Skip to content
Highring
Staffing Solutions•9 October 2026
10 min read

DPDP Act for Recruiters: What Hiring Teams and Agencies Must Do Before May 2027

DPDP Act for Recruiters: What Hiring Teams and Agencies Must Do Before May 2027

Hiring runs on personal data. A single candidate profile can carry a name, phone number, email, address, work history, current salary and expected salary. That profile is often forwarded across email, WhatsApp and spreadsheets, passes through one or more agencies, and ends up with several people at the hiring company.

India's Digital Personal Data Protection (DPDP) Act was built for exactly this kind of data flow. The rules that make it enforceable were notified in November 2025, and the clock is already running. This guide explains what it means for hiring teams and recruitment agencies, in plain language.

This article is general information, not legal advice. Talk to a qualified lawyer about your own situation.

The timeline

The DPDP Rules, 2025 were published on 13 November 2025 and apply in phases.

When What starts
November 2025 Parts of the Act come into force, including the setup of the Data Protection Board of India
November 2026 Registration of consent managers begins
13 May 2027 The main obligations for companies start: notice and consent, security safeguards, breach reporting, candidate rights, and the penalty provisions

For a hiring team, the real deadline is May 2027. That is about seven months away, and hiring processes take time to change.

Who is who in a hiring process

The Act uses three terms. Here is how they map to recruitment.

  • Data Principal: the candidate. It is their data.
  • Data Fiduciary: whoever decides why and how the data is used. A company is a fiduciary for the candidates it hires. An agency is a fiduciary for the candidate database it builds for itself.
  • Data Processor: anyone who handles data on behalf of a fiduciary under a contract, such as an applicant tracking system or a background check provider.

Roles depend on the facts. An agency can be a fiduciary for its own database and still act on behalf of a client for a specific role. The Act does not put direct duties on processors. Instead, the fiduciary must make sure processors comply, through written contracts.

What gives you the right to use candidate data

The Act allows processing in two main ways: with the person's consent, or under a "legitimate use" that does not need consent.

Two legitimate uses matter in hiring:

  1. Voluntary submission for a specified purpose. If a candidate sends a resume to be considered for a job and has not objected, using it for that purpose is allowed.
  2. Employment related purposes. The Act recognises certain employment uses. Lawyers note one open question: how far this covers candidates who have not yet become employees.

Given that uncertainty, the safe habit is simple. Use the data only for the role the candidate applied for. For anything beyond that, give a clear notice and get consent. That includes:

  • keeping a profile in a talent pool for future roles
  • sharing a profile with other client companies
  • running background checks
  • passing data to another company or country

Nine duties to build into your process

1. Map your candidate data. List every place candidate data lives: email inboxes, WhatsApp groups, shared drives, spreadsheets, your applicant tracking system. You cannot protect what you cannot find.

2. Give a clear notice. Tell candidates what you collect, why, who will see it, how long you will keep it, and how to withdraw consent or ask a question. Use plain language, not legal text.

3. Record consent where you need it. Keep a record of who agreed to what, and when. If you rely on consent, the Act puts the burden on you to prove that a notice was given and consent was taken. Consent must also be specific, so a single blanket checkbox is weak.

4. Collect only what you need at each stage. You may need skills and notice period at screening. You rarely need identity documents or full salary slips that early.

5. Secure the data. The Act requires reasonable security safeguards. In practice that means access controls, encryption, activity logs and backups. It also means no resumes sitting in personal inboxes or on shared phones.

6. Have a breach plan. Under the Rules as notified, you must tell the Data Protection Board and affected people without delay, and send the Board a detailed report within 72 hours (the Board can allow longer on a written request). Decide today who does what.

7. Decide how long you keep data, and delete it. The Act requires you to erase personal data when consent is withdrawn, or as soon as it is reasonable to assume the purpose is no longer served, unless a law requires you to keep it. It does not fix a number of months for candidate data. Choose a period you can justify, such as a set number of months after a role closes, and delete when it ends or when a candidate asks.

8. Put contracts in place. Every service provider that handles candidate data for you needs a written agreement covering security, limits on use, and deletion.

9. Handle candidate rights. Candidates can ask what data you hold, ask for corrections, ask for deletion, and raise complaints. Name a contact person and answer within the time the Rules set for grievances.

What the penalties look like

The Act lists maximum penalties in a Schedule. The two that matter most for hiring teams are failing to keep reasonable security safeguards, which can carry a penalty of up to ₹250 crore, and failing to report a data breach, which can carry up to ₹200 crore.

Three things are worth knowing before you worry about those numbers:

  • They are ceilings, not usual fines. The Board can penalise only a breach it finds significant, and it must weigh factors such as how serious and how long the breach was, what data was involved, and what you did to limit the harm.
  • They are not live yet. The penalty provisions start together with the main obligations in May 2027.
  • They can change. The Act lets the Central Government amend the Schedule, up to twice the original amounts. Check the current text before you quote a figure: the Act on India Code.

The practical message is simple. The law puts its weight on protecting data and telling people when it is lost.

What this means for recruitment agencies

Agencies handle more candidate data than almost anyone in the hiring chain, and many still run on personal email and WhatsApp. Three habits are worth fixing first:

  • Get the candidate's agreement before submitting them to a client. It is good recruiting practice and it matches the Act's idea of a specified purpose.
  • Stop circulating resumes in open groups. Share a profile only with the people who need it for that role.
  • Know what you hold. If a candidate asks you to delete their data, you should be able to find it in minutes, not days.

Where a platform helps

A structured hiring platform makes several of these duties easier. There is one place for access controls, one record of who has seen a profile, and one place to delete data when asked. A recruitment agency marketplace also keeps submissions in one system instead of scattering them across inboxes.

A platform does not make you compliant on its own. You stay responsible for your notices, your consent records and your contracts. But moving off email and chat groups is one of the largest single steps you can take.

A simple plan for the next seven months

  • Now to December 2026: map where candidate data lives, and draft a candidate notice and consent wording.
  • January to March 2027: tighten access and security, set a retention period, and sign written agreements with service providers.
  • April to May 2027: run a mock breach and a mock deletion request, so your team has practised before it counts.

The bottom line

The DPDP Act does not stop you from hiring. It asks you to know what candidate data you hold, use it only for the purpose it was given for, protect it, and tell people when it goes wrong. Teams that start now will reach May 2027 with a process that is both safer and easier to run.

Official sources

Laws and rules can be amended, so always check the current text.


See how a recruitment agency marketplace keeps candidate submissions in one place. Book a free 20-minute demo.

Highring is a recruitment agency marketplace for companies and agencies. We are not a job board and do not accept direct resumes from candidates. This article is for general information only and is not legal advice.