Employee Data Under the DPDP Act: What Amazon's €32m Monitoring Fine Teaches Indian Employers
The DPDP Act lets employers process employee data without consent for employment purposes. That is not a licence for unlimited monitoring, as a €32 million French fine over warehouse scanners shows.
Most Indian SMEs assume their HR data is the safe corner of their DPDP compliance work. Customers need consent banners and privacy notices; employees signed an appointment letter, so surely that covers it? Partly. Employee data under the DPDP Act gets a special route that does not require consent, but the route has edges, and productivity tools, CCTV, laptop monitoring software and attendance apps can push you past them.
A useful warning comes from France. On 27 December 2023, the French regulator CNIL fined Amazon France Logistique €32 million for monitoring warehouse staff in a way it found excessive. The case predates India's Rules, but the reasoning maps closely onto what the DPDP Act asks of employers, and with core obligations taking effect on 13 May 2027, now is the time to check your own setup.
What the Amazon case was about
Warehouse workers used handheld barcode scanners to do their jobs. Every scan was recorded, and the data fed indicators on each worker's productivity, quality and periods of inactivity. According to summaries of the decision published by Ashurst and Fieldfisher, the CNIL objected to:
- indicators that measured scanner idle time and how fast items were scanned, which it treated as continuous pressure on individual workers;
- keeping all this raw data and the resulting statistics for 31 days for every employee and temp worker;
- temporary workers not being properly told their data was collected;
- a video surveillance system with a weak access password and shared login accounts.
Note what the CNIL did not say. It did not ban scanners, stock tracking or CCTV. The problem was granularity, retention, transparency and security. Those are exactly the levers an Indian employer controls.
How the DPDP Act treats employee data
Section 7(i) of the DPDP Act, 2023 allows a Data Fiduciary to process personal data without consent "for the purposes of employment", or to safeguard the employer from loss or liability. The Act gives examples: preventing corporate espionage, keeping trade secrets and intellectual property confidential, and providing a service or benefit the employee has asked for.
Law firms writing on the provision, including commentary in Chambers and Legal500, read "purposes of employment" broadly. Recruitment, background checks, onboarding, payroll, tax, performance reviews, disciplinary action and internal investigations all plausibly fit. You do not need a consent form for each of these, and you should avoid relying on consent from employees anyway, since consent given to your own employer is hard to call free.
So far, so convenient. Here is the catch.
The obligations that still apply to employee data
Legitimate use removes the consent requirement. It does not remove the rest of your duties as a Data Fiduciary under Section 8. In practice that means:
- Reasonable security safeguards. Rule 6 of the DPDP Rules, 2025 expects measures such as encryption or masking, access controls, logging and backups. A CCTV system with a shared password, as in the Amazon case, is the kind of gap that would fail this test. Failing to take reasonable safeguards carries a penalty of up to ₹250 crore.
- Breach notification. A leak of salary files, Aadhaar copies or medical records is a personal data breach. It must be reported to the Data Protection Board and to affected employees, with a fuller report to the Board within 72 hours. Failure to notify can attract up to ₹200 crore.
- Retention limits. Once the purpose is served, data should be erased. Ex-employee files kept "just in case" for a decade are a liability, subject to whatever retention periods other laws (tax, labour, PF) actually require.
- Grievance redressal. Employees can raise grievances with you, and you need a working process to answer them.
There is also an open legal debate. A February 2026 guest post on the Indian Constitutional Law and Philosophy blog argued that Section 7(i) is too broad and enables workplace surveillance. Whatever happens to that argument, the direction of travel is towards more scrutiny of employer monitoring, not less.
Where Indian SMEs usually overreach
In our work with smaller companies, the risk rarely sits in payroll. It sits in tools bought for productivity and switched on with default settings. Common examples:
- Laptop monitoring software that captures screenshots every few minutes, logs keystrokes or records personal browsing during breaks.
- Attendance and field-sales apps that track location around the clock rather than only during working hours.
- CCTV covering areas where people change or rest, or footage kept for months with no clear reason.
- WhatsApp groups and shared drives holding scans of PAN cards, Aadhaar, bank details and medical certificates, accessible to anyone in HR or admin.
Each of these can be tied to an employment purpose. The question a regulator will ask is whether the extent of monitoring was necessary for that purpose. Amazon could justify tracking stock. It could not justify measuring every worker's idle seconds and keeping the data for a month.
A practical checklist for employee data under the DPDP Act
You can make real progress in a few weeks:
- List every system that touches employee data. HRMS, payroll, attendance, monitoring software, CCTV, background-check vendors, insurance providers. Many SMEs find ten or more.
- Write down the purpose for each. One line is enough: "GPS tracking during field visits to verify client meetings." If you cannot write the purpose, switch the feature off.
- Reduce granularity. Aggregate productivity metrics at team level where individual tracking adds little. Turn off keystroke logging and screenshot capture unless there is a specific security reason.
- Set retention periods. For example, CCTV overwritten after 30 days unless an incident is flagged; monitoring logs deleted after a defined period; ex-employee files reviewed against statutory retention needs.
- Tell people anyway. The Act does not require a Section 5 notice for legitimate-use processing, but an internal employee privacy policy builds trust and avoids the "temp workers were never told" problem the CNIL flagged. Include contractors and interns.
- Fix access and passwords. No shared CCTV logins. Restrict ID documents and medical records to named HR staff. Encrypt files at rest.
- Check vendor contracts. Your payroll provider and background-verification agency are Data Processors. Your contracts should cover security, breach reporting and deletion.
For monitoring that is truly intrusive, a short privacy impact assessment is worth doing before rollout. It forces the necessity question onto paper.
Why act before May 2027
The Data Protection Board will start hearing complaints once the substantive provisions take effect. Employee complaints are among the most likely triggers, because employees know exactly what is being collected about them and often leave on bad terms. An unhappy ex-employee with screenshots of your monitoring dashboard is a stronger complainant than any customer.
If you want a structured view of where your HR processes stand, our DPDP Act compliance team can map employee data flows alongside your customer data work.
This article is general guidance and not legal advice. For decisions specific to your organisation, consult a qualified professional.
Start with our free DPDP readiness checklist, or talk to us about reviewing your workplace monitoring setup.
Get help implementing this
Turn this reading into a compliance plan.
Book a free 30-minute consultation. We'll map your DPDP Act exposure and give you a prioritized 90-day action list — no obligation.
Book a free 30-minute consultation