The Digital Personal Data Protection (DPDP) Act, 2023 is India's first comprehensive data protection law, and it directly affects how every employer in the country runs background verification. If your HR or TA team collects a candidate's Aadhaar number, address proof, employment history, or education records to run a BGV check, you are now a "Data Fiduciary" under the law — and that comes with specific obligations, not just good practice.
Here is what actually changes for background verification, stripped of the legal jargon.
1. Consent has to be real, not implied
Before the DPDP Act, most companies treated a candidate submitting documents as implicit consent to verify them. That's no longer enough. The Act requires clear, specific, and informed consent before you collect and process personal data for verification purposes. In practice, this means:
- A consent notice that plainly states what will be verified (identity, address, education, employment, criminal record, etc.) and why.
- Consent captured as a distinct, recorded step — not buried in an offer letter's fine print.
- The candidate must be able to withdraw consent, and you need a process for what happens if they do mid-process.
If your BGV vendor is collecting documents on your behalf, the consent language needs to name both your company and the vendor — data fiduciary obligations don't disappear just because a third party runs the check.
2. You are accountable for data even after you hand it to a vendor
Outsourcing verification to a BGV partner doesn't transfer your legal responsibility. Under the DPDP Act, the employer (data fiduciary) remains accountable for how a "data processor" — your verification vendor — handles a candidate's personal data. Before signing or renewing a BGV contract, it's worth confirming in writing:
- How long the vendor retains documents and verification records after a check is complete.
- Whether data is stored within India or moved elsewhere, and under what safeguards.
- What happens to a candidate's data if they are not hired — is it deleted, and on what timeline?
3. Purpose limitation matters more than most HR teams realize
The Act requires that personal data collected for one purpose isn't quietly repurposed for another. A candidate's Aadhaar or PAN collected for identity verification during hiring shouldn't end up in a general employee database used for unrelated purposes without fresh consent. This is a common gap: BGV data collected during hiring often gets folded into HRMS records post-joining without anyone re-checking whether that's covered by the original consent.
4. Data minimization: stop collecting more than you need
A practical DPDP habit is to map each document you ask candidates for against the specific check it supports. If a role doesn't require a credit history check, there's no reason to be collecting financial documents "just in case." Over-collection isn't just a compliance risk — it's also extra liability sitting in your systems for no operational benefit.
5. Candidates have rights you need a process to honor
The Act gives individuals the right to access what data a company holds about them, request correction of inaccurate data, and request erasure once it's no longer needed for the purpose it was collected for. For BGV specifically, this means your HR team (or your vendor) should be able to answer, within a reasonable time, if a former candidate asks "what did you verify about me, and can you delete it now?"
6. Breach notification is now a legal obligation, not a PR decision
If a candidate's verification data — identity documents, criminal record check results, employment history — is exposed in a data breach, the DPDP Act requires notifying both the Data Protection Board and the affected individuals. This is one more reason vendor due diligence matters: ask your BGV partner directly what their breach response process looks like, before you need it.
What this means practically, this quarter
For most Indian employers, DPDP compliance for background verification comes down to five concrete actions:
- Add a clear, standalone consent step to your BGV process — don't rely on the offer letter to cover it.
- Get written confirmation from your BGV vendor on data retention, storage location, and deletion timelines.
- Audit what documents you're actually asking for against what each role's checks require.
- Set a policy for how long you keep verification records for candidates who weren't hired.
- Know who owns the response if a candidate exercises their access or erasure rights.
The short version
The DPDP Act doesn't make background verification harder to do — it makes sloppy background verification a legal liability. Employers who already run consent-first, well-documented BGV processes have little to change. Those still treating document collection as a formality have real exposure, and it's worth closing that gap before it becomes a Data Protection Board matter rather than an internal audit finding.