India’s DPDP Act and candidate data
India’s first comprehensive data protection statute, and the one most likely to surprise an employer that assumed a recruitment database was theirs to keep indefinitely.
The Digital Personal Data Protection Act 2023 governs digital personal data in India. An employer processing candidate data is a Data Fiduciary and must give an itemised notice of what is collected and why, have a lawful basis — consent, or a legitimate use such as employment purposes — and honour rights of access, correction, erasure and grievance redressal. A Grievance Officer’s contact details must be published. Personal data must be erased once the purpose is served, unless retention is legally required.
Last reviewed
The short version
- The vocabulary is its own: Data Fiduciary (controller), Data Processor, Data Principal (the person). Mapping it to GDPR terms gets you most of the way, not all of it.
- Consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action — and withdrawable as easily as it was given.
- "Employment purposes" is a legitimate use that can cover processing without consent, but its edges around CANDIDATES rather than employees are the part to take advice on.
- Erasure is a duty, not only a right: once the purpose is served, the Data Fiduciary must erase unless law requires retention.
- A published Grievance Officer is mandatory. Not an inbox that reaches someone eventually — a published contact.
The terms the Act actually uses
Reading DPDP with GDPR vocabulary in your head works until it quietly does not. These are the four that matter for hiring.
- Data Fiduciary
- The person who alone or with others determines the purpose and means of processing personal data. An employer deciding to screen candidates is a Data Fiduciary. The word is doing deliberate work: a fiduciary holds something on someone else’s behalf.
- Data Principal
- The individual the data relates to — the candidate. Where the individual is a child, the parent or lawful guardian. The Act attaches the rights to this person and the duties to the fiduciary.
- Notice
- An itemised description of the personal data being collected and the purpose of processing, given at or before the point of collection, along with how to exercise rights and how to complain to the Board. Itemised is the operative word: a general privacy policy paragraph is not a notice.
- Grievance Officer
- The contact a Data Principal goes to first with a complaint, whose details a Data Fiduciary must publish. A Data Principal is expected to exhaust this route before approaching the Data Protection Board.
What an employer hiring in India has to get right
In rough order of how often it is missed rather than how the Act lists it.
- 1
Give an itemised notice at collection
What data, for what purpose, how to exercise rights, and how to complain. At or before collection — not on the offer letter, and not only in a policy linked from a footer.
- 2
Establish the basis, and be able to say which
Consent, or a legitimate use. If you are relying on consent it must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and withdrawable as easily as it was given.
- 3
Decide your retention period before you collect
This is the one that catches recruitment. Erasure is a duty once the purpose is served. A talent pool kept indefinitely "in case something comes up" needs a basis that survives the question "what purpose is still being served here?".
- 4
Publish a Grievance Officer
Reachable contact details, published, with a process behind them. It is the route a candidate is expected to use before going to the Board, which makes it your chance to resolve something.
- 5
Bind your processors by contract
A Data Fiduciary may engage a processor only under a valid contract, and remains responsible for compliance regardless of any arrangement with the Data Principal. Your ATS and your assessment vendor are processors.
Why volume makes this sharper in India than elsewhere
Indian hiring runs at a scale most markets do not see: a graduate role can attract thousands of applications, and the standard response has been to filter on institution tier and marks because a human cannot read them all.
That produces two problems the DPDP Act now attaches consequences to. The first is volume of retained data — a proxy filter still requires collecting everything from everyone, and the retained pile grows with every campaign. The second is that the filter is a poor predictor, so the data is collected, kept and then used for something it does not support well.
A verified assessment changes the arithmetic rather than the paperwork. If ability is established before identity is collected, the amount of personal data that has to exist to run a screening round drops — and data minimisation stops being a policy you write and becomes a shape your process already has.
Where CalHire sits, stated plainly
For candidate data on this platform, CalHire is the Data Fiduciary and our Grievance Officer contact is published in the Privacy Policy rather than described here. The officer is identified by post rather than by personal name, which the Act permits: what it requires is reachable business contact information.
Three product facts are the relevant ones. Evaluation is anonymous, so employers see ability before they see a person — which is data minimisation enforced by the pipeline rather than promised in a notice. Identity is released to one employer, on the candidate’s consent, and that consent is logged immutably. Export and erasure run through the privacy console rather than through a support queue.
Arihance Systems Private Limited is incorporated in India, so this is our home jurisdiction rather than an export market. That does not make us your compliance department: you are the Data Fiduciary for the candidate data you collect, and the notice, basis and retention decisions in your own process are yours.
Primary sources
The Act was passed in 2023 and its rules and Board have followed on their own timetable. Check the ministry rather than a summary, including this one.
- Digital Personal Data Protection Act 2023 and the data protection frameworkMinistry of Electronics and Information Technology, Government of India
What this page does not do
It is not legal advice. Whether "employment purposes" as a legitimate use covers a given piece of candidate processing — as opposed to employee processing — is exactly the kind of question to put to Indian counsel rather than to a vendor page.
It does not cover the rules and notifications that follow the Act, which arrive on their own schedule and can change operational detail such as timelines and thresholds.
It does not address Significant Data Fiduciary obligations, which apply to entities the Government designates as such and bring additional duties including a Data Protection Officer based in India.
It does not make CalHire your Data Fiduciary. For the candidate data you collect in your own hiring process, that is you.
Compliance with DPDP says nothing about whether a screening process is fair. A perfectly lawful notice can sit on top of a filter that has never been validated against anything.
Questions people actually ask
Do we need consent to process candidate data in India?
How long can we keep an applicant’s data?
What is a Grievance Officer and do we need one?
Is DPDP basically India’s GDPR?
Does anonymous screening help with DPDP?
Who is the Data Fiduciary for a candidate on CalHire?
Related
Where this connects to the rest of the platform.
Hiring in India
Enormous applicant volume, heavy credential signalling, and a data protection act that changed what consent means for candidate data.
The UAE PDPL and candidate data
The UAE’s federal personal data protection law covers candidate data like any other personal data — consent, purpose limitation and data-subject rights — and the financial free zones run their own regimes on top.
Anonymous candidate screening
Employers evaluate candidates with no name, photo, age, school or employer attached, because that information is never sent rather than merely hidden.
Read the reasoning
The evidence and the argument behind what is on this page.
GDPR and candidate data: what recruiting teams get wrong
Consent is usually the wrong lawful basis for recruitment. What to rely on instead, how long to keep applications, and the rules on automated decisions.
ReadDoes an ATS really reject your résumé? What actually happens
The "75% of résumés are rejected by robots" claim has no verifiable source. What an ATS actually does, where filtering happens, and what to do.
ReadDropping the degree requirement: what has to replace it
Removing a degree requirement without replacing the signal makes hiring more subjective, not less. What the degree was doing, and what to measure instead.
ReadSee a verified pipeline for one of your roles
Post a role free and review anonymous, skill-ranked candidates. No card, no sales call to get started.