Shiftelio
Payroll and Compliance12 min read · 3,211 words

The DPDP Act and Your Attendance Data: Why Asking Staff for Consent Makes Your Position Worse

Every vendor checklist says get employee consent for biometric and GPS attendance. Section 7(i) means you do not need it, and asking switches on rights you would not otherwise owe.

By Oscar Jamuar, Founder, Shiftelio

If you have looked into what India's data protection law means for your attendance system, you have almost certainly been told to do one thing: collect written consent from every employee before you scan a fingerprint, take a selfie or record a location. It appears in vendor checklists, in HR newsletters and in most of the articles ranking for this topic today.

It is the wrong advice. Not merely unnecessary, which would be harmless, but a change that leaves you in a weaker legal position than doing nothing. The Digital Personal Data Protection Act already gives employers a basis to process attendance data without asking, and the rights an employee can exercise against you are written so that they attach to consent based processing. Ask for consent you did not need, and you switch those rights on over your own statutory register.

This article walks through what the Act actually says, which parts bind you no matter what you do, and what an Indian SME should have in place before the runway closes.

What the DPDP Act Is, and the Dates That Actually Matter

The Digital Personal Data Protection Act, 2023 is India's first comprehensive data protection statute. It sat without operative rules for two years. The Digital Personal Data Protection Rules were notified on 13 November 2025, and that notification started the clock everyone is now working against.

Three dates are worth writing down:

  • 13 November 2025. Rules notified. The framework becomes real, with obligations phased in rather than switched on at once.
  • 13 November 2026. The Consent Manager framework becomes operational, and the first year of the implementation period closes. Supervision is widely expected to sharpen from here.
  • Mid May 2027. End of the roughly 18 month implementation phase. The day to day obligations, notice and consent operations, breach reporting and rights handling, are enforceable in full.

The gap matters for planning but not for complacency. The penalties in the Schedule to the Act are not scaled to company size: up to Rs 250 crore for failing to take reasonable security safeguards, and up to Rs 200 crore for failing to report a breach. A twelve person firm and a listed company face the same ceiling.

And attendance data is squarely in scope. The Act covers digital personal data, which is your biometric templates, your GPS coordinates, your check in selfies, your payroll file and your leave records.

Section 7 of the Act is headed "Certain legitimate uses", and it opens: "A Data Fiduciary may process personal data of a Data Principal for any of following uses". Clause (i) is the one employers need:

"for the purposes of employment or those related to safeguarding the employer from loss or liability, such as prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property, classified information or provision of any service or benefit sought by a Data Principal who is an employee."
Section 7(i), Digital Personal Data Protection Act, 2023

Recording who worked, when they started, when they finished and where they were when they said so is processing "for the purposes of employment". So is running that record into payroll, calculating overtime, and keeping the muster roll a labour inspector can ask for. None of it needs consent.

There is a second consequence that is easy to miss. The notice obligation in Section 5 is framed around requests for consent: a notice accompanies or precedes the consent request. Where you are not asking for consent, that particular statutory trigger does not fire. You may still want to tell your staff what you collect, and further down this article argues that you should, but it is a decision about disputes and trust rather than a statutory box.

Here is the part that inverts the standard advice. Read the rights chapter closely and you find that the two headline employee rights are written as consequences of consent, not of processing.

Section 11(1), the right of access, begins: "The Data Principal shall have the right to obtain from the Data Fiduciary to whom she has previously given consent, including consent as referred to in clause (a) of section 7 ... for processing of personal data". The right runs against a fiduciary the person consented to, and the only non consent basis pulled in is clause (a), the voluntary provision case. Clause (i), employment, is not in that list.

Section 12(1) does the same for correction and erasure: the right applies to personal data "for the processing of which she has previously given consent". Section 12(2) opens "A Data Principal, who has consented to the processing of her personal data by a Data Fiduciary, shall have the right to".

Section 6(4) then makes consent withdrawable at any time, with the ease of withdrawal comparable to the ease of giving it, and Section 6(6) requires that on withdrawal the fiduciary shall, within a reasonable time, cease processing, unless the processing without consent is required or authorised by law.

Now put the employer in the picture. You run GPS attendance under Section 7(i) and you are done. You take a consent form because a checklist told you to, and you have created the conditions for an employee to make a request under Section 11, a correction or erasure demand under Section 12, and a withdrawal under Section 6(4) that you must then answer.

You process attendance data either way. What changes is what you invited in.
If you take consent
Employee may withdraw at any time under s.6(4), and you must cease processing within a reasonable time under s.6(6).
Access right under s.11(1) attaches, including the identities of everyone you shared the data with.
Correction and erasure right under s.12 attaches to the attendance record itself.
If you rely on Section 7(i)
No consent exists, so there is nothing to withdraw.
s.11 and s.12 are drafted around prior consent, so on the face of the text they do not attach.
No Section 5 consent notice is triggered, though a plain notice is still worth giving.
Identical in both columns: reasonable security safeguards (s.8(5), up to Rs 250 crore) and breach reporting (s.8(6) with Rule 7, up to Rs 200 crore). This is where the real exposure sits.
Taking consent you did not need does not add protection. It adds obligations, and it does nothing about the two duties that carry the largest penalties.

A caveat this claim deserves. The consent gating in Sections 11 and 12 is what the text says, and the Data Protection Board has not yet been asked to rule on whether an employer who took unnecessary consent can later disclaim it and fall back on Section 7(i). The prudent reading is that you cannot reliably un ask. That is the whole argument for not asking in the first place, and for documenting Section 7(i) as your basis in writing now, before someone in your HR team downloads a consent template.

One boundary worth being clear about. Section 7(i) covers employment purposes. It does not cover everything you might like to do with the same data. Selling location histories to a third party, using attendance patterns for marketing, or sharing staff data with a partner for that partner's own purposes are all outside the clause and back in consent territory.

What You Owe Regardless of Which Basis You Use

Section 8 sets the duties that follow the data rather than the basis. These apply whether you took consent or not, and they are the ones with the ceiling figures attached.

  • Section 8(4). Implement appropriate technical and organisational measures to ensure effective observance of the Act.
  • Section 8(5). Protect personal data in your possession or control by taking reasonable security safeguards to prevent a breach. Maximum penalty Rs 250 crore, and it can be triggered by inadequate safeguards even where no harm followed.
  • Section 8(6). On a breach, give the Board and each affected person intimation in the prescribed form and manner. Maximum penalty Rs 200 crore.
  • Section 8(7). Unless retention is necessary for compliance with any law in force, erase personal data on withdrawal of consent or as soon as it is reasonable to assume the specified purpose is no longer served, whichever is earlier.

Read that list against how attendance data is actually handled in most small Indian businesses and the mismatch is obvious. The exported muster roll sits in a WhatsApp group. The payroll spreadsheet lives on a manager's personal laptop with no password. The biometric machine in reception has had the same admin PIN since it was installed, and the vendor who services it has a login nobody has ever reviewed. Not one of those is a consent problem. All of them are Section 8(5) problems.

Biometric, GPS or Selfie: The Question Worth Asking Instead

Biometric data has a property that separates it from the rest of your HR file. A leaked salary figure is embarrassing. A leaked fingerprint template is permanent, because the employee cannot be issued a new fingerprint. The Act does not create a separate sensitive data category the way some other regimes do, but the risk asymmetry is real and it should drive the design.

The honest position on the law: DPDP does not import a GDPR style necessity and proportionality test into Section 7. What it does say is "for the purposes of employment", and a collection that goes beyond what the employment purpose needs is, on a plain reading, outside the clause and therefore unprotected by it. That is a reading, not a decided point, and it is the sensible basis for a design decision regardless.

So the practical question is not "did we get a signature". It is: what is the least data that answers "was this person at work, at the right place, at the right time"?

  • A fingerprint template answers it, and creates a permanent, irrevocable identifier held on a device in your reception.
  • A geofenced check in with a selfie answers the same question with a photograph and a coordinate pair, both of which can be deleted and neither of which can be reused to impersonate the employee elsewhere.
  • Continuous background location answers considerably more than the question, and is the hardest thing on this list to defend as being "for the purposes of employment" once the shift has ended.

If you already run continuous tracking, the fix is not a consent form. It is to bound the collection to working hours and to say so in writing. We covered the operational case for moving off fingerprint hardware in our guide to GPS attendance without a biometric machine; the data protection case points the same way, which is unusual and worth noticing.

The 72 Hour Breach Rule Nobody Has Rehearsed

Rule 7 of the DPDP Rules 2025 puts procedure behind Section 8(6), and it is a two stage obligation that catches people out because the two stages have different clocks.

  • To affected individuals, without delay. Every employee whose data was caught in the breach is told, not just the Board.
  • To the Data Protection Board, without delay, then in detail within 72 hours. An initial intimation goes immediately, and a fuller report covering the broad facts of the breach and its causes follows within 72 hours, or longer if the Board allows it.

Seventy two hours is not long enough to work out who to call. The realistic preparation for a small business is a single page that names who declares a breach, who writes to the Board, where the list of affected employees comes from, and which vendor contacts are needed at 9pm on a Saturday. If your attendance data sits with a software provider, the question to ask them now, in writing, is how quickly they will tell you about an incident on their side, because your 72 hours starts when the breach is known and their delay eats your window.

How Long You Keep Attendance Records: Two Laws Pulling Opposite Ways

Section 8(7) says erase when the purpose is no longer served. Indian labour law says keep. Both are correct, and the resolution is in the words "unless retention is necessary for compliance with any law for the time being in force".

Attendance registers, wage registers and muster rolls carry statutory retention periods under the labour codes and the rules made under them. That is a law in force, so the retention exception applies and you keep them. What the exception does not cover is everything else that accumulated alongside: the four year old check in selfies, the raw location pings from a project that closed in 2024, the WhatsApp exports, the CV attachments of candidates you did not hire. None of that is a statutory register, and the purpose it was collected for stopped being served a long time ago.

The practical output is a two line retention policy. Statutory registers are kept for the period the labour law prescribes. Everything else has a defined life and is deleted at the end of it. If you are not sure which of your records are statutory, our guide to statutory registers and wage slips under the labour codes lists them.

A Practical DPDP Checklist for an Indian SME

In rough order of how much risk each removes per hour spent:

  • Write down your basis. One paragraph recording that employee attendance, payroll and leave data is processed under Section 7(i) for employment purposes. Do this before anyone circulates a consent form.
  • Stop collecting consent for core HR processing. Withdraw any template already in circulation. Keep consent only for things genuinely outside employment purposes.
  • Find every copy of the data. Personal laptops, WhatsApp exports, the spreadsheet emailed to the accountant, the old biometric machine. You cannot safeguard what you have not located.
  • Fix access. Individual logins rather than a shared password, access removed the day someone leaves, and no standing export of the full staff file to anyone who does not need it.
  • Write the breach page. Names, phone numbers, the 72 hour sequence. One page.
  • Set retention. Statutory registers for the prescribed period, everything else on a defined life.
  • Ask your vendors. Where is the data hosted, who at their end can read it, and how fast will they tell you about an incident.
  • Give a plain notice anyway. Not because Section 5 compels it here, but because an employee who was told what is collected and why is an employee who does not raise a complaint about it.

What This Means for the Attendance System You Already Run

Most of the list above is not really a legal exercise. It is a question of whether your attendance data lives in one system with real accounts and a real audit trail, or in a scatter of exports, spreadsheets and chat groups that no policy can reach.

That is the honest argument for using a purpose built system rather than a WhatsApp group and a spreadsheet, and it is worth stating plainly rather than dressing up. Shifteliokeeps attendance, payroll and leave in a single multi tenant record where each business's data is isolated, every user has their own login, access ends when you end it, and check ins carry a location and a timestamp that can be produced later. Because check in is geofenced with a selfie rather than a fingerprint, there is no permanent biometric identifier to lose in the first place, which is the cheapest way to be on the right side of the proportionality argument.

No software makes you compliant on its own, and any vendor claiming otherwise is selling you something. What it can do is collapse the first three items on that checklist into a state you can actually describe: one place, real accounts, a retention setting you chose rather than inherited.

Frequently Asked Questions

Do I need employee consent for biometric attendance in India?
On the text of the Act, no. Section 7(i) permits processing for the purposes of employment without consent, and attendance sits inside that. Taking consent anyway is likely to attach the withdrawal right in Section 6(4) and the access and erasure rights in Sections 11 and 12 to a record you are required to keep.

Can an employee refuse to be tracked by a GPS attendance app?
Where you rely on Section 7(i) there is no consent for them to withdraw, so the Act does not give them a switch to flip. That is a different question from whether tracking outside working hours is defensible, and from what your employment contract and state shops and establishments rules say. Bound the collection to the shift and the question mostly stops arising.

What is the deadline for DPDP compliance?
The Rules were notified on 13 November 2025 with an implementation period of roughly 18 months, so full compliance is expected by mid May 2027. The Consent Manager framework becomes operational on 13 November 2026. The security and breach reporting duties are the ones worth treating as live now.

What is the penalty if we get this wrong?
The Schedule sets maximums of Rs 250 crore for failure to take reasonable security safeguards and Rs 200 crore for failure to report a breach. They are ceilings rather than tariffs, and the Board weighs the circumstances, but they are not scaled to turnover.

Does the DPDP Act apply to a business with only ten employees?
Yes. The Act applies to processing of digital personal data, with no small business exemption from the core duties. Some additional obligations fall only on Significant Data Fiduciaries, which a ten person firm will not be, but Section 8 applies to everyone.

The Bottom Line

The advice being repeated across the internet, that DPDP compliance for attendance means collecting consent, gets the Act backwards. Employment purposes are a legitimate use under Section 7(i) and need no consent, while the access and erasure rights in Sections 11 and 12 are drafted to attach to consent based processing. Asking adds exposure and removes nothing.

What genuinely binds every employer, on any basis, is Section 8: reasonable security safeguards, breach intimation within 72 hours, and erasure of what no law requires you to keep. Those three carry the large numbers, and they are the three that most Indian SMEs would fail today, not because of a missing signature but because the staff file exists in nine places and four of them are chat groups.

There is time. The runway runs to May 2027. The work is finding your data, putting it somewhere with real accounts, and writing down two short policies. None of it needs a consent form.

Sources and Further Reading

The primary material for this article is the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 notified on 13 November 2025. The Act as published is available from the Ministry of Electronics and Information Technology, which administers the legislation, and the full statutory text is on the Government of India's India Code repository. The wording of Sections 7, 11 and 12 quoted above was verified against the bare text reproduced at Indian Kanoon.

This article describes the position as at 4 September 2026. The implementation period runs to mid 2027 and the Data Protection Board has not yet issued decisions interpreting the employment legitimate use or the consent gating of the rights chapter. It is general information, not legal advice. Take advice on your own facts before changing how you collect or keep employee data.

See how Shiftelio does this in practice with attendance, payroll and leave in one record with per user access.

Still deciding what to buy? Compare the attendance apps Indian small businesses actually use, ranked by real annual cost.

Stop managing this manually.

Shiftelio handles GPS attendance, payroll calculation, PF/ESI, and leave for 25 employees at Rs 5,999 per year. No biometric machine. No per-seat fees.

Start Free Trial