A payroll export sits on a laptop that goes missing on a client visit. A former employee emails to ask what records you still keep about her. A few years ago, your HR team handled both with a shrug and a password reset. Under the Digital Personal Data Protection (DPDP) Rules, 2025, each one now has a defined response, a clock, and a penalty attached.
The short answer for HR is this. Most employment processing does not need fresh consent, because the DPDP Act treats employment as a legitimate use. However, the rules on security, breach reporting, retention, vendor contracts, and grievances apply to every employee record you hold. Most of those duties apply from 13 May 2027.
Key Takeaways
- The DPDP Rules were notified on 13 November 2025. Most obligations apply from 13 May 2027.
- Section 7(i) of the Act lets you process employee data for employment purposes without consent. Optional activities, such as using employee photos in marketing, still need consent.
- You must tell the Data Protection Board about a breach without delay and send a detailed report within 72 hours. Affected employees must also hear from you without delay.
- Keep access logs for at least one year, and erase employee data once its purpose ends, unless another law requires you to keep it.
- Your payroll provider, HRMS, and background verification vendor are data processors. You stay responsible for what they do with your employees’ data.
This guide explains the law in plain terms. It is not legal advice, so review your final policies with counsel.
What the DPDP Rules Mean for Employee Data
The Digital Personal Data Protection Act, 2023 sets out the principles. The DPDP Rules, 2025 explain how to follow them in practice. Together, they cover personal data collected in digital form, as well as paper records that you later digitize.
For an HR team, three terms matter most:
| DPDP Term | What It Means in HR |
| Data Fiduciary | Your company, as the employer that decides why and how employee data is used |
| Data Principal | Each employee, candidate, intern, or former employee whose data you hold |
| Data Processor | Any vendor that handles employee data for you, such as a payroll provider, HRMS, or background check agency |
So when the Rules say “Data Fiduciary,” read “employer.” In addition, remember that candidates and ex-employees count as Data Principals too. That point shapes how you handle resume databases and exit records later in this guide.
DPDP Rules Timeline: When Each Obligation Applies to HR
The Rules come into force in three steps, measured from their publication in the Gazette on 13 November 2025. The government’s announcement describes this as an 18-month phased timeline.
| Date | What Comes Into Force | What It Means for HR |
| 13 November 2025 | Definitions and the rules that set up the Data Protection Board | No new HR duties yet. The regulator starts forming |
| 13 November 2026 | Registration and duties of Consent Managers (Rule 4) | Consent Managers can register. Useful if you plan to route optional consents through one |
| 13 May 2027 | Notice, security, breach reporting, retention, rights, and grievance rules (Rules 3 and 5 to 16) | Your full employee data program must work by this date |
Reports in early 2026 said the government had discussed shortening this window for large data handlers. We could not find a notified amendment as of September 2026. Even so, check the Ministry of Electronics and Information Technology (MeitY) website before you lock your internal deadlines.
Consent vs Legitimate Use: Which One Covers Employee Data?
This is the first question most HR teams ask, and the answer saves you a lot of paperwork.
The DPDP Act allows processing on two grounds: consent, or a “legitimate use” listed in Section 7. Section 7(i) covers processing for the purposes of employment. It also covers work that protects the employer from loss or liability, such as guarding trade secrets. Finally, it covers any service or benefit an employee asks for.
As a result, you do not need to collect consent to run payroll, file TDS, or approve a timesheet. Many companies still bury a blanket consent clause in the offer letter. Under the DPDP Act, that clause is often unnecessary for core HR work. It can also cause trouble, because an employee can withdraw consent at any time.
Still, Section 7(i) has limits. It covers what employment needs, so activities outside that scope need consent or another basis. The table below shows how many advisers read common HR activities. Treat it as a starting point for your own legal review.
| HR Activity | Likely Lawful Basis | What to Do |
| Payroll, TDS, PF, and other statutory filings | Legitimate use, Section 7(i) | Document the purpose. No consent form needed |
| Timesheets, project allocation, and performance reviews | Legitimate use, Section 7(i) | Limit access to people who need it |
| Reimbursements and benefits an employee requests | Legitimate use, Section 7(i) | Collect only what the claim needs |
| Security monitoring on company devices | Legitimate use, Section 7(i), if proportionate | Tell employees what you monitor and why |
| Background checks on candidates | Debated among lawyers | Many firms use a clear notice plus consent |
| Employee photos or quotes in marketing | Consent | Use a separate, easy-to-withdraw consent |
| Optional wellness or engagement surveys | Consent | Keep participation optional and consent specific |
| Alumni and rehire databases after exit | Consent | Ask at exit and honor withdrawals |
One more detail matters here. The rights to access, correct, and erase data under Sections 11 and 12 attach to data given with consent or voluntarily shared under Section 7(a). Data processed only under the employment legitimate use falls outside those two rights. Even so, the grievance right under Section 13 and every general duty in Section 8 still apply. Many employers will answer access requests anyway, because good records make that easy and it builds trust.
8 Changes HR Teams Need to Make Under the DPDP Rules
The Rules turn broad principles into specific tasks. Below are the eight changes that affect HR most, with the exact rule behind each one.
1. Map Every Place Employee Data Lives
You cannot protect data you cannot find. So, start with an inventory of every system and file that holds employee or candidate data.
For most firms, that list is longer than expected. It usually includes:
- The HRMS and payroll system, including salary structures, bank details, and national IDs
- Attendance devices and timesheet tools
- Reimbursement claims and receipts
- Recruitment inboxes and resume folders
- Background verification reports held by vendors
- Shared drives and spreadsheets used for appraisals or bonus planning
Professional services firms have one extra place to check. When you staff people on client projects, their pay rates often sit inside project budgets and margin reports. That is salary data too, and it needs the same access controls as your payroll register. For a structured way to run this review, use the records and data security steps in our HR audit guide.
2. Rewrite Employee Notices Wherever You Rely on Consent
Rule 3 sets out what a consent notice must contain. It must stand on its own and use clear, plain language. At minimum, it must include:
- An itemized description of the personal data you collect
- The specific purpose of processing and what it enables
- A link to withdraw consent, which must be as easy as giving it
- How the employee can exercise their rights and complain to the Data Protection Board
For consent-based activities, such as marketing photos or optional surveys, build a separate notice for each. For core employment processing under Section 7(i), a notice is not strictly required. Nevertheless, a short employee privacy statement explaining what you collect and why is good practice and reduces grievances later.
3. Restrict Who Can See Salary and Identity Data
Rule 6 lists the minimum “reasonable security safeguards” every employer must take. Two of them hit HR directly. First, you must protect data through measures such as encryption, masking, or obfuscation. Second, you must control access to the systems that hold it.
In practice, that means role-based access. A project manager may need to see who is on the team and how many hours they logged. However, they rarely need each person’s pay rate or bank account number. Likewise, an employee should see their own payslip and nobody else’s.
Also, add a check on sensitive changes. When someone updates a bank account or national ID, a second person should approve it before payroll runs. It also makes payroll fraud through changed bank details harder.
4. Turn On Access Logs and Keep Them for a Year
Rule 6 also asks for visibility into who accessed personal data, through logs, monitoring, and review. It then requires you to keep those logs, along with the related personal data, for one year, unless another law says otherwise.
Separately, Rule 8(3) sets a minimum one-year retention period for personal data, traffic data, and processing logs, for purposes listed in the Seventh Schedule. These purposes relate to lawful requests from the State.
For HR, the takeaway is simple. Do not purge system logs on a short cycle. Check whether your HRMS and payroll vendor keep an audit trail of views and edits, and confirm how long they store it.
5. Build a 72-Hour Breach Response Playbook
Rule 7 sets out two parallel duties when a breach happens.
Tell affected employees without delay
Your message must describe the breach and its likely effect on them. It must also say what you are doing about it, how they can protect themselves, and who to contact.
Tell the Data Protection Board in two stages
First, send a description of the breach without delay. Then, within 72 hours of becoming aware of it, send a detailed report. That report covers the facts, causes, mitigation steps, any findings about who caused it, and what you told employees.
A lost laptop with a payroll export counts. So does a salary file emailed to the wrong list. Therefore, agree in advance who in HR, IT, and leadership owns each step. Keep message templates ready, and run one tabletop drill before May 2027.
6. Set Retention and Deletion Rules for Candidates and Ex-Employees
Section 8(7) of the Act requires you to erase personal data once it is reasonable to assume its purpose is over. The exception is data that another law requires you to keep. You must also make your data processors erase it.
This rule reaches two groups that HR often forgets:
- Rejected candidates. A resume database built over five years, with no purpose attached, is now a liability. Set a clear retention period, and ask for consent if you want to keep profiles for future roles.
- Former employees. Tax, provident fund, and labor laws require you to keep certain payroll and employment records for fixed periods. Keep those records. Then delete what no law requires, such as old ID scans kept “just in case.”
Build this into your offboarding process. Once the full and final settlement closes, trigger a review of what to keep and what to erase.
You may read elsewhere that employers must warn people 48 hours before deleting their data. That rule, in Rule 8(1) and 8(2), applies only to large e-commerce, online gaming, and social media platforms listed in the Third Schedule. It does not apply to employers as a class.
7. Put Your HR Vendors Under a Proper Contract
Every vendor that touches employee data acts as your data processor. Under Section 8 of the Act, you stay responsible for their compliance. Rule 6 adds that your contract with each processor must include provisions on reasonable security safeguards.
List every HR vendor and review each contract for:
- Security measures the vendor commits to
- How fast they will tell you about a breach, so you can meet your 72-hour deadline
- Deletion or return of data when the contract ends
- Any subcontractors they use
Fewer vendors means fewer contracts to manage. That is one reason many growing firms move payroll, attendance, timesheets, and reimbursements onto one platform.
8. Publish a Privacy Contact and a 90-Day Grievance Process
Rule 9 requires you to publish the business contact details of the person who can answer questions about how you process personal data. You must also mention those details in every reply to a rights request.
In addition, Rule 14(3) asks you to publish your grievance response period. That period cannot exceed 90 days. For HR, put the contact in your employee handbook and on your intranet. Then set up a tracked inbox or ticket queue, so no request sits unanswered.
A good employee self-service portal reduces the volume of these requests, because employees can see their own records without asking.
What Does Not Change for HR Under the DPDP Rules
Some duties stay exactly as they are today. It helps to be clear about them before you plan the work:
- You do not need consent for core payroll and HR work: Section 7(i) covers it.
- Statutory retention still applies: Tax, provident fund, and labor law record-keeping periods continue. DPDP erasure duties sit behind them.
- “Verifiable consent” does not mean every employee: Under Rules 10 and 11, verifiable consent applies to data about children and about persons with disabilities who have a lawful guardian.
- Most firms do not need a formal Data Protection Officer: That duty applies to Significant Data Fiduciaries, which the government notifies separately. You still need a named contact under Rule 9.
DPDP Penalties HR Leaders Should Know
The Schedule to the DPDP Act sets the maximum penalty for each type of failure. The Data Protection Board decides the actual amount in each case.
| Failure | Maximum Penalty |
| Not taking reasonable security safeguards to prevent a breach | Up to ₹250 crore |
| Not notifying the Board and affected people of a breach | Up to ₹200 crore |
| Breaching duties related to children’s data | Up to ₹200 crore |
| Breaching additional duties of a Significant Data Fiduciary | Up to ₹150 crore |
| Breaching any other provision of the Act or Rules | Up to ₹50 crore |
For a 100-person firm, the more realistic risk is a finding that your controls were weak when a breach happened. Most of the eight changes above exist to prevent that finding.
DPDP-Ready HR Tech Stack: 5 Tools, Ranked
Software alone will not make you compliant. Even so, the right tools make each of the eight changes far easier to run every month. Here is how we would rank the tool types for a professional services firm with 25 to 150 employees.
1. Juntrax: One Platform for HR, Projects, and Payroll Data
Juntrax brings HRMS, payroll, timesheets, projects, and billing onto one platform. For DPDP, that matters because every extra tool is another system to map, secure, and contract with.
Here is how Juntrax supports the changes in this guide:
- Role-based portals: Employees see their own records, managers see approvals and team views, and admins handle configuration. This supports the access controls Rule 6 asks for.
- Masked sensitive fields: Details such as date of birth and email display masked rather than in plain text.
- Approval before identity changes: Employees cannot edit bank accounts or national IDs directly. Instead, a Request Edit goes to HR for approval.
- Project permissions that hide pay rates: Custom project roles decide who sees team financials. So, a project lead can manage delivery without viewing colleagues’ pay rates.
- Entity-level separation: Firms with offices in more than one country can scope payroll and policies by legal entity.
- A clear processor commitment: The Juntrax Data Protection Addendum sets out how breaches are notified and how data is deleted after the agreed retention period.
You can see the portals screen by screen in our employee self-service portal tour.
Best for: Services firms that want HR, payroll, and project data in one controlled system.
What to check: As the employer, you remain the Data Fiduciary. Pair the platform with your own notices, retention policy, and breach playbook.
2. Consent Management Tool
A consent management tool records who agreed to what, and when. It also makes withdrawal easy.
Best for: Firms with several consent-based activities, such as marketing use of employee content or optional surveys.
What to check: From 13 November 2026, registered Consent Managers must be Indian companies with a net worth of at least ₹2 crore. Confirm registration status if you plan to use one in that role.
3. Endpoint and Data Loss Prevention Software
These tools control what leaves company laptops and inboxes. As a result, they reduce the chance that a salary file ends up somewhere it should not.
Best for: Teams where payroll or appraisal files still move by email or spreadsheet.
What to check: Monitoring must stay proportionate, and employees should know what you track.
4. Background Verification Vendor with a DPDP Contract
Background checks involve some of the most sensitive data HR ever handles.
Best for: Firms that verify education, employment history, or identity before hiring.
What to check: Breach notice timelines, deletion after the check, and where the vendor stores reports.
5. Secure Document Storage with Retention Controls
Offer letters, signed policies, and ID proofs need a home with access limits and automatic retention rules.
Best for: HR teams replacing shared drives and email attachments.
What to check: Whether you can set deletion schedules by document type.
DPDP Checklist for HR Teams
Use this table to track progress before 13 May 2027.
| Task | Rule or Section | Owner |
| Inventory of all employee and candidate data | Section 8 | HR with IT |
| Lawful basis recorded for each HR activity | Sections 4, 6, and 7 | HR with Legal |
| Consent notices for optional activities | Rule 3 | HR |
| Role-based access to salary and ID data | Rule 6 | HR with IT |
| Access logs kept for at least one year | Rules 6 and 8(3) | IT |
| Breach playbook with 72-hour Board report | Rule 7 | IT, HR, and Leadership |
| Retention schedule for candidates and ex-employees | Section 8(7) | HR with Legal |
| Security clauses in every HR vendor contract | Rule 6 | Procurement with Legal |
| Published privacy contact | Rule 9 | HR |
| Grievance process with a period of 90 days or less | Rule 14(3) | HR |
Getting Employee Data DPDP-Ready Before May 2027
The DPDP Rules ask HR teams to know where employee data lives, use it for clear reasons, protect it, and let it go when its job is done.
Start with the data map this quarter. Next, fix access to salary and identity data, because that is where the biggest penalties sit. Finally, run your breach drill and vendor review well before the May 2027 deadline.
If your employee records are spread across payroll software, spreadsheets, and a separate project tool, each gap adds work to every step above. Bringing them onto one platform makes the whole program easier to run.
Run HR, payroll, and project data on one platform
Frequently Asked Questions
Do Employers Need Employee Consent Under the DPDP Act?
Not for core employment processing. Section 7(i) of the DPDP Act lets employers process personal data for employment purposes without consent. This covers payroll, statutory filings, and attendance. You still need consent for optional activities, such as using employee photos in marketing.
When Do the DPDP Rules Apply to Employee Data?
The Rules were notified on 13 November 2025. Consent Manager rules apply from 13 November 2026. Most obligations that affect HR, including notices, security, breach reporting, retention, and grievances, apply from 13 May 2027.
How Quickly Must HR Report an Employee Data Breach?
Under Rule 7, you must inform affected employees and the Data Protection Board without delay. You must then send the Board a detailed report within 72 hours of learning about the breach. The Board can allow more time if you ask in writing.
How Long Can Employers Keep Former Employee Data?
Keep records that tax, provident fund, or labor laws require for the period those laws set. Beyond that, Section 8(7) requires you to erase personal data once its purpose is over. Access logs must be kept for at least one year under the Rules.
Is a Payroll Provider Responsible for DPDP Compliance?
Your payroll provider is a data processor, and it must follow its contract with you. However, the employer remains the Data Fiduciary and stays responsible for compliance. Rule 6 requires your contract with each processor to include security safeguards.
Do Small Companies Need a Data Protection Officer Under DPDP?
Usually not. The formal Data Protection Officer duty applies to Significant Data Fiduciaries notified by the government. Every employer, however, must publish contact details of a person who can answer questions about its processing, under Rule 9.
