WebHR

Employee data under the DPDP Act

How the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 apply to HR data, the employment “legitimate use”, and what must be ready by 13 May 2027.

Applies to:
All India (Central)
For:
HR, IT, Leadership
Last reviewed:

When the obligations start

DateWhat applies
13 November 2025DPDP Rules, 2025 notified; the Data Protection Board is set up
13 November 2026Registration and duties of consent managers
13 May 2027The main duties of every data fiduciary: notices, security safeguards, breach reporting, retention and erasure, and data principals’ rights

The employment “legitimate use”

An employer is a data fiduciary for its employees’ and candidates’ personal data. Section 7(i) of the Act lets it process personal data for the purposes of employment — recruitment, onboarding, payroll, benefits, statutory compliance, and protecting itself from loss or liability — without separate consent.

That covers the purpose, not everything: processing that is not needed for employment (marketing to employees, sharing with a third party for its own purposes) still needs consent, and the section 8 duties apply to all of it.

What HR must have in place by May 2027

  • Collect only what the purpose needs, and keep it accurate.
  • Reasonable security safeguards — access control, encryption, logging — including at vendors who process data for you.
  • Report a personal data breach to the Data Protection Board and to affected people, as the Rules prescribe.
  • Erase data when the purpose is served and no law requires keeping it — ex-employees’ records are kept for statutory periods, and the rest removed.
  • A way for employees to access, correct and ask for erasure of their data, and a contact for grievances.
  • Parental consent for anyone under 18 (for example interns), and care with children’s data.
In WebHR

WebHR encrypts data in transit and sensitive fields at rest, keeps an audit log of who read and changed what, lets you set roles down to individual permissions, handles employees’ privacy requests (HR Operations → Privacy Requests), and has a retention job that pseudonymises ex-employee records once the statutory periods end. Our privacy policy, DPA and sub-processors set out our side as your processor.

References

  1. PIB — DPDP Rules, 2025 notified
  2. EY — DPDP Rules 2025 notified: complete guide
  3. Shardul Amarchand Mangaldas — enforcement of the DPDP Act and Rules
  4. Chambers — the legitimate-use exemption for employee data

Related

Plain-language guidance for HR teams, not legal advice. Checked against the sources above on 29 September 2026; the notification or your authority’s portal is final. Spotted something out of date? Tell us.