Part of SKAD HR Group β€” HR for every stage of business  Β·  HRTailor.com  Β·  HRTailor.AI

The DPDP Act Is No Longer “Coming Soon”

The Digital Personal Data Protection Act, 2023 is India’s first comprehensive data privacy law. With the Rules notified on 14 November 2025, the law is now fully operational β€” and it applies to every piece of digital personal data your organisation processes, including employee data.

The penalty for a data breach under the DPDP Act: up to β‚Ή250 crore per incident. Employee data β€” payroll, biometrics, health records β€” is all covered. No exemptions for size.

For HR teams, this is not a marginal change. The DPDP Act covers salary records, biometric attendance data, health and insurance records, performance reviews, background verification reports, and any other employee information stored or processed digitally.

The penalty for a data breach? Up to β‚Ή250 crore per incident. There is no “minor violation” category.


What Counts as Employee Personal Data Under the DPDP Act?

The Act defines personal data broadly: any data that identifies or can identify a natural person. For HR departments, this includes:

  • Payroll data: Salary breakups, bank account details, PAN, tax declarations
  • Identity documents: Aadhaar copies, passport details, address proofs
  • Biometric data: Fingerprints, facial recognition records from attendance systems
  • Health records: Medical insurance claims, fitness certificates, disability disclosures
  • Performance data: Appraisal scores, disciplinary records, promotion histories
  • Communication data: Official email content, internal chat records, recorded calls

Every one of these categories falls under the Act’s protection framework. The obligation lies with the Data Fiduciary β€” your organisation β€” to ensure this data is collected, stored, processed, and shared in compliance with the Act.


The Two Roles You Must Understand

Data Fiduciary (Your Company)

Your organisation is the Data Fiduciary. This means you determine the purpose and means of processing employee data. You bear primary legal responsibility for compliance, including:

  • Obtaining valid consent from employees for data processing
  • Ensuring data is used only for the stated purpose
  • Implementing reasonable security safeguards
  • Responding to data access and correction requests

Data Processor (Your Vendors)

Every external vendor that handles employee data on your behalf β€” payroll providers, background verification agencies, insurance administrators, cloud HR platforms β€” is a Data Processor. The critical requirement: you must have a signed Data Processing Agreement (DPA) with each Data Processor before sharing any employee data.

This is not optional. The absence of a DPA makes every data transfer a potential compliance violation.


Six Steps Every HR Team Must Take Now

1. Map Every Data Flow

Create a complete inventory of where employee personal data is collected, stored, processed, and shared. This includes:

  • Internal systems (HRMS, payroll software, attendance systems, email)
  • External vendors (payroll outsourcing, BGV agencies, insurance providers, IT service providers)
  • Cloud storage and backup locations
  • Physical records that have been digitised

You cannot protect what you have not mapped.

2. Audit Consent Mechanisms

The DPDP Act requires “free, specific, informed, and unambiguous” consent. A generic line in the employment agreement signed three years ago is unlikely to meet this standard.

Review and update:

  • The consent clause in your offer letter / employment agreement
  • Consent for specific processing purposes (payroll, insurance, background checks)
  • Consent for data sharing with third-party processors
  • The mechanism for employees to withdraw consent

3. Execute Data Processing Agreements

For every vendor that touches employee data:

  • Draft or review the DPA to ensure it covers data security obligations, breach notification timelines, data retention and deletion policies, and sub-processor restrictions
  • Ensure the DPA is signed before any data sharing begins (or renewed if the existing agreement predates the DPDP Rules)

4. Implement a Data Breach Response Plan

The Act mandates breach notification to the Data Protection Board and affected individuals. Your plan should include:

  • A defined incident response team with clear roles
  • Breach detection and escalation procedures
  • Notification templates and timelines
  • Post-breach remediation steps

Do not wait for a breach to create this plan.

5. Review Data Retention Policies

The DPDP Act requires that personal data be deleted once the purpose for which it was collected has been fulfilled. For HR data, this means:

  • Defining retention periods for each data category (payroll records, BGV reports, medical records)
  • Automating deletion workflows where possible
  • Documenting exceptions (statutory requirements for PF/ESI records, for example, mandate longer retention)

6. Train Your HR Team

The most sophisticated compliance framework fails if the people handling data daily do not understand their obligations. Conduct DPDP-specific training for:

  • HR operations staff handling employee records
  • Payroll team members processing salary and tax data
  • IT administrators managing HR systems and access controls
  • Managers who access performance and disciplinary records

The Payroll Outsourcing Angle

Payroll is the single largest concentration of sensitive employee data in most organisations. Every payroll cycle involves processing salary details, bank accounts, PAN numbers, PF/ESI contributions, and tax computations for every employee.

When you outsource payroll, the vendor becomes a Data Processor with access to this entire dataset. Under the DPDP Act, this relationship must be governed by a formal DPA, the vendor must implement security safeguards equivalent to or exceeding your own, and any breach at the vendor’s end is ultimately your liability as the Data Fiduciary.

This is why choosing a payroll outsourcing partner is no longer just about accuracy and turnaround time. It is about data governance, security infrastructure, and DPDP readiness.


How TMS Handles Employee Data

TMS processes payroll and employee data for companies with 100 to 5,000+ employees across India. Our data handling framework is built for the DPDP Act:

  • Signed Data Processing Agreements as standard practice with every client
  • Role-based access controls on all employee data systems
  • Defined data retention and deletion policies aligned with statutory requirements
  • Documented breach response procedures with defined notification timelines
  • Regular security audits of our processing infrastructure

If your current payroll or HR vendor cannot show you a signed DPA and a documented data protection framework, that is a compliance gap β€” and it is your liability, not theirs.

Is Your Employee Data DPDP-Compliant?

TMS processes payroll and employee data with signed DPAs, role-based access, and documented security protocols as standard.

Contact TMS Explore HR Outsourcing

Sources: Digital Personal Data Protection Act, 2023; DPDP Rules (notified 14 Nov 2025); SaachiHRMS DPDP & Employee Data Guide; India Briefing HR Compliance Guide 2026

Powered by Joinchat