Ninebloomninebloom
Blog
Enterprise & IT

Workplace Privacy Under DPDP: Navigating Section 7(i) Employment Uses, Biometrics, and ATS Retention

Does employment provide blanket consent for employee tracking? Discover the statutory boundaries of Section 7(i), facial biometrics, and candidate CV archiving.


Workplace Privacy Under DPDP: Navigating Section 7(i) Employment Uses, Biometrics, and ATS Retention

Human resources, talent acquisition, and corporate operations departments handle vast volumes of personal data: candidate resumes, Aadhaar and PAN cards, biometric facial vectors, payroll records, medical insurance dependent details, and employee productivity telemetry.

Historically, employers assumed that an employment contract gave management unrestricted authority over employee data. The DPDP Act, 2023 decisively alters this dynamic, establishing strict statutory boundaries around how organizations collect, monitor, and retain workplace data.

Section 7(i) Demystified: The Employment Grounds for Processing

Under Section 7(i) of the Act, personal data may be processed without explicit consent for 'purposes of employment or those related to safeguarding the employer from loss or liability, such as prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property, classified information or provision of any service or benefit sought by a Data Principal who is an employee.'

However, this exception is frequently misconstrued as a blank check. The statutory test requires strict proportionality and operational necessity:

  • Permitted Under Section 7(i): Processing bank account details for payroll, maintaining attendance logs, providing provident fund (EPF) records, and monitoring corporate email accounts to prevent trade secret exfiltration.
  • NOT Permitted Without Explicit Consent: Invasive keystroke logging on personal devices, tracking employee location outside working hours, sharing employee contact directories with external commercial partners, or processing biometric data for non-essential administrative purposes.

Biometric Attendance & Facial Recognition Under Scrutiny

Many corporate offices, factories, and IT campuses enforce mandatory facial recognition attendance systems. Biometric identifiers are unique, permanent, and immutable; if a biometric hash database is compromised, the affected individuals cannot reset their faces or fingerprints.

Under the DPDP Act, employers must demonstrate that biometric data collection is strictly necessary and that less invasive alternatives (e.g., RFID cards, mobile check-ins) are insufficient. Storing raw biometric images in unencrypted cloud repositories violates Section 8(5) safeguards, carrying penalties up to ₹250 crore.

The ATS Resume Hoarding Trap: Storage Limitation Violations

Corporate talent acquisition teams and recruitment agencies routinely archive millions of candidate resumes in Applicant Tracking Systems (ATS) for years after a job opening has closed. Candidates who were rejected 5 years ago remain indexed in company databases without their knowledge.

Under the storage limitation mandate in Section 8(7), personal data must be erased once the specified purpose has been fulfilled. Warehousing candidate CVs indefinitely without affirmative consent or refreshed purpose is an immediate regulatory violation.

Candidate & Employee Data VectorPermissible Processing GroundMandatory Retention / Purge Policy
Unselected Candidate ResumesConsent (Section 6)Purge within 6 months of rejection unless explicit consent given for talent pool
Employee Payroll & Tax RecordsStatutory Requirement (Income Tax / EPF)Retain for mandatory 7-year audit statutory window, then archive
Biometric Attendance VectorsSection 7(i) / Explicit ConsentEncrypt with HSM tokens; delete immediately upon employee separation
Health Insurance Dependent RecordsEmployee Benefit ConsentPurge upon employee offboarding

How Ninebloom Modernizes Workplace Privacy Governance

Ninebloom delivers a comprehensive HR & Workplace Privacy Suite that safeguards corporate operations while respecting employee rights:

  • Automated Candidate Consent Workflows: Integrates with Greenhouse, Lever, Workday, and custom job portals to capture verified talent consent with automated expiry timers.
  • Automated Resume TTL Purging: Automatically anonymizes or permanently purges unselected applicant records after the declared hiring cycle.
  • Employee Data Vault: Employees log in to view company-retained records, manage dependent benefits consent, and update banking information self-service.
  • Biometric Encryption & Masking: Secures attendance pipelines with tokenized surrogate keys, preventing the persistent storage of raw biometric facial vectors.
  • Grievance Redressal Portal: Dedicated internal portal for employee privacy inquiries and corrections, fulfilling statutory internal dispute mechanisms.

Respecting workplace privacy fosters trust, attracts top-tier talent, and mitigates substantial enterprise liability. Progressive employers treat privacy not as an administrative burden, but as a foundational pillar of ethical corporate culture.

Take Action on Your Compliance

Ready to Implement DPDP Compliance for Your Organisation?

Don't wait for a Board inquiry or a regulatory penalty under Section 33. Ninebloom automates the entire compliance lifecycle from tracker discovery to cryptographic consent proofs.

DPDP Compliance Audit & Board Readiness →44-section gap analysis, 72h breach drill, and signed Board Audit Pack.Consent Management Platform & VPC →22 Indian languages, verifiable parental consent for minors, and hash-chained ledger.Automated Data Mapping & ROPA →Scan client & server trackers, map third-party processors, and export live inventories.