September 16, 2026 | By Gopareto Marketing
Your employees trust your company with deeply personal information—names, addresses, bank details, health records, family information and performance evaluations. Under India’s Digital Personal Data Protection Act, protecting this data isn’t just good practice, it’s a legal mandate.
But employee data protection goes deeper than securing servers. It’s about understanding what data you can collect, how employees control their information, and what happens when they leave.
This guide explains employee rights under DPDP, shows how to structure data collection responsibly, and gives you a practical compliance roadmap.
The DPDP Act gives employees five critical rights over their personal data. As an employer you need to understand and respect them, or face regulatory action.
Employees have the right to know what data you’re collecting and why, before you collect it. Before asking for health information, biometric data or family details, you must clearly explain:
Common mistake: collecting “optional” data on employment forms without explaining the purpose. An employee ticks yes to sharing emergency contact information without realising it will sit in your database permanently.
An employee can ask to see everything you hold about them. You must provide personal data, work history, performance data, attendance records, training history and anything else stored—typically within 30 to 45 days.
Most manual systems cannot easily pull every record about one person. HRMS platforms with proper search and export make this simple.
Employees can request their data in a portable, machine-readable format such as CSV, JSON or PDF, and take it elsewhere. DPDP wants to prevent lock-in: employees shouldn’t feel trapped by data that exists only in your HR system. If your HRMS cannot export in portable formats, that’s a major compliance gap.
Employees can request corrections to inaccurate data and deletion when data is no longer needed. If an employee says their address is wrong, you update it immediately. If a former employee asks for performance evaluations to be deleted and the retention period has passed, you cannot legally refuse.
Many companies keep decades of employee files “just in case.” DPDP says you can’t. You need defined retention periods and you must actually delete data when they expire.
If an employee consented to optional data collection, they can withdraw that consent at any time. Someone who agreed to biometric attendance tracking in 2024 can ask you to stop in 2025, and you must stop immediately—though you may keep historical data for legitimate business reasons. Your HRMS must flag withdrawals, or you’ll keep processing data illegally.
Not all personal data is equal under DPDP, and you can’t treat it all the same way.
For every field, document why you need it:
To calculate payroll and track leave compliance.
To assess job performance and plan career development.
To verify attendance and prevent time theft.
If you can’t articulate a legitimate business purpose, you shouldn’t be collecting the data.
A weak approach is an email asking “is it OK if we collect biometric data?” with a reply-email response and no audit trail. A strong approach is an HRMS portal notification with explanation, a timestamped checkbox, and an audit trail showing the confirmation.
| Data type | Typical retention | Reason |
|---|---|---|
| Payroll records | 7 years | Tax compliance |
| Attendance logs | 2 years | Operational history |
| Performance evaluations | 5 years | Career history |
| Exit interviews | 3 years | Knowledge retention |
Document these in your HR policies, then enforce them in your HRMS through automatic deletion.
Use role-based access control and the principle of least privilege: people see only the data their job requires.
Collecting data compliantly is half the battle. Protecting it is the other half.
If you use a cloud HRMS, your vendor’s security becomes your security. Verify ISO 27001 certification, request the SOC 2 Type II report, check incident response procedures, understand disaster recovery, and confirm the vendor is DPDP-compliant. The question worth asking: “what happens to our data if your company has a breach?”
Our guide to auditing HR software for DPDP compliance has the full vendor checklist.
DPDP follows a principle called data minimisation—collect the minimum data necessary for your purpose. The common mistake is requesting exhaustive information during onboarding just in case you might need it someday.
For each field ask: do we absolutely need this for them to do their job? If the answer is no, remove it.
This is where many companies get DPDP wrong.
| Data | Handling after exit |
|---|---|
| Personal data such as home address and emergency contacts | Usually deleted immediately |
| Payroll data: salary history, tax forms | Retain 7 years for tax compliance |
| Attendance records | Retain 2–3 years, then delete |
| Performance evaluations | Often 3–5 years, depending on policy |
| Medical and health data | Delete after 2 years where legally permitted |
Former employees keep their DPDP rights: access to data you still hold, correction of inaccurate data, and deletion once retention expires. Some data must be kept regardless—payroll records for tax, stock option records while options are vested, anything under legal hold during pending litigation.
Only with a documented retention purpose. If your period is five years and the evaluation is six years old, it must be deleted.
You can’t process that data without consent unless it is strictly necessary for employment—and you can’t punish them for refusing.
Yes, but only under a signed Data Processing Agreement, which makes the vendor responsible for protecting it.
Report it to affected employees within three days, and to the DPDP authority if serious. Document your incident response.
Employee data protection under DPDP isn’t just about legal compliance—it’s about respecting employee privacy and building trust. Employees who know their data is protected are happier, more engaged and more likely to stay.
Collect only what you need, get explicit consent, secure everything properly and respect employee rights. You’re not just avoiding penalties; you’re building an ethical HR practice that attracts and retains talent.
See the wider picture in our India labour law compliance guide.
Request a DemoGoPareto - Simple & Complete Business Management solution, Omkar Nandan Apartment, A1 201, near Navale Bridge, Kudale Baug, Narhe, Pune, Maharashtra 411041.
Related Blogs