DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
DPDP for HR Teams

DPDP for HR Teams: Managing Employee Data Under DPDP Rules 2025

HR functions collect more employee personal data than any other department — Aadhaar, health records, salary history, biometrics. DPDP Rules 2025 impose new consent, vendor, and retention obligations that HR leaders must act on before May 2027.

Quick Answer

The DPDP Act 2023 and DPDP Rules 2025 apply fully to employee personal data collected and processed by Indian employers. HR teams are on the front line: every piece of data collected at onboarding — Aadhaar, PAN, bank account, health and insurance details — now requires an explicit, purpose-specific consent notice that cannot be bundled into the employment contract. HRMS platforms, payroll processors, and background verification companies are Data Processors under DPDP, and HR must ensure Data Processing Agreements (DPAs) are in place with each vendor. Post-exit, employee data must be deleted on a defined schedule once the purpose for retention lapses. Non-compliance exposes employers to penalties up to ₹250 crore per incident under the DPDP Act 2023.

HR Directors & CHROs People Ops Leaders HR Managers Payroll Teams Talent Acquisition
DPDP Rules 2025 specialists
HR & payroll data expertise
Fixed-price engagements
Enforcement deadline: May 2027
4 Key HR DPDP Obligations

What DPDP Rules 2025 Require from HR Teams

These are the four obligations most HR departments are currently unprepared for — and they all require action before the May 2027 enforcement deadline.

📋

Employee Consent at Onboarding

Aadhaar, PAN, bank account details, and health or insurance data are all collected at the point of hire. Under DPDP Rules 2025, each category requires an explicit, purpose-specific consent notice before collection — written in plain language, itemised by data type, and presented separately from the employment contract. Bundling data collection consent into an offer letter or appointment agreement is not valid consent under DPDP. HR teams must redesign onboarding forms and issue a standalone Employee Privacy Notice.

💻

HRMS Vendor Accountability

Payroll and HRMS platforms — including greytHR, Keka, Darwinbox, and others — process the complete personal data of every employee on your behalf. Under DPDP, these vendors are Data Processors and your organisation is the Data Fiduciary. You are legally responsible for how they handle employee data. HR must ensure a signed Data Processing Agreement (DPA) is in place with every HRMS and payroll vendor, specifying purpose, data minimisation obligations, sub-processor restrictions, breach notification timelines, and deletion obligations.

🔍

Background Verification Compliance

BGV companies such as AuthBridge, IDfy, and SpringVerify access sensitive personal data — identity documents, criminal records, employment history, education certificates, and in some cases financial and credit information. Each background check requires two things: a valid consent notice informing the candidate of exactly what will be verified and who will access their data, and a signed DPA with the BGV company. Using a blanket "we may verify your background" clause in an offer letter does not meet the DPDP standard for informed, specific consent.

🗑️

Post-Exit Data Retention

DPDP requires that personal data be deleted when the purpose for which it was collected has been fulfilled — not kept indefinitely "just in case." For ex-employees, HR must define a retention schedule by data category: statutory obligations (PF, TDS, gratuity records) drive minimum retention periods, but personal data beyond those categories — performance reviews, onboarding documents, BGV results — must be deleted on a defined schedule. Without a documented retention schedule and deletion workflow, your organisation is exposed to both DPDP penalties and erasure-right demands from ex-employees.

HR Data Inventory

Employee Data Categories Under DPDP

Every category below is personal data under the DPDP Act 2023. Each requires a documented legal basis, purpose, and defined retention period. This table is the foundation of any HR DPDP compliance programme.

Data Category Examples Sensitivity Typical Retention Driver
Personal ID Documents Aadhaar, PAN, passport, voter ID High Statutory (PF, TDS filing)
Health & Insurance Data Medical history, group health policy, disability records High Insurance claim periods
Bank & Financial Details Account number, IFSC, salary account, PF UAN High Payroll & PF regulations (8 yrs)
Salary & Compensation History CTC breakup, increment history, bonus payouts Medium Income Tax Act (6 yrs)
Performance Reviews Appraisal ratings, manager feedback, PIP records Medium Operational need (typically 2–3 yrs post-exit)
Biometrics & Access Logs Fingerprint attendance, face recognition, RFID entry logs High Security policy (typically 90 days–1 yr)
Background Check Results Criminal clearance, education verification, reference reports Medium Employment period + 1 yr (delete after)
Emergency Contacts Next-of-kin name, relationship, mobile number Standard Employment period only (delete at exit)
Disciplinary Records Warning letters, show-cause notices, termination orders Medium Legal limitation period (3 yrs from incident)
Training & Certifications Course completion records, licence certifications, L&D logs Standard Operational need (typically 2 yrs post-exit)
HR Action Plan

6-Step HR DPDP Compliance Action Plan

A structured roadmap for HR teams to achieve DPDP compliance before the May 2027 enforcement deadline — starting with the highest-risk areas.

1

Update Onboarding Forms with Purpose-Specific Consent Notices

Audit every data collection point in your onboarding process — physical forms, HRMS self-service portals, offer letter annexures. Replace omnibus data collection clauses with purpose-specific consent notices: one notice for payroll and statutory compliance data (Aadhaar, PAN, bank account), a separate notice for health and insurance data, and a third for optional data (emergency contacts, dietary preferences for travel). Each notice must state what data is collected, why, who it is shared with, and how long it will be retained. Consent must be given freely and cannot be a condition of employment for optional categories.

2

Issue an Employee Privacy Notice to All Staff

Draft and publish a comprehensive Employee Privacy Notice — a document that tells your existing and new employees what personal data the organisation collects, the legal basis for processing each category, the identities of all third-party processors (HRMS vendor, payroll provider, BGV company, group insurance provider), employee data rights under DPDP, and how to raise a data-related grievance. This notice must be issued to all current employees (not just new joiners) and updated whenever your data processing activities materially change. Host it on your intranet and reference it in your employment contract as a standalone document.

3

Audit All HRMS and Payroll Vendors

Create a vendor register listing every third-party system that processes employee personal data: HRMS platform, payroll software, attendance system, LMS, performance management tool, expense management system, group health insurer, group term life provider. For each vendor, check whether a current Data Processing Agreement (DPA) exists. A DPA must specify: the categories of data processed, the purpose, sub-processor restrictions, security standards (ISO 27001 or equivalent), breach notification timelines (72 hours to your organisation), and data deletion obligations on contract end. If no DPA exists with a vendor, that relationship is non-compliant under DPDP.

4

Sign DPAs with All BGV Companies

Background verification is one of the highest-risk data processing activities HR runs — BGV vendors access criminal records, financial history, and identity documents. Ensure a signed DPA is in place with every BGV partner (AuthBridge, IDfy, SpringVerify, or others). The DPA must cover: what data categories the BGV company can access, who their sub-processors are (e.g., court record aggregators, credit bureaus), how they secure data, the maximum retention period for check results (recommended: delete within 30 days of report delivery for rejected candidates), and the procedure for candidate DSAR requests related to BGV reports. Also update your candidate consent form to explicitly name the BGV vendor and the specific checks being run.

5

Define and Implement a Data Retention Schedule

Build a retention schedule that maps every employee data category to a retention period and the legal or operational basis for that period. Statutory minima (PF records: 8 years; tax records: 6 years; gratuity: 5 years) define the floor for specific categories. For all other categories, set the shortest defensible period. Implement deletion workflows in your HRMS: trigger an automated deletion task when an employee exits, schedule deletion of BGV results 30 days post-report, and purge performance review data 2 years after the last employment date unless there is an active legal dispute. Document every decision in writing — defensible retention requires a paper trail.

6

Create a Data Rights Response Process

Under DPDP, employees have the right to access their personal data, request corrections, and in some cases request deletion. HR must establish a formal Data Subject Access Request (DSAR) process: a designated contact or form for submitting requests, a 30-day response deadline, a process for validating the requester's identity, and defined response templates. Appoint and publicly name a Grievance Officer — their name and contact details must appear in the Employee Privacy Notice. For erasure requests from ex-employees, prepare a decision matrix that maps each data category to its retention justification so that valid refusals are documented and defensible.

Enforcement Timeline

DPDP Deadlines HR Teams Must Plan For

HR DPDP compliance is not a one-day project — vendor DPA negotiations, onboarding form redesigns, and HRMS system changes each take months. Planning must begin now.

Key milestones for HR and People Ops leaders

  • Now — Immediate: Vendor DPA audit. Map every third-party processor handling employee data. Most organisations discover they have no signed DPAs with their HRMS vendor, payroll provider, or BGV company. Negotiating and executing DPAs with major vendors typically takes 8–12 weeks. Begin now so you are not scrambling in 2027.
  • Q3 2026 — Employee Privacy Notice & consent form redesign. Draft the Employee Privacy Notice and updated onboarding consent forms. Circulate the Privacy Notice to all current employees. Update HRMS onboarding workflows so new joiners receive DPDP-compliant consent notices before data collection begins. This should be completed well ahead of enforcement.
  • Q4 2026 — Retention schedule and deletion workflows. Finalise the data retention schedule by category. Configure HRMS triggers for post-exit deletion. Run a first deletion cycle for ex-employees whose retention periods have already lapsed. Document all decisions.
  • May 13, 2027 — Full DPDP Enforcement. The Data Protection Board begins accepting complaints and can impose penalties. HR teams that have not issued Employee Privacy Notices, obtained valid onboarding consent, signed DPAs with vendors, and implemented retention schedules will be directly exposed. Penalties can reach ₹250 crore per incident — independent of any Labour Ministry or statutory compliance penalties.
Our Services for HR Teams

HR DPDP Compliance Tools & Engagements

Fixed-price tools and expert services built for People Ops and HR leaders. Start with a free checklist or go deep with an audit.

Employee Data Audit

₹999
Guided online tool
  • Maps all employee data categories
  • Flags missing DPAs with HRMS vendors
  • Identifies consent gaps at onboarding
  • Generates a retention schedule template
  • Downloadable audit report
Start Audit →

DPDP Compliance Checklist

Free
Self-service tool
  • HR-specific DPDP checklist (40 items)
  • Covers consent, vendors, retention, rights
  • Identifies your highest-risk gaps
  • Downloadable as PDF
  • No sign-up required
Get the Checklist →

Vendor Risk Scorecard

₹1,499
Online assessment tool
  • Assess HRMS, payroll & BGV vendors
  • DPA gap analysis per vendor
  • Security and sub-processor review
  • Risk-ranked vendor report
  • DPA clause checklist included
Assess Your Vendors →

Book an HR Team DPDP Consultation

Tell us about your organisation and your biggest employee data challenge. We'll come prepared with specific observations on HR consent design, HRMS vendor accountability, and retention schedules — not generic compliance advice.

Your consultation request has been received. We'll reach out within one business day to confirm your slot.
FAQ

Frequently Asked Questions — HR Teams & DPDP

Answers to the DPDP questions we hear most from CHROs, HR Directors, and People Ops leaders.

Can employees refuse to give Aadhaar for employment?

+
Yes — employees can refuse to provide Aadhaar for purposes beyond those mandated by law. Aadhaar collection is compulsory only for specific statutory purposes such as PF registration and income tax filing under Section 139AA of the Income Tax Act. For other HR purposes (access cards, general HR records), an employee's refusal cannot be grounds for withholding employment. Under DPDP, HR teams must issue a purpose-specific consent notice before collecting Aadhaar, and collection bundled into an employment contract as a non-negotiable term is not valid consent under the DPDP Act 2023.

Does DPDP apply to contract workers and consultants?

+
Yes. The DPDP Act 2023 applies to any natural person whose personal data is processed in India — the employment relationship is not a prerequisite. Contract workers, gig workers, freelance consultants, and third-party agency staff whose personal data (name, bank details, PAN, contact information) is processed by your HR or payroll systems are Data Principals under DPDP. This means your consent, purpose limitation, data minimisation, retention, and data rights obligations apply equally to their personal data as to permanent employees.

How long can we retain ex-employee data?

+
Retention periods depend on the data category and applicable law. Statutory obligations drive minimum periods: payroll records and PF data must be retained for at least 8 years under EPF regulations; tax-related records for 6 years under the Income Tax Act. For data categories without a statutory mandate (performance reviews, interview records, disciplinary communications), DPDP requires deletion once the purpose is fulfilled. HR teams must create a written retention schedule by category, document the legal basis for each period, and implement deletion workflows in their HRMS for lapsed data.

Can we share employee data with our parent company abroad?

+
Cross-border transfer of employee personal data to a foreign parent company is permitted under DPDP Rules 2025 only to countries approved by the Government of India. HR teams must confirm whether the destination country is on the approved list. If approved, the transfer still requires a valid consent notice that specifically informs employees their data may be transferred abroad, the country, and the purpose. Additionally, a Data Processing Agreement must be in place with the foreign entity, and employees retain their DPDP rights regardless of where their data is processed.

Do performance reviews fall under DPDP?

+
Yes. Performance reviews, appraisal ratings, manager feedback, and PIP records are personal data under the DPDP Act 2023 because they identify an individual and contain evaluative information about them. Employees have the right to access personal data held about them — which includes their performance records. HR should ensure performance data has a documented purpose, a defined retention period (typically 2–3 years post-exit unless there is an active dispute), and is accessible to employees on request through a defined DSAR process.
Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
DPDP for In-House Legal Teams: Implementation Chec…DPDP Security Safeguards Checker (Section 8) for C…DPIA Trigger CheckerDPDP Enforcement 2027See all By Role tools →📝 What Is Data Protection Board India📝 How to Present DPDP Compliance to Board