Every offer letter, medical record and exit file is personal data.
The scene
The staffing firm's database held two million CVs. Most came from job portals, some from referrals, some from a scrape nobody admits to. Candidates from 2014 still received calls about roles. None had been asked if they minded.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
Employee data is exempt.
Section 7(i) covers specified employment purposes, not everything done with staff data.
Map each HR process to the employment use, or to consent.
Candidates applied, so we can keep them.
An application is for a role, not for a lifetime database.
Set a retention period for rejected candidates, and keep it.
Background checks are the vendor's job.
The verifier processes on your behalf.
Contract, limit and audit what verifiers collect.
Monitoring employees
Productivity tools, keystroke logging and camera monitoring may go beyond what employment purposes justify. The test is necessity for the purpose, not availability of the software.
The full HR & Staffing briefing 3 deep dives
Deep dive 01 →
The candidate you rejected is still in your database.
A CV is not a subscription.
Deep dive 02 →
The software can see everything. The law asks what you need.
Watching is easy. Justifying it is the work.
Deep dive 03 →
The verifier knows more than the hiring manager.
You outsourced the check. You kept the liability.
Monday morning
01 Set a deletion date for rejected candidates.
02 List every monitoring tool in use and the purpose it serves.
03 Review what your background verifier collects.
Questions, answered plainly
Does DPDPA require consent for employee data? +
Section 7(i) allows processing without consent for employment purposes and to safeguard the employer from loss or liability, among other listed purposes. Processing outside those purposes may require consent.
How long can employers keep candidate data under DPDPA? +
Only as long as needed for the purpose, such as the recruitment for which it was provided, unless law requires longer. Employers should set and apply a retention period for unsuccessful candidates.
Sector · Gaming Your fastest-growing segment may legally be children. Read →
Sector · Government vendors The State's exemption is not your exemption. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).