Checklist · HR Head

DPDPA Checklist for HR Heads

Substantive DPDPA obligations commence 13 May 2027. HR starts from a stronger position than most functions — Section 7(i) covers employment processing without consent. The risk is assuming it covers everything. It does not reach candidates, dependants, or anything unrelated to the employment relationship. Ten items to own.

Last reviewed: 30 July 2026

What must an HR head do for DPDPA compliance?

  1. Split the workforce data map by lawful ground before doing anything else. Three buckets, and the whole programme depends on drawing them correctly:
    Population / purposeGroundNote
    Current employees — hiring-to-exit administration, payroll, statutory filings, performance, discipline, IP and confidentiality protection, benefits the employee soughtSection 7(i)No consent required
    Candidates and applicantsSection 6 consent, or 7(a) narrowly for the role applied toNot employees yet — 7(i) is unavailable
    Anything unrelated to employment — employer branding using employee images, alumni marketing, data shared with a third party for their purposesSection 6 consentSeparate, itemised, withdrawable
    Section 7(i) covers processing for the purposes of employment, or to safeguard the employer from loss or liability — prevention of corporate espionage, maintenance of confidentiality of trade secrets, IP and classified information — and provision of a service or benefit sought by an employee. Read the second half carefully: it is bounded by employment, not by "we are the employer, so we may."
  2. Fix the application form and stop the silent talent pool. A candidate who applies to an advertised role has voluntarily provided data for that role. Section 7(a) reasonably supports processing that application; it does not support indefinite retention in your ATS, submission to a group company, or contacting them about unrelated openings two years later. Add an explicit, separate, defaulted-off choice for "keep me on file for future roles," with a stated period. Then delete the rejected pipeline you cannot account for. Owner: you + TA lead.
  3. Publish an employee privacy notice and run the Section 5(2) exercise. Section 7(i) removes the consent requirement — it does not remove transparency, purpose limitation, accuracy, security or rights. Serve a notice meeting Rule 3: an itemised description of the personal data and the specified purposes, in clear plain language, presented independently of your other HR policy documents, in English or any Eighth Schedule language. Separately, Section 5(2) requires that where consent was obtained before commencement, you give those Data Principals the required notice as soon as reasonably practicable — so wherever you did take employee consent historically, that population needs the notice too. Do it in an appraisal off-cycle.
  4. Treat dependants, nominees and emergency contacts as separate Data Principals. Spouse, children, parents and nominees in your gratuity, PF, group medical and insurance records are individuals with their own access and correction rights over data you hold about them — collected from the employee, never from them. And any dependant under 18 triggers Section 9: verifiable parental consent with Rule 10 due diligence that the consenting individual is an identifiable adult, verified by reliable identity and age details you already hold, details voluntarily provided, or a virtual token from an authorised entity including a Digital Locker service provider. Same applies to interns and apprentices under 18 on your rolls. No education or healthcare carve-out under Rule 12 applies to a private employer.
  5. Get written processor contracts on the HR stack — and characterise each vendor deliberately. Payroll bureau, HRIS, ATS, background verification, assessment platforms, wellness and EAP apps, biometric attendance, expense and travel tools, cloud host. Most are Data Processors and may process only under a valid written contract; Rule 6(1)(f) requires appropriate security provisions in it. Add purpose limits, sub-processing consent, deletion on exit, and an incident-escalation SLA in hours. But some are Data Fiduciaries in their own right — your group insurer and its TPA process claims for their own regulated purposes, which makes the disclosure to them a third-party disclosure, not an instruction to a processor. Wellness and EAP vendors are the ones to look at hardest: if the app profiles employees for its own product improvement or aggregates health signals back to you, that is a purpose neither 7(i) nor your contract covers.
  6. Build a retention map against statutory floors — in both directions. There is no 12-month or any other blanket re-consent rule under DPDPA; retention is governed by purpose limitation plus the erasure duty, qualified where retention is necessary for compliance with a law in force. So map: data class → statutory basis and period → what happens at expiry. Your EPF, ESI, income-tax and TDS, Payment of Wages, Shops and Establishments, Contract Labour and POSH records each have their own retention basis — cite the specific one, not "we may need it." Then note the floors that cut the other way: Rule 6(1)(e) requires retaining access logs and personal data for one year as a security safeguard, and Rule 8(3) sets a one-year minimum for personal data, associated traffic data and processing logs. What survives neither test: rejected-candidate files from closed mandates, exit-interview transcripts past their purpose, appraisal drafts, WhatsApp groups full of salary discussions, and scanned Aadhaar and PAN copies retained out of habit.
  7. Draw the line on monitoring before Legal has to. CCTV, email and endpoint monitoring, device management, biometric attendance and access logs sit substantially within Section 7(i) — safeguarding the employer from loss or liability and maintaining confidentiality of trade secrets and IP is expressly named. What sits outside: continuous location tracking of employees off duty, monitoring personal devices beyond the managed work container, productivity or sentiment scoring sold to you as analytics but built on content the notice never mentioned, and anything repurposed from a security control into a performance input. The test is whether the processing is genuinely for employment or loss-prevention. Document the scope and disclose it in the notice — undisclosed monitoring is a transparency failure even where the ground holds.
  8. Stand up the rights machinery, and size it for volume. Rule 9 requires prominently publishing on your website or app the business contact information of the person able to answer processing questions, and repeating it in every response to a rights request. Rule 14(1) requires publishing the means by which a Data Principal makes a request and any identifier you need. Rule 14(3) requires the grievance system to respond within a period not exceeding ninety days. Rule 14(4) requires supporting nomination. Two HR-specific warnings: employee access requests spike during disputes and exits, so build the retrieval workflow before you need it under adversarial conditions; and your DPDPA grievance channel is not your POSH Internal Committee, your works committee, or your ethics hotline — keep them separate and route correctly.
  9. Check where Indian employee data physically sits and who abroad can open it. Rule 15 applies to every Data Fiduciary transferring personal data outside India, subject to requirements the Central Government may specify by general or special order — it is not an SDF-only obligation. If your HRIS is hosted offshore, or a global HQ, regional COE or shared-service centre can query Indian employee records, that is a transfer to inventory and document now. The stricter localisation restriction under Rule 13(4) applies only if you are notified as a Significant Data Fiduciary.
  10. Rehearse an HRIS or payroll breach on paper. Four obligations run in parallel and are cumulative, not alternatives: CERT-In within 6 hours of noticing; Rule 7(1) intimation to each affected employee without delay; Rule 7(2)(a) initial intimation to the Data Protection Board without delay; Rule 7(2)(b) detailed report to the Board within 72 hours. Most playbooks have only the 72-hour filing — the Board gets two. Rule 7(1) prescribes the employee notice contents: nature, extent and timing of the breach, consequences relevant to them, mitigation implemented, safety steps they can take, and business contact information for someone who can respond. Pre-draft it, name an owner and an alternate, and run the scenario as a Friday-evening payroll-vendor compromise, since that is the realistic shape.

Frequently asked questions

Section 7(i) means we never need employee consent — right?

For the core employment relationship, largely yes, and that is a real advantage over sectors that must consent everything. Section 7(i) permits processing for the purposes of employment, or to safeguard the employer from loss or liability — expressly including prevention of corporate espionage and maintenance of confidentiality of trade secrets, IP and classified information — and for providing a service or benefit sought by an employee. Payroll, statutory filings, performance management, discipline, access control and IP protection all sit there. Where it stops: candidates and applicants, because there is no employment relationship yet; dependants, nominees and emergency contacts, who are separate Data Principals; ex-employees beyond what a retention obligation or live purpose supports; and anything unrelated to employment, such as using employee photographs and testimonials in recruitment marketing or on your website, sharing employee data with a group entity or partner for their own purposes, or letting a wellness vendor profile your workforce for its own product. Those need Section 6 consent — itemised, plain language, by clear affirmative action, and as easy to withdraw as to give. And note the ground is not the whole obligation: even under 7(i) you still owe notice, purpose limitation, accuracy, reasonable security safeguards, erasure, breach notification and the full rights set.

An ex-employee emails asking us to delete everything we hold. What must we actually do?

Answer within the ninety-day ceiling under Rule 14(3), and split the request. Data you are required to retain under a law in force stays — your EPF, ESI, income-tax and TDS, wage register, POSH proceedings and contract-labour records each have their own statutory basis and period, and you should be able to name it per record rather than asserting a general need. There is also a one-year floor from Rule 6(1)(e) and Rule 8(3) on personal data, associated traffic data and processing logs. Everything else goes once the purpose is served: retained CVs and interview notes, internal chat and email copies, appraisal drafts, engagement-survey responses linked to them, wellness and EAP records, and copies sitting in your payroll bureau's and HRIS vendor's environments — that last one is the commonly missed piece, because deletion in your primary system does not propagate to a processor unless you cause it to. Tell them plainly what you are keeping and why. And to retire the myth directly: there is no 12-month re-consent rule in DPDPA or the DPDP Rules, 2025, for employee or candidate data. The three-year erasure duty in the Third Schedule attaches to specified classes — large e-commerce entities, online gaming intermediaries and social media intermediaries — not to employers.

Our HRIS is breached. What do we report, what does it cost, and do we need a DPO and an annual audit?

Report on all four lanes above — CERT-In at 6 hours, employees without delay, the Board without delay and again in detail at 72 hours — and remember the obligation is yours as Data Fiduciary even when the breach originated at your payroll bureau or HRIS vendor, which is why their contracts need an alert SLA in hours. Two scoping points: ransomware that locks your HRIS is a personal data breach even with no confirmed exfiltration, because loss of access counts, and a misconfigured storage bucket or an over-permissioned report is a breach with no attacker at all. On exposure, two separate heads under the Schedule, assessed independently, so one incident can attract both: up to ₹250 crore for failure to take reasonable security safeguards under Section 8(5), and up to ₹200 crore for failure to give the required breach intimation under Section 8(6). These are statutory ceilings, not expected fines — the Board sets quantum on the facts, weighing gravity, duration, the type of data affected, whether the conduct was repetitive, and the mitigation you undertook and how promptly, which is precisely why documented safeguards and a rehearsed notification are worth more than a policy document. On governance: Rule 13 — annual DPIA and independent audit, algorithmic due diligence over software used in processing, an India-based Data Protection Officer, and the localisation restriction — binds Significant Data Fiduciaries only, a status conferred by Central Government notification under Section 10 and not triggered automatically by headcount. If you use automated CV screening or attrition-risk scoring, note that algorithmic due diligence is SDF-specific, but the accuracy duty and the individual's correction right apply to you regardless. Every employer still owes the Rule 9 named contact person, whether or not a DPO is required. One last point that catches HR: DPDPA has no separate "sensitive personal data" tier — occupational health records, disability disclosures, POSH complaint files and a mobile number all sit under one legal standard. The difference is the harm, not the rule, and it should drive your access controls even though it does not change the law that applies.

Official sources

Thirty minutes on where Section 7(i) actually ends

We walk your HR stack: employee notice vs candidate form, dependant and nominee records, HRIS and payroll contracts, monitoring scope, retention against statutory floors, and what happens when an ex-employee emails "delete everything." You leave with a written gap list mapped to Section 7(i), Section 6 and the security safeguards duty — whether or not you work with us.

Book a demo call Free Gap Analysis

Bring your employee privacy notice and the name of your HRIS. No deck.

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.