Real Scenario

An employee resigns. HR still has their Aadhaar, cancelled cheque, fingerprint template from the gate device, and last year’s appraisal sitting in a shared Drive and a payroll vendor login that three people use. Six months later the person asks: delete my data. Nobody can say where every copy lives. Under the Digital Personal Data Protection Act, 2023, that is no longer an “IT hygiene” problem. It is a Data Fiduciary problem on the company’s name.

What DPDP actually changed for HR

The Digital Personal Data Protection Act, 2023 (with Rules notified thereafter) treats digital personal data of people in India as regulated — including employees, candidates and contractors. GDPR language on your website does not substitute for DPDP. Your India compliance page may still mention GDPR; search and regulators now ask for DPDP.

  • The company is typically the Data Fiduciary
  • Payroll processors, BGV vendors and HRMS hosts are processors acting on your instructions
  • Notice, purpose limitation, security safeguards and retention still apply even when employment is a legitimate use
  • Penalties for significant failures can run into crores — biometric misuse is a high-severity path

The HR data map most companies have never drawn

1. Identity and money

PAN, Aadhaar (where lawfully collected), bank account, UAN, ESIC number, Form 16 inputs.

2. Time, body and location

Attendance punches, GPS at check-in, face or fingerprint templates, shift logs. Biometrics are the most sensitive layer — see geo-fence vs biometric attendance.

3. Career and conduct

Performance notes, POSH files, medical certificates, disciplinary emails.

4. Copies you forgot

WhatsApp KYC, recruiter inboxes, unused Excel salaries, a founder’s laptop, an old vendor who still has last year’s dump.

What leadership is actually liable for

Biometric without a real choice

Fingerprint-only gates with no card/app fallback and no recorded consent.

No retention schedule

Keeping every resigned employee’s Aadhaar forever “in case of PF queries”.

Shared payroll logins

Everyone in Accounts sees every CTC. No role-based access, no access log.

Vendor with no DPA

BGV and payroll vendors holding data without purpose, deletion and sub-processor clauses.

Spreadsheet HR vs a DPDP-ready HRMS

ObligationDrive + Excel + WhatsAppHRMS with access control
Who can see salaryAnyone with the sheet linkRBAC + permission overrides
Biometric templatesDevice vendor, unknown retentionConsent log + delete on exit
Correction / erasure requestCannot find every copyOne employee record, documented retention
Vendor processorsForwarded ZIPsProcessors under contract, logged access
Proof for the BoardPolicy PDF onlyAudit trail of access and changes
The leadership view

DPDP will not be won with a privacy policy footer. It will be won when salary, biometrics and KYC live in a system that can answer “who saw this, why do we still have it, and can we delete it?” in minutes. That is the same discipline as HR audit trails.

The way forward

Draw a one-page data map. Move payroll and documents off personal inboxes. Require a non-biometric attendance option. Encrypt, restrict salary views, delete biometric templates on exit, and put processor clauses in every BGV and payroll contract. See Bynarize security, SSO and RBAC and the employee document vault. Use India Readiness Check as a starting score — then add DPDP to the same conversation as POSH and S&E.

This is operational guidance, not legal advice. DPDP Rules, Board procedures and overlap with labour-record retention should be confirmed with qualified counsel.

If you are a Founder, HR Head or CISO: assume the next complaint will ask for a copy of what you hold and proof of deletion. If that proof is “we think we deleted the Excel”, you are not DPDP-ready.

Can your HR system honour a DPDP deletion request?

Put employee files, salary access and attendance identity in one controlled tenant.