Playbooks14 min read

DPDP Act Compliance for AI Recruiting Tools: What Indian Companies Need

India's DPDP Act reaches every AI recruiting tool touching an Indian candidate's data, and full enforcement arrives May 2027 with penalties up to ₹250 crore. Here's what the law actually requires for sourcing, screening, and outreach — and the questions Indian companies should be asking every AI recruiting vendor before enforcement begins.

By Huntlo Team

India's Digital Personal Data Protection Act reaches every AI recruiting tool that touches an Indian candidate's data, and the compliance runway is shorter than most HR and talent acquisition teams realize. Final Rules were notified on November 13, 2025, and the law now follows a defined three-phase rollout: the Data Protection Board became operational immediately, the Consent Manager framework takes effect in November 2026, and full substantive enforcement — with real penalty authority — begins May 13, 2027, according to RAIL's detailed implementation guide. That guide also reports a genuinely alarming adoption gap: 83% of organizations have not yet begun comprehensive implementation, and only 16% of Indian consumers even understand the law exists — a combination that suggests most companies using AI recruiting tools today have not yet examined whether those tools comply.

This guide covers what the DPDP Act actually requires for AI recruiting specifically — sourcing, screening, and outreach — where the law's genuine ambiguities sit, and the concrete questions an Indian company should be asking any AI recruiting vendor before enforcement begins in earnest.

What the DPDP Act Actually Covers, and Why AI Recruiting Tools Are Squarely in Scope

The DPDP Act governs the processing of digital personal data within India, and its reach extends to data collected directly in digital form or digitized later from non-digital records, according to Lexology's overview of the DPDP Rules. Critically, the law is extraterritorial: it applies to processing outside India when that processing relates to offering goods or services to individuals within India, which means a US-headquartered AI recruiting vendor sourcing or screening Indian candidates falls under the Act regardless of where its servers sit or where the company is legally incorporated.

AI recruiting tools sit at the center of this scope for an obvious reason — they process exactly the kind of personal data the Act is built around: names, contact details, employment history, education, and increasingly behavioral and inferred data drawn from public profiles or interview recordings. DPDPA.com's guide to AI and machine learning under the Act states the principle directly: the DPDP Act applies to all AI and machine learning systems that process personal data, regardless of whether they're used internally or deployed as a consumer-facing product, and that includes training data, the algorithms themselves, and any automated decision-making layered on top.

Who's Actually Responsible: Data Fiduciary vs. Data Processor

Understanding the DPDP Act's core roles matters immediately for any company evaluating an AI recruiting vendor, because it determines who's legally on the hook when something goes wrong. A Data Fiduciary is the entity that determines the purpose and means of processing personal data — in a recruiting context, this is almost always the hiring company itself. A Data Processor is an entity that processes data on behalf of a Data Fiduciary, under contract, and this is where most AI recruiting vendors sit.

The distinction matters because responsibility doesn't transfer just because processing gets outsourced. As Atlas's 2026 DPDP compliance guide puts it plainly, Data Fiduciaries remain ultimately responsible for the actions of any Data Processor they engage, even though processors themselves carry obligations to process data only as instructed, implement security measures, assist with rights fulfillment, and delete data when it's no longer needed. In practice, this means an Indian company adopting an AI sourcing or screening tool cannot treat vendor compliance as the vendor's problem alone — a breach or violation originating in the vendor's systems still exposes the hiring company that chose to use it.

The Employment "Legitimate Use" Exception — And Its Real Limits for Recruiting Specifically

One of the most important, and most misunderstood, provisions for HR teams is the "legitimate use" exemption under Section 7 of the DPDP Act. This provision allows employers to process personal data for employment purposes without obtaining explicit consent for every instance, covering routine activities like payroll, onboarding, performance management, and statutory compliance, according to Lexology's detailed analysis of the employee consent question.

For recruiting specifically, though, the exemption's application is genuinely murkier than most HR teams assume. Chambers and Partners' analysis of the legitimate use exemption flags a real gap in the statute: the DPDP Act is silent on whether pre-employment activities — shortlisting, interviews, background checks — fall cleanly under "purposes of employment," since a candidate isn't yet an employee at the point most sourcing and screening happens. That analysis notes this leaves genuine ambiguity about whether explicit consent is required for processing candidate data during recruitment, pending clearer guidance through formal rules or regulatory FAQs.

A separate, more optimistic reading comes from Lexology's employee-consent analysis, which points to a different provision — Section 7(a) — covering situations where a data principal has voluntarily provided personal data for a specified purpose and hasn't objected to its use for that purpose. That provision, the analysis argues, may extend naturally to job applicants who voluntarily submit resumes and related information specifically to be considered for employment. The honest state of play, though, is that these two readings aren't fully reconciled in the statute itself, and companies relying entirely on an implied legitimate-use argument for recruitment-stage processing are operating in genuinely unsettled legal territory rather than a clearly settled exemption.

Sourcing From Public Platforms: The Publicly Available Data Exemption Is Narrower Than It Looks

This is the provision most directly relevant to AI sourcing tools specifically, and it's worth understanding in more depth than a surface reading suggests. Section 3(c)(ii) of the DPDP Act excludes personal data that has been made publicly available by the data principal themselves, or by another party under a legal obligation to do so, from the Act's scope entirely. On its face, this looks like it should cover AI sourcing tools that pull candidate profiles from LinkedIn, GitHub, and other public professional platforms.

The reality is considerably more constrained. Law.asia's analysis of the publicly available data exemption is direct about this: businesses will not be able to indiscriminately scrape data from publicly available sources, because relying on the exemption first requires verifying the actual source of the personal data — specifically, confirming the data was made public by the individual themselves or under a genuine legal obligation, not simply that it happens to be technically accessible online. The same analysis raises a scenario directly relevant to recruiting platforms: if a business obtains personal data from another organization that collected it directly — rather than from a source the individual made public themselves — it's genuinely unclear under Indian law whether that data still qualifies as "publicly available" for exemption purposes.

A more recent legal analysis pushes this further in the specific context of AI systems. The Law School Policy Review's 2026 analysis of publicly available data under AI-driven processing argues that public availability alone cannot function as a blanket permission for unrestricted AI-driven data use, particularly because AI systems routinely combine data across sources and reuse it in ways far removed from the context in which it was originally shared — a dynamic the exemption's drafters likely didn't contemplate when writing a provision aimed more at simple, single-source scenarios like a public social media post. The practical implication for AI recruiting tools is that leaning entirely on the publicly-available-data exemption as a blanket justification for cross-platform sourcing is a riskier legal position than it might appear, and companies should treat it as one factor in a broader compliance approach rather than a complete shield.

Automated Decision-Making Transparency: What Section 8 Requires for AI Screening and Ranking Tools

For any AI recruiting tool that scores, ranks, or filters candidates — not just sources them — Section 8's transparency requirements around automated decision-making become directly relevant. According to DPDPA.com's guidance, organizations using automated systems to make decisions about individuals, including hiring decisions, must maintain technical documentation of how the algorithm actually works, provide data subjects with meaningful information about the decision logic, explain the factors material to a given decision in language the person can actually understand, and implement genuine human oversight mechanisms for significant automated decisions — not a token review step, but real oversight capable of overriding the system's output.

This has real teeth in practice, illustrated by a hypothetical compliance failure DPDPA.com's guide walks through directly: an AI screening system trained on historical hiring data that systematically downgraded applications from women for similar positions, without candidates ever being informed an automated system made the decision, without documentation of how the algorithm weighted different factors, and without any mechanism for a rejected candidate to request human review. The compliance path the guide recommends — bias auditing of training data, explicit opt-in consent for algorithmic screening specifically, accessible technical documentation of the algorithm's logic, and mandatory human review for shortlisted candidates — is a useful template for any company deploying AI screening tools to measure its own process against.

Breach Notification: Stricter Than Many Teams Assume

The DPDP Act's breach notification requirement is one of the sharper departures from GDPR that HR and legal teams frequently underestimate. Unlike GDPR, which allows some proportionality in notification based on the severity of a breach, RAIL's implementation guide is explicit that the DPDP Act requires notification for all breaches regardless of severity, with detection, assessment, and reporting expected within 72 hours. For a recruiting context specifically, this means even a relatively contained incident — a misconfigured sourcing tool exposing a batch of candidate contact details, for instance — triggers the same notification clock as a large-scale breach, with no lower threshold exempting smaller incidents from the requirement.

Cross-Border Data Transfers: Why Vendor Hosting Location Matters More Than It Used To

A large share of AI recruiting tools are foreign-built SaaS platforms, which makes cross-border data transfer rules directly relevant to vendor selection. The DPDP Act takes a notably different approach than GDPR here — rather than GDPR's adequacy-based framework requiring a country to meet defined standards, the DPDP Act uses what RingSafe's compliance guide describes as a "blacklist" model, which is more permissive by default but allows the government to restrict transfers to specific notified territories going forward. RingSafe's practical AI compliance guide for India recommends a conservative posture regardless: preferring Indian-region hosting — such as AWS Mumbai or Azure South India — or self-hosting for genuinely sensitive data, specifically because cross-border transfer rules are still being finalized under the DPDP Rules and are likely to tighten over time rather than loosen.

For companies evaluating AI recruiting vendors, this translates into a concrete due-diligence question: where is candidate data actually stored and processed, and does the vendor have a clear answer rather than a vague assurance about "industry-standard security"?

Significant Data Fiduciaries: A Higher Bar for Large-Scale Recruiting Operations

The DPDP Act uses a tiered risk model rather than applying identical obligations to every organization, designating certain entities as Significant Data Fiduciaries based on factors like the volume and sensitivity of personal data processed. This tier carries additional obligations — typically including mandatory Data Protection Officer appointments, more rigorous audit requirements, and periodic Data Protection Impact Assessments. Large enterprises and GCCs running high-volume AI-driven recruiting across thousands of candidates a year should assume they're more likely to be classified in this tier than a small business running occasional hiring, and should plan governance structures accordingly rather than waiting for a formal notification to start building the required documentation.

A Practical Vendor Due-Diligence Checklist for AI Recruiting Tools

Given everything above, a few concrete questions separate a defensible AI recruiting deployment from real legal exposure once enforcement begins in May 2027:

  • Where is candidate data actually hosted, and does the vendor support India-region hosting or clear commitments on cross-border transfer restrictions?

  • Can the vendor produce a signed Data Processor agreement that flows down DPDP obligations — security requirements, breach notification timelines, and audit rights — rather than a generic global data-processing addendum written for GDPR alone?

  • For any tool that sources candidates from public platforms, can the vendor explain its data provenance and verification approach, rather than relying on a blanket "it's public" justification that the current legal analysis suggests won't hold up cleanly?

  • For any tool that scores, ranks, or filters candidates automatically, does it produce documentation explaining the factors behind a given decision, and does it support a genuine human review step rather than a rubber-stamp formality?

  • Does the vendor commit to the 72-hour breach detection and reporting timeline, and can it demonstrate the technical capability to actually meet that window — not just a policy stating intent to comply?

  • Is there a clear data retention and deletion policy for candidate data that wasn't hired, addressing the DPDP Act's purpose-limitation principle rather than retaining sourced candidate data indefinitely by default?

Where a Tool Like Huntlo Fits Into This Compliance Picture

It's worth being direct about what a vendor relationship can and can't resolve here: under the DPDP Act's Data Fiduciary framework, the hiring company — not the AI recruiting vendor — remains ultimately responsible for how candidate data gets processed, regardless of which tool is doing the sourcing or outreach. No AI recruiting platform, including Huntlo, removes that underlying responsibility, and any vendor claiming otherwise should be treated skeptically.

What a company evaluating a tool like Huntlo should actually look for is whether the platform is built with the specific due-diligence questions above in mind — sourcing that operates from verifiable public professional data rather than opaque scraping, outreach practices that respect consent and suppression preferences rather than treating every sourced contact as fair game indefinitely, and a vendor relationship structured around a real data processing agreement rather than a boilerplate terms-of-service page. For Indian companies and GCCs specifically, that also means confirming data handling practices align with the India-specific considerations covered above — hosting location, breach notification commitments, and retention policy — as a standard part of vendor selection, not an afterthought handled after a tool is already in production use.

Frequently Asked Questions

Does sourcing candidates from LinkedIn or GitHub automatically count as compliant "publicly available data" under DPDP? Not automatically. Current legal analysis suggests the exemption requires verifying that the data was genuinely made public by the individual themselves, and several unresolved questions remain about data obtained indirectly or reused across contexts in AI-driven systems. Treat it as one relevant factor in a compliance approach, not a complete shield.

Do we need candidate consent for AI-driven resume screening or ranking? The safest approach, given the current ambiguity around pre-employment processing under the legitimate-use exemption, is to build in explicit consent for algorithmic screening specifically, along with accessible documentation of how the system reaches its decisions and a genuine human review option — rather than relying solely on an implied employment-purposes exemption that hasn't been fully clarified.

What's the actual deadline for full DPDP compliance? Full substantive enforcement, with real penalty authority, begins May 13, 2027. However, earlier milestones matter too — the Consent Manager framework becomes operational in November 2026, and given that 83% of organizations haven't started comprehensive implementation as of early 2026, treating 2026 as a genuine "build year" rather than waiting until closer to the 2027 deadline is the more defensible posture.

How much can a DPDP violation actually cost? Penalties can reach ₹250 crore — roughly $30 million USD — for serious violations, with a separate, specific penalty tier up to ₹150 crore for violations involving children's data protections. There are no criminal penalties under the current Act, unlike earlier draft versions, but the financial exposure alone is substantial enough to warrant real compliance investment.

The Bottom Line

The DPDP Act's reach into AI recruiting is broad, its specific application to pre-employment and recruitment-stage processing is genuinely unsettled in places, and the compliance runway before full enforcement in May 2027 is shorter than the 83%-not-yet-started statistic suggests it feels. Companies using AI recruiting tools — for sourcing, screening, or outreach — remain the Data Fiduciary responsible for how that processing happens, which makes vendor due diligence a direct compliance activity, not a procurement afterthought.

If you're evaluating AI sourcing and outreach tools as part of building a defensible recruiting stack ahead of full DPDP enforcement, Huntlo is worth including in that evaluation directly — with the understanding that the compliance questions above are worth asking of any vendor being considered, not assumed answered by default.

This guide is intended as general information, not legal advice — companies should consult qualified counsel to assess their specific DPDP compliance posture.

Related Reading on the Huntlo Blog


#dpdp act compliance#dpdp act recruiting#india data protection law#ai recruiting compliance india#digital personal data protection act#candidate data privacy india#hr data compliance india#dpdp act 2023#recruiting technology compliance

Related articles

Playbooks13 min read

The Future of Hiring Belongs to Recruiters Who Never Let Candidates Feel Forgotten

Aarav spent eleven years building his engineering team at a Series D fintech company. His philosophy was simple: no candidate should ever wonder whether the company remembered them. When the company tripled its headcount target, his follow-ups arrived too late and his acceptance rate dropped by half. Then he adopted an AI recruiting platform that maintained continuous candidate awareness. His rate recovered and exceeded its previous peak.

Read article
Playbooks13 min read

Why Recruitment Teams Need AI to Build Better Candidate Relationships

AI-powered recruitment helps recruiters build stronger candidate relationships at scale by reducing administrative workload. Learn how automated scheduling, real-time candidate intelligence, and personalized engagement recommendations improve recruiter productivity, increase offer acceptance rates, reduce candidate withdrawals, and create a better candidate experience throughout the hiring process.

Read article
Playbooks13 min read

Candidate Engagement Is the New Recruitment Marketing

Attracting more candidates does not guarantee better hiring outcomes. Learn how candidate engagement, personalized recruiter communication, AI-powered recruitment tools, and relationship-driven hiring help convert more prospects into successful hires. Discover how improving engagement can increase offer acceptance, reduce time-to-fill, strengthen the candidate experience, and help recruitment teams hire more effectively with fewer candidates.

Read article