Skip to content
🚨 DPDP Rules 2025: Compliance Deadline 36 weeks awayRead handbook β†’

DPDP Act Employee Data: India's Biggest Ungoverned Dataset, and an 'Employment Purposes' Exemption That Covers Less Than HR Thinks

Nasscom's new advisory to India's 2,117 GCCs says HR data needs a privacy reset. Section 7(1)(i) is narrower than employers assume.

D
DPDPBot Research Team
πŸ• 12 min read

#DPDP Act Employee Data: India's Biggest Ungoverned Dataset, and an 'Employment Purposes' Exemption That Covers Less Than HR Thinks

Nasscom has told India's Global Capability Centres that their HR function needs a privacy reset β€” not a policy refresh, a reset. In an advisory published to its GCC community on 2 August, the industry body's argument lands on a single uncomfortable point: DPDP Act employee data obligations apply in full to payroll, attendance, performance and background-verification records, and most GCCs have no idea whether that data is moving through a legal framework or simply moving because it always has.

That distinction matters more than it sounds. The employers reading this advisory are overwhelmingly leaning on one statutory ground β€” Section 7(1)(i) of the Digital Personal Data Protection Act, the "purposes of employment" legitimate use β€” as a blanket permission slip for everything HR touches. It isn't one. The exemption is a closed, narrowly drafted clause, and a meaningful share of what a modern GCC does with employee data falls outside it.

#What Nasscom actually told the GCC sector

The Nasscom community advisory frames the problem as governance rather than paperwork. Its central claim is that with the DPDP Act and the DPDP Rules, 2025 both in force, "employment data can no longer be viewed only as an internal HR record β€” it is regulated personal data." For GCCs, it says, employee data has historically been treated as an operational HR resource, and the governance question now is whether that data "is being processed through a controlled legal framework, or is it simply flowing through systems because the organisation has always worked that way."

The prescription is unglamorous and specific: run an employment data audit, rewrite HR privacy notices, review vendor contracts, document cross-border flows, create retention rules, and train HR and line managers. The advisory is blunt that this cannot be parked with legal β€” HR owns operational execution, working with IT, legal and security.

The scale explains the urgency. The Zinnov–Nasscom GCC Landscape 2026 report counts 2,117 GCCs in India employing 2.36 million professionals and generating roughly USD 98.4 billion in revenue, with more than 506 Forbes Global 2000 companies operating a centre here. That is a workforce dataset larger than the customer base of many of the fintechs and health platforms that have absorbed most of the DPDP commentary so far β€” and it is concentrated in entities whose primary function is processing data on behalf of a foreign parent.

#The Section 7(1)(i) exemption is a closed list, not a safe harbour

Section 7 of the DPDP Act sets out "legitimate uses" β€” grounds on which a data fiduciary may process personal data without consent. Clause (i) permits processing "for the purposes of employment or those related to safeguarding the employer from loss or liability," including protection of trade secrets and prevention of espionage.

Read plainly, that covers the operational core of HR. Practitioner analysis, including Tsaaro's breakdown of the employment ground, places recruitment screening, payroll and statutory benefits, attendance tracking, performance and disciplinary records, workplace investigations, and IP-protection monitoring inside the exemption. Employers are on firm ground there, and they do not need to chase consent for it.

The problem is the edge, and the edge is wider than most HR teams have mapped. The same analysis puts outside the exemption: voluntary programmes such as wellness initiatives, optional surveys and charitable drives; analysis of employee data for purposes unrelated to the employment relationship; data pulled from third-party sources for unrelated profiling; and processing that touches minors or guardianship. Add the things GCCs have quietly industrialised since 2023 β€” engagement analytics, attrition-prediction models, AI-assisted performance scoring, sentiment analysis on internal collaboration tools β€” and the question stops being academic. None of that is obviously "for the purposes of employment" in the sense of administering the employment relationship, and none of it protects the employer from loss or liability in the way the clause contemplates.

This is where India's design differs sharply from the framework most GCC parents already comply with. As practitioners have noted comparing the two regimes, the GDPR's "legitimate interests" is an open-ended basis subject to a proportionality and balancing assessment, while the DPDP Act uses a closed list of legitimate uses precisely to limit discretion. A GCC that inherits its parent's legitimate-interests assessment and assumes the analysis transfers has made a category error: there is no balancing test available under Section 7(1)(i) to stretch it. Either the processing is for the purposes of employment, or it needs consent.

And consent, in an employment context, is the harder path. Section 6 requires consent that is free, specific, informed, unconditional and unambiguous. A clause buried in an offer letter signed four years ago does not meet that standard β€” a point the Nasscom advisory makes directly, noting that "a generic line in the employment agreement signed years ago is unlikely to meet this standard." Nor does an employer easily obtain freely given consent from someone whose appraisal it controls; that structural imbalance is why GDPR Recital 43 treats consent as suspect where there is a clear power asymmetry, and why Article 88 lets member states legislate specially for employment. India's answer was to hand employers a statutory ground instead. Employers who push borderline processing back onto consent are relying on the weakest instrument available to them.

#Biometric attendance: where the professional advice openly splits

The clearest live ambiguity in DPDP Act employee data compliance is the fingerprint scanner at the office door.

One reading places biometric attendance squarely inside Section 7(1)(i) β€” it is attendance tracking, an employment purpose, no consent required. Another body of advice treats biometrics as requiring explicit, purpose-specific, revocable consent regardless of employment context; HR Hub's compliance guidance takes exactly that line, insisting employees be informed before collection and that consent be documented and transparently presented.

Both positions are defensible on the statutory text, because the DPDP Act β€” unlike the GDPR's Article 9 β€” does not create a special category for biometric data at all. There is no heightened basis to satisfy and no explicit-consent requirement to trigger. What survives is Section 8's purpose limitation, data minimisation and the Section 8(5) obligation to take reasonable security safeguards, breach of which carries the Act's steepest penalty: up to β‚Ή250 crore.

For a GCC running biometric or facial-recognition attendance across several thousand employees, the practical answer is not to pick a side and hope. It is to document why biometrics rather than a card or app-based alternative, retain templates rather than raw images, set a hard retention clock, and offer a non-biometric fallback for employees who object. That posture is defensible under either reading. "Our vendor said it was fine" is defensible under neither.

#Three laws now sit on top of the same payroll record

The DPDP Act does not operate alone, and Section 38 says so explicitly: it applies "in addition to and not in derogation of" other laws. For GCCs, the practical consequence is that one operational change to how payroll runs can trigger three separate legal reviews.

The four Labour Codes came into force on 21 November 2025 β€” eight days after the DPDP Rules were notified. That collision is now working its way through HR operations, as recent analysis of interlinked cross-border compliance sets out: the revised wage definition changes gratuity exposure, fixed-term employment classification changes statutory liability, and remote and seconded workers trigger obligations in more than one jurisdiction. Layer on international tax β€” transfer pricing on intercompany services, TDS on foreign vendor payments, permanent-establishment risk from an India-based team serving global operations β€” and the same employee record is simultaneously a privacy artefact, a labour-law artefact and a tax artefact.

The recommendation that emerges is one integrated compliance map: data flows, worker classifications, countries involved and cross-border payments, feeding coordinated controls rather than three teams each solving their own slice. Very few Indian GCCs have that map today.

#Cross-border HR flows and the negative list nobody has seen

Almost every GCC transfers employee data out of India β€” to a global HRMS, a parent-company data lake, an offshore payroll processor, or a group insurer. Section 16 of the DPDP Act permits this by default: transfers are allowed to any country except those the Central Government restricts. As of early August 2026, no restricted-country list has been notified. Transfers are broadly permitted.

That is a licence with a fuse in it. Two things bite later. First, Rule 12 imposes additional obligations on Significant Data Fiduciaries, including measures to prevent transfer outside India of categories of personal data and related traffic data that the government may specify. Large GCCs β€” particularly those processing at scale for financial, telecom or health-sector parents β€” are plausible SDF candidates once designations are notified. Second, Section 16 preserves stricter localisation rules that sit in other Indian laws, and those keep arriving: the Department of Telecommunications' Telecommunications (Authorisation for Telecommunication Network) Rules, 2026, notified on 20 July, require under Rule 25(3) that every system of a telecommunication network and all associated data and logs sit inside India, with no copy routed or shared abroad. Sectoral localisation is tightening while the DPDP negative list stays empty.

The compliance instruction for now is narrow and doable: disclose the transfer in the HR notice, identify the recipient country and purpose, and hold the contractual chain to your processors β€” including the parent, if the parent is processing on your instruction. An organisation that has documented its flows can absorb a negative list when it lands. One that has not will be reverse-engineering its own HRMS under deadline.

Recruitment is where employee data leaves the building fastest, and where the least governance usually applies. BGV agencies, education verifiers, criminal-record checkers and identity vendors typically receive a candidate's Aadhaar, PAN, address history and employment record β€” often before that person is an employee at all, and often under a consent form drafted well before the DPDP Rules existed.

Current BGV compliance guidance is unambiguous about the technical path: authentication should run through a licensed AUA/KUA channel, raw Aadhaar numbers should stay masked, and DigiLocker pulls with masked eKYC tokens should replace photocopy collection. Each consent click should map to a specific named purpose, which is exactly what the Act's purpose-limitation principle expects.

The governance gap is the vendor contract. Under the DPDP Act the employer remains the data fiduciary and the BGV agency is a processor β€” which means the employer carries the liability for the processor's failures. The Nasscom advisory's line on this is the right one: vendor contracts need explicit obligations on confidentiality, security, breach reporting, deletion, access restriction and purpose limitation. Where a BGV vendor is holding candidate files indefinitely "for audit," that is the employer's retention violation, and the employer's β‚Ή250 crore exposure if those files leak.

Employees and candidates also have teeth here. Section 11 gives a data principal the right to a summary of the personal data a fiduciary holds and the identities of the other fiduciaries with whom it has been shared. An ex-employee who asks a GCC to enumerate every third party that received their file is asking a question most HR teams currently cannot answer.

#The clock, and what has to happen before it runs out

The staggered commencement is now the only calendar that matters. The DPDP Rules, 2025 were notified on 13 November 2025. Rules 1–2 and 17–21 took effect immediately. Rule 4, governing Consent Manager registration, takes effect one year on β€” 13 November 2026. Rules 3 and 5–16 and 22–23, which carry the substantive notice, security-safeguard, breach-reporting, retention and data-principal-rights machinery, take effect at eighteen months: 13 May 2027.

The enforcement backdrop changed quietly in June. The Data Protection Board of India, described through the first half of 2026 as an enforcer that wasn't there, had its Chairperson and Members appointed on 6 June 2026, and its grievance portal is live. 2026 remains a soft-enforcement year of guidance rather than fines. But a Board that exists, with a live intake channel, is a Board that can receive an employee complaint β€” and employee complaints are cheap to file and awkward to defend, because the complainant already has documentary evidence of the relationship.

Breach obligations are the sharpest near-term risk. Affected individuals must be notified without delay, and the Board must receive an intimation followed by a detailed report within 72 hours. A payroll vendor compromise or a misconfigured HRMS export is a reportable event, and the 72-hour window assumes an organisation already knows which records were exposed and whose they were. That capability is built during the audit, not during the incident.

Six things to do between now and May 2027, in order: inventory every system and vendor holding employee data, from HRMS and payroll to attendance hardware, BGV agencies, insurers and IT service providers; classify each processing purpose as inside or outside Section 7(1)(i), and be honest about the analytics; rewrite the HR privacy notice as a standalone DPDP notice rather than an employment-contract clause; re-paper processor contracts with breach, deletion and purpose-limitation terms; set and enforce retention clocks, including at vendors; and build the data-principal request workflow before someone uses it.

#The reset is a governance decision, not an HR project

The reason Nasscom's advisory is worth reading is not that its checklist is novel β€” most of it has appeared in DPDP guidance since 2023. It is that the body representing India's GCC sector is now saying, in public, that employee data governance in these organisations is not currently defensible, and that the people who own the fix are HR and the leadership team rather than counsel.

For 2.36 million people working in Indian GCCs, that is the difference between a right on paper and a right that functions. For the employers, it is the difference between a nine-month runway and a scramble.

If you are mapping employment data flows, classifying processing purposes against Section 7, or working out what a DPDP-grade HR notice actually has to say, our resources library covers the notice, retention and processor-contract requirements in detail. If your organisation is evaluating consent infrastructure ahead of the 13 November 2026 registration date β€” including for the HR processing that genuinely does need consent β€” start with our consent manager guide.

The employers who treat this as a records exercise will produce a binder. The ones who treat it as a governance question will be able to answer, in 72 hours, whose data was in the export.

Automate your DPDP compliance

Capture consent, honour data principal rights, and stay audit-ready β€” all in one platform.

Start free trial