Skip to main content

SalaryBox

Impact of India’s DPDP Act on HR & Payroll Data Handling in 2026: Complete Compliance Guide

The Digital Personal Data Protection Act, 2023 (DPDP Act or DPDPA), read with the Digital Personal Data Protection Rules, 2025, is India’s primary law governing the collection, processing, storage, and sharing of digital personal data, including employee and payroll information.

In 2026, employers handling digital employee data are Data Fiduciaries under the law. Core HR and payroll activities such as salary processing, statutory filings, and attendance for compensation generally fall under “legitimate use” for purposes of employment, so separate consent is often not required. However, notice, purpose limitation, data minimisation, security safeguards, retention controls, and vendor accountability still apply. Penalties can reach ₹250 crore for serious failures. This guide explains the practical impact on HR and payroll teams and the steps organisations should take during the current implementation window.

Why the DPDP Act Matters for HR and Payroll in 2026

Almost every piece of information HR and payroll teams handle—name, PAN, bank details, Aadhaar (where lawfully collected), salary structure, PF/ESI records, attendance logs, performance notes, and exit documents—qualifies as personal data when it relates to an identifiable individual.

The DPDP Rules were notified in November 2025. Substantive obligations around notice, rights handling, breach response, and many fiduciary duties phase in with full enforcement targeted for mid-May 2027. 2026 is therefore the critical year for mapping data, updating notices, tightening vendor contracts, and building operational processes.

Key data points:

  • Maximum penalty for failure to implement reasonable security safeguards is ₹250 crore.
  • Processing for “purposes of employment” is recognised as a legitimate use under Section 7, reducing the need for separate consent in many routine HR and payroll scenarios.
  • Employers remain responsible even when data is processed by third-party payroll or HRMS vendors.

Core Concepts HR Teams Must Understand

Data Principal – the employee or candidate whose data is processed.

Data Fiduciary – the employer that determines the purpose and means of processing.

Data Processor – vendors (payroll processors, background-check agencies, attendance system providers) that process data on the fiduciary’s behalf.

The employer stays accountable for the processor’s compliance. Contracts must reflect this responsibility.

Legitimate Use vs Consent for Employee Data

For most core employment activities—recruitment necessary for hiring, onboarding, payroll, statutory deductions (PF, ESI, TDS), leave and attendance linked to compensation, performance management, and disciplinary processes—processing can rely on the legitimate-use ground for purposes of employment. Separate consent is generally not required.

Consent becomes relevant when processing goes beyond what is necessary for employment (for example, using employee photos in external marketing, certain forms of monitoring, or collecting data for purposes unrelated to the employment relationship). When consent is used, it must be free, specific, informed, unconditional, and unambiguous, and withdrawal must be as easy as giving it.

Even under legitimate use, a clear privacy notice is still required. The notice should explain what data is collected, the purpose, rights available, and how to raise queries or grievances.

Decision Table: Consent vs Legitimate Use for Common HR Data

Data / Activity Typical Lawful Basis Consent Usually Required? Key Notes Best For Whom
Payroll, bank details, salary structure Legitimate use (employment) No Necessary for payment and tax compliance All employers
PF, ESI, TDS filings Legitimate use + legal obligation No Statutory requirements All employers
Basic attendance for salary calculation Legitimate use No Keep collection proportionate Most organisations
Biometric attendance (finger/face) Case-by-case; often higher scrutiny Often recommended/required Assess necessity; strong notice + safeguards High-security or large workforces
Background verification Depends on stage and scope Frequently yes Proportionate to role; clear notice Hiring teams
Performance & disciplinary records Legitimate use No Limit to employment purposes Managers & HR
Employee photos for marketing Consent Yes Outside core employment Communications / marketing teams
Health / medical data beyond ESI Higher care; often consent or specific ground Frequently yes Sensitive in practice; minimise collection Benefits & wellbeing teams

Clear recommendation: Map every data category and processing purpose. Default to legitimate use only where the link to employment is direct and necessary. Document the assessment.

Impact on Specific HR and Payroll Processes

Payroll data

Salary, bank account, PAN, and statutory contribution data are personal data. Processing for payment and compliance falls under legitimate use. Still apply data minimisation, restrict access, encrypt sensitive fields, and set clear retention periods aligned with tax and labour-law requirements.

Attendance and biometric data

Ordinary attendance records used for payroll generally fit legitimate use. Biometric data (fingerprints, facial templates) attracts higher practical scrutiny because of its sensitive nature. Organisations should assess whether biometrics are genuinely necessary, issue a clear notice, implement strong security (encryption, access controls), and consider consent or alternative methods where feasible.

Recruitment and background verification

Candidate data before employment often relies more heavily on consent or careful notice. Limit collection to what is needed for the role and delete or anonymise data of unsuccessful candidates once the purpose ends, subject to any legal hold.

Third-party vendors (payroll software, HRMS, background-check agencies)

The employer remains the Data Fiduciary. Contracts must require processors to follow instructions, implement security safeguards, assist with rights requests and breaches, and delete or return data when the relationship ends. Conduct due diligence and maintain an inventory of processors.

Employer Responsibilities and Practical Compliance Steps

  1. Identify and map all employee and candidate personal data, systems, and flows.
  2. Define purposes clearly and apply purpose limitation and data minimisation.
  3. Issue or update privacy notices for employees and candidates.
  4. Determine lawful basis (legitimate use or consent) for each processing activity and document it.
  5. Control access — role-based permissions for HR and payroll staff.
  6. Review and update vendor contracts; ensure processors meet security and contractual standards.
  7. Set retention periods and implement deletion or anonymisation once the purpose is served or legal retention ends.
  8. Prepare breach response processes, including internal escalation and notification pathways.
  9. Train HR, payroll, and managers on data-handling rules and employee rights.
  10. Enable Data Principal rights — access, correction, and erasure where applicable, with published response timelines.

Best for whom:

  • Small and mid-sized companies: Start with data mapping, basic notices, access controls, and vendor contract reviews.
  • Larger or multi-location organisations: Add formal records of processing, stronger technical safeguards, and dedicated privacy ownership.
  • Companies using biometric systems or extensive monitoring: Prioritise necessity assessments and enhanced notices/security.

Clear recommendation: Treat 2026 as the build year. Complete data mapping and notice updates first, then harden security and vendor management before the full enforcement date in 2027.

Data Retention, Deletion, and Employee Rights

Retain personal data only for as long as necessary for the specified purpose or as required by other laws (tax, labour, PF, etc.). Once the purpose is served and no legal retention applies, delete or anonymise the data. Employees (Data Principals) have rights to access, correction, and erasure of data that is no longer necessary. Organisations should publish how these rights can be exercised and respond within the timelines they set.

Security, Breaches, and Penalties

Reasonable security safeguards are mandatory. Failure that leads to a personal data breach can attract penalties up to ₹250 crore. Failure to notify the Data Protection Board or affected individuals can attract up to ₹200 crore. Other violations carry lower but still significant ceilings. A documented breach-response plan and regular security reviews reduce both risk and potential penalty exposure.

SalaryBox helps organisations manage attendance, leave, and payroll processes with structured digital records, supporting clearer data handling and operational discipline while teams work through DPDP readiness.

Final Recommendations for 2026

  • Complete an employee-data inventory and purpose map this year.
  • Update privacy notices and employment documentation.
  • Rely on legitimate use only for processing that is genuinely necessary for employment; use consent where the link is weaker.
  • Strengthen access controls, encryption, and vendor contracts.
  • Define retention schedules and deletion processes.
  • Train teams and prepare for Data Principal requests and breach handling.
  • Document decisions so the organisation can demonstrate accountability.

The DPDP Act does not stop normal HR and payroll operations, but it requires greater discipline around purpose, minimisation, security, retention, and transparency. Organisations that treat 2026 as a structured preparation year will be far better positioned when full enforcement arrives.

Frequently Asked Questions

Does the DPDP Act apply to employee data in India?

Yes. The Digital Personal Data Protection Act applies to digital personal data of employees and candidates. Employers that determine the purpose and means of processing this data are Data Fiduciaries. The Act covers data collected during recruitment, employment, and post-employment stages, including identity details, financial and payroll information, attendance records, performance data, and more. Both the Act and the DPDP Rules 2025 create obligations around notice, purpose limitation, security, retention, and individual rights. 2026 is the key year for building compliance before full enforcement in 2027.

How does the DPDP Act affect HR departments?

HR teams must treat employee data as regulated personal data. They need to map what data is collected, why it is processed, how long it is kept, who can access it, and which vendors process it. Core employment processing often relies on legitimate use rather than consent, but privacy notices, data minimisation, access controls, and security safeguards are still required. HR must also support employee rights requests and coordinate with IT and legal on breach readiness. Training and clear internal processes become essential.

Does the DPDP Act apply to payroll data?

Yes. Salary details, bank account information, PAN, PF/ESI records, and related tax data are personal data when linked to an identifiable employee. Processing for salary payment and statutory compliance generally qualifies as a legitimate use for purposes of employment, so separate consent is typically not needed. However, purpose limitation, security, restricted access, proper retention, and vendor accountability still apply. Payroll systems and service providers must be brought within the compliance framework.

Is employee consent required under the DPDP Act?

Consent is the default ground for processing, but the Act expressly recognises “purposes of employment” (and related safeguarding of the employer) as a legitimate use. For routine HR and payroll activities that are necessary for the employment relationship, consent is generally not required. Consent is needed when processing goes beyond what is necessary for employment. Even under legitimate use, a clear notice must still be provided to employees.

Is consent required to process employee salary and payroll data?

In most cases, no. Processing salary and payroll data for payment, tax deduction, and statutory contributions falls under the legitimate-use ground for purposes of employment. Organisations should still issue a privacy notice, collect only necessary data, restrict access, secure the information, and retain it only as long as required by the purpose or by law. If payroll data is used for unrelated purposes, consent or another valid ground would be needed.

What employee data is covered under the DPDP Act?

Any digital data that relates to an identifiable employee or candidate is covered. This includes identity and contact details, government IDs (where collected), bank and salary information, PF/ESI records, attendance and leave data, biometric templates, performance and disciplinary records, health-related information collected for employment purposes, recruitment and background-check material, and exit documentation. Sensitivity and risk vary, but the Act’s obligations apply across these categories.

How should HR teams protect employee personal data?

Implement role-based access controls, encryption for sensitive fields, secure storage, and regular access reviews. Apply data minimisation and purpose limitation. Maintain clear retention and deletion schedules. Ensure third-party vendors have appropriate contracts and security standards. Train staff, maintain records of processing activities, and prepare incident-response procedures. Document the lawful basis for each major processing activity.

What are an employer’s responsibilities under the DPDP Act?

As Data Fiduciary, the employer must process data lawfully (consent or legitimate use), provide notice, limit processing to stated purposes, ensure accuracy where relevant, implement reasonable security safeguards, retain data only as long as necessary, honour Data Principal rights, notify breaches as required, and remain accountable for processors. Significant Data Fiduciaries face additional obligations if notified as such.

How does the DPDP Act affect employee attendance data?

Attendance data used for salary calculation and workforce administration generally falls under legitimate use for employment purposes. Organisations should still minimise the data collected, secure it, limit access, and define retention periods. When attendance is linked to payroll or statutory records, longer retention may be justified by other laws. Clear notice to employees remains important.

Does the DPDP Act apply to biometric attendance data?

Yes. Biometric data (fingerprints, facial recognition, etc.) is personal data and often treated with heightened care because of its sensitive nature. While attendance for employment purposes may rely on legitimate use, many organisations conduct a necessity assessment, provide detailed notice, obtain explicit consent where appropriate, encrypt templates, and restrict access. Less intrusive alternatives should be considered where they meet the business need.

How long can HR departments retain employee data?

Data should be retained only for as long as necessary for the specified purpose or as required by other applicable laws (tax, labour, PF, etc.). Once the purpose is served and no legal retention obligation remains, the data should be deleted or anonymised. Organisations should define and document retention schedules for different categories of employee records and implement processes to enforce them.

What should HR teams consider when using third-party payroll or HRMS vendors?

The employer remains the Data Fiduciary and is accountable for the vendor’s processing. Contracts should require the processor to follow instructions, implement security safeguards, assist with rights requests and breach notification, and delete or return data at the end of the engagement. Conduct due diligence, maintain an inventory of processors, and ensure data flows and purposes are clearly defined and limited.