HR Strategy
What Proxy Bias Hides From You: Ethical AI in HR Under the DPDP Act
Ethical AI in HR: AI in HR management: Learn how to integrate predictive analytics while maintaining workforce trust. Discover practical...
Nishant Tandon
Co-founder & Lead Partner, Razor Infotech · 15 min read · 5 August 2026
Most bias in HR algorithms does not arrive labelled. No Indian vendor ships a model with a "reject candidates from small towns" switch. What ships instead is a scoring model trained on ten years of your own hiring decisions, which learns that people from four metro institutions got hired and people from a hundred district colleges did not. The model has no prejudice of its own; it is obedient to a history you handed it. That is the harder problem, and it is why ethical AI in HR is an operational discipline rather than a line in a values deck. Our team spends most of its time on the unglamorous layer underneath these tools: the Employee Data Management records that every prediction is ultimately built from.
The gap in almost every guide on this subject is that it was written for a jurisdiction India does not sit in. GDPR-shaped advice, EEOC-shaped advice, adverse-impact ratios drawn from US case law. Useful, but not the law your grievance officer will answer to.
Why Ethical AI in HR Starts With the DPDP Act, Not a Values Statement
The Digital Personal Data Protection Act, 2023 is published by the Ministry of Electronics and Information Technology, and its architecture matters more to your AI programme than any ethics manifesto. It treats your organisation as a data fiduciary and your employees and candidates as data principals. Consent must be tied to a stated purpose. Data collected for one purpose does not automatically become training fuel for another. And the exposure is not theoretical: penalties in the Schedule to the Act reach ₹250 crore for a single class of breach, which is the number that moves this from an HR conversation to a board conversation.

Read that purpose-limitation point again with your HRMS in mind.
Attendance punches were collected to validate presence. Performance ratings were collected to decide increments. Resignation records were collected because people leave. The moment a predictive model consumes all three to produce an attrition risk score, you have created a new purpose, and quite possibly one your notice never mentioned. Most Indian HR AI programmes are exposed right here, in the consent paperwork that came before the model rather than in the model itself.
Three practical consequences follow.
Purpose limitation forces you to name the model. Your privacy notice cannot say "HR analytics". It has to say what the system infers, from which categories of data, and what happens with the output.
Data principal rights are operational, not theoretical. An employee can ask what you hold about them and ask for correction. If a wrong entry in a past appraisal is feeding a promotion-readiness score, correction is not a filing exercise. It is a re-scoring event.
Grievance redressal needs a real queue. Someone has to receive a complaint about an automated decision and answer it within a defined window. A shared HR inbox cannot tell you whether that happened, which is precisely what a tracked route with an SLA timer, of the kind an internal helpdesk such as Ticket Management provides, exists to prove.
Where the DPDP framework sits as of 2026
Beyond the Act's core duties sit three machines HR teams rarely account for. The Data Protection Board of India hears complaints and imposes penalties, which means a rejected candidate now has a forum that is not your inbox. The consent manager is a registered entity through which a data principal can give, manage and withdraw consent, so consent stops being a checkbox you own and becomes a record they control. And the significant data fiduciary tier carries heavier obligations, including a data protection impact assessment, periodic audit and an independent data auditor.
Two things get misread. That tier is not a headcount threshold; it is a designation the government makes based on the volume and sensitivity of data processed and the risk involved. The Rules under the Act have also been rolling out on a phased timeline, so before you fix an internal compliance deadline, check the current notification status on the MeitY site rather than a vendor's compliance blog.
We wrote separately about where autonomous systems in HR software actually sit today in our piece on agentic AI in HRMS; the short version is that legal accountability has not moved an inch toward the machine.
Proxy Bias: The Indian Variables Your Model Is Quietly Using
Direct discrimination is easy to code out. Nobody feeds caste or religion into a shortlisting model. Proxy variables are the problem: neutral-looking fields that correlate tightly with the protected thing you removed. This is the shape bias in HR tech usually takes here, and it survives every audit that only checks which columns you deleted.
The four proxies that matter most in Indian hiring
Institution tier. Any model trained on historical shortlists in India will learn institutional prestige, because your recruiters did. That single feature carries a great deal of socio-economic information with it.
Pincode and address distribution. Residential location in most Indian cities is not randomly distributed across community lines. A "commute distance" feature is rarely just a commute distance feature.
Career gaps. Gap-penalising features fall hardest on women returning after maternity, and on candidates who supported family illness. The model reads absence; it cannot read cause.
Language and name signals. Resume-parsing that rewards a particular register of English rewards schooling, not capability.
Testing it with arithmetic you can argue with
You do not need a data science team to find this. You need a funnel and a calculator.
Illustrative model, using round numbers you should replace with your own: 1,200 applications for a batch of engineering roles. 700 from metro-tier institutions, 500 from Tier-2 and Tier-3 colleges. The tool shortlists 60. If 54 of those 60 come from the metro pool, your selection rate is roughly 1 in 13 for metro applicants and 1 in 83 for everyone else. A gap of about six times.
A gap that size is not proof of unlawful discrimination, but it is the flag that tells you where to look. Run the same cut on gender, on gap-in-service, on city. If the difference holds after you control for the qualification the role actually requires, the model has learned something you did not intend to teach it. Adjust the assumed volumes to your own funnel and the method still works, which is the point of doing it this way rather than trusting a vendor's fairness badge.
For the analytics side of this question, our guide on predictive HR analytics for attrition covers how the same signals get used on the retention side.
The Decision Ledger: Making Every AI-Assisted Call Contestable
Here is the framework we would defend in front of a regulator or an angry high performer: the Decision Ledger.

The rule is simple. Any people decision that an algorithm influenced gets one row in a ledger, and that row must be complete before the decision is communicated.
A row has five fields:
| Field | What goes in it |
|---|---|
| Decision | The concrete action taken |
| Model input | Which data categories the system used |
| System output | What the tool actually suggested |
| Human call | What the accountable person decided |
| Reason | One or two sentences a named human wrote |
That last field is doing most of the work. A dropdown reason satisfies an auditor; a written sentence is the only artefact that shows anyone actually thought. When a manager has to type why they accepted a low ranking for a candidate they never met, the quality of the decision changes before anyone audits anything.
Who signs, and what they can override
Human-in-the-loop fails when the human is a rubber stamp on 400 rows. Make it structural instead. Set volume caps per approver per day. Require the reviewer to see the candidate's material, not just the score. And define an override that carries no penalty: a reviewer who disagrees with the model should never have to justify that upward, only record it.
Set a hard rule alongside it. No adverse action, meaning rejection, a performance flag, or a PIP trigger, goes out on a model output alone. The system can propose; the decision and the name attached to it stay human, and both live in the ledger. That is the whole of what "co-pilot" should mean in a people function. Goal and rating data feeding this belongs in a governed Employee Performance Management record, not in a spreadsheet a manager keeps privately.
Which brings up something worth saying plainly: informal workarounds feel harmless right up until the person who knew them leaves. A recruiter's personal weighting rules, held in their head for six years, walk out of the building with them and take the explanation for six years of HR decision making along.
Drafting an AI Ethics Charter Your Indian C-Suite Will Actually Sign
Most charters fail because they are aspirational. A usable one is short, and most of its value sits in the prohibitions. Cover these:
- Scope. Which systems are in, by name.
- Prohibited uses. Write the list. Emotion inference from video interviews. Health prediction. Anything that scores an employee's private communications. Say no in writing, once.
- Accountability. A named owner per system, plus a small governance council.
- Employee notice. What people are told, when, and in which language.
- Retention. How long inputs and outputs are kept, with a purge date attached.
- Appeal route. Who an employee writes to, and the maximum days to a substantive response.
Keep it to two pages. A charter nobody reads governs nothing.
Explainability the Candidate Can Actually Read
Explainability in HR has little to do with model interpretability in the research sense; the working test is whether a rejected candidate or a flagged employee can be told, in one honest paragraph, what happened.
Two questions we would put to any HR AI feature before it goes live. Can the accountable manager restate the reason in plain language without using the word "algorithm"? Would you be comfortable if that explanation were read aloud in a conciliation proceeding? A system that produces a score nobody can unpack into human reasons is not ready for decisions about people.
The distinction matters commercially too. Tools that rank work rather than workers carry far less of this risk. That is the design choice behind Productivity Lens, which tracks task completion and milestone progression from aggregated metadata to show where work is stuck: no screenshots, no keystroke capture, no screen recording.
Preventing Drift: The Quarterly Audit
Models degrade quietly. Your hiring mix changes, and a tool validated in March is scoring a different population by September. Put a recurring 90-minute review on the calendar and work through six things:
- Re-run the selection-rate arithmetic above on the last quarter's funnel, cut by gender and by institution tier.
- Compare override frequency. If human reviewers overrode the model often in Q1 and almost never in Q3, the humans have stopped reviewing.
- Sample ten Decision Ledger rows at random and read the reason field. Blank or copy-pasted reasons are your real finding.
- List every new data source connected to the model since the last audit, and check each against the stated purpose in your notice.
- Count grievances raised about automated decisions and time-to-resolution.
- Confirm retention purges actually ran.
Integration debt is what usually breaks this. AIHR's practitioner analysis notes that the cost and effort of integrating AI tools becomes an ongoing operational headache, producing manual data transfers and inconsistent data sets. Inconsistent data is how a fairness audit becomes impossible to run.
Vetting an Indian HRMS Vendor's AI Claims
Ask these in the demo. Write down the answers.

| Ask this | Weak answer | What you want to hear |
|---|---|---|
| What data trains the model? | "It's proprietary." | A clear yes or no, and a contractual clause |
| Where is the data stored? | Vague reference to the cloud | Named region, with a data processing agreement |
| Can I see the reason for any recommendation? | "The AI considers many factors." | A per-decision explanation surfaced in the UI |
| Can we run it in observation mode? | "Everyone goes live directly." | Yes, with a defined shadow period |
| What is deleted, and when? | Silence on retention | A stated retention window per data type |
| Who is the accountable contact? | Generic support email | A named grievance route with a response SLA |
Our note on evaluating the best HRMS software in India goes deeper on procurement mechanics.
On our own side, two commitments are worth stating because they are concrete rather than promissory. Mobile attendance may capture GPS to validate a geofenced punch; raw location and derived geofence fields are purged after 90 days, and only punch validity survives. Organisations moving onto our attendance engine can also run it in shadow mode, where employees punch as usual and payroll continues on existing calculations while the new logic runs alongside, so nobody's salary is a test case. Where a capability is still being built rather than shipped, we say so: several performance-scoring numbers in our dashboards are placeholders while the real engine is wired up, and they are labelled as such so leadership does not treat them as ground truth.
Where Predictive HR Analytics Does Not Belong
Some honest limits, because vendors rarely publish these.
Termination and disciplinary action. No model should contribute to a dismissal decision. The evidentiary standard in an Indian domestic inquiry rests on documents and testimony the worker can contest, which is the assumption running through the industrial relations framework administered by the Ministry of Labour & Employment, and a risk score is neither.
Small teams. Below roughly 50 people, statistical patterns are noise. A "flight risk" flag on a team of nine is a rumour with a progress bar.
POSH and grievance matters. These require confidentiality and a defined statutory process, applied by people. Automation has no role in the assessment itself.
Anything you cannot explain. If the tool works but nobody can say why, it belongs in a low-stakes queue rather than a decision path.
The common mistake is subtler than any of these: teams pilot a model on historical data, find it predicts past decisions accurately, and treat that as validation. Accuracy against a biased history only measures how faithfully the model copied you.
Frequently Asked Questions
How can HR leaders ensure AI recruitment tools are free from bias? You cannot guarantee it, and any vendor promising bias-free recruitment software is overselling. What you can do is measure selection rates across groups every quarter and strip proxy features like institution tier and pincode out of the scoring. Then require a named human decision with a written reason before any rejection goes out.
How does the DPDP Act affect AI use in an Indian HRMS? It ties data use to the purpose you stated when you collected it. If employee records are being used to train or feed a predictive model, that purpose has to appear in your notice, employees need a correction and grievance route, and retention periods have to be defined and actually enforced.
What are the risks of using predictive analytics for promotions? Promotion models learn from past promotion decisions, so they reproduce whatever pattern already existed, including who got the visible projects. Used as one input alongside evidence and manager judgment, they are fine. Used as a gate, they entrench yesterday's distribution and are very hard to defend if challenged.
How do we maintain employee trust while introducing AI recruitment tools? Tell people before you deploy, not after, and be specific about what the system does and does not see. Publish the appeal route. Running new logic in observation mode for a cycle, where it influences nothing, buys more credibility than any internal communication campaign.
Conclusion
Go back to the candidate from the district college whose application never reached a human. Nothing in that outcome was malicious, and nothing about it was accidental either. A model learned a pattern from your history, applied it at volume, and left no row anyone could inspect. What proxy bias hides is not a decision; it is the absence of one.
Build the ledger during a quiet quarter rather than during an inquiry. The five fields are in the table above, and copying them into a shared sheet this week costs you an afternoon. Under the DPDP framework the accountability for an automated people decision sits with you as the data fiduciary, with penalties in the Schedule running to ₹250 crore, and "the vendor's model decided" has never been a defence in an Indian employment forum.
Ready to stop shipping people decisions nobody can explain? Book a walkthrough with our team and ask us the six vendor questions above first.
About the Author & Reviewer
Nishant Tandon — Co-founder & Lead Partner, Razor Infotech
Nishant Tandon is Co-founder and Lead Partner at Razor Infotech, with over a decade in IT, customer support and business operations, helping SMEs achieve cost efficiency, stronger customer experience and scalable, sustainable growth.
Connect on LinkedIn
Reviewed & approved by Sameer Hameed — Founder & Chairman, Razor Infotech
Sameer Hameed is the Founder & Chairman of Razor Infotech, where he is guiding the creation of Human Maximizer. An entrepreneur across technology, real estate, mining and travel, he builds organisations on clarity, trust and responsible growth — on the belief that businesses grow only when the people behind them grow.
Connect on LinkedIn
Human Maximizer is built by Razor Infotech in New Delhi, India (founded 2019). About Human Maximizer.