Skip to content
AuthMantraPraxis
authmantra.com ↗Start free trial

Compliance

What the DPDP Act means for employee data

AuthMantra Team5 min readPractical

Short version: headings, key sentences, diagrams and callouts.
Who is who under the DPDP Actdata + consentinstructsData Principal(the person)Data Fiduciary(decides why)Processor(acts for you)

Note

This article is general information, not legal advice. The law, its rules and official guidance can change, and how it applies depends on your facts. Check with your compliance counsel before acting on anything here.

Employees are people whose personal data you hold in large amounts: identity documents, bank details, addresses, health and family information, performance records, device and sign-in logs.

The Digital Personal Data Protection Act, 2023 (the DPDP Act) is India's law on how digital personal data is processed.

Organisations that decide why and how personal data is processed are described as Data Fiduciaries, and the individuals the data is about are Data Principals. In an employment setting, you are the Data Fiduciary and your employees are Data Principals.

This article stays at the level of concepts, because the detailed rules and timelines are best confirmed with counsel and the official text.

Why employee data deserves its own thought

Much commentary on data protection focuses on customers. Employee data has its own character:

  • The relationship is unequal, so consent given "freely" is a harder concept than with a customer who can walk away.
  • The data is varied and sensitive in practice, even if the law's categories are simpler than in some other regimes.
  • Records must often be kept for long periods because of other obligations, such as tax, labour and provident fund requirements, which sit alongside data protection.
  • Many people inside the company, in HR, IT, payroll and management, touch it.

How the Act treats employment-related processing, including any specific allowances for it, is something to confirm with counsel rather than assume.

Tip

Start by writing down what you hold. Every other duty depends on that list.

Concepts that matter in practice

Notice. People should be told what data you collect and why, in clear language. For employees this usually means a privacy notice given at onboarding and updated when purposes change.

Purpose limitation. Use data for the purpose it was collected for. Using sign-in logs gathered for security to evaluate productivity is the kind of drift to avoid.

Data minimisation and accuracy. Collect what you need. Keep records correct.

Reasonable security safeguards. Protect personal data from unauthorised access, loss and misuse. For identity and access teams this is the most directly relevant idea, because who can see what is the heart of it.

Retention. Do not keep personal data longer than needed for its purpose or any legal requirement. This means you need a retention schedule.

Rights of Data Principals. Employees can ask for information about their data and ask for correction and erasure, subject to the law's conditions and to other laws that require you to retain data.

Grievance redressal. You need an accessible way for people to raise concerns and a process to respond.

Breach intimation. If personal data is breached, there are duties to inform the regulator and the affected people. Separately, CERT-In's directions of 28 April 2022 require specified cyber incidents to be reported within 6 hours and logs to be retained for 180 days. Your incident process should handle both, and counsel can advise how they interact.

A practical groundwork plan

1. Build a data inventory

You cannot protect or delete what you cannot find. Make a table with one row per category of employee data:

DataSystemOwnerPurposeWho has accessKept for
Bank detailsPayrollFinance headSalary payment3 payroll staffPer policy
Sign-in logsIdentity platformSecurity leadSecurity monitoringSecurity team, auditor180 days minimum
Medical certificatesHR folderHR headLeave approval2 HR staffPer policy

Do not forget the unofficial copies: spreadsheets in email, exports on laptops, shared drives and chat attachments.

2. Decide retention, by category

For each category, write down how long you keep it and why. Tie leavers to this schedule. When someone leaves, the leaver process should trigger the clock, and a periodic job or review should apply the deletion.

Our offboarding checklist includes where to fit it.

3. Control access by role

"Reasonable safeguards" is easier to defend when access follows roles and is reviewed. Give HR staff access only to the populations they serve. Give IT administrators no access to payroll content merely because they administer the server.

Review access on a schedule, and keep the evidence; see Access reviews auditors accept.

4. Make requests answerable

Decide how you will respond when an employee asks "what do you hold about me?" or "please correct this". Who receives the request, who gathers data from each system, and within what period will you reply?

Rehearse it once with a volunteer.

5. Set up a grievance route

Name a contact, publish how to reach them, and log each complaint and outcome. A mailbox nobody reads is worse than none.

6. Prepare for incidents

Know who decides whether an event is a personal data breach, who informs whom, and where the logs are. Keep audit logs long enough, and in a form you can export. See Streaming identity logs to your SIEM.

7. Check your processors

If a vendor processes employee data for you, such as payroll or background verification, your contracts and due diligence should reflect your obligations. Counsel should review these terms.

Identity systems and personal data

An identity platform is itself a store of employee personal data: names, email addresses, phone numbers, roles, sign-in times and device details. Treat it like any other system in your inventory.

Where it is hosted, how it is encrypted, who administers it and how long logs are kept are all questions your inventory should answer.

AuthMantra is hosted in the Mumbai region, offers customer-managed encryption keys, and provides a grievance workflow, data export and consent records, which are built with DPDP-oriented needs in mind.

These are tools to help you run a process; they do not by themselves make an organisation compliant, and you should not treat them as a certificate of anything. See the audit and DPDP readiness use case.

Common mistakes

  • Assuming the law applies only to customer data.
  • Keeping everything forever "just in case".
  • Using one broad consent clause for all purposes.
  • Relying on spreadsheets with no owner or access control.
  • Treating deletion as a one-off project instead of a recurring task.

What to do this week

  • Start the inventory table above with the five systems that hold the most employee data.
  • Ask each system owner two questions: who can see this, and when is it deleted?
  • Locate your current employee privacy notice, and note when it was last updated.
  • Name the grievance contact and publish the route.
  • Book time with your compliance counsel to confirm the points that depend on your sector and circumstances.

Try it

DPDP ActData FiduciaryData PrincipalConsent