Every Indian Employee Record Is Personal Data Under DPDPA — There Is No Employment Exemption
The DPDPA does not exempt employee data from its scope. Name, address, Aadhaar, PAN, salary, performance reviews, medical records, biometric attendance — all personal data, all within scope, all requiring compliance architecture.
Multinational employers with Indian employees — whether through subsidiaries, branches, GICs, or EOR arrangements — process personal data of Indian Data Principals in the employment context. The DPDPA does not create an employment exemption. Every piece of employee data — from recruitment and onboarding through performance management, payroll, benefits administration, and exit — is personal data requiring compliance with the full statutory framework.
For global employers, the challenge is compounded by cross-border data flows inherent in multinational HR operations. Global HRIS platforms, centralised payroll systems, expatriate management, and group insurance programmes all involve transferring Indian employee data outside India. Each transfer must comply with Section 16.
Legal Basis for Employee Data Processing
The legal basis for most employee data processing is Section 7(a) — processing necessary for compliance with any law. This covers statutory obligations: provident fund contributions, tax deductions, ESI, labour law compliance. But Section 7(a) does not cover all HR processing. Performance management, employee engagement surveys, internal communications monitoring, and career development analytics are not mandated by law — they require consent under Section 6.
Statutory HR processing
Section 7(a) legitimate use — PF, ESI, TDS, labour law compliance. Consent not required but notice under Section 5 still mandatory.
Discretionary HR processing
Section 6 consent required — performance analytics, engagement surveys, learning platform data, internal social platforms.
Biometric data
Biometric attendance systems process personal data. Consent required unless mandated by establishment-level law.
Key DPDPA Obligations
| Obligation | Section / Rule | Description |
|---|---|---|
| Employee notice | Section 5 | Clear notice to every Indian employee specifying all processing purposes and manner of exercising rights |
| Legal basis mapping | Sections 6, 7 | Each HR processing activity mapped to consent or specific legitimate use |
| HRIS cross-border compliance | Section 16 | Global HRIS and payroll data transfers verified against restricted jurisdiction notification |
| Exit and data retention | Section 8(7) | Purpose-mapped retention schedules — statutory retention where required, erasure where purpose fulfilled |
| Vendor HR tech DPAs | Section 8(2) | DPAs with HRIS providers, payroll vendors, background verification agencies, and benefits administrators |
Request a Cross-Border Employer DPDPA Compliance Assessment
A confidential assessment of your India workforce data governance — HR processing legal basis, HRIS compliance, cross-border transfers, and vendor governance.
Request a Confidential Briefing
Our data privacy counsel will reach out within one working day.
Frequently Asked Questions
Does DPDPA apply to employee data?
Yes. The DPDPA does not create an employment exemption. All personal data of Indian employees — including HR records, payroll data, performance evaluations, biometric attendance, and medical records — is within scope. The employer is a Data Fiduciary for employee data under Section 2(i).
Can employee data be transferred to the global headquarters?
Yes, subject to Section 16 compliance. If the headquarters is located in a jurisdiction not on the restricted list, the transfer is permitted. However, the employer must map all data categories transferred, document the legal basis, and ensure the global HRIS infrastructure does not route data through restricted jurisdictions.
