
Every employer is a Data Fiduciary for its staff. HR systems hold identity documents, bank accounts, salary, health and family details, often for years after someone leaves. The DPDP Act gives employers a specific legitimate use, but it is narrower than many HR teams assume.
The employment legitimate use
The Act permits processing without consent for the purposes of employment, or to safeguard the employer from loss or liability, such as preventing corporate espionage, keeping trade secrets and intellectual property confidential, or providing a service or benefit an employee asks for. Payroll, attendance, statutory filings and benefits fit within this.
Candidates are not employees
Applicants give data voluntarily for a hiring decision. Once the role is filled, the purpose for unsuccessful candidates is over. Keeping résumés in a talent pool needs consent and a time limit. Recruitment software should record the source of each profile and the basis for keeping it.
A résumé database with no retention rule is a liability that grows every month.
Monitoring and background verification
Security monitoring to protect company systems can fall under safeguarding the employer from loss, but it should be proportionate, disclosed in policy and limited to work systems. Background verification involves third-party agencies and often past employers and educational institutions; tell candidates what will be checked and by whom, and contract with the agency as a processor.
What HR software should provide
Whether you buy or build, the system should make compliance a matter of configuration.
Payroll and benefits vendors
Payroll processors, HRMS vendors, insurers and benefits platforms process employee data on the employer's behalf. The employer remains responsible. Agreements should cover security safeguards, breach notification, sub-processors, location of data and deletion at exit. Where a vendor uses the data for its own purposes, such as an insurer underwriting a policy, it is a separate Data Fiduciary and employees should be told.
Ex-employees and retention
Labour, tax and provident fund laws require employers to keep certain records for set periods, and the Act permits retention where a law requires it. Beyond those periods, delete. Employees and former employees can ask for a summary of their data, correction and erasure, and the employer must respond through a published grievance process within ninety days at most.
- Digital Personal Data Protection Act, 2023 (MeitY)
- Digital Personal Data Protection Rules, 2025: notification summary (Press Information Bureau)
This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.





