calhire
Regulation

India’s DPDP Act and candidate data

India’s first comprehensive data protection statute, and the one most likely to surprise an employer that assumed a recruitment database was theirs to keep indefinitely.

The Digital Personal Data Protection Act 2023 governs digital personal data in India. An employer processing candidate data is a Data Fiduciary and must give an itemised notice of what is collected and why, have a lawful basis — consent, or a legitimate use such as employment purposes — and honour rights of access, correction, erasure and grievance redressal. A Grievance Officer’s contact details must be published. Personal data must be erased once the purpose is served, unless retention is legally required.

Last reviewed

The short version

  • The vocabulary is its own: Data Fiduciary (controller), Data Processor, Data Principal (the person). Mapping it to GDPR terms gets you most of the way, not all of it.
  • Consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action — and withdrawable as easily as it was given.
  • "Employment purposes" is a legitimate use that can cover processing without consent, but its edges around CANDIDATES rather than employees are the part to take advice on.
  • Erasure is a duty, not only a right: once the purpose is served, the Data Fiduciary must erase unless law requires retention.
  • A published Grievance Officer is mandatory. Not an inbox that reaches someone eventually — a published contact.

The terms the Act actually uses

Reading DPDP with GDPR vocabulary in your head works until it quietly does not. These are the four that matter for hiring.

Data Fiduciary
The person who alone or with others determines the purpose and means of processing personal data. An employer deciding to screen candidates is a Data Fiduciary. The word is doing deliberate work: a fiduciary holds something on someone else’s behalf.
Data Principal
The individual the data relates to — the candidate. Where the individual is a child, the parent or lawful guardian. The Act attaches the rights to this person and the duties to the fiduciary.
Notice
An itemised description of the personal data being collected and the purpose of processing, given at or before the point of collection, along with how to exercise rights and how to complain to the Board. Itemised is the operative word: a general privacy policy paragraph is not a notice.
Grievance Officer
The contact a Data Principal goes to first with a complaint, whose details a Data Fiduciary must publish. A Data Principal is expected to exhaust this route before approaching the Data Protection Board.

What an employer hiring in India has to get right

In rough order of how often it is missed rather than how the Act lists it.

  1. 1

    Give an itemised notice at collection

    What data, for what purpose, how to exercise rights, and how to complain. At or before collection — not on the offer letter, and not only in a policy linked from a footer.

  2. 2

    Establish the basis, and be able to say which

    Consent, or a legitimate use. If you are relying on consent it must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and withdrawable as easily as it was given.

  3. 3

    Decide your retention period before you collect

    This is the one that catches recruitment. Erasure is a duty once the purpose is served. A talent pool kept indefinitely "in case something comes up" needs a basis that survives the question "what purpose is still being served here?".

  4. 4

    Publish a Grievance Officer

    Reachable contact details, published, with a process behind them. It is the route a candidate is expected to use before going to the Board, which makes it your chance to resolve something.

  5. 5

    Bind your processors by contract

    A Data Fiduciary may engage a processor only under a valid contract, and remains responsible for compliance regardless of any arrangement with the Data Principal. Your ATS and your assessment vendor are processors.

Why volume makes this sharper in India than elsewhere

Indian hiring runs at a scale most markets do not see: a graduate role can attract thousands of applications, and the standard response has been to filter on institution tier and marks because a human cannot read them all.

That produces two problems the DPDP Act now attaches consequences to. The first is volume of retained data — a proxy filter still requires collecting everything from everyone, and the retained pile grows with every campaign. The second is that the filter is a poor predictor, so the data is collected, kept and then used for something it does not support well.

A verified assessment changes the arithmetic rather than the paperwork. If ability is established before identity is collected, the amount of personal data that has to exist to run a screening round drops — and data minimisation stops being a policy you write and becomes a shape your process already has.

Where CalHire sits, stated plainly

For candidate data on this platform, CalHire is the Data Fiduciary and our Grievance Officer contact is published in the Privacy Policy rather than described here. The officer is identified by post rather than by personal name, which the Act permits: what it requires is reachable business contact information.

Three product facts are the relevant ones. Evaluation is anonymous, so employers see ability before they see a person — which is data minimisation enforced by the pipeline rather than promised in a notice. Identity is released to one employer, on the candidate’s consent, and that consent is logged immutably. Export and erasure run through the privacy console rather than through a support queue.

Arihance Systems Private Limited is incorporated in India, so this is our home jurisdiction rather than an export market. That does not make us your compliance department: you are the Data Fiduciary for the candidate data you collect, and the notice, basis and retention decisions in your own process are yours.

Primary sources

The Act was passed in 2023 and its rules and Board have followed on their own timetable. Check the ministry rather than a summary, including this one.

What this page does not do

It is not legal advice. Whether "employment purposes" as a legitimate use covers a given piece of candidate processing — as opposed to employee processing — is exactly the kind of question to put to Indian counsel rather than to a vendor page.

It does not cover the rules and notifications that follow the Act, which arrive on their own schedule and can change operational detail such as timelines and thresholds.

It does not address Significant Data Fiduciary obligations, which apply to entities the Government designates as such and bring additional duties including a Data Protection Officer based in India.

It does not make CalHire your Data Fiduciary. For the candidate data you collect in your own hiring process, that is you.

Compliance with DPDP says nothing about whether a screening process is fair. A perfectly lawful notice can sit on top of a filter that has never been validated against anything.

Questions people actually ask

Do we need consent to process candidate data in India?
Not necessarily — the Act allows processing for certain legitimate uses as well as on consent, and employment purposes is one of them. Where you do rely on consent it must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and as easy to withdraw as it was to give. Which basis you are relying on for candidate processing is a question worth settling with counsel rather than assuming.
How long can we keep an applicant’s data?
Until the purpose is served, at which point erasure is a duty rather than a request you wait for — unless retention is required by law. An indefinite talent pool is the common practice the Act is least comfortable with, so decide the retention period before you collect rather than after someone asks.
What is a Grievance Officer and do we need one?
It is the published contact a candidate approaches first with a complaint, and a Data Fiduciary must publish the details. A Data Principal is expected to exhaust that route before going to the Data Protection Board, which makes it your opportunity to fix something before it becomes a regulatory matter. It can be a post rather than a named individual — what matters is that the contact is published and reachable.
Is DPDP basically India’s GDPR?
Close enough to be useful as orientation and different enough to be dangerous as a shortcut. The structure is familiar — notice, basis, rights, processors under contract — but the vocabulary differs, the legitimate uses are drawn differently, there is no separate special-category regime in the same shape, and the enforcement architecture is its own.
Does anonymous screening help with DPDP?
It helps with the part most employers find hardest, which is minimisation. If ability is established before identity is collected, there is simply less personal data in the process that has to be notified, secured, retained and then erased. That is a structural reduction rather than a policy commitment.
Who is the Data Fiduciary for a candidate on CalHire?
For candidate data on the platform, CalHire is. For the candidate data you collect and process in your own hiring workflow, you are. Both can be true at once, which is why your own notice and retention decisions are not discharged by ours.

Where this connects to the rest of the platform.

  • Hiring in India

    Enormous applicant volume, heavy credential signalling, and a data protection act that changed what consent means for candidate data.

  • The UAE PDPL and candidate data

    The UAE’s federal personal data protection law covers candidate data like any other personal data — consent, purpose limitation and data-subject rights — and the financial free zones run their own regimes on top.

  • Anonymous candidate screening

    Employers evaluate candidates with no name, photo, age, school or employer attached, because that information is never sent rather than merely hidden.

Read the reasoning

The evidence and the argument behind what is on this page.

Compliance9 min read

GDPR and candidate data: what recruiting teams get wrong

Consent is usually the wrong lawful basis for recruitment. What to rely on instead, how long to keep applications, and the rules on automated decisions.

Read
Candidate Guide8 min read

Does an ATS really reject your résumé? What actually happens

The "75% of résumés are rejected by robots" claim has no verifiable source. What an ATS actually does, where filtering happens, and what to do.

Read
Hiring Playbook7 min read

Dropping the degree requirement: what has to replace it

Removing a degree requirement without replacing the signal makes hiring more subjective, not less. What the degree was doing, and what to measure instead.

Read

Browse all topics on the blog

See a verified pipeline for one of your roles

Post a role free and review anonymous, skill-ranked candidates. No card, no sales call to get started.