Most of HR does not run on consent, and that is the point
18 September 2026
Sec. 7(i) makes employment a legitimate use, so most HR processing is not consent-based. Safeguards, breach duties and your vendor chain still apply.
HR teams reading the DPDP Act usually reach for a consent form. In most cases that is the wrong instrument, and using it creates a problem rather than solving one.
Sec. 7 lists certain legitimate uses, processing that does not require consent. Clause (i) covers processing for the purposes of employment, and processing related to safeguarding the employer from loss or liability — the examples given include preventing corporate espionage and maintaining confidentiality of trade secrets.
Payroll, attendance, provisioning, performance records, statutory filings: these sit inside employment. Asking for consent implies the employee could refuse, and consent given under the imbalance of an employment relationship is the weakest possible footing for something you are going to do regardless.
What still applies, and it is most of the Act
Legitimate use removes the consent question, and with it the two duties that hang off consent. It leaves the rest where it was.
Notice under Sec. 5 is not the instrument here. Sec. 5(1) attaches the notice to a request for consent under Sec. 6, so processing resting on Sec. 7(i) never triggers it. What does attach is Sec. 8(9) with Rule 9: the business contact information of the Data Protection Officer, or of whoever can answer questions about the processing, published prominently and mentioned in every response to a communication exercising rights. Telling employees what is processed and why is worth doing on its own merits, in a language each of them reads — which in a distributed Indian workforce is not a rhetorical point. It is good practice, not a Sec. 5 duty.
Security safeguards under Sec. 8(5) apply to the HR system, which typically holds identity documents, bank details, health declarations and family information in one place.
Breach reporting under Sec. 8(6) applies. An HRMS breach is a reportable breach.
Rights under Sec. 13 and Sec. 14 apply; Sec. 11 and Sec. 12 follow the consent. The access right in Sec. 11(1) runs against a Data Fiduciary to whom the Data Principal has previously given consent, including consent as referred to in Sec. 7(a), and Sec. 12(1) limits correction, completion, updating and erasure the same way. Processing that rests on Sec. 7(i) alone sits outside both. Grievance redressal under Sec. 13 and nomination under Sec. 14 carry no such limitation, Sec. 8(10) requires the grievance mechanism regardless, and Rule 14 requires the means of making a request to be published and a grievance answered within a period not exceeding ninety days.
The line is not tidy in practice, and that is the part worth getting right. An employer that asked for consent, or that holds data an employee volunteered for a specified purpose under Sec. 7(a) without indicating she does not consent, is inside Sec. 11 and Sec. 12 for that processing. An access request from a departing employee is still the one that finds the gaps, because answering it means knowing which basis each part of the record sits on.
Where employment stops
The clause covers employment. It does not stretch to everything an employer might like to do with employee data.
Wellness apps, engagement analytics, productivity monitoring, optional benefits marketed by a partner, alumni communications after exit — none of these is obviously "for the purposes of employment", and each needs its own analysis and, where it falls outside, consent that is genuinely refusable.
Candidate data is its own question. An applicant is not yet an employee, and the rejected ones never will be. Retaining a CV database for future roles is a purpose, and a purpose needs a basis and a retention answer.
The vendors are the exposure
An HR stack is a chain of processors: payroll bureau, background verification, benefits administrator, HRMS, engagement tool, exit-interview platform. Each receives personal data under your responsibility as Data Fiduciary.
Two questions decide whether that chain is defensible. Was the purpose you gave each vendor one the employee was noticed about? And when an obligation ends — an employee leaves, a vendor is replaced, a retention period expires — does the instruction to stop actually reach them, with something recording that it did?
Retention after exit
Some employment records must be kept under other law, and the Act accommodates retention a law requires. That accommodation covers the specific records the law names. It does not license keeping the whole HRMS profile, the engagement scores and the CCTV footage on the same schedule because they happen to live in the same system.
Questions people ask
- Is employee data covered by the DPDP Act?
- Yes. Employee personal data is personal data. But Sec. 7(i) makes employment a legitimate use, covering processing for the purposes of employment and for safeguarding the employer from loss or liability, so consent is not the basis for most of it.
- Do we need employee consent for payroll and attendance?
- Generally no. Those sit within the Sec. 7(i) legitimate use, and the Sec. 5 notice duty attaches to a request for consent rather than to this processing. Sec. 8 still applies: safeguards under Sec. 8(5), breach intimation under Sec. 8(6), erasure once the purpose is no longer served under Sec. 8(7), and a grievance mechanism under Sec. 8(10), answered within a period not exceeding ninety days under Rule 14(3).