DPDP compliance for HR: A 5-step framework for nonprofits
- Piyali Paul

- Jul 29
- 10 min read
Your HR function holds the most sensitive data in the organisation, and it is usually the least governed data you hold
Salaries, Bank details, Aadhaar and PAN scans, Medical certificates. Emergency contacts, Appraisal notes. It sits in a Drive folder here, an email thread there, one spreadsheet on somebody’s laptop, and a WhatsApp group from onboarding week that nobody ever cleared.
India’s Digital Personal Data Protection Act now applies to all of it. Most nonprofits are still treating data protection as a programme problem, something to do with beneficiary records and field surveys. Meanwhile the exposure is sitting in HR.
This guide covers what the law actually asks of an HR team, where nonprofits are most exposed, and a five-step framework you can start on this month. No legalese.
The short version
The DPDP Act applies to every organisation holding personal data. There is no small-NGO exemption.
Core obligations start 13 May 2027. The cleanup is what takes time, not the paperwork.
You do not need consent for payroll, attendance or statutory filings. Those are legitimate uses.
Maximum penalty for failing to secure personal data: ₹250 crore.
Your HRMS vendor being compliant does not make you compliant. Accountability stays with you.
1. What is the DPDP Act, and does it apply to us?
The Digital Personal Data Protection Act, 2023 is India’s first dedicated data protection law. It governs how organisations collect, use, store and protect personal data. The Digital Personal Data Protection Rules, 2025 were published in the Gazette on 13 November 2025 and fill in the operational detail: what a notice must contain, what security counts as reasonable, what to do after a breach.
Yes, it applies to you. There is no exemption for size, registration type, or not being a tech company. If you hold personal data, you are covered. A five-person foundation and a five-hundred-person NGO carry the same core obligations.

2. Which employee data does DPDP cover?
Personal data means any data about an identifiable individual. In an HR context, that is broader than most teams assume, and the scope question is less interesting than the location question.
Category | What it includes | Where it usually ends up |
Identity | Name, employee ID, Aadhaar, PAN, UAN | Onboarding email threads, WhatsApp |
Financial | Salary, CTC, bank account, PF details | Payroll sheets shared with finance |
Health | Medical certificates, insurance and ESI records | Personal inboxes, printed files |
Attendance | Location check-ins, biometric logs, leave records | Attendance app exports |
Performance | Appraisal scores, PIPs, disciplinary notes | A manager’s personal Drive |
Recruitment | CVs, interview notes, reference checks | The recruitment inbox, forever |
Exit | Resignation letters, full-and-final settlements | Wherever the last HR person left them |
The third column is where the risk sits. The data itself is usually fine. The uncontrolled copies are the problem.
3. Who is who under the law
Three terms, and every obligation hangs off them.
Term | Who it is | In your organisation |
Data Principal | The person the data is about | Your employee |
Data Fiduciary | The organisation deciding why and how data is used | You |
Data Processor | A vendor handling data on your instructions | Payroll provider, HRMS, cloud storage |
What this means in practice: accountability does not transfer. If your processor mishandles employee data, you are still the one answerable under the Act. The Rules also require your contract with that vendor to carry security obligations of its own.
The key takeaway: choosing a vendor is a compliance decision, not only a procurement one. “Our software provider handles that” is not a defence.

4. What happens if you get it wrong
The Act sets a maximum penalty of ₹250 crore for failing to take reasonable security safeguards against a data breach.
Realistically, a small nonprofit is not the Data Protection Board’s first stop. But the figure tells you how seriously the obligation is meant to be taken, and the Board has investigative powers.
The quieter risk arrives sooner. Funders are already adding data protection questions to due diligence. Staff notice how their salary information gets handled. A leak of HR data does not read as a technical failure to the people affected. It reads as a breach of trust, and that is harder to repair than a system.

5. When does this actually kick in?
Date | What happens | What it means for HR |
13 Nov 2025 | DPDP Rules published; Data Protection Board established | Framework is live |
13 Nov 2026 | Consent Manager provisions take effect | Mostly relevant to platforms, not employers |
13 May 2027 | Notice, security, erasure and breach obligations take effect | This is your deadline |
Under a year of comfortable runway, then.
The paperwork is the fast part. Finding every copy of your employee data and deciding what to do with it is the slow part, and that cannot be done in a fortnight. Organisations planning to sort it out in early 2027 are the ones who will spend 2027 panicking.

6. The 5-Step DPDP framework for HR
None of this needs a legal team. It needs five decisions and someone to own them
Step 1: Know what you collect

What the law expects: your privacy notice must give an itemised description of the personal data you process. You cannot itemise what you have not mapped.
What this means in practice: one sheet, five columns. What you collect, why, where it is stored, who can see it, how long you keep it. Start with the obvious categories, then add the awkward ones:
CVs of candidates you did not hire
Documents scanned into a WhatsApp thread during onboarding
The salary sheet emailed to your auditor last March
An intern list from 2021 nobody has opened since
The key takeaway: give this an afternoon before you do anything else. For most teams the exercise itself is the eye-opener, because the honest answer to “who can see it” turns out to be “more people than we thought.”
Where a system helps: when employee records and documents live in one platform instead of five locations, the map becomes a report you pull rather than an excavation. PeopleHub holds profiles, documents, payroll and attendance in a single place, which is most of why the inventory stops being a six-week project.
Step 2: Fix your privacy notices

What the law expects: a notice that stands on its own, in plain language, itemising the data and the purposes, and telling people how to withdraw consent, exercise their rights and complain to the Board. You must also publish contact details for someone who can answer employee questions about their data, and repeat those details in every response to a rights request.
What this means in practice: a notice is not one document signed once at joining. It belongs at every point where you collect data.
Job application form
Onboarding pack
Attendance app
Expense claims
That wellness survey someone circulated last quarter
The key takeaway: new form collecting a new data point means a new notice. That rule is simple enough to hand to whoever builds your forms, and it stops the problem recurring.
Where a system helps: fewer collection points means fewer notices to write and keep current. Consolidating recruitment, onboarding, attendance and expenses into PeopleHub cuts down the number of places you are maintaining a notice for.
Step 3: Take consent only where it is needed

This is the step organisations overcomplicate, usually by asking for consent for everything.
No consent needed (legitimate use) | Consent required |
Payroll and salary processing | Photos used in marketing or social media |
Attendance and leave records | Optional wellness or engagement apps |
Statutory filings: PF, ESI, TDS | Sharing data with a third party for something unrelated to employment |
Benefits administration | Any use beyond the purpose you originally stated |
Protecting the employer from loss or liability | — |
What this means in practice: building a consent flow around payroll creates a mechanism you cannot honour, because you cannot stop paying someone who withdraws consent. Skip it.
Where you do take consent, the standard is specific. Free, informed, unambiguous, given by a clear affirmative action, limited to the stated purpose, and as easy to withdraw as it was to give. A blanket clause in the employment contract saying the employee agrees to all data processing does not meet that test.
The key takeaway: you need to show when and how each consent was taken. That means a record, not a recollection.
Where a system helps: onboarding checklists and document acknowledgements in PeopleHub leave a dated, retrievable trail, so consent is evidenced by the system instead of reconstructed from an inbox two years later.
Step 4: Restrict who can see what

What the law expects: the Rules are unusually specific here. Reasonable security safeguards include encryption or masking of personal data, controls over who can access the systems holding it, logs and monitoring good enough to detect and investigate unauthorised access, backups, and a contract with every processor requiring the same. Those logs must be kept for a year.
This is also the obligation the ₹250 crore figure attaches to, which tells you where scrutiny will land.
What this means in practice: two habits.
Give access by role. Finance sees payroll, managers see their own team, and a shared Drive folder stops being treated as an access control system.
Revoke on the last working day, not three months later when someone remembers. Your offboarding checklist should be your onboarding checklist, reversed.
The key takeaway: ask your HR software, payroll and cloud vendors this quarter whether your contract carries the security obligations the Rules require. If nobody can answer, you have found a gap.
Where a system helps: in PeopleHub, records, payroll, documents and approvals sit behind individual logins in one platform, so offboarding closes access to all of it in a single action rather than depending on someone remembering which shared folders to update.
Step 5: Decide how long you keep things

What the law expects: personal data should be erased once the purpose it was collected for has been served, unless a law requires you to keep it.
Two clarifications, because this step attracts more bad advice than any other.
The three-year erasure clock people quote from the Rules does not apply to you. It is written for large e-commerce platforms, online gaming intermediaries and social media intermediaries above specific user thresholds. As an employer, you set and defend your own retention schedule.
And “delete when done” has a floor. The Rules require personal data and the associated processing logs to be kept for at least a year, and separately require security logs retained for a year. Labour, provident fund and tax laws impose their own minimums on registers and payroll records, and those override whatever policy you write.
What this means in practice: a schedule with three columns.
Data type | What ends the purpose | Where the minimum comes from |
Rejected candidate CVs | Role is filled | Nothing requires you to keep these |
Payroll and salary records | Employment ends | Tax and PF law: confirm with your auditor |
Attendance and leave | Statutory register period passes | Labour law: confirm with your auditor |
Performance records | Employment ends, plus your own review window | Your policy |
Exit documents | Full and final settlement completed | Tax and labour law |
The key takeaway: start with row one. Old CVs sitting in a recruitment inbox from three hiring rounds ago serve no purpose and carry pure risk. Deleting them costs you nothing and takes ten minutes.
Where a system helps: structured records with joining and exit dates make retention a rule you apply consistently, rather than a judgement call someone makes each time they open a folder.
7. What this looks like in most organisations right now
Before that framework starts sounding too tidy, here is what we usually find when we look at HR data properly.
What we see | Why it is a problem | Which step fixes it |
Employee records in a personal Google Drive | No ownership, no audit trail, leaves with the person | Steps 1 and 4 |
Ex-staff accounts still active | Access continues after the employment purpose ends | Step 4 |
Salary details on personal laptops | Outside every control you think you have | Step 4 |
Same data across Drive and three sheets | You cannot delete or correct what you cannot find | Step 1 |
Records kept indefinitely | Retention with no defensible basis | Step 5 |
Data collected without telling anyone | No notice, no lawful basis on record | Steps 2 and 3 |
If you recognise more than one, you are not behind. That is the sector’s starting point.

8. Your first 30 days
None of this needs budget approval or a lawyer.
# | Action | Owner | Timeline |
1 | Build the inventory: every data item, where it lives, who can see it | HR | Week 1 |
2 | Pull the access list and close every account belonging to someone who has left | HR + IT | Week 1 to 2 |
3 | Write one proper notice, starting with the job application form or onboarding pack | HR | Week 2 to 3 |
4 | Delete the obvious: old CVs, duplicate spreadsheets, documents you cannot justify holding | HR | Week 3 to 4 |
The organisations that will struggle in May 2027 are not the ones without a policy document. They are the ones who still cannot say where their employee data is.
9. Frequently asked questions
Q: Does the DPDP Act apply to small NGOs?
Yes. It applies to any organisation processing digital personal data, with no exemption for size, turnover or registration type. A five-person foundation carries the same core obligations as a large employer.
Q: Do we need employee consent to run payroll?
No. Processing employee data for employment purposes, including payroll, attendance, statutory filings and protecting the employer from loss or liability, is recognised as a legitimate use under the Act. Consent is required for uses beyond employment, such as marketing photographs or optional wellness apps.
Q: When do we actually have to comply?
The obligations affecting HR most directly, covering notice, security safeguards, erasure and breach reporting, take effect on 13 May 2027. The Rules were published on 13 November 2025 and the Data Protection Board is already established.
Q: How long should we keep employee data?
Long enough to serve the purpose you collected it for and to satisfy any law requiring retention, and no longer. The Rules also set a floor: personal data and processing logs must be retained for at least one year. Tax and labour law minimums apply on top, so confirm those with your auditor before deleting anything.
Q: Our HR software vendor had a breach. Are we liable?
Your vendor is a Data Processor and you remain the Data Fiduciary. Accountability for how employee data is handled stays with you, which is why the Rules require your contract with any processor to include security obligations.
Q: Do we need a Data Protection Officer?
Only organisations notified as Significant Data Fiduciaries must appoint one. Every data fiduciary, however, must publish contact details for a person who can answer questions about how personal data is processed, and include those details in every response to a rights request.
Q: What do we do if there is a breach?
Tell each affected person without delay, in plain language: what happened, what it means for them, what you are doing about it, and who to contact. Inform the Data Protection Board without delay as well, followed by a detailed report within 72 hours.
10. Where to start
Check where you stand. Our DPDP Readiness Assessment for HR takes five minutes and five questions and shows which of the five areas needs attention first. Take the assessment →
Talk it through. A free 30-minute DPDP readiness consultation: what your results mean, what to prioritise, and what can honestly wait. Book a free consultation →
See it working. PeopleHub HRMS is built for nonprofits and impact organisations, bringing employee records, attendance, payroll, documents and offboarding into one system. Book a PeopleHub demo →
Comments