Ethics in HR means making people decisions, hiring, firing, pay, promotions, based on fairness and transparency rather than just what’s legally defensible. In India, that isn’t only a values statement. It’s backed by specific, mandatory legal structures, POSH Act committees, whistleblower vigil mechanisms, data protection obligations, that most companies still treat as paperwork rather than the actual ethical infrastructure they are.
Compliance asks “is this legal?” Ethics asks “is this right, even in the cases the law doesn’t clearly cover?” A layoff selection process can be perfectly legal and still unfairly target older employees or a particular team disproportionately. HR’s job is to catch that gap before it becomes a lawsuit, a resignation wave, or a story that damages the employer brand for years.
Three principles do most of the real work here: fairness (consistent standards applied the same way regardless of who’s involved), transparency (employees understand the policies and reasoning behind decisions that affect them), and confidentiality (personal and performance information handled with real discretion, not office gossip currency).
Three specific frameworks turn “be ethical” from an aspiration into something with actual teeth:
Any workplace with 10 or more employees is legally required to constitute an Internal Committee (IC) under Section 4 of the Act. At least half the committee, including the Presiding Officer, must be women, and the committee must include one external member (typically someone from an NGO or with relevant legal expertise) who isn’t a company employee. The IC handles complaints, and the company must file an annual report with the District Officer. Companies that treat this as a one-time policy document instead of an actively functioning, trained committee are the ones that get caught flat-footed when an actual complaint arrives.
Listed companies, companies that accept public deposits, and companies that have borrowed more than ₹50 crore from banks or financial institutions are legally required to maintain a vigil mechanism, a channel for employees and directors to report suspected fraud or ethics violations, with protection against retaliation and, in serious cases, direct access to the Audit Committee chairperson. It’s not mandatory for every private company, but any HR function serious about ethics adopts something similar voluntarily, since a policy nobody trusts enough to actually use isn’t protecting anyone.
HR sits on some of the most sensitive personal data a company holds: salary, health records, background checks, sometimes biometric attendance data. The Digital Personal Data Protection Act requires clear consent before collecting this, a defined purpose for using it, and deletion once that purpose is served. An HR team that keeps former employees’ biometric or health data indefinitely “just in case” isn’t just creating legal exposure, it’s failing the basic ethical obligation to only hold what it actually needs.
Moonlighting policy. When India’s IT sector fought this out publicly in 2022-2023, some companies terminated employees for undisclosed second jobs while others (Swiggy, notably) formalized a policy explicitly permitting it under conditions. Neither position is inherently “the ethical one.” The actual ethical failure is having no clear, communicated policy at all and then handling each case inconsistently based on who gets caught.
Layoff selection fairness. “Last in, first out” feels objectively fair but can systematically wipe out recent diversity hiring gains. Performance-based selection feels more merit-driven but is only as fair as the appraisal data behind it, which, per most traditional appraisal methods, carries real subjectivity. There’s no clean answer, only a documented, defensible process.
Referral and nepotism friction. Employee referral programs are genuinely effective for recruiting, but unmanaged, they quietly recreate the same networks and backgrounds over and over, which is its own quiet form of unfairness even without anyone intending discrimination.
Monitoring and surveillance. Attendance systems, email monitoring, and productivity trackers are increasingly common, and they’re legal within DPDP’s framework if consent and purpose are handled properly. Legal doesn’t automatically mean employees experience it as fair, especially when monitoring tools get deployed without a clear, upfront explanation of what’s actually being tracked and why.
Much of this overlaps directly with what falls under the core responsibilities of an HR manager, and specifically with how HR policies get written and enforced day to day, not just drafted once and forgotten.
Yes, once a workplace has 10 or more employees, Section 4 of the POSH Act requires a properly constituted Internal Committee, regardless of company size or sector.
Listed companies, companies accepting public deposits, and companies that have borrowed more than ₹50 crore from banks or financial institutions, under Section 177 of the Companies Act, 2013. It’s not legally mandatory for other private companies, though many adopt an equivalent policy voluntarily.
Compliance is about meeting legal minimums. Ethics covers the broader question of fairness and transparency, including situations the law doesn’t explicitly address, like whether a technically legal layoff selection process actually treats people fairly.
It applies to employee data too. Salary records, health information, background checks, and biometric attendance data all count as personal data under the Act, with the same consent and purpose-limitation requirements that apply to customer data.
At least half the members, including the Presiding Officer, must be women, and the committee must include at least one external member who isn’t employed by the company, typically someone with relevant legal or NGO experience.
There’s no single right answer; it depends entirely on the company’s stated policy. The real ethical failure is a company having no clear policy at all and then reacting inconsistently case by case once someone gets caught.
Non-compliance with POSH Act reporting requirements can result in penalties, and repeated non-compliance can lead to cancellation of business licenses or registrations in serious cases. It’s a genuine legal risk, not just a formality.
Attendance and productivity monitoring can be entirely legal under the DPDP Act if consent and purpose are properly disclosed, but ethical practice goes further: employees should clearly understand what’s being tracked and why before it’s deployed, not discover it after the fact.
Consistent, well-documented HR practices, the kind that actually hold up to ethical and legal scrutiny, are easier to maintain with the right HR software behind them.