CozyHR
Menu
Products
Docs
Resources
Compliance
Company
Support
Blog
DPDP ActData PrivacyHR ComplianceHR Tech

DPDP Act for HR Teams: Employee Data Privacy Guide

What the DPDP Act means for HR and payroll teams in India: data mapping, notices, rights requests, vendors and a 90-day plan.

CozyHR editorial team 30 September 2026 25 min read
CozyHR Blog
DPDP Act for HR Teams: Employee Data Privacy Guide

HR teams hold some of the most sensitive data in any company. A single employee file can contain identity documents, bank details, salary history, family information, medical certificates, background verification reports, performance notes, biometric templates, location traces and disciplinary records. For years, most small companies stored this information in shared folders, email attachments and spreadsheets with little thought about who could see it or how long it stayed there.

India's data protection framework, built around the Digital Personal Data Protection Act, 2023 (the DPDP Act) and its rules, changes that. It places clear duties on organisations that decide why and how personal data is processed, and it applies to employee data as much as customer data. This guide explains, in plain language, what the DPDP Act means for HR and payroll teams in Indian companies: the key concepts, where employee data is handled, what a practical compliance programme looks like, a step-by-step implementation plan, and common pitfalls. It is written for HR managers, founders and payroll teams, not for lawyers, and it is general information rather than legal advice.

Important: The Act's rules, timelines and enforcement machinery have been rolling out in phases, and details continue to be clarified. Always verify the current position, effective dates and requirements from official government publications and take advice from a qualified privacy or employment lawyer before making decisions.

Why DPDP matters for HR specifically

Many companies think of data protection as a marketing or IT topic, about cookies and customer emails. In reality, HR is often the largest and most sensitive processor of personal data in the organisation.

  • Volume. Every employee, applicant, intern, contractor, dependant and nominee generates personal data.
  • Sensitivity. Salary, bank accounts, identity numbers, health-related leave records, biometric data and disciplinary history can cause real harm if misused or leaked.
  • Power imbalance. Employees cannot easily refuse when an employer asks for data, which is why the law looks closely at fairness, purpose and consent.
  • Third-party flows. HR data passes to payroll vendors, insurers, banks, background verification agencies, recruitment platforms, cloud providers, auditors and government bodies.
  • Lifecycle. Data is collected at hiring, used through employment, and retained long after exit for legal reasons.

If your company handles even a small amount of digital personal data, the Act likely applies to how HR operates.

Key concepts in plain language

Personal data

Any data about an individual who is identifiable by or in relation to such data. Names, phone numbers, email addresses, PAN numbers, bank account numbers, photographs and employee IDs are all personal data when they relate to an identifiable person.

Digital personal data

The Act applies to personal data collected in digital form, or collected in non-digital form and then digitised. A paper form that is later scanned or typed into your HR system is covered from the point of digitisation.

Data Principal

The individual whose personal data it is. In HR, this includes candidates, employees, former employees, interns, contractors, nominees and dependants whose data you process.

Data Fiduciary

The organisation that determines the purpose and means of processing. Your company, as an employer, is typically the Data Fiduciary for employee data.

Data Processor

A party that processes data on behalf of the Data Fiduciary, such as a payroll provider, cloud HR platform, BGV agency or insurance administrator. The Fiduciary remains responsible for the processor's handling and must have a valid contract in place.

Consent

A free, specific, informed, unconditional and unambiguous indication, by clear affirmative action, that the individual agrees to the processing of their data for a specified purpose. Consent must be accompanied or preceded by a notice.

Legitimate uses

The Act recognises certain situations where data may be processed without consent. One of them relates to employment: processing for purposes of employment or those related to safeguarding the employer from loss or liability, such as prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property or classified information, or the provision of services or benefits sought by an employee. Other legitimate uses include compliance with law, and certain situations where a person has voluntarily provided data for a stated purpose. The scope of these provisions needs careful reading, and you should not treat them as a blanket exemption for everything HR does.

Significant Data Fiduciary

Some organisations may be designated as Significant Data Fiduciaries based on factors like volume and sensitivity of data, risk to individuals and other criteria. These face extra duties such as appointing a data protection officer based in India, independent audits and impact assessments. Most SMBs are unlikely to be designated, but check the criteria as they are clarified.

Data Protection Board

The regulatory body set up under the Act to handle complaints, breach reports and enforcement. Penalties for non-compliance can be substantial, so verify the current schedule of penalties from the Act itself.

Where employee data lives: mapping the HR data landscape

You cannot protect what you have not mapped. Begin with a data inventory that answers: what personal data do we collect, from whom, for what purpose, where is it stored, who can access it, who do we share it with, and how long do we keep it?

Typical HR data categories

StageData collectedTypical sources
RecruitmentRésumés, contact details, education, work history, interview notes, assessment scoresJob portals, career page, referrals, agencies
Pre-joiningIdentity proofs, address proofs, photographs, references, BGV reportsCandidate, BGV vendor
OnboardingBank details, PAN, Aadhaar-related details where lawfully required, UAN, nominee and family details, emergency contactsForms, HRMS
EmploymentAttendance, leave, location punches, biometric templates, performance reviews, training records, expense claimsHRMS, devices, apps
PayrollSalary, deductions, tax declarations, investment proofs, loan and advance recordsPayroll system
BenefitsInsurance enrolment, dependants' details, claims metadataInsurer, TPA, HR
Employee relationsGrievances, investigations, disciplinary records, POSH complaintsHR, committees
ExitResignation, exit interview, settlement, relieving documentsHR, payroll
Post-exitArchived files, statutory records, alumni contact dataHR, finance

Data flow mapping

For each category, draw where the data travels. A simple diagram showing candidate to careers page to ATS to HRMS to payroll to bank and statutory portals, with vendors labelled, is enough to start. Look for surprises: personal WhatsApp groups where salary slips are shared, spreadsheets emailed to managers, screenshots saved on personal phones, or old vendors who still hold data.

Lawful basis: consent versus legitimate use in HR

A common question is whether HR must take consent for everything. The answer is nuanced.

When consent-based processing is likely to be appropriate

  • Optional programmes such as wellness initiatives, voluntary surveys with identifiable responses, alumni networks and marketing use of employee photographs
  • Collection of data that is not necessary for employment, for example, optional social media links
  • Certain uses of biometric data where you rely on consent, depending on how the law and rules develop
  • Sharing employee data with third parties for benefits that are optional

Consent must be genuinely voluntary. If an employee cannot decline without penalty, the consent may not be valid. Design optional programmes so that opting out has no adverse consequence.

When legitimate use for employment purposes may apply

  • Processing personal and financial data needed to run payroll and pay salary
  • Statutory contributions and filings such as provident fund, ESI, tax deduction and returns
  • Maintaining attendance and leave records required by labour laws
  • Maintaining records to safeguard the company from loss or liability, such as confidentiality and security controls

Even where consent is not required, good practice is to give employees a clear privacy notice explaining what you collect and why. The safest path is to document your purpose for each category and check with your lawyer whether the employment-related legitimate use squarely covers it.

When you must be careful

Employer-monitoring measures, extensive location tracking, social media screening, continuous biometric surveillance, and use of employee data for profiling or AI-based decisions are areas where purpose, proportionality and transparency matter greatly. Document your reasoning.

Core obligations for HR under DPDP

The following is a practical translation of the Fiduciary's duties into HR tasks. Confirm details against the Act and rules.

1. Notice

Provide clear notice describing the personal data being collected, the purpose, how to exercise rights, and how to complain to the Board. For HR, this means:

  • A candidate privacy notice on the careers page and in application forms
  • An employee privacy notice at onboarding and available on the HR portal
  • Notices at the point of specific collections such as biometric enrolment or health-related benefit enrolment
  • Notice content that is in plain language and available in languages your workforce understands, as required by the rules

2. Purpose limitation and data minimisation

Collect only what is necessary for the stated purpose. Common HR examples of over-collection include asking for full family details for all employees when only nominees are needed, collecting copies of identity documents that are not required, storing photographs of documents in WhatsApp, and keeping interview recordings without reason.

3. Accuracy

Keep data accurate and up to date. Provide self-service for employees to update address, bank and emergency contact details. Errors in bank details, for example, cause payroll failures and can result in payments to the wrong person.

4. Storage limitation and retention

Retain data only as long as necessary for the purpose or as required by law. Many labour, tax and company laws require records for defined periods, so retention schedules should reflect both statutory requirements and business need. After the period ends, erase or anonymise.

5. Security safeguards

Implement reasonable security measures to prevent personal data breaches. This includes access controls, encryption, secure backups, logging and monitoring, vendor controls, staff training and incident response plans.

6. Breach notification

If a personal data breach occurs, the Fiduciary must notify the Board and affected individuals in the manner prescribed. HR should be part of the incident response process. Plan for who decides, who communicates, what template is used, and what timelines apply as per the rules.

7. Rights of Data Principals

Individuals have rights that HR must be ready to handle:

  • Right to access information about personal data being processed and the identities of those with whom it has been shared
  • Right to correction and erasure of personal data, subject to retention required by law
  • Right to grievance redressal, with a mechanism to receive and respond to complaints
  • Right to nominate another person to exercise rights in case of death or incapacity

Set up a simple request process: a form or email address, an identity verification step, a tracking log, a response timeline, and an escalation path. Your HR helpdesk can host this. See our HR helpdesk and ticketing guide.

8. Children's data

The Act has special provisions for processing personal data of children, which includes those under eighteen. HR may encounter this with young apprentices, interns, employees' dependants, and nominee details. Get legal advice before processing data of minors, and avoid collecting more than required.

9. Vendor management

Use written contracts with processors requiring them to follow your instructions, apply security safeguards, assist with rights requests, notify you of breaches, delete data on termination and allow audits where appropriate.

10. Grievance officer or contact point

Publish the contact details of a person who can answer questions about personal data processing. For larger or designated entities, additional roles such as a data protection officer may apply.

11. Cross-border transfers

If you use global HR tools, or your parent company is abroad, employee data may leave India. The Act permits transfers except to countries the government may restrict by notification. Check the current position, and document transfers in your data map.

DPDP applied to each stage of the employee lifecycle

Recruitment

  • Add a privacy notice to job application forms and the careers page.
  • Do not scrape social media profiles without a clear, lawful and proportionate reason.
  • Delete unsuccessful candidates' data after a defined period unless they agree to be kept in a talent pool. Our recruitment metrics and skills-based hiring guides show how to manage talent pools responsibly.
  • Ensure agencies and job portals you use have proper terms.
  • Be careful with AI screening tools. Ask vendors how candidate data is used and whether it is retained or used to train models. See our AI resume screening guide.

Background verification

  • Obtain the candidate's informed authorisation.
  • Limit checks to what is relevant to the role.
  • Ensure the BGV vendor is bound by a data processing agreement.
  • Store reports securely with restricted access and set retention limits. See our BGV guide.

Onboarding

  • Provide the employee privacy notice.
  • Collect only the documents required for statutory registration and payroll.
  • Use a secure upload portal instead of email attachments.
  • Explain how family and nominee data will be used.
  • Avoid collecting sensitive data, like detailed health information, unless needed and lawful.

Attendance and monitoring

  • Choose the least intrusive method that meets your purpose. Our attendance capture guide compares options.
  • Provide notice for biometric and location data collection.
  • Limit access and retention of biometric templates and location trails.
  • Avoid always-on tracking outside working hours.

Payroll and benefits

  • Restrict payroll data to the payroll team and approvers.
  • Encrypt bank files and payroll registers in transit and at rest.
  • Use secure payslip delivery rather than email attachments with weak passwords.
  • Ensure insurers and TPAs have a clear purpose for the data they receive.
  • Share dependants' data only as necessary. See our group health insurance guide.

Performance and employee relations

  • Restrict access to performance notes, ratings and investigation records.
  • Keep POSH and whistleblower records under special confidentiality. See our POSH and whistleblower guides.
  • Ensure survey tools protect anonymity where promised. Our engagement survey guide covers this.

Exit

  • Remove access promptly.
  • Keep only records required for legal and business reasons.
  • Inform employees how long their data will be retained after exit.
  • Delete or anonymise data at the end of retention periods. See our offboarding and exit interview guide.

Alumni and rehire

  • Get consent before adding former employees to alumni communications.
  • Provide easy opt-out.

Special categories: handle with extra care

The DPDP Act does not create a separate formal category of sensitive personal data in the way some other laws do, but the risk of harm rises sharply with certain types of data, and other laws may impose additional requirements. Treat the following as high-risk in your HR context.

  • Biometric data such as fingerprints and face templates
  • Health information in medical certificates, sick leave documentation, maternity records and insurance claims
  • Financial data such as bank details, salary, loans and tax declarations
  • Government identifiers such as PAN, Aadhaar-related information, passport and driving licence
  • Disciplinary and investigation records
  • Data about children and dependants
  • Location data
  • Data on caste, religion or sexual orientation, if collected for diversity purposes. Avoid collecting unless clearly justified, voluntary and safeguarded. Our guide on hiring persons with disabilities discusses handling disability data sensitively.

Apply stricter access, shorter retention, stronger encryption and clearer notices to these categories.

Building a practical HR privacy programme: step by step

Step 1: Assign ownership

Nominate a privacy lead in HR and a technical counterpart in IT or security. In small companies, the founder or HR head may play the role initially. Define responsibilities, escalation paths and reporting to leadership.

Step 2: Create your data inventory

Use a spreadsheet with these columns:

ColumnExample
Data categoryBank account details
Data subjectsEmployees
PurposeSalary payment
Lawful basis or groundEmployment-related legitimate use
SourceEmployee via onboarding form
System or locationHRMS, payroll system, bank portal
Access rolesPayroll team, finance approver
Shared withBank, payroll vendor
Retention periodAs per legal and business requirements
Security measuresEncryption, access logs
RisksEmailing spreadsheets

Update it whenever you introduce a new tool or process.

Step 3: Assess gaps

Compare your practices with the obligations above. Rate gaps by risk and effort. Focus first on high-risk areas: unencrypted files with bank details, uncontrolled access to HRMS, biometric data with no notice, vendor contracts with no data terms.

Step 4: Draft notices and policies

Prepare:

  • Candidate privacy notice
  • Employee privacy notice
  • Consent forms for optional processing
  • Data retention schedule
  • Access control policy
  • Acceptable use policy
  • Data breach response plan
  • Data subject request procedure
  • Vendor management standards

Have your lawyer review them. Then integrate them into your employee handbook. See our guide on creating an employee handbook.

Step 5: Implement technical and organisational controls

Access controls

  • Use role-based access so that people see only what they need.
  • Enforce strong passwords and multi-factor authentication.
  • Review access rights quarterly and at every role change or exit.

Data protection

  • Encrypt sensitive files and databases.
  • Use secure file-sharing tools with expiry, not email attachments.
  • Disable local downloads of payroll data where practical.
  • Mask sensitive fields such as bank account numbers and identity numbers for users who do not need to see full values.

Logging and monitoring

  • Maintain audit logs of who viewed or changed sensitive records.
  • Monitor unusual access, such as bulk exports.

Backups and continuity

  • Encrypt backups and test restoration.
  • Limit who can access backups.

Devices

  • Enforce screen locks and device encryption on laptops that hold HR data.
  • Prohibit storing employee files on personal devices or messaging apps.

Physical security

  • Store paper files in locked cabinets and shred when retention ends.

Step 6: Fix vendor relationships

List all vendors that handle employee data. For each, review contracts and add or negotiate:

  • Purpose and instructions for processing
  • Security requirements
  • Sub-processor rules
  • Breach notification duties and timelines
  • Support for rights requests
  • Data location and cross-border transfer terms
  • Deletion or return of data at termination
  • Audit or assurance rights
  • Insurance or liability provisions where appropriate

Step 7: Train people

Train HR, payroll, IT and managers on:

  • What personal data is and how to handle it
  • Do's and don'ts, such as not sharing salary data on chat groups
  • How to spot phishing and social engineering, which often target payroll teams
  • How to recognise and report a breach
  • How to handle rights requests

Keep training short, scenario-based and repeated annually.

Step 8: Build a rights request process

Design a simple workflow.

  1. Employee submits a request through a form or the HR helpdesk.
  2. HR verifies identity.
  3. HR logs the request and classifies it.
  4. Relevant data owners gather information.
  5. Legal review where necessary.
  6. Response provided within the timeline.
  7. Record of the outcome retained.

Prepare template responses for access, correction, erasure and grievance requests. Clarify what cannot be erased due to legal retention obligations.

Step 9: Prepare for incidents

Write a breach response plan.

  • Detect and report. Anyone who suspects a breach reports to a designated contact immediately.
  • Contain. IT isolates affected systems, revokes credentials and stops further exposure.
  • Assess. Determine what data was affected, how many individuals, and the likely harm.
  • Notify. Follow the rules on informing the Board and affected individuals in the required form and time. Notify vendors and insurers as needed.
  • Remediate. Fix the root cause.
  • Review. Document lessons learned and update controls.

Run a tabletop exercise once a year, for example, "a payroll spreadsheet was emailed to the wrong recipient".

Step 10: Review and improve

Schedule an annual review of the inventory, notices, retention schedule, vendors and training. Update after significant changes such as new HR tools, acquisitions or new legal requirements.

Retention: how long should HR keep what?

Retention is one of the hardest areas because different laws prescribe different periods, and there is often a business need to keep records for potential disputes. Build a retention schedule with your legal or compliance advisor. The table below lists categories and factors to consider, not fixed periods.

Record typeFactors that determine retention
Unsuccessful candidate dataTalent pool consent, limitation for potential hiring disputes
Employee personnel fileDuration of employment plus periods required by labour, tax and company laws
Payroll registers and payslipsRequirements under wage, tax, provident fund, ESI and labour law rules
Attendance and leave recordsLabour law register requirements
Tax records and Form 16 copiesIncome tax record-keeping timelines
Medical and insurance recordsPurpose limitation, legal claims, insurer requirements
Disciplinary and investigation recordsNeed to defend claims, limits on use
POSH complaints and inquiry recordsRequirements under the POSH Act and rules
Biometric templatesDelete when employment ends unless a specific legal reason exists
CCTV footagePurpose, policy and security needs

Automate deletion where possible. At minimum, set a calendar reminder to review and purge annually.

Employee monitoring and AI in HR

Two areas deserve special attention because they are growing quickly.

Monitoring

Monitoring tools that track screen activity, keystrokes, emails, location or webcams raise serious privacy and morale issues. If you use monitoring:

  1. Define a specific, legitimate purpose, such as security or compliance.
  2. Choose the least intrusive means.
  3. Tell employees clearly what is monitored, when and why.
  4. Limit access to monitoring data.
  5. Avoid monitoring private spaces or personal devices without clear consent.
  6. Set short retention periods.
  7. Do not use monitoring data for unrelated purposes such as performance ranking, unless disclosed and proportionate.

AI and automated decisions

AI is increasingly used in recruitment screening, chatbots, performance analytics and attrition prediction. Data protection considerations include:

  • Are you feeding personal data into external AI services, and does the vendor use it to train models?
  • Is there a human in the loop for decisions with significant effects on people?
  • Can you explain how the tool reaches its conclusions?
  • Have you tested for bias?
  • Have you told employees and candidates that AI is being used?

Our guides on AI in performance reviews, AI resume screening and AI chatbots for employee self-service cover the practical side.

Payroll teams: specific safeguards

Payroll is a prime target for fraud and data leaks, so give it special protection.

  • Limit payroll system access to named users, with multi-factor authentication.
  • Use separate roles for creating employees, changing bank details, running payroll and approving payments.
  • Verify bank detail change requests through a second channel, not just an email.
  • Encrypt bank files and store them in restricted locations.
  • Send payslips through an authenticated portal or app rather than email attachments.
  • Mask account numbers and PAN in reports where full values are not needed.
  • Keep a log of who downloaded payroll registers.
  • Train the team to spot payroll diversion scams where fraudsters impersonate employees to change bank details.
  • Include payroll in your incident response drills.

These controls also support good financial governance, as discussed in our payroll audit readiness and variance analysis guides.

Working with managers

Managers often hold HR data informally: salary details of team members, performance notes, personal circumstances shared in confidence, and screenshots of attendance. Give them clear guidance.

  • Access only the data needed to manage the team, ideally through HR system dashboards rather than exported files.
  • Do not forward personal data on messaging apps.
  • Keep notes factual and professional.
  • Refer employees' requests about their data to HR.
  • Report any incident or loss immediately.

Communicating with employees

Trust is built through openness.

  • Explain in plain language what data you collect, why, and how it is protected.
  • Share a short FAQ.
  • Provide a named contact for queries.
  • Announce new tools or monitoring measures before they go live.
  • Respond to concerns respectfully and promptly.
  • Report on your privacy improvements occasionally, for instance in town halls.

Employees who understand the reasons are far more likely to cooperate with controls such as multi-factor authentication.

A sample employee privacy notice outline

Adapt the following outline with your legal advisor.

  1. Who we are. Company name and contact.
  2. What personal data we collect. By category and source.
  3. Why we collect it. Purposes such as payroll, statutory compliance, benefits, attendance, performance, security and communication.
  4. Legal basis. Employment-related legitimate use, legal obligations, or consent for optional activities.
  5. Who we share it with. Categories of recipients such as payroll processors, banks, insurers, government authorities, auditors and BGV agencies.
  6. Where it is stored and transferred. Locations and cross-border transfers if any.
  7. How long we keep it. Retention approach.
  8. How we protect it. High-level security measures.
  9. Your rights. Access, correction, erasure, grievance and nomination, and how to exercise them.
  10. How to contact us. Grievance contact and escalation.
  11. How to complain to the Data Protection Board.
  12. Changes to this notice. How you will inform employees.

Common mistakes to avoid

  1. Assuming the law applies only to customer data. Employee data is covered.
  2. Relying on a blanket consent clause in the offer letter. Bundled, unclear consent may not be valid. Be specific.
  3. Treating "legitimate use for employment" as unlimited. It has boundaries. Document your reasoning.
  4. Ignoring paper records that later get digitised.
  5. Sharing payroll files via email or chat groups.
  6. Giving every HR staff member full access.
  7. Keeping everything forever. Retention should be justified.
  8. No vendor contracts covering data processing.
  9. Not knowing where data is. Without a data map you cannot answer rights requests or assess breaches.
  10. No breach plan. Panic wastes time.
  11. Collecting biometric or location data without notice.
  12. Using AI tools with employee data without checking vendor terms.
  13. Forgetting candidates and ex-employees. Their data is protected too.
  14. Treating compliance as a one-time project. It is an ongoing process.

A 90-day implementation plan for a small company

PeriodFocusKey outputs
Days 1–15Governance and discoveryPrivacy lead named, data inventory started, vendor list compiled
Days 16–30Gap assessmentRisk-ranked gap list, quick wins identified, legal adviser engaged
Days 31–45Policies and noticesDraft candidate and employee notices, retention schedule, rights request procedure, breach plan
Days 46–60ControlsRole-based access, MFA, encryption of payroll files, secure payslip delivery, device rules
Days 61–75Vendors and contractsData processing terms added or updated with key vendors
Days 76–90Training and launchTraining sessions, notices published, acknowledgements collected, first tabletop exercise

After 90 days, schedule quarterly reviews, and set an annual full review.

Metrics for your privacy programme

  • Percentage of data inventory completed and reviewed
  • Number of vendors with data processing terms in place
  • Percentage of HR and payroll users with multi-factor authentication
  • Training completion rate
  • Number of rights requests received and average response time
  • Number of incidents, near misses and time to contain
  • Percentage of records past retention that were deleted on schedule
  • Access review completion rate

Report these to leadership in your regular HR dashboard.

Frequently asked questions

Does the DPDP Act apply to employee data?

Yes. It applies to the processing of digital personal data, and employees, candidates and former employees are Data Principals whose data your company processes as a Data Fiduciary. The Act includes provisions relating to processing for employment purposes, but your company must still provide notice, apply safeguards and respect rights.

Do we need employee consent to run payroll?

Payroll and statutory compliance are generally closely linked to the employment relationship and to legal obligations, and the Act recognises legitimate uses related to employment. Confirm with your legal advisor how these provisions apply to your specific processing, and still provide a clear privacy notice.

Do we need consent for biometric attendance?

Biometric data is high-risk. Depending on your purpose and the legal analysis, you may rely on employment-related grounds, or you may prefer to obtain explicit acknowledgement and offer alternatives. Give clear notice, collect only what you need, protect templates and delete them when employment ends. Take legal advice on your specific case.

What are the penalties for non-compliance?

The Act provides for monetary penalties that can be significant, determined by the Data Protection Board according to the nature and gravity of the breach. Check the schedule in the Act and the latest rules for current details.

Do small companies and startups need to comply?

The Act applies to data fiduciaries in general, and certain exemptions may be available for specified classes such as some startups, as the government may notify. Do not assume you are exempt. Check current notifications and plan to comply proportionately.

Who is responsible when a payroll vendor has a data breach?

The Data Fiduciary, which is your company, remains responsible for ensuring appropriate safeguards, including through contracts with processors. Ensure your vendor contracts require security measures, breach notification and cooperation.

Can we keep employee data after they leave?

You may keep data for as long as needed for legal, tax and statutory requirements, and for defending claims where justified. Do not keep it indefinitely without purpose. Set a retention schedule and delete or anonymise after it expires.

Can we use employee data to train AI tools or analytics?

Only if the purpose is compatible with what employees were told and the law allows it. Avoid sending identifiable data to external AI tools without approval, contractual protections and a clear purpose. Consider anonymised or aggregated data for analytics.

How should we respond if an employee asks what data we hold about them?

Verify their identity, gather the information from HR, payroll and other systems, review it for information about other people that must be protected, and respond within the timeline set by the rules. Keep a record of the request and response.

What should be the first step for a small HR team?

Build a simple data inventory, secure payroll files with access controls and encryption, publish an employee privacy notice, and put contracts with your key vendors in order. Those steps address the largest risks with modest effort.

Conclusion

Data protection is no longer a specialist topic that HR can leave to IT or lawyers. The people function decides what employee data is collected, how it is used and who sees it, which means HR is at the centre of compliance. The good news is that a proportionate programme is achievable for a small team: map your data, collect less, tell people what you do, control access, sort out vendors, plan for incidents and review regularly.

Approach this as an opportunity to build trust rather than merely avoid penalties. Employees who see that their salary, bank details and personal circumstances are handled with care are more likely to engage with your HR systems and speak up when something is wrong.

If you are looking to bring HR data, payroll, attendance and employee self-service into a single, access-controlled system instead of scattered spreadsheets, consider trying CozyHR. It is designed to help Indian teams keep employee information organised, restrict access by role and reduce risky file-sharing, which is a strong foundation for privacy compliance.

Note: This article is general information, not legal advice. Data protection law and rules in India continue to be notified and clarified in phases. Verify current requirements, effective dates and penalties with official government sources and consult a qualified privacy or employment lawyer before making compliance decisions.