AMLEGALS — Strategic Lawyering

Candidate and Applicant Data Under DPDPA: Recruitment Is Not Employment

Candidate and Applicant Data Under DPDPA: Recruitment Is Not Employment

A CV is not a subscription.

The scene

A candidate applied in 2017 and was rejected. Since then she has been called for eleven roles, her CV has been shared with four clients, and her salary expectation from nine years ago is still in the system as a filter.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

Candidates consented by applying.

They applied for a role; storing and sharing for others is a new purpose.

Ask separately to keep a CV for future roles.

Employment legitimate use covers recruitment.

Section 7(i) covers employment purposes; its reach before employment is uncertain.

Rely on consent for talent pools.

A talent pool with consent

Offer the candidate a clear choice: keep my CV for twelve months for similar roles, or delete it when this role closes. Honour the choice automatically.

Monday morning

01 Count CVs older than two years.

02 Set a default retention for rejected candidates.

03 Add the talent-pool opt-in to applications.

Questions, answered plainly

Can companies keep CVs of rejected candidates under DPDPA? +

Only as long as needed for the recruitment purpose, unless the candidate consents to longer retention, for example for future roles. Data should be erased once the purpose is served.

Does the employment exemption cover job applicants? +

Section 7(i) permits processing for employment purposes. Whether it extends to candidates who never become employees is not settled; relying on consent for talent pools is safer.

Sector · HR & Staffing The candidate you never hired is still your Data Principal. Read →

HR & Staffing · Deep dive The software can see everything. The law asks what you need. Read →

HR & Staffing · Deep dive The verifier knows more than the hiring manager. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).