Employee data privacy policy template
Copy the text below and replace everything in square brackets with your company details.
1. Purpose
This policy explains how [Company Name] collects, uses, stores, shares and deletes the personal data of its employees, and the choices and rights employees have over that data.
2. Scope
It covers current and former employees, job applicants, trainees and interns, and the family members and nominees whose details we hold. It applies to data in HR and payroll systems, email, spreadsheets and paper files at every location.
3. Data we collect
- Identity and contact: name, photograph, date of birth, address, phone, email and emergency contact.
- Statutory identifiers: PAN, Aadhaar in masked form where possible, UAN, ESI number and passport details where needed.
- Employment: offer and appointment letters, designation, grade, reporting line, goals and ratings, and disciplinary records.
- Pay and bank: salary structure, payslips, bank account, tax declarations, and PF and ESI contributions.
- Attendance: punch times, the source of each punch, and the location at the moment of a punch where location checks are switched on.
- Family and nominees: details needed for nominations, insurance and benefits.
- Health: medical certificates for sick leave, fitness certificates, and disability information shared for an accommodation.
4. Policy
- We collect only the data needed for employment, pay, statutory compliance, safety and security, and use it only for the purposes stated when it was collected.
- Access is limited by role. Salary, bank and health data are restricted further, to named HR, payroll and finance staff.
- We do not sell employee data. We share it only with service providers bound by confidentiality, such as our bank, insurer, auditors and background verification agency, and with authorities where the law requires.
- Data is kept only as long as needed for its purpose and for legal retention periods, as set out in the Document Retention Policy, and is then deleted or anonymised.
- Location is captured only at the moment of a punch, never tracked continuously, and only where the employee has been told in advance.
5. Procedure for requests and breaches
- To see the personal data we hold or correct an error, write to [Privacy Contact Email]. HR responds within [Number] working days.
- Where we rely on consent for optional data, such as showing your birthday to colleagues, you may withdraw that consent at any time.
- Report any suspected data breach to [Privacy Contact Name] at once. The Company will contain it, assess the impact, inform affected employees and notify authorities where the law requires.
6. Responsibilities
- Privacy contact, [Name, Designation]: answer requests, keep a record of breaches and advise on new data uses.
- HR and payroll: collect only necessary data, store it securely and share it only as this policy allows.
- Managers: use team data only for managing the team, and never download it to personal devices.
- IT: secure systems, manage access rights and keep access logs.
7. Exceptions
Personal data may be kept or disclosed without consent where the law requires it, where it is needed to establish or defend a legal claim, or where it is needed to protect someone's life or safety.
8. Review
[Privacy Contact Designation] and [HR Head Designation] review this policy every [12] months and whenever data protection law or rules change, or the Company starts using a new system that holds employee data.
What to include
A clear list of data
Tell employees exactly what you hold, grouped into simple categories. People are far more comfortable sharing documents when they can see why each one is needed.
Purpose limitation
Use each piece of data only for the reason it was collected. Bank details collected for salary should not be used for anything else.
Role-based access
Decide who sees salary, bank and health data, and restrict it further than general employee records. Most managers need headcount and attendance, not bank accounts.
Location and biometrics
If you capture punch locations or use biometric devices, say so, explain why, and state that location is recorded only at the moment of a punch.
A route for corrections
Give employees a simple way to see and correct their data, with a response time. Wrong bank or nominee details cause real harm.
Retention and deletion
Link to your document retention schedule and actually delete data when the period ends. Old files kept forever are a breach waiting to happen.
Common mistakes to avoid
- Collecting full Aadhaar copies from everyone when a masked copy would serve the purpose.
- Emailing the full salary register to managers who only need headcount figures.
- Capturing punch locations without telling employees when and why.
- Keeping former employees' documents indefinitely on a shared drive.
- Letting managers export team data to personal phones and laptops.
Run it in ZeniaHR
Access Control decides what each role can view, export or edit in each module, with data scopes and masking of salary, bank and contact fields. Employee documents open through time-limited download links. Capture controls set whether web punches are limited to office networks and whether a browser location check applies, and in the mobile app employees can request a correction to a profile field, which goes to HR for approval. Celebrations let each person hide their birthday.
See it on your own data
A 30-minute demo on a video call. We set up your departments, shifts and leave rules and show attendance, leave and payroll running for your team. Free for your first 50 employees.
Book a free demoSee pricingFrequently asked questions
What personal data does HR usually hold about employees?
HR usually holds identity and contact details, statutory numbers such as PAN, UAN and ESI number, bank details, salary and tax records, attendance punches, leave records, family and nominee details, performance and disciplinary records, and medical certificates where leave or fitness requires them. A privacy policy lists these and explains why each is needed.
Should employers keep copies of Aadhaar cards?
Keep only what you need. For most HR purposes a masked Aadhaar copy, which shows only the last four digits, is enough. Store any copy securely with restricted access, never share it on email or messaging groups, and delete it when the retention period ends.
Can an attendance app record employee location?
Location recorded only at the moment of a punch is far less intrusive than continuous tracking, and is common for field and multi-site staff. If you use it, the policy should say when location is captured, who can see it and how long it is kept, and employees should be told before it starts. Tracking outside working hours is hard to justify.
What should HR do after an employee data breach?
Contain it first by revoking access, recalling emails where possible and securing the source. Then work out what data was affected and whose, inform the affected employees with practical advice, and check with your legal adviser whether the breach must be reported to any authority. Record what happened and fix the cause.