NNeevHR
← All posts

Compliance · 05 Sept 2026 · NeevHR Team · 3 min read

The DPDP Act 2023: what HR teams need to do

Consent, purpose limitation and data-principal rights applied to employee data, plus the technical controls that make compliance practical.

Compliance

The Digital Personal Data Protection Act, 2023 (DPDP) is India's data protection law, and HR sits at the centre of it. HR systems hold some of the most sensitive personal data in any company: identity documents, bank details, salary, health information, performance records and family details. Handling that data lawfully is now a legal duty, not just good practice.

The core principles

The DPDP framework rests on a few ideas that HR should internalise:

  • Purpose limitation: process personal data only for a lawful, specified purpose.
  • Lawful basis: rely on consent, or another permitted legal basis, to process data.
  • Data minimisation: collect only what you actually need.
  • Accuracy and retention: keep data accurate, and only for as long as the purpose requires.
  • Security: protect data with reasonable safeguards.

Employee rights as data principals

Under DPDP, individuals (called data principals) have rights over their data, and employees are no exception. In HR terms, an employee can:

  • Access the personal data you hold about them.
  • Seek correction of inaccurate data.
  • Seek erasure of data no longer needed for the purpose.
  • Nominate someone to exercise rights in the event of death or incapacity.

HR needs a defined way to receive and act on these requests within reasonable timelines, and a record that it did so.

Practical HR steps

Area What to do
Collection Collect only what the role and law require, with a clear purpose
Consent Capture consent where it is the basis, and record it
Access control Restrict who can see sensitive fields such as salary, bank and health
Retention Set retention schedules and delete or archive when the purpose ends
Requests Have a process to handle access, correction and erasure
Breach Have a plan to detect, contain and report a data breach

Security by design

DPDP compliance is far easier when the HR system enforces the right controls automatically rather than relying on people to be careful. The controls that matter most are:

  • Row-level isolation, so one company's data cannot leak into another's.
  • Role-based access, so people see only what their role needs.
  • Field masking, so sensitive fields are hidden from those who should not see them.
  • An audit trail, so every access and change is recorded.
  • Retention schedules and legal holds, so data is kept and removed by policy.

Consent and notice

Where consent is the basis for processing, it must be free, informed, specific and capable of being withdrawn as easily as it was given. Employees should receive a clear notice of what data is processed and why. For much employment processing, other lawful bases may apply, but consent handling still matters for optional uses.

Common mistakes to avoid

  • Collecting more employee data than the purpose needs.
  • Giving broad access to sensitive fields.
  • Keeping data forever with no retention policy.
  • Having no process for employee data requests.
  • Treating security as an IT-only concern, separate from HR.

Frequently asked questions

Does DPDP apply to employee data? Yes, employees are data principals and their personal data is covered.

Do we always need consent? Not always; other lawful bases can apply to employment, but consent handling is still relevant for optional processing.

What about existing HR records? They fall within the framework; retention and access controls should be applied to them too.

Key takeaways

  • Process employee data for a lawful, specified purpose, and minimise it.
  • Employees have access, correction and erasure rights.
  • Access control, masking, audit and retention are the practical backbone.
  • Build security into the system rather than relying on manual care.

NeevHR builds in row-level isolation, role-based access, field masking and an audit trail, with consent capture and data-principal request handling for employees, so DPDP compliance is a configuration rather than a project.

Run all of this on one platform

NeevHR handles payroll, attendance and compliance for Indian teams of 500 to 5,000.

Book a demo