Industries/HR Tech and Payroll

You process employee data for dozens of companies. Each one is your liability.

HR platforms and payroll processors act as Data Processors for every employer-client on their platform. Each one needs a formal DPA. Any secondary use of that data — benchmarking, analytics, product insights — makes the platform a Fiduciary for those activities. We build the contracts, the classification, and the breach infrastructure that scales across your entire client base.

The data chain

Six entities. Employee data flowing through all of them.

HR and payroll platforms sit in the middle of an employee data ecosystem that spans the employer, statutory agencies, background check vendors, and staffing partners. DPDP accountability follows control over purpose — not the org chart.

Employee

Data Principal

Data handled

Aadhaar, PAN, bank account, salary, performance data, health and leave records

DPDP obligation

Consent or legitimate use basis required. Employment-related processing has a legitimate use basis under DPDP, but marketing, profiling, and analytics do not.

Employer (Client)

Data Fiduciary

Data handled

All employee PII passed to the HR or payroll platform

DPDP obligation

The employer owns the consent and purpose obligation for employee data. The HR platform processes on their behalf.

HR Tech Platform

Data Processor (for clients); Fiduciary (for own product analytics)

Data handled

HRMS data, payroll inputs, attendance, performance reviews

DPDP obligation

Processor contract required with every employer-client. Any secondary use for product analytics or benchmarking is a Fiduciary activity requiring separate consent.

Payroll and Compliance Vendors

Sub-Processor

Data handled

Salary structures, statutory deductions, PF and ESI records

DPDP obligation

Sub-processor disclosure required in the master DPA. Statutory retention mandates (PF, ESI, TDS) must be documented as legal bases for continued processing.

Background Verification Agencies

Data Processor

Data handled

Identity, criminal, and employment history

DPDP obligation

Processor contract required. Background check data is particularly sensitive — access must be limited, retention minimised, and purpose strictly bounded.

Staffing and Recruitment Platforms

Independent Data Fiduciary

Data handled

Candidate PII, CVs, interview assessments

DPDP obligation

Candidate consent required before data is shared with employer-clients. Data cannot be retained beyond the recruitment purpose without separate consent.

What we build

Five obligations. All of them are engineering problems.

Processor contracts for every employer-client

DeliverableMaster DPA template, client onboarding process, sub-processor disclosure register

If your platform processes employee data on behalf of employer-clients, each client relationship needs a written data processing agreement. The agreement must cover purpose limitation, security safeguards, sub-processor disclosure, breach cooperation, and data return or deletion on contract termination. We draft a master DPA template and a scalable execution process so you can cover your entire client base.

Separating processor and fiduciary activities

DeliverableProcessing activity classification, secondary use consent flows, purpose limitation controls

When your platform uses employee data for its own product analytics, salary benchmarking, or workforce insights, you are no longer acting as a processor — you are a Fiduciary for those activities. That requires independent consent from employees, separate from anything their employer has agreed to. We map every data processing activity, classify each one correctly, and build the right legal mechanism for it.

Statutory retention vs DPDP erasure

DeliverableRetention policy per data category, legal basis documentation, erasure automation

PF, ESI, TDS, and labour law records have mandatory retention periods that override DPDP erasure rights. But the same platform also holds performance data, attendance logs, and appraisal records with no statutory basis for long-term retention. We document the legal basis for every data category and automate erasure where no statutory exception applies.

Employee rights portal

DeliverableEmployee rights portal, request routing logic, 7-day SLA tracking

Employees have the right to access their data, correct inaccuracies, and raise grievances under DPDP. Even as a processor, your platform may be the technical entry point for those requests. We build a rights portal that routes requests to the correct Fiduciary, tracks SLA compliance, and maintains audit trails for every interaction.

Breach runbook covering every client

DeliverableBreach runbook, multi-client notification cascade, Board notification template

A breach of your platform's systems is a breach affecting every employer-client's employee data. Your incident response must cover Board notification, and your DPAs must specify the breach cooperation obligations of each client. We build the runbook and notification cascade so every party knows exactly what to do when it happens.

Common questions

Questions we get from HR tech platforms.

Employment data has a legitimate use basis under DPDP. Do we still need consent?

Processing necessary for employment-related purposes has a legitimate use basis under DPDP — payroll, statutory compliance, and performance management fall within this. But marketing to employees, using workforce data for product analytics, or profiling employees beyond the employment purpose does not. Consent is required for those activities regardless of the employment relationship.

We process data for 50+ employer-clients. Do we need a separate DPA for each?

Yes — each client relationship is a separate processing relationship. In practice, a well-drafted master DPA template with client-specific schedules is the scalable approach. The key is that the template must be comprehensive enough to cover purpose limitation, sub-processor disclosure, breach response, and data deletion, and each client must execute it before you process their data.

What happens to employee data when an employer-client offboards?

The DPA must specify what happens at termination: whether data is returned to the client, deleted from your systems, or both — and within what timeline. Under DPDP, continued retention after contract termination without a lawful basis is non-compliant. We implement automated offboarding pipelines that trigger data return or deletion when a client relationship ends.

We run salary benchmarking reports using aggregated workforce data. Is that a Fiduciary activity?

If the benchmarking data can be traced back to identifiable individuals — even indirectly — and you are determining the purpose of that analysis independently, yes. Aggregation is not anonymisation under DPDP. If personal data underlies the analysis, you need a lawful basis for it, and processing it beyond the employer's original instruction makes you a Fiduciary for that activity.

Background verification agencies share sensitive data about candidates. How do we manage that?

Background verification agencies are processors. They need a written DPA specifying the exact data they can access, the purpose it is used for, the retention period, and their obligation to notify you of any breach. The candidate must also have been informed — through your platform's notice — that a background check will be conducted and what data will be used.

Penalties under the DPDP Act can reach ₹250 crore per violation. This engagement covers the technical and product layer of DPDP compliance. Pair it with legal counsel for full coverage, including statutory labour law retention obligations across PF, ESI, and TDS frameworks.

Ready to build DPDP compliance into your HR platform?

Take the readiness check