Skip to main content
Compliance Guides
HR
Employee Data
DPDPA
Employment
Legitimate Uses
India
Workplace Privacy

Employee Data Under the DPDP Act: What Indian HR Teams Must Fix Before 2027

HR holds more sensitive personal data than marketing ever will — Aadhaar, bank details, medical records, background checks, CCTV, and now productivity monitoring. The DPDP Act covers all of it. The good news: much of it does not need consent. The bad news: most HR teams have no idea which parts do.

Consently Team
10 July 2026
9 min read

Short answer: The DPDP Act applies fully to employee data, but Section 7 provides an employment-related legitimate use, so most core HR processing — payroll, benefits, attendance, workplace safety — does not require consent. Processing that falls outside employment purposes, such as marketing to employees or sharing data with third parties for their own purposes, still needs consent. Notice obligations and Data Principal rights apply either way.

HR Is the Highest-Risk Data Estate in Most Companies

Ask an Indian company where its sensitive personal data lives and the answer will usually be "the customer database." It is almost always wrong. HR holds:

  • Aadhaar and PAN, plus copies retained as scanned images,
  • bank account details for salary credit,
  • medical records from pre-employment checks and insurance claims,
  • background verification reports, including criminal-record checks,
  • performance reviews, disciplinary records, and exit interviews,
  • biometric attendance data,
  • CCTV footage, access-card logs, and increasingly device and productivity monitoring,
  • family details for insurance dependants, including children's data.

The DPDP Act does not have a "sensitive personal data" category the way the old SPDI Rules did — all digital personal data is treated alike. But the ₹250 crore security-safeguards penalty applies to a payroll spreadsheet on a shared drive exactly as it applies to a customer database.

The Employment Legitimate Use

Section 7 lists processing grounds that do not require consent. The employment ground permits processing for purposes of employment, or for safeguarding the employer from loss or liability, including prevention of corporate espionage, maintenance of confidentiality of trade secrets and intellectual property, and provision of any service or benefit sought by an employee.

Key insight: this is the single most useful provision in the Act for Indian HR teams, and it is routinely misread in both directions. It is broader than people expect — it covers loss prevention and confidentiality protection, not just payroll. And it is narrower than people hope — it does not cover everything HR happens to do with employee data.

HR processingBasisConsent needed?
Payroll, PF, ESI, tax deductionEmployment / legal obligationNo
Attendance and leave managementEmploymentNo
Performance management, appraisalsEmploymentNo
Workplace safety, access controlEmployment / safeguarding from lossNo
Insurance administration for the employeeProvision of a benefit sought by the employeeNo
Insurance for dependants (spouse, children)Dependants are not your employeesYes — and parental consent for children
Background verification via a third-party agencyEmployment, but agency is a processorNo, if properly scoped and contracted
Publishing employee photos on the website or LinkedInMarketing, not employmentYes
Sharing employee data with a group company for its own purposesNew purpose, new fiduciaryYes
Alumni communications after exitNo longer an employeeYes
Wellness app that profiles employees for a vendor's productVendor's own purposeYes

The Four Places HR Teams Get It Wrong

1. Consent forms in the appointment letter

Many Indian offer letters bundle a broad data-processing consent clause into the employment contract. Two problems. First, consent under the Act must be free — consent given as a condition of employment, by someone who cannot realistically refuse, is difficult to defend as freely given. Second, it is unnecessary for anything already covered by the employment legitimate use, and relying on invalid consent where a solid legitimate use exists actively weakens your position.

The fix: rely on the legitimate use for employment processing and issue a notice rather than a consent form. Seek genuine, separable consent only for the processing that sits outside employment purposes — and make declining it consequence-free.

2. Dependants' data treated as employee data

Your employee's spouse and children are Data Principals in their own right and they are not your employees, so the employment ground does not reach them. Collecting a child's date of birth and medical history for a group insurance policy means processing children's data, which triggers verifiable parental consent obligations and prohibitions on tracking and behavioural monitoring. Our guide to verifiable parental consent covers the mechanics.

3. Ex-employee records kept forever

The default in most Indian HR systems is to keep everything indefinitely. The Act requires erasure when the purpose is no longer served, unless retention is required by law. Statutory retention periods do exist — under labour codes, the Income Tax Act, PF and ESI rules — and they justify keeping specific records for specific periods. They do not justify keeping the full personnel file, the CCTV footage, the Slack export, and the laptop image for a decade.

The deliverable is a retention schedule with a legal citation per record class. Anything without a citation gets a purpose-based expiry. Our retention and erasure guide covers how to automate the clocks.

4. Monitoring that nobody was told about

Device monitoring, keystroke logging, screen capture, email scanning, and productivity analytics have all spread quickly in Indian workplaces since remote work normalised. Some of it can be defended under safeguarding the employer from loss. None of it can be defended if employees were never told it was happening — the notice obligation applies to legitimate-use processing too. Covert monitoring is the fact pattern most likely to produce an employee complaint to the Board.

Candidates, Contractors, and Gig Workers

The employment legitimate use is anchored to employment. Three populations sit outside it, and all three are usually managed by the same HR systems.

Job candidates

A candidate who did not get the job was never your employee, so the employment ground is a stretch at best for anything beyond running the hiring process itself. Applicant data is typically retained far too long — ATS records from five years ago, rejected candidates kept "in case something opens up." That retention needs consent, and a candidate who consented to being kept on file must be able to withdraw. Set a default purge window on the ATS and ask candidates explicitly if you want to keep them longer.

Contractors and consultants

Independent contractors are not employees. Processing their data usually rests on contract performance and the voluntary-provision ground rather than the employment limb. In practice the obligations look similar, but the basis is different and your notice should say so.

Gig and platform workers

This is the genuinely hard one, and the most exposed. Platform workers are frequently subject to location tracking, performance scoring, and algorithmic allocation — processing that is far more intrusive than anything a salaried employee experiences. Whether the employment ground applies at all depends on the contractual relationship, which is itself contested in Indian labour law. Where algorithmic allocation materially affects earnings, the fairness and human-review considerations from the AI Governance Guidelines apply alongside DPDP obligations. Platforms should assume this area attracts scrutiny early.

Employees Have Rights You Must Service

Data Principal rights are not switched off by the employment relationship. An employee — or a former employee — can ask for:

  • Access — a summary of the personal data being processed and the processing activities undertaken.
  • Correction — including of inaccurate or incomplete records.
  • Erasure — where the purpose is served and no legal retention applies.
  • Grievance redressal — a published channel with a response obligation.
  • Nomination — nominating another individual to exercise rights in the event of death or incapacity.

A disgruntled ex-employee filing an access request is a predictable stress test. The realistic worst case is not the request itself but discovering that HR data is scattered across an HRMS, three spreadsheets, a shared drive, WhatsApp groups, and the previous HR manager's inbox — with no way to compile a complete response.

The HR Readiness Checklist

  1. Inventory HR data systems — HRMS, payroll vendor, background-check agency, insurance broker, attendance hardware, CCTV, monitoring tools, and the shadow spreadsheets.
  2. Classify each processing activity as employment legitimate use or consent-requiring, using the table above as a starting point.
  3. Write an employee privacy notice in clear language, covering what is collected, why, who it is shared with, how long it is kept, and how to exercise rights. Issue at onboarding and on material change.
  4. Strip blanket consent clauses out of appointment letters; replace with notice plus specific, separable consents where genuinely needed.
  5. Handle dependants separately, with parental consent where children's data is involved.
  6. Build a retention schedule with statutory citations and automated expiry for everything else.
  7. Bind your processors — payroll bureau, background-check agency, HRMS vendor — by contract, with security and deletion obligations.
  8. Publish a grievance channel and staff it, with the DPO as contact if you are a Significant Data Fiduciary.
  9. Disclose monitoring explicitly, and scope it to what safeguarding actually requires.
  10. Secure the estate — access control on payroll files, encryption for Aadhaar and bank data, logging on HRMS access.

Frequently Asked Questions

Does the DPDP Act apply to employee data in India?

Yes, fully. Employees are Data Principals and employers processing their digital personal data are Data Fiduciaries. The Act draws no distinction between customer and employee data, and the same penalties apply.

Do employers need employee consent to process HR data?

Generally no for core HR processing. Section 7 provides a legitimate use covering employment purposes, safeguarding the employer from loss or liability, protecting confidentiality and trade secrets, and providing services or benefits the employee has sought. Consent is still required for processing outside employment purposes — marketing, alumni outreach, publishing photos, or sharing data with third parties for their own purposes.

Is a consent clause in the appointment letter valid?

It is weak. Consent under the DPDP Act must be free, and consent obtained as a condition of employment from someone who cannot realistically refuse is hard to defend. For employment processing it is also unnecessary, since the legitimate use already applies. Use a notice for employment processing and seek genuinely separable consent only where the processing falls outside it.

How long can we keep ex-employee records?

As long as a specific law requires, and no longer. Statutory retention obligations under labour, tax, PF, and ESI rules justify keeping defined record classes for defined periods. Everything else must be erased once the purpose is served. Build a retention schedule with a legal citation per record class; anything lacking a citation needs a purpose-based expiry date.

Can we monitor employee devices and productivity under the DPDP Act?

Potentially, under the safeguarding-from-loss limb of the employment legitimate use — but only if employees have been told. The notice obligation applies to legitimate-use processing as well as consent-based processing, so covert monitoring is not defensible. Scope monitoring to what loss prevention actually requires rather than collecting everything available.

Does the employment legitimate use cover employees' family members?

No. Spouses and children are separate Data Principals and are not your employees, so the employment ground does not extend to them. Collecting dependant data for insurance requires consent, and where children are involved it requires verifiable parental consent, with the accompanying prohibitions on tracking and behavioural monitoring.

Where Consently Fits

HR compliance under the DPDP Act is mostly a records problem: proving what each person was told, what they agreed to where consent applied, and when data is due for erasure. Consently handles employee-facing notices in all 22 Scheduled languages, itemised consent for the processing that genuinely needs it, immutable consent records tied to notice versions, Data Principal rights workflows that work equally for employees and ex-employees, and retention clocks with automated erasure. Talk to us about your HR data estate.

Share this article

Related Articles

Compliance Guides

DPDP Consent Manager Registration: Eligibility, the ₹2 Crore Net Worth Bar, and the Application Checklist

The Consent Manager framework goes live on 13 November 2026. Registration requires incorporation in India, a minimum net worth of ₹2 crore, and demonstrated technical capability to run consent across fiduciaries. Here is who qualifies, what the application needs, and — importantly — why most businesses should not apply.

14 Jul 20269 min
Compliance Guides

Significant Data Fiduciary Under DPDP: Obligations, DPO Requirements, Audits and Cross-Border Rules

Being designated a Significant Data Fiduciary adds four obligations no ordinary Data Fiduciary has: a resident DPO, an independent data auditor, annual Data Protection Impact Assessments, and algorithmic due diligence. MeitY has also signalled cross-border restrictions for SDFs. Here is what the designation means and how to prepare.

6 Jul 202610 min
Compliance Guides

Can You Train AI on Indian Customer Data? What the DPDP Act Says About AI Training Data

India's DPDP Act has no research exemption for commercial AI, no legitimate-interests basis, and no concept of anonymised-enough. If you are fine-tuning a model on customer support transcripts or building a RAG index over user records, here is what the law actually requires — and what breaks.

23 Jun 202610 min