HR teams treating biometric attendance DPDPA as a joining-kit tick are mixing two questions. Attendance can sit under Section 7(i) of the Digital Personal Data Protection Act, 2023. The fingerprint or face scan is a separate method — and background verification is a third.

TL;DR

  • Biometric attendance DPDPA work is a necessity test, not a gadget purchase. Section 7(i) can cover processing for employment purposes or to safeguard the employer from loss or liability. It does not automatically bless every biometric device.
  • Ordinary attendance (who was present, for wages and leave) is usually Section 7(i). If a card, PIN, or roster would do the same job, the biometric method likely needs Section 6 consent — free, specific, informed, unconditional, unambiguous, by clear affirmative action.
  • Background checks are the same split: proportionate, role-relevant screening may sit under Section 7(i); fishing expeditions need Section 6. The BGV agency is a Data Processor; you stay the Data Fiduciary.
  • Biometrics are not a current “sensitive personal data” category (the old SPDI tier is gone). They are personal data under Section 2(t), with full Section 8 duties and Rule 6 safeguards.
  • Fix this before 13 May 2027. A leaked attendance template or BGV pack starts the dual clock: CERT-In (6 hours) and the Data Protection Board of India (DPB) under Rule 7 (72 hours). Section 8(5) sits under the ₹250 crore slab.

What does biometric attendance DPDPA actually require from HR?

Biometric attendance DPDPA compliance is not “buy a device and take a joining signature.” It is three separate findings HR must write down.

First — is attendance itself an employment purpose? Usually yes. Wage calculation, leave, and shift integrity are employment processing. Section 7(i) is built for that. Manufacturing consent for core attendance creates a Section 6(4) withdrawal problem you do not want: you cannot stop running the roster because someone clicked withdraw.

Second — is the biometric method necessary? This is where most factories and offices fail. If RFID cards, PINs, or a supervised register achieve the same employment purpose, the face-scan or fingerprint is convenience, not necessity. Convenience is not Section 7(i). It needs Section 6, and inside employment “free” consent is the hard part: refusing cannot mean being marked absent or losing the offer.

Third — who else is in the stream? Device cloud, vendor app, and the security guard’s WhatsApp export are still personal data. Section 8(2) wants a contract. Tokenised templates are still personal data if they can identify the person.

The DPDPA does not revive the old SPDI “sensitive personal data” category. Fingerprints, face vectors, and salary files are one class under Section 2(t). Protection is purpose, security, and erasure — not a special biometric statute inside the Act.

The employment-ground overview is in employee data: consent, notice, HR. Why you are already a fiduciary is in if you have employees. This piece is the policy cut for the two surfaces that actually sit on the shop floor: devices and screening vendors.

Biometric attendance DPDPA: necessity test decides Section 7(i) versus Section 6

QuestionIf yesIf no
Is the purpose employment (wages, leave, site access for staff)?Section 7(i) is in play for the purposeFind another Section 7 limb or use Section 6
Is the biometric method necessary, or would a card/PIN/roster do?Document the necessity; still apply Section 8 and Rule 6Section 6 for the biometric method; offer a real alternative
Are contractors or visitors in the same gate stream?Split the flowSection 7(i) does not cover them
Does the vendor store templates in its cloud?Section 8(2) contract; name it in the employee noticeDo not skip the contract because “it is only a clock”

Interns under 18 are children. Section 9 and Rule 10 sit on top of whatever ground you chose. Do not enrol a minor’s biometrics on a staff device and call it HR.

When the check is proportionate and aimed at safeguarding the employer from loss or liability — the second limb of Section 7(i) — not when HR buys a 40-point social-media pack for every intern.

CheckTypical purposeLikely groundWhat “done” looks like
Identity / address / prior employment, role-relevantSafeguard from impersonation and CV fraudOften Section 7(i) if documented as necessaryNotice names the check; vendor under Section 8(2); report erased when the purpose ends
Education / professional licence where the role requires itFit for the jobOften Section 7(i)Collect the certificate, not a lifetime dossier
Criminal / credit where a sector rule or the role’s risk requires itSafeguard from loss or liabilityFact-specific Section 7(i)Cite the rule or the risk in the notice; do not copy the pack into Slack
Social-media scrape, family politics, caste, unrelated healthCuriosity / culture-fit theatreSection 6 if you do it at all; often: stopRefusal must not kill a 7(i) hire
Reuse of BGV for marketing, group-company hiring, or a later unrelated roleSecondary purposeSection 6New purpose, new ground, or erase

Aadhaar in a BGV pack is not a special DPDPA tier. It is personal data plus whatever UIDAI / EPFO rule actually requires for that purpose. If you cannot name the rule, do not retain the copy. The same minimisation logic as admission-form Aadhaar applies to HR files.

Rejected candidates are the quiet leak. Once you decide not to hire, most of the BGV purpose is over. Section 8(7) wants erasure, subject to a documented legal retention. “Keep the pack in case we hire them next year” is not a purpose.

How should HR treat BGV vendors and biometric device makers as processors?

You determine purpose and means. They process on your behalf. Section 8(2) is the contract. Their breach is still yours.

Biometric attendance DPDPA: employer is fiduciary; device and BGV vendors are processors

VendorWhat they holdContract must sayCommon failure
Biometric device / cloud attendanceTemplates, timestamps, sometimes photosPurpose lock (attendance only), access log, deletion at exit, hours-based incident SLA, no reuse for ads or trainingTemplates live forever in a vendor SaaS
BGV / screening agencyID copies, employment history, reportsPurpose lock, no further sharing, sub-processor list, CERT-In / Board escalation that lets you hit 6h / 72hReport forwarded on WhatsApp
HRMS / payrollAttendance feed + salarySame Section 8(2) + Rule 6(1)(f) security termsAttendance CSV dumped into a shared drive

Do not tell yourself the vendor’s “ISO certificate” is your Section 8(5) safeguard. Rule 6 still wants encryption or tokenisation and access control on your side. Privigo’s architecture claim for this cohort is a sealed PII vault so identifiers are not copied into every HRMS export, append-only consent records where Section 6 is the ground, and an audit trail that can show who pulled a BGV file. Software is not your DPO. The HR solution page is the product walkthrough.

Rule 13 annual DPIA and audit remain Significant Data Fiduciary only, after Section 10 notification. Most employers will not be notified. Hygiene still matters. SDF extras: Significant Data Fiduciary under DPDPA.

Why does a joining-kit tick fail for biometrics and screening?

Because Section 6 consent, when you need it, cannot be bundled, cannot be a condition of the job for an optional method, and must be withdrawable as easily as it was given.

A handbook line that says “I consent to all HR processing including biometrics, background verification, and photographs” fails specific, informed, and unconditional in one stroke. If the biometric is your only attendance method, “consent” is also not free. Pick a ground and live with it: document Section 7(i) necessity, or offer a non-biometric alternative and take real Section 6 consent.

Where you rely on Section 7(i), you still need a plain-language employee notice: what you collect, why, who the vendors are, how long templates and BGV reports last, and the Section 8(9) contact read with Rule 9. Notice is not consent. Keep the documents distinct.

Who owns the HR policy pack before 13 May 2027?

AreaOwnerStatus ☐
Written necessity note: biometric method vs card/PIN/rosterHR + Security☐
Split gate flows: employees vs contractors vs visitorsAdmin / Security☐
Employee notice names device vendor + BGV vendorHR + Legal☐
Section 8(2) contracts: device cloud, BGV, HRMSLegal☐
BGV field list: role-relevant only; erase rejected packsHR + Legal☐
Template / report erasure on exit (s.8(7))IT + HR☐
Dual-clock drill on an HRMS or vendor leak: CERT-In 6h + DPB 72hIT + HR☐
Named Section 8(9) contact (not titled DPO unless notified)Founder / HR☐

What should an HR head do this month?

Three moves, in order:

  1. Write the two-ground sentence — “Attendance purpose: Section 7(i). Biometric method: 7(i) because [necessity] / Section 6 because [alternative exists]. BGV: 7(i) for [named checks] / Section 6 for [named extras].” Put it in the Board pack.
  2. Offer one non-biometric attendance path this fortnight — even if most staff stay on the device. If you cannot offer it, stop calling the biometric “consent.”
  3. Pull one rejected-candidate BGV pack and delete it — then put the date in the HRMS. One erasure beats a 20-page policy.

Book a 30-minute DPDPA discovery call →

Sources

  1. Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), MeitY — Sections 2, 5–9, 33 and the Schedule: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
  2. Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), MeitY — Rules 6, 7, 9, 10, 13: https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf
  3. DPDP Act commencement, G.S.R. 843(E), 13 November 2025, MeitY: https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf
  4. Press Information Bureau — Digital Personal Data Protection (DPDP) Rules, 2025: https://www.pib.gov.in/PressReleasePage.aspx?PRID=2190014
  5. CERT-In — Directions under section 70B(6) of the IT Act, 2000, No. 20(3)/2022-CERT-In, 28 April 2022: https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf

This article is operational commentary for HR heads and founders, not legal advice and not a determination that any named employer’s biometric or background-verification programme is lawful. Confirm positions with qualified Indian counsel. Sector employment, labour, and UIDAI rules continue in parallel with the DPDPA.

FAQ

No. Biometric attendance DPDPA analysis is fact-specific. If the biometric method is genuinely necessary for an employment purpose, Section 7(i) may apply without consent, subject to Section 8. If a less intrusive method (card, PIN, roster) serves the same purpose, valid Section 6 consent is needed — and that consent must be free.

Not as a categorical yes. Proportionate, role-relevant checks aimed at safeguarding the employer from loss or liability may sit under Section 7(i). Intrusive or role-irrelevant screening needs Section 6 consent. The BGV vendor is a Data Processor; the employer stays the Data Fiduciary under Section 8(2).

Does DPDPA keep the old SPDI sensitive personal data category for employee biometrics?

No. The DPDPA does not carry forward the old SPDI sensitive personal data category. Biometric templates are personal data under Section 2(t), protected by purpose limitation, Rule 6 security, and Section 8(7) erasure — not by a special tier.

Do contract workers and visitors fall under Section 7(i) for gate biometrics?

No. Section 7(i) covers specified processing for employment purposes. Contract workers and visitors are not your employees. Gate biometrics for them need another ground — usually Section 6 — plus a Section 8(2) contract with the device vendor.