Employee data protection India in one line: DPDPA Section 7(i) covers HR processing that employment genuinely requires — without consent — while Section 6 consent governs everything optional, and both need fixing before 13 May 2027.
TL;DR
- The most common HR mistake under the Digital Personal Data Protection Act, 2023 is collecting consent for everything. For processing genuinely necessary for employment, Section 7(i) is usually the correct lawful ground — no consent needed.
- Section 7(i) is not unlimited. It covers specified processing for employment purposes or safeguarding the employer from loss or liability. Optional, secondary or unrelated uses fall outside it.
- Where consent is the ground, Section 6 demands that it be free, specific, informed, unconditional, unambiguous and given through clear affirmative action — a hard test inside an employment relationship.
- The DPDPA has no “sensitive personal data” tier: biometrics and salary data are personal data like everything else, protected by Section 8 fiduciary duties.
- Breaches run on two clocks where applicable: CERT-In within 6 hours, detailed DPB report within 72 hours. Security failures risk penalties up to ₹250 crore per instance.
- Substantive obligations phase in, with remaining duties commencing on 13 May 2027. HR should fix lawful-ground mapping now, not in Q1 2027.
What does employee data protection India require from HR teams?
Employee data protection India is now governed by the DPDPA, 2023 and the DPDP Rules, 2025 — and your employees are Data Principals just like your customers. Every HR file, payroll record, CCTV feed and biometric log is digital personal data, and your company is the Data Fiduciary for all of it — a status we unpack in If You Have Employees, You’re Already a Data Fiduciary.
Here is the one mistake most HR teams make: treating consent as the default lawful basis for every employee-data activity. Teams roll out blanket consent forms at onboarding — “I consent to the processing of my personal data for all employment-related purposes” — and assume the job is done.
That instinct is backwards. The DPDPA gives employers a purpose-built ground: Section 7(i) permits processing for the purposes of employment, or for safeguarding the employer from loss or liability — such as preventing corporate espionage, protecting trade secrets, or providing a service or benefit an employee has sought. Where Section 7(i) genuinely applies, what HR needs is a clear notice and disciplined data governance, not manufactured consent. Blanket consent is worse than unnecessary: it implies employees can refuse or withdraw from processing the employment itself requires, and it may fail the Section 6 validity test anyway.
When can employers process employee data without consent under Section 7(i)?
Section 7(i) is a legitimate use, not an exemption from the Act. Three things follow:
First, necessity is the gate. Ask whether the specific processing is genuinely necessary for an employment purpose — running payroll, meeting statutory obligations, administering leave, managing performance. If HR could do its job without the data, Section 7(i) is a shaky foundation.
Second, Section 8 still applies in full. Purpose limitation, data minimisation, accuracy, reasonable security safeguards, breach intimation, and erasure once the purpose is served remain binding regardless of lawful ground. Notice and transparency obligations remain relevant too: even where Section 5’s consent-linked notice is not triggered, a clear employee privacy notice is the practical baseline for demonstrating compliance.
Third, Section 7(i) does not cover everything HR does. Marketing to employees, publishing profiles on your website, sharing data with group companies for their own purposes, or reusing HR data for unrelated analytics are not employment necessities. Those need their own lawful ground — usually Section 6 consent.
Do biometric attendance and background checks require employee consent?
Not categorically — and beware anyone selling you a categorical rule. The DPDPA does not classify biometric or financial information as “sensitive personal data”; that special-category framework belonged to the old SPDI Rules, 2011 and was not carried into the 2023 Act. The analysis is fact-specific:
| Employee-data activity | Typical purpose | Likely lawful-ground analysis | Required controls |
|---|---|---|---|
| Recruitment applications | Assessing candidates | Voluntary provision for a benefit sought; Section 7(i) analysis for applicants entering employment | Notice, retention limits for rejected candidates, erasure |
| Pre-employment background verification | Safeguarding employer from loss or liability | Fact-specific: proportionate checks may fall under Section 7(i); intrusive or role-irrelevant checks need consent | Documented necessity assessment, minimisation, vendor contracts |
| Payroll and statutory benefits | Wages, PF, ESI, TDS | Section 7(i) — core employment necessity | Access controls, processor agreements, accuracy |
| Attendance records | Wage calculation, leave | Section 7(i) | Minimisation, defined retention |
| Biometric attendance | Attendance integrity | Fact-specific: Section 7(i) if genuinely necessary; consent if a less intrusive method serves the purpose | Necessity assessment, encryption, strict retention, alternative mechanism where consent-based |
| Performance records | Appraisals, promotions | Section 7(i) | Accuracy, access limited to need |
| Workplace monitoring | Security, loss prevention | Fact-specific: proportionate monitoring may fall under Section 7(i); pervasive monitoring needs careful justification | Transparency notice, proportionality review, audit trail |
| Health or insurance information | Group insurance, statutory leave | Section 7(i) for benefits the employee has sought; consent for optional wellness programmes | Strict minimisation, insurer contracts, confidentiality |
| Emergency contacts | Employee safety | Section 7(i); note the contact is a third-party Data Principal | Minimisation, purpose-locked use |
| Former-employee records | Statutory retention, references | Section 7(i) / legal obligation for mandated retention; erase the rest | Retention schedule, erasure evidence |
| Employee photographs and public profiles | Website, marketing | Optional and unrelated to employment necessity — Section 6 consent | Genuine opt-in, easy withdrawal, no workplace consequence for refusal |
The pattern: mandatory employment processing generally rests on Section 7(i) with notice and governance; optional, secondary or unrelated processing needs valid consent.
Why can employee consent fail the “freely given” test?
Section 6 requires consent that is free, specific, informed, unconditional, unambiguous and signalled by clear affirmative action — for a specified purpose, limited to data necessary for that purpose. Inside an employment relationship, “free” is the hard part of any DPDPA employee consent request. When refusing means losing a job offer, being marked absent, or facing manager displeasure, the consent is arguably coerced — and coerced consent is invalid consent. You would have built your processing on a ground that collapses under scrutiny, when Section 7(i) plus a proper notice might have been the defensible answer all along.
This is also why consent, where you do use it, must be operationally real: the employee can refuse without employment consequences, can withdraw as easily as they consented, and processing actually stops on withdrawal. If your systems cannot deliver that, you were never really relying on consent.
What notice must an employer give its employees under the DPDPA?
Where you request consent, Section 5 requires a notice describing the personal data, the purpose of processing, how rights can be exercised, and how to complain to the Data Protection Board. Where you rely on Section 7(i), issue a plain-language employee privacy notice anyway: what you collect, why, who it is shared with, how long you keep it, and whom to contact. It costs little, evidences Section 8 accountability, and is what a DPB inquiry will ask for first. Keep the two documents distinct — a notice informs; a consent request asks. For the Act’s foundational structure before the HR specifics, start with the Privigo fundamentals guide.
How should HR govern employee data across its lifecycle?
Map every stage from application to alumni, assign owners, and record the lawful ground for each activity:
| Area | Owner | Status |
|---|---|---|
| Recruitment and background checks | HR + Legal | ☐ |
| Employee privacy notices | HR + Legal | ☐ |
| Payroll and benefits processors | HR + Finance | ☐ |
| Biometric attendance assessment | HR + Security | ☐ |
| Access controls and audit trails | IT + Security | ☐ |
| Retention and erasure schedule | HR + Legal | ☐ |
| Data Principal request workflow | HR Operations | ☐ |
| Breach-response ownership | CISO + HR + Legal | ☐ |
Two clarifications founders often miss. Rule 13 audits and DPIAs apply only to notified Significant Data Fiduciaries — most mid-size companies are not SDFs, though the underlying hygiene is still worth adopting as a risk control. And breach response has two parallel clocks where applicable: CERT-In reporting within 6 hours of noticing a cyber incident, and a detailed report to the DPB within 72 hours. An HR-system breach starts both.
This is where Privigo is built differently from checklist tools. Employee PII sits in a sealed PII vault, with tokenisation outside the vault so payroll, HRMS and analytics systems work on tokens, never raw identifiers. Consent records are cryptographically immutable, and every access, purpose and retention decision lands in an evidentiary-grade audit trail — so when the DPB asks “prove who accessed this employee’s data, on what ground, and why it still exists,” you have provable purpose, access and retention controls, not a policy PDF.
Who owns DPDPA HR compliance before 13 May 2027?
Not “Legal, eventually.” HR owns the data, IT owns the systems, Legal owns the grounds — and the founder owns the deadline. Remaining substantive duties commence on 13 May 2027, and lawful-ground mapping, notice rollout and retention clean-up take quarters, not weeks. For the company-wide readiness picture beyond HR, see our DPDPA compliance roadmap for Indian SMBs.
Closing
Three things HR can finish this quarter:
- Run a lawful-ground audit. List every employee-data activity, tag it Section 7(i), Section 6 consent, or “no valid ground — stop or fix,” and document the necessity reasoning.
- Ship a real employee privacy notice. Plain language, covering data, purposes, sharing, retention and grievance contact — separate from any consent requests.
- Fix retention for leavers and rejected candidates. Define what statute requires you to keep, schedule erasure for the rest, and keep evidence that erasure happened.
Book a 30-minute HR compliance call with Privigo
Frequently Asked Questions
Do employers need consent to process employee data under the DPDPA?
No, not always. Section 7(i) of the DPDPA permits specified processing for employment purposes or to safeguard the employer from loss or liability, without consent. Where processing goes beyond what is necessary for employment and no other legitimate use applies, Section 6 consent is required.
Does biometric attendance always require employee consent?
No. Biometric attendance must be assessed on its facts: if it is genuinely necessary for an employment purpose, Section 7(i) may apply without consent, subject to Section 8 obligations. If it exceeds what employment requires, valid Section 6 consent is needed.
Does the DPDPA classify employee biometrics as sensitive personal data?
No. The DPDPA, 2023 applies one uniform definition of personal data under Section 2(t) and does not retain a separate sensitive personal data category. Biometric and financial information are personal data, protected through purpose limitation, security and other Section 8 duties, not a special tier.
What is the maximum penalty for failing to protect employee data?
Up to ₹250 crore per instance under Section 33 read with the Schedule, for failing to take the reasonable security safeguards required by Section 8(5) — and employee data breaches count the same as customer data breaches.
Sources
- Digital Personal Data Protection Act, 2023 — Ministry of Electronics and Information Technology
- Digital Personal Data Protection Rules, 2025 — MeitY notified text
- Press Information Bureau — DPDP framework press note (November 2025)
This article provides general information about employee data protection India and is not legal advice; consult qualified counsel for decisions specific to your organisation.
