You are a Data Fiduciary for your own staff and candidates, and usually a Data Processor for the client data your teams work on. Data of people outside India, handled under a contract with a foreign client, is mostly outside the Act, but security and responsibility for sub-contractors still apply.
The first four things to sort out
Candidate retention period.
Background check vendor terms.
Staff notice.
Salary data access.
A worked example: Background check reports in shared mail
Day 1Reports are found in a shared mailbox.
Week 1Moved to the HRMS with limited access.
Week 2Mailbox cleaned.
AfterVendor uploads to the portal.
Evidence kept: Move record; Cleanup.
Sensitive reports belong in a restricted system.
What others in the sector usually do. Expiry dates on candidate records are becoming common.
Short answer: For the hiring purpose, then delete unless the candidate agrees
Only as long as you need it for the hiring purpose. If you want to keep CVs for future roles, ask the candidate. Background check reports are sensitive and should have a short retention and limited access.
From your seat: HR department. Set the ATS retention this month.
Short answer: Not for employment purposes; yes for anything extra
Usually not for normal employment purposes. Section 7(i) lets you process employee data for employment, such as payroll, attendance, safety and preventing corporate espionage. Anything beyond that, such as wellness apps, photos for marketing or sharing with a bank for offers, needs consent.
From your seat: HR department. Prepare the employee privacy notice and give it to every joiner.
In IT and ITeS
Large hiring volumes mean large records. Set retention by record type.
Their data is your responsibility when you decide why and how it is used, for example gate passes, attendance, biometrics and safety records. The agency holds payroll and personal files, so your contract with the agency must cover how it protects that data.
From your seat: HR department. Agree with Admin and agencies who holds which worker records.
In IT and ITeS
Contractors and consultants placed through agencies need the same access rules as staff.
What the law says
Section 7(i) covers employment purposes. Section 8(1) and 8(2) make you responsible for processors such as manpower agencies working on your behalf. Section 7 · Section 8(1)–(2) · Section 8(5) · Rule 6
Steps
List what you hold about contract workers: ID copies, photos, biometrics, attendance, medical fitness.
Decide who is the Data Fiduciary for each item: you or the agency.
Put data terms in every manpower contract.
Give a short notice in the workers' language at the gate or induction.
Short answer: For the legal or business period, then erase
Keep data for as long as its purpose needs, or as long as a law requires, and then erase it. Every organisation must keep personal data and logs for at least one year under Rule 8(3). Write a retention schedule by record type, with the law or reason against each period.
From your seat: HR department. Set periods for candidate, employee and ex-employee records.
In IT and ITeS
Candidates, employees, alumni, and client data at project end.
What the law says
Section 8(7) asks for erasure when the purpose is over, unless a law requires retention. Rule 8(3) sets a one-year minimum for personal data, traffic data and logs. Section 8(7) · Rule 8 · Section 8(5) · Rule 6
Steps
List the record types you hold.
Write the period for each, with the law, regulator rule or business reason.
Set a trigger for the period to start: end of relationship, date of transaction, exit date.
Automate deletion where you can; for paper, schedule shredding.
Keep a deletion log.
Evidence to keep
Retention schedule approved by Legal
Deletion log
Shredding or disposal certificates
Common mistakes
'Keep everything forever' because storage is cheap
Short answer: Everyone who handles personal data, by role
Everyone who handles personal data needs short, practical training on what to do in their own job. Front-line staff need examples from their counter or desk. Managers need to know the clocks and their own duties. Management needs to know what to ask.
From your seat: HR department. Put DPDP into induction and the yearly refresher.
In IT and ITeS
Delivery teams need training on client access and data handling.
What the law says
Section 8(4) and 8(5) ask for appropriate technical and organisational measures. Training is part of showing those measures work. Section 8(5) · Rule 6
Steps
Group staff by what they handle: front line, back office, IT, managers, management.
Write three to five real scenarios for each group.
Short answer: Yes, with notice, limits and a deletion period
All three are personal data. Put a clear notice where people are recorded, collect only what you need at reception, keep footage and registers for a set period, and protect biometric templates carefully. Do not keep copies of ID documents unless you must.
From your seat: HR department. Biometric attendance data needs limited access and a deletion date after exit.
Short answer: Yes, a clear summary, inside the published timeline
Send a summary of the personal data you hold about them and what you do with it, and the names of the other organisations you shared it with and what was shared. Check the person's identity first, log the request and keep a copy of your reply.
From your seat: HR department. Staff can ask what HR holds about them. Have the summary process ready.
In IT and ITeS
Requests about client data go to the client. Requests from staff and candidates come to you.
What the law says
Section 11 gives the right to a summary and the list of organisations it was shared with. Rule 14 asks you to publish how requests are made and to answer within the period you publish. Sections 11–14 · Rule 14 · Section 8(9)–(10) · Rules 9, 14
Steps
Log the request in one register the day it arrives.
Verify identity using details you already hold.
Search every system, including vendors' copies.
Write a plain summary: what data, why it is used, who received it.
Send it, and file the request, search notes and reply.
Section 7: Uses allowed without consent. Payroll, access control, background checks and security monitoring of staff are employment purposes.
Section 5 · Rule 3: Notice. Candidate portals, employee onboarding and your own website forms need notices. For client data, the client normally gives the notice.
Report specified cyber incidents within six hours. Keep ICT logs for 180 days within India. Sync clocks to NIC or NPL time servers. Data centres, VPS, cloud and VPN providers keep specified subscriber information for five years.
Breach handling must meet the six-hour CERT-In clock and the DPDP report to the Board. Subscriber records need DPDP-level protection.