GVS - Genuine Verification Services
Talk to sales

The DPDP Act and background verification

India's Digital Personal Data Protection Act, 2023 changed what an employer has to be able to show about a check it commissioned. Written in the language of the work rather than the statute.

9 min readReviewed August 2026Regulation & news
Trusted by 500+ companies
Canara BankChannelplayTata AIG InsuranceMacgenceIndiaMARTOlive Green ConsultingPunjab & Sind BankZee MediaJobkartKazamAvalon Information SystemsMeruBTCQuytechGreat Eastern Energy CorporationGiginBharat BhushanPilot IndustriesShipex IndiaKW GroupWise FinServPTC NetworkOrcapodadaanSouthern TravelsElectricaBaby & Mom RetailSyscomLarkRoots DevelopersGMSCircleRightRudra ShieldEssential EnergyAviaxpert
In short
  • The obligations sit primarily with the employer, not with the verification provider. You cannot outsource the compliance with the work.
  • Consent has to be specific to the checks being run, and a blanket clause buried in an offer letter is not it.
  • Collecting documents you are not going to use is not neutral. It is an obligation you took on for nothing.
  • Retention needs a written period per data type, and something that actually deletes on it.

This piece explains what the Act asks for in operational terms. It is not legal advice, and the implementation detail continues to develop. Take a view with your own counsel before setting policy on it.

Why it applies to you

A background check is the collection and processing of a person's personal data: their identity documents, their employment history, their education, their address, sometimes their financial and legal records. That is squarely within the scope of the Digital Personal Data Protection Act, 2023.

The part employers most often get wrong is who carries the obligation. The employer decides that checks will be run, on whom, and which ones. That makes the employer the one determining the purpose and means of the processing, and the primary duties follow. The verification provider processes data on the employer's instructions.

Practically: buying verification from a certified provider does not discharge your obligations. It gives you a processor who should be handling data properly, which is necessary and not sufficient. The notice, the consent, the retention decision and the response to a candidate's request are yours.

Notice: telling people before you collect

Before personal data is collected, the person has to be given a notice describing what is being collected and the purpose it will be used for. For verification that means the candidate should know, before they hand anything over:

  • which categories of personal data are being collected;
  • which checks will be run, and why;
  • that a third-party provider will process the data on the employer's behalf;
  • how to exercise their rights, and where to complain if they need to.

This is a low bar and most employers clear it with one clear page. What does not clear it is a sentence in an offer letter saying the offer is subject to satisfactory background verification. That tells a candidate an outcome matters; it does not tell them what is being collected or why.

Consent under the Act has to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the purpose stated in the notice.

The word doing the work is specific. A consent that authorises "background verification" in general does not obviously authorise a credit check, and it certainly does not authorise a check the employer decided to add three weeks later. A consent record that names the checks it covers is both better practice and a much easier thing to produce if anybody ever asks.

Two situations worth handling explicitly in the consent record, because both go wrong regularly:

  • The current employer. Whether they may be contacted, and at what point. Getting this wrong can cost a candidate the job they still have, and it is the single most damaging avoidable error in this process. See employment verification.
  • Additional checks added later. If the package changes, the consent has to catch up. It does not work the other way round.

Consent can also be withdrawn, and withdrawal should be as easy as giving it. In practice, checks stop, the employer is told, and the employer decides what that means for the offer. What is not acceptable is continuing to process after withdrawal.

Collect less, which is also cheaper

Personal data should be collected for the stated purpose and limited to what is necessary for it. This is the requirement that most changes day-to-day habits, because the common practice in Indian hiring is to collect everything at onboarding and sort it out later.

Under the Act, a document you collected and are not using is not neutral. It is personal data you now hold, have to secure, have to be able to describe if the candidate asks, and have to delete on a schedule. You took on an obligation and got nothing for it.

The practical version is to work backwards from the package. If the role's checks are identity, employment and education, then you need the documents those checks need, and not a full set of everything a person owns. This is another argument for scoping the package by role before you build the submission form, rather than after.

Retention: a number, written down

Data should be kept only as long as the purpose requires, or as long as a separate legal obligation requires it to be kept. The Act does not hand you a figure, which means somebody in your organisation has to decide one and be able to justify it.

A workable approach is to set a period per data type rather than one period for everything, because the justifications genuinely differ.

DataWhy it might be keptWhat to decide
The verification report and findingsTo evidence that a hiring decision was properly based, and for client or regulatory auditA defined period tied to that purpose, not "forever"
The consent recordTo show consent existed and what it coveredUsually at least as long as the report it authorised
Underlying identity documentsFrequently no ongoing purpose once the check is completeThe shortest period on the list, and often the one nobody has set
Data on candidates who were not hiredRarely any continuing purpose at allA short, specific period, and an actual deletion process

That last row is where most organisations are exposed. Rejected candidates' verification data sits in inboxes and shared drives indefinitely because nobody owns deleting it. It is the highest-volume personal data most employers hold with the weakest justification for holding it.

What a candidate can ask for

The Act gives people rights over their own data, and a verification programme has to be able to answer when one is exercised.

  • Access. A summary of the personal data being processed and what is being done with it.
  • Correction and completion. Inaccurate or incomplete data corrected. This maps directly onto disputing a finding, and it is why a route to query a finding is not optional. See how to read a discrepancy.
  • Erasure, where the data is no longer needed for its purpose.
  • Nomination, allowing someone else to exercise the rights.
  • Grievance redressal, with a route that actually responds.

Two practical consequences. You need to know where candidate verification data lives, including the copies in email, or you cannot answer an access request. And you need a named person who owns responding, because a grievance route with nobody behind it is worse than none.

A short operational checklist

  1. A notice that says what is collected and why, given before collection.
  2. A consent record that names the specific checks, including whether the current employer may be contacted.
  3. A submission form that asks only for what the package needs.
  4. A written retention period per data type, and a process that actually deletes.
  5. A named owner for candidate requests and grievances.
  6. A provider agreement covering security, retention and what happens at the end of the relationship.
  7. A defined route for a candidate to query a finding, and a record of the correction alongside the original.

An employer with those seven in place is in reasonable shape. An employer with a background verification clause in the offer letter and nothing else is not, and the gap is mostly paperwork rather than expense.

How GVS handles it

Checks run on written candidate consent that names the checks it covers, nothing starts without it, and if consent is withdrawn the work stops and the employer is told. Data is held under access control for a defined retention period. A candidate can ask what is held about them and ask for a correction, and a corrected finding goes on the case with the original still visible so the record shows what changed.

The full detail, including the DPDP grievance route and the acknowledgement and response timelines, is in the Trust Centre, and the candidate-facing version is on the candidates page.

Questions we get asked

Does the DPDP Act apply to background verification?
Yes. A background check processes a candidate's personal data, so the requirements around notice, consent, purpose limitation, retention, security and data principal rights apply. They apply to the employer commissioning the check as well as to the provider running it.
Who is responsible, the employer or the provider?
The employer determines why and how the candidate's data is processed, so the primary obligations sit there. The provider processes on the employer's instructions. This matters practically: an employer cannot hand the compliance question to a vendor along with the work.
What does valid consent look like?
Free, specific, informed and unambiguous, given by a clear affirmative action and limited to the stated purpose. In practice: a consent record naming the specific checks it authorises, given alongside a notice explaining what is collected and why, and capable of being withdrawn.
Can a candidate withdraw consent?
Yes, and withdrawal should be as easy as giving it was. The checks stop, the employer is told they have stopped, and the employer decides what that means for the offer. What is not acceptable is continuing to check after withdrawal.
How long can a report be kept?
Only as long as the purpose requires, plus any period a separate legal obligation requires. The Act does not set a single number, so the employer has to decide a defensible period per data type, write it down, and actually delete on it. Indefinite retention because storage is cheap is the position the Act is aimed at.
What rights does a candidate have?
To be told what is collected and why, to access a summary of what is being processed, to have inaccurate data corrected or completed, to have data erased where no longer needed, to nominate someone to exercise these rights, and to a grievance route that answers.

Read next

Ask us how your consent flow looks

Send us what your candidates sign today and we will say where the gaps are.

Talk to sales