Why employee data is fully within scope
Section 2(t) defines personal data as any data about an individual who is identifiable by or in relation to such data. Employee records — name, contact details, Aadhaar, PAN, salary, designation, performance ratings, medical records, leave records — are personal data.
The employer is the Data Fiduciary: the entity that determines the purpose and means of processing (Section 2(i)). Where an HR vendor (payroll processor, background-check agency, benefits platform) processes data on the employer’s behalf, that vendor is a Data Processor under Section 2(k).
Consent versus legitimate use for employment data
Section 7(i) of the DPDPA lists employment-related legitimate uses that allow processing without consent. These include purposes related to recruitment, onboarding, termination of employment, provision of any service or benefit, verification of attendance, and assessment of performance. Processing for these purposes does not require separate consent from the employee.
Processing for purposes NOT listed in Section 7(i) — for example, sharing employee photos on social media, using employee data for marketing, or profiling beyond performance assessment — requires consent under Section 6.
The practical challenge is mapping each HR processing activity to its lawful ground. The RoPA must distinguish between Section 7(i) activities and those requiring consent.
Background verification and reference checks
Background verification involves collecting personal data from third parties (previous employers, educational institutions, criminal-records databases). The employer must determine the lawful ground for each element:
- Employment verification and reference checks: likely covered by Section 7(i) as recruitment-related processing.
- Criminal-record checks: may require consent depending on the source and the sector regulation.
- The background-check agency is a Data Processor. Section 8(1) requires a valid contract. Section 8(2) requires the processor to process data only for the purpose for which it was shared.
Biometric attendance and access control
Biometric data (fingerprints, iris scans, facial recognition) is personal data. Section 7(i) lists verification of attendance as a legitimate use. However, the security safeguards under Section 8(5) and Rule 6 apply with particular force to biometric data because of the harm from a breach.
Rule 6 requires reasonable security safeguards including encryption, access controls and logging. Biometric templates must be stored securely, access must be restricted, and logs must be retained for at least one year.
Employee monitoring and surveillance
Monitoring employee email, internet use, device activity or location raises the question of lawful ground. Section 7(i) covers assessment of performance, but continuous surveillance may exceed what is necessary for that purpose.
The notice under Section 5 must clearly describe any monitoring. The Data Principal must know what data is collected and for what purpose. Covert monitoring without notice is difficult to reconcile with Section 5.
Cross-border transfers of HR data
Many employers in India are subsidiaries of foreign companies. HR data is often transferred to the parent company for global payroll, benefits, performance management or workforce analytics. Section 16 restricts transfers to countries not notified as restricted by the Central Government. Rule 15 prescribes the conditions.
The employer must identify every HR data transfer, the destination country, the recipient and the purpose, and record these in the RoPA.
How AMLEGALS helps with HR data compliance
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder & Managing Partner. The team includes Rohit Lalwani, Associate Partner, who works on DPDPA compliance.
The team maps every HR processing activity to its lawful ground, reviews vendor contracts (payroll, background check, benefits), advises on biometric data safeguards, and designs the employee privacy notice.

