Human resources, talent acquisition, and corporate operations departments handle vast volumes of personal data: candidate resumes, Aadhaar and PAN cards, biometric facial vectors, payroll records, medical insurance dependent details, and employee productivity telemetry.
Historically, employers assumed that an employment contract gave management unrestricted authority over employee data. The DPDP Act, 2023 decisively alters this dynamic, establishing strict statutory boundaries around how organizations collect, monitor, and retain workplace data.
Section 7(i) Demystified: The Employment Grounds for Processing
Under Section 7(i) of the Act, personal data may be processed without explicit consent for 'purposes of employment or those related to safeguarding the employer from loss or liability, such as prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property, classified information or provision of any service or benefit sought by a Data Principal who is an employee.'
However, this exception is frequently misconstrued as a blank check. The statutory test requires strict proportionality and operational necessity:
- Permitted Under Section 7(i): Processing bank account details for payroll, maintaining attendance logs, providing provident fund (EPF) records, and monitoring corporate email accounts to prevent trade secret exfiltration.
- NOT Permitted Without Explicit Consent: Invasive keystroke logging on personal devices, tracking employee location outside working hours, sharing employee contact directories with external commercial partners, or processing biometric data for non-essential administrative purposes.
Biometric Attendance & Facial Recognition Under Scrutiny
Many corporate offices, factories, and IT campuses enforce mandatory facial recognition attendance systems. Biometric identifiers are unique, permanent, and immutable; if a biometric hash database is compromised, the affected individuals cannot reset their faces or fingerprints.
Under the DPDP Act, employers must demonstrate that biometric data collection is strictly necessary and that less invasive alternatives (e.g., RFID cards, mobile check-ins) are insufficient. Storing raw biometric images in unencrypted cloud repositories violates Section 8(5) safeguards, carrying penalties up to ₹250 crore.
The ATS Resume Hoarding Trap: Storage Limitation Violations
Corporate talent acquisition teams and recruitment agencies routinely archive millions of candidate resumes in Applicant Tracking Systems (ATS) for years after a job opening has closed. Candidates who were rejected 5 years ago remain indexed in company databases without their knowledge.
Under the storage limitation mandate in Section 8(7), personal data must be erased once the specified purpose has been fulfilled. Warehousing candidate CVs indefinitely without affirmative consent or refreshed purpose is an immediate regulatory violation.
| Candidate & Employee Data Vector | Permissible Processing Ground | Mandatory Retention / Purge Policy |
|---|---|---|
| Unselected Candidate Resumes | Consent (Section 6) | Purge within 6 months of rejection unless explicit consent given for talent pool |
| Employee Payroll & Tax Records | Statutory Requirement (Income Tax / EPF) | Retain for mandatory 7-year audit statutory window, then archive |
| Biometric Attendance Vectors | Section 7(i) / Explicit Consent | Encrypt with HSM tokens; delete immediately upon employee separation |
| Health Insurance Dependent Records | Employee Benefit Consent | Purge upon employee offboarding |
How Ninebloom Modernizes Workplace Privacy Governance
Ninebloom delivers a comprehensive HR & Workplace Privacy Suite that safeguards corporate operations while respecting employee rights:
- Automated Candidate Consent Workflows: Integrates with Greenhouse, Lever, Workday, and custom job portals to capture verified talent consent with automated expiry timers.
- Automated Resume TTL Purging: Automatically anonymizes or permanently purges unselected applicant records after the declared hiring cycle.
- Employee Data Vault: Employees log in to view company-retained records, manage dependent benefits consent, and update banking information self-service.
- Biometric Encryption & Masking: Secures attendance pipelines with tokenized surrogate keys, preventing the persistent storage of raw biometric facial vectors.
- Grievance Redressal Portal: Dedicated internal portal for employee privacy inquiries and corrections, fulfilling statutory internal dispute mechanisms.
Respecting workplace privacy fosters trust, attracts top-tier talent, and mitigates substantial enterprise liability. Progressive employers treat privacy not as an administrative burden, but as a foundational pillar of ethical corporate culture.
Ready to Implement DPDP Compliance for Your Organisation?
Don't wait for a Board inquiry or a regulatory penalty under Section 33. Ninebloom automates the entire compliance lifecycle from tracker discovery to cryptographic consent proofs.