DPDP Act for HR: employee data, Aadhaar, retention and the May 2027 deadline
The DPDP Act for HR teams: when you need consent for employee data, what to do with Aadhaar, how long to keep records, and what applies from 13 May 2027.
Last checked 6 min read
Most HR teams have heard that the DPDP Act "applies to employee data" and stopped there, because the main deadline felt far away. It is now seven months off. The DPDP Act for HR is less frightening than the headlines suggest: employment processing does not need consent. But it does change how you handle Aadhaar, how long you keep files, and what you do on the day a laptop full of payslips goes missing.
DPDP Rules 2025 deadlines in one table
The Digital Personal Data Protection Act was passed in 2023. Its Rules were notified on 13 November 2025, and they come in stages.
| From | What applies |
|---|---|
| 13 November 2025 | Definitions, the Data Protection Board and its procedures |
| 13 November 2026 | Consent managers |
| 13 May 2027 | Notice, security safeguards, breach reporting, retention and erasure, grievances, data transfers |
For an employer, 13 May 2027 is the date that matters. Until then, the older IT Act rules on sensitive personal data still apply.
Legitimate use for employment: where consent is not needed
Section 7(i) of the Act lets an employer process personal data "for the purposes of employment" or to protect itself from loss or liability. That covers the core: hiring records, attendance, payroll, PF and ESI, appraisals, discipline and exit.
So you do not need an employee's consent to run payroll. Telling employees clearly what you collect and why is still good practice, and wherever you do rely on consent, a notice is required.
Consent comes back for anything outside employment. Three common examples:
- Birthdays on the company wall. Showing a birthday to colleagues is not needed for employment. Make it opt-in, day and month only.
- Photos in marketing. A team photo on the careers page needs a yes from each person in it.
- Background checks. The check itself may be part of hiring, but a candidate can withdraw consent for the parts that rely on it. Record what happens if they do, for example that the offer may lapse.
Employee data under DPDP: the duties that bite
From May 2027, these are the obligations HR will notice most.
Security safeguards. Section 8(5) asks for reasonable security safeguards. In HR terms: role-based access to salary and ID data, encryption of sensitive fields, masking in reports, and a record of who opened what.
Breach reporting. If employee data leaks, the company must tell the Data Protection Board and each affected person without delay, and send a detailed report within 72 hours of becoming aware. Agree in advance who decides, who drafts and who signs. If your HR software vendor is a processor, your contract should promise you an early warning, well inside those 72 hours.
Retention and erasure. Erase personal data once its purpose is over, unless another law requires you to keep it. Statutory records are kept: payroll and expense vouchers usually need eight years. A rejected candidate's résumé from 2021 does not.
Logs for one year. The Rules also ask for logs of processing to be kept for at least a year, even after the data itself is erased. That matters for systems such as visitor logs, which we cover in visitor management and DPDP.
A grievance contact. Publish the contact of a person who can answer employees' questions about their data, and resolve grievances within the time the Rules set.
Penalties under the Act go up to ₹250 crore, which is why enterprise customers now ask their HR vendors detailed questions about all of the above.
Aadhaar storage by employer: you probably need less than you hold
Aadhaar is where most HR files are over-collected.
- You cannot make Aadhaar compulsory. After the Supreme Court's 2018 judgment, a private employer must accept another government ID.
- EPFO no longer needs it from you. Since 1 August 2025, new UANs are created by the employee in the UMANG app with Aadhaar face authentication. The employer only receives the UAN.
- ESIC made Aadhaar voluntary in August 2025; PAN, passport or driving licence are accepted.
- Masked is the norm. UIDAI's masked Aadhaar shows only the last four digits. Under the Aadhaar sharing regulations, a number must never be displayed publicly and should be kept no longer than the purpose needs.
For most employers, the right default is to keep the last four digits only. If you genuinely need the full number, say for KYC seeding you still do yourself, keep it encrypted, masked on every screen and export, visible only to a named role, and purge it back to four digits after exit.
A practical example
A 500-person logistics company in Gurugram ran a quick audit before the deadline. It found:
- full Aadhaar numbers in three places: the HRMS, a shared drive of scanned joining kits, and an old BGV vendor portal;
- 6,000 résumés of rejected candidates going back to 2019;
- a birthday wall showing full dates of birth to everyone.
The fixes took four weeks: last four digits only in the HRMS, the shared drive cleaned and locked, the BGV vendor asked to delete, a 12-month retention for unsuccessful candidates, and birthdays switched to opt-in with day and month only.
DPDP Act for HR: checklist before 13 May 2027
- Map the data. What you hold about employees, candidates and ex-employees, and where.
- Tag the basis. Employment (legitimate use) or consent. Move anything outside employment to opt-in.
- Cut Aadhaar to the last four digits wherever you can.
- Set retention per record type, with statutory periods first.
- Write the breach runbook and test it once.
- Review vendor contracts for processor terms and breach notice times.
- Publish a grievance contact and train whoever answers it.
Employee data is not the only personal data HR and admin handle. Shared IT credentials raise access-control questions of their own, covered in shared password management for IT teams.
How we handle security and data on our side is on the security page. In Vatsin HRMS, Aadhaar defaults to the last four digits, keeping the full number is a company setting with masking and a separate reveal right, and birthdays on the wall are opt-in.