14d free & 10% off for early users

Start trial
Back to Blog
Compliance 11 min read

DPDP Act for HR Teams — What You Must Know in 2026

A practical guide to India's Digital Personal Data Protection Act for HR: what applies to resume screening and AI interviews, vendor questions to ask, and a compliance checklist for 2026. Not legal advice.

DPDP Compliance HR Software India Data Protection

India's DPDP Act treats résumés, interview recordings, and AI-generated candidate scores as personal data — meaning HR teams need a documented lawful basis, retention limits, and vendor data processing agreements for every tool that touches candidate data, not just a line on a security page.

Why HR Teams Can't Ignore DPDP in 2026

India's Digital Personal Data Protection Act, 2023 (DPDP) is now part of how every company that processes candidate data must operate. Resume screening, AI interviews, background checks, and offer-stage workflows all touch personal data — names, contact details, employment history, and often inferences about skills, fit, or performance.

Under DPDP, you remain accountable as the data fiduciary even when a vendor runs the software. That means your ATS, your resume screening tool, and your AI interview platform all need to fit a documented compliance program — not just a checkbox on a security page.

This article is operational guidance for talent leaders; it is not legal advice. Involve qualified counsel for your specific program, especially if you process data at scale or across borders.

What Counts as Personal Data in Hiring

For HR teams, DPDP-relevant data typically includes:

  • Identifiers: name, email, phone, address, government ID (where collected)
  • Professional history: employment dates, employers, titles, education, certifications
  • Application artifacts: résumés, cover letters, portfolios, interview recordings and transcripts
  • Derived data: AI-generated scores, rankings, "fit" labels, and notes attached to candidates

If your screening stack processes any of this — and it does — DPDP applies. The question isn't whether you're in scope; it's whether your processes and contracts match what the law expects in 2026.

Core Principles HR Should Map to Resume Screening

1. Lawful Basis and Notice

Candidates should understand why their data is collected, what it will be used for, and how long it will be kept. Your careers page, application form, and privacy notice should align — vague "we may use AI" language isn't enough for informed candidates or audit readiness.

2. Purpose Limitation

Data collected for hiring should be used for hiring — not repurposed for unrelated marketing analytics, sold to third parties, or used to train public models without clear contractual boundaries. Map each vendor's data use in your Data Processing Agreement (DPA).

3. Data Minimization

Collect only what you need for the role. If you don't need date of birth at application stage, don't ask. If AI screening only needs work history and skills, avoid uploading unnecessary sensitive fields into tools that don't need them.

4. Security Safeguards

Encryption in transit and at rest, role-based access control, audit logs, and incident response plans are baseline expectations — especially when AI models process résumés and interview audio. See your vendor's security documentation and SOC 2 / ISO reports where available.

5. Data Principal Rights

Data principals (candidates) may request access, correction, or erasure in defined circumstances. Your HR ops team needs a process — not an ad-hoc email chain — for handling requests within statutory timelines.

6. Cross-Border Transfers

If candidate data is processed or stored outside India, understand transfer restrictions and contractual safeguards. Many Indian enterprises and startups now require India data residency for hiring data; verify where your vendor actually processes workloads, not just where they invoice from.

AI Screening and Interviews: Extra Scrutiny in 2026

Regulators and candidates increasingly expect transparency when AI influences hiring outcomes:

  • Explainability: Prefer tools that tie scores to rubric dimensions and evidence — not opaque pass/fail labels.
  • Human oversight: Document where AI recommends and humans decide. Fully automated rejection without review is a governance risk.
  • Bias monitoring: Periodically review score distributions by source channel, college tier, or geography. Patterns without business justification warrant investigation.
  • Retention of AI artifacts: Interview recordings and model outputs may have different retention rules than the résumé itself — define policies explicitly.

EchoHire's approach is rubric-first scoring with evidence citations — so hiring teams and candidates can understand what was evaluated, not just the number.

Vendor Checklist: 12 Questions Before You Sign

  1. Where is data processed and stored — India, EU, US, or multi-region?
  2. Do you provide a DPA aligned with DPDP expectations?
  3. What is default candidate data retention, and can we configure it?
  4. Can we export or delete candidate records on request?
  5. How do you handle data principal access/correction/erasure requests?
  6. Is there encryption at rest and in transit? What key management model?
  7. Who has access to candidate data on your side — and is it logged?
  8. Are subprocessors listed, and will we be notified of changes?
  9. Is AI training performed on our candidate data? Opt-in or opt-out?
  10. Do you support human-in-the-loop review for automated decisions?
  11. What certifications do you hold (SOC 2 Type II, ISO 27001, etc.)?
  12. What is your incident notification timeline and process?

Don't accept marketing answers — get contractual commitments in your DPA and security appendix.

Building Your 2026 HR Compliance Checklist

Use this as a starting point for internal audit:

  • [ ] Privacy notice and careers-page language updated for DPDP
  • [ ] Lawful basis documented for each hiring data flow
  • [ ] DPAs signed with ATS, screening, and interview vendors
  • [ ] Data retention schedule defined per data type
  • [ ] Process for data principal requests (owner + SLA)
  • [ ] Access control matrix for recruiters and hiring managers
  • [ ] AI governance doc: what is automated vs. human-decided
  • [ ] Cross-border / residency requirements verified with vendors
  • [ ] Annual vendor security review calendar

Common Mistakes Indian HR Teams Make

  1. Assuming the ATS vendor covers everything. Screening AI and interview tools are separate processors — each needs its own contract review.
  2. Ignoring derived data. Scores and rankings are personal data too; retention and deletion policies must include them.
  3. No erasure workflow. "We'll handle it manually" breaks at scale after campus drives or viral job posts.
  4. US/EU tools without residency clarity. Invoice address ≠ data location. Ask for architecture diagrams.

Why This Is a Competitive Advantage

Beyond compliance, DPDP readiness signals maturity to enterprise buyers, global clients, and candidates who care about data rights. Indian startups selling to regulated industries (BFSI, healthcare, government contractors) increasingly lose deals when they can't answer basic data-protection questions in security questionnaires.

Getting this right in 2026 is cheaper than retrofitting after a failed enterprise procurement or a candidate complaint.

Next Steps

Document your screening workflow end-to-end, map it to DPDP principles, and align contracts with vendors this quarter. EchoHire is built with transparent scoring, security controls, and India deployment options in mind.

Review our Security page, see pricing for Indian teams, or book a demo to walk through your DPDP checklist with our team.

Weekly Digest

Enjoyed this article?

Get weekly insights on AI hiring, evaluation infrastructure, and talent strategy — straight to your inbox.

No spam. Unsubscribe anytime.