top of page

DPDP compliance for HR: A 5-step framework for nonprofits


Your HR function holds the most sensitive data in the organisation, and it is usually the least governed data you hold Salaries, Bank details, Aadhaar and PAN scans, Medical certificates. Emergency contacts, Appraisal notes. It sits in a Drive folder here, an email thread there, one spreadsheet on somebody’s laptop, and a WhatsApp group from onboarding week that nobody ever cleared. 

India’s Digital Personal Data Protection Act now applies to all of it. Most nonprofits are still treating data protection as a programme problem, something to do with beneficiary records and field surveys. Meanwhile the exposure is sitting in HR. 

This guide covers what the law actually asks of an HR team, where nonprofits are most exposed, and a five-step framework you can start on this month. No legalese. 

 

The short version 

  • The DPDP Act applies to every organisation holding personal data. There is no small-NGO exemption. 

  • Core obligations start 13 May 2027. The cleanup is what takes time, not the paperwork. 

  • You do not need consent for payroll, attendance or statutory filings. Those are legitimate uses. 

  • Maximum penalty for failing to secure personal data: ₹250 crore

  • Your HRMS vendor being compliant does not make you compliant. Accountability stays with you.


 

1. What is the DPDP Act, and does it apply to us? 

The Digital Personal Data Protection Act, 2023 is India’s first dedicated data protection law. It governs how organisations collect, use, store and protect personal data. The Digital Personal Data Protection Rules, 2025 were published in the Gazette on 13 November 2025 and fill in the operational detail: what a notice must contain, what security counts as reasonable, what to do after a breach. 

Yes, it applies to you. There is no exemption for size, registration type, or not being a tech company. If you hold personal data, you are covered. A five-person foundation and a five-hundred-person NGO carry the same core obligations. 

 

2. Which employee data does DPDP cover? 

Personal data means any data about an identifiable individual. In an HR context, that is broader than most teams assume, and the scope question is less interesting than the location question. 

Category 

What it includes 

Where it usually ends up 

Identity 

Name, employee ID, Aadhaar, PAN, UAN 

Onboarding email threads, WhatsApp 

Financial 

Salary, CTC, bank account, PF details 

Payroll sheets shared with finance 

Health 

Medical certificates, insurance and ESI records 

Personal inboxes, printed files 

Attendance 

Location check-ins, biometric logs, leave records 

Attendance app exports 

Performance 

Appraisal scores, PIPs, disciplinary notes 

A manager’s personal Drive 

Recruitment 

CVs, interview notes, reference checks 

The recruitment inbox, forever 

Exit 

Resignation letters, full-and-final settlements 

Wherever the last HR person left them 

 

The third column is where the risk sits. The data itself is usually fine. The uncontrolled copies are the problem. 

 

3. Who is who under the law 

Three terms, and every obligation hangs off them. 

Term 

Who it is 

In your organisation 

Data Principal 

The person the data is about 

Your employee 

Data Fiduciary 

The organisation deciding why and how data is used 

You 

Data Processor 

A vendor handling data on your instructions 

Payroll provider, HRMS, cloud storage 

 

What this means in practice: accountability does not transfer. If your processor mishandles employee data, you are still the one answerable under the Act. The Rules also require your contract with that vendor to carry security obligations of its own. 

The key takeaway: choosing a vendor is a compliance decision, not only a procurement one. “Our software provider handles that” is not a defence. 

 

4. What happens if you get it wrong 

The Act sets a maximum penalty of ₹250 crore for failing to take reasonable security safeguards against a data breach. 

Realistically, a small nonprofit is not the Data Protection Board’s first stop. But the figure tells you how seriously the obligation is meant to be taken, and the Board has investigative powers. 

The quieter risk arrives sooner. Funders are already adding data protection questions to due diligence. Staff notice how their salary information gets handled. A leak of HR data does not read as a technical failure to the people affected. It reads as a breach of trust, and that is harder to repair than a system. 

 

5. When does this actually kick in? 

Date 

What happens 

What it means for HR 

13 Nov 2025 

DPDP Rules published; Data Protection Board established 

Framework is live 

13 Nov 2026 

Consent Manager provisions take effect 

Mostly relevant to platforms, not employers 

13 May 2027 

Notice, security, erasure and breach obligations take effect 

This is your deadline 

Under a year of comfortable runway, then. 

The paperwork is the fast part. Finding every copy of your employee data and deciding what to do with it is the slow part, and that cannot be done in a fortnight. Organisations planning to sort it out in early 2027 are the ones who will spend 2027 panicking. 

 


6. The 5-Step DPDP framework for HR 

None of this needs a legal team. It needs five decisions and someone to own them Step 1: Know what you collect 

What the law expects: your privacy notice must give an itemised description of the personal data you process. You cannot itemise what you have not mapped. 

What this means in practice: one sheet, five columns. What you collect, why, where it is stored, who can see it, how long you keep it. Start with the obvious categories, then add the awkward ones: 

  • CVs of candidates you did not hire 

  • Documents scanned into a WhatsApp thread during onboarding 

  • The salary sheet emailed to your auditor last March 

  • An intern list from 2021 nobody has opened since 

 

The key takeaway: give this an afternoon before you do anything else. For most teams the exercise itself is the eye-opener, because the honest answer to “who can see it” turns out to be “more people than we thought.” 

Where a system helps: when employee records and documents live in one platform instead of five locations, the map becomes a report you pull rather than an excavation. PeopleHub holds profiles, documents, payroll and attendance in a single place, which is most of why the inventory stops being a six-week project. 

 

Step 2: Fix your privacy notices 

What the law expects: a notice that stands on its own, in plain language, itemising the data and the purposes, and telling people how to withdraw consent, exercise their rights and complain to the Board. You must also publish contact details for someone who can answer employee questions about their data, and repeat those details in every response to a rights request. 

What this means in practice: a notice is not one document signed once at joining. It belongs at every point where you collect data. 

  • Job application form 

  • Onboarding pack 

  • Attendance app 

  • Expense claims 

  • That wellness survey someone circulated last quarter 

 

The key takeaway: new form collecting a new data point means a new notice. That rule is simple enough to hand to whoever builds your forms, and it stops the problem recurring. 

Where a system helps: fewer collection points means fewer notices to write and keep current. Consolidating recruitment, onboarding, attendance and expenses into PeopleHub cuts down the number of places you are maintaining a notice for. 

 

Step 3: Take consent only where it is needed 

This is the step organisations overcomplicate, usually by asking for consent for everything. 

No consent needed (legitimate use) 

Consent required 

Payroll and salary processing 

Photos used in marketing or social media 

Attendance and leave records 

Optional wellness or engagement apps 

Statutory filings: PF, ESI, TDS 

Sharing data with a third party for something unrelated to employment 

Benefits administration 

Any use beyond the purpose you originally stated 

Protecting the employer from loss or liability 

— 

 

What this means in practice: building a consent flow around payroll creates a mechanism you cannot honour, because you cannot stop paying someone who withdraws consent. Skip it. 

Where you do take consent, the standard is specific. Free, informed, unambiguous, given by a clear affirmative action, limited to the stated purpose, and as easy to withdraw as it was to give. A blanket clause in the employment contract saying the employee agrees to all data processing does not meet that test. 

The key takeaway: you need to show when and how each consent was taken. That means a record, not a recollection. 

Where a system helps: onboarding checklists and document acknowledgements in PeopleHub leave a dated, retrievable trail, so consent is evidenced by the system instead of reconstructed from an inbox two years later. 

 

Step 4: Restrict who can see what 

What the law expects: the Rules are unusually specific here. Reasonable security safeguards include encryption or masking of personal data, controls over who can access the systems holding it, logs and monitoring good enough to detect and investigate unauthorised access, backups, and a contract with every processor requiring the same. Those logs must be kept for a year. 

This is also the obligation the ₹250 crore figure attaches to, which tells you where scrutiny will land. 

What this means in practice: two habits. 

  • Give access by role. Finance sees payroll, managers see their own team, and a shared Drive folder stops being treated as an access control system. 

  • Revoke on the last working day, not three months later when someone remembers. Your offboarding checklist should be your onboarding checklist, reversed. 

The key takeaway: ask your HR software, payroll and cloud vendors this quarter whether your contract carries the security obligations the Rules require. If nobody can answer, you have found a gap. 

Where a system helps: in PeopleHub, records, payroll, documents and approvals sit behind individual logins in one platform, so offboarding closes access to all of it in a single action rather than depending on someone remembering which shared folders to update. 

 

Step 5: Decide how long you keep things 

What the law expects: personal data should be erased once the purpose it was collected for has been served, unless a law requires you to keep it. 

Two clarifications, because this step attracts more bad advice than any other. 

  • The three-year erasure clock people quote from the Rules does not apply to you. It is written for large e-commerce platforms, online gaming intermediaries and social media intermediaries above specific user thresholds. As an employer, you set and defend your own retention schedule. 

  • And “delete when done” has a floor. The Rules require personal data and the associated processing logs to be kept for at least a year, and separately require security logs retained for a year. Labour, provident fund and tax laws impose their own minimums on registers and payroll records, and those override whatever policy you write. 

What this means in practice: a schedule with three columns. 

Data type 

What ends the purpose 

Where the minimum comes from 

Rejected candidate CVs 

Role is filled 

Nothing requires you to keep these 

Payroll and salary records 

Employment ends 

Tax and PF law: confirm with your auditor 

Attendance and leave 

Statutory register period passes 

Labour law: confirm with your auditor 

Performance records 

Employment ends, plus your own review window 

Your policy 

Exit documents 

Full and final settlement completed 

Tax and labour law 

 

The key takeaway: start with row one. Old CVs sitting in a recruitment inbox from three hiring rounds ago serve no purpose and carry pure risk. Deleting them costs you nothing and takes ten minutes. 

Where a system helps: structured records with joining and exit dates make retention a rule you apply consistently, rather than a judgement call someone makes each time they open a folder. 

 

 

7. What this looks like in most organisations right now  

Before that framework starts sounding too tidy, here is what we usually find when we look at HR data properly. 

What we see 

Why it is a problem 

Which step fixes it 

Employee records in a personal Google Drive 

No ownership, no audit trail, leaves with the person 

Steps 1 and 4 

Ex-staff accounts still active 

Access continues after the employment purpose ends 

Step 4 

Salary details on personal laptops 

Outside every control you think you have 

Step 4 

Same data across Drive and three sheets 

You cannot delete or correct what you cannot find 

Step 1 

Records kept indefinitely 

Retention with no defensible basis 

Step 5 

Data collected without telling anyone 

No notice, no lawful basis on record 

Steps 2 and 3 

If you recognise more than one, you are not behind. That is the sector’s starting point. 

 

8. Your first 30 days 

None of this needs budget approval or a lawyer. 

# 

Action 

Owner 

Timeline 

1 

Build the inventory: every data item, where it lives, who can see it 

HR 

Week 1 

2 

Pull the access list and close every account belonging to someone who has left 

HR + IT 

Week 1 to 2 

3 

Write one proper notice, starting with the job application form or onboarding pack 

HR 

Week 2 to 3 

4 

Delete the obvious: old CVs, duplicate spreadsheets, documents you cannot justify holding 

HR 

Week 3 to 4 

 

The organisations that will struggle in May 2027 are not the ones without a policy document. They are the ones who still cannot say where their employee data is. 

 

9. Frequently asked questions

Q: Does the DPDP Act apply to small NGOs? 

Yes. It applies to any organisation processing digital personal data, with no exemption for size, turnover or registration type. A five-person foundation carries the same core obligations as a large employer. 

Q: Do we need employee consent to run payroll? 

No. Processing employee data for employment purposes, including payroll, attendance, statutory filings and protecting the employer from loss or liability, is recognised as a legitimate use under the Act. Consent is required for uses beyond employment, such as marketing photographs or optional wellness apps. 

Q: When do we actually have to comply? 

The obligations affecting HR most directly, covering notice, security safeguards, erasure and breach reporting, take effect on 13 May 2027. The Rules were published on 13 November 2025 and the Data Protection Board is already established. 

Q: How long should we keep employee data? 

Long enough to serve the purpose you collected it for and to satisfy any law requiring retention, and no longer. The Rules also set a floor: personal data and processing logs must be retained for at least one year. Tax and labour law minimums apply on top, so confirm those with your auditor before deleting anything. 

Q: Our HR software vendor had a breach. Are we liable? 

Your vendor is a Data Processor and you remain the Data Fiduciary. Accountability for how employee data is handled stays with you, which is why the Rules require your contract with any processor to include security obligations. 

Q: Do we need a Data Protection Officer? 

Only organisations notified as Significant Data Fiduciaries must appoint one. Every data fiduciary, however, must publish contact details for a person who can answer questions about how personal data is processed, and include those details in every response to a rights request. 

Q: What do we do if there is a breach? 

Tell each affected person without delay, in plain language: what happened, what it means for them, what you are doing about it, and who to contact. Inform the Data Protection Board without delay as well, followed by a detailed report within 72 hours.


10. Where to start 

Check where you stand. Our DPDP Readiness Assessment for HR takes five minutes and five questions and shows which of the five areas needs attention first. Take the assessment → 

Talk it through. A free 30-minute DPDP readiness consultation: what your results mean, what to prioritise, and what can honestly wait. Book a free consultation → 

See it working. PeopleHub HRMS is built for nonprofits and impact organisations, bringing employee records, attendance, payroll, documents and offboarding into one system. Book a PeopleHub demo → 

 

Comments


bottom of page