Aggregate-only workforce reporting means employers see group patterns, not a person’s private entry, conversation, journal or score.

For an Indian HR or procurement team, that boundary should be testable in the product, contract and incident process. “Anonymous dashboard” is not enough if a small department, rare attribute or repeated filter can point back to one employee.

What aggregate-only workforce reporting means

Aggregate-only reporting is a reporting design in which the employer receives totals, rates, distributions or trends for groups, while individual-level wellbeing content remains outside the employer view.

Pseudonymisation replaces a direct identifier, such as a name, with another reference. It can reduce risk, but the information remains linkable when the additional key exists. The UK Information Commissioner’s Office warns that pseudonymous information is still personal data; simply removing names is not the same as making information anonymous.

Effective anonymisation aims to make identification sufficiently remote in the context where information is released. That context matters. A department average may look harmless until the department has very few people or HR can combine it with attendance, location and roster knowledge.

ManoYatra, an India-native AI wellbeing companion by Sochware Private Limited, states that employer analytics are aggregate-only and separated by organisation. Its public boundary is that employers do not receive individual entries or conversations. Buyers should still ask every vendor, including ManoYatra, to document exactly how group thresholds, filter combinations and suppressed views behave before contracting.

Why a group average can still expose a person

Aggregation changes the output, but it does not automatically remove identification risk. NIST’s de-identification guidance says organisations should evaluate the release model, likely re-identification risk and measurable performance before sharing de-identified results.

A small-cohort example makes the problem clear. If one site has a single night-shift supervisor, a “night-shift supervisor” result is effectively about that person even when their name is absent. The same issue can appear through narrow age bands, rare job roles, small locations or repeated filtering.

A safe review therefore considers the whole information environment:

  • Cohort size — how many people contribute to each visible result.
  • Attribute rarity — whether a role, location or combination is unique.
  • Filter history — whether two permitted views can be subtracted to reveal a person.
  • Roster knowledge — what managers already know from HR systems.
  • Time windows — whether a sudden change maps to a known leave, incident or disclosure.

[Benchmark — external, not an India requirement] The NHS publication standard cited by the ICO uses a k-anonymity value of 5, meaning each described record shares its attributes with at least four others. This is a useful procurement example, not a universal threshold and not a claim about ManoYatra.

The DPDP check is broader than the dashboard

India’s Digital Personal Data Protection Act, 2023 applies to digital personal data about an identifiable individual. A dashboard may show only group results while the underlying service still processes identifiable account, usage or support data. Procurement must therefore cover the full data path, not just the screen HR sees.

The Act requires reasonable security safeguards and gives people rights around access, correction, erasure and grievance handling in the applicable circumstances. The Digital Personal Data Protection Rules, 2025 add operational detail and a staged commencement timeline. Buyers should have counsel confirm which provisions apply on the contract date.

[Benchmark — statutory maximum] The Act’s Schedule permits a penalty of up to ₹250 crore for a failure to take reasonable security safeguards to prevent a personal-data breach. That ceiling is not a prediction of liability; it shows why vague vendor assurances are not a sufficient control.

[Benchmark — notified rule timing] The Rules specify a 72-hour window for providing detailed breach information to the Data Protection Board after awareness, subject to the rule’s commencement and application. Ask how the vendor will supply facts quickly enough for your own response obligations.

A procurement matrix for aggregate reporting

Use this matrix during demos and security review. A strong answer should be supported by a live product view, architecture note, contract term or test result.

ControlWeak answerStrong answerEvidence to request
Employer visibility“HR only sees insights”Individual entries, conversations and scores are structurally excludedRole-permission map and sample export
Small groups“Reports are anonymous”Results below a stated threshold are suppressed or broadenedThreshold policy and boundary test
Combined filters“Managers use filters responsibly”The system blocks differencing and rare combinationsFilter test across role, site and time
Organisation separation“Each customer has a dashboard”Tenant identity is enforced from authenticated accessArchitecture note and access-control test
Retention“We keep data as needed”Each data class has a purpose, period and deletion pathRetention schedule and deletion evidence
Incident response“We notify customers promptly”Named owners, evidence preservation and timed notices are documentedIncident clause and sample notice

The matrix separates a marketing promise from an enforceable system. It also fits naturally beside a broader employee wellbeing platform RFP template and a DPDP employee-data checklist.

Questions to ask in the product demonstration

A useful demonstration should let the buyer try boundary cases, not just watch prepared charts.

  1. Show the smallest reportable department, site and demographic group.
  2. Apply two overlapping filters and explain whether subtraction can isolate a person.
  3. Remove contributors until the threshold is crossed and show the resulting screen.
  4. Export a report and identify every field that leaves the platform.
  5. Switch from an employer administrator to a standard employee account and compare access.
  6. Explain who can reach raw records for support, security or legal operations.
  7. Delete a test account and show what disappears, what remains and why.
  8. Walk through a simulated breach notice, including evidence, ownership and timing.

Record answers in the tender pack. “Available on request” should remain an open item until the promised document or test is supplied.

Contract terms that preserve the boundary

Product controls can drift after procurement unless the contract fixes the important ones. Define employer-visible data classes, prohibited individual outputs, minimum-group behaviour, permitted filters and export formats. Make material changes subject to notice and review.

Require purpose and retention terms for each data class. Specify sub-processor disclosure, access logging, deletion handling, incident cooperation and exit exports. Ensure the employer cannot request a custom report that bypasses the group boundary.

Privacy also depends on internal incentives. Managers should receive guidance that group trends support programme planning, not employee evaluation. A dashboard designed for aggregate decisions can still be misused when a manager treats a small team’s result as a performance signal.

For broader tender evidence, use the employee wellbeing vendor readiness checklist. It places privacy evidence alongside implementation, governance and commercial controls.

How ManoYatra should be evaluated

ManoYatra’s employer proposition is an aggregate-only analytics boundary: individual wellbeing entries and conversations are not presented to employers, and organisation separation is part of the architecture. That is the starting claim a buyer should verify, not a reason to skip diligence.

Ask ManoYatra for the same threshold, filtering, retention, incident and export evidence demanded from any other vendor. Compare the answers against the matrix above and preserve them in the procurement record.

The practical decision is simple: choose the vendor whose privacy boundary remains intact in a small-team test, a combined-filter test, an export and a written contract. Explore ManoYatra’s business platform and request a procurement discussion only after those checks are part of your evaluation.

Sources