DPDP Act 2023 Compliance for Recruitment: What Companies and Agencies Must Know
Hiringseed Team · 19 August 2026
Why the DPDP Act matters for recruitment
The Digital Personal Data Protection (DPDP) Act, 2023 is India's first comprehensive data protection law. For recruitment companies, staffing agencies, and HR teams, it changes how candidate data must be collected, stored, and shared.
Recruitment is inherently data-intensive. A single hiring process involves collecting resumes, contact details, salary information, employment history, and sometimes identity documents. This data is shared between recruiters, companies, and sometimes third-party background verification services.
Under the DPDP Act, every entity that processes personal data is either a Data Fiduciary (the one who decides why and how data is processed) or a Data Processor (the one who processes data on behalf of a Fiduciary). Most recruitment companies are Data Fiduciaries — and that comes with significant obligations.
Key requirements for recruitment companies
Here are the DPDP Act requirements most relevant to recruitment:
1. Consent (Section 6): You must obtain free, specific, informed, and unambiguous consent from candidates before collecting their data. A general "by submitting your resume, you agree" is no longer sufficient. Consent must be obtained through a clear affirmative action.
2. Purpose limitation: Candidate data collected for one role cannot be used for unrelated purposes without fresh consent. If a candidate applies for a Java developer role, you can't use their data to pitch them insurance products.
3. Data minimisation: Collect only what you need. Asking for Aadhaar numbers, family details, or religion during initial screening is unnecessary and now legally risky.
4. Right to erasure (Section 12): Candidates can request deletion of their data. You must have a process to handle this within 30 days.
5. Data breach notification (Section 8(6)): If candidate data is breached, you must notify the Data Protection Board within 72 hours.
Practical steps for compliance
Here's a practical compliance checklist for recruitment companies:
Consent management: - Add explicit consent checkboxes to all candidate registration forms - Keep records of when and how consent was obtained - Make consent withdrawal as easy as giving it
Data storage: - Store candidate data on servers within India (Section 16 restricts cross-border transfers to countries not blocked by the Central Government) - Encrypt data in transit and at rest - Implement role-based access controls — not everyone in your team needs access to every candidate's salary details
Retention policies: - Define clear retention periods: how long do you keep a candidate's resume after the role is filled? - Hiringseed retains candidate data for 12 months after the hiring process ends, unless the candidate requests earlier deletion - Set up automated deletion or anonymisation when the retention period expires
Candidate rights: - Create a clear process for data access, correction, and deletion requests - Appoint a Grievance Officer (mandatory under Section 8(10)) - Respond to requests within 30 days
Common mistakes to avoid
The most common DPDP compliance mistakes in recruitment:
1. Sharing resumes without consent: Recruiters often forward candidate resumes to companies without explicit candidate consent for that specific role. Under the DPDP Act, this is a violation. Always get role-specific consent.
2. Indefinite data retention: Many agencies keep candidate databases forever. The DPDP Act requires data to be deleted when the purpose is fulfilled. Define and enforce retention periods.
3. No breach notification process: Most recruitment companies don't have an incident response plan. A data breach — even an employee accidentally emailing resumes to the wrong company — triggers the 72-hour notification requirement.
4. Ignoring children's data: Section 9 prohibits processing children's (under 18) data without verifiable parental consent. If you recruit interns or apprentices, verify ages.
5. No grievance officer: This is mandatory, not optional. It can be an existing employee designated for this purpose.
How Hiringseed handles DPDP compliance
Hiringseed is operated by Arhamin Innovations Private Limited, a registered Data Fiduciary under the DPDP Act, 2023. Here's how we handle compliance:
- Affirmative consent: All users (companies, recruiters, and candidates) provide explicit consent at registration through a clear checkbox with links to our Privacy Policy.
- Cookie consent banner: Non-essential cookies are only placed after explicit user consent.
- Purpose-limited sharing: Candidate data is shared only with the company posting the specific role the candidate was submitted for.
- Defined retention periods: Account data (90 days after closure), candidate profiles (12 months), payment records (7 years per tax law), analytics (24 months anonymised).
- Unified data rights process: One email to [email protected] for access, correction, deletion, or consent withdrawal. 48-hour acknowledgment, 30-day resolution.
- Grievance officer appointed and accessible via the Privacy Policy.
For recruitment companies using Hiringseed, this means a significant portion of your DPDP compliance is handled at the platform level. Your primary responsibility is ensuring you have candidate consent before submitting their profiles — and our submission flow enforces this.