Recruitment Data Privacy: Five DPDP Duties Every Hiring Team Owns (2026)
India's DPDP Rules landed in November 2025 and recruiting holds more personal data than any other function.
India's DPDP Rules started an 18-month clock in November 2025. The five duties recruiting owns, defensible retention windows, and the penalty ceilings.

TL;DR
Recruitment data privacy became an operational problem for Indian hiring teams on 13 November 2025, when the Digital Personal Data Protection Rules were notified and started an eighteen month implementation clock that runs out in mid-May 2027. Recruiting is the most exposed function in most companies, because it collects the largest volume of personal data from people who never become employees and who nobody remembers to delete. The penalties are set in rupees rather than as a share of turnover, and the ceiling for a security failure is ₹250 crore. If your screening stack is also making decisions, pair this with our AI hiring compliance guide.
What is actually happening
India's Digital Personal Data Protection Act passed in 2023 but sat without operative rules for two years. That changed on 13 November 2025, when the Ministry of Electronics and Information Technology notified the DPDP Rules, 2025 through Gazette notification G.S.R. 846(E).
The Rules did not switch everything on at once. Most day to day obligations, including notice and consent mechanics, breach reporting and handling of individual rights requests, phase in across roughly eighteen months, with full compliance expected by the middle of 2027. That sounds generous until you count the systems involved.
Recruitment is unusual because of the ratio. A company hiring 200 people a year might collect résumés, contact details, identity documents and interview recordings from ten or twenty thousand applicants, and 99% of those people never join. Employment law gives you reasons to keep employee records for years, but it gives you very little reason to keep the rejected pile indefinitely.
The Act also treats employment differently from marketing. Processing personal data for purposes connected to employment sits within the legitimate uses framing, which means standard recruitment, onboarding and payroll activity generally does not require a separate consent flow in the way a newsletter signup does. That is a relief on the consent side and it changes nothing about security, retention or vendor contracts.
Those are the three places recruiting teams are actually exposed. Applicant data usually sits in an ATS, a sourcing tool, a scheduling tool, an assessment vendor, a background check provider and a shared drive nobody has audited since 2023.
The numbers
Two number sets matter here and they pull in opposite directions. The DPDP penalty schedule tells you the ceiling, and retention guidance tells you the discipline that keeps you away from it.
On retention, the GDPR is the more mature reference point and it does not name a fixed period for candidate data. What exists is supervisory authority guidance and settled market practice, which cluster at six to twelve months for unsuccessful applicants, with longer holds for talent pools where the candidate has actually agreed to it. The DPDP framework works on the same principle: keep data while the specified purpose lasts, then erase it.
The penalty side is blunter. The Schedule to the DPDP Act sets fixed rupee ceilings rather than turnover percentages: up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to notify a breach, up to ₹150 crore for breaches of the additional duties placed on Significant Data Fiduciaries, and up to ₹50 crore as a residual category.
How to read this chart:
- These are retention windows, not statutory maximums. Neither the GDPR nor the DPDP Act fixes a number for candidate data, so treat the bars as defensible practice you would have to justify, rather than a safe harbour.
- The low end of each band is the conservative position and the high end is the outer edge of common practice. Sitting above the high end without a documented reason is where teams get into difficulty.
- Consent extends the purpose, not the principle. A candidate agreeing to a talent pool does not let you keep the file forever, and a withdrawal has to actually delete something.
How it actually works, and where it breaks
The Act's structure is simple once you translate the vocabulary. Your company is the Data Fiduciary, the candidate is the Data Principal, and every vendor that touches applicant data on your behalf is a Data Processor whose obligations flow through your contract with them.
The first failure mode is the retention hole. Almost every ATS is configured to keep everything forever, because that is the default and because nobody wants to be the person who deleted a record. Purpose limitation means the opposite: once a requisition closes and the appeal window passes, the reason for holding a rejected applicant's identity documents has expired.
The second is the shadow copy. Candidate data leaks out of the ATS into spreadsheets, WhatsApp threads, mailbox attachments and sourcing tools, and a deletion request served on the ATS does not reach any of them. When a Data Principal asks for erasure, an answer that covers only the system of record is not an answer.
The third is the processor contract nobody wrote. The Rules expect vendor arrangements to carry data protection obligations, confidentiality, security safeguards and breach reporting duties. Recruiting buys a lot of point tools on credit cards and self-serve plans, and those agreements usually contain none of that.
The fourth is quieter and it interacts with automation. If your stack scores or ranks applicants, the data protection question and the fairness question arrive together, and teams often answer only one of them. Our note on AI resume screening in India covers the screening half of that problem.
"Recruiting is the only function that collects personal data from thousands of people it will never employ and then forgets it did."
What this means for your team
None of this requires a privacy team. It requires someone in recruiting operations to spend a few weeks doing unglamorous inventory work before the deadline arrives, in roughly this order.
These are the five duties a talent function actually owns, in the order that makes each of the next ones cheaper.
- Map where applicant data lives. List every tool, drive, inbox and spreadsheet holding candidate information, and name an owner for each. Most teams find between six and fifteen locations, and the surprises are usually mailboxes and personal drives.
- Write a retention schedule and automate it. Decide a window per category, defend it in one sentence each, then configure automatic deletion. A schedule nobody enforces is worse than no schedule, because it documents the gap.
- Fix the notice. Candidates should be told what you collect, why, how long you keep it and how to ask for erasure, in language a person can read at the point of application rather than buried in a careers page footer.
- Paper the vendors. Add data protection, confidentiality, security and breach reporting terms to every processor that touches applicant data, including the small self-serve tools.
- Rehearse a breach and a deletion request. Both are timed exercises under pressure. If you have never tried to fulfil an erasure request across every system on your map, you do not know whether you can.
Teams running high applicant volumes should sequence retention before anything else, because volume is what turns a small process gap into a large exposure. Our note on high volume hiring covers the operational side of that scale.
Recruitment data privacy vs bias compliance
These are separate obligations with separate owners, and conflating them leaves both half done. Bias compliance asks whether your process treats groups of candidates differently, and it is measured statistically after the fact. Data privacy asks what you collected, why you still have it, who else can see it and whether you can delete it on request.
A screening tool can be scrupulously fair and still be a privacy problem because it retains every applicant's identity documents for six years. A perfectly governed data estate can still produce discriminatory outcomes. Our guide to bias free hiring covers the fairness workstream, and the two programmes should share a data map but not an owner.
The overlap worth watching is automated decision-making, where a candidate may have rights about the decision itself as well as the data behind it.
How to actually do this (and the four traps)
Trap one: assuming the employment exemption covers everything. Processing for employment purposes is treated as a legitimate use, which helps enormously on consent. It does not relax the duties on security, retention, vendor contracts or breach notification, and those are where the large penalties sit.
Trap two: treating mid-2027 as the deadline. The phase-in ends then, but retention debt accrues from today. Every month you keep collecting applicant data without a deletion rule makes the eventual cleanup larger and the breach surface wider.
Trap three: deleting from the ATS only. Erasure has to reach the shadow copies, which means the data map has to exist before the first request arrives. Teams that skip the mapping step discover the gap while a clock is running.
Trap four: buying a tool to fix a process. Consent management platforms are useful once you know what you hold and why. Bought first, they add a layer of records over an estate nobody has mapped, and our note on budget AI recruitment tools is a reasonable reminder that tooling follows the process rather than replacing it.
"A retention rule is the rare compliance control that makes every other obligation cheaper the moment you switch it on."
The one thing every hiring leader should take from this
Ask your ATS administrator one question: what happens to a rejected applicant's file after twelve months. If the answer is that nothing happens, you have found both your largest privacy exposure and the cheapest thing to fix, because a retention rule is a configuration change rather than a project. Every other duty in the DPDP framework gets easier once the volume of data you are holding stops growing without limit. At TheHireHub we think that single question separates teams who will be ready in 2027 from teams who will be negotiating with a regulator, and we look at this stuff all day if you want help scoping it.
Frequently Asked Questions
The Digital Personal Data Protection Act, 2023 is India's general data protection law. It became operational when the DPDP Rules, 2025 were notified on 13 November 2025 via Gazette notification G.S.R. 846(E), starting a phased implementation of roughly eighteen months with full compliance expected by the middle of 2027.
Generally not in the way a marketing list requires it. Processing personal data for purposes connected with employment falls within the legitimate uses framing of the Act, so standard recruitment, onboarding and payroll handling does not need a separate consent flow. Notice, security, retention and vendor obligations still apply in full.
Neither the GDPR nor the DPDP Act fixes a number. Supervisory authority guidance and common market practice cluster at six to twelve months for unsuccessful applicants, with twelve to twenty-four months for talent pools where the candidate has agreed. The governing principle is that you keep data only while the purpose you collected it for still exists.
The Schedule sets fixed rupee ceilings rather than a percentage of turnover: up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to notify a breach, up to ₹200 crore for children's data obligations, up to ₹150 crore for the extra duties on Significant Data Fiduciaries, and up to ₹50 crore for other contraventions.
The employer is the Data Fiduciary because it determines why and how candidate data is processed. Applicants are Data Principals. Recruitment vendors, ATS providers, assessment platforms and background check firms act as Data Processors, and their obligations reach them through your contract.
Yes, though the role depends on the arrangement. An agency processing candidate data purely on a client's instructions is generally a Processor, while an agency building and marketing its own candidate database is determining its own purposes and is acting as a Fiduciary for that database.
What categories of data you collect, the purpose, how long you retain it, who it is shared with including named vendor categories, and how to exercise rights such as access and erasure. It should be readable at the point of application rather than buried in a careers page footer.
They stack rather than substitute. Data protection duties govern collection, retention, sharing and deletion, while fairness and oversight duties govern how a decision gets made. A screening tool can be compliant on one axis and exposed on the other, so the two reviews need separate owners and separate evidence.
Configure retention. Deleting applicant data you no longer need shrinks the breach surface, reduces the scope of every future erasure request and costs nothing but a configuration change, which makes it the highest-yield first move for almost every talent team.
That duty attaches to Significant Data Fiduciaries, a category the government designates based on factors including data volume and sensitivity, rather than to every company. Most mid-sized employers will not be designated, but all of them still need a named internal owner who can answer rights requests and coordinate breach reporting.


