Employee Data Under DPDPA: What HR Teams Can (and Cannot) Do Without Consent
HR systems are dense with personal data — identification, salary, health declarations, performance notes, biometic attendance, family details for insurance. The DPDPA applies to all of it, and "our employees signed an offer letter" is not a compliance strategy.
The employment legitimate use — Section 7(i)
The Act permits processing without consent for the purposes of employment or to safeguard the employer from loss or liability — think payroll, statutory deductions, attendance, performance management, workplace safety and preventing corporate espionage.
This is genuinely useful: routine HR operations do not need consent artefacts. But the exemption covers processing necessary for the employment relationship — not everything an employer might fancy doing with employee data.
Where Section 7(i) runs out
- Background verification of candidates — a candidate is not yet an employee; BGV generally needs consent or another Section 7 ground.
- Alumni/ex-employee data — once employment ends, the purpose narrows to legal retention duties (payroll records, PF) plus defined needs like reference verification. Indefinite retention of full HR files fails Section 8's purpose-limitation and erasure duties.
- Marketing to employees, wellness analytics, selling engagement data — outside employment purposes; consent required.
- Extensive surveillance — monitoring beyond what is proportionate to a legitimate employment aim invites both DPDPA scrutiny (detriment, minimisation) and reputational damage.
Obligations that apply regardless of basis
Legal basis only answers "may we process?". You still owe employees: security safeguards (s.8(5)) over some of the most sensitive data you hold; breach notification if HR data leaks; accuracy; erasure when the purpose is served; and functioning rights handling — an employee can file an access or correction request like any other Data Principal (see rights workflow).
And your HRMS, payroll vendor and insurance broker are processors — DPDPA obligations must flow down contractually, with you accountable for their failures.
The HR compliance sprint
- Inventory employee data across HRMS, payroll, spreadsheets and mailboxes.
- Map each processing activity to Section 7(i) or to consent.
- Fix retention: define schedules per record class; automate deletion.
- Paper the processors with DPDPA-grade DPAs.
- Publish an internal privacy notice and a rights channel for staff.
Drishti discovers and classifies employee data across connected systems, and Lekhak drafts the internal notices. Start with the free readiness assessment.
Data Adhikaar Editorial Team
DPDPA Compliance Specialists, Qodequay Technologies
Get DPDPA-ready before the enforcement window closes.
Start with a free readiness assessment, or book a demo of the Data Adhikaar agent fabric.
Or call +91 98226 28174