What India's DPDP Act means for employee performance data
Author
MeritFlo Editorial
Date Published

India's Digital Personal Data Protection Act (DPDP) is usually discussed in terms of customer data. But performance reviews, ratings, feedback comments, probation records and development plans are all personal data of your employees — and the Act applies to them too. For HR teams, that shifts several long-standing habits from "untidy" to "non-compliant". This overview describes the areas HR teams should examine; it is not legal advice, and your obligations depend on your specific circumstances — involve your counsel.
Performance data is personal data
A review score is data about an identifiable person. So are the free-text comments a manager writes, the peer feedback in a 360, and the reasoning behind an extension of probation. Under DPDP, processing this data requires a lawful basis, and the employment relationship covers a good deal — but "we have always done it this way" is not a basis, and data collected for one purpose does not automatically become available for every other purpose.
Purpose limitation meets the spreadsheet
The habit most exposed by DPDP is the copied spreadsheet. A ratings file exported for a calibration meeting, mailed to six managers, then forwarded "for context" to a hiring discussion — each hop widens access beyond the original purpose, and nobody can say afterwards who saw what. Purpose limitation and data minimisation are difficult to even claim, let alone demonstrate, when performance data lives in files that copy freely.
What "reasonable security safeguards" look like for HR
The Act expects data fiduciaries to implement reasonable security safeguards. For performance data, the practical baseline is role-based access (a manager sees their team, not the company), encryption in transit and at rest, an audit trail of who accessed and changed what, and retention rules so records do not live forever by default. These map directly onto what a serious performance platform provides and what spreadsheets structurally cannot.
Common HR habit | The DPDP problem | The structured alternative |
|---|---|---|
Ratings exported to spreadsheets and emailed | Access spreads beyond purpose; no record of who saw what | Role-based access in one system |
Feedback kept in manager inboxes | Unretrievable when an employee exercises access rights | Feedback attached to the employee record |
Records kept forever by default | No retention discipline | Retention rules per record type |
Scores adjusted in meetings, no trail | Decisions cannot be evidenced later | Audit trail on every change |
Employees will ask what you hold
DPDP gives data principals — your employees — rights to access and correction. When an employee asks what performance data you hold about them, the answer needs to be retrievable: their reviews, their scores, the feedback attached to their record. If fulfilling that request means grepping through managers' inboxes and shared drives, the process itself demonstrates the absence of safeguards.
Residency and the boards that care
DPDP's cross-border transfer rules are permissive-with-exceptions today, but sectoral rules and internal policies increasingly demand that employee data stay in-region — and GCC jurisdictions have their own, often stricter, regimes. Knowing where your performance data physically lives, and being able to choose, is becoming a procurement question. MeritFlo offers regional hosting for India and the GCC for exactly this reason.
The encouraging part: DPDP compliance for performance data is mostly a by-product of running performance management properly — structured records, controlled access, documented decisions, deliberate retention. The teams with work to do are the ones whose performance system is a folder of spreadsheets. If that is you, the compliance deadline is a good forcing function for a change that was already worth making.