Employee data protection India in one line: DPDPA Section 7(i) covers HR processing that employment genuinely requires — without consent — while Section 6 consent governs everything optional, and both need fixing before 13 May 2027.

TL;DR

  • The most common HR mistake under the Digital Personal Data Protection Act, 2023 is collecting consent for everything. For processing genuinely necessary for employment, Section 7(i) is usually the correct lawful ground — no consent needed.
  • Section 7(i) is not unlimited. It covers specified processing for employment purposes or safeguarding the employer from loss or liability. Optional, secondary or unrelated uses fall outside it.
  • Where consent is the ground, Section 6 demands that it be free, specific, informed, unconditional, unambiguous and given through clear affirmative action — a hard test inside an employment relationship.
  • The DPDPA has no “sensitive personal data” tier: biometrics and salary data are personal data like everything else, protected by Section 8 fiduciary duties.
  • Breaches run on two clocks where applicable: CERT-In within 6 hours, detailed DPB report within 72 hours. Security failures risk penalties up to ₹250 crore per instance.
  • Substantive obligations phase in, with remaining duties commencing on 13 May 2027. HR should fix lawful-ground mapping now, not in Q1 2027.

What does employee data protection India require from HR teams?

Employee data protection India is now governed by the DPDPA, 2023 and the DPDP Rules, 2025 — and your employees are Data Principals just like your customers. Every HR file, payroll record, CCTV feed and biometric log is digital personal data, and your company is the Data Fiduciary for all of it — a status we unpack in If You Have Employees, You’re Already a Data Fiduciary.

Here is the one mistake most HR teams make: treating consent as the default lawful basis for every employee-data activity. Teams roll out blanket consent forms at onboarding — “I consent to the processing of my personal data for all employment-related purposes” — and assume the job is done.

That instinct is backwards. The DPDPA gives employers a purpose-built ground: Section 7(i) permits processing for the purposes of employment, or for safeguarding the employer from loss or liability — such as preventing corporate espionage, protecting trade secrets, or providing a service or benefit an employee has sought. Where Section 7(i) genuinely applies, what HR needs is a clear notice and disciplined data governance, not manufactured consent. Blanket consent is worse than unnecessary: it implies employees can refuse or withdraw from processing the employment itself requires, and it may fail the Section 6 validity test anyway.

Section 7(i) is a legitimate use, not an exemption from the Act. Three things follow:

First, necessity is the gate. Ask whether the specific processing is genuinely necessary for an employment purpose — running payroll, meeting statutory obligations, administering leave, managing performance. If HR could do its job without the data, Section 7(i) is a shaky foundation.

Second, Section 8 still applies in full. Purpose limitation, data minimisation, accuracy, reasonable security safeguards, breach intimation, and erasure once the purpose is served remain binding regardless of lawful ground. Notice and transparency obligations remain relevant too: even where Section 5’s consent-linked notice is not triggered, a clear employee privacy notice is the practical baseline for demonstrating compliance.

Third, Section 7(i) does not cover everything HR does. Marketing to employees, publishing profiles on your website, sharing data with group companies for their own purposes, or reusing HR data for unrelated analytics are not employment necessities. Those need their own lawful ground — usually Section 6 consent.

Employee data protection India lawful-ground decision tree

Not categorically — and beware anyone selling you a categorical rule. The DPDPA does not classify biometric or financial information as “sensitive personal data”; that special-category framework belonged to the old SPDI Rules, 2011 and was not carried into the 2023 Act. The analysis is fact-specific:

Employee-data activityTypical purposeLikely lawful-ground analysisRequired controls
Recruitment applicationsAssessing candidatesVoluntary provision for a benefit sought; Section 7(i) analysis for applicants entering employmentNotice, retention limits for rejected candidates, erasure
Pre-employment background verificationSafeguarding employer from loss or liabilityFact-specific: proportionate checks may fall under Section 7(i); intrusive or role-irrelevant checks need consentDocumented necessity assessment, minimisation, vendor contracts
Payroll and statutory benefitsWages, PF, ESI, TDSSection 7(i) — core employment necessityAccess controls, processor agreements, accuracy
Attendance recordsWage calculation, leaveSection 7(i)Minimisation, defined retention
Biometric attendanceAttendance integrityFact-specific: Section 7(i) if genuinely necessary; consent if a less intrusive method serves the purposeNecessity assessment, encryption, strict retention, alternative mechanism where consent-based
Performance recordsAppraisals, promotionsSection 7(i)Accuracy, access limited to need
Workplace monitoringSecurity, loss preventionFact-specific: proportionate monitoring may fall under Section 7(i); pervasive monitoring needs careful justificationTransparency notice, proportionality review, audit trail
Health or insurance informationGroup insurance, statutory leaveSection 7(i) for benefits the employee has sought; consent for optional wellness programmesStrict minimisation, insurer contracts, confidentiality
Emergency contactsEmployee safetySection 7(i); note the contact is a third-party Data PrincipalMinimisation, purpose-locked use
Former-employee recordsStatutory retention, referencesSection 7(i) / legal obligation for mandated retention; erase the restRetention schedule, erasure evidence
Employee photographs and public profilesWebsite, marketingOptional and unrelated to employment necessity — Section 6 consentGenuine opt-in, easy withdrawal, no workplace consequence for refusal

The pattern: mandatory employment processing generally rests on Section 7(i) with notice and governance; optional, secondary or unrelated processing needs valid consent.

Section 6 requires consent that is free, specific, informed, unconditional, unambiguous and signalled by clear affirmative action — for a specified purpose, limited to data necessary for that purpose. Inside an employment relationship, “free” is the hard part of any DPDPA employee consent request. When refusing means losing a job offer, being marked absent, or facing manager displeasure, the consent is arguably coerced — and coerced consent is invalid consent. You would have built your processing on a ground that collapses under scrutiny, when Section 7(i) plus a proper notice might have been the defensible answer all along.

This is also why consent, where you do use it, must be operationally real: the employee can refuse without employment consequences, can withdraw as easily as they consented, and processing actually stops on withdrawal. If your systems cannot deliver that, you were never really relying on consent.

What notice must an employer give its employees under the DPDPA?

Where you request consent, Section 5 requires a notice describing the personal data, the purpose of processing, how rights can be exercised, and how to complain to the Data Protection Board. Where you rely on Section 7(i), issue a plain-language employee privacy notice anyway: what you collect, why, who it is shared with, how long you keep it, and whom to contact. It costs little, evidences Section 8 accountability, and is what a DPB inquiry will ask for first. Keep the two documents distinct — a notice informs; a consent request asks. For the Act’s foundational structure before the HR specifics, start with the Privigo fundamentals guide.

How should HR govern employee data across its lifecycle?

Map every stage from application to alumni, assign owners, and record the lawful ground for each activity:

DPDPA HR compliance employee-data lifecycle

AreaOwnerStatus
Recruitment and background checksHR + Legal
Employee privacy noticesHR + Legal
Payroll and benefits processorsHR + Finance
Biometric attendance assessmentHR + Security
Access controls and audit trailsIT + Security
Retention and erasure scheduleHR + Legal
Data Principal request workflowHR Operations
Breach-response ownershipCISO + HR + Legal

Two clarifications founders often miss. Rule 13 audits and DPIAs apply only to notified Significant Data Fiduciaries — most mid-size companies are not SDFs, though the underlying hygiene is still worth adopting as a risk control. And breach response has two parallel clocks where applicable: CERT-In reporting within 6 hours of noticing a cyber incident, and a detailed report to the DPB within 72 hours. An HR-system breach starts both.

This is where Privigo is built differently from checklist tools. Employee PII sits in a sealed PII vault, with tokenisation outside the vault so payroll, HRMS and analytics systems work on tokens, never raw identifiers. Consent records are cryptographically immutable, and every access, purpose and retention decision lands in an evidentiary-grade audit trail — so when the DPB asks “prove who accessed this employee’s data, on what ground, and why it still exists,” you have provable purpose, access and retention controls, not a policy PDF.

Who owns DPDPA HR compliance before 13 May 2027?

Not “Legal, eventually.” HR owns the data, IT owns the systems, Legal owns the grounds — and the founder owns the deadline. Remaining substantive duties commence on 13 May 2027, and lawful-ground mapping, notice rollout and retention clean-up take quarters, not weeks. For the company-wide readiness picture beyond HR, see our DPDPA compliance roadmap for Indian SMBs.

Closing

Three things HR can finish this quarter:

  1. Run a lawful-ground audit. List every employee-data activity, tag it Section 7(i), Section 6 consent, or “no valid ground — stop or fix,” and document the necessity reasoning.
  2. Ship a real employee privacy notice. Plain language, covering data, purposes, sharing, retention and grievance contact — separate from any consent requests.
  3. Fix retention for leavers and rejected candidates. Define what statute requires you to keep, schedule erasure for the rest, and keep evidence that erasure happened.

Book a 30-minute HR compliance call with Privigo

Frequently Asked Questions

No, not always. Section 7(i) of the DPDPA permits specified processing for employment purposes or to safeguard the employer from loss or liability, without consent. Where processing goes beyond what is necessary for employment and no other legitimate use applies, Section 6 consent is required.

No. Biometric attendance must be assessed on its facts: if it is genuinely necessary for an employment purpose, Section 7(i) may apply without consent, subject to Section 8 obligations. If it exceeds what employment requires, valid Section 6 consent is needed.

Does the DPDPA classify employee biometrics as sensitive personal data?

No. The DPDPA, 2023 applies one uniform definition of personal data under Section 2(t) and does not retain a separate sensitive personal data category. Biometric and financial information are personal data, protected through purpose limitation, security and other Section 8 duties, not a special tier.

What is the maximum penalty for failing to protect employee data?

Up to ₹250 crore per instance under Section 33 read with the Schedule, for failing to take the reasonable security safeguards required by Section 8(5) — and employee data breaches count the same as customer data breaches.

Sources

  1. Digital Personal Data Protection Act, 2023 — Ministry of Electronics and Information Technology
  2. Digital Personal Data Protection Rules, 2025 — MeitY notified text
  3. Press Information Bureau — DPDP framework press note (November 2025)

This article provides general information about employee data protection India and is not legal advice; consult qualified counsel for decisions specific to your organisation.