DPDP Compliance for HR & Employee Data: The Biggest Gap No Indian Company Has Fixed

Written by the ProtectComply team. Reviewed by Dinkar Singh, Chief Data Privacy Officer and Co-Founder, ProtectComply. This article explains the law in plain terms and is not legal advice.
Ask most Indian companies about their DPDP programme and they will show you a cookie banner, a consent flow and a privacy notice. Ask them where employee Aadhaar numbers, salary slips, medical claims and CCTV footage sit, and the room goes quiet. In our experience, DPDP employee data is the biggest gap in most programmes, and the reason is simple: many teams read section 7(i) as “no consent needed, so nothing to do”. That reading is wrong.
This guide explains what the DPDP Act and the DPDP Rules 2025 actually require for HR and employee data, how a working compliance process looks, where HR teams usually fail, and how to measure progress before obligations commence on 13 May 2027.
Why DPDP employee data is the gap most companies miss
HR holds some of the most sensitive personal data in any company. For instance, a single onboarding file can contain Aadhaar, PAN, bank details, address proof, emergency contacts, nominee details and a medical declaration. Then payroll, attendance, devices and access badges add more every day.
Yet HR data rarely gets the same attention as customer data. There are three reasons. First, the employment legitimate use removes the consent step, so the visible “consent project” never touches HR. Second, HR data is spread across an HRMS, a payroll vendor, background verification agencies, insurance brokers and shared drives. Third, nobody owns it end to end, because HR, IT and legal each see only a piece.
What the DPDP Act says about employee data
Section 7 of the Digital Personal Data Protection Act, 2023 lists “certain legitimate uses” where consent is not required. Clause (i) covers processing for the purposes of employment, or to safeguard the employer from loss or liability. The examples it gives include preventing corporate espionage, protecting trade secrets and intellectual property, and providing a service or benefit an employee asks for.
However, a legitimate use changes the lawful basis, not the rest of the Act. Here is what still applies:
- Section 8 duties: complete and accurate data where it is used for decisions, reasonable security safeguards, breach intimation, erasure once the purpose is served, and a published grievance contact.
- Processor contracts: payroll providers, HRMS vendors and verification agencies must work under a valid contract.
- Purpose limits: using HR data for something unrelated to employment, such as marketing a group company’s products to staff, needs its own basis.
- Children’s data: if you take interns under 18, section 9 requires verifiable parental consent.
There is also a subtle point about rights. The access and correction rights in sections 11 and 12 are framed around consent and section 7(a). So employees processed under section 7(i) may not have those statutory rights, although the grievance route in section 13 remains. Even so, most employers will find it easier to answer employee requests than to argue about them.
DPDP employee data and the 2027 timeline
The DPDP Rules were notified on 13 November 2025. Most substantive obligations, including the penalty schedule, commence on 13 May 2027. For reference, the schedule allows penalties of up to ₹250 crore for failing to take reasonable security safeguards and up to ₹200 crore for failing to notify a breach. Our DPDP Rules timeline and penalties guide cover the detail.
How DPDP employee data compliance actually works
In practice, HR compliance is a data-flow problem more than a policy problem. Therefore, it works best as a repeatable loop rather than a one-time document.

- Input: every system that touches staff data, including the HRMS, payroll, ATS, verification vendors, insurance, email, CCTV and biometric attendance.
- Processing and mapping: each HR activity becomes an entry in your records of processing activities, with purpose, lawful basis, data categories, systems, processors and retention.
- Decision layer: for each activity you decide whether section 7(i) applies, or whether consent or another basis is needed, and you record why.
- Controls: Rule 6 of the DPDP Rules expects encryption or masking, access control, logging and monitoring, backups, and logs kept for one year.
- Output: an HR privacy notice, updated vendor contracts, a retention schedule and a breach runbook.
- Monitoring: quarterly reviews of access, retention jobs and new HR tools, plus the Rule 7 duty to report a breach to the Board within 72 hours.
A practical example
Consider an illustrative 800-person manufacturer with two plants. It outsources payroll, uses a background verification agency, runs biometric attendance and CCTV, and buys group health cover that includes dependants.
- Discovery finds candidate CVs from 2019 in a shared mailbox and scanned Aadhaar cards on a plant file server.
- Mapping creates entries for recruitment, payroll, attendance, CCTV, insurance and exit, each with a named owner.
- Decisions confirm payroll and attendance under section 7(i), while an optional wellness app for staff moves to consent.
- Controls mask Aadhaar to the last four digits, restrict CCTV access to security leads and add DPDP clauses to the payroll and verification contracts.
- Retention sets rejected-candidate data to a fixed deletion period and keeps payroll records only as long as tax and labour law require.
As a result, the company can show the Board exactly what HR holds, why it holds it and who can see it. That evidence is what an inquiry will ask for.
The DPDP employee data lifecycle
Each stage of employment brings different data and different risks. The diagram and table below summarise where duties attach.

| Stage | Typical data | Key DPDP question |
|---|---|---|
| Candidate | CV, references, BGV report | How long do we keep rejected applicants? |
| Onboarding | Aadhaar, PAN, bank, nominees | Is ID data masked and access-limited? |
| Employment | Payroll, attendance, devices | Is monitoring tied to a stated purpose? |
| Exit | F&F, clearances, letters | Is system access removed on time? |
| After exit | Archived files, BGV requests | What is erased, and when? |
Seven HR gaps to fix first
- Rejected candidate data kept indefinitely in inboxes and ATS exports.
- Full Aadhaar numbers stored in shared folders instead of masked or tokenised copies.
- Dependants and nominees treated as “HR data” when they are data principals in their own right.
- CCTV, biometric and device monitoring with no documented purpose or retention period.
- Payroll, verification and insurance vendors working without DPDP clauses; see our vendor risk guide.
- No HR scenario in the breach runbook, although a leaked salary sheet is a reportable breach.
- Ex-employee files kept “just in case”, with no retention policy behind them.
ProtectComply vs other ways to manage DPDP employee data
| Criteria | ProtectComply | Spreadsheets and email | HRMS settings only | Law firm opinion only |
|---|---|---|---|---|
| HR data map and RoPA | RoPA and data map with processor catalogue | Manual, goes stale | Covers the HRMS only | Advice, not a system |
| Vendor tracking | Vendor and processor catalogue | Manual list | Not covered | Contract review |
| Requests and grievances | Rights Manager with 90-day grievance timer | Inbox | Partial | Not covered |
| Breach handling | Breach lifecycle workflow | Ad hoc | Not covered | Advice after the event |
| Policies | AI policy generator with a 30-policy bank | Templates | Not covered | Bespoke drafting |
| Evidence for audits | Audit trail and reports | Hard to prove | Limited logs | Opinion letters |
Notably, these options work best together. A law firm can interpret grey areas, the HRMS holds the records, and ProtectComply keeps the map, workflows and evidence current. For a wider comparison, see ProtectComply vs manual DPDP compliance.
Pros and cons of using ProtectComply for HR data
Pros
- One place to map HR activities, processors and retention alongside customer data, so HR is not a separate project.
- Rights and grievance workflows with a built-in 90-day resolution clock.
- Breach lifecycle support that covers HR incidents as well as customer ones.
- A 350-plus question sectoral assessment that exposes HR gaps early.
Cons
- ProtectComply does not replace your HRMS or payroll system; it governs how they use data.
- There is no HR-only module today, so HR is handled through the general RoPA, rights and breach modules.
- It does not give legal opinions; grey areas such as candidate data still need your counsel’s view.
- Initial mapping needs time from HR, IT and each vendor owner.
How we measure success
We do not publish invented compliance scores. Instead, we suggest tracking HR progress against this framework:
| Measure | What good looks like |
|---|---|
| Coverage | Every HR system and vendor appears in the RoPA |
| Basis recorded | Each HR activity has a documented lawful basis |
| Vendor terms | Share of HR processors with DPDP clauses signed |
| Retention | Deletion jobs run and evidenced on schedule |
| Access | Quarterly review of who can see salary and ID data |
| Readiness | Time to produce a breach report in a drill |
Then review the same measures each quarter until May 2027, and afterwards as part of normal operations.
Frequently asked questions on DPDP employee data
Do employers need consent to process employee data under the DPDP Act?
Usually not for employment purposes. Section 7(i) lets an employer process personal data for purposes of employment, or to protect itself from loss or liability, without consent. Processing unrelated to employment still needs consent or another valid basis.
Do DPDP obligations still apply to employee data processed without consent?
Yes. Section 8 duties still apply, including accuracy, reasonable security safeguards, breach intimation, erasure once the purpose is served, processor contracts and a grievance mechanism.
Are job applicants covered by the employment legitimate use?
The Act does not define purposes of employment, so this is a matter of interpretation. Many employers treat recruitment as covered but still give candidates a clear notice and delete rejected applications after a stated period.
Can employees ask for a copy of their personal data under DPDP?
The access and correction rights in sections 11 and 12 are tied to consent-based processing and section 7(a). Employment processing under section 7(i) may fall outside them, but employees can still use the grievance route under section 13.
How long can an employer keep ex-employee data under DPDP?
Only as long as the purpose or another law requires, for example tax, labour or litigation needs. Rule 6 also expects logs and related personal data to be kept for one year for security purposes.
When do DPDP obligations for employee data start?
The DPDP Rules were notified on 13 November 2025. Most substantive obligations, including sections 3 to 17 and the penalty provisions, commence on 13 May 2027.
Close the HR gap before May 2027
If your DPDP work so far has focused on customers, HR is likely where your biggest exposure sits. ProtectComply helps you map every HR system and vendor, record the lawful basis for each activity, run grievances and breaches on a clock, and keep the evidence ready. See the ProtectComply features or talk to our team about an HR data assessment.
Related reading: data principal rights under DPDP, the 72-hour breach clock, the DPO role and the DPDP compliance checklist.