← All posts

22 Sep 2026

DPDP Compliance for HR & Employee Data: The Biggest Gap No Indian Company Has Fixed

Written by the ProtectComply team. Reviewed by Dinkar Singh, Chief Data Privacy Officer and Co-Founder, ProtectComply. This article explains the law in plain terms and is not legal advice.

Ask most Indian companies about their DPDP programme and they will show you a cookie banner, a consent flow and a privacy notice. Ask them where employee Aadhaar numbers, salary slips, medical claims and CCTV footage sit, and the room goes quiet. In our experience, DPDP employee data is the biggest gap in most programmes, and the reason is simple: many teams read section 7(i) as “no consent needed, so nothing to do”. That reading is wrong.

This guide explains what the DPDP Act and the DPDP Rules 2025 actually require for HR and employee data, how a working compliance process looks, where HR teams usually fail, and how to measure progress before obligations commence on 13 May 2027.

Why DPDP employee data is the gap most companies miss

HR holds some of the most sensitive personal data in any company. For instance, a single onboarding file can contain Aadhaar, PAN, bank details, address proof, emergency contacts, nominee details and a medical declaration. Then payroll, attendance, devices and access badges add more every day.

Yet HR data rarely gets the same attention as customer data. There are three reasons. First, the employment legitimate use removes the consent step, so the visible “consent project” never touches HR. Second, HR data is spread across an HRMS, a payroll vendor, background verification agencies, insurance brokers and shared drives. Third, nobody owns it end to end, because HR, IT and legal each see only a piece.

What the DPDP Act says about employee data

Section 7 of the Digital Personal Data Protection Act, 2023 lists “certain legitimate uses” where consent is not required. Clause (i) covers processing for the purposes of employment, or to safeguard the employer from loss or liability. The examples it gives include preventing corporate espionage, protecting trade secrets and intellectual property, and providing a service or benefit an employee asks for.

However, a legitimate use changes the lawful basis, not the rest of the Act. Here is what still applies:

There is also a subtle point about rights. The access and correction rights in sections 11 and 12 are framed around consent and section 7(a). So employees processed under section 7(i) may not have those statutory rights, although the grievance route in section 13 remains. Even so, most employers will find it easier to answer employee requests than to argue about them.

DPDP employee data and the 2027 timeline

The DPDP Rules were notified on 13 November 2025. Most substantive obligations, including the penalty schedule, commence on 13 May 2027. For reference, the schedule allows penalties of up to ₹250 crore for failing to take reasonable security safeguards and up to ₹200 crore for failing to notify a breach. Our DPDP Rules timeline and penalties guide cover the detail.

How DPDP employee data compliance actually works

In practice, HR compliance is a data-flow problem more than a policy problem. Therefore, it works best as a repeatable loop rather than a one-time document.

How DPDP employee data compliance works: discover, map in RoPA, control, operate and evidence
How HR DPDP compliance works in practice: from HR data map to evidence.

A practical example

Consider an illustrative 800-person manufacturer with two plants. It outsources payroll, uses a background verification agency, runs biometric attendance and CCTV, and buys group health cover that includes dependants.

As a result, the company can show the Board exactly what HR holds, why it holds it and who can see it. That evidence is what an inquiry will ask for.

The DPDP employee data lifecycle

Each stage of employment brings different data and different risks. The diagram and table below summarise where duties attach.

DPDP employee data lifecycle from candidate to after exit, with section 7(i) scope and common HR gaps
The employee data lifecycle under the DPDP Act, and where HR programmes usually fail.
Stage Typical data Key DPDP question
Candidate CV, references, BGV report How long do we keep rejected applicants?
Onboarding Aadhaar, PAN, bank, nominees Is ID data masked and access-limited?
Employment Payroll, attendance, devices Is monitoring tied to a stated purpose?
Exit F&F, clearances, letters Is system access removed on time?
After exit Archived files, BGV requests What is erased, and when?

Seven HR gaps to fix first

ProtectComply vs other ways to manage DPDP employee data

Criteria ProtectComply Spreadsheets and email HRMS settings only Law firm opinion only
HR data map and RoPA RoPA and data map with processor catalogue Manual, goes stale Covers the HRMS only Advice, not a system
Vendor tracking Vendor and processor catalogue Manual list Not covered Contract review
Requests and grievances Rights Manager with 90-day grievance timer Inbox Partial Not covered
Breach handling Breach lifecycle workflow Ad hoc Not covered Advice after the event
Policies AI policy generator with a 30-policy bank Templates Not covered Bespoke drafting
Evidence for audits Audit trail and reports Hard to prove Limited logs Opinion letters

Notably, these options work best together. A law firm can interpret grey areas, the HRMS holds the records, and ProtectComply keeps the map, workflows and evidence current. For a wider comparison, see ProtectComply vs manual DPDP compliance.

Pros and cons of using ProtectComply for HR data

Pros

Cons

How we measure success

We do not publish invented compliance scores. Instead, we suggest tracking HR progress against this framework:

Measure What good looks like
Coverage Every HR system and vendor appears in the RoPA
Basis recorded Each HR activity has a documented lawful basis
Vendor terms Share of HR processors with DPDP clauses signed
Retention Deletion jobs run and evidenced on schedule
Access Quarterly review of who can see salary and ID data
Readiness Time to produce a breach report in a drill

Then review the same measures each quarter until May 2027, and afterwards as part of normal operations.

Frequently asked questions on DPDP employee data

Do employers need consent to process employee data under the DPDP Act?

Usually not for employment purposes. Section 7(i) lets an employer process personal data for purposes of employment, or to protect itself from loss or liability, without consent. Processing unrelated to employment still needs consent or another valid basis.

Do DPDP obligations still apply to employee data processed without consent?

Yes. Section 8 duties still apply, including accuracy, reasonable security safeguards, breach intimation, erasure once the purpose is served, processor contracts and a grievance mechanism.

Are job applicants covered by the employment legitimate use?

The Act does not define purposes of employment, so this is a matter of interpretation. Many employers treat recruitment as covered but still give candidates a clear notice and delete rejected applications after a stated period.

Can employees ask for a copy of their personal data under DPDP?

The access and correction rights in sections 11 and 12 are tied to consent-based processing and section 7(a). Employment processing under section 7(i) may fall outside them, but employees can still use the grievance route under section 13.

How long can an employer keep ex-employee data under DPDP?

Only as long as the purpose or another law requires, for example tax, labour or litigation needs. Rule 6 also expects logs and related personal data to be kept for one year for security purposes.

When do DPDP obligations for employee data start?

The DPDP Rules were notified on 13 November 2025. Most substantive obligations, including sections 3 to 17 and the penalty provisions, commence on 13 May 2027.

Close the HR gap before May 2027

If your DPDP work so far has focused on customers, HR is likely where your biggest exposure sits. ProtectComply helps you map every HR system and vendor, record the lawful basis for each activity, run grievances and breaches on a clock, and keep the evidence ready. See the ProtectComply features or talk to our team about an HR data assessment.

Related reading: data principal rights under DPDP, the 72-hour breach clock, the DPO role and the DPDP compliance checklist.