Agentic AI in HR vs DPDP 2023: automate your workforce without leaking employee data
India's DPDP Act 2023 makes any HR tool that sends employee data to an AI model a data-protection question. Whether automation and privacy actually conflict comes down to one detail: what the tool sends to the model.
The rush to put AI in HR collided with a law. India's Digital Personal Data Protection Act 2023 is now the frame every people-tech decision sits inside, and HR holds the densest concentration of sensitive personal data in the company: names, salaries, performance ratings, PAN, Aadhaar, bank details, health and leave records.
Most "AI in HR" works by doing the thing DPDP is wary of: sending those records to a third-party language model to answer a question. Under DPDP, the employer is the Data Fiduciary, accountable for every downstream processor, including any AI vendor. So the useful question is narrower than "should we use AI in HR?" — it is whether a given tool automates the work without the automation itself becoming the data-protection problem.
Why HR is where DPDP bites hardest
DPDP 2023 rests on a few principles that land squarely on HR data: you may only process personal data for a stated purpose, with a lawful basis; the individual has rights of access and erasure; and you remain accountable when a processor handles the data on your behalf. HR breaks all three the moment an AI feature sends a full employee record off to a model:
- Purpose drifts. Data collected to run payroll is quietly reused to train or prompt an AI feature, a new purpose with no fresh basis.
- The transfer is invisible. You often cannot see, log, or undo what left the building, or where the model ran.
- Erasure stops at the database. A "delete this employee" request clears your tables but not the prompts, caches and logs the data already flowed into.
The tell: a data-leaking chatbot vs a governed agent
Not all "AI in HR" carries the same risk. The dividing line is simple: what actually reaches the model.
| Typical HR AI chatbot | Governed AI agent | |
|---|---|---|
| What reaches the model | Names, salary, sometimes PAN / Aadhaar in the prompt | Opaque IDs and skill codes only |
| Who can see the PII | The model and its provider | Only your authorised user, after the model finishes |
| Trains on your data | Often unclear, or on by default | Never, PII never enters the model |
| Audit trail | Rarely | Every action logged, de-identified |
| Who decides | Sometimes auto-acts | Human-in-the-loop, always |
| DPDP posture | Retrofit | Built in |
Both can reasonably be called "AI in HR". The difference that matters under DPDP is whether the model receives identifiable data at all, and only one of these two designs can answer that with a clear no.
The common DPDP pitfalls in HR-tech vendors
When you evaluate an HR-AI vendor, these are the six failure modes that turn a feature into a liability:
- PII in the prompt. The employee record is pasted straight into the model call. Everything downstream inherits that exposure.
- No purpose limitation. Data gathered for one reason (payroll, attendance) is reused for AI features without a fresh lawful basis.
- Consent and erasure don't reach the AI. DSAR and "right to be forgotten" flows stop at the database, not the model, its logs, or its caches.
- Training on your data. Your employees' records quietly improve the vendor's, or a third party's, model, a transfer you cannot pull back.
- No audit trail. You cannot show a regulator, or an employee, what the AI saw and what it did.
- Silent cross-border transfer. The model runs offshore and the transfer is neither disclosed nor logged.
Anonymised talent mapping: capability without PII leakage
The fix is not to abandon AI. It is to separate capability from identity. Map your workforce as skills, levels and gaps; let the AI reason over opaque IDs and non-identifying skill codes; and re-attach a person's name only on the authorised user's screen, after the model has finished. The model never holds identity, so your consent and erasure obligations stay intact, because the identity never left your side in the first place.
How SKILWI does it. Agent Skye runs on a Zero-Data Architecture: the model receives only a non-identifying code for the person and the skill, never a name, salary, PAN or Aadhaar. Names, salaries and identifiers stay encrypted inside SKILWI and are re-attached only on the authorised user's screen, after the model has finished. The data path has been independently penetration-tested. For how this works in the product, see Meet Agent Skye: what AI in HR actually looks like.
This is what lets you run agentic AI on your workforce without your workforce's personal data ever entering a model's prompt or training path.
Building employee trust through transparent AI workflows
Compliance is the floor. Trust is the point, and it is what determines whether people actually engage with an AI-assisted HR process instead of quietly routing around it. Three practices earn it:
- Human-in-the-loop. The agent drafts; a person decides. Accountability stays with a human, which is both good governance and, increasingly, a regulatory expectation.
- Explainability. Every recommendation ships with its reasoning and its numbers, so an employee can see why, not just what.
- Aggregate-only sensitive signals. Wellbeing and inclusion insights are read at the group level, never as individual surveillance.
An employee who can see that the AI never held their salary, and that a named human made the call, trusts the system. That is the difference between automation people accept and automation they resent.
A DPDP vendor-evaluation checklist
Take these seven questions into any HR-AI vendor conversation. The safe answer is in brackets:
- Does employee PII ever enter the model's prompt or training data?
- No.
- What exactly does the model receive?
- Opaque IDs and non-identifying skill codes, nothing that names a person.
- Where does the model run, and is any transfer logged and disclosed?
- Known location, logged, disclosed.
- Do your DSAR and erasure flows reach the AI's logs and caches, not just the database?
- Yes.
- Is there a per-action audit trail of what the AI saw and did?
- Yes.
- Does a human approve every people-affecting action?
- Yes.
- Has the data path been independently penetration-tested?
- Yes, with a report you can see.
Common questions
- Is agentic AI allowed under DPDP 2023?
- Yes, if built for it: no PII to the model, consent, purpose limitation, audit and erasure intact, and a human approving every people-affecting action.
- Chatbot vs governed agent, what's the real difference?
- The chatbot ingests PII to answer; the governed agent reasons over anonymised data and re-identifies only on your side.
- Does SKILWI's AI see salaries, PAN or Aadhaar?
- No. Zero-Data Architecture: the model sees opaque IDs and skill codes; PII stays encrypted inside SKILWI; the path is independently pen-tested.
Agentic AI and DPDP 2023 are not opposites. Whether a tool treats them as a trade-off comes down to a design choice: send employee data out to the model, or keep it in place and send only what is non-identifying. For how SKILWI handles this, see our approach to DPDP 2023 and to workforce intelligence.
See how it works in practice
A walkthrough shows how Agent Skye drafts a hire-vs-upskill decision while the model only ever sees opaque IDs, not names or salaries.
Book a demo