When India's Digital Personal Data Protection Act, 2023 (DPDP Act) was passed, most discussions focused on consumer apps, fintech platforms, and social media companies. HR teams in enterprise organisations largely felt it wasn't their problem to solve.
That instinct is understandable but incorrect. Recruitment is, at its core, a data-intensive activity. You collect names, phone numbers, email addresses, educational records, employment histories, salary details, identity documents, medical information (for BGV), and in some cases caste/religion data inadvertently through certificates. Every candidate whose CV sits in your ATS is a data principal under the DPDP Act — and your organisation is the data fiduciary responsible for protecting that data.
This guide is written for HR teams, not lawyers. It explains what the DPDP Act actually requires in the context of recruitment, what you're probably doing wrong today, and how to get compliant without rebuilding your entire HR process from scratch.
What the DPDP Act Actually Says (The Short Version)
The DPDP Act 2023 establishes a framework around the collection and processing of "digital personal data" — any data about an identifiable individual that exists in digital form. The key principles HR teams need to understand are:
- Consent is required. You can only collect and process a candidate's personal data if they have given free, specific, informed, and unambiguous consent. Passive data collection — scraping LinkedIn, sourcing from third-party databases without disclosure — without a valid consent mechanism is a violation.
- Purpose limitation. Data collected for a specific purpose (e.g., evaluating a candidate for a Sales Manager role) cannot be repurposed for something else (e.g., marketing research, building a talent pool for different roles) without fresh consent.
- Data minimisation. You may only collect what you actually need to make the hiring decision. Asking for Aadhaar numbers at the application stage when you don't need them until post-offer BGV is a violation of this principle.
- Retention limits. You cannot keep candidate data indefinitely "just in case." Rejected candidates' data must be deleted within a defined retention window unless the candidate has consented to being retained in a talent pool.
- Rights of data principals. Candidates have the right to access their data, correct inaccuracies, and request deletion. Your process must be able to honour these requests.
The DPDP Act prescribes penalties of up to ₹250 crore per violation for significant data breaches or non-compliance with consent requirements. While enforcement will build gradually, the reputational risk of a high-profile candidate data breach is immediate — especially as candidates become more aware of their rights.
Where Most HR Teams Are Non-Compliant Today
Let's be direct about the current state in most mid-to-large Indian enterprises. These are the most common violations we see:
1. No consent mechanism at the application stage
A candidate uploads their CV on your careers portal. There is no statement explaining what data you're collecting, how it will be used, how long it will be retained, and how they can request deletion. There is no checkbox. There is no confirmation. Under the DPDP Act, you are processing their data without valid consent from the moment they submit.
2. CVs in email inboxes with no retention policy
A recruiter receives 200 CVs over email for a position. The position gets filled. Those 199 rejected CVs sit in the recruiter's inbox indefinitely — and in the company's email servers, potentially forever. The company has no way to fulfil a data deletion request from any of those 199 candidates because it doesn't even know where all their data lives.
3. Bulk CV databases and shared drives
Many companies maintain a "CV database" — a shared drive folder or a mass upload into a spreadsheet or ATS — containing thousands of CVs collected over years from various sources. Unless every one of those candidates gave explicit consent for their data to be used in an ongoing talent pool, this database is non-compliant.
4. BGV data collected too early
Many companies collect Aadhaar, PAN, address proof, and previous employer contact details during the application or early interview stage. The DPDP Act's data minimisation principle means you should only collect this data when you actually need it — which is post-offer, pre-joining, when BGV is actually being initiated.
5. No process to handle access/deletion requests
A candidate emails your HR department saying "Please share all personal data you hold about me and delete it." How does your organisation respond? In most companies, there is no defined process, no designated point of contact, no SLA. Under the DPDP Act, you are required to have this process — and failure to respond is itself a violation.
The Candidate Data Lifecycle Under DPDP
Think of candidate data as having five stages, each with distinct compliance requirements:
| Stage | Data Collected | DPDP Requirement |
|---|---|---|
| Application | Name, email, phone, resume, experience summary | Explicit consent notice at point of submission; purpose stated clearly |
| Screening & Interviews | Interview scores, assessments, interviewer notes | Data stays within hiring workflow; no unauthorised sharing; retention policy starts |
| Offer Stage | Salary details, notice period, offer acceptance | Consent for extended retention if offer is delayed or candidate is waitlisted |
| BGV / Pre-Joining | Aadhaar, PAN, address proof, educational certificates, reference contacts | Separate explicit consent for BGV processing; data minimised to what's needed |
| Rejection / Closure | All candidate data | Deletion within defined retention window (e.g., 180 days) unless talent pool consent obtained |
Practical Steps to Get Compliant
Step 1: Audit your data touchpoints
Map every place where candidate data enters your organisation: careers portal, email applications, job portal integrations, WhatsApp submissions, vendor-submitted CVs, campus drive registrations. For each one, document what data is collected and where it goes.
Step 2: Add a DPDP-compliant consent notice to every entry point
Every application form, careers portal registration, and campus drive registration needs a clear, plain-language consent notice. It should state: what data is collected, for what purpose, how long it will be retained, and how the candidate can exercise their rights. This cannot be buried in a 20-page privacy policy.
Step 3: Implement a data retention policy — and enforce it
Define retention windows for each stage. A common approach: rejected candidates' data is held for 180 days (in case of a re-application or reference check), then automatically flagged for deletion. Candidates who consent to your talent pool can be retained for 24 months, after which consent must be renewed.
The key word is "automatically." If your process relies on a recruiter manually deleting CVs every six months, it won't happen consistently. The system needs to enforce the policy.
Step 4: Create a candidate rights fulfilment process
Designate a point of contact for data requests. Define an SLA (the DPDP Act requires response within a reasonable timeframe; best practice is 30 days). Ensure your ATS can generate a complete data export for a named candidate and delete their records on request.
Step 5: Train recruiters and HR BPs
Data protection isn't just a technology problem — it's a behaviour problem. Recruiters who forward CVs over WhatsApp, store candidate data on personal devices, or share candidate details with unauthorised third parties are creating violations. Annual training is now a compliance obligation, not a nice-to-have.
How RecruitVerse Addresses DPDP Compliance
RecruitVerse was built with India's regulatory context in mind. The platform includes a dedicated DPDP compliance module:
- Consent capture at application: Every application form presents a mandatory consent notice with a checkbox. Consent is timestamped and stored against the candidate's record permanently.
- Configurable retention policies: HR admins set retention windows per candidate stage. The system automatically flags records for deletion when the window expires and generates a deletion report.
- Candidate data export: Any candidate's complete data profile can be exported in under 60 seconds — name, all application data, consent record, communication log, assessment scores, and offer details.
- Right-to-erasure workflow: A designated HR admin can trigger full data deletion for a candidate, with a confirmation audit trail showing when deletion occurred and what was deleted.
- BGV data separation: Identity and verification documents are stored in a separate, access-controlled module that only HR compliance roles can access — not general recruiters or hiring managers.
Beyond avoiding penalties, DPDP-compliant hiring practices visibly improve candidate trust. When a candidate sees a clear, honest consent notice, it signals professionalism and transparency. In a competitive talent market, the impression your hiring process makes matters — and companies that treat candidate data with respect consistently report higher offer acceptance rates and better Glassdoor reviews of their hiring experience.
A Note on Timing
The DPDP Act 2023 is in force, but full enforcement ramps up as the Data Protection Board and rules are operationalised. The companies that are building compliant processes now are buying themselves time, expertise, and competitive positioning. The companies that wait for enforcement to begin will be scrambling under pressure.
For HR leaders, the right framing isn't "are we legally required to do this today?" It's "when our candidates and candidates' advocates know their rights — which will happen very soon — are we the kind of organisation that took their data seriously, or are we the organisation caught scrambling?"
That answer is entirely within HR's control. And unlike most compliance projects, this one is genuinely achievable with the right tools, a clear policy, and two quarters of focused implementation work.