

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating

Subscribe to our newsletter.
Don’t miss out!

Thanks for subscribing!

Contact Us

Reetika Gupta

4 LH, Lanco Hills

Manikonda

Hyderabad- 500089

Email: reetika@aristolegal.co.in

Subscribe to our newsletter.
Don’t miss out!

Thanks for subscribing!

Head Office

Reetika Gupta

21082, Prestige Falcon City, Kanakpura road,

Bangalore- 560062

Email: reetika@aristolegal.co.in

Explore PoSH Solutions

Posh expert solutions logo
  • LinkedIn

©2023 by aristolegal

Terms & Conditions

bottom of page