HR Strategy

What India's DPDP Act means for employee performance data

Author

MeritFlo Editorial

Date Published

DPDP and employee performance data — MeritFlo article cover

India's Digital Personal Data Protection Act (DPDP) is usually discussed in terms of customer data. But performance reviews, ratings, feedback comments, probation records and development plans are all personal data of your employees — and the Act applies to them too. For HR teams, that shifts several long-standing habits from "untidy" to "non-compliant". This overview describes the areas HR teams should examine; it is not legal advice, and your obligations depend on your specific circumstances — involve your counsel.

Performance data is personal data

A review score is data about an identifiable person. So are the free-text comments a manager writes, the peer feedback in a 360, and the reasoning behind an extension of probation. Under DPDP, processing this data requires a lawful basis, and the employment relationship covers a good deal — but "we have always done it this way" is not a basis, and data collected for one purpose does not automatically become available for every other purpose.

Purpose limitation meets the spreadsheet

The habit most exposed by DPDP is the copied spreadsheet. A ratings file exported for a calibration meeting, mailed to six managers, then forwarded "for context" to a hiring discussion — each hop widens access beyond the original purpose, and nobody can say afterwards who saw what. Purpose limitation and data minimisation are difficult to even claim, let alone demonstrate, when performance data lives in files that copy freely.

What "reasonable security safeguards" look like for HR

The Act expects data fiduciaries to implement reasonable security safeguards. For performance data, the practical baseline is role-based access (a manager sees their team, not the company), encryption in transit and at rest, an audit trail of who accessed and changed what, and retention rules so records do not live forever by default. These map directly onto what a serious performance platform provides and what spreadsheets structurally cannot.

Common HR habit

The DPDP problem

The structured alternative

Ratings exported to spreadsheets and emailed

Access spreads beyond purpose; no record of who saw what

Role-based access in one system

Feedback kept in manager inboxes

Unretrievable when an employee exercises access rights

Feedback attached to the employee record

Records kept forever by default

No retention discipline

Retention rules per record type

Scores adjusted in meetings, no trail

Decisions cannot be evidenced later

Audit trail on every change

Employees will ask what you hold

DPDP gives data principals — your employees — rights to access and correction. When an employee asks what performance data you hold about them, the answer needs to be retrievable: their reviews, their scores, the feedback attached to their record. If fulfilling that request means grepping through managers' inboxes and shared drives, the process itself demonstrates the absence of safeguards.

Residency and the boards that care

DPDP's cross-border transfer rules are permissive-with-exceptions today, but sectoral rules and internal policies increasingly demand that employee data stay in-region — and GCC jurisdictions have their own, often stricter, regimes. Knowing where your performance data physically lives, and being able to choose, is becoming a procurement question. MeritFlo offers regional hosting for India and the GCC for exactly this reason.

The encouraging part: DPDP compliance for performance data is mostly a by-product of running performance management properly — structured records, controlled access, documented decisions, deliberate retention. The teams with work to do are the ones whose performance system is a folder of spreadsheets. If that is you, the compliance deadline is a good forcing function for a change that was already worth making.