DPDP for HR: Employee Data Has No Carve-Out
Every company has this obligation from the day it hires someone, and in most organisations HR data is governed less carefully than customer data.
There is no employment exemption
Some regimes handle employment separately. The DPDP Act does not. An employee is a Data Principal like anyone else, and the employer is the Data Fiduciary.
This usually covers more data than people expect: recruitment pipelines and rejected candidates, payroll and bank details, performance records, background verification results, health and attendance data, and exit records.
Why HR is the weakest link in most companies
- It sits outside engineering, so it rarely appears on a data inventory.
- Applicant tracking systems accumulate rejected candidate data indefinitely with no defined retention.
- Spreadsheets and shared drives hold copies of payroll and appraisal data outside any access control.
- Rule 6(1)(b) access control and 6(1)(c) logging are frequently absent from HR tooling entirely.
Retention is the fastest win
Rule 8 requires erasure once the specified purpose is no longer served, subject to retention required by law. Rejected candidate data has a clear point at which the purpose ends. Setting and enforcing that period removes a large volume of risk with little operational cost.
Most companies protect customer data far better than employee data, then discover that the employee data set is larger, older and more sensitive.
Infosek Team
Priorities
- Add HR, payroll and recruitment systems to the data inventory. They are often missing entirely.
- Set a retention period for candidate data and enforce it in the applicant tracking system.
- Review who can read payroll and appraisal data, and whether that access is logged.
- Assess your basis for each HR processing activity rather than relying on a contractual consent clause.
- Get processor clauses in place with payroll providers, background verification vendors and benefits administrators.
Common questions
Does the DPDP Act cover employee data?
Yes. Nothing in section 3 exempts processing in an employment context. HR records, payroll, recruitment and performance data are all processing of digital personal data with the employer as Data Fiduciary.
Can employers rely on consent for processing employee data?
Consent under section 6 must be free, and consent given in an employment relationship is often argued not to be. Section 7 sets out certain legitimate uses, including for purposes of employment, which is usually the more appropriate footing to examine.
Mapping your HR systems?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment