---
title: "Employee data under the DPDP Act: HR, payroll and workplace processing"
url: https://dpdp.myndsolution.com/wiki/guides/employee-data-hr-and-payroll/
description: "What the DPDP Act and Rules say about processing employee personal data, including the employment legitimate use, notice, security, erasure and payroll…"
kind: guide
updated: 2026-09-09
text_type: analysis
publisher: MYND Integrated Solutions
license: Official Government of India texts are reproduced verbatim (public domain / open government data). Interpretation is CC BY 4.0, MYND Integrated Solutions.
disclaimer: Not legal advice. Official text prevails over any interpretation.
html_version: https://dpdp.myndsolution.com/wiki/guides/employee-data-hr-and-payroll/
---
# Employee data under the DPDP Act: HR, payroll and workplace processing

> This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.


An employee is a Data Principal like any other, and an employer processing her salary, attendance or background records is a Data Fiduciary. The Act does not carve employment out. It gives employers one legitimate use to rely on instead of consent, and leaves the general obligations in place.

## The employment legitimate use, as printed

[Section 4(1)](/wiki/act/section-4/) allows processing only for a lawful purpose and on one of two footings: consent, or one of the "certain legitimate uses" in [section 7](/wiki/act/section-7/). A lawful purpose is "any purpose which is not expressly forbidden by law" ([section 4(2)](/wiki/act/section-4/)).

[Section 7(i)](/wiki/act/section-7/) is the clause that speaks to employers. A Data Fiduciary may process personal data:

> "for the purposes of employment or those related to safeguarding the employer from loss or liability, such as prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property, classified information or provision of any service or benefit sought by a Data Principal who is an employee."

Two halves sit in that sentence. The first, "for the purposes of employment", is broad and undefined in the Act. The second is anchored to protecting the employer from loss or liability, with examples: corporate espionage, confidentiality of trade secrets, intellectual property and classified information, and a service or benefit the employee sought. Nothing in [section 7](/wiki/act/section-7/) adds a purpose-limitation or retention test for clause (i), so [section 8](/wiki/act/section-8/) does that work.

## What still applies when consent is not the basis

Relying on [section 7(i)](/wiki/act/section-7/) removes the need for consent. It does not remove [section 8](/wiki/act/section-8/), which binds a Data Fiduciary whatever the ground.

| Obligation | Where it sits | What it requires |
| --- | --- | --- |
| Overall responsibility | [Section 8(1)](/wiki/act/section-8/) | The employer answers for processing done by it or on its behalf, whatever any agreement says |
| Accuracy | [Section 8(3)](/wiki/act/section-8/) | Completeness, accuracy and consistency where the data is likely to be used for a decision affecting the employee or disclosed to another Data Fiduciary |
| Security | [Section 8(5)](/wiki/act/section-8/), [rule 6](/wiki/rules/rule-6/) | Reasonable safeguards, with a minimum list: encryption, masking or tokens, access controls, logging and monitoring, backups, one year of log retention, and security terms in processor contracts |
| Breach reporting | [Section 8(6)](/wiki/act/section-8/), [rule 7](/wiki/rules/rule-7/) | Tell each affected employee without delay through her registered channel, and the Board without delay, with fuller detail within seventy-two hours |
| Erasure | [Section 8(7)](/wiki/act/section-8/) | Erase, and make processors erase, once the specified purpose is no longer served, unless a law requires retention |
| Contact point | [Section 8(9)](/wiki/act/section-8/), [rule 9](/wiki/rules/rule-9/) | Publish contact information for the Data Protection Officer, if applicable, or a person who can answer questions about the processing |
| Grievances | [Section 8(10)](/wiki/act/section-8/), [rule 14(3)](/wiki/rules/rule-14/) | An effective mechanism, with a published response period not exceeding ninety days |

The erasure duty repays a careful read. [Section 8(7)(a)](/wiki/act/section-8/) is triggered by the employee withdrawing consent, or by the point at which "it is reasonable to assume that the specified purpose is no longer being served", whichever is earlier. Where processing rests on [section 7(i)](/wiki/act/section-7/) there is no consent to withdraw, so the second trigger governs.

## Notice, when consent is the basis

Some workplace processing will sit outside [section 7(i)](/wiki/act/section-7/) and rest on consent. Where it does, every consent request must be accompanied or preceded by a notice telling the employee the personal data and the purpose it will be processed for, how she may exercise her rights under [section 6(4)](/wiki/act/section-6/) and [section 13](/wiki/act/section-13/), and how she may complain to the Board ([section 5(1)](/wiki/act/section-5/)). It must be available in English or any language in the Eighth Schedule to the Constitution ([section 5(3)](/wiki/act/section-5/)).

[Rule 3](/wiki/rules/rule-3/) sets out how that notice must read. It has to be understandable on its own, independently of anything else the employer has made available, and must give "in clear and plain language, a fair account of the details necessary to enable the Data Principal to give specific and informed consent", including at minimum an itemised description of the personal data and the specified purposes. It must also give the link and other means for withdrawing consent as easily as it was given, exercising rights and complaining to the Board.

Consent itself must be "free, specific, informed, unconditional and unambiguous with a clear affirmative action", limited to the data necessary for the specified purpose ([section 6(1)](/wiki/act/section-6/)). If it becomes a question in a proceeding, the burden of proving notice and consent lies on the Data Fiduciary ([section 6(10)](/wiki/act/section-6/)). Where consent was taken before commencement, the employer must give the notice as soon as reasonably practicable and may keep processing until it is withdrawn ([section 5(2)](/wiki/act/section-5/)).

## Employee rights, and how they meet the legitimate uses

Employees hold the same rights as any other Data Principal, but the wording of two matters here. Both [section 11(1)](/wiki/act/section-11/) and [section 12(1)](/wiki/act/section-12/) attach the right to a Data Fiduciary "to whom she has previously given consent, including consent as referred to in clause (a) of section 7". Clause (a) is the legitimate use where the individual voluntarily provided her data. Clause (i), the employment clause, is not mentioned, so on the text those two rights run against consent-based and clause (a) processing.

The other two carry no such qualifier. Grievance redressal covers "any act or omission of such Data Fiduciary or Consent Manager regarding the performance of its obligations in relation to the personal data of such Data Principal or the exercise of her rights" ([section 13(1)](/wiki/act/section-13/)), and the right to nominate someone to act on death or incapacity is unqualified ([section 14(1)](/wiki/act/section-14/)). The obligations in [section 8](/wiki/act/section-8/) apply whichever ground the processing rests on.

## Payroll vendors and other processors

A payroll bureau, benefits administrator or background-check firm processing employee data on the employer's instructions is a [Data Processor](/wiki/glossary/data-processor/): "any person who processes personal data on behalf of a Data Fiduciary" ([section 2(k)](/wiki/act/section-2/)). The employer stays the Data Fiduciary and answers for what the processor does ([section 8(1)](/wiki/act/section-8/)).

[Section 8(2)](/wiki/act/section-8/) is the contract requirement, and its wording is narrow: a Data Fiduciary may involve a Data Processor "to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract". Two other provisions reach processors directly. Security safeguards must cover processing done by a processor on the fiduciary's behalf ([section 8(5)](/wiki/act/section-8/)), and [rule 6(1)(f)](/wiki/rules/rule-6/) requires the contract to provide for them. On erasure, the employer must "cause its Data Processor to erase any personal data that was made available" to it ([section 8(7)(b)](/wiki/act/section-8/)).

## The Third Schedule does not list employers

[Rule 8(1)](/wiki/rules/rule-8/) sets a fixed erasure clock, but only for a Data Fiduciary "who is of such class and is processing personal data for such corresponding purposes as are specified in Third Schedule". The [Third Schedule](/wiki/rules/schedule-3/) names three classes and no others: an e-commerce entity with not less than two crore registered users in India, an online gaming intermediary with not less than fifty lakh, and a social media intermediary with not less than two crore. Each carries a three-year period, and [rule 8(2)](/wiki/rules/rule-8/) requires at least forty-eight hours' warning before erasure.

Employers, as employers, are not among those classes. The three-year clock and the forty-eight-hour notice do not reach workplace processing unless the organisation independently falls into one of the three. What does apply to every Data Fiduciary is [rule 8(3)](/wiki/rules/rule-8/): personal data, associated traffic data and other logs must be kept for at least one year from the date of processing, for the purposes in the [Seventh Schedule](/wiki/rules/schedule-7/), unless another law requires longer. The open-ended duty in [section 8(7)](/wiki/act/section-8/) still applies on its own terms.

## Dates that matter

Nothing in the operative parts of the Act reaches an employer yet. [G.S.R. 843(E)](/wiki/notifications/gsr-843e-2025/) brought the definitions and the Board provisions into force on 13 November 2025. On 13 May 2027, eighteen months from publication, sections 3 to 5, most of section 6 and sections 7 to 17 come into force, which is when [section 7(i)](/wiki/act/section-7/), [section 8](/wiki/act/section-8/) and the employee rights bind. [Rule 3](/wiki/rules/rule-3/) and rules 5 to 16 start the same day ([rule 1(4)](/wiki/rules/rule-1/)).

## Key provisions

- [Section 4](/wiki/act/section-4/): grounds for processing
- [Section 5](/wiki/act/section-5/), [rule 3](/wiki/rules/rule-3/): notice where consent is the basis
- [Section 6](/wiki/act/section-6/): valid consent, and who must prove it
- [Section 7(i)](/wiki/act/section-7/): the employment legitimate use
- [Section 8](/wiki/act/section-8/): general obligations of a Data Fiduciary
- [Section 11](/wiki/act/section-11/) to [section 14](/wiki/act/section-14/): employee rights
- [Rule 6](/wiki/rules/rule-6/): reasonable security safeguards
- [Rule 7](/wiki/rules/rule-7/): breach intimation
- [Rule 8](/wiki/rules/rule-8/), [Third Schedule](/wiki/rules/schedule-3/): retention classes, one-year log rule
- [G.S.R. 843(E)](/wiki/notifications/gsr-843e-2025/): commencement
