Our resources provide the essential tools, guides, and insights to help your business stay ahead of data privacy regulations. From practical templates to expert articles, we ensure you have everything you need to navigate compliance with confidence.
Table of content
Last Updated: 2026-09-03 ~ DPDP Consultants
Chapter 1: Your HR Tech Stack Knows Everything About Your Employees. Does It Comply with the DPDPA?
Every modern organisation runs on HR technology.
From the moment a candidate submits their resume on your Applicant Tracking
System (ATS) to the day an employee exits and their full-and-final settlement
is processed through payroll, HR tech platforms collect, store, process, and
share an extraordinary volume of personal data.
Consider what a typical HR tech stack knows
about a single employee: their full name, date of birth, gender, address,
Aadhaar number, PAN, bank account details, salary structure, tax declarations,
medical insurance claims, emergency contacts, family details, performance
ratings, disciplinary records, biometric attendance data, learning history, and
in many cases, their fingerprints or facial geometry.
This is not peripheral data. This is the most
intimate digital profile any organisation holds about any individual. And until
now, most HR departments have collected, processed, and shared this data with
minimal regard for the individual employee's data protection rights.
The Digital Personal Data Protection Act, 2023
(DPDPA), fundamentally changes this. Under the Act, every employer that
processes employee personal data is a Data Fiduciary. Every HR tech platform,
whether it is an HRIS, payroll system, ATS, performance management tool, LMS,
or biometric attendance system, is processing personal data that is now subject
to the Act's requirements for lawful processing, purpose limitation, data
minimisation, security safeguards, and the rights of Data Principals.
This guide provides a comprehensive analysis of
how the DPDPA applies to every layer of the HR tech stack, identifies the
compliance gaps that most organisations have not addressed, and offers a
practical roadmap for achieving compliance without disrupting HR operations.
Chapter 2: Employee Personal Data Across the HR Tech Stack
The modern HR tech ecosystem is not a single
platform. It is a constellation of interconnected systems, each collecting and
processing specific categories of employee personal data. Understanding these
data flows is the foundation of DPDPA compliance.
|
HR Tech System |
Personal Data Collected |
DPDPA Risk Level |
Data Volume |
|
HRIS
/ HCM |
Name,
DOB, gender, address, Aadhaar, PAN, bank details, family info, emergency
contacts, photos |
Very
High |
Comprehensive |
|
Payroll Systems |
Salary structure, tax declarations, PF
contributions, bank account, investment proofs, reimbursements |
Very High |
Monthly recurring |
|
Recruitment
/ ATS |
Resumes,
cover letters, interview notes, assessment scores, background verification
reports, reference checks |
High |
High
volume |
|
Performance Mgmt |
Goals, self-assessments, manager
ratings, peer feedback, PIP documentation, promotion records |
High |
Annual/Quarterly |
|
Biometric
Attendance |
Fingerprints,
facial geometry, iris scans, GPS location, work hours, overtime records |
Very
High |
Daily |
|
Learning / LMS |
Training records, certifications, skill
assessments, learning preferences, course completion data |
Medium |
Ongoing |
|
Employee
Engagement |
Survey
responses, sentiment analysis, feedback, wellbeing scores, pulse check data |
High |
Periodic |
|
Benefits / Insurance |
Medical claims, dependant details,
health conditions, disability status, insurance nominees |
Very High |
Ongoing |
|
Exit
Management |
Resignation
letters, exit interview notes, full-and-final calculations, relieving
documentation |
High |
Event-based |
A single employee record, when aggregated across
these systems, can contain over 50 distinct personal data fields. For an
organisation with 5,000 employees, this translates to hundreds of thousands of
personal data points flowing through multiple platforms, many of which are
cloud-hosted by third-party vendors in different jurisdictions.
Chapter 3: Where Standard HR Tech Practices Violate the DPDPA
Most HR tech implementations were designed for
operational efficiency, not data protection compliance. The result is a set of
deeply embedded practices that directly conflict with DPDPA requirements.
1. Blanket Consent at Onboarding
Most organisations present new joiners with a
single consent form during onboarding that covers everything: payroll
processing, benefits administration, performance management, marketing
communications, data sharing with group entities, and background verification.
Under the DPDPA, consent must be specific to each purpose, freely given, and
easily withdrawable. A single blanket consent covering dozens of unrelated
processing activities is not valid consent. Each purpose requires its own
consent mechanism, and the employee must be able to consent to payroll
processing while declining marketing communications.
2. Excessive Data Collection
HR teams routinely collect data that goes far
beyond what is necessary. Asking for a father's name, mother's maiden name,
spouse's occupation, children's details, and blood group during onboarding when
none of these are required for the employment relationship violates the DPDPA's
data minimisation principle. If the data is not necessary for the stated
purpose, it should not be collected.
3. Biometric Data Without Adequate
Safeguards
Biometric attendance systems that capture
fingerprints, facial geometry, or iris patterns are processing some of the most
sensitive personal data possible. Unlike a password, biometric data cannot be
changed if compromised. Many organisations deploy biometric systems without
informing employees about how their biometric data is stored, who has access to
it, whether it is shared with third-party vendors, and what happens to it after
the employee leaves the organisation. Under the DPDPA, this data requires informed
consent, robust security safeguards, and defined retention and deletion
policies.
4. Uncontrolled Vendor Data
Sharing
A typical HR tech stack involves multiple
vendors: a cloud HRIS provider, a separate payroll processor, an ATS vendor, a
background verification agency, an insurance administrator, a learning
platform, and an employee engagement tool. Employee personal data flows to all
of these vendors, often without the employee's knowledge or explicit consent.
Under the DPDPA, the Data Fiduciary (the employer) is responsible for ensuring
that every Data Processor (vendor) processes data only for the specified
purpose and implements adequate security safeguards. Most organisations have
not audited their HR vendor contracts for DPDPA compliance.
5. Indefinite Retention of
Employee Records
Organisations retain employee records for years,
sometimes decades, after an employee has left. Full personnel files, including
Aadhaar copies, PAN cards, bank details, medical records, and performance
reviews, remain in HR systems indefinitely. The DPDPA requires that personal
data be erased when the purpose for which it was collected has been fulfilled.
While certain records must be retained under labour law, tax law, or regulatory
requirements, the vast majority of HR data has no legal basis for retention
beyond a reasonable period after the employment relationship ends.
6. Performance Data and Automated
Decision-Making
HR tech platforms increasingly use algorithms
for performance scoring, promotion recommendations, compensation benchmarking,
and even termination risk prediction. These automated decisions directly affect
employees' careers and livelihoods. Under the DPDPA, Data Principals have the
right to information about how their data is being processed. When algorithmic
decisions affect employees, organisations must be transparent about the data
inputs, the decision logic, and the basis for outcomes. Most HR tech platforms
offer no such transparency.
7. Cross-Border Data Transfers
Without Assessment
Cloud-based HR tech platforms often store and
process data in servers located outside India. Multinational organisations
share employee data with parent companies or group entities in other countries.
Under the DPDPA, cross-border transfers are permitted except to jurisdictions
specifically restricted by the Central Government. However, the employer
remains fully responsible for ensuring that overseas processors maintain
adequate security safeguards. Many organisations have not assessed whether
their HR tech vendors' data hosting locations comply with DPDPA requirements.
Chapter 4: DPDPA Obligations Specific to HR Tech
Informed, Purpose-Specific Consent
Employees must be informed, in clear and plain
language, about what personal data is being collected, why it is being
collected, which systems will process it, which vendors will receive it, and
how long it will be retained. Consent must be obtained separately for each
distinct purpose: payroll, benefits, performance management, learning and
development, biometric attendance, employee surveys, and any other processing
activity. Employees must be able to withdraw consent for non-essential
processing without affecting their employment.
Data Minimisation Across HR
Systems
Each HR system should collect only the data
fields necessary for its specific function. The payroll system needs bank
account details and tax declarations. It does not need the employee's blood
group or spouse's occupation. The LMS needs training records and
certifications. It does not need the employee's Aadhaar number. Every data
field collected across the HR tech stack must be justified against a specific,
documented purpose.
Purpose Limitation and Data
Segregation
Data collected for one HR purpose cannot be used
for another without fresh consent. Biometric data collected for attendance
tracking cannot be repurposed for security surveillance analytics. Performance
review data cannot be used for marketing case studies. Survey response data
collected anonymously cannot be de-anonymised and linked to individual
employees. Each HR tech system must enforce purpose limitation through
technical controls and access restrictions.
Employee Data Principal Rights
Under the DPDPA, employees are Data Principals
with the right to access their data, correct inaccurate data, request erasure,
and file grievances. This means the HR tech stack must support individual-level
data retrieval across all systems. When an employee asks "What data do you
have on me?", the organisation must be able to produce a comprehensive
response covering HRIS, payroll, ATS, performance management, biometrics, LMS,
engagement platforms, and benefits systems. When an employee requests data erasure,
it must be executed across every system where their data resides.
Security Safeguards for HR Data
Given the sensitivity of HR data (identity
documents, financial information, medical records, biometric data), the DPDPA
requires robust security safeguards. These include encryption of employee data
at rest and in transit across all HR systems, role-based access controls
ensuring that recruitment teams cannot access payroll data and payroll teams
cannot access performance reviews, multi-factor authentication for all HR tech
platforms, comprehensive audit logging of who accessed what data and when, and regular
security assessments covering every platform in the HR tech stack.
Breach Notification for HR Data
A data breach affecting HR systems is
particularly damaging because it exposes the most sensitive categories of
personal data: identity documents, financial information, medical records, and
biometric data. Under the DPDPA, the Data Fiduciary must notify the Data
Protection Board and each affected employee about the breach. Given that HR
databases are high-value targets for cybercriminals, organisations must
implement breach detection, response, and notification capabilities
specifically for their HR tech infrastructure.
Chapter 5: System-by-System Compliance Breakdown How DPDP Consultants Can Help
HRIS and HCM Platforms
HRIS platforms (SAP SuccessFactors, Workday,
Darwinbox, Keka, greytHR) are the central repository of employee data.
Compliance requires a comprehensive data field audit to identify and remove
unnecessary fields, implementation of granular access controls, defined
retention policies for each data category, mechanisms for handling employee
data access and deletion requests, and data processing agreements with the HRIS
vendor covering DPDPA requirements.
Payroll Systems
Payroll systems process financial personal data
including salary, tax, PF, and bank details on a recurring monthly cycle.
Compliance requires ensuring that payroll data is encrypted and
access-restricted, that historical payroll records are retained only as long as
required by tax and labour law, that payroll vendors have DPDPA-compliant data
processing agreements, and that employees can access their payroll data upon
request.
Recruitment and ATS
Recruitment platforms accumulate large volumes
of candidate personal data: resumes, interview notes, assessment scores, and
background verification reports. Most organisations retain rejected candidate
data indefinitely. Under the DPDPA, candidate data should be retained only for
a reasonable period. Candidates who were not hired must have their data deleted
unless they provide specific consent for retention in a talent pool. Background
verification reports, which often contain highly sensitive information, require
particular attention to consent and retention.
Biometric Attendance Systems
Biometric systems present the highest compliance
risk in the HR tech stack. Fingerprint and facial recognition data is
irrevocable: unlike a password, a compromised fingerprint cannot be reset.
Compliance requires explicit, informed consent for biometric data collection
with a clear alternative for employees who decline, encryption and secure
storage of biometric templates, strict access controls limiting who can access
raw biometric data, immediate deletion of biometric data when the employment
relationship ends, and regular security audits of the biometric system and its
vendor.
Performance Management Platforms
Performance data directly affects employees'
careers: promotions, compensation, role changes, and terminations. Compliance
requires transparency about what data feeds into performance assessments,
clarity on whether algorithmic scoring or recommendations are used, employee
access to their complete performance records, defined retention periods for
performance history, and policies on how performance data is used after an
employee exits.
Employee Engagement and Survey
Platforms
Engagement surveys often promise anonymity but
collect metadata that can identify respondents: department, tenure band,
location, role level. If survey data can be linked to an individual employee,
directly or indirectly, it is personal data under the DPDPA. Compliance
requires genuine anonymisation where anonymity is promised, clear consent when
surveys collect identifiable data, defined retention and deletion policies, and
transparency about who accesses survey results and at what level of granularity.
Chapter 6: HR Tech DPDPA Compliance Roadmap
Step 1: Audit Every HR System
Conduct a comprehensive audit of every platform
in your HR tech stack. Map every personal data field collected by each system:
HRIS, payroll, ATS, performance management, biometrics, LMS, engagement
platforms, and benefits administration. Document what data is collected, from
where, for what purpose, who has access, which vendors receive it, and how long
it is retained. This data map is the foundation of your compliance programme.
Step 2: Redesign Employee Consent
Replace blanket onboarding consent with
granular, purpose-specific consent mechanisms. Create separate consent flows
for payroll processing, benefits administration, performance management,
biometric attendance, learning and development, engagement surveys, and any
other distinct processing purpose. Ensure consent notices are in clear, plain
language and available in English, Hindi, and relevant regional languages.
Implement mechanisms for employees to withdraw consent for non-essential
processing.
Step 3: Secure Every HR Platform
Implement encryption for all employee data at
rest and in transit across every HR system. Configure role-based access
controls so that each team accesses only the data relevant to their function.
Enable multi-factor authentication on all HR tech platforms. Establish
comprehensive audit logging. Conduct penetration testing on all HR platforms,
particularly cloud-hosted and internet-facing systems.
Step 4: Train HR Teams
HR professionals handle personal data daily but
are rarely trained on data protection. Deliver DPDPA-specific training covering
what constitutes personal data, how to obtain valid consent, how to handle
employee data requests, how to respond to potential breaches, and the
consequences of non-compliance. Training must cover every HR role: recruiters,
HR business partners, payroll teams, benefits administrators, and HR
leadership.
Step 5: Review Every HR Tech
Vendor
Audit every vendor that receives employee data.
Review data processing agreements with your HRIS provider, payroll processor,
ATS vendor, background verification agency, insurance administrator, biometric
system provider, LMS vendor, and engagement platform. Ensure each agreement
specifies DPDPA-compliant data handling obligations, security requirements,
retention limits, breach notification procedures, and sub-processor
restrictions. Where agreements are absent or inadequate, renegotiate them.
Step 6: Implement Ongoing
Monitoring
DPDPA compliance is not a one-time project.
Implement automated data retention policies that delete employee records when
their retention period expires. Set up continuous monitoring of access patterns
and data flows across HR systems. Maintain documentation of consent records,
processing activities, vendor assessments, and employee data requests. Conduct
periodic compliance audits and update your data protection framework as your HR
tech stack evolves.
Chapter 7: How DPDP Consultants Can Help
HR tech compliance under the DPDPA requires
specialised expertise that bridges data protection law, human resources
operations, and technology. DPDP Consultants provides end-to-end compliance
services tailored to the HR tech ecosystem.
DPDPA Gap Assessment
We audit your entire HR tech stack, covering
HRIS, payroll, ATS, biometrics, performance management, LMS, engagement
platforms, and benefits systems, against every DPDPA requirement. Our
assessment identifies exactly where your HR data processing stands and what
needs to change.
Privacy Framework Implementation
We design and implement an HR-specific privacy
framework covering employee consent workflows, purpose mapping for every HR
data touchpoint, data minimisation policies, retention schedules for each data
category, and Data Principal rights fulfilment mechanisms tailored to the
employer-employee relationship.
Consent Management Platform
Our Data Principal Consent Management tool
integrates with your HRIS and onboarding workflows to capture granular,
purpose-specific consent at every employee touchpoint, manage consent
withdrawal, and maintain audit-ready records that demonstrate compliance.
Grievance Redressal System
Our automated Grievance Redressal platform
handles employee requests for data access, correction, and erasure, tracking
every request from receipt to fulfilment within DPDPA timelines across all HR
systems.
DPO as a Service
Our Data Protection Officers provide ongoing
oversight of your HR data processing, manage vendor compliance, handle
regulatory communications, oversee breach response, and ensure continuous DPDPA
adherence across your HR tech stack.
Awareness Programme
We deliver DPDPA awareness training programmes
customised for HR teams, covering recruiters, HR business partners, payroll and
benefits administrators, HR leadership, and people managers who handle employee
data daily.
Third-Party Assessment
We evaluate every HR tech vendor in your
ecosystem, including HRIS, payroll, ATS, biometrics, LMS, and engagement
platforms, ensuring appropriate data processing agreements and DPDPA-compliant
security safeguards are in place.
Chapter 8: Frequently Asked Questions (FAQs)
Q: Does the DPDPA apply to
employee data or only customer data?
The DPDPA applies to all personal data processed
by any organisation, including employee data. Employers are Data Fiduciaries
for their employees' personal data. Every HR system that collects, stores, or
processes employee information must comply with the Act.
Q: Can we use biometric attendance
without employee consent?
No. Biometric data is personal data under the
DPDPA. Organisations must obtain informed, specific consent before collecting
fingerprints, facial geometry, or any biometric data. Employees who decline
biometric consent must be provided with an alternative attendance mechanism.
Q: Do we need separate consent for
each HR tech system?
You need separate consent for each distinct
processing purpose, not necessarily each system. However, if different HR
systems process data for different purposes (payroll for salary processing, LMS
for learning, engagement platform for surveys), each purpose requires its own
consent. Bundling all purposes into a single onboarding checkbox is
non-compliant.
Q: How long can we retain employee
data after they leave?
Only as long as required by law or a valid
purpose. Tax records may need to be retained for 7-8 years under Income Tax Act
requirements. PF records have their own retention periods. However, data such
as biometric templates, performance reviews, interview notes, and survey
responses should be deleted once the employment relationship ends and any legal
retention obligation has expired.
Q: Are cloud-based HR platforms
compliant with the DPDPA?
Using a cloud-based platform does not
automatically make you non-compliant or compliant. The employer (as Data
Fiduciary) must ensure the platform vendor (as Data Processor) processes data
only for specified purposes, implements adequate security safeguards, and has a
DPDPA-compliant data processing agreement in place. If the platform stores data
outside India, the employer must verify the hosting jurisdiction is not
restricted.
Q: Can HR share employee data with
group companies?
Sharing employee data with group companies or
parent organisations is a separate processing purpose that requires its own
consent. An employee consenting to their data being processed for payroll by
their employer does not automatically consent to that data being shared with
the parent company for global workforce analytics.
Q: What are the penalties for HR
data non-compliance?
Penalties under the DPDPA range up to Rs 250
crore depending on the nature and severity of the violation. For HR data
breaches involving Aadhaar numbers, bank details, medical records, and
biometric data, the exposure is significant. Beyond financial penalties, HR
data breaches severely damage employer brand and employee trust.
Q: Does the DPDPA affect
background verification processes?
Yes. Background verification involves collecting
and processing personal data including educational records, employment history,
criminal records, and reference checks. Organisations must obtain specific
consent for background verification, inform candidates about what checks will
be conducted, and ensure the verification agency has adequate data processing
agreements. Verification reports should be retained only as long as necessary.
Make Your HR Tech Stack DPDPA-Compliant
Your HR tech stack processes the
most sensitive personal data in your organisation. The DPDPA holds you
accountable for protecting it.
DPDP Consultants provides the
expertise and technology to make your HR operations fully compliant. From Gap
Assessments and Privacy Framework Implementation to Consent Management, DPO as
a Service, and Third-Party Assessments, we cover every aspect of HR data
protection.
Contact us today:
Website: www.dpdpconsultants.com
Email: info@dpdpconsultants.com
Disclaimer: This
document is prepared by DPDP Consultants for informational purposes only. It
does not constitute legal advice and should not be relied upon as a substitute
for professional legal counsel. The information contained herein is based on
the Digital Personal Data Protection Act, 2023, and publicly available
information about the DPDP Rules as of August 2026. Laws, regulations, and
their interpretations may change. Readers should consult qualified legal
professionals for advice specific to their circumstances. DPDP Consultants
assumes no liability for any actions taken or not taken based on the contents
of this document.