[Company Logo][Company Name]
- Policy No.:
- [Reference Number]
- Version:
- [Version Number]
- Effective Date:
- [Date]
- Policy Owner:
- [Privacy Officer / HR Head]
1. Purpose
[Company Name] respects the privacy of its employees, candidates and others whose personal data it handles. This policy explains how such data is processed lawfully, fairly and securely, in line with the Digital Personal Data Protection Act, 2023 and other applicable laws.
2. Scope
It applies to personal data of current and former employees, candidates, interns, contractors, nominees and dependants, processed by the company or by vendors on its behalf.
3. Definitions
- Personal data: any data about an individual who is identifiable by or in relation to it.
- Data principal: the individual to whom the data relates.
- Data processor: a vendor that processes personal data on the company's behalf.
- Personal data breach: unauthorised processing, loss or disclosure of personal data.
4. Policy
- Personal data is collected only for specified purposes: recruitment, employment administration, payroll and benefits, statutory compliance (PF, ESI, tax), safety, and performance management.
- Individuals receive a clear notice at the time of collection describing the data, purpose and how to contact us.
- Only necessary data is collected. Aadhaar is collected as a masked copy (last 4 digits) unless a law requires the full number.
- Health and other sensitive information is accessed only by authorised HR staff.
- Data is shared with processors only under written agreements requiring security and confidentiality.
- Data is kept as per the retention table below and then deleted or anonymised.
- Individuals may request access, correction or erasure, or raise a grievance, by writing to [Privacy Email]; requests are answered within [Number] days.
- Personal data breaches are handled under the Information Security Policy and notified to the Data Protection Board and affected individuals as required.
| Data Category | Purpose | Retention |
|---|
| Candidate CVs (not hired) | Recruitment | [Number] months |
| Employee master and payroll records | Employment, statutory compliance | [Number] years after exit |
| Medical certificates | Leave, insurance | [Number] years |
| CCTV footage | Security | [Number] days |
5. Procedure
- HR maintains a register of HR data processing activities.
- New tools or vendors handling personal data are reviewed by the Privacy Officer before use.
- Retention reviews are carried out every [Number] months.
6. Responsibilities
- Privacy Officer: oversee compliance and requests.
- HR and managers: handle personal data only for stated purposes.
- IT: security controls.
- Employees: keep their data updated and protect others' data.
7. Non-compliance
Unauthorised access to or disclosure of personal data is serious misconduct and will be dealt with under the Disciplinary Policy.
8. Review & Approval
This policy will be reviewed annually and whenever rules under the DPDP Act are notified or amended.
Approved by
[Authorised Signatory][Designation]Date:
[Date]Acknowledged by
[Employee Name]Date:
[Date]