Eighteen months into its rollout, roughly 83% of Indian organisations still haven’t begun serious DPDP Act compliance work. That gap is about to matter a great deal more.
MeitY is currently consulting industry on a proposal to shorten the compliance window for larger organisations from eighteen months to twelve. The change hasn’t been formalised yet, but it’s being actively discussed in the press right now, and it would pull the deadline for readiness considerably closer than most HR teams have planned for.
Recruitment sits at the centre of this exposure in a way most compliance conversations still underweight. A hiring process collects more personal data, and more sensitive personal data, than almost any other business function touches on a routine basis: resumes, salary history, identity documents, background check results, sometimes biometric or health information.
This guide sets out what the DPDP Act actually requires, and a practical checklist for HR teams working out where their own hiring process stands.
What the DPDP Act Actually Requires
The Digital Personal Data Protection Act, passed in 2023 and brought into force through Rules notified on 14 November 2025, is India’s first comprehensive data protection law. It establishes a consent-centric framework.
Organisations, called data fiduciaries under the Act, must obtain clear, specific consent before collecting personal data. That data can only be used for the purpose stated, and must be deleted once that purpose no longer applies.
The Act applies to every business processing personal data in India, regardless of size or sector. There is no small-company exemption and no industry carve-out. A ten-person startup collecting candidate resumes carries the same underlying obligations as a listed enterprise running a national hiring programme, even if the practical scale of the risk differs considerably.
The Data Protection Board of India oversees enforcement, investigating breaches and issuing penalties, with appeals routed through the Telecom Disputes Settlement and Appellate Tribunal. Serious violations, particularly failures in basic security safeguards, carry penalties of up to ₹250 crore per violation, and penalties can stack across multiple failures arising from the same incident.
Why HR Teams Carry More Exposure Than They Realise
Data protection conversations in most Indian businesses still centre on marketing consent and IT infrastructure. HR sits underneath a comparable, and in some ways larger, layer of risk that gets far less boardroom attention.
Candidate data arrives before any formal employment relationship exists, often through third-party job boards, recruitment agencies or applicant tracking systems a company doesn’t fully control. Background verification adds identity documents, criminal record checks and, for some roles, credit history.
Attendance and access systems increasingly rely on biometric data. Benefits administration touches health information. HR teams are frequently the ones handling all of this day to day, without always being the ones setting the compliance policy around it.
This matters more now than it did a year ago. Senior leadership accountability has become a defining feature of how the DPDP Act is expected to be enforced. Privacy risk is increasingly treated as a board-level concern, alongside financial and operational risk.
An HR team collecting candidate data without a properly designed consent process isn’t just creating a compliance gap. It’s creating a board-level exposure that happens to sit inside recruitment.
The Timeline HR Teams Need to Track Right Now
The DPDP Act’s rollout is happening in stages, and several of the most relevant milestones for HR fall in the next twelve months.
Full enforcement, including the Board’s complete adjudicatory powers, is expected from 13 May 2027.
The proposal to shorten the compliance window for larger organisations to twelve months is still under consultation, not yet confirmed. It’s a live development worth tracking closely rather than assuming the original eighteen-month runway will hold.
A Practical Compliance Checklist for Hiring
Consent needs to be its own explicit step, never bundled into an offer letter or buried in a generic terms-and-conditions checkbox. A line reading “by applying, you consent to background checks” attached to an offer letter doesn’t meet the Act’s standard for informed, specific consent. This is one of the most common failures in background verification specifically.
The checklist below covers the areas most likely to expose a hiring process:
- Separate, explicit consent at each stage of data collection, never bundled into an offer letter or a generic checkbox.
- Defined and enforced retention limits for resumes, interview notes and background check reports, especially for candidates who weren’t hired.
- Data processing agreements with every vendor touching candidate data: job boards, background verification providers, assessment platforms, staffing agencies.
- A higher standard of care for biometric and health data, wherever they appear in hiring or onboarding.
- A cross-border transfer check for any part of the recruitment stack, an ATS, an assessment tool, an HR platform, that stores or processes data outside India.
- A tested breach response plan, since serious incidents require notification within a tight window.
Retention limits deserve particular attention, since a policy that exists only on paper rarely holds up in practice. Resumes and background check reports sitting indefinitely in a shared drive or an old recruiter’s inbox are exactly the kind of gap regulators are expected to look for.
Vendor accountability matters just as much. The responsibility for a vendor’s compliance gap doesn’t disappear once the vendor is technically the one holding the data.
What Getting This Wrong Actually Costs
The financial exposure is enough to change how a board thinks about hiring infrastructure, not just how a compliance officer thinks about it. Penalties reaching ₹250 crore for a single serious violation, with the possibility of stacked penalties across multiple failures tied to one incident, sit well outside what most HR budgets are built to absorb.
The reputational cost of a well-publicised breach involving candidate data tends to outlast the financial one considerably.
The less visible cost is slower and just as real. A hiring process candidates don’t trust with their data becomes a hiring process strong candidates start avoiding, particularly once a breach or a mishandled complaint becomes public. Compliance here isn’t purely a legal exercise. It’s also, increasingly, a candidate experience one.
Compliance Doesn’t Stop at the Recruiter’s Door
None of this responsibility sits with a single party by default. A recruitment partner handling candidate data on a client’s behalf, sourcing, screening, background verification, carries real accountability for how that data is collected, stored and eventually deleted, not just the client whose name appears on the job posting.
Explicit, purpose-specific consent at every stage, clear retention limits instead of indefinite storage, and straightforward transparency about what’s collected and why should be table stakes for any hiring partner in 2026, not a differentiator worth advertising.
Any business evaluating a recruitment partner is well within its rights to ask a direct question about DPDP compliance before signing anything. A partner unable to answer clearly isn’t one worth the exposure, however strong the candidate pipeline looks on paper.