Naresh K Matta Senior HR & Business Advisor

DPDP Act Compliance for HR Data

India's Digital Personal Data Protection Act applies squarely to the data HR holds — salary, performance records, medical information, background checks, candidate CVs. Most HR functions collect far more than they need and keep it indefinitely.

The problem

HR is usually the largest uncontrolled store of personal data in the organisation. CVs sit in an inbox for years. Salary data circulates by spreadsheet. Background verification reports are stored without a retention policy. Payroll, insurance and recruitment vendors hold employee data under agreements that were never reviewed for data protection. This rarely appears on a compliance checklist until something goes wrong.

What this covers

  • Data mapping across the employee lifecycle, from application through to post-exit records
  • Notice and consent aligned to how you actually collect data
  • Retention schedules, and safe disposal of data being kept without a reason
  • Vendor and processor review — payroll, insurance, background verification, recruitment
  • Access controls within HR, so sensitive data is not open to the whole team
  • Breach readiness — what to do, who decides, and within what timeline
  • Training for the HR team, who are the people actually handling the data

Why me for this

Active focus on data security and governance advocacy, including GDPR and the DPDP Act, alongside twenty-four years of running the HR processes that generate and hold this data.

Common questions

Does the DPDP Act apply to employee data?

Yes. Employee and candidate information is personal data, and in the case of medical or background check information it is particularly sensitive. HR is typically the function holding the largest volume of it, and frequently the function with the weakest controls around it.

How long can we retain candidate CVs?

Only as long as there is a purpose for holding them. Indefinite retention of unsuccessful candidates' data is a common and easily corrected exposure. The practical fix is a documented retention schedule applied consistently, rather than a decision made case by case.

Are we liable if our payroll vendor has a data breach?

Responsibility does not transfer simply because processing has been outsourced. The employer remains accountable for the data it has entrusted to a processor, which makes vendor agreements and the security assurances within them a live HR issue rather than purely a procurement one.

Call WhatsApp