DPDP Act for HR teams: employee data, section 7 and what needs consent
By Abhijeet Singh · Reviewed by dpdprules.org source verificationPublished · Last reviewed 3 min read
The short answer
Not for core employment purposes. Section 7(i) of the DPDP Act 2023 lists employment among the certain legitimate uses for which personal data may be processed without consent: for the purposes of employment or those related to safeguarding the employer from loss or liability, such as preventing corporate espionage, maintaining confidentiality of trade secrets, intellectual property or classified information, or providing a service or benefit sought by an employee. Payroll, attendance and core HR administration sit naturally inside that ground. But the exemption is purpose based, not a blanket for anything touching staff: processing outside employment purposes, such as selling employee data or unrelated marketing, needs its own ground, and the fiduciary obligations of section 8, including security safeguards, breach intimation and erasure, apply to employee data regardless of the ground. These provisions sit in the commencement group computed to 13 May 2027, interpretation until officially confirmed.
The most common DPDP question inside companies is not about customers. It is HR asking: do we now need every employee's consent to run payroll? The Act's answer is more precise, and more interesting, than a yes or no.
The employment ground: section 7(i)
Section 4 permits processing personal data on exactly two kinds of ground: consent, or the certain legitimate uses listed in section 7. Employment is one of them, in the Act's own words:
"(i) for the purposes of employment or those related to safeguarding the employer from loss or liability, such as prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property, classified information or provision of any service or benefit sought by a Data Principal who is an employee."
Section 7(i) of the DPDP Act 2023.
That single clause carries most of what an HR function does. Processing for the purposes of employment reasonably covers the administration an employment relationship requires: payroll, attendance, leave, performance management, statutory deductions and filings. The safeguarding limb covers protective processing, and the Act's own examples are telling: corporate espionage prevention, trade secret confidentiality, intellectual property and classified information. The final limb covers services or benefits an employee actually asks for.
What the employment ground does not do
Three edges matter, and each is where an HR programme built on "section 7 covers us" goes wrong.
It is purpose based, not person based. The ground attaches to employment purposes, not to employees as a category. Processing employee data for something unconnected to employment, such as monetising it or unrelated marketing, is outside the clause and needs its own ground, which in most cases means consent under section 6.
It does not switch off the fiduciary duties. Whatever ground you rely on, section 8 still applies in full to employee data: reasonable security safeguards under section 8(5), breach intimation to affected employees and the Board under section 8(6), erasure when the purpose is no longer served under section 8(7), and responsibility for what your payroll and HR software vendors do as Data Processors. An employer that leaks its own HR database owes its employees the same breach intimations it would owe customers.
Candidates and former employees need thought. The clause speaks of employment and of a Data Principal who is an employee. How far it stretches to recruitment pipelines before employment begins, and to records kept after it ends, is a judgment call the text does not settle expressly; treat those flows as requiring their own analysis rather than assuming the clause covers them.
What HR should actually do
Map the HR data flows and tag each with its ground: employment purposes under section 7(i), employee requested benefits under the same clause, or consent for anything outside them. Where consent is the ground, remember it must meet the full section 6 standard: free, specific, informed, unconditional and unambiguous, which on a reasonable reading means an employee can refuse without losing what the employment itself provides. Then run the section 8 duties across all of it: a retention and erasure position for employee records, breach response that includes staff data, and processor contracts with your HR and payroll vendors.
These provisions sit in the commencement group computed to 13 May 2027, interpretation until officially confirmed, which makes this a planning window rather than a live obligation. The company compliance plan sequences the work, with HR flows treated as one of the processing activities it walks through.
Related tool
Applicability Checker
Find out whether the DPDP framework likely applies to your organisation and processing.
Open
Related tool
Compliance Plan
Generate one company level action plan and see the work for your role first.
Open
Section 7, official text with sources →Section 8, official text with sources →
Sources cited on this page
- [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 7, p. 7. Published 11 August 2023. Official source ↗ · Official requirement · Verified 21 August 2026Section 7(i), the employment clause of the certain legitimate uses. Section 7 begins on Gazette page 6; the quoted clause (i) appears on page 7.
- [2]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 4, p. 4. Published 11 August 2023. Official source ↗ · Official requirement · Verified 21 August 2026Section 4: personal data may be processed only for a lawful purpose for which the Data Principal has given her consent or for certain legitimate uses.
- [3]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 8, p. 7. Published 11 August 2023. Official source ↗ · Official requirement · Verified 21 August 2026Section 8: general obligations of the Data Fiduciary, including reasonable security safeguards under section 8(5), breach intimation under section 8(6) and erasure under section 8(7), apply to processing regardless of the ground relied on.
- [4]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), (c), p. 2. Published 13 November 2025. Official source ↗ · Official requirement · Verified 21 August 2026Notification G.S.R. 843(E) places sections 3 to 5, most of section 6, and sections 7 to 17 in the group that comes into force eighteen months from the date of publication of the notification gazette.
- [5]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), p. 1. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 21 August 2026The calendar date 13 May 2027 is computed from the printed publication date of 13 November 2025 plus eighteen months and is presented as interpretation until officially confirmed.