Do job applicants need a privacy notice under the DPDP Act? Yes. From the moment a person applies for a role, you collect their personal data — CV, contact details, work history, and often background-check and reference information — which makes you a Data Fiduciary and triggers Section 5 of the DPDP Act 2023: you must give applicants a clear notice of what you collect, why, and how they can exercise their rights. Recruitment is a frequently-missed gap because it happens before someone becomes an employee, sits in an applicant tracking system (ATS) or a hiring inbox, and holds data on many people you never hire but whose CVs you keep. A candidate privacy notice for DPDP India covers exactly this. This generator builds one tailored to your hiring process, including background checks and rejected-applicant retention.
Generate a DPDP Section 5-compliant privacy notice for job applicants — what you collect, background checks, who sees it, and how long you keep the CVs of candidates you do not hire.
The introduction makes clear that this notice applies to job applicants and candidates — a distinct audience from current employees, and one whose data you begin collecting the instant they apply, well before any employment relationship exists. It names your organisation as the Data Fiduciary for applicant data, states that the notice is provided under Section 5 of the DPDP Act 2023, and explains its scope in one line: it covers everyone who applies for or is considered for a role, whether or not they are ultimately hired. That last point matters, because the majority of people in your recruitment systems are candidates you did not hire, and they are covered too.
The notice should be surfaced at the point of application — on the careers page form, in the ATS application flow, or referenced in the acknowledgement email — so the applicant sees it before or as they submit their data, not buried afterwards. A clear opening ("This notice explains how [Organisation] handles your personal information when you apply for a role with us") sets the right expectation and demonstrates a candidate-respecting hiring process, which is itself an employer-brand advantage.
Section 5 requires the notice to itemise the categories of data collected. For recruitment this typically includes: application data (CV/resume, contact details, work and education history); reference data (referee names and contact details, and the references they provide); assessment data (test scores, interview notes and panel ratings); verification data (ID, education and experience proofs); background-check data where you run them; and, only where genuinely necessary and lawful, any health or disability declarations relevant to reasonable accommodation. The notice must be honest about all of it — including the data collected about a candidate from third parties such as referees and background-check vendors, not only what the candidate hands over directly.
The generator itemises exactly the categories you select, so the notice matches your real hiring data flow. This is where recruitment notices most often fall short — they describe the CV a candidate uploads but stay silent on the reference, background-check and assessment data a company also holds about them. A candidate reading the notice should recognise the full picture of what your process captures.
Candidate-data categories selected for your notice:
DPDP compliance programmes tend to cover customers first and current employees second, and recruitment falls through the gap between them. Yet the hiring process collects a great deal of personal data — CVs, contact details, references, assessment results, ID proofs and background-check reports — and it collects that data about a large number of people, most of whom are never hired but whose CVs sit in the ATS or a hiring inbox for months. In respect of all of them you are a Data Fiduciary, and Section 5 of the DPDP Act 2023 requires a clear notice at the point of application. A candidate privacy notice for DPDP India is the artefact that closes this gap.
The rejected-applicant question is where recruitment risk concentrates. Many companies keep every CV they ever received, indefinitely, with no notice given and no consent basis for the retention — a textbook minimisation and notice failure. A proper candidate notice states plainly how long applicant data is kept and separates the consent basis for holding a CV in a future-roles talent pool from the immediate hiring purpose, turning a quiet liability into a documented, defensible practice.
A recruitment notice is only useful if it is honest about the parts of hiring candidates cannot see: the background check run by a third-party vendor, the reference collected from a former manager, the assessment scored by an external platform, and the ATS provider that stores everything. Section 5 expects the notice to disclose data collected from third parties and shared with them, not just the CV the candidate uploaded. A tailored candidate notice names these flows explicitly, which is exactly what a privacy-conscious applicant — and a regulator — looks for.
Getting this right is also an employer-brand asset: candidates increasingly judge companies by how respectfully they handle applicant data, and a clear, specific notice signals a mature organisation. Niti Bharat maps the full employee-lifecycle data flow — candidate, employee and alumnus — and drafts the matching Section 5 notices as part of its fixed-price DPDP compliance engagements (Rs 75,000–Rs 3.2 lakh); this generator produces the candidate-facing notice on its own for teams closing the recruitment gap first.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.