If you are lead HR or talent acquisition at your company, you’ve probably asked yourself a version of this question recently:
"We run background checks on every single new hire. Does the DPDP Act mean we have to change our entire recruitment process?"
The short answer is - no need to change the background verification process . But the way your team handles candidate data and the way your third-party background verification (BGV) vendors store and process those files will need closer review.
Most legal summaries of the DPDP (Digital Personal Data Protection) Act focus on heavy corporate jargon and headline-grabbing fines. But for HR teams, compliance comes down to a few basic, practical adjustments.
Here is what you actually need to know.
What Is the DPDP Act in Simple Terms?
At its core, the Digital Personal Data Protection (DPDP) Act is India’s data privacy law. It sets rules for how organisations collect, use, store and share a person’s personal data.
In the past, many companies treated candidate information as something they could simply collect and keep once it was submitted - resumes, ID proofs, salary slips and other documents.
The DPDP Act brings more accountability to how that information is handled. Organisations need to have a clear purpose for collecting personal data, handle it responsibly, protect it appropriately and retain it only as required.
Where Does Policy Stand Right Now?
To understand how urgently your team needs to review your processes, it helps to look at the official implementation roadmap:The Rules Are Official: The Ministry of Electronics and Information Technology (Meity) notified the official DPDP Rules, establishing the Data Protection Board of India and setting the implementation roadmap.
The Transition Window (Where We Are Now): The government established a phased implementation schedule. Rule 4, relating to Consent Managers, takes effect in November 2026.
Remaining Substantive Provisions: The remaining provisions of the Act and Rules are scheduled to take effect in May 2027, bringing the wider operational requirements of the framework into effect.
This means you do not need to panic, but you cannot afford to delay. Setting up compliant vendor contracts, reviewing retention practices and updating candidate-facing processes takes time.What the DPDP Act Actually Means for HR
At its core, the law establishes stronger rights and protections around personal data and places clear responsibilities on organisations processing it.
When job applicants share their PAN cards, degree certificates, payslips, and past employment details, HR teams need to understand why that information is being collected, how it will be used, who it will be shared with and how long it needs to be retained.
That puts three basic principles in place for every background screening process:
Clear Notice: Candidates should be clearly informed about the relevant processing of their personal data and the purpose behind it.Specific Use: Verification information should be handled for defined and legitimate purposes rather than being reused for unrelated purposes.No Indefinite Storage: Background check reports should not simply sit on your servers or vendor portals indefinitely. Organisations should have a structured approach to retention and deletion based on the purpose and applicable requirements.
Fullscan - India's First AI-Powered BGV Platform
No more slow background checks. Fullscan’s AI-powered platform verifies candidates in hours, not weeks, backed by real expertise, so you hire with confidence.
The Catch: You Are Responsible for What Your Vendors Do
This is where many HR leaders face their biggest exposure.
Most companies rely on third-party BGV agencies for background checks, while some use external providers for specific checks such as court records or police verification.
Under the DPDP Act:
Your company is the "Data Fiduciary" - the party that determines the purpose and means of processing personal data.
Your verification vendor may act as a "Data Processor" - an external party processing personal data on behalf of the organisation.
The organisation remains responsible for compliance where personal data is processed on its behalf by a Data Processor.
If your verification partner experiences a server breach, exposes candidate records, or holds onto old background reports for years "just in case," your organisation needs to understand what happened, what controls were in place and what action is required.
If a candidate asks, "Why does your verification vendor still have my bank statement from three years ago?", your HR and leadership team should be able to explain how that information was handled and why it was retained.
3 Practical Steps to Audit Your BGV Process This Week
1. Review Your Vendor Contracts
Pull your active agreements with all background screening agencies and inspect the data retention clauses.
Are they bound to delete candidate records after completing the check? Or are they storing files indefinitely on legacy servers?
If the contract is silent on data retention or destruction, review the agreement and address the gap appropriately.
2. Upgrade to a Plain-Language Candidate Notice
Replace lengthy legal disclaimers with a clear, direct candidate-facing notice that explains:
The exact checks being conducted, such as employment history, criminal antecedents or education verification.The reason those checks are required for the role.How the candidate's information will be handled and the applicable retention approach.
The exact process and wording should reflect the organisation's applicable legal basis and privacy requirements.
3. Track Sub-Processors and Field Vendors
Many BGV companies pass physical address verifications or local court checks to regional sub-agents.
Ask your primary vendor to disclose the other parties that handle your candidates' personal information and confirm how those parties are expected to secure and handle that data.
The Real Risk Isn't Just Fines - It's Candidate Trust
While government penalties grab attention, the impact isn't limited to regulatory penalties.
Poor handling of candidate information can also affect employer reputation and candidate trust.
Top talent - especially mid-to-senior professionals, increasingly expects organisations to handle personal information responsibly. Demonstrating that your organisation treats candidate data with appropriate security and transparency sets a strong standard from day one and can contribute to a more trustworthy candidate experience.
Key Takeaway
The DPDP Act is not designed to stop companies from conducting thorough background checks or making secure hires. It requires organisations to manage personal data with clear boundaries, transparency and accountability.
Audit your vendor agreements, review your candidate-facing notices, check your data retention practices, and your HR team will be better prepared well ahead of the regulatory deadlines.
FAQs
What should HR check with BGV vendors under the DPDP Act?
HR teams should check data collection, storage, access, retention, deletion, sub-processors and security controls. Vendor contracts should also clearly address responsibilities for handling candidate personal data. Who is responsible for candidate data when BGV is outsourced?
The organisation remains responsible for ensuring that outsourced personal-data processing is appropriately governed. HR should therefore understand how the BGV vendor and its relevant third parties handle candidate information. Should HR update its candidate privacy notice?
Yes, HR teams should review their candidate notices. The notice should clearly explain what personal data is collected, why it is processed and the relevant information candidates need about their data. What candidate data should HR review for DPDP compliance?
HR should review resumes, identity documents, education records, employment details, addresses, salary documents and BGV reports to determine why each category is collected, who receives it and how long it is retained.