Share 💬 💼
DPDP

DPDPA for HR & Employee Data — Complete Compliance Guide 2025

📅 Mar 31, 2026
👤 Adv. Deepak Kumar
⏱️ 31 min read
📂 DPDP
DPDPA for HR & Employee Data — Complete Compliance Guide 2025
Every Indian employer — from a 2-person startup to a 50,000-person enterprise — collects Aadhaar, salary, medical, biometric, and performance data from employees. All of it is regulated under DPDPA 2023 with zero headcount threshold. This complete guide covers lawful bases for 12 HR data categories, why appointment letters fail as consent, Aadhaar obligations, biometric attendance rules, BGV data flows, employee monitoring, exit-day deletion obligations, vendor DPAs, and a 60-day HR compliance roadmap.
DPDP Act 2023 + DPDP Rules 2025 — Complete HR & Employee Data Compliance Guide

Every company in India — from a two-person startup to a fifty-thousand-person conglomerate — collects and processes the personal data of its employees. Aadhaar numbers for compliance. Bank account details for payroll. Medical records for ESI and group insurance. Fingerprints for attendance. Performance ratings that determine careers. Background verification reports. Disciplinary proceedings. Termination letters. Every single one of these data flows is regulated under the Digital Personal Data Protection Act, 2023 — and the obligations apply to every employer in India regardless of size, sector, revenue, or whether the company is Indian or a foreign MNC. This guide explains exactly what the DPDPA requires from HR and employer functions, what the most common violations are, and what every company must fix before May 2027.

600M+
Workers in India's organised and unorganised sector — every employer-employee relationship involves regulated personal data
₹250 Cr
Maximum penalty for breach of security safeguards — employee payroll database breach hits this ceiling
₹0
Revenue or headcount threshold — a company with 1 employee is a Data Fiduciary with full DPDPA obligations
May 2027
Full enforcement deadline — HR documentation, consent, and vendor DPAs must all be in place
Nov 2025
DPDP Rules notified — Board operational
Nov 2026
Consent Manager registration opens
May 2027
All DPDPA obligations enforceable — DEADLINE
📋 What This Guide Covers
  1. Does DPDPA apply to employee data — the definitive answer
  2. The complete map of employee data employers collect
  3. The consent problem — why employment contracts don't work as consent
  4. Lawful bases for HR data processing — what applies to what
  5. Aadhaar, PAN, and government ID data — the highest-risk obligation
  6. Payroll, salary, and financial data — what the law requires
  7. Medical and health data — the most sensitive employee data category
  8. Biometric attendance — fingerprint, face recognition, iris scans
  9. Performance management, appraisals, and disciplinary records
  10. Background verification — candidates, agencies, and data flows
  11. Employee monitoring — CCTV, email, location, and productivity tracking
  12. HR vendors and payroll processors — your Data Processor obligations
  13. Employee rights under DPDPA — what HR must be prepared to handle
  14. Departing and former employees — the most commonly missed obligation
  15. MNC subsidiaries — global HR systems and cross-border employee data
  16. The most common HR-DPDPA violations in Indian companies today
  17. Practical HR compliance roadmap — 60-day implementation plan

1. Does DPDPA Apply to Employee Data — The Definitive Answer

There is a persistent misconception in Indian HR circles that the DPDPA does not apply to employee data — that the employer-employee relationship creates a special carve-out, or that because employment is regulated by labour law, data protection does not additionally apply. This is incorrect.

❌ The Misconception
  • "Employee data is covered by labour law, not data protection law"
  • "Employees consent when they sign the appointment letter"
  • "DPDPA is for customer-facing businesses, not HR"
  • "We only collect what's required for payroll — that's permitted"
  • "Our company is too small for DPDPA to apply"
✅ The Legal Reality
  • DPDPA applies to all digital personal data — there is no employee exemption in the Act
  • An appointment letter is a contract — it is not valid DPDPA consent
  • Every employer collecting digital employee data is a Data Fiduciary
  • Payroll-required processing is legitimate use — but must be documented
  • No minimum size threshold — 1 employee = Data Fiduciary obligations
⚖️ The Legal Position — Why Employee Data Is Covered

Section 2(t) of the DPDPA defines "personal data" as "any data about an individual who is identifiable by or in relation to such data." An employee's name, Aadhaar number, bank account, medical records, and performance rating are all data about an identifiable individual. The fact that the individual is an employee — rather than a customer — is irrelevant to the definition.

The Act exempts personal data processed for "personal or domestic purposes" — but no court or regulator has ever interpreted the employer-employee relationship as a personal or domestic purpose. Employing people is a commercial activity, and processing their data in that context is commercial data processing to which the Act applies in full.

2. The Complete Map of Employee Data Employers Collect

Before any compliance programme can be built, every HR team must understand the full scope of personal data their organisation processes. This is almost always larger than initially assumed.

Data Category Specific Examples Who Holds It Sensitivity
Government IDs Aadhaar number, PAN card, passport, driving licence, voter ID HR, payroll, compliance CRITICAL
Biometric Data Fingerprint for attendance, face recognition, iris scan, voice authentication IT, facilities, HR CRITICAL
Financial & Payroll Data Salary, bank account, IFSC, PF account, gratuity, TDS, Form 16, salary slips Finance, payroll, HR VERY HIGH
Medical & Health Data Pre-employment medical test, disability status, ESI records, group insurance health data, sick leave medical certificates HR, admin, insurance VERY HIGH
Identity & Contact Name, DOB, address, emergency contacts, family details, personal email, personal mobile HR, admin HIGH
Performance & Appraisal KPI scores, appraisal ratings, promotion decisions, PIP records, promotion/rejection history Manager, HR, HRIS HIGH
Background Verification Criminal record checks, employment history verification, education verification, reference check reports, credit checks HR, BGV agency, security VERY HIGH
Disciplinary Records Show cause notices, warning letters, suspension orders, inquiry reports, termination letters HR, legal, management HIGH
Monitoring & Surveillance CCTV footage, email logs, internet usage data, location tracking (field staff), productivity software output, device monitoring IT, security, managers VERY HIGH
Leave & Attendance Leave records (including medical leave reasons), attendance logs, overtime records, remote work logs HR, managers, HRMS MEDIUM
Candidate Data (Pre-Hire) CV, interview notes, assessment scores, psychometric test results, salary expectations, rejection reasons HR, recruitment, ATS HIGH
Family & Nominee Data Spouse/children details (insurance), PF nominee, gratuity nominee, emergency contact personal data HR, finance, insurance HIGH

3. The Consent Problem — Why Employment Contracts Don't Work as Consent

This is the most consequential misunderstanding in HR data protection compliance. The vast majority of Indian companies believe that because an employee signed an appointment letter or employment contract, they have consented to all HR data processing. This belief is legally incorrect under the DPDPA.

❌ Why Your Appointment Letter Is Not Valid DPDPA Consent
It is not free. Section 6(1) requires consent to be "free" — meaning not conditioned on accepting it as a precondition for receiving something else. When an employee is told "sign this appointment letter (which includes data processing consent) or you do not get the job," that consent is not free. The power imbalance of the employment relationship makes consent inherently coerced. An employee who needs the job cannot freely refuse to share their data.
It is not specific. Section 6(2) requires one consent notice per distinct purpose. A single appointment letter clause saying "you consent to the company processing your personal data" covers multiple purposes — payroll processing, performance management, marketing the company's success stories, background verification, biometric attendance, CCTV monitoring — each requiring its own specific consent notice.
It is buried in a contract. Rule 3 requires the notice to be separate from any other document. A data processing clause inside an employment contract is not a standalone consent notice — it fails the separateness requirement on its face.

What this means in practice: Consent is not the right lawful basis for most HR data processing. The correct approach — which DPDPA's legitimate use framework supports — is to rely on legitimate use grounds (contract performance, legal obligation) for most core HR activities, and use consent only for the narrow category of processing that genuinely requires it (such as optional wellness programmes, company newsletter subscriptions, or use of employee photographs in marketing). This is a fundamental redesign of how most HR teams think about their legal basis for data processing.

4. Lawful Bases for HR Data Processing — What Applies to What

Instead of relying on consent for everything, employers must map each category of HR data processing to the correct lawful basis. Under DPDPA, the two primary lawful bases available to employers are consent and legitimate use (Section 7). Here is how they map to actual HR activities:

HR Processing Activity Correct Lawful Basis Why This Basis Applies
Payroll processing — salary calculation, bank transfer Legitimate Use — Contract Necessary to perform the employment contract — paying salary is the core contractual obligation
TDS deduction, Form 16, PF contribution, ESIC Legitimate Use — Legal Obligation Mandated by Income Tax Act, EPF Act, ESIC Act — employer has a statutory obligation to process this data
Aadhaar collection for PF, ESIC, and statutory compliance Legitimate Use — Legal Obligation Required by specific statutes. However, Aadhaar collection beyond statutory necessity (e.g. for attendance or ID cards) requires re-evaluation and may need consent
Performance management — appraisals, KPI tracking Legitimate Use — Contract Necessary to manage the employment relationship and fulfil the employer's obligations under the contract
Disciplinary proceedings and termination records Legitimate Use — Contract / Legal Necessary for managing the employment relationship and complying with Industrial Disputes Act and applicable labour laws
Pre-employment background verification Consent — Specific Notice Required Not strictly required by law in most sectors — requires specific, informed consent before the BGV process begins. Candidate must know what is being checked and by which agency
Biometric attendance (fingerprint / face recognition) Consent — Specific + Alternative Required Biometric data is among the most sensitive categories. Requires explicit, separate consent — AND an alternative non-biometric attendance mechanism must be available to employees who decline
CCTV surveillance of workplace Legitimate Use — Security Permitted for security purposes under legitimate use — but employees must be informed through notice (signage, employee privacy notice). No covert surveillance of personal areas.
Email monitoring, internet usage tracking, device monitoring Consent + Clear Policy Required Highly privacy-invasive. Requires explicit disclosure in the employee privacy notice and monitoring policy. Covert monitoring without disclosure is a direct DPDPA violation.
Employee photographs for website, marketing, publications Consent — Separate Notice Required Using employee photos for external marketing is not necessary for the employment contract. Requires specific, separate consent that can be withdrawn without affecting employment
Medical/health data for group insurance Consent — Specific Notice Required Sharing medical data with insurance companies is not mandated by law — it requires specific consent naming the insurer, data shared, and purpose. Must be separate from employment contract.
Wellness programmes, EAP (Employee Assistance Programmes) Consent — Voluntary and Separate Participation must be genuinely voluntary. Consent must be specific and separate. Employees must know the employer cannot access individual wellness programme data.

5. Aadhaar, PAN, and Government ID Data — The Highest-Risk HR Obligation

Aadhaar numbers are processed by virtually every Indian employer — for PF registration, ESIC enrollment, TDS filing, and often for general identity verification. Under DPDPA, this is the highest-risk data category in the entire HR function.

The Aadhaar Act and DPDPA overlap: The Aadhaar Act 2016 has its own strict rules on who may collect, store, and use Aadhaar numbers — including criminal penalties for unauthorised collection. DPDPA adds an additional layer. An employer who collects Aadhaar beyond the statutory purposes permitted by the Aadhaar Act is simultaneously violating both statutes. The combined penalty exposure is severe.

✅ Permitted Aadhaar Collection by Employers
  • PF (EPF) registration and seeding — mandated under EPF Act
  • ESIC registration — mandated under ESIC Act
  • Income tax TDS filing — where Aadhaar-PAN linking is required
  • Direct benefit transfer schemes where employer is required to verify
  • Any other collection explicitly mandated by a specific statute
❌ Common Unlawful Aadhaar Uses by Employers
  • Using Aadhaar as a general employee ID number (no statutory basis)
  • Photocopying and filing physical Aadhaar cards in employee files
  • Storing Aadhaar numbers in HR spreadsheets without encryption
  • Sharing Aadhaar with hotels for travel booking or third-party vendors
  • Requiring Aadhaar for internal access control or biometric attendance
  • Retaining Aadhaar data after the employee leaves without legal basis

What every employer must do with Aadhaar data:

  • Audit every place Aadhaar numbers are stored — HRMS, payroll software, spreadsheets, physical files, email
  • Delete Aadhaar data that serves no statutory purpose
  • Encrypt all stored Aadhaar data at rest and in transit
  • Restrict access to Aadhaar data to only those with a statutory need to access it
  • Document the specific statutory basis for each instance of Aadhaar collection
  • Delete Aadhaar data within 30 days of an employee's departure, unless legal obligations require retention

6. Payroll, Salary, and Financial Data — What the Law Requires

Payroll data is the most operationally critical HR data — and it is also among the most sensitive. An employee's salary is personal data that reveals their economic status, family situation, and negotiating position. Its exposure can cause real harm including discrimination, harassment, and targeted financial fraud.

🔒
Access control — need-to-know principle
Individual salary data should be accessible only to those with a legitimate need — typically the HR/payroll team and the employee's direct manager for budgeting purposes. All-company payroll spreadsheets, salary data shared in group emails, or payroll accessible to all finance staff without role-based access control violates the data minimisation obligation under Section 8(1).
📄
Salary slips and Form 16 — employee rights
These are documents containing the employee's personal financial data. Employees have a right to access their own salary data under Section 11 of DPDPA. But critically — employers cannot share salary slips with third parties (banks, landlords, loan applications) without the employee's specific consent for that disclosure. A salary slip issued to a bank for a home loan requires a separate consent from the employee for that sharing.
🏦
Payroll processors and cloud payroll software
Every third-party payroll platform — Darwinbox, Keka, Razorpay Payroll, GreytHR, SAP SuccessFactors, ADP — is a Data Processor under DPDPA. You must have a DPDPA-compliant Data Processing Agreement with every one of them before any payroll data flows to their platform. Most currently operating payroll platforms in India do not yet have DPDPA-specific DPAs — they have GDPR-compliant DPAs at best. This is an immediate compliance gap.
⚠️
Payroll data retention after employee exits
Payroll records must be retained for at least 7 years under GST and tax regulations. But this legal retention obligation does not extend to all employee data — only to the records actually required for tax compliance. Bank account numbers, UPI IDs, and other payment data can be deleted much earlier. The retention schedule must distinguish between legally required and operationally convenient retention.

7. Medical and Health Data — The Most Sensitive Employee Data Category

Employers regularly collect and process medical information about employees — through pre-employment medicals, sick leave certificates, ESI and insurance processes, and occupational health programmes. This is the most sensitive category of personal data the average employer holds.

🚨 The Medical Data Risk Matrix
  • Pre-employment medical report given to hiring manager — exposes health conditions to someone making employment decisions. Direct discrimination risk.
  • Medical leave certificate filed in general HR records — other HR staff can see diagnosis and health condition details that they have no need to know
  • Group insurance health data shared with insurer — requires specific employee consent; insurer cannot receive health data without it
  • Mental health data from EAP counselling — absolutely cannot flow to employer without explicit consent; EAP must be genuinely confidential
  • Disability information used in accommodation decisions — can only be used for the accommodation purpose; cannot be retained in general HR files or shared beyond those with a direct need
✅ How to Handle Medical Data Compliantly
  • Pre-employment medicals: doctor reports only to HR (fit/not fit) — specific health details not shared with hiring managers
  • Sick leave certificates: filed in a separate, access-controlled medical file accessible only to HR — not in the general employee file
  • Specific consent for insurance data sharing — naming the insurer and the data categories being shared
  • EAP is contractually prohibited from sharing individual data with employer — documented in the EAP vendor agreement
  • Separate, restricted storage for all health data — encrypted, role-based access, separate from general HR records
  • Clear retention policy — medical data deleted or anonymised when no longer needed for the specific purpose

8. Biometric Attendance — Fingerprint, Face Recognition, Iris Scans

Biometric attendance systems have become standard across Indian workplaces — from factories to offices to hospitals. Under DPDPA, biometric data is the most sensitive category of personal data, and collecting it without proper compliance is one of the highest-risk activities an employer can engage in.

🔍 5 Non-Negotiable Rules for Biometric Attendance Under DPDPA
1
Separate, specific consent before enrollment. The biometric consent notice must be a standalone document — separate from the appointment letter, the employee handbook, and the general HR privacy notice. It must explain what biometric data is collected, how it is stored (on-device template vs. central database), who can access it, and how long it is retained.
2
An alternative must exist. Consent for biometric attendance must be genuinely voluntary — which means if an employee declines biometric enrollment, the employer must have an alternative attendance mechanism (card swipe, manual register, OTP) that works equally well. Telling an employee "either enroll biometrics or you cannot mark attendance" makes the consent coerced and therefore invalid.
3
DPA with the biometric system vendor. The company that installed and maintains your biometric attendance system — Mantra, Matrix, eSSL, Identix, or any other — processes biometric data on your behalf. A DPDPA-compliant DPA must be in place with them before any enrollment happens. The DPA must specify that the vendor cannot access, use, or retain biometric templates for any purpose beyond the attendance function.
4
Secure storage — templates, not raw images. Best practice is to store a mathematical template of the biometric data (which cannot be reverse-engineered into a fingerprint image) rather than the raw biometric data itself. The storage must be encrypted and access-controlled. On-device storage is preferable to central database storage wherever technically feasible.
5
Deletion on exit — immediately. When an employee leaves, their biometric template must be deleted from the system within a defined, short period (recommend 7 days of exit). Retaining an ex-employee's fingerprint or face scan beyond this period without a specific legal basis is a direct DPDPA violation with no defensible justification.

9. Performance Management, Appraisals, and Disciplinary Records

Performance and disciplinary records are among the most consequential personal data an employer holds — they determine promotions, compensation, and termination. Their handling must meet DPDPA standards across the entire lifecycle.

HR Record Type DPDPA Obligations Common Violation
Annual appraisal ratings Employee has right to access their own appraisal rating and comments. Manager feedback visible to the appraisee is the employee's personal data — they can request a copy. Role-based access so only authorised managers and HR can view ratings. Calibration meetings where all employees' ratings are visible to all managers simultaneously — no need-to-know restriction.
PIP (Performance Improvement Plan) PIP records are the employee's personal data. Employee must be given a copy. Access restricted to the employee, HR, and the direct management chain. Cannot be shared without a specific legitimate need. Sharing PIP status with cross-functional colleagues, client-facing teams, or in company-wide communications as a "performance concern".
Show cause notices and inquiry reports Highly sensitive personal data involving allegations and findings about an individual. Must be maintained in a strictly restricted, access-controlled file. The employee has the right to access their own disciplinary file. Disciplinary records stored in shared folders accessible to all HR staff, or copied to colleagues uninvolved in the matter.
Reference checks (as referee) When a former employee applies elsewhere and names your company as a reference, responding to reference check queries involves processing the ex-employee's personal data for a new purpose. Requires care — factual responses only, no disclosure beyond what the ex-employee consented to when naming you as a reference. Sharing disciplinary history, termination reasons, or salary data in reference checks without the ex-employee's specific consent for that disclosure.
Termination letters and severance records Termination reasons are sensitive — they affect the employee's future employment prospects. Strict access control. Clear retention schedule (typically 7 years for labour law compliance). The employee has a right to a copy of their own termination letter. Informing colleagues or clients about the reason for an employee's departure without legal necessity — even as a "heads up".

10. Background Verification — Candidates, Agencies, and Data Flows

Background verification (BGV) is standard practice for most Indian employers — particularly for roles involving financial access, client data, or security clearances. Under DPDPA, BGV creates a complex data flow involving the employer, the candidate, the BGV agency, and multiple third parties (former employers, educational institutions, courts).

📋
Consent before the BGV begins — not buried in the offer letter
BGV must begin with a specific, standalone consent notice that names: (a) the BGV agency being used, (b) the specific checks being conducted (education, employment, criminal, credit, reference), (c) what data will be shared with the agency, (d) whether any data will be shared with other third parties, (e) how long the BGV report will be retained, and (f) the right to withdraw consent — and what happens if consent is withdrawn before the BGV is complete. This consent must be obtained before any data is shared with the BGV agency.
🤝
DPA with the BGV agency — mandatory before engagement
The BGV agency (AuthBridge, HireRight, First Advantage, Karza Technologies, etc.) is a Data Processor. A DPDPA-compliant DPA must be in place with them before any candidate data is shared. The DPA must specify: the checks to be conducted, the data to be shared, security standards, breach notification obligations, and crucially — that the BGV agency cannot retain candidate data for their own purposes (such as building a database of candidates with fraud histories) without the candidate's consent.
🚨
Adverse BGV findings — the highest-risk moment
When a BGV returns an adverse finding — a discrepancy, a criminal record, or an employment history mismatch — what happens next is the highest-risk moment in the entire process. The candidate has a right to be informed of the finding under DPDPA's right to information and the right to correction. They must be given the opportunity to contest or explain an adverse finding before it is used as the basis for withdrawal of an offer. Using a BGV finding to reject a candidate without giving them this opportunity is both a DPDPA violation and a potential legal challenge under contract law.

11. Employee Monitoring — CCTV, Email, Location, and Productivity Tracking

Employee monitoring is the area where employer interests — security, productivity, compliance — and employee privacy rights are most directly in tension. DPDPA does not prohibit monitoring, but it requires it to be transparent, proportionate, and disclosed.

📹 CCTV in the Workplace
Permitted for security purposes under legitimate use — but employees must be informed through prominent signage at all entry points and through the employee privacy notice. CCTV in toilets, changing rooms, prayer rooms, or any area with a reasonable expectation of privacy is absolutely prohibited. Footage retention must be limited — recommend 30 days maximum unless required for a specific incident investigation.
📧 Email and Internet Monitoring
Requires explicit disclosure in the employee privacy notice and a separate acceptable use / monitoring policy. Employees must know that company email accounts and internet usage on company devices or networks can be monitored. Covert monitoring without this disclosure is a direct DPDPA violation. The scope of monitoring must be proportionate to the business need — monitoring every email for a junior employee is unlikely to be proportionate.
📍 Location Tracking
Permitted for field staff with disclosure — delivery personnel, field sales, and service engineers can have location tracked during working hours if disclosed and consented to. Location tracking outside working hours is not permitted without separate, specific consent. Tracking personal devices (rather than company-issued devices) requires explicit, separate consent that employees can withdraw without employment consequence.
💻 Productivity Monitoring Software
Highest-risk monitoring category. Tools like Hubstaff, Time Doctor, Teramind, or ActivTrak that capture screenshots, keystrokes, active window tracking, and webcam images are processing highly personal behavioural data at scale. Covert installation is a criminal offence under the IT Act in addition to being a DPDPA violation. Any such tool requires explicit, informed disclosure — and most employees, if properly informed of the full scope of monitoring, would reasonably object to it.

12. HR Vendors and Payroll Processors — Your Data Processor Obligations

The average Indian company's HR function relies on a stack of 5–15 third-party vendors, each of which receives, stores, and processes employee personal data. Every single one of them is your Data Processor. Every single one requires a DPDPA-compliant DPA before any data flows to them.

Vendor Type Examples Employee Data Processed DPA Required?
HRMS / HCM Platform Darwinbox, Keka, Zoho People, SAP SuccessFactors, Workday Complete employee record — identity, salary, performance, leave, documents YES — Priority 1
Payroll Software GreytHR, RazorpayX Payroll, ADP, Ramco, Ascent HCM Salary, bank account, PAN, Aadhaar, TDS, PF data YES — Priority 1
Background Verification Agency AuthBridge, HireRight, First Advantage, Karza, Cibil BGV Full candidate identity, criminal record, employment history, education YES — Priority 1
Biometric Attendance System Mantra, eSSL, Matrix, Identix, ESSL Biometric, ZKTeco Biometric templates, attendance records, location within facility YES — Priority 1
Group Health Insurer / TPA Star Health, Bajaj Allianz, HDFC Ergo, Medi Assist TPA Health data, family data, hospitalisation records, claims history YES — Priority 1
Recruitment / ATS Platform Naukri RMS, LinkedIn Talent, SmartRecruiters, Lever, Greenhouse Candidate CV, contact details, interview notes, assessment scores YES — Priority 2
Learning Management System Coursera for Business, LinkedIn Learning, Udemy for Business, Docebo Learning progress, assessment scores, competency data, completion records YES — Priority 2
Travel & Expense Management Expensify, Zoho Expense, SAP Concur, Happay Travel receipts (may include hotel, location, time data), expense claims, reimbursement history YES — Priority 2

13. Employee Rights Under DPDPA — What HR Must Be Prepared to Handle

Every employee is a Data Principal under DPDPA — with legally enforceable rights. HR must have documented processes for handling each of these rights requests. An employee who exercises a data right and receives no response, or is told "we can't help with that," is entitled to escalate to the Data Protection Board.

👁 Right to Information (Section 11)
Employee can ask: what personal data does the company hold about me, and how is it being used? HR must be able to produce a comprehensive summary of all personal data held — not just payroll records, but also performance data, disciplinary records, BGV reports, attendance records, CCTV footage containing the employee, and monitoring logs. Most HR systems today cannot produce this on demand. A data inventory and HRMS with search functionality is essential.
✏️ Right to Correction (Section 12)
Employee can ask for correction of inaccurate personal data. This is most commonly exercised for: incorrect addresses, wrong bank account details, inaccurate attendance records, or incorrect performance ratings. For performance data, the correction right is nuanced — an employee cannot demand that a subjective performance rating be changed, but can request that factually incorrect supporting data (wrong sales figures, incorrect attendance records) be corrected. HR must have a defined process for reviewing and acting on correction requests within the prescribed timeline.
🗑 Right to Erasure (Section 12)
Employee can request deletion of their personal data — subject to legal retention obligations. HR must know which data must be retained by law (tax records, EPF records, ESI records, labour law compliance records) and which data can be deleted on request. For current employees, erasure rights are limited by the continuing employment relationship — you cannot delete someone's entire HR file while they are still employed. But upon exit, the right to erasure becomes much stronger for data beyond the legally required retention period.
🙋 Right to Grievance Redressal (Section 13)
Every employee can raise a data-related grievance with the company's Grievance Officer. This is separate from HR grievance mechanisms — it specifically covers data protection complaints. The Grievance Officer must be a named individual (not the HR team generally) with a published email address and defined response timelines. Unresolved grievances can be escalated to the Data Protection Board. HR teams must understand that a data protection grievance is not an HR matter — it requires legal involvement and a formal documented response.

14. Departing and Former Employees — The Most Commonly Missed Obligation

The DPDPA obligations related to departing and former employees are the most commonly overlooked area in HR compliance. When an employee leaves, the employer's data obligations do not end — they transform.

⚠️
Exit day data obligations — what must happen on the day an employee leaves
Immediately on exit: Biometric template deleted from attendance system (within 7 days). Access to all company systems revoked. Company device wiped. Monitoring systems (location tracking, productivity software) deactivated for that individual. Personal data on company devices returned or deleted with employee's confirmation.

Within 30 days of exit: Personal email accounts, personal social media accounts, personal phone numbers removed from company systems. Data shared with third parties specifically for the employment relationship (travel tools, expense systems) deletion triggered. Bank account details retained only for final payroll processing, then deleted.
📋
What can be retained — and for how long
Retain for 7 years: Payroll records and salary history (Income Tax Act, PF Act), tax documents (Form 16, TDS records), EPF and ESIC records, GST-related employment records.

Retain for 3 years: Employment contract and appointment letter (contract limitation period), basic identity information for settlement of any future claims, termination letter and settlement records.

Delete within 30 days of exit: Biometric data, performance management records beyond what is legally required, disciplinary records unless litigation is pending, monitoring data (CCTV footage unless needed for a specific incident), personal contact details (personal email, personal phone, home address), family and nominee data, medical records (retain only statutory minimum for ESI/PF purposes).
🔄
Background checks for re-hire — do not assume old data is current consent
When a former employee applies to rejoin the company, any BGV conducted previously cannot be relied upon without fresh consent and a fresh BGV process. The prior consent for the original BGV was specific to that employment — it does not extend to a new application. Similarly, the employer cannot use performance data from the previous employment as the basis for decisions about the new application without disclosing that they are doing so and obtaining consent for that use of historical data.

15. MNC Subsidiaries — Global HR Systems and Cross-Border Employee Data

For MNC India subsidiaries, employee data compliance has an additional layer: the flow of Indian employee personal data to the global parent company's HR systems, shared service centres, and global payroll processors creates cross-border transfer obligations under DPDPA Section 16.

Cross-Border Employee Data Flow DPDPA Obligations
Global Workday / SAP SuccessFactors instance hosted abroad Indian employee data flowing to US/EU-hosted HRMS is a cross-border transfer. Employee privacy notice must disclose this. DPA between Indian subsidiary and parent / HRMS vendor. Monitor Board's restricted country notifications.
Global HR shared service centre (Philippines, Eastern Europe) Shared service processing of Indian employee payroll or HR queries is a cross-border transfer. The shared service entity is a Data Processor — DPA required. Indian employees must be informed that their data is processed by a shared service in a named country.
Global performance calibration — ratings visible to global leadership When India employees' performance ratings and names are shared with regional or global leadership teams in other countries, this is both a cross-border transfer and a need-to-know restriction issue. Access should be role-limited to those with a genuine management need for that data.
Intra-group background check sharing (global fraud databases) If Indian employee background check data is shared with a global internal fraud register or blacklist, this requires: Indian employee consent for that sharing, a DPA with the entity maintaining the register, and cross-border transfer compliance. Intra-group is not automatically permitted under DPDPA.

16. The Most Common HR-DPDPA Violations in Indian Companies Today

# Violation Prevalence Max Penalty
1 Appointment letter treated as consent for all HR data processing — no separate privacy notice or consent mechanism exists for any HR data category ~98% of Indian companies ₹50 Cr per employee
2 No Data Processing Agreement with HRMS, payroll software, or BGV agency — employee personal data flowing to these platforms without contractual protection ~95% of Indian companies ₹50 Cr
3 Biometric attendance system deployed without specific consent and without an alternative non-biometric attendance mechanism ~80% of biometric users ₹250 Cr
4 Aadhaar numbers stored in unencrypted HR spreadsheets or filed as physical photocopies accessible to all HR team members ~90% of Indian companies ₹250 Cr
5 No named Grievance Officer — employees have no accessible mechanism to exercise their DPDPA data rights or raise complaints about HR data handling ~99% of Indian companies ₹50 Cr
6 Employee monitoring (CCTV, email monitoring, productivity software) deployed without disclosure in employee privacy notice or monitoring policy ~85% of companies with monitoring ₹50–250 Cr
7 No employee exit data process — ex-employee biometric data, personal contact details, and non-essential HR data retained indefinitely after departure ~95% of Indian companies ₹50 Cr
8 Medical data from sick leave certificates accessible to managers or stored in general HR files without access control — not in a separate, restricted medical file ~75% of Indian companies ₹250 Cr

17. Practical HR Compliance Roadmap — 60-Day Implementation Plan

D1–7
Days 1–7: HR Data Audit — Map Every Data Flow
Conduct a full inventory of every category of employee and candidate data collected, the purpose for which it is collected, the lawful basis, where it is stored (HRMS, spreadsheets, physical files, email), who has access, and which third-party vendors receive it. This data register is the foundation for every subsequent compliance step and is itself a compliance document. Most HR teams are surprised by the volume and scope of data they process — including data they had forgotten existed.
D8–14
Days 8–14: Employee Privacy Notice Drafting
Draft a comprehensive Employee Privacy Notice — a standalone document (not a clause in the appointment letter) that covers every category of HR data processing, the lawful basis for each, all third parties who receive employee data (naming the HRMS, payroll platform, BGV agency, insurer, and cloud providers), retention periods, employee rights, and the Grievance Officer's contact details. This notice must be provided to all current employees and to every new joiner going forward — before their first day of data collection.
D15–21
Days 15–21: Consent Notices for Consent-Required Processing
Draft separate, specific consent notices for each processing activity that genuinely requires consent: biometric attendance enrollment, background verification, use of employee photographs in marketing, optional wellness programme participation, monitoring policy (for email/internet/device monitoring). For biometric attendance: simultaneously implement an alternative non-biometric attendance option so consent is genuinely voluntary. Distribute biometric consent notices to all enrolled employees and obtain fresh, documented consent.
D22–35
Days 22–35: Vendor DPA Execution
Execute DPDPA-compliant Data Processing Agreements with all priority HR vendors — HRMS platform, payroll software, BGV agency, biometric attendance vendor, group health insurer/TPA. For each, review their existing DPA (most have GDPR-compliant DPAs) and either obtain a DPDPA addendum or use your own DPDPA-compliant DPA template. Prioritise by volume of data processed — the HRMS and payroll platform first, then BGV and insurance.
D36–50
Days 36–50: Governance, Security, and Data Housekeeping
Appoint and formally designate a Grievance Officer — publish their details in the Employee Privacy Notice and on the company's HR portal. Implement role-based access controls for sensitive employee data in the HRMS. Encrypt all Aadhaar numbers and PAN numbers in storage. Build the employee exit data process — a checklist that triggers data deletion actions on the employee's last day. Separate medical files from general HR files with restricted access. Delete all non-statutory Aadhaar copies from spreadsheets and physical files.
D51–60
Days 51–60: HR Team Training and Compliance Certification
Train every HR team member on DPDPA obligations — specifically: what data they can access and why, how to respond to employee rights requests, what to do if an employee raises a data protection grievance, and how to handle a data breach involving employee data. Document the training. Conduct a final compliance walkthrough. Obtain legal sign-off on the Employee Privacy Notice and all consent notices. Obtain a compliance certificate confirming that HR data processing meets DPDPA obligations. Schedule an annual review.
📊 DPDPA HR Compliance — At a Glance
₹250 Cr
Max penalty — biometric or health data breach. Every employer with biometric attendance faces this ceiling.
12
Employee data categories — every one regulated under DPDPA regardless of size
17
Compliance dimensions covered — from Aadhaar to exit day obligations
60 Days
Full HR compliance implementation — achievable for any size company
May 2027
Enforcement deadline — one appraisal cycle away. Start now.

Make Your HR Function DPDPA-Compliant Before Your Next Hiring Cycle

Every new employee your company hires from now until May 2027 is a Data Principal whose data you are processing — and every HR activity from their first day interview to their exit interview is regulated. The good news is that HR compliance under DPDPA is very achievable with the right structure: an Employee Privacy Notice, consent notices for biometric and BGV, vendor DPAs with your HRMS and payroll platform, a Grievance Officer, and a clear exit day data process.

Our HR Data Protection Compliance Package covers the complete programme — employee data audit, Employee Privacy Notice drafting, consent notices for biometric and BGV, DPDPA-reviewed DPAs with your HRMS, payroll, and BGV vendors, Grievance Officer setup, exit data process documentation, and HR team training. Delivered in 15 working days. Fixed price. Suitable for companies from 10 employees to 10,000.

We also offer a standalone Employee Privacy Notice drafting service for companies that already have their vendor DPAs in place and need only the core disclosure document — turnaround in 5 working days.

AD
Adv. Deepak Kumar
IP & Legal Expert · Vakil Help Desk
Our editorial team comprises experienced IP advocates, DPDPA compliance specialists, and legal professionals dedicated to making India's legal landscape accessible to every business. We cover trademark law, patent filing, copyright protection, and DPDP Act 2023 compliance.
Found this helpful? Share it →
💼 LinkedIn

Need Expert Help with DPDP?

Our team of advocates and compliance specialists are ready to help. Free consultation — response within 2 hours.

⚡ Get Free Consultation →
📋 Table of Contents
    Free Consultation
    Get expert advice on DPDP matters. We respond within 2 hours.
    Book Free Call → 💬 WhatsApp Us
    DPDPA Deadline
    Days to May 2027 enforcement
    Get Compliant Now →
    Get Free Consultation
    Call Now WhatsApp