Employee Data Under the DPDP Act: What Indian HR Teams Must Fix Before 2027
HR holds more sensitive personal data than marketing ever will — Aadhaar, bank details, medical records, background checks, CCTV, and now productivity monitoring. The DPDP Act covers all of it. The good news: much of it does not need consent. The bad news: most HR teams have no idea which parts do.
Short answer: The DPDP Act applies fully to employee data, but Section 7 provides an employment-related legitimate use, so most core HR processing — payroll, benefits, attendance, workplace safety — does not require consent. Processing that falls outside employment purposes, such as marketing to employees or sharing data with third parties for their own purposes, still needs consent. Notice obligations and Data Principal rights apply either way.
HR Is the Highest-Risk Data Estate in Most Companies
Ask an Indian company where its sensitive personal data lives and the answer will usually be "the customer database." It is almost always wrong. HR holds:
- Aadhaar and PAN, plus copies retained as scanned images,
- bank account details for salary credit,
- medical records from pre-employment checks and insurance claims,
- background verification reports, including criminal-record checks,
- performance reviews, disciplinary records, and exit interviews,
- biometric attendance data,
- CCTV footage, access-card logs, and increasingly device and productivity monitoring,
- family details for insurance dependants, including children's data.
The DPDP Act does not have a "sensitive personal data" category the way the old SPDI Rules did — all digital personal data is treated alike. But the ₹250 crore security-safeguards penalty applies to a payroll spreadsheet on a shared drive exactly as it applies to a customer database.
The Employment Legitimate Use
Section 7 lists processing grounds that do not require consent. The employment ground permits processing for purposes of employment, or for safeguarding the employer from loss or liability, including prevention of corporate espionage, maintenance of confidentiality of trade secrets and intellectual property, and provision of any service or benefit sought by an employee.
Key insight: this is the single most useful provision in the Act for Indian HR teams, and it is routinely misread in both directions. It is broader than people expect — it covers loss prevention and confidentiality protection, not just payroll. And it is narrower than people hope — it does not cover everything HR happens to do with employee data.
| HR processing | Basis | Consent needed? |
|---|---|---|
| Payroll, PF, ESI, tax deduction | Employment / legal obligation | No |
| Attendance and leave management | Employment | No |
| Performance management, appraisals | Employment | No |
| Workplace safety, access control | Employment / safeguarding from loss | No |
| Insurance administration for the employee | Provision of a benefit sought by the employee | No |
| Insurance for dependants (spouse, children) | Dependants are not your employees | Yes — and parental consent for children |
| Background verification via a third-party agency | Employment, but agency is a processor | No, if properly scoped and contracted |
| Publishing employee photos on the website or LinkedIn | Marketing, not employment | Yes |
| Sharing employee data with a group company for its own purposes | New purpose, new fiduciary | Yes |
| Alumni communications after exit | No longer an employee | Yes |
| Wellness app that profiles employees for a vendor's product | Vendor's own purpose | Yes |
The Four Places HR Teams Get It Wrong
1. Consent forms in the appointment letter
Many Indian offer letters bundle a broad data-processing consent clause into the employment contract. Two problems. First, consent under the Act must be free — consent given as a condition of employment, by someone who cannot realistically refuse, is difficult to defend as freely given. Second, it is unnecessary for anything already covered by the employment legitimate use, and relying on invalid consent where a solid legitimate use exists actively weakens your position.
The fix: rely on the legitimate use for employment processing and issue a notice rather than a consent form. Seek genuine, separable consent only for the processing that sits outside employment purposes — and make declining it consequence-free.
2. Dependants' data treated as employee data
Your employee's spouse and children are Data Principals in their own right and they are not your employees, so the employment ground does not reach them. Collecting a child's date of birth and medical history for a group insurance policy means processing children's data, which triggers verifiable parental consent obligations and prohibitions on tracking and behavioural monitoring. Our guide to verifiable parental consent covers the mechanics.
3. Ex-employee records kept forever
The default in most Indian HR systems is to keep everything indefinitely. The Act requires erasure when the purpose is no longer served, unless retention is required by law. Statutory retention periods do exist — under labour codes, the Income Tax Act, PF and ESI rules — and they justify keeping specific records for specific periods. They do not justify keeping the full personnel file, the CCTV footage, the Slack export, and the laptop image for a decade.
The deliverable is a retention schedule with a legal citation per record class. Anything without a citation gets a purpose-based expiry. Our retention and erasure guide covers how to automate the clocks.
4. Monitoring that nobody was told about
Device monitoring, keystroke logging, screen capture, email scanning, and productivity analytics have all spread quickly in Indian workplaces since remote work normalised. Some of it can be defended under safeguarding the employer from loss. None of it can be defended if employees were never told it was happening — the notice obligation applies to legitimate-use processing too. Covert monitoring is the fact pattern most likely to produce an employee complaint to the Board.
Candidates, Contractors, and Gig Workers
The employment legitimate use is anchored to employment. Three populations sit outside it, and all three are usually managed by the same HR systems.
Job candidates
A candidate who did not get the job was never your employee, so the employment ground is a stretch at best for anything beyond running the hiring process itself. Applicant data is typically retained far too long — ATS records from five years ago, rejected candidates kept "in case something opens up." That retention needs consent, and a candidate who consented to being kept on file must be able to withdraw. Set a default purge window on the ATS and ask candidates explicitly if you want to keep them longer.
Contractors and consultants
Independent contractors are not employees. Processing their data usually rests on contract performance and the voluntary-provision ground rather than the employment limb. In practice the obligations look similar, but the basis is different and your notice should say so.
Gig and platform workers
This is the genuinely hard one, and the most exposed. Platform workers are frequently subject to location tracking, performance scoring, and algorithmic allocation — processing that is far more intrusive than anything a salaried employee experiences. Whether the employment ground applies at all depends on the contractual relationship, which is itself contested in Indian labour law. Where algorithmic allocation materially affects earnings, the fairness and human-review considerations from the AI Governance Guidelines apply alongside DPDP obligations. Platforms should assume this area attracts scrutiny early.
Employees Have Rights You Must Service
Data Principal rights are not switched off by the employment relationship. An employee — or a former employee — can ask for:
- Access — a summary of the personal data being processed and the processing activities undertaken.
- Correction — including of inaccurate or incomplete records.
- Erasure — where the purpose is served and no legal retention applies.
- Grievance redressal — a published channel with a response obligation.
- Nomination — nominating another individual to exercise rights in the event of death or incapacity.
A disgruntled ex-employee filing an access request is a predictable stress test. The realistic worst case is not the request itself but discovering that HR data is scattered across an HRMS, three spreadsheets, a shared drive, WhatsApp groups, and the previous HR manager's inbox — with no way to compile a complete response.
The HR Readiness Checklist
- Inventory HR data systems — HRMS, payroll vendor, background-check agency, insurance broker, attendance hardware, CCTV, monitoring tools, and the shadow spreadsheets.
- Classify each processing activity as employment legitimate use or consent-requiring, using the table above as a starting point.
- Write an employee privacy notice in clear language, covering what is collected, why, who it is shared with, how long it is kept, and how to exercise rights. Issue at onboarding and on material change.
- Strip blanket consent clauses out of appointment letters; replace with notice plus specific, separable consents where genuinely needed.
- Handle dependants separately, with parental consent where children's data is involved.
- Build a retention schedule with statutory citations and automated expiry for everything else.
- Bind your processors — payroll bureau, background-check agency, HRMS vendor — by contract, with security and deletion obligations.
- Publish a grievance channel and staff it, with the DPO as contact if you are a Significant Data Fiduciary.
- Disclose monitoring explicitly, and scope it to what safeguarding actually requires.
- Secure the estate — access control on payroll files, encryption for Aadhaar and bank data, logging on HRMS access.
Frequently Asked Questions
Does the DPDP Act apply to employee data in India?
Yes, fully. Employees are Data Principals and employers processing their digital personal data are Data Fiduciaries. The Act draws no distinction between customer and employee data, and the same penalties apply.
Do employers need employee consent to process HR data?
Generally no for core HR processing. Section 7 provides a legitimate use covering employment purposes, safeguarding the employer from loss or liability, protecting confidentiality and trade secrets, and providing services or benefits the employee has sought. Consent is still required for processing outside employment purposes — marketing, alumni outreach, publishing photos, or sharing data with third parties for their own purposes.
Is a consent clause in the appointment letter valid?
It is weak. Consent under the DPDP Act must be free, and consent obtained as a condition of employment from someone who cannot realistically refuse is hard to defend. For employment processing it is also unnecessary, since the legitimate use already applies. Use a notice for employment processing and seek genuinely separable consent only where the processing falls outside it.
How long can we keep ex-employee records?
As long as a specific law requires, and no longer. Statutory retention obligations under labour, tax, PF, and ESI rules justify keeping defined record classes for defined periods. Everything else must be erased once the purpose is served. Build a retention schedule with a legal citation per record class; anything lacking a citation needs a purpose-based expiry date.
Can we monitor employee devices and productivity under the DPDP Act?
Potentially, under the safeguarding-from-loss limb of the employment legitimate use — but only if employees have been told. The notice obligation applies to legitimate-use processing as well as consent-based processing, so covert monitoring is not defensible. Scope monitoring to what loss prevention actually requires rather than collecting everything available.
Does the employment legitimate use cover employees' family members?
No. Spouses and children are separate Data Principals and are not your employees, so the employment ground does not extend to them. Collecting dependant data for insurance requires consent, and where children are involved it requires verifiable parental consent, with the accompanying prohibitions on tracking and behavioural monitoring.
Where Consently Fits
HR compliance under the DPDP Act is mostly a records problem: proving what each person was told, what they agreed to where consent applied, and when data is due for erasure. Consently handles employee-facing notices in all 22 Scheduled languages, itemised consent for the processing that genuinely needs it, immutable consent records tied to notice versions, Data Principal rights workflows that work equally for employees and ex-employees, and retention clocks with automated erasure. Talk to us about your HR data estate.