Checklists4 mins

DPDP HR and Candidate Data Compliance Checklist for Enterprise SaaS

An actionable HR and candidate data compliance checklist under the DPDP Act 2023 and Rules 2025, designed for enterprise B2B SaaS vendors proving readiness to clients.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

When to use this checklist

Large enterprise SaaS providers face strict scrutiny from Indian banking and corporate clients during procurement. This checklist operationalizes compliance for your own workforce and candidate data under the Digital Personal Data Protection Act, 2023 and Rules, 2025. Use it when closing enterprise deals is stalled because your internal HR data practices cannot pass a client vendor assessment. Exactly 287 days remain until the DPDP hard compliance deadline of 13 May 2027, meaning you must secure a verifiable audit trail for candidate and employee data processing immediately.

Prerequisites for execution

Before initiating this runbook, the compliance team must lock down three assets. First, a mapped data inventory detailing all HR systems, applicant tracking systems, and payroll vendors. Second, a designated Data Protection Officer or named control owner. Third, an updated RoPA specifically isolating employee records, candidate CVs, and background check data.

Step-by-step HR data checklist

The following steps separate consent-based processing from Section 7 legitimate uses for employment purposes. Execute each to generate the evidence pack an enterprise client or auditor will demand.

1. Categorize processing bases. Action: Separate HR data into data processed for employment benefits under Section 7 legitimate uses and data requiring consent, like optional diversity surveys. Owner: Legal and HR. Evidence: Documented legal basis in the RoPA. Frequency: One-time setup with annual review.

2. Issue itemised notices to candidates. Action: Deploy an itemised notice outlining the personal data collected and the specified purpose during the application process, in accordance with the Rules, 2025. Owner: Talent Acquisition. Evidence: Timestamped notice acknowledgement logs. Frequency: Ongoing at point of collection.

3. Update employee vendor contracts. Action: Review payroll, background check, and HRIS vendors to ensure data processing agreements restrict use to specified purposes. Owner: Procurement and Legal. Evidence: Executed DPDP addendums. Frequency: One-time per vendor.

4. Enforce Data Principal duties. Action: Update employee handbooks to reference Section 15 duties, requiring employees to provide verifiably authentic information and avoid frivolous grievances. Owner: HR. Evidence: Signed handbook acknowledgements. Frequency: Annual.

DPBI breach intimation workflows

If an HR system is compromised, the DPDP Rules, 2025 mandate strict timelines. The designated control owner must submit a detailed report to the Data Protection Board of India within 72 hours of identifying the breach. Concurrently, intimation to the affected employees or candidates must occur without delay. Your incident response plan must pre-define the required fields for the DPBI form to avoid missing this window.

Effort and budget reality

For a 1000-person SaaS company, manually drafting itemised notices, securing vendor addendums, and logging candidate consent artefacts takes roughly 200 to 250 hours initially. Standing manual processes demand 15 to 20 hours monthly for reconciliation. Tooling changes this math by absorbing the manual tracking of consent artefacts and vendor attestations, reducing monthly upkeep to under 4 hours and instantly generating a regulator-ready evidence trail for enterprise clients.

HR documentation pack requirements

To pass a vendor security assessment, maintain an updated HR privacy policy, an internal incident response policy covering 72-hour board reporting, and candidate itemised notices. Your RoPA must reflect the exact data fields shared with payroll and benefits providers. Cross-border transfers of employee data are permitted unless the Central Government restricts transfer to notified countries, so map all overseas HR SaaS hosting locations.

Red flags failing vendor audits

Relying entirely on consent for all HR data processing is a red flag showing poor legal comprehension, as consent is the primary basis for processing except where Section 7 legitimate uses apply. Other failure signals include lacking timestamped logs for candidate notices and having no verifiable mechanism to handle employee data erasure requests upon termination. Do not lose an enterprise deal over fixable internal HR gaps. Run a scan at freescan.complydp.com to baseline your covered steps and remaining gaps today.

Sources

Frequently asked questions

Do we need consent for processing employee payroll data under DPDP?

Consent is the primary basis for processing except where Section 7 legitimate uses apply. Under Section 7, you can process employee data without consent for purposes related to employment, safeguarding the employer from loss, or providing employee benefits.

How much time does it take to get our HR data DPDP compliant?

For an enterprise SaaS with over 1000 staff, initial manual compliance takes 200 to 250 hours to map data, draft itemised notices, and update vendor contracts. Maintaining this manually takes 15 to 20 hours a month, though tooling drastically cuts this ongoing effort by automating consent artefacts.

What do enterprise clients look for in our DPDP vendor assessment?

Clients expect a regulator-ready evidence pack to prove you handle data safely. This includes an updated RoPA, proof of itemised notices for candidates, executed data processing addendums with your subcontractors, and a documented 72-hour breach response plan.

What happens if an applicant tracking system is breached?

Under the Rules, 2025, you must submit a detailed breach report to the Data Protection Board of India within 72 hours of noticing the breach. Concurrently, you must send an intimation to the affected candidates without delay.

Can we host Indian candidate and employee data outside India?

Yes, cross-border transfers are permitted unless the Central Government restricts transfer to notified countries or territories. You must map your HR software architecture to ensure your vendors do not host data in any negatively listed jurisdictions.