Article

Key insights from the webinar “DPDP Act 2023: What HR Professionals Need to Know”
Webinar held on 26 September 2026 | Presented by Sushobhan Mukherjee | Prime Infoserv Pvt. Ltd.
Human Resources sits at the centre of an organisation’s personal-data ecosystem. It receives candidate profiles before employment begins, creates identity and payroll records when a person joins, accumulates attendance and performance information throughout employment, and retains selected records after exit.
The webinar’s central message was direct: DPDP compliance cannot be delegated only to legal, information technology or cybersecurity teams. HR must become an active custodian of purpose, access, retention, vendor governance and incident response.
The session, conducted jointly with HR Gurucul, brought the Digital Personal Data Protection Act, 2023 into everyday HR language. Instead of treating privacy as a section-by-section legal exercise, the discussion followed the employee-data journey and examined the practical decisions HR teams make every day. This article captures the key lessons and converts them into an implementation agenda for HR leaders.
Watch the webinar recording
Watch the complete webinar on YouTube:
Watch the webinar directly on YouTube
Why the DPDP Act matters so deeply to HR
The Act applies to digital personal data collected in digital form and to information first collected on paper and later digitised. That scope immediately brings a large part of modern HR operations into focus: emails, scanned identity documents, recruitment portals, spreadsheets, HRMS records, payroll systems, biometric attendance, medical-benefit records, performance platforms, visitor systems and cloud-based collaboration tools.
An employee may appear to be one person, but the organisation sees a long and expanding data trail. A candidate’s CV may move from a recruitment mailbox to an interviewer, a background-verification agency and an HRMS. Bank details may travel to payroll partners. Family details may reach insurance providers. Performance information may sit in appraisal systems, manager emails and spreadsheets. Exit records may remain with HR, finance, IT and former vendors.
The risk is rarely located in one database; it lies in the movement, duplication and continued retention of data across the ecosystem.
The organisation normally acts as the Data Fiduciary because it determines why and how personal data is processed. Employees, candidates and other individuals are Data Principals. HRMS providers, payroll processors, recruitment agencies and background-verification partners may act as Data Processors when they process information on the organisation’s behalf. These roles matter because outsourcing a process does not outsource accountability.
The employee data lifecycle is the real compliance map
A critical transition occurs when a candidate becomes an employee. Candidate information should not automatically become a permanent employee file. The same principle applies when an employee becomes a former employee: not every record must remain accessible indefinitely. Privacy controls must move with the individual as the purpose, access requirement and retention justification change.
| Lifecycle stage | Typical personal data | Primary HR control question |
|---|---|---|
| Recruitment | CVs, contact details, qualifications, salary history, interview notes and background checks | Have we explained the purpose, recipients and retention period to the candidate? |
| Joining | Identity, address, bank, tax, statutory, emergency-contact and benefit information | Are we collecting only what is necessary for employment and applicable obligations? |
| Employment | Attendance, biometrics, access records, performance, learning, health and benefit information | Is access role-based, and is every use connected to a stated and lawful purpose? |
| Exit | Settlement, access revocation, asset return, references, claims and disciplinary records | Which records must be retained, which should be restricted, and what triggers deletion? |
| Post-employment | Legally required records, disputes, references and archived employment history | Can we demonstrate the legal or documented business reason for continued retention? |
Consent is important, but it is not the answer to everything
One of the most common misconceptions is that HR must collect consent for every activity involving employee data. The DPDP Act also recognises certain legitimate uses, including processing for employment purposes and for safeguarding an employer from loss or liability in the circumstances described by the Act. Organisations may also process information to meet obligations under other applicable laws.
That does not make consent irrelevant. Optional activities such as publishing employee testimonials, using photographs for external promotion or enrolling people in voluntary programmes may require a properly designed consent process. Where consent is relied upon, it must be free, specific, informed, unconditional and unambiguous, and withdrawing it should be as easy as giving it.
The practical lesson for HR is to stop collecting consent mechanically. Each processing activity should be mapped to a clear purpose and an appropriate legal basis. A notice should explain what information is collected, why it is needed, how it will be used, who may receive it and how the individual can exercise applicable rights.
Purpose limitation changes familiar HR practices
A system may technically allow an organisation to use information in several ways, but that does not mean every use is appropriate. If CCTV is introduced for physical security, subsequently using the footage as a general performance-monitoring tool may create a mismatch between the stated purpose and the actual use. Similar concerns arise with location tracking, productivity software, biometric attendance and behavioural analytics.
Before introducing or changing an HR process, teams should ask five questions:
- Why are we collecting this information?
- Which specific fields are genuinely necessary?
- Who needs access, and through which approved systems?
- How long should the information remain, and what law or purpose supports that period?
- What event will trigger restriction, anonymisation or secure deletion?
If these questions do not produce clear answers, the process is not ready to proceed. A policy alone will not close the gap; each obligation needs an owner, a workflow, a time expectation and evidence that the activity was completed.
Recruitment and background verification need tighter discipline
Recruitment creates personal-data risk before an individual becomes an employee. Red flags include asking for excessive documents too early, conducting informal reference checks, retaining unsuccessful candidate profiles indefinitely, maintaining open spreadsheets and sharing CVs casually with agencies or interview panels.
A mature recruitment process tells candidates how their information will be used and who may receive it. It limits collection to the relevant stage, controls access, records transfers to vendors and establishes a retention period for unsuccessful applications. Background-verification partners should receive only the fields necessary for the authorised check, under a valid contract and with clear deletion expectations.
Retention is a decision process, not a single number
A former employee’s deletion request should not result in either immediate deletion of everything or permanent retention of everything. HR must assess the records by category. Some information may need to remain because of statutory, tax, employment, claims or dispute-related obligations. Other records may have no continuing purpose and should be deleted.
Where continued retention is justified, access should be restricted and the information should be archived rather than left in everyday working folders.
A defensible retention programme connects each record category to its purpose, legal requirement, owner, location and deletion trigger. It must also reach copies held by processors and former service providers. Deleting a record from the HRMS while leaving it in email, shared drives or a vendor portal does not complete the lifecycle.
Vendors extend the HR risk boundary
HR depends on a wide vendor network: HRMS and payroll providers, recruiters, background-verification agencies, insurers, wellness providers, attendance platforms, learning systems and collaboration tools. Before sharing employee data, HR should participate in vendor due diligence and understand the provider’s security, hosting, subprocessors, incident-response capability and deletion practices.
Contracts should define the approved purpose, data fields, recipients and permitted use. They should require reasonable safeguards, prompt incident support, limits on secondary use and AI training, audit or assurance rights where appropriate, and return or deletion of information at the end of the relationship. Vendor trust should be supported by evidence, not assumption.
A data breach is not only an IT event
If a recruiter accidentally sends a candidate database to the wrong external recipient, recalling the email or requesting deletion is not enough. The organisation should activate its incident-response process, preserve evidence, identify the affected records and recipients, contain further exposure, assess notification obligations and document the response.
HR understands the individuals, purpose and sensitivity of the information. IT can trace systems and contain exposure. Legal and compliance teams assess regulatory and contractual obligations. Leadership manages broader organisational impact. Effective response depends on these functions working from one defined playbook rather than treating the incident as an individual’s mistake to be hidden.
The most practical audience question was about email
During the Q&A, a participant asked how organisations can protect personal data collected and exchanged through Outlook when authorised users can see it. The answer is not to stop using email. It is to treat email as one endpoint in the organisation’s data flow and apply layered controls.
Organisations first need visibility: which personal data enters email, where it moves, who can access it and where copies are stored. Technical measures may include access controls, data-loss prevention, encryption, secure sharing, email security, endpoint protection, monitoring and backup governance.
Equally important is behaviour. Convenience-driven sharing through personal email, open links or messaging applications can bypass formal controls. Technology and working habits must therefore change together.
AI creates a new and immediate HR exposure
Generative AI makes it easy to summarise appraisals, compare candidate profiles or rewrite manager comments. The convenience can conceal a serious risk: names, ratings, performance concerns, medical information or interview notes may be uploaded into an unapproved service with unknown retention, training or cross-border processing arrangements.
HR should use only approved AI tools and approved use cases. Personal data should be minimised and, where feasible, de-identified before use. Organisations need clarity on whether prompts and outputs are retained, whether data is used for model training, who can access results and how human review will prevent automated summaries from creating unfair or inaccurate employment decisions.
A practical 90-day roadmap for HR leaders
| Period | Focus | Priority actions |
|---|---|---|
| Days 1–30 | Discover | Map HR processes, systems, spreadsheets, mailboxes and vendors. Identify personal-data categories, purposes, owners, recipients and current retention practices. |
| Days 31–60 | Design | Correct collection forms and notices. Define role-based access, retention schedules, candidate-data handling, vendor requirements, rights workflows and incident escalation. |
| Days 61–90 | Test and improve | Run sample rights and deletion requests, test a breach scenario, review AI use cases, validate vendor evidence, train HR users and establish a readiness scorecard. |
The shift HR must now make
DPDP readiness is not achieved by publishing one privacy policy or buying one tool. It requires HR to know where personal data resides, question why it is being collected, control who receives it, challenge indefinite retention, govern vendors, respond quickly when something goes wrong and maintain evidence of every important decision.
The webinar ended with five disciplines worth carrying into every HR process: know the data, question the purpose, control the ecosystem, respond with discipline and keep evidence. These are not abstract legal ideas. They are operational habits that protect employees, candidates and the organisation itself.
For HR leaders, the starting point is not a perfect enterprise-wide programme. It is one process examined honestly. Map recruitment, payroll, background verification, employee benefits, performance management or exit. Identify where personal data enters, where it travels, who can see it and when it should leave. That first map will often reveal more than a policy review ever could.
Continue the DPDP readiness journey
Explore practical DPDP learning resources, a self-assessment and implementation support at www.dpdpconsulting.com.
Organisations seeking support can use the platform to begin a structured discussion around data discovery, notices and consent, employee-data governance, vendor risk, rights handling, breach readiness and privacy technology.
Official references
- Digital Personal Data Protection Act, 2023
- Digital Personal Data Protection Rules, 2025
Disclaimer: This article is intended for awareness and general information. It is not legal advice. Organisations should evaluate their obligations in the context of applicable law, notifications, rules, employment requirements and their own processing activities.
About the author
Sushobhan Mukherjee is the CEO of Prime Infoserv Pvt. Ltd. and Chairman of the InfoSec Foundation. He works with organisations on cybersecurity, privacy, DPDP readiness, governance and resilience, helping leadership teams translate regulatory expectations into practical operating controls.
About Prime Infoserv
Prime Infoserv Pvt. Ltd. supports organisations across cybersecurity, privacy, risk and compliance. Its DPDP services include readiness assessment, data discovery and flow mapping, notices and consent, rights-request workflows, retention governance, vendor risk, breach preparedness, awareness and privacy technology enablement.
Connect:
www.primeinfoserv.comwww.dpdpconsulting.com
smukherjee@primeinfoserv.com
+91 98300 17040
- Data Privacy
- cybersecurity
- DPDP Act 2023
- AI Governance
- HR Compliance
- Employee Data
- HR Data Governance
- Vendor Risk

