The average data breach in India cost an organisation ₹25.5 crore in 2026, an all-time high and a 15.9% jump over the previous year, according to IBM’s Cost of a Data Breach Report. Buried inside that number is a category most boardrooms underweight: the department that holds Aadhaar numbers, bank details, salary structures, medical declarations, background-check files, and disciplinary records for the entire workforce.
HR runs one of the densest concentrations of sensitive personal data in any company, and most Indian firms do so without a formal security standard governing how that data is collected, stored, shared, and destroyed. That gap is where ISO 27001 comes in.
ISO/IEC 27001 is the international standard for an information security management system, a documented framework for managing risk to the confidentiality, integrity, and availability of information. It matters to HR because the function sits on data that is both legally protected and commercially damaging when exposed, and because India’s new statutory regime now attaches real financial consequences to failing to protect it.
The Risk Sitting Inside The HR Function
HR data is uniquely exposed because it combines financial, identity, and health information in a single system, often accessed by dozens of people across payroll, recruitment, and benefits. A single compromised HRMS login can expose the full workforce in one pull, whereas a customer-facing breach might leak a single record. That concentration is what makes the function a high-value target rather than an administrative afterthought.
The financial stakes have moved sharply. The same IBM report found that Indian organisations without AI and security automation paid an average of ₹31.6 crore per breach, against ₹21.3 crore for those with extensive deployment, and that the average breach now compromises 39,500 records. Phishing remains the leading entry point, targeting HR inboxes that handle CVs, offer letters, and payroll queries from unknown senders every day.
The regulatory stakes have moved further. Under the Digital Personal Data Protection Act, 2023, an employer is a Data Fiduciary for its employees’ personal data, and failure to implement reasonable security safeguards that results in a breach carries a penalty of up to ₹250 crore.
The Act does not define “reasonable safeguards” in technical terms, which is why a recognised standard becomes useful: certification gives an organisation a defensible answer to what “reasonable” looked like. TPB has covered the DPDP Act’s implications for HR leaders in detail, and the security-standard question is the operational half of that compliance story.
What ISO 27001 Actually Governs
ISO 27001 is not antivirus software or a firewall setting. It is a management system, meaning it governs how an organisation identifies information risks, decides which controls to apply, assigns accountability, and reviews the whole arrangement on a cycle. The mandatory requirements live in clauses 4 to 10 of the standard, covering context, leadership, planning, and continual improvement. The menu of security measures sits in Annex A.
The current version, ISO/IEC 27001:2022, restructured Annex A into 93 controls across four themes: organisational, people, physical, and technological, down from 114 controls in the 2013 edition.
Annex A functions as a reference set rather than a mandatory checklist. An organisation selects the controls that address its assessed risks and documents the rest in a Statement of Applicability. The controls most relevant to an HR team cluster around access management, data handling, and the human factors that cause most breaches in the first place.
The Controls That Map Directly To HR Work
Several Annex A control areas translate almost one-to-one into everyday HR responsibilities. Understanding which ones touch the function helps HR move from bystander to owner in a certification effort, rather than treating security as something IT does to the systems HR happens to use.
| Annex A Theme | Control Area | HR Application |
| People | Screening and terms of employment | Background verification, confidentiality clauses, security responsibilities written into contracts |
| People | Awareness and disciplinary process | Security training during onboarding; consequences for policy breaches |
| Organisational | Access control and information classification | Role-based access to HRMS; classifying salary and medical data as restricted |
| Organisational | Supplier relationships | Security clauses in contracts with payroll processors and background-check vendors |
| Technological | Access rights and data leakage prevention | Deprovisioning system access on exit; controls on bulk data export |
The “people” theme is where HR’s ownership is least ambiguous. The standard treats employees as both a risk to be managed and a control to be strengthened, which is squarely HR’s remit.
Why Indian Employers Are Moving Now
India’s IT and business-services sector has held ISO 27001 certification for years, largely because global clients demanded it in contracts long before any domestic law did. Infosys, Wipro, and TCS build client trust partly on the certifications their delivery centres carry, and enterprise buyers routinely make ISO 27001 a procurement precondition. What has changed is that the pressure has spread inward, from client contracts to statutory obligation, and downward, from IT services firms to every employer holding personal data.
The DPDP Rules, 2025 gave the Act operational teeth, and the enforcement architecture, including the Data Protection Board of India, is now taking shape following MeitY’s November 2025 notifications. The practical reading for an HR leader is that “we have an IT team” is no longer a sufficient answer to a data-protection question. A structured, auditable approach to the specific data HR holds has become part of the compliance baseline, and ISO 27001 is the most widely recognised way to demonstrate one.
Certification Is Not The Only Destination
Adopting the framework and getting certified are different commitments, and the distinction matters for smaller employers weighing cost against benefit. A company can implement ISO 27001 controls to strengthen its posture without paying for an external audit and certificate, capturing much of the risk reduction without the recurring expense.
The considerations below help frame that decision honestly, since the standard is often oversold as a compliance silver bullet when it is really a disciplined risk-management practice.
- Certification value: An external certificate provides third-party assurance that satisfies client procurement teams and signals diligence to a regulator, which unaudited adoption cannot match.
- Cost and effort: Certification involves audit fees, internal preparation time, and annual surveillance audits, a genuine burden for a small firm with a lean HR team.
- DPDP alignment, not equivalence: ISO 27001 supports a “reasonable safeguards” defence but does not by itself equal DPDP compliance, which also demands consent, purpose limitation, and breach notification that the security standard does not fully cover.
- Scope discipline: A certificate covering only the data centre while leaving out HR systems and processes offers limited comfort for employee-data risk specifically.
Where HR Owns The Work
Some ISO 27001 controls cannot be handed to IT, because they live inside work only HR does: hiring people, moving them through the organisation, and letting them go. That makes a specific slice of the standard HR’s job to run rather than merely assist with. The controls that follow are the ones where HR is the natural owner, and each comes down to a single action a team can put on a calendar.
The table pairs each control with the action that delivers it and the risk it removes. Reading across a row answers the practical question for that control: what HR actually does, and what breaks if it does not.
| HR-Owned Control | Concrete Action | Failure It Prevents |
| Security-awareness induction | Build a mandatory data-handling module into onboarding, with a short assessment the new hire has to pass before HRMS access is granted | Phishing and mishandling by untrained staff, the leading breach vector |
| Access deprovisioning | Trigger a same-day access-revocation checklist the moment an exit is logged, tied to the final-settlement workflow so it cannot be skipped | Live credentials pointing at salary, Aadhaar, and medical records after an employee leaves |
| Role-based access | Review who can view or export bulk employee data every quarter, and strip access that role changes have made unnecessary | Over-broad access that turns one compromised login into a full-workforce exposure |
| Vendor data clauses | Audit payroll, background-check, and benefits contracts for a data-protection and breach-notification clause; flag any missing one for renewal | Unaccountable third parties holding employee data with no contractual security floor |
| Data classification | Label salary, health, and identity fields as restricted in the HRMS so access and retention rules attach automatically | Sensitive fields treated with the same laxity as a public org chart |
Deprovisioning deserves particular attention because it fails silently and constantly. An employee exits, the laptop comes back, and the HRMS, payroll, and email accounts stay live for weeks because no single owner was assigned to close them. Tying revocation to the exit workflow, so the account closes on the same trigger that stops the salary, removes the gap. TPB’s guidance on background verification and DPDP compliance shows how tightly the vendor side of this now intersects with statutory duty.
The through-line across every one of these actions is ownership. Getting employee records genuinely breach-proofed through disciplined cybersecurity practice depends on HR treating each step as its own accountability rather than a borrowed one, which is the mindset shift the standard ultimately asks for.
In the End…
Map the employee data your HR function holds before anything else. List every system, every vendor, and every person with access to salary, identity, and health records, then rank each store by the damage its exposure would cause. That inventory is the foundation of the risk assessment ISO 27001 is built on, and only HR can do it because only HR knows where the data actually sits.
From there, act on the two controls that fail most often and cost least to fix: revoke system access the moment an employee exits, and put a real security-awareness step into onboarding rather than a slide nobody reads. Pull the vendor contracts for payroll and background checks and confirm each one carries a data-protection clause.
If certification is on the table, scope it to include HR systems explicitly, not just the data centre. None of this requires waiting for an IT-led programme to reach the HR function, and given the ₹250 crore ceiling now attached to a preventable breach, waiting is the expensive option.
FAQs
What is ISO 27001 and why does it matter for HR?
ISO/IEC 27001 is the international standard for an information security management system; it matters to HR because the function holds legally protected, commercially sensitive employee data.
Which ISO 27001 controls does HR own?
Security-awareness induction, access deprovisioning, role-based access, vendor data clauses, and data classification.
Does ISO 27001 certification equal DPDP compliance?
No. It supports a “reasonable safeguards” defence but does not cover consent, purpose limitation, or breach notification.
What is the penalty for an HR data breach under the DPDP Act?
Up to ₹250 crore for failing to implement reasonable security safeguards.
Do small employers need to get certified?
Not necessarily; controls can be adopted without a paid external audit, capturing much of the risk reduction.

