Skip to content

India hiring

India's DPDP Act for recruiters: consent, notices and candidate data

The Itya team · Updated · 8 min read

The short answer

India's DPDP Act covers the candidate data recruiters collect or digitize. Give a clear notice and get consent unless a "legitimate use" applies, and note that the Act's employment clause does not clearly cover candidates who are not yet employees. Most duties under the DPDP Rules 2025 apply from 13 May 2027, with penalties of up to ₹250 crore.

The timeline

Phased dates per Hogan Lovells and Fisher Phillips. Hogan Lovells dates the notification 13 November 2025; the government's PIB backgrounder says 14 November.
DateWhat happens
11 August 2023Parliament enacts the Digital Personal Data Protection Act.
November 2025The Ministry of Electronics and IT notifies the DPDP Rules 2025. Rules on the Data Protection Board apply at once.
13 November 2026Consent managers must register with the Board (Rule 4).
13 May 2027Most duties apply: notice, breach reporting, retention and erasure, children's data, and Significant Data Fiduciary duties (Rules 3, 5 to 16, 22 and 23).

Does the Act cover candidate data?

In almost every hiring process, yes. The Act applies to digital personal data processed in India, including data collected on paper and digitized later (Section 3). "Personal data" means any data about an individual who is identifiable by or in relation to it. A résumé, an application form, an interview recording, a transcript and a scorecard all qualify.

One limit matters for sourcing. The Act does not apply to personal data that the person has made, or caused to be made, publicly available. Whether a given public profile falls under that limit is a question for counsel, not a default.

Section 4 allows processing for a lawful purpose on one of two grounds: the person's consent, or a "legitimate use" listed in Section 7. Two clauses of Section 7 come up in hiring. The first is the employment clause:

for the purposes of employment or those related to safeguarding the employer from loss or liability, such as prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property, classified information or provision of any service or benefit sought by a Data Principal who is an employee.
Digital Personal Data Protection Act 2023, Section 7(i)

The clause names employment and employees. It does not mention candidates or recruitment, and commentators read that gap differently. NovoJuris Legal, writing in Bar & Bench, says the Act is silent on pre-employment steps such as shortlisting, interviews and background checks, so it is unclear whether they fall under "purposes of employment". Fisher Phillips takes the broader view that employers generally will not need explicit consent for standard HR activities, recruitment included.

The second is Section 7(a). It covers data a person "has voluntarily provided" for a specified purpose, where she has not indicated that she does not consent. The Act's illustrations involve a pharmacy and a property broker, not an employer, and we found no official guidance applying it to job applications.

Until the Data Protection Board or the courts say more, the cautious path is simple. Give every candidate a notice. Get consent for anything a candidate would not expect from applying, such as recording an interview, AI analysis or keeping a profile for future roles.

Under Section 5, every request for consent must come with, or after, a notice that tells the person:

  • the personal data and the purpose for which it will be processed;
  • how to withdraw consent and how to use your grievance route (the rights in Sections 6(4) and 13);
  • how to complain to the Data Protection Board.

Under the Rules, Hogan Lovells notes, the notice must be presented independently of other information, in clear and plain language, with "an itemized description of the personal data to be processed". The Act also requires you to give the person the option to read the notice in English or any language listed in the Eighth Schedule to the Constitution.

Consent itself must be "free, specific, informed, unconditional and unambiguous with a clear affirmative action", and limited to the data needed for the purpose (Section 6(1)). Withdrawing it must be as easy as giving it. A pre-ticked box on a careers form is hard to square with "clear affirmative action".

Your duties once you hold candidate data

  • Accuracy for decisions. Where data is likely to be used to make a decision that affects the person, you must ensure it is complete, accurate and consistent (Section 8(3)). A hiring decision is such a decision.
  • Vendors under contract. A data processor, such as an ATS or interview vendor, may process data for you only under a valid contract (Section 8(2)). You remain responsible for what it does on your behalf (Section 8(1)).
  • Security. Take reasonable security safeguards to prevent a personal data breach (Section 8(5)).
  • Breach reporting. Tell the Board and each affected person (Section 8(6)). Under the Rules, affected people must be told without delay, in plain language, what happened and what they can do (PIB), and the Board must get a detailed report within 72 hours (Hogan Lovells).
  • Erasure. Erase data when consent is withdrawn or the purpose is no longer served, unless a law requires you to keep it, and make your processors erase it too (Section 8(7)). The Rules also require personal data, traffic data and certain logs to be kept for at least one year (Hogan Lovells).
  • A named contact. Publish the business contact of a Data Protection Officer, or of a person who can answer questions about the processing (Section 8(9)).
  • Grievances and rights. Run an effective grievance mechanism (Section 8(10)). Requests to access, correct, update or erase data must be answered within 90 days (PIB).

Hiring under-18s

Under the Act, a child is anyone under 18. Before processing a child's personal data you need verifiable consent from a parent or lawful guardian. You may not process it in a way likely to harm the child's well-being, and you may not track or behaviorally monitor children (Section 9). Plan for this before you open apprenticeships, internships or part-time roles to applicants under 18.

Significant Data Fiduciaries

The government can notify some organizations as Significant Data Fiduciaries, based on factors such as the volume and sensitivity of the data and the risk to people's rights (Section 10). They must appoint a Data Protection Officer based in India, engage an independent data auditor, and run periodic impact assessments and audits. Under the Rules, Hogan Lovells adds, they "must ensure that technical and algorithmic systems do not harm data principals' rights". The label applies only to organizations the government notifies.

Penalties

Maximum penalties per the PIB backgrounder of 17 November 2025.
FailureMaximum penalty
Failing to take reasonable security safeguards₹250 crore
Failing to notify the Board or affected people of a breach₹200 crore
Breaching the duties on children's data₹200 crore
Any other breach of the Act or Rules by a Data Fiduciary₹50 crore

A recruiter's checklist

  1. Map candidate data. List what you collect at each stage, from application to offer, where it is stored and which vendors touch it.
  2. Write one standalone candidate notice. Itemize the data, state each purpose, and explain how to withdraw consent, raise a grievance and complain to the Board.
  3. Ask for consent for anything beyond the application, such as recording, AI analysis or a talent pool, and make withdrawing as easy as agreeing.
  4. Set retention periods. Decide how long you keep rejected candidates' data, and delete on schedule.
  5. Sign contracts with every processor: ATS, assessment, interview and background-check vendors.
  6. Rehearse a breach. Know who tells candidates and who sends the Board its 72-hour report.
  7. Name a contact and set up a grievance route that answers within 90 days.
  8. Check ages for roles open to under-18s, and plan for verifiable parental consent.

Itya captures consent before an interview is recorded, publishes a DPA and subprocessor list, and offers a DPDP grievance route; see our trust page. Features like these help you meet specific duties, such as keeping consent records and giving candidates a contact for grievances. The choices above, from your lawful basis to your retention periods, stay with you. For rules outside India, see AI interview laws by jurisdiction.

Questions people ask

Do I need consent to process a candidate's résumé in India?
The Act does not answer this directly. Section 7(i) lets organizations process data "for the purposes of employment" without consent, but it does not mention candidates, and commentators disagree on whether recruitment is covered. The cautious approach is a clear notice for every candidate, and consent for anything beyond the application itself.
When do the DPDP duties apply to recruiters?
Most duties, including notice, breach reporting and erasure, apply from 13 May 2027 under the DPDP Rules 2025. Consent managers must register from 13 November 2026. A 2026 proposal to shorten the timeline had not been notified when we checked on 10 October 2026.
How quickly must a data breach be reported under the DPDP Rules?
You must inform the Data Protection Board and each affected person. Affected people must be told without delay, in plain language, and the Board must receive a detailed report within 72 hours. These duties apply from 13 May 2027.
How long can I keep data on rejected candidates?
Only while the purpose you told them about is still served, unless a law requires longer. Erase it when consent is withdrawn or the purpose ends, and make your vendors erase it too. If you want to keep profiles for future roles, say so in the notice and ask for consent.
Do interview recordings and transcripts fall under the DPDP Act?
Yes. They are digital personal data about the candidate, so notice, purpose limits, security, breach reporting and erasure all apply. Asking for consent before recording also sidesteps the open question about candidates and Section 7(i).
What are the penalties under the DPDP Act?
Up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore each for failing to report a breach or breaching the duties on children's data, and up to ₹50 crore for other breaches, according to the government's PIB backgrounder.

Sources

Every source was opened and checked on 10 October 2026.

  1. The Digital Personal Data Protection Act, 2023 (Gazette of India text), PRS Legislative Research
  2. DPDP Rules, 2025 notified (backgrounder), Press Information Bureau, Government of India
  3. India's Digital Personal Data Protection Act 2023 brought into force, Hogan Lovells
  4. India's new data privacy rules are here: 8 steps for businesses as key compliance deadlines approach, Fisher Phillips
  5. Navigating legitimate use exemption for employee data under Digital Personal Data Protection Act 2023, Bar & Bench (NovoJuris Legal)
  6. MeitY plans to cut short DPDP compliance timeline and notify cross-border restrictions for SDFs, S.S. Rana & Co.

The AI listens. People decide.

See how Itya handles consent, notices and candidate data, and what we deliberately do not claim.