Your go-to hub for Expert Insights,
Publications, and Resources
on
data privacy and compliance

Our resources provide the essential tools, guides, and insights to help your business stay ahead of data privacy regulations. From practical templates to expert articles, we ensure you have everything you need to navigate compliance with confidence.

Last Updated: 2026-09-03 ~ DPDP Consultants

HR Tech Under DPDPA: What Every Employer Must Know

HR tech stack and DPDPA compliance visual showing employee data flowing between HR systems and data protection shield

Chapter 1: Your HR Tech Stack Knows Everything About Your Employees. Does It Comply with the DPDPA?

Every modern organisation runs on HR technology. From the moment a candidate submits their resume on your Applicant Tracking System (ATS) to the day an employee exits and their full-and-final settlement is processed through payroll, HR tech platforms collect, store, process, and share an extraordinary volume of personal data.

Consider what a typical HR tech stack knows about a single employee: their full name, date of birth, gender, address, Aadhaar number, PAN, bank account details, salary structure, tax declarations, medical insurance claims, emergency contacts, family details, performance ratings, disciplinary records, biometric attendance data, learning history, and in many cases, their fingerprints or facial geometry.

This is not peripheral data. This is the most intimate digital profile any organisation holds about any individual. And until now, most HR departments have collected, processed, and shared this data with minimal regard for the individual employee's data protection rights.

The Digital Personal Data Protection Act, 2023 (DPDPA), fundamentally changes this. Under the Act, every employer that processes employee personal data is a Data Fiduciary. Every HR tech platform, whether it is an HRIS, payroll system, ATS, performance management tool, LMS, or biometric attendance system, is processing personal data that is now subject to the Act's requirements for lawful processing, purpose limitation, data minimisation, security safeguards, and the rights of Data Principals.

This guide provides a comprehensive analysis of how the DPDPA applies to every layer of the HR tech stack, identifies the compliance gaps that most organisations have not addressed, and offers a practical roadmap for achieving compliance without disrupting HR operations.


Chapter 2: Employee Personal Data Across the HR Tech Stack

The modern HR tech ecosystem is not a single platform. It is a constellation of interconnected systems, each collecting and processing specific categories of employee personal data. Understanding these data flows is the foundation of DPDPA compliance.

HR Tech System

Personal Data Collected

DPDPA Risk Level

Data Volume

HRIS / HCM

Name, DOB, gender, address, Aadhaar, PAN, bank details, family info, emergency contacts, photos

Very High

Comprehensive

Payroll Systems

Salary structure, tax declarations, PF contributions, bank account, investment proofs, reimbursements

Very High

Monthly recurring

Recruitment / ATS

Resumes, cover letters, interview notes, assessment scores, background verification reports, reference checks

High

High volume

Performance Mgmt

Goals, self-assessments, manager ratings, peer feedback, PIP documentation, promotion records

High

Annual/Quarterly

Biometric Attendance

Fingerprints, facial geometry, iris scans, GPS location, work hours, overtime records

Very High

Daily

Learning / LMS

Training records, certifications, skill assessments, learning preferences, course completion data

Medium

Ongoing

Employee Engagement

Survey responses, sentiment analysis, feedback, wellbeing scores, pulse check data

High

Periodic

Benefits / Insurance

Medical claims, dependant details, health conditions, disability status, insurance nominees

Very High

Ongoing

Exit Management

Resignation letters, exit interview notes, full-and-final calculations, relieving documentation

High

Event-based

 

A single employee record, when aggregated across these systems, can contain over 50 distinct personal data fields. For an organisation with 5,000 employees, this translates to hundreds of thousands of personal data points flowing through multiple platforms, many of which are cloud-hosted by third-party vendors in different jurisdictions.


Chapter 3: Where Standard HR Tech Practices Violate the DPDPA

Most HR tech implementations were designed for operational efficiency, not data protection compliance. The result is a set of deeply embedded practices that directly conflict with DPDPA requirements.

1. Blanket Consent at Onboarding

Most organisations present new joiners with a single consent form during onboarding that covers everything: payroll processing, benefits administration, performance management, marketing communications, data sharing with group entities, and background verification. Under the DPDPA, consent must be specific to each purpose, freely given, and easily withdrawable. A single blanket consent covering dozens of unrelated processing activities is not valid consent. Each purpose requires its own consent mechanism, and the employee must be able to consent to payroll processing while declining marketing communications.

2. Excessive Data Collection

HR teams routinely collect data that goes far beyond what is necessary. Asking for a father's name, mother's maiden name, spouse's occupation, children's details, and blood group during onboarding when none of these are required for the employment relationship violates the DPDPA's data minimisation principle. If the data is not necessary for the stated purpose, it should not be collected.

3. Biometric Data Without Adequate Safeguards

Biometric attendance systems that capture fingerprints, facial geometry, or iris patterns are processing some of the most sensitive personal data possible. Unlike a password, biometric data cannot be changed if compromised. Many organisations deploy biometric systems without informing employees about how their biometric data is stored, who has access to it, whether it is shared with third-party vendors, and what happens to it after the employee leaves the organisation. Under the DPDPA, this data requires informed consent, robust security safeguards, and defined retention and deletion policies.

4. Uncontrolled Vendor Data Sharing

A typical HR tech stack involves multiple vendors: a cloud HRIS provider, a separate payroll processor, an ATS vendor, a background verification agency, an insurance administrator, a learning platform, and an employee engagement tool. Employee personal data flows to all of these vendors, often without the employee's knowledge or explicit consent. Under the DPDPA, the Data Fiduciary (the employer) is responsible for ensuring that every Data Processor (vendor) processes data only for the specified purpose and implements adequate security safeguards. Most organisations have not audited their HR vendor contracts for DPDPA compliance.

5. Indefinite Retention of Employee Records

Organisations retain employee records for years, sometimes decades, after an employee has left. Full personnel files, including Aadhaar copies, PAN cards, bank details, medical records, and performance reviews, remain in HR systems indefinitely. The DPDPA requires that personal data be erased when the purpose for which it was collected has been fulfilled. While certain records must be retained under labour law, tax law, or regulatory requirements, the vast majority of HR data has no legal basis for retention beyond a reasonable period after the employment relationship ends.

6. Performance Data and Automated Decision-Making

HR tech platforms increasingly use algorithms for performance scoring, promotion recommendations, compensation benchmarking, and even termination risk prediction. These automated decisions directly affect employees' careers and livelihoods. Under the DPDPA, Data Principals have the right to information about how their data is being processed. When algorithmic decisions affect employees, organisations must be transparent about the data inputs, the decision logic, and the basis for outcomes. Most HR tech platforms offer no such transparency.

7. Cross-Border Data Transfers Without Assessment

Cloud-based HR tech platforms often store and process data in servers located outside India. Multinational organisations share employee data with parent companies or group entities in other countries. Under the DPDPA, cross-border transfers are permitted except to jurisdictions specifically restricted by the Central Government. However, the employer remains fully responsible for ensuring that overseas processors maintain adequate security safeguards. Many organisations have not assessed whether their HR tech vendors' data hosting locations comply with DPDPA requirements.


Chapter 4: DPDPA Obligations Specific to HR Tech

Informed, Purpose-Specific Consent

Employees must be informed, in clear and plain language, about what personal data is being collected, why it is being collected, which systems will process it, which vendors will receive it, and how long it will be retained. Consent must be obtained separately for each distinct purpose: payroll, benefits, performance management, learning and development, biometric attendance, employee surveys, and any other processing activity. Employees must be able to withdraw consent for non-essential processing without affecting their employment.

Data Minimisation Across HR Systems

Each HR system should collect only the data fields necessary for its specific function. The payroll system needs bank account details and tax declarations. It does not need the employee's blood group or spouse's occupation. The LMS needs training records and certifications. It does not need the employee's Aadhaar number. Every data field collected across the HR tech stack must be justified against a specific, documented purpose.

Purpose Limitation and Data Segregation

Data collected for one HR purpose cannot be used for another without fresh consent. Biometric data collected for attendance tracking cannot be repurposed for security surveillance analytics. Performance review data cannot be used for marketing case studies. Survey response data collected anonymously cannot be de-anonymised and linked to individual employees. Each HR tech system must enforce purpose limitation through technical controls and access restrictions.

Employee Data Principal Rights

Under the DPDPA, employees are Data Principals with the right to access their data, correct inaccurate data, request erasure, and file grievances. This means the HR tech stack must support individual-level data retrieval across all systems. When an employee asks "What data do you have on me?", the organisation must be able to produce a comprehensive response covering HRIS, payroll, ATS, performance management, biometrics, LMS, engagement platforms, and benefits systems. When an employee requests data erasure, it must be executed across every system where their data resides.

Security Safeguards for HR Data

Given the sensitivity of HR data (identity documents, financial information, medical records, biometric data), the DPDPA requires robust security safeguards. These include encryption of employee data at rest and in transit across all HR systems, role-based access controls ensuring that recruitment teams cannot access payroll data and payroll teams cannot access performance reviews, multi-factor authentication for all HR tech platforms, comprehensive audit logging of who accessed what data and when, and regular security assessments covering every platform in the HR tech stack.

Breach Notification for HR Data

A data breach affecting HR systems is particularly damaging because it exposes the most sensitive categories of personal data: identity documents, financial information, medical records, and biometric data. Under the DPDPA, the Data Fiduciary must notify the Data Protection Board and each affected employee about the breach. Given that HR databases are high-value targets for cybercriminals, organisations must implement breach detection, response, and notification capabilities specifically for their HR tech infrastructure.


Chapter 5: System-by-System Compliance Breakdown How DPDP Consultants Can Help

HRIS and HCM Platforms

HRIS platforms (SAP SuccessFactors, Workday, Darwinbox, Keka, greytHR) are the central repository of employee data. Compliance requires a comprehensive data field audit to identify and remove unnecessary fields, implementation of granular access controls, defined retention policies for each data category, mechanisms for handling employee data access and deletion requests, and data processing agreements with the HRIS vendor covering DPDPA requirements.

Payroll Systems

Payroll systems process financial personal data including salary, tax, PF, and bank details on a recurring monthly cycle. Compliance requires ensuring that payroll data is encrypted and access-restricted, that historical payroll records are retained only as long as required by tax and labour law, that payroll vendors have DPDPA-compliant data processing agreements, and that employees can access their payroll data upon request.

Recruitment and ATS

Recruitment platforms accumulate large volumes of candidate personal data: resumes, interview notes, assessment scores, and background verification reports. Most organisations retain rejected candidate data indefinitely. Under the DPDPA, candidate data should be retained only for a reasonable period. Candidates who were not hired must have their data deleted unless they provide specific consent for retention in a talent pool. Background verification reports, which often contain highly sensitive information, require particular attention to consent and retention.

Biometric Attendance Systems

Biometric systems present the highest compliance risk in the HR tech stack. Fingerprint and facial recognition data is irrevocable: unlike a password, a compromised fingerprint cannot be reset. Compliance requires explicit, informed consent for biometric data collection with a clear alternative for employees who decline, encryption and secure storage of biometric templates, strict access controls limiting who can access raw biometric data, immediate deletion of biometric data when the employment relationship ends, and regular security audits of the biometric system and its vendor.

Performance Management Platforms

Performance data directly affects employees' careers: promotions, compensation, role changes, and terminations. Compliance requires transparency about what data feeds into performance assessments, clarity on whether algorithmic scoring or recommendations are used, employee access to their complete performance records, defined retention periods for performance history, and policies on how performance data is used after an employee exits.

Employee Engagement and Survey Platforms

Engagement surveys often promise anonymity but collect metadata that can identify respondents: department, tenure band, location, role level. If survey data can be linked to an individual employee, directly or indirectly, it is personal data under the DPDPA. Compliance requires genuine anonymisation where anonymity is promised, clear consent when surveys collect identifiable data, defined retention and deletion policies, and transparency about who accesses survey results and at what level of granularity.


Chapter 6: HR Tech DPDPA Compliance Roadmap

Step 1: Audit Every HR System

Conduct a comprehensive audit of every platform in your HR tech stack. Map every personal data field collected by each system: HRIS, payroll, ATS, performance management, biometrics, LMS, engagement platforms, and benefits administration. Document what data is collected, from where, for what purpose, who has access, which vendors receive it, and how long it is retained. This data map is the foundation of your compliance programme.

Step 2: Redesign Employee Consent

Replace blanket onboarding consent with granular, purpose-specific consent mechanisms. Create separate consent flows for payroll processing, benefits administration, performance management, biometric attendance, learning and development, engagement surveys, and any other distinct processing purpose. Ensure consent notices are in clear, plain language and available in English, Hindi, and relevant regional languages. Implement mechanisms for employees to withdraw consent for non-essential processing.

Step 3: Secure Every HR Platform

Implement encryption for all employee data at rest and in transit across every HR system. Configure role-based access controls so that each team accesses only the data relevant to their function. Enable multi-factor authentication on all HR tech platforms. Establish comprehensive audit logging. Conduct penetration testing on all HR platforms, particularly cloud-hosted and internet-facing systems.

Step 4: Train HR Teams

HR professionals handle personal data daily but are rarely trained on data protection. Deliver DPDPA-specific training covering what constitutes personal data, how to obtain valid consent, how to handle employee data requests, how to respond to potential breaches, and the consequences of non-compliance. Training must cover every HR role: recruiters, HR business partners, payroll teams, benefits administrators, and HR leadership.

Step 5: Review Every HR Tech Vendor

Audit every vendor that receives employee data. Review data processing agreements with your HRIS provider, payroll processor, ATS vendor, background verification agency, insurance administrator, biometric system provider, LMS vendor, and engagement platform. Ensure each agreement specifies DPDPA-compliant data handling obligations, security requirements, retention limits, breach notification procedures, and sub-processor restrictions. Where agreements are absent or inadequate, renegotiate them.

Step 6: Implement Ongoing Monitoring

DPDPA compliance is not a one-time project. Implement automated data retention policies that delete employee records when their retention period expires. Set up continuous monitoring of access patterns and data flows across HR systems. Maintain documentation of consent records, processing activities, vendor assessments, and employee data requests. Conduct periodic compliance audits and update your data protection framework as your HR tech stack evolves.


Chapter 7: How DPDP Consultants Can Help

HR tech compliance under the DPDPA requires specialised expertise that bridges data protection law, human resources operations, and technology. DPDP Consultants provides end-to-end compliance services tailored to the HR tech ecosystem.

DPDPA Gap Assessment

We audit your entire HR tech stack, covering HRIS, payroll, ATS, biometrics, performance management, LMS, engagement platforms, and benefits systems, against every DPDPA requirement. Our assessment identifies exactly where your HR data processing stands and what needs to change.

Privacy Framework Implementation

We design and implement an HR-specific privacy framework covering employee consent workflows, purpose mapping for every HR data touchpoint, data minimisation policies, retention schedules for each data category, and Data Principal rights fulfilment mechanisms tailored to the employer-employee relationship.

Consent Management Platform

Our Data Principal Consent Management tool integrates with your HRIS and onboarding workflows to capture granular, purpose-specific consent at every employee touchpoint, manage consent withdrawal, and maintain audit-ready records that demonstrate compliance.

Grievance Redressal System

Our automated Grievance Redressal platform handles employee requests for data access, correction, and erasure, tracking every request from receipt to fulfilment within DPDPA timelines across all HR systems.

DPO as a Service

Our Data Protection Officers provide ongoing oversight of your HR data processing, manage vendor compliance, handle regulatory communications, oversee breach response, and ensure continuous DPDPA adherence across your HR tech stack.

Awareness Programme

We deliver DPDPA awareness training programmes customised for HR teams, covering recruiters, HR business partners, payroll and benefits administrators, HR leadership, and people managers who handle employee data daily.

Third-Party Assessment

We evaluate every HR tech vendor in your ecosystem, including HRIS, payroll, ATS, biometrics, LMS, and engagement platforms, ensuring appropriate data processing agreements and DPDPA-compliant security safeguards are in place.


Chapter 8: Frequently Asked Questions (FAQs)

Q: Does the DPDPA apply to employee data or only customer data?

The DPDPA applies to all personal data processed by any organisation, including employee data. Employers are Data Fiduciaries for their employees' personal data. Every HR system that collects, stores, or processes employee information must comply with the Act.

Q: Can we use biometric attendance without employee consent?

No. Biometric data is personal data under the DPDPA. Organisations must obtain informed, specific consent before collecting fingerprints, facial geometry, or any biometric data. Employees who decline biometric consent must be provided with an alternative attendance mechanism.

Q: Do we need separate consent for each HR tech system?

You need separate consent for each distinct processing purpose, not necessarily each system. However, if different HR systems process data for different purposes (payroll for salary processing, LMS for learning, engagement platform for surveys), each purpose requires its own consent. Bundling all purposes into a single onboarding checkbox is non-compliant.

Q: How long can we retain employee data after they leave?

Only as long as required by law or a valid purpose. Tax records may need to be retained for 7-8 years under Income Tax Act requirements. PF records have their own retention periods. However, data such as biometric templates, performance reviews, interview notes, and survey responses should be deleted once the employment relationship ends and any legal retention obligation has expired.

Q: Are cloud-based HR platforms compliant with the DPDPA?

Using a cloud-based platform does not automatically make you non-compliant or compliant. The employer (as Data Fiduciary) must ensure the platform vendor (as Data Processor) processes data only for specified purposes, implements adequate security safeguards, and has a DPDPA-compliant data processing agreement in place. If the platform stores data outside India, the employer must verify the hosting jurisdiction is not restricted.

Q: Can HR share employee data with group companies?

Sharing employee data with group companies or parent organisations is a separate processing purpose that requires its own consent. An employee consenting to their data being processed for payroll by their employer does not automatically consent to that data being shared with the parent company for global workforce analytics.

Q: What are the penalties for HR data non-compliance?

Penalties under the DPDPA range up to Rs 250 crore depending on the nature and severity of the violation. For HR data breaches involving Aadhaar numbers, bank details, medical records, and biometric data, the exposure is significant. Beyond financial penalties, HR data breaches severely damage employer brand and employee trust.

Q: Does the DPDPA affect background verification processes?

Yes. Background verification involves collecting and processing personal data including educational records, employment history, criminal records, and reference checks. Organisations must obtain specific consent for background verification, inform candidates about what checks will be conducted, and ensure the verification agency has adequate data processing agreements. Verification reports should be retained only as long as necessary.


 

Make Your HR Tech Stack DPDPA-Compliant

Your HR tech stack processes the most sensitive personal data in your organisation. The DPDPA holds you accountable for protecting it.

DPDP Consultants provides the expertise and technology to make your HR operations fully compliant. From Gap Assessments and Privacy Framework Implementation to Consent Management, DPO as a Service, and Third-Party Assessments, we cover every aspect of HR data protection.

 

Contact us today:

Website: www.dpdpconsultants.com

Email: info@dpdpconsultants.com

 

Disclaimer: This document is prepared by DPDP Consultants for informational purposes only. It does not constitute legal advice and should not be relied upon as a substitute for professional legal counsel. The information contained herein is based on the Digital Personal Data Protection Act, 2023, and publicly available information about the DPDP Rules as of August 2026. Laws, regulations, and their interpretations may change. Readers should consult qualified legal professionals for advice specific to their circumstances. DPDP Consultants assumes no liability for any actions taken or not taken based on the contents of this document.