DPDP Act Compliance Checklist for Recruiters: Candidate Data Handling | HireBound Blog

Key Takeaways
- 1Most DPDP obligations for Data Fiduciaries start applying in May 2027, 18 months after the Rules were notified on 13 November 2025, so build the process now.
- 2Consent must be free, specific, informed and unambiguous under Section 6, and a talent-pool opt-in should never be bundled into a job application.
- 3The Act sets no fixed retention period for candidate data. Delete when the purpose ends, and set a written schedule of 6 to 12 months for rejected applicants.
- 4Your ATS, job board, screening and background-check vendors are Data Processors, but you stay accountable for them. Fix that in the contract.
- 5Penalties reach ₹250 crore for weak security safeguards, and IBM’s 2026 report puts the average Indian breach at ₹25.5 crore.
DPDP Act compliance for recruiters means handling candidate personal data, such as résumés, phone numbers, interview recordings and screening answers, the way India’s Digital Personal Data Protection Act, 2023 requires. You give clear notice, collect valid consent where needed, secure the data, delete it when the purpose ends, and answer candidate requests.
Every recruiter holds a lot of this data. A mid-size agency’s database can hold hundreds of thousands of profiles, many of them collected years ago with no consent record at all. Under the Act, that database becomes a liability if you cannot show where each profile came from and why you still have it.
Want a hiring workflow built with candidate consent in mind? Explore HireBound →
This guide walks through what the Act asks of recruiters, which candidate data it covers, what valid consent looks like in a recruiting flow, how long you can keep data, what you owe your vendors and what they owe you. It ends with a 12-step checklist and a look at penalties. It is a working guide, not legal advice, so have counsel review your final policy.
What Does the DPDP Act Require of Recruiters?
The Act splits the world into Data Principals (the candidates), Data Fiduciaries (whoever decides why and how their data is processed) and Data Processors (whoever handles it on the fiduciary’s behalf). If you run a hiring process, you are a fiduciary. An agency that keeps its own candidate database is a fiduciary in its own right, and a client that receives a profile from the agency becomes one too.
Parliament passed the Act in 2023, and the Ministry of Electronics and Information Technology notified the DPDP Rules on 13 November 2025. The Rules phase in over 18 months.
The Data Protection Board was set up straight away, consent manager provisions follow at 12 months, and the main fiduciary obligations apply from May 2027. Mapping data, rewriting notices and renegotiating vendor contracts takes longer than it sounds.
The core duties for a recruiter are these:
- Give each candidate a notice that lists the data you collect and why (Section 5).
- Obtain consent that meets the Section 6 standard, unless a legitimate use under Section 7 applies.
- Keep candidate data accurate if you use it to make a decision about them (Section 8(3)).
- Protect it with reasonable security safeguards (Section 8(5)).
- Tell the Data Protection Board and affected candidates about a breach (Section 8(6)).
- Erase data once consent is withdrawn or the purpose is served (Section 8(7)).
- Publish a contact point for candidate questions and run a grievance process (Sections 8(9) and 8(10)).
What Candidate Data Does the DPDP Act Cover?
The Act covers any digital personal data about an identifiable person, and it also reaches paper records once they are digitised. In a recruiting flow that is far more than the résumé.
- Identity and contact details: name, phone, email, address, date of birth.
- Résumé content: employment history, education, skills, photographs.
- Compensation data: current CTC, expected CTC, offer history.
- Identity documents: Aadhaar, PAN, passport, or bank details collected for onboarding.
- Conversation data: WhatsApp chat logs, SMS, email threads and call recordings with their transcripts.
- Assessment data: test scores, video interview files, AI screening outputs and rankings.
- Third-party data: referee names and numbers, and background verification reports.
Two points catch recruiters out. First, the DPDP Act has no separate “sensitive personal data” category, unlike the earlier drafts of the law. The same consent and security rules apply to everything, including health or caste details, so ask for less.
Second, Section 3©(ii) excludes personal data that the person made publicly available themselves, such as a profile they posted openly. That helps with sourcing, but only partly.
Once you copy that profile into your own database and contact the person, you are running a hiring process with their data, and the rest of your duties still apply. Data bought from a third-party database is a different case, because it was not made public by the candidate.
Referees deserve a separate mention, since you hold their data without ever having dealt with them. Our guide to reference checks in 2026 covers how to tell a referee what you hold and why.
What Does Valid Consent Look Like in a Recruiting Flow?
Valid consent under Section 6 is free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and limited to the data necessary for the stated purpose. A pre-ticked box fails that test. So does a line buried in a footer saying “by applying you agree to everything.”
The notice behind the consent has its own rules. Under Section 5 and Rule 3 it must list the data you collect, state each purpose in plain language, explain how the candidate can withdraw consent, and say how to complain to the Data Protection Board. It must also make sense on its own, without the reader hunting through another document.
Language matters in India. Section 5(3) says the candidate can ask for the notice in English or any of the 22 languages in the Eighth Schedule of the Constitution. A notice that exists only in English will not serve a warehouse applicant in Marathi or a call-centre candidate in Tamil.
HireBound’s Voice AI already runs conversations in 14 Indian languages, and the consent script should run in the same language as the call.
Consent in a WhatsApp or Voice Screening Flow
WhatsApp and voice are where most Indian high-volume hiring now happens. HireBound data shows a 64% WhatsApp response rate in India, compared with about 12% for email. A fast channel makes the consent step easy to skip, so build it in.
A workable opening message names the employer or agency, states the purpose in one line (screening for a specific role), links to the full notice, and asks the candidate to reply to proceed. The reply is your timestamped consent record.
On a voice call, the agent reads a short disclosure, including that the call is recorded and that the candidate is speaking with an AI agent, and waits for a spoken yes before asking anything else.
Record four things for every consent: the timestamp, the channel, the version of the notice shown and the purpose consented to. Without them, you cannot prove consent when someone asks.
Do You Need Consent for AI Screening?
The Act has no separate rule for automated screening. What it does have is Section 8(3), which requires a fiduciary to ensure the data is complete, accurate and consistent when it is used to make a decision affecting the candidate. It also has the notice rule, so the purpose “AI-assisted screening and ranking” must appear in the notice.
For the mechanics of what an autonomous agent does at each stage, see our comparison of agentic AI and recruiting automation. In practice, disclose the AI step, keep a human able to review a rejection, and store the scoring inputs so you can correct a wrong record if a candidate challenges it.
Can You Rely on the Employment Exception Instead?
Section 7 lists “legitimate uses” where consent is not required. Section 7(a) covers data a person volunteers for a stated purpose when they have not indicated that they withhold consent. Section 7(i) covers processing for employment purposes. Some practitioners read these as covering an applicant who sends a résumé for a specific job.
We would not build a compliance model on that reading alone. The Act does not define how far “employment” stretches to people who never become employees, and neither exception clearly covers a talent pool, a voice recording, sourced profiles or sharing data with a client. Use the exception as a fallback for the basic act of reading an application, and collect explicit consent for everything else.
Apprentices and campus hires need one more check. Section 9 requires verifiable parental or guardian consent for anyone under 18, so an internship drive that reaches 17-year-olds needs a different flow.
How Long Can You Keep Candidate Data Under the DPDP Act?
The Act sets no fixed retention period for recruiters. Section 8(7) says to erase personal data when the candidate withdraws consent or the purpose is no longer served, unless a law requires you to keep it. The purpose of a rejected application ends when the role closes.
The purpose of a hired candidate’s file moves into the employee record.
That leaves you to set a period and defend it. The schedule below is our suggestion for a typical Indian recruiter, not a statutory limit. Adjust it to your own legal advice.
- Rejected applicants, no talent-pool consent: delete or anonymise 6 to 12 months after the role closes.
- Talent-pool members with explicit consent: keep while consent is active, and re-confirm every 12 months.
- Call recordings and video interviews: shorter than the transcript. Keep only as long as you need them to resolve a dispute.
- Hired candidates: move the relevant records into HR files, then delete the recruiting copies.
- Access logs and security records: keep for at least one year, since Rule 6 requires that for logs used to detect unauthorised access.
What Are Your DPDP Obligations When Sharing Data With Vendors?
You remain responsible for candidate data even when a vendor handles it. Section 8(1) makes the fiduciary answerable for processing done on its behalf, and Section 8(2) allows you to engage a processor only under a valid contract. If your ATS vendor leaks a candidate database, the Board will look at you first.
Your recruiting stack probably includes more processors than you think:
- Your ATS or CRM.
- Job boards that pull or push candidate data through integrations.
- WhatsApp Business API and SMS providers.
- Voice AI and interview recording tools.
- Assessment and proctoring platforms.
- Background verification agencies.
- Cloud hosting and email providers.
Each contract should cover the same essentials. Limit the vendor to your stated purposes, require security safeguards that meet Rule 6, and require breach notice fast enough for you to meet the 72-hour window. Add deletion at contract end and approval rights over sub-processors.
Section 16 allows transfers outside India except to countries the government restricts, so ask where the data is stored.
Staffing agencies face one more flow. When you send a candidate profile to a client, tell the candidate first, and agree in writing what the client may do with it. A client that keeps the résumé after rejecting the candidate is now holding data it has no basis to hold.
The 12-Step DPDP Act Compliance Checklist for Recruiters
Work through these twelve steps in order. The first three take the longest, and everything else depends on them.
- Map your candidate data. List every place candidate data lives: ATS, spreadsheets, WhatsApp exports, email inboxes, recruiter laptops, vendor tools. Note the source and purpose for each.
- Name your role for each flow. Mark where you are the fiduciary, where a vendor is your processor, and where a client is a second fiduciary.
- Audit the legacy database. Flag profiles with no consent record or no known source, and decide whether to re-permission or delete them.
- Publish a plain-language notice. List data types, purposes, withdrawal steps and the Board complaint route. Offer it in the languages your candidates use.
- Build consent capture into every entry point. Career page, WhatsApp opener, voice script and walk-in forms all need a recorded, unbundled opt-in. Keep talent-pool consent separate from the application.
- Disclose AI screening and keep a human review path. State the automated step in the notice, and let a recruiter override a rejection.
- Collect less. Do not ask for Aadhaar, bank details or salary history at the screening stage if the decision does not need them.
- Set the retention schedule and automate deletion. Tie it to role-closure dates and consent status.
- Lock down access. Use role-based permissions, encryption, backups and access logs kept for at least one year.
- Rewrite vendor contracts. Cover purpose limits, security standards, breach notice timing, deletion and sub-processors.
- Write a breach plan and a rights process. Name who tells the Board and candidates, and how you handle access, correction and erasure requests inside the time the Rules prescribe. Publish a contact for candidate queries.
- Train recruiters and review quarterly. Most breaches start with a recruiter forwarding a résumé to a personal email. Retest the process each quarter, and check the Rules and Board notices for updates.
Our guide to change management for AI recruiting rollouts covers how to introduce steps like these without stalling the team.
See how consent, screening and scheduling run in one workflow. Book a free demo →
What Happens If You Don’t Comply With the DPDP Act?
The Data Protection Board can inquire into a complaint or a breach and impose financial penalties. The Schedule to the Act sets the maximums, and the Board weighs the nature, gravity and duration of the breach when it fixes an amount.
- Failure to maintain reasonable security safeguards: up to ₹250 crore.
- Failure to notify the Board and candidates of a breach: up to ₹200 crore.
- Breach of the children’s data obligations: up to ₹200 crore.
- Breach of additional obligations of a Significant Data Fiduciary: up to ₹150 crore.
- Any other breach of the Act or Rules: up to ₹50 crore.
The penalty is not the whole cost. IBM’s 2026 Cost of a Data Breach Report puts the average breach in India at ₹25.5 crore, up from ₹22 crore the year before. For a staffing agency, the harder loss is trust, because candidates and clients both hand you data on the assumption that you will look after it.
Candidates carry duties too. Section 15 obliges them not to file false or frivolous complaints, and the Schedule allows a penalty of up to ₹10,000 for breaching that duty. That protects you from abuse of the process, but it does not soften your own obligations.
Start with the data map and the legacy database, because those two steps tell you how big the rest of the job is.


