Skip to content

Advocate Nitin Kumar Vashista

Home » Blog » DPDP Act Employee Data: What HR Teams Are Getting Wrong

DPDP Act Employee Data: What HR Teams Are Getting Wrong

DPDP Act Employee Data What HR Teams Are Getting Wrong

An HR head told me something during a consultation. I’ve heard it in different words many times since. “We’ve been so focused on customer data compliance, we honestly never thought about our own employee records.” Fair enough, honestly. Most DPDP Act conversations center around customers. Companies quietly treat employee data as somehow separate, exempt, internal-only.

It isn’t. And that assumption is exactly where a lot of HR teams are currently exposed.

Employee Data Isn’t a Special Category, It’s Fully Covered

Here’s the core point worth sitting with. The DPDP Act makes every employer in India a Data Fiduciary. This applies whether you’re a five-person startup or a company with 50,000 employees. The moment you collect a job applicant’s resume, store an Aadhaar number for EPFO purposes, process salary through payroll, or share health insurance data with an insurer, the Act covers you. That’s not a narrow reading of the law. That’s the law applying exactly as written.

Yet a recent EY India readiness survey found that only around 23% of Indian employers have actually assessed their HR data processing activities for DPDP compliance. The remaining majority are essentially operating on an assumption that employment data sits outside the Act’s scope. It doesn’t, and that gap is becoming a genuine liability.

The Good News: Most Core HR Processing Doesn’t Need Fresh Consent

Here’s where the picture gets more manageable than people initially fear. Section 7 of the Act treats employment-related processing as a “legitimate use.” This means core HR functions, payroll, benefits administration, attendance tracking, statutory deductions like PF and ESI, and workplace safety generally don’t require separate, explicit consent from employees for each activity.

However, this legitimate use exemption has real limits. Some processing falls outside genuine employment purposes. Using employee data for marketing, sharing it with third parties for their own separate purposes, or repurposing it beyond what employment reasonably requires — all of this does require proper, specific consent. The exemption covers running your business as an employer. It doesn’t cover everything you might want to do with the data you happen to hold.

Where HR Teams Are Genuinely Exposed

A few specific areas deserve particular attention. Compliance gaps show up most often here in practice.

Background verification processes. Indian employers routinely send candidate data to third-party BGV companies — Aadhaar, PAN, educational certificates, previous employment records. These companies then contact multiple downstream sources themselves. This chain of data sharing needs proper contractual protection at every link. An informal arrangement with your verification vendor isn’t enough.

Vendor relationships without signed Data Processing Agreements. Can your payroll provider, HRMS platform, or insurance partner show you a signed DPA? It should outline their security obligations, breach notification timelines, and data handling practices. If they can’t, that’s a compliance gap. Importantly, it’s your liability as the employer, not theirs.

Data collected but never mapped. A lot of HR data ends up scattered. Resumes sit in one system, biometric attendance data in another, performance reviews somewhere else entirely, insurance details with a third-party administrator. You genuinely cannot protect what you haven’t inventoried in the first place.

Retention that runs indefinitely by default. The days of keeping every HR record forever in an old spreadsheet are effectively over, legally speaking. The Act expects defined retention periods tied to actual statutory or business need, not indefinite storage out of habit.

What Rights Do Employees Actually Have

Employees hold the same core Data Principal rights as customers under this Act. They can request access to their personal data, or ask for correction of inaccurate records. Where consent was the actual basis for processing, they can withdraw it at any time. And if they believe someone has mishandled their data, they can raise a grievance.

One nuance worth understanding here: the right to erasure isn’t absolute. An employer generally can’t delete payroll records simply because a former employee requests it, if Income Tax Act compliance or other statutory retention obligations still require those records. The erasure right yields to legitimate legal retention requirements. Still, HR teams need a defined, documented process for handling these requests properly, rather than either ignoring them or over-complying beyond what’s actually required.

Importantly, if an employee’s grievance goes unresolved through your internal process, they can escalate directly to the Data Protection Board of India. That creates a direct regulatory pathway from an individual employee straight to the regulator. This makes it a genuine governance risk, not just an HR policy detail.

What a Practical HR Compliance Approach Looks Like

Given all this, here’s where HR and legal teams should realistically focus their energy.

Map your actual employee data estate first. Identify internal systems like your HRMS, payroll software, and attendance trackers. Also identify external vendors like BGV agencies, insurance providers, and IT service providers. You need this full picture before anything else makes sense to fix.

Get signed DPAs with every vendor touching employee data. This should be standard practice, not an afterthought. Each agreement should clearly cover breach notification timelines, security obligations, and what happens to data upon contract termination.

Review your consent language honestly. Does a generic clause from an employment agreement you signed years ago meet the Act’s standard? Consent must be free, specific, informed, and unambiguous for the processing activities that actually require it. Most old clauses fall short.

Build a real process for employee rights requests. Access, correction, and grievance requests need clear channels, verification steps, and defined timelines. Don’t leave this to an ad-hoc response scrambled together whenever someone happens to ask.

Set actual retention and deletion policies. Define how long different categories of employee data genuinely need to be kept. Build deletion into your process rather than treating it as optional cleanup nobody gets around to.

Why HR Can’t Treat This as Someone Else’s Problem

Penalties under the DPDP Act can reach up to ₹250 crore for serious violations. Employee data breaches carry the same exposure as customer data breaches under this framework. HR departments typically hold sensitive information — salaries, health records, biometric data, performance reviews, government ID numbers. Given this, HR often represents one of the highest-risk areas in an entire organization, even though companies rarely treat it that way.

Regulators expect full enforcement by May 2027. HR teams genuinely have a window to close these gaps properly, rather than scrambling once regulators start paying closer attention. Fewer than a quarter of Indian employers have even assessed their HR data practices so far. Getting ahead of this now is a real competitive advantage, not just a compliance checkbox.

If your HR team isn’t sure whether your employee data practices would hold up under scrutiny, it’s worth finding out now. I help businesses across Delhi NCR build proper DPDP compliance frameworks, including the HR and vendor side of things, through my DPDP Act Compliance Consulting services. For ongoing support, take a look at DPO services as well. Book a free consultation — Advocate Nitin Kumar Vashista, DPDP Act & GDPR Compliance Consultant, Gurgaon.

Leave a Reply

Your email address will not be published. Required fields are marked *