Candidate Consent and Privacy During Recruitment
Recruitment requires personal information to identify, assess and communicate with candidates, but consent should not become a blanket form that claims permission for every future use. A trustworthy process links each data item and action to a clear purpose, access boundary and lifecycle.
Map data across the candidate journey
List information collected through career sites, resumes, referrals, assessments, interviews, background checks, agencies, video platforms, talent pools and onboarding. Record purpose, source, system, users, processors, location, retention and deletion route. Include inferred scores and recruiter notes, not only fields supplied by candidates.
Use the right legal analysis
Consent is one possible basis in privacy frameworks, but it is not a magic label. Obtain current legal advice for the organisation, locations and processing. The official DPDP Rules and commencement material (PDF) sets out phased commencement from November 2025; in August 2026, many substantive provisions and related rules are scheduled for later commencement. Prepare for them without presenting future duties as already operative.
Write a useful candidate notice
Explain the recruiting entity, information categories, purposes, key recipients or processors, assessment and automation, retention approach, candidate choices, contact and applicable rights. Place the notice where collection occurs and make it readable without forcing candidates through unrelated legal text.
Make choices specific
An application for a current role should not silently enrol someone in marketing or an indefinite talent pool. Ask separately where a genuinely optional future-opportunity relationship is offered. Record the choice and make withdrawal or preference changes usable.
Collect only what the stage needs
Early application usually does not require identity documents, bank information or extensive family details. Delay sensitive checks until justified and explain them. Remove fields retained only because an old form contained them.
Control recruiters, managers and agencies
Give access according to role and stage. Hiring managers should not download candidate packs to personal drives or reuse them for unrelated vacancies. Contracts with agencies and assessment vendors should define instructions, security, retention, incident reporting, subprocessors and end-of-service handling.
Manage referrals transparently
A referrer may provide limited contact information, but the candidate should receive notice and a genuine choice about proceeding. Do not treat an employees referral as the candidates consent to profiling or repeated contact.
Handle assessments and automated tools
Explain what the tool evaluates and how results affect selection at an appropriate level. Validate job relevance, accessibility, human oversight, error correction and vendor data use. Avoid collecting video, voice or behavioural signals merely because a product offers them.
Protect interview notes
Record job-related evidence against agreed criteria. Avoid speculative comments about health, family, age, religion or personality. Set access and retention, and ensure informal chat or email does not become an uncontrolled candidate record.
Set lifecycle events
Define active application, rejection, offer, withdrawal, dispute, future-opportunity invitation and deletion. Stop campaign messages when preferences change while preserving only records justified under the approved process. Make provider deletion and exports part of the workflow.
Prepare for candidate requests and incidents
Name owners who can find records across systems, correct facts, apply current rights and respond to a misdirected resume or exposed interview file. A privacy inbox without system ownership cannot provide an effective response.
Review cross-border and group access
Global recruiting systems may make profiles visible across entities and countries. Identify which entity is hiring, which teams need access, where vendors process data and what current transfer requirements apply. A group brand does not make every internal reuse expected or authorised.
Separate verification from exploration
Background screening should begin at the justified stage, follow defined scope and give candidates clear information and correction routes. Informal internet searches can collect inaccurate, irrelevant or protected information without consistent review. Set recruiter boundaries rather than leaving every manager to investigate independently.
Control test and demonstration data
Implementation teams should not use live candidate resumes in vendor demos or unsecured test systems. Use synthetic or properly approved test data, restrict migration extracts and reconcile deletion after testing. Procurement timelines do not remove candidate privacy risk.
Example
A finalist is not selected but is relevant to a future specialist role. The recruiter closes the application, gives the correct outcome notice and separately invites the candidate to a defined talent pool. Declining the invitation does not change the completed selection record.