EOR and employee data privacy intersect the moment a foreign company hires anyone in India. The Digital Personal Data Protection Act, 2023 treats employee records exactly the same as customer data. There is no carve-out for HR files. Salary details, Aadhaar numbers for Provident Fund registration, medical records for insurance, even attendance biometrics, all of it counts as personal data. The employer is legally responsible for handling it correctly. When an Employer of Record sits in the middle of that relationship, working out exactly who holds that responsibility becomes a genuine question. It is worth answering before it becomes a problem.
This guide covers what the DPDP Act actually requires, and how responsibility splits between a client company and its EOR. It also covers what global employers need to check before assuming their data handling is already compliant.
The Digital Personal Data Protection Act received presidential assent in August 2023. This made it India’s first comprehensive data privacy law. For years, employee records sat outside the spotlight, treated as internal HR business rather than data requiring formal protection. The Act ends that assumption directly. An employer processing employee data is legally a Data Fiduciary. Each employee is a Data Principal with enforceable rights over their own information.
The government notified the accompanying DPDP Rules in November 2025. Implementation is rolling out in phases, rather than all at once. Certain provisions commenced immediately. Further sections take effect in November 2026. The remaining provisions, including most of the day-to-day obligations around notice, consent, and breach handling, become fully enforceable by May 2027. Employers who wait until that deadline to start preparing will likely find themselves scrambling. Building compliant processes across payroll, HR, and vendor systems takes real time.
The Act does not distinguish between customer data and employee data. The scope is broader than most HR teams initially assume. Salary and bank account details, Aadhaar numbers for statutory registrations, health and medical records for insurance enrolment, biometric attendance data, and background verification reports all fall under it. Performance reviews and disciplinary records count too. If an HRIS, payroll system, or applicant tracking tool touches it, the DPDP Act almost certainly applies.
This is the question that matters most for global employers. It does not have a single, simple answer that applies to every arrangement. The Employer of Record is the legal employer on paper. That means it directly collects and holds much of the employment documentation, contracts, payroll records, and statutory filings that trigger Data Fiduciary obligations. At the same time, the client company still directs the employee’s actual work. It often receives performance data, reporting information, and other details back from that relationship.
Third-party vendors that process personal data on an organisation’s behalf generally count as Data Processors, rather than Data Fiduciaries. This includes payroll providers, background verification agencies, insurance administrators, and cloud HR platforms. An EOR performing payroll and employment administration functions fits this description closely. The exact allocation of responsibility between the EOR and the client company, though, depends on how their service agreement actually structures it. This is not a detail to leave ambiguous. A company should clarify which party holds Data Fiduciary responsibility, and confirm the EOR’s own data handling practices meet the Act’s standards, as part of its due diligence before signing with any provider.
| Role | Under the DPDP Act | Typical Position in an EOR Arrangement |
| Data Fiduciary | Determines the purpose and means of processing personal data; carries primary legal responsibility | Often the EOR, given it holds the direct employment relationship, though this should be confirmed contractually |
| Data Processor | Processes personal data on behalf of a Data Fiduciary, under instruction | May apply to specific vendors the EOR itself uses, such as payroll software or background check providers |
| Data Principal | The individual whose personal data is being processed | The employee |
Consent is the Act’s default legal basis for processing personal data. It must be free, specific, informed, unconditional, and unambiguous. A clear affirmative action must establish it, rather than silence or a pre-checked box implying it. Employment relationships get a practical exception to this default, however. Processing that is genuinely necessary for employment purposes, running payroll, administering statutory benefits, workforce administration, recruitment records, generally qualifies as a recognised legitimate use. It does not require separate consent for each activity.
That exception has real limits. Using employee data for purposes unrelated to the employment relationship itself, marketing communications, or sharing it with third parties beyond what statutory compliance requires, falls outside the legitimate use exemption. It needs its own specific, informed consent instead. A company should not assume that payroll processing being covered means every use of employee data automatically is too.
The financial exposure under the DPDP Act is substantial enough that it deserves attention at the leadership level, not just from HR or IT. The Act authorises penalties of up to 250 crore rupees, roughly 30 million dollars, for serious violations. Fines scale according to the severity of the breach. Organisations must also notify the Data Protection Board of India and the affected individuals within a prescribed timeframe, once a breach occurs.
For a company using an EOR, this raises a practical question worth resolving upfront. If a data breach originates on the EOR’s systems, who is responsible for notification, and who bears the resulting liability? A well-structured service agreement should answer this explicitly. It should not wait until the company has to work this out after an incident has already happened.
The Act’s reach extends beyond India’s borders. It applies to processing outside India when that processing involves offering goods or services to individuals in India. It also includes specific provisions governing cross-border data transfers more broadly. For a global employer headquartered outside India, this matters directly. It applies whenever employee data, payroll records, performance reviews, or contact details move between an India-based EOR and systems the parent company maintains elsewhere.
Companies already navigating similar frameworks, UK GDPR or EU GDPR in particular, will recognise the shape of these obligations, even though the specific mechanics differ. Confirming exactly how an EOR partner handles cross-border data flow, and whether it documents appropriate safeguards, belongs in the same due diligence conversation as pricing and service scope. It should not be an afterthought a company raises once employees are already on payroll.
EOR and employee data privacy under the DPDP Act is not a box to check once and forget. The Act’s phased rollout through 2027 means obligations will keep expanding. Enforcement will only sharpen as the framework matures. Global employers hiring through an EOR should confirm in writing how they allocate Data Fiduciary responsibility, what data processing practices the EOR actually follows, and how they handle breach notification and cross-border transfer, before any employee data starts moving. For the fuller picture of how these compliance questions fit into the broader EOR decision, our guide to fifty questions on Employer of Record services in India covers the wider context, and our statutory benefits guide covers the specific employee records this data protection framework applies to most directly.
This article is for general informational purposes and does not constitute legal advice. Companies should confirm their specific compliance obligations with qualified legal counsel.