process 01Smarter ScreeningRead and score every application, not just the top of the pile. 02Better ShortlistingRank on twenty signals, with the evidence behind each one. 03Faster SchedulingNo calendars, no slots. One link, good for fourteen hours. 04Fairer InterviewsQuestions built from the role, answers scored against a written rubric.
Pricing
resources 01Our blogAI hiring tips, recruitment strategies, and growth insights. 02AcademyThe recruiter's guide to thriving in an AI-first hiring world.
use cases 01Resume VerificationEvery claim read in context, not lifted out as a keyword. 02AI Cheating PreventionBuilt for the copilot era: divided attention, novel questions. 03Volume ScreeningThe same rubric for applicant one and applicant a thousand. 04Pre-BGV FilterA consistency check before formal verification spend.
For candidates For investors Candidate login Employer login Get access →
explained

Is AI Screening Legal Under India's DPDP Act? What Changes in 2027

India's DPDP Act permits AI resume screening. It gives candidates no right to challenge an automated decision, and full enforcement starts only in May 2027.

Yes: India's DPDP Act does not ban AI resume screening. It regulates the candidate data behind the decision, not the decision itself, and unlike the EU's GDPR it gives candidates no right to demand a human review of an automated hiring call. Full enforcement of that data-handling duty only phases in through 2026 and 2027.

Most compliance guides answer this question as a checklist: get consent, give notice, keep data accurate. That's correct as far as it goes, and every AI-screening vendor operating in India has heard it. What almost none of them say is the part that actually matters for how you build the process: the Digital Personal Data Protection Act, 2023 is silent on the decision an algorithm makes. It has nothing resembling the EU's right to contest a fully automated outcome. That silence is not a loophole to exploit: it is the reason a hiring team's own choices about human review carry more legal weight in India than they would in Europe, precisely because the law is not going to make that choice for you.

What the DPDP Act Actually Requires Before You Screen With AI

The Act treats AI-based screening as ordinary “processing” of personal data, so the standard data-fiduciary duties apply in full, whether the sorting is done by a person or a model. Two of those duties decide most of what a hiring team has to do differently.

The first is the lawful basis. Section 7(i) permits processing “for the purposes of employment” without fresh consent for each use, but the Act does not spell out how far that exemption reaches into pre-employment recruitment, and secondary legal analysis of the Act, via Consently's DPDP Act guide, treats candidate screening as the more exposed case precisely because the applicant is not yet an employee. The practical result: most counsel advise treating consent as the safer default for external applicants, even where an argument for the employment exemption exists.

The second is vendor accountability. Whoever built the screening model is a Data Processor; the company doing the hiring stays the Data Fiduciary and carries the legal exposure if that vendor mishandles the data, regardless of what the vendor's own terms say. That allocation does not shift no matter how much of the screening is automated.

The Right India Doesn't Give Candidates That GDPR Does

This is the gap that most compliance content skips. Europe's GDPR gives a data subject a right, under Article 22, to not be subject to a decision “based solely on automated processing” that produces legal or similarly significant effects, and to demand meaningful human intervention. A side-by-side legal comparison of the two regimes lists the DPDP Act's equivalent right as simply “Absent,” concluding that Indian data principals “do not get portability, objection, restriction or an Art. 22 automated-decision right” (source).

In plain terms: nothing in Indian law requires a hiring team to have a person look at a rejection an algorithm generated. A company screening a thousand applicants a week with a keyword-matching tool and zero human review of the discards is handling the underlying data lawfully, provided the fiduciary duties above are met, and is still not breaking any Indian data-protection rule by letting the model make every call unsupervised. Whether that is acceptable is a question of risk, fairness and who you would rather have to explain a bad rejection to, not a question the DPDP Act currently answers.

The Compliance Timeline: What's Live Now, and What Starts in 2026 and 2027

The DPDP Rules, 2025 were notified on November 13, 2025, and they set an eighteen-month runway rather than a single start date, confirmed in the government's own notification (PIB, November 2025).

Live already: the four-member Data Protection Board of India is operating, taking complaints through an online portal, with a six-month deadline, extendable by three months, to close an inquiry.

From November 13, 2026: any company acting as a registered Consent Manager, and the operational, technical and financial conditions attached to that role, become enforceable, with the Board empowered to oversee and investigate them.

From May 13, 2027: the obligations most relevant to a hiring team all land at once, per legal analysis of the phased rollout (Consently, 2026): verifiable consent with an eight-element notice covering identity, data types, purpose, withdrawal method, rights, grievance mechanism, retention period and third-party sharing, candidate rights to access, correction and erasure, mandatory breach notification, and data-retention limits requiring deletion once the hiring purpose is served.

Ignore any of it and the exposure is real money. The Act's own penalty schedule under Section 33 tops out at ₹250 crore, roughly $30 million, per instance, specifically for failing to take reasonable security safeguards against a data breach under Section 8(5). Breach-notification failures and children's-data violations sit at ₹200 crore, and a Significant Data Fiduciary that skips its DPO, impact-assessment or audit obligations faces ₹150 crore (penalty schedule summary). These are per-instance figures the Board sets after weighing remediation and cooperation, not a fixed annual cap.

Where Hiring Teams Get This Wrong

The most common mistake is treating a resume a candidate already posted on Naukri or LinkedIn as data the company is free to run through a screening model without its own notice, on the theory that the candidate already made it public. The DPDP Act does not carve out an exception for previously public data; the fiduciary obligations attach the moment the company processes it for its own purpose, not the moment the candidate first published it.

The second is assuming a vendor contract transfers the legal risk. It does not. The company doing the hiring is the fiduciary either way, and a processor's data breach is the fiduciary's problem to answer for to the Board.

The third is treating consent as a one-time checkbox at application stage that covers every later use, including retraining a model or sharing scores with a client in a staffing arrangement. Purpose limitation means each new use needs its own basis, not a blanket signature collected months earlier.

Questions People Ask

Does a DPDP-compliant process also need a bias audit, the way NYC's Local Law 144 requires?

No. As covered in what NYC's Local Law 144 actually checks, that is a US requirement to test whether a scoring tool rates demographic groups at different rates. The DPDP Act has nothing equivalent; it governs data handling, not the fairness of the score itself, so a company can be fully DPDP-compliant and still be running a screening tool no one has ever tested for disparate impact.

Does the employment exemption in Section 7(i) cover a background-verification check as well as the resume screen?

The Act does not distinguish between the two processing steps by name, so the safer reading is that pre-employment verification carries the same exposure as pre-employment screening: treat both as needing their own notice and basis rather than assuming one covers the other.

What happens to a rejected candidate's data after the role is filled?

Once the hiring purpose is served, the retention-limit obligation that phases in from May 2027 requires deleting it rather than holding it indefinitely on the chance a similar role opens later; holding it for that reason needs its own stated purpose and notice, not a default.

Is this any different from how the EU's own AI Act treats hiring?

Yes, and the difference cuts the opposite way from what people expect. The EU AI Act, which moved its own deadline by 16 months this year, classifies hiring tools as high-risk and regulates the tool itself; the DPDP Act regulates only the data flowing through it. A tool can clear India's bar entirely and still fail the EU's.

Where AgentR Fits, and Where It Doesn't

AgentR reads applications in full and checks candidates' claims against the public record, then runs structured interviews scored against a rubric written before anyone applied. Every shortlist stays a recommendation for a human to weigh, not an auto-reject; that design choice predates this piece and is not a response to any DPDP requirement, because nothing in Indian law currently requires it.

What it does not do: AgentR is not a consent-management platform, does not issue the DPDP-compliant notices a hiring team still has to draft itself, and has not been through a Data Protection Board audit, because none has happened yet for anyone in this category. A company that adopts structured, human-reviewed screening still owns its own DPDP compliance program; the tool does not discharge that duty by itself, whatever it screens with.