HR functions collect more employee personal data than any other department — Aadhaar, health records, salary history, biometrics. DPDP Rules 2025 impose new consent, vendor, and retention obligations that HR leaders must act on before May 2027.
The DPDP Act 2023 and DPDP Rules 2025 apply fully to employee personal data collected and processed by Indian employers. HR teams are on the front line: every piece of data collected at onboarding — Aadhaar, PAN, bank account, health and insurance details — now requires an explicit, purpose-specific consent notice that cannot be bundled into the employment contract. HRMS platforms, payroll processors, and background verification companies are Data Processors under DPDP, and HR must ensure Data Processing Agreements (DPAs) are in place with each vendor. Post-exit, employee data must be deleted on a defined schedule once the purpose for retention lapses. Non-compliance exposes employers to penalties up to ₹250 crore per incident under the DPDP Act 2023.
These are the four obligations most HR departments are currently unprepared for — and they all require action before the May 2027 enforcement deadline.
Aadhaar, PAN, bank account details, and health or insurance data are all collected at the point of hire. Under DPDP Rules 2025, each category requires an explicit, purpose-specific consent notice before collection — written in plain language, itemised by data type, and presented separately from the employment contract. Bundling data collection consent into an offer letter or appointment agreement is not valid consent under DPDP. HR teams must redesign onboarding forms and issue a standalone Employee Privacy Notice.
Payroll and HRMS platforms — including greytHR, Keka, Darwinbox, and others — process the complete personal data of every employee on your behalf. Under DPDP, these vendors are Data Processors and your organisation is the Data Fiduciary. You are legally responsible for how they handle employee data. HR must ensure a signed Data Processing Agreement (DPA) is in place with every HRMS and payroll vendor, specifying purpose, data minimisation obligations, sub-processor restrictions, breach notification timelines, and deletion obligations.
BGV companies such as AuthBridge, IDfy, and SpringVerify access sensitive personal data — identity documents, criminal records, employment history, education certificates, and in some cases financial and credit information. Each background check requires two things: a valid consent notice informing the candidate of exactly what will be verified and who will access their data, and a signed DPA with the BGV company. Using a blanket "we may verify your background" clause in an offer letter does not meet the DPDP standard for informed, specific consent.
DPDP requires that personal data be deleted when the purpose for which it was collected has been fulfilled — not kept indefinitely "just in case." For ex-employees, HR must define a retention schedule by data category: statutory obligations (PF, TDS, gratuity records) drive minimum retention periods, but personal data beyond those categories — performance reviews, onboarding documents, BGV results — must be deleted on a defined schedule. Without a documented retention schedule and deletion workflow, your organisation is exposed to both DPDP penalties and erasure-right demands from ex-employees.
Every category below is personal data under the DPDP Act 2023. Each requires a documented legal basis, purpose, and defined retention period. This table is the foundation of any HR DPDP compliance programme.
| Data Category | Examples | Sensitivity | Typical Retention Driver |
|---|---|---|---|
| Personal ID Documents | Aadhaar, PAN, passport, voter ID | High | Statutory (PF, TDS filing) |
| Health & Insurance Data | Medical history, group health policy, disability records | High | Insurance claim periods |
| Bank & Financial Details | Account number, IFSC, salary account, PF UAN | High | Payroll & PF regulations (8 yrs) |
| Salary & Compensation History | CTC breakup, increment history, bonus payouts | Medium | Income Tax Act (6 yrs) |
| Performance Reviews | Appraisal ratings, manager feedback, PIP records | Medium | Operational need (typically 2–3 yrs post-exit) |
| Biometrics & Access Logs | Fingerprint attendance, face recognition, RFID entry logs | High | Security policy (typically 90 days–1 yr) |
| Background Check Results | Criminal clearance, education verification, reference reports | Medium | Employment period + 1 yr (delete after) |
| Emergency Contacts | Next-of-kin name, relationship, mobile number | Standard | Employment period only (delete at exit) |
| Disciplinary Records | Warning letters, show-cause notices, termination orders | Medium | Legal limitation period (3 yrs from incident) |
| Training & Certifications | Course completion records, licence certifications, L&D logs | Standard | Operational need (typically 2 yrs post-exit) |
A structured roadmap for HR teams to achieve DPDP compliance before the May 2027 enforcement deadline — starting with the highest-risk areas.
Audit every data collection point in your onboarding process — physical forms, HRMS self-service portals, offer letter annexures. Replace omnibus data collection clauses with purpose-specific consent notices: one notice for payroll and statutory compliance data (Aadhaar, PAN, bank account), a separate notice for health and insurance data, and a third for optional data (emergency contacts, dietary preferences for travel). Each notice must state what data is collected, why, who it is shared with, and how long it will be retained. Consent must be given freely and cannot be a condition of employment for optional categories.
Draft and publish a comprehensive Employee Privacy Notice — a document that tells your existing and new employees what personal data the organisation collects, the legal basis for processing each category, the identities of all third-party processors (HRMS vendor, payroll provider, BGV company, group insurance provider), employee data rights under DPDP, and how to raise a data-related grievance. This notice must be issued to all current employees (not just new joiners) and updated whenever your data processing activities materially change. Host it on your intranet and reference it in your employment contract as a standalone document.
Create a vendor register listing every third-party system that processes employee personal data: HRMS platform, payroll software, attendance system, LMS, performance management tool, expense management system, group health insurer, group term life provider. For each vendor, check whether a current Data Processing Agreement (DPA) exists. A DPA must specify: the categories of data processed, the purpose, sub-processor restrictions, security standards (ISO 27001 or equivalent), breach notification timelines (72 hours to your organisation), and data deletion obligations on contract end. If no DPA exists with a vendor, that relationship is non-compliant under DPDP.
Background verification is one of the highest-risk data processing activities HR runs — BGV vendors access criminal records, financial history, and identity documents. Ensure a signed DPA is in place with every BGV partner (AuthBridge, IDfy, SpringVerify, or others). The DPA must cover: what data categories the BGV company can access, who their sub-processors are (e.g., court record aggregators, credit bureaus), how they secure data, the maximum retention period for check results (recommended: delete within 30 days of report delivery for rejected candidates), and the procedure for candidate DSAR requests related to BGV reports. Also update your candidate consent form to explicitly name the BGV vendor and the specific checks being run.
Build a retention schedule that maps every employee data category to a retention period and the legal or operational basis for that period. Statutory minima (PF records: 8 years; tax records: 6 years; gratuity: 5 years) define the floor for specific categories. For all other categories, set the shortest defensible period. Implement deletion workflows in your HRMS: trigger an automated deletion task when an employee exits, schedule deletion of BGV results 30 days post-report, and purge performance review data 2 years after the last employment date unless there is an active legal dispute. Document every decision in writing — defensible retention requires a paper trail.
Under DPDP, employees have the right to access their personal data, request corrections, and in some cases request deletion. HR must establish a formal Data Subject Access Request (DSAR) process: a designated contact or form for submitting requests, a 30-day response deadline, a process for validating the requester's identity, and defined response templates. Appoint and publicly name a Grievance Officer — their name and contact details must appear in the Employee Privacy Notice. For erasure requests from ex-employees, prepare a decision matrix that maps each data category to its retention justification so that valid refusals are documented and defensible.
HR DPDP compliance is not a one-day project — vendor DPA negotiations, onboarding form redesigns, and HRMS system changes each take months. Planning must begin now.
Fixed-price tools and expert services built for People Ops and HR leaders. Start with a free checklist or go deep with an audit.
Tell us about your organisation and your biggest employee data challenge. We'll come prepared with specific observations on HR consent design, HRMS vendor accountability, and retention schedules — not generic compliance advice.
Answers to the DPDP questions we hear most from CHROs, HR Directors, and People Ops leaders.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.