Every company in India — from a two-person startup to a fifty-thousand-person conglomerate — collects and processes the personal data of its employees. Aadhaar numbers for compliance. Bank account details for payroll. Medical records for ESI and group insurance. Fingerprints for attendance. Performance ratings that determine careers. Background verification reports. Disciplinary proceedings. Termination letters. Every single one of these data flows is regulated under the Digital Personal Data Protection Act, 2023 — and the obligations apply to every employer in India regardless of size, sector, revenue, or whether the company is Indian or a foreign MNC. This guide explains exactly what the DPDPA requires from HR and employer functions, what the most common violations are, and what every company must fix before May 2027.
- Does DPDPA apply to employee data — the definitive answer
- The complete map of employee data employers collect
- The consent problem — why employment contracts don't work as consent
- Lawful bases for HR data processing — what applies to what
- Aadhaar, PAN, and government ID data — the highest-risk obligation
- Payroll, salary, and financial data — what the law requires
- Medical and health data — the most sensitive employee data category
- Biometric attendance — fingerprint, face recognition, iris scans
- Performance management, appraisals, and disciplinary records
- Background verification — candidates, agencies, and data flows
- Employee monitoring — CCTV, email, location, and productivity tracking
- HR vendors and payroll processors — your Data Processor obligations
- Employee rights under DPDPA — what HR must be prepared to handle
- Departing and former employees — the most commonly missed obligation
- MNC subsidiaries — global HR systems and cross-border employee data
- The most common HR-DPDPA violations in Indian companies today
- Practical HR compliance roadmap — 60-day implementation plan
1. Does DPDPA Apply to Employee Data — The Definitive Answer
There is a persistent misconception in Indian HR circles that the DPDPA does not apply to employee data — that the employer-employee relationship creates a special carve-out, or that because employment is regulated by labour law, data protection does not additionally apply. This is incorrect.
- "Employee data is covered by labour law, not data protection law"
- "Employees consent when they sign the appointment letter"
- "DPDPA is for customer-facing businesses, not HR"
- "We only collect what's required for payroll — that's permitted"
- "Our company is too small for DPDPA to apply"
- DPDPA applies to all digital personal data — there is no employee exemption in the Act
- An appointment letter is a contract — it is not valid DPDPA consent
- Every employer collecting digital employee data is a Data Fiduciary
- Payroll-required processing is legitimate use — but must be documented
- No minimum size threshold — 1 employee = Data Fiduciary obligations
Section 2(t) of the DPDPA defines "personal data" as "any data about an individual who is identifiable by or in relation to such data." An employee's name, Aadhaar number, bank account, medical records, and performance rating are all data about an identifiable individual. The fact that the individual is an employee — rather than a customer — is irrelevant to the definition.
The Act exempts personal data processed for "personal or domestic purposes" — but no court or regulator has ever interpreted the employer-employee relationship as a personal or domestic purpose. Employing people is a commercial activity, and processing their data in that context is commercial data processing to which the Act applies in full.
2. The Complete Map of Employee Data Employers Collect
Before any compliance programme can be built, every HR team must understand the full scope of personal data their organisation processes. This is almost always larger than initially assumed.
| Data Category | Specific Examples | Who Holds It | Sensitivity |
|---|---|---|---|
| Government IDs | Aadhaar number, PAN card, passport, driving licence, voter ID | HR, payroll, compliance | CRITICAL |
| Biometric Data | Fingerprint for attendance, face recognition, iris scan, voice authentication | IT, facilities, HR | CRITICAL |
| Financial & Payroll Data | Salary, bank account, IFSC, PF account, gratuity, TDS, Form 16, salary slips | Finance, payroll, HR | VERY HIGH |
| Medical & Health Data | Pre-employment medical test, disability status, ESI records, group insurance health data, sick leave medical certificates | HR, admin, insurance | VERY HIGH |
| Identity & Contact | Name, DOB, address, emergency contacts, family details, personal email, personal mobile | HR, admin | HIGH |
| Performance & Appraisal | KPI scores, appraisal ratings, promotion decisions, PIP records, promotion/rejection history | Manager, HR, HRIS | HIGH |
| Background Verification | Criminal record checks, employment history verification, education verification, reference check reports, credit checks | HR, BGV agency, security | VERY HIGH |
| Disciplinary Records | Show cause notices, warning letters, suspension orders, inquiry reports, termination letters | HR, legal, management | HIGH |
| Monitoring & Surveillance | CCTV footage, email logs, internet usage data, location tracking (field staff), productivity software output, device monitoring | IT, security, managers | VERY HIGH |
| Leave & Attendance | Leave records (including medical leave reasons), attendance logs, overtime records, remote work logs | HR, managers, HRMS | MEDIUM |
| Candidate Data (Pre-Hire) | CV, interview notes, assessment scores, psychometric test results, salary expectations, rejection reasons | HR, recruitment, ATS | HIGH |
| Family & Nominee Data | Spouse/children details (insurance), PF nominee, gratuity nominee, emergency contact personal data | HR, finance, insurance | HIGH |
3. The Consent Problem — Why Employment Contracts Don't Work as Consent
This is the most consequential misunderstanding in HR data protection compliance. The vast majority of Indian companies believe that because an employee signed an appointment letter or employment contract, they have consented to all HR data processing. This belief is legally incorrect under the DPDPA.
What this means in practice: Consent is not the right lawful basis for most HR data processing. The correct approach — which DPDPA's legitimate use framework supports — is to rely on legitimate use grounds (contract performance, legal obligation) for most core HR activities, and use consent only for the narrow category of processing that genuinely requires it (such as optional wellness programmes, company newsletter subscriptions, or use of employee photographs in marketing). This is a fundamental redesign of how most HR teams think about their legal basis for data processing.
4. Lawful Bases for HR Data Processing — What Applies to What
Instead of relying on consent for everything, employers must map each category of HR data processing to the correct lawful basis. Under DPDPA, the two primary lawful bases available to employers are consent and legitimate use (Section 7). Here is how they map to actual HR activities:
| HR Processing Activity | Correct Lawful Basis | Why This Basis Applies |
|---|---|---|
| Payroll processing — salary calculation, bank transfer | Legitimate Use — Contract | Necessary to perform the employment contract — paying salary is the core contractual obligation |
| TDS deduction, Form 16, PF contribution, ESIC | Legitimate Use — Legal Obligation | Mandated by Income Tax Act, EPF Act, ESIC Act — employer has a statutory obligation to process this data |
| Aadhaar collection for PF, ESIC, and statutory compliance | Legitimate Use — Legal Obligation | Required by specific statutes. However, Aadhaar collection beyond statutory necessity (e.g. for attendance or ID cards) requires re-evaluation and may need consent |
| Performance management — appraisals, KPI tracking | Legitimate Use — Contract | Necessary to manage the employment relationship and fulfil the employer's obligations under the contract |
| Disciplinary proceedings and termination records | Legitimate Use — Contract / Legal | Necessary for managing the employment relationship and complying with Industrial Disputes Act and applicable labour laws |
| Pre-employment background verification | Consent — Specific Notice Required | Not strictly required by law in most sectors — requires specific, informed consent before the BGV process begins. Candidate must know what is being checked and by which agency |
| Biometric attendance (fingerprint / face recognition) | Consent — Specific + Alternative Required | Biometric data is among the most sensitive categories. Requires explicit, separate consent — AND an alternative non-biometric attendance mechanism must be available to employees who decline |
| CCTV surveillance of workplace | Legitimate Use — Security | Permitted for security purposes under legitimate use — but employees must be informed through notice (signage, employee privacy notice). No covert surveillance of personal areas. |
| Email monitoring, internet usage tracking, device monitoring | Consent + Clear Policy Required | Highly privacy-invasive. Requires explicit disclosure in the employee privacy notice and monitoring policy. Covert monitoring without disclosure is a direct DPDPA violation. |
| Employee photographs for website, marketing, publications | Consent — Separate Notice Required | Using employee photos for external marketing is not necessary for the employment contract. Requires specific, separate consent that can be withdrawn without affecting employment |
| Medical/health data for group insurance | Consent — Specific Notice Required | Sharing medical data with insurance companies is not mandated by law — it requires specific consent naming the insurer, data shared, and purpose. Must be separate from employment contract. |
| Wellness programmes, EAP (Employee Assistance Programmes) | Consent — Voluntary and Separate | Participation must be genuinely voluntary. Consent must be specific and separate. Employees must know the employer cannot access individual wellness programme data. |
5. Aadhaar, PAN, and Government ID Data — The Highest-Risk HR Obligation
Aadhaar numbers are processed by virtually every Indian employer — for PF registration, ESIC enrollment, TDS filing, and often for general identity verification. Under DPDPA, this is the highest-risk data category in the entire HR function.
The Aadhaar Act and DPDPA overlap: The Aadhaar Act 2016 has its own strict rules on who may collect, store, and use Aadhaar numbers — including criminal penalties for unauthorised collection. DPDPA adds an additional layer. An employer who collects Aadhaar beyond the statutory purposes permitted by the Aadhaar Act is simultaneously violating both statutes. The combined penalty exposure is severe.
What every employer must do with Aadhaar data:
- Audit every place Aadhaar numbers are stored — HRMS, payroll software, spreadsheets, physical files, email
- Delete Aadhaar data that serves no statutory purpose
- Encrypt all stored Aadhaar data at rest and in transit
- Restrict access to Aadhaar data to only those with a statutory need to access it
- Document the specific statutory basis for each instance of Aadhaar collection
- Delete Aadhaar data within 30 days of an employee's departure, unless legal obligations require retention
6. Payroll, Salary, and Financial Data — What the Law Requires
Payroll data is the most operationally critical HR data — and it is also among the most sensitive. An employee's salary is personal data that reveals their economic status, family situation, and negotiating position. Its exposure can cause real harm including discrimination, harassment, and targeted financial fraud.
7. Medical and Health Data — The Most Sensitive Employee Data Category
Employers regularly collect and process medical information about employees — through pre-employment medicals, sick leave certificates, ESI and insurance processes, and occupational health programmes. This is the most sensitive category of personal data the average employer holds.
8. Biometric Attendance — Fingerprint, Face Recognition, Iris Scans
Biometric attendance systems have become standard across Indian workplaces — from factories to offices to hospitals. Under DPDPA, biometric data is the most sensitive category of personal data, and collecting it without proper compliance is one of the highest-risk activities an employer can engage in.
9. Performance Management, Appraisals, and Disciplinary Records
Performance and disciplinary records are among the most consequential personal data an employer holds — they determine promotions, compensation, and termination. Their handling must meet DPDPA standards across the entire lifecycle.
| HR Record Type | DPDPA Obligations | Common Violation |
|---|---|---|
| Annual appraisal ratings | Employee has right to access their own appraisal rating and comments. Manager feedback visible to the appraisee is the employee's personal data — they can request a copy. Role-based access so only authorised managers and HR can view ratings. | Calibration meetings where all employees' ratings are visible to all managers simultaneously — no need-to-know restriction. |
| PIP (Performance Improvement Plan) | PIP records are the employee's personal data. Employee must be given a copy. Access restricted to the employee, HR, and the direct management chain. Cannot be shared without a specific legitimate need. | Sharing PIP status with cross-functional colleagues, client-facing teams, or in company-wide communications as a "performance concern". |
| Show cause notices and inquiry reports | Highly sensitive personal data involving allegations and findings about an individual. Must be maintained in a strictly restricted, access-controlled file. The employee has the right to access their own disciplinary file. | Disciplinary records stored in shared folders accessible to all HR staff, or copied to colleagues uninvolved in the matter. |
| Reference checks (as referee) | When a former employee applies elsewhere and names your company as a reference, responding to reference check queries involves processing the ex-employee's personal data for a new purpose. Requires care — factual responses only, no disclosure beyond what the ex-employee consented to when naming you as a reference. | Sharing disciplinary history, termination reasons, or salary data in reference checks without the ex-employee's specific consent for that disclosure. |
| Termination letters and severance records | Termination reasons are sensitive — they affect the employee's future employment prospects. Strict access control. Clear retention schedule (typically 7 years for labour law compliance). The employee has a right to a copy of their own termination letter. | Informing colleagues or clients about the reason for an employee's departure without legal necessity — even as a "heads up". |
10. Background Verification — Candidates, Agencies, and Data Flows
Background verification (BGV) is standard practice for most Indian employers — particularly for roles involving financial access, client data, or security clearances. Under DPDPA, BGV creates a complex data flow involving the employer, the candidate, the BGV agency, and multiple third parties (former employers, educational institutions, courts).
11. Employee Monitoring — CCTV, Email, Location, and Productivity Tracking
Employee monitoring is the area where employer interests — security, productivity, compliance — and employee privacy rights are most directly in tension. DPDPA does not prohibit monitoring, but it requires it to be transparent, proportionate, and disclosed.
12. HR Vendors and Payroll Processors — Your Data Processor Obligations
The average Indian company's HR function relies on a stack of 5–15 third-party vendors, each of which receives, stores, and processes employee personal data. Every single one of them is your Data Processor. Every single one requires a DPDPA-compliant DPA before any data flows to them.
| Vendor Type | Examples | Employee Data Processed | DPA Required? |
|---|---|---|---|
| HRMS / HCM Platform | Darwinbox, Keka, Zoho People, SAP SuccessFactors, Workday | Complete employee record — identity, salary, performance, leave, documents | YES — Priority 1 |
| Payroll Software | GreytHR, RazorpayX Payroll, ADP, Ramco, Ascent HCM | Salary, bank account, PAN, Aadhaar, TDS, PF data | YES — Priority 1 |
| Background Verification Agency | AuthBridge, HireRight, First Advantage, Karza, Cibil BGV | Full candidate identity, criminal record, employment history, education | YES — Priority 1 |
| Biometric Attendance System | Mantra, eSSL, Matrix, Identix, ESSL Biometric, ZKTeco | Biometric templates, attendance records, location within facility | YES — Priority 1 |
| Group Health Insurer / TPA | Star Health, Bajaj Allianz, HDFC Ergo, Medi Assist TPA | Health data, family data, hospitalisation records, claims history | YES — Priority 1 |
| Recruitment / ATS Platform | Naukri RMS, LinkedIn Talent, SmartRecruiters, Lever, Greenhouse | Candidate CV, contact details, interview notes, assessment scores | YES — Priority 2 |
| Learning Management System | Coursera for Business, LinkedIn Learning, Udemy for Business, Docebo | Learning progress, assessment scores, competency data, completion records | YES — Priority 2 |
| Travel & Expense Management | Expensify, Zoho Expense, SAP Concur, Happay | Travel receipts (may include hotel, location, time data), expense claims, reimbursement history | YES — Priority 2 |
13. Employee Rights Under DPDPA — What HR Must Be Prepared to Handle
Every employee is a Data Principal under DPDPA — with legally enforceable rights. HR must have documented processes for handling each of these rights requests. An employee who exercises a data right and receives no response, or is told "we can't help with that," is entitled to escalate to the Data Protection Board.
14. Departing and Former Employees — The Most Commonly Missed Obligation
The DPDPA obligations related to departing and former employees are the most commonly overlooked area in HR compliance. When an employee leaves, the employer's data obligations do not end — they transform.
Within 30 days of exit: Personal email accounts, personal social media accounts, personal phone numbers removed from company systems. Data shared with third parties specifically for the employment relationship (travel tools, expense systems) deletion triggered. Bank account details retained only for final payroll processing, then deleted.
Retain for 3 years: Employment contract and appointment letter (contract limitation period), basic identity information for settlement of any future claims, termination letter and settlement records.
Delete within 30 days of exit: Biometric data, performance management records beyond what is legally required, disciplinary records unless litigation is pending, monitoring data (CCTV footage unless needed for a specific incident), personal contact details (personal email, personal phone, home address), family and nominee data, medical records (retain only statutory minimum for ESI/PF purposes).
15. MNC Subsidiaries — Global HR Systems and Cross-Border Employee Data
For MNC India subsidiaries, employee data compliance has an additional layer: the flow of Indian employee personal data to the global parent company's HR systems, shared service centres, and global payroll processors creates cross-border transfer obligations under DPDPA Section 16.
| Cross-Border Employee Data Flow | DPDPA Obligations |
|---|---|
| Global Workday / SAP SuccessFactors instance hosted abroad | Indian employee data flowing to US/EU-hosted HRMS is a cross-border transfer. Employee privacy notice must disclose this. DPA between Indian subsidiary and parent / HRMS vendor. Monitor Board's restricted country notifications. |
| Global HR shared service centre (Philippines, Eastern Europe) | Shared service processing of Indian employee payroll or HR queries is a cross-border transfer. The shared service entity is a Data Processor — DPA required. Indian employees must be informed that their data is processed by a shared service in a named country. |
| Global performance calibration — ratings visible to global leadership | When India employees' performance ratings and names are shared with regional or global leadership teams in other countries, this is both a cross-border transfer and a need-to-know restriction issue. Access should be role-limited to those with a genuine management need for that data. |
| Intra-group background check sharing (global fraud databases) | If Indian employee background check data is shared with a global internal fraud register or blacklist, this requires: Indian employee consent for that sharing, a DPA with the entity maintaining the register, and cross-border transfer compliance. Intra-group is not automatically permitted under DPDPA. |
16. The Most Common HR-DPDPA Violations in Indian Companies Today
| # | Violation | Prevalence | Max Penalty |
|---|---|---|---|
| 1 | Appointment letter treated as consent for all HR data processing — no separate privacy notice or consent mechanism exists for any HR data category | ~98% of Indian companies | ₹50 Cr per employee |
| 2 | No Data Processing Agreement with HRMS, payroll software, or BGV agency — employee personal data flowing to these platforms without contractual protection | ~95% of Indian companies | ₹50 Cr |
| 3 | Biometric attendance system deployed without specific consent and without an alternative non-biometric attendance mechanism | ~80% of biometric users | ₹250 Cr |
| 4 | Aadhaar numbers stored in unencrypted HR spreadsheets or filed as physical photocopies accessible to all HR team members | ~90% of Indian companies | ₹250 Cr |
| 5 | No named Grievance Officer — employees have no accessible mechanism to exercise their DPDPA data rights or raise complaints about HR data handling | ~99% of Indian companies | ₹50 Cr |
| 6 | Employee monitoring (CCTV, email monitoring, productivity software) deployed without disclosure in employee privacy notice or monitoring policy | ~85% of companies with monitoring | ₹50–250 Cr |
| 7 | No employee exit data process — ex-employee biometric data, personal contact details, and non-essential HR data retained indefinitely after departure | ~95% of Indian companies | ₹50 Cr |
| 8 | Medical data from sick leave certificates accessible to managers or stored in general HR files without access control — not in a separate, restricted medical file | ~75% of Indian companies | ₹250 Cr |
17. Practical HR Compliance Roadmap — 60-Day Implementation Plan
Make Your HR Function DPDPA-Compliant Before Your Next Hiring Cycle
Every new employee your company hires from now until May 2027 is a Data Principal whose data you are processing — and every HR activity from their first day interview to their exit interview is regulated. The good news is that HR compliance under DPDPA is very achievable with the right structure: an Employee Privacy Notice, consent notices for biometric and BGV, vendor DPAs with your HRMS and payroll platform, a Grievance Officer, and a clear exit day data process.
Our HR Data Protection Compliance Package covers the complete programme — employee data audit, Employee Privacy Notice drafting, consent notices for biometric and BGV, DPDPA-reviewed DPAs with your HRMS, payroll, and BGV vendors, Grievance Officer setup, exit data process documentation, and HR team training. Delivered in 15 working days. Fixed price. Suitable for companies from 10 employees to 10,000.
We also offer a standalone Employee Privacy Notice drafting service for companies that already have their vendor DPAs in place and need only the core disclosure document — turnaround in 5 working days.