Strategy

Employee Data is the Universal DPDP Wedge

Jan 28, 20265 min read

Every company has employees. That makes every company subject to DPDP. Here is why employee data is the right place to start.

Every company has employees. That single fact makes every company in India — regardless of sector, product, or revenue — a data fiduciary under DPDP. For most startups, the fastest, lowest-risk path to demonstrable compliance starts not with customer data, but with the data held about their own people.

Why employee data is different

Under DPDP, processing employee personal data for employment purposes falls under 'legitimate use' — one of the permitted bases for processing without explicit consent. You do not need to obtain consent from an employee to process their Aadhaar for PF registration, their PAN for salary TDS, or their bank account for payroll. The employment relationship itself provides the legal basis.

This simplifies compliance significantly. Instead of designing and managing a consent infrastructure for employee data (which would be operationally complex and likely inappropriate for an employment relationship), you need to: identify what data you hold, document the legitimate use basis, minimise data to what is necessary, and ensure it is adequately protected.

What personal data the average Indian startup holds on its employees

  • Identity documents: Aadhaar number, PAN card, passport (for visa processing), driving licence. All classified as sensitive personal data under DPDP — highest protection obligations.
  • Financial data: Bank account details, salary structure, Form 16, TDS certificates. Often stored in payroll systems, spreadsheets, and accounting software — frequently without adequate access controls.
  • Biometric data: Fingerprint or face data from attendance systems. Classified as sensitive. Many SMBs have deployed biometric attendance terminals without realising this triggers specific DPDP obligations.
  • Health and insurance data: Medical insurance policy details, dependents, pre-existing conditions submitted during onboarding. Sensitive personal data requiring higher protection standards.
  • Contact and location data: Personal mobile numbers, home addresses, emergency contacts. Frequently shared via WhatsApp groups — a significant compliance risk.
  • Performance and disciplinary records: Appraisal data, PIPs, termination records. Subject to data principal rights — employees can request access to this data.

The hidden exposure in the Indian SMB stack

Most Indian startups and SMBs have their employee data distributed across systems that were not designed with DPDP in mind. The typical configuration: HRMS (Keka, Zoho People, or Darwinbox) holding the authoritative records; Google Workspace or Microsoft 365 with employee files, contracts, and appraisal documents; WhatsApp groups used for payroll confirmations and salary slips; Excel sheets on employee laptops containing Aadhaar and PAN numbers; and payroll software with bank account details.

Each of these is a data source. Each carries DPDP obligations. The Excel sheet on a departing employee's laptop is a breach waiting to happen.

DPDP Rule 5 requires data minimisation: personal data must be limited to what is necessary for the specified purpose. Retaining an employee's Aadhaar copy on a shared Google Drive folder two years after they left is a violation. Retention schedules are not optional.

The compliance path for employee data

  1. 1Connect your HRMS to a data posture tool and map what fields are collected, stored, and who has access.
  2. 2Audit your Google Workspace and file storage for employee documents — contracts, offer letters, Aadhaar/PAN copies.
  3. 3Document your legitimate use basis for each processing activity. Employment → payroll processing. Legal obligation → PF, ESIC, TDS filings.
  4. 4Set and enforce retention schedules. Departed employee data should not persist indefinitely.
  5. 5Review access controls. Who in your org can access employee Aadhaar numbers? Should they all be able to?
  6. 6Eliminate informal channels (WhatsApp, personal email) for sharing sensitive employee documents.

Why starting here matters strategically

Employee data is the universal DPDP entry point because every company has it, the legal basis is clear (no consent architecture needed), the data is finite and well-defined, and demonstrating control over employee data builds the organisational muscle for handling customer data later.

Companies that start with customer data often underestimate the complexity of managing consent across millions of data principals. Starting with employee data — a bounded, well-understood dataset — lets you build the systems, processes, and evidence practices that will then scale to customer data.

Takeaway

DPDP compliance does not require you to solve every problem at once. It requires you to start somewhere defensible. Employee data is that place — legally clear, operationally bounded, and universally applicable. Get that right, and the practices you build will extend naturally to customer data, vendor data, and beyond.