An employee resigns. HR still has their Aadhaar, cancelled cheque, fingerprint template from the gate device, and last year’s appraisal sitting in a shared Drive and a payroll vendor login that three people use. Six months later the person asks: delete my data. Nobody can say where every copy lives. Under the Digital Personal Data Protection Act, 2023, that is no longer an “IT hygiene” problem. It is a Data Fiduciary problem on the company’s name.
What DPDP actually changed for HR
The Digital Personal Data Protection Act, 2023 (with Rules notified thereafter) treats digital personal data of people in India as regulated — including employees, candidates and contractors. GDPR language on your website does not substitute for DPDP. Your India compliance page may still mention GDPR; search and regulators now ask for DPDP.
- The company is typically the Data Fiduciary
- Payroll processors, BGV vendors and HRMS hosts are processors acting on your instructions
- Notice, purpose limitation, security safeguards and retention still apply even when employment is a legitimate use
- Penalties for significant failures can run into crores — biometric misuse is a high-severity path
The HR data map most companies have never drawn
1. Identity and money
PAN, Aadhaar (where lawfully collected), bank account, UAN, ESIC number, Form 16 inputs.
2. Time, body and location
Attendance punches, GPS at check-in, face or fingerprint templates, shift logs. Biometrics are the most sensitive layer — see geo-fence vs biometric attendance.
3. Career and conduct
Performance notes, POSH files, medical certificates, disciplinary emails.
4. Copies you forgot
WhatsApp KYC, recruiter inboxes, unused Excel salaries, a founder’s laptop, an old vendor who still has last year’s dump.
What leadership is actually liable for
Biometric without a real choice
Fingerprint-only gates with no card/app fallback and no recorded consent.
No retention schedule
Keeping every resigned employee’s Aadhaar forever “in case of PF queries”.
Shared payroll logins
Everyone in Accounts sees every CTC. No role-based access, no access log.
Vendor with no DPA
BGV and payroll vendors holding data without purpose, deletion and sub-processor clauses.
Spreadsheet HR vs a DPDP-ready HRMS
| Obligation | Drive + Excel + WhatsApp | HRMS with access control |
|---|---|---|
| Who can see salary | Anyone with the sheet link | RBAC + permission overrides |
| Biometric templates | Device vendor, unknown retention | Consent log + delete on exit |
| Correction / erasure request | Cannot find every copy | One employee record, documented retention |
| Vendor processors | Forwarded ZIPs | Processors under contract, logged access |
| Proof for the Board | Policy PDF only | Audit trail of access and changes |
DPDP will not be won with a privacy policy footer. It will be won when salary, biometrics and KYC live in a system that can answer “who saw this, why do we still have it, and can we delete it?” in minutes. That is the same discipline as HR audit trails.
The way forward
Draw a one-page data map. Move payroll and documents off personal inboxes. Require a non-biometric attendance option. Encrypt, restrict salary views, delete biometric templates on exit, and put processor clauses in every BGV and payroll contract. See Bynarize security, SSO and RBAC and the employee document vault. Use India Readiness Check as a starting score — then add DPDP to the same conversation as POSH and S&E.
This is operational guidance, not legal advice. DPDP Rules, Board procedures and overlap with labour-record retention should be confirmed with qualified counsel.
If you are a Founder, HR Head or CISO: assume the next complaint will ask for a copy of what you hold and proof of deletion. If that proof is “we think we deleted the Excel”, you are not DPDP-ready.
Can your HR system honour a DPDP deletion request?
Put employee files, salary access and attendance identity in one controlled tenant.