India’s DPDP Rules and GCC Employment Data: Why HR Compliance Needs a Privacy Reset | nasscom

WorkAI.TV Editorial Desk
4 Min Read

Share with your CHRO

India’s Digital Personal Data Protection Act and the DPDP Rules 2025 now classify employee data as regulated personal data, not internal HR records, forcing Global Capability Centres to rethink how employment information flows through recruitment platforms, payroll vendors, performance tools, and overseas parent companies. The nasscom community post, written from a compliance advisory posture that naturally tilts toward structural caution, maps twelve distinct HR data categories and argues that purpose-by-purpose classification beats blanket consent clauses buried in offer letters.

What this means for your business

GCCs sit in a structurally exposed position that most domestic Indian employers don’t share. They report to an overseas parent, run global HR platforms, and routinely push Indian employee data, performance reviews, compensation benchmarks, investigation records, to group entities abroad. That cross-border flow is where the DPDP framework bites hardest, because each transfer now needs documented purpose, identified recipient, and defined retention, not just a shared-services agreement that predates the regulation. If your GCC headcount in India exceeds a few hundred, this is almost certainly already happening informally.

The consent-as-compliance instinct is the failure mode to watch. The power imbalance between employer and employee means that a broad privacy clause signed at onboarding will attract regulatory and legal scrutiny the moment it covers something vague or non-essential. The practical reframe is to separate mandatory processing, payroll, tax filings, statutory benefits, from discretionary processing, AI productivity scoring, wellness analytics, biometric attendance, and treat each bucket differently. That distinction isn’t just legal hygiene; it determines which HR technology you can deploy without rebuilding your notice-and-consent architecture from scratch.

The vendor layer is where most GCCs will discover their actual exposure. Payroll processors, background verification agencies, HRMS providers, and investigation support firms all touch employee data, and most vendor contracts written before 2024 don’t include deletion obligations, breach notification timelines, or purpose-limitation clauses that the DPDP framework now effectively requires. A CHRO who reviews those contracts before a regulator or an employee rights complaint does will have significantly more room to negotiate remedies quietly. I’d revise this view if the government’s enforcement guidance carves out group-company transfers as a low-priority category, but nothing in the draft rules suggests that’s coming.

Concept deep-dive: Purpose limitation

Purpose limitation means data collected for one reason, say, calculating payroll, can’t legally be used for a different reason, say, building an attrition risk model, without separate notice and a fresh legal basis. Think of it as a contractual lane marker on a highway: the data can travel fast, but only in the lane it entered. For GCCs deploying people analytics or AI-driven workforce tools, this is the constraint that decides which datasets you’re actually allowed to feed into those models.

Based on reporting from India’s DPDP Rules and GCC Employment Data: Why HR Compliance Needs a Privacy Reset | nasscom, originally published 2026-07-31 06:43:00.

TAGGED:
Share This Article