For CHROs, HR Heads and People Ops

DPDP for HR Teams in India. Employee data, POSH, and Labour, one console.

HR holds more personal data than any other function in your company — Aadhaar, PAN, bank details, health insurance, biometric attendance, performance ratings, background checks. From May 2027 every one of these is regulated. dcomply gives you consent, DSR, breach, POSH, retention and Labour Codes in a single workspace, alongside your existing HRMS.

No HRMS integration required   POSH IC ready in 24 hours   Cancel anytime

HR compliance snapshot · live
DPDP + POSH readiness
83 / 100
amber — 4 open items
POSH IC quorum
Compliant
Employee consent re-collected
94%
Biometric DPIA
Pending
BGV vendor DPA
Draft
Where HR gets exposed

Four data risks HR does not want to be caught on

Employee Aadhaar & KYC

Aadhaar copies in payroll folders, PAN in spreadsheets, bank details in email attachments. Every one is personal data under DPDP Section 2(t). PII Discovery scans your file shares and flags exposure in minutes.

Biometric attendance

Biometric is high-risk under Rule 12. You need explicit consent (Section 6, not Section 7 exemption), encryption, DPIA and purpose limitation. dcomply\'s DPIA module walks through it in 30-60 minutes.

POSH confidentiality

POSH Act Section 16 mandates complainant confidentiality. DPDP adds consent + purpose limits on top. dcomply\'s POSH module ships redacted committee reports and encrypted evidence storage by default.

Health & insurance data

Group health forms, dependent details, pre-existing conditions, insurance claims — all sensitive personal data. Consent capture, retention rules and insurer DPA are all in dcomply\'s Consent + Vendor modules.

The maths

Why HR leaders pick dcomply

May 2027
DPDP full-enforcement deadline for all HR data
10+
Employees = POSH IC mandatory. Configured in 24h.
₹250 Cr
Max penalty for HR data breach. Insured with dcomply.
22
Indian languages for consent artefacts (Rule 3)
Common questions

HR + DPDP FAQ

Does the DPDP Act apply to employee data?

Yes. Every HR record — resume, Aadhaar, PAN, bank details, health insurance forms, biometric attendance, performance ratings — is personal data under the DPDP Act 2023. HR is arguably the largest volume of personal data your company processes.

Do we still need employee consent under Section 7?

Section 7(a) provides a "legitimate use" exemption for processing that is necessary for the employment relationship, so blanket consent for payroll or PF is not required. But this covers only what is strictly necessary. Voluntary programmes (wellness apps, biometric attendance beyond time-tracking, background checks by third parties, marketing to alumni) still need explicit consent under Section 6.

What happens if an ex-employee asks for their data to be deleted?

You must respond within statutory timelines. But you can retain data required by other laws — PF records (5 years), tax records (8 years), gratuity records (3+ years), CCTV footage (varies by state). dcomply's DSR module auto-applies retention exemptions and shows the ex-employee what was kept and why.

How does POSH compliance fit into DPDP?

POSH complaint files are personal + sensitive data. Complainant identity must be kept confidential (POSH Act Sec. 16), and the DPDP Act adds consent + purpose limitation on top. dcomply's POSH module ships with DPDP-compliant complaint intake, redacted committee reports and encrypted evidence storage.

We use biometric attendance. Is that a problem?

Biometric data is high-risk under DPDP. Section 8(4) requires reasonable security safeguards and Rule 12 flags biometric processing as high-risk for DPIA. You need: explicit consent (Section 6, not Section 7 exemption), encryption at rest, purpose limitation, and a DPIA. dcomply's DPIA module walks through this in 30-60 minutes.

What about background verification vendors (BGV)?

BGV vendors (AuthBridge, IDfy, BetterPlace) are Data Processors under Section 8(2). You are the Data Fiduciary. Requirements: signed DPA, purpose limitation, consent from the candidate (Section 6), breach flow-through, sub-processor visibility. dcomply's Vendor Register templates the DPA and tracks all of the above.

Does DPDP change how we handle exit interviews or PIP records?

Yes on retention. PIP and exit-interview notes have no statutory retention period, so under DPDP purpose limitation they should be deleted once the purpose is served (usually 12-24 months post-exit). dcomply's Retention module runs the schedule automatically.

How do we handle employee grievances under DPDP Section 13?

Every Data Fiduciary must have a published grievance mechanism reachable by data principals — including your own employees. dcomply's Grievance module publishes a portal, tracks SLA, escalates to your DPO (or vDPO), and produces the Section 13 audit trail.

What about workforce in different states with different labour laws?

Labour Codes are being notified state-by-state. Your PF, ESI, gratuity, minimum wages and Shop & Establishment obligations vary by state and employee headcount. dcomply's Labour Codes module tracks the applicable regime per state per employee.

Can we use dcomply alongside our existing HRMS (Keka, greytHR, Zoho People)?

Yes. dcomply is a compliance workspace, not an HRMS. Employee data stays in your HRMS. Compliance evidence, DPDP consent, POSH complaints, retention schedules, DSR responses and audit trails live in dcomply. Native connectors are on the roadmap; today the integration is via CSV import + API sync.

What is the penalty exposure for HR data specifically?

Failure to secure HR data can trigger Schedule 1 penalties up to ₹250 crore. Failure to notify a breach involving employee data triggers up to ₹200 crore. Given typical HR data volumes (thousands of Aadhaar + payroll records), exposure is real. dcomply's Financial Risk module quantifies your specific exposure.

How fast can we go live?

Most HR-focused deployments are operational within 5-7 working days: policy generation (Day 1), employee-consent re-collection sweep (Days 2-3), POSH IC verification (Day 3), DSR portal published (Day 4), DPO/grievance officer contact published (Day 5). Full audit-defensibility within 30 days.

Start with POSH + Consent. Ship in 5 days.

Free tenant. Set up POSH IC and re-collect employee consent for HRMS data. See what audit-defensibility looks like before May 2027.