All insights
ChecklistDPDP Compliance

HR vendor privacy checklist under the DPDP Act

A practical checklist for reviewing payroll, recruitment, benefits and HR technology vendors before employee personal data is shared.

Data>Nuance

HR vendor files are where privacy notices often go looking for a payslip and find a maze.

What to review

HR vendors routinely touch salary records, identity documents, attendance data, benefits information, background verification material and grievance records. Under the DPDP Act, the employer usually remains the Data Fiduciary when it decides why and how employee personal data is processed, while the payroll platform, recruitment system, benefits administrator or background check provider may act as a Data Processor.

Start with a simple data map. Record which HR process uses the vendor, what personal data is shared, whether sensitive workplace context is included, where the system is hosted, who can access exports, and when data should be deleted. The review should also test whether the vendor contract supports lawful purpose, notice alignment, security safeguards, breach cooperation and erasure instructions.

This is not just a legal-paper exercise. HR tools tend to accumulate old applicants, former employees, duplicate profiles and unstructured documents. A useful checklist therefore joins contract review with operational evidence: access lists, retention settings, export logs, support-ticket practices and incident escalation contacts.

Give extra attention to vendors that sit between HR and finance, or between HR and external candidates. They often receive data from several systems and then send reports back to managers, recruiters, payroll teams and auditors. That movement creates practical control questions: who can download bulk reports, whether masked views are available, how implementation consultants are removed after go-live, and whether support teams can see attachments. A privacy review that ignores these everyday paths may look complete while the actual risk remains untouched.

Implementation steps

  1. Classify each HR vendor as processor, independent fiduciary or mixed-role provider. Payroll, attendance and HRIS vendors are commonly processor-like; insurers, statutory platforms and background verification networks may need closer role analysis.
  2. Match every data field shared with a defined HR purpose. Remove optional fields that the vendor asks for by habit rather than necessity.
  3. Check whether the employee or applicant notice describes the vendor category, processing purpose, grievance route and relevant rights in clear language.
  4. Put processor instructions in the contract: process only on documented instructions, restrict sub-processors, maintain safeguards, support breach assessment, return or delete data, and help with correction and erasure requests.
  5. Review admin access. HR, finance, vendor support and implementation partners should have role-based access, named accounts, multi-factor authentication and periodic access recertification.
  6. Test retention controls. Applicant data, resigned employee records and payroll archives should have business, statutory or dispute-retention reasons, not indefinite default storage.
  7. Ask for breach procedures that name the notification contact, evidence to be preserved, decision timeline and support expected from the vendor.
  8. Keep review evidence in one place: contract extract, security summary, data map, retention decision, risk owner and next review date.

For higher-risk HR vendors, add a short control test before approval. Ask the business owner to show how a new joiner is created, how a former employee is disabled, how an exported payroll file is protected, and how an old applicant record is deleted or anonymised. The answers usually reveal whether the contract language has become a working process. If the vendor cannot demonstrate a control, record the gap with an owner and target date rather than approving the risk in vague terms.

Common mistakes

  • Treating every HR vendor as low risk because the relationship feels administrative.
  • Accepting a generic data processing clause without deletion, breach support or sub-processor controls.
  • Reviewing the contract once but never checking access logs, exports and inactive employee data.

How DataNuance can help

DataNuance helps Indian HR, legal and privacy teams convert vendor reviews into usable DPDP evidence. We can map HR data flows, review processor clauses, build a vendor checklist, and prepare a practical remediation tracker before audits or procurement renewals. For support with HR vendor privacy controls, contact DataNuance at our privacy advisory team.

FAQs

Is every HR vendor a Data Processor under the DPDP Act?

No. Many HR vendors process personal data on the employer's instructions, but some providers decide parts of the processing themselves. Classify the role by looking at who determines purpose, data fields, retention and onward sharing.

What should an HR vendor contract include?

It should include documented processing instructions, confidentiality, access controls, security safeguards, sub-processor restrictions, breach assistance, deletion or return duties, audit support and cooperation for rights requests.

Should applicant data be included in the checklist?

Yes. Recruitment platforms often hold resumes, interview notes, assessments and identity documents. Applicant data needs purpose limits, access controls and retention rules just like employee records.

How often should HR vendors be reviewed?

Review high-risk or high-volume HR vendors at onboarding, renewal and after major changes in data fields, hosting, sub-processors, security incidents or employment processes.

This publication is general information and is not legal advice for a specific organisation or matter.

Continue reading

Processors and vendors

Data processing clauses for Indian customer contracts

A practical checklist for Indian businesses adding DPDP-ready data processing clauses to customer contracts and order forms.

Read insight

Processors and vendors

Vendor due diligence before sharing personal data

A practical due-diligence model for Indian teams before personal data is shared with vendors, SaaS tools or processors.

Read insight

Start with context

Book a focused DPDP Act consultation.

Bring an upcoming launch, notice review, data mapping question, incident readiness issue or implementation deadline. We will help identify the right next step.