Back to Sectors & Impact

HR / Employment Data

DPDPA compliance for HR & employment - employee data processing under Section 7(i), consent for background checks, payroll data retention, and exit data erasure.

7 min read

Sector Overview

Every organisation processes employee personal data - from recruitment and onboarding through payroll, benefits, performance management, and exit. The DPDPA applies to all digital processing of employee personal data, making HR functions a critical compliance area across all industries. The DPDPA recognises employment as a legitimate use for processing without explicit consent, but this exemption has boundaries. Organisations must understand where the legitimate use exemption applies and where explicit consent remains necessary.

Key DPDPA Provisions for HR

Legitimate Uses (Section 7): The DPDPA recognises processing for employment purposes - including payroll, benefits administration, performance management, and occupational health - as a legitimate use that does not require explicit consent. This is one of the most significant provisions for HR functions. Section 5-6 (Consent): Processing employee data for purposes beyond employment - such as marketing, employee wellness programmes, social media management, or alumni relations - requires explicit consent. Section 8 (Obligations): Employers must implement security safeguards for employee data, maintain accuracy (particularly important for payroll and benefits), and establish retention policies. Data collected during employment should be erased when the purpose is fulfilled post-separation. Section 11-12 (Data Principal Rights): Employees retain their rights as Data Principals, including the right to access information about processing, request correction of inaccurate data, and request erasure of data no longer necessary for its purpose. Rule 14 (Grievance Redressal): Employers must provide employees with a web-based grievance mechanism. Rule 14 prescribes a maximum 90-day window for general grievances, but for employees this interacts with Standing Orders and labour laws. The DPDP Rules 2025 also indicate that for Significant Data Fiduciaries (SDFs), the operational expectation for resolving internal grievances is significantly shorter (typically 30 days) before the Data Principal can approach the Data Protection Board.

Compliance Considerations

1. Scope of Legitimate Use: Employment processing covers core HR functions - payroll, statutory benefits, leave management, performance reviews, and occupational safety. Non-core processing such as employee engagement surveys, wellness programmes, and social media requires separate consent. 2. Background Verification: Pre-employment background checks involve processing personal data of candidates. Consent should be obtained during the recruitment process. Third-party verification agencies are data processors requiring appropriate contractual safeguards. 3. Workplace Monitoring: CCTV surveillance, email monitoring, internet usage tracking, and GPS tracking of company vehicles involve processing personal data. Section 7(i) explicitly allows processing for "safeguarding the employer from loss or liability" (e.g., preventing corporate espionage or IP theft), which legalises a broad range of monitoring without separate consent. However, employers must still provide a Notice (per Section 5) covering monitoring activities and ensure proportionality. 4. Data Retention Post-Employment: Employee data should be retained only for the period required by applicable labour laws and statutory obligations. Once these periods expire and no other legitimate use applies, the data must be erased. 5. Contractor and Gig Worker Data: Organisations engaging contractors, consultants, and gig workers must determine the appropriate legal basis for processing their data. The employment legitimate use may not apply to non-employees. 6. Cross-Border HR Data: Multinational employers sharing employee data with global headquarters or shared service centres must comply with cross-border transfer restrictions.

Practical Compliance Checklist

*Note: This checklist is interpretive guidance derived from the DPDPA's general provisions (Sections 5-8, 7(i), 11-12, Rules 6, 14). It should be validated by legal counsel for your specific organisational context.* • Map all employee data processing activities and classify by legitimate use vs. consent • Update employment contracts and offer letters with DPDPA privacy notices • Implement consent mechanisms for non-employment processing (wellness, surveys, social) • Review background verification vendor contracts for DPDPA compliance • Establish data retention schedules aligned with labour law requirements • Implement web-based employee grievance mechanism per Rule 14 • Review workplace monitoring practices for proportionality and transparency • Upgrade security safeguards for HRIS and payroll systems per Rule 6 • Address cross-border data transfers for multinational HR operations • Train HR teams on DPDPA obligations and employee data rights

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.