Under the DPDP Act 2023, an employer is a Data Fiduciary for its employees' personal data across the entire lifecycle — from a candidate's application, through onboarding and active employment, to offboarding and post-exit retention. Each stage triggers its own obligations: lawful basis and notice at collection, purpose limitation and security during employment, and defined deletion or retention rules at exit. This guide walks HR teams through every lifecycle stage and flags where the most common DPDP gaps sit.
DPDP obligations do not stop at hiring. Check how ready your HR function is to handle employee personal data lawfully at every stage, from application to post-exit.
Most HR teams think about DPDP compliance at the point of hiring and stop there. In reality, the employee data lifecycle generates obligations at every stage: a lawful basis and clear notice when data is first collected, purpose limitation and reasonable security safeguards while the person is employed, and a defined approach to deletion or retention once they leave. A single employee record can pass through a recruitment system, an HRMS, payroll, a background-check vendor and a benefits portal — each of which is a point where DPDP duties attach.
The two stages most commonly neglected are the very start and the very end. At the start, employers frequently rely on a generic clause buried in the offer letter rather than a proper privacy notice. At the end, ex-employee records are often held indefinitely with no retention schedule, which sits uncomfortably with storage-limitation expectations. Mapping the full lifecycle is the fastest way for an HR function to see where its real exposure is.
A practical way to get compliant is to treat each lifecycle stage as its own workstream with an owner and an evidence trail: a dated notice for hiring, access controls for active employment, documented lawful bases for secondary uses, and a retention schedule for exit. This is far more actionable than a single generic HR privacy policy that tries to cover everything at once, because it lets you prioritise the stages where your exposure is highest.
Niti Bharat helps Indian mid-market HR teams map their employee data lifecycle and close stage-by-stage gaps through fixed-price DPDP engagements (₹75K–₹3.2L depending on scope), building the notice, access, retention and rights-handling records that a Data Protection Board inquiry would expect to see well before the May 2027 enforcement date.
A downloadable stage-by-stage map of every DPDP obligation across the employee data lifecycle, with owner and evidence columns ready for your HR compliance tracker.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.