The DPDP Act lets an employer process an employee’s data without consent for the purposes of employment. Read the words: they presuppose an employment relationship. The populations HR processes hardest sit outside it — candidates who have not been hired, contractors and gig workers the platform insists are not employees, alumni after exit — and every one of them needs a consent nobody collects. Background verification runs on that missing consent, at scale, on instruction from an employer who carries the whole liability.
FROM THE SEPTEMBER 2026 PROBLEM REGISTER · 4 HR PROBLEMS SWEPT · 4 SHOWN HERE, ONE PRESENTED FROM THE STATUTE ALONE · HOW THIS WAS BUILT
Confirmed means two independent sources, at least one the instrument itself or a practitioner record. One card below is presented from the statute and the structural fact alone, because the practitioner record behind it is reporting about a single named company — which these pages do not cite.
Section 7(i) permits processing without consent “for the purposes of employment.” Pre-employment screening, retention of rejected candidates, contractor and gig processing, post-exit alumni data and use of employee data for marketing all fall outside a relationship that does not exist, or has ended, or is contested. The Rules add nothing. Employers are guessing at the boundary, and a systematic wrong guess is what runs the whole recruitment funnel on absent consent.
SOURCES · DPDP Act s.7(i) (statute) · converging practitioner commentary on the employee-data exemption (context)
Confirmed for the textual gap · sweep of 2 Sep 2026Candidate screening sits outside s.7(i), so it needs s.6 consent: specific, itemised, naming the vendor, the retention and the rights. The reality is a generic offer-letter line; the vendor never faces the candidate; the previous employer discloses the subject’s data on a phone call with no consent instrument; and the hiring employer holds full s.8(1) liability. Consent given to keep a job offer is not obviously free. The industry’s own leaders are re-architecting post-exit verification around consent — the fix being productised is the evidence of the gap.
SOURCES · DPDP Act s.6, s.7(i), s.8(1) (statute) · A leading verification vendor on post-exit credentials under DPDP (practitioner — the industry describing its own remediation)
Confirmed · the supply chain of data has no consent instrumentationA major delivery platform’s published terms reserve location tracking for “safety, security, technical, marketing, and commercial purposes” — beyond delivery necessity. If workers are contractors, as the platforms maintain, s.7(i) does not apply and everything needs s.6 consent; bundled into terms that condition work, that consent fails the Act’s “free” standard and its withdrawal-without-detriment requirement. A platform cannot claim both classifications. Withdrawal of consent meaning loss of income is the textbook failure of “free.”
SOURCES · DPDP Act s.6, s.7(i) (statute) · The platform’s terms, quoted in a labour-law analysis (the instrument, via practitioner analysis)
Confirmed for the practice and the contradiction · enforcement untestedSection 6 purpose limitation and s.8(7) meet the talent-pool model, in which a resume uploaded years ago remains sellable inventory. Job platforms are not in the Third Schedule, so no automatic erasure clock applies — only the general s.8(7) standard, which the business model directly contradicts. What a recruiter does after export is unobservable. The practitioner record behind this card is investigative reporting about one named platform; we present the collision from the statute and the structural fact instead.
SOURCES · DPDP Act s.6, s.8(7); DPDP Rules 2025, Third Schedule (text) · practitioner reporting exists but names a single company, so it is not cited here
Presented from the statute · the collision is real; the named record is deliberately not linkedThe register started from AI-drafted hypotheses and kept only what the instruments supported. These are the workforce-specific claims that changed on the way.
The Third Schedule names e-commerce, gaming and social media above their thresholds. A job platform answers to the general s.8(7) standard — erase when the purpose is served — which is vaguer and, for a talent-pool model, harder to meet, not easier.
The s.7(i) ground is real and broad, and it presupposes the employment relationship. Belt-and-braces consent at application undermines the exemption and raises coercion questions; stretching “purposes of employment” to candidates is untested. Neither is a settled answer, and material that presents either as one is ahead of the law.
Algorithmic scoring of gig workers is automated decision-making, but the Act’s recourse is the fiduciary’s grievance process and then the Board — there is no GDPR-style right against solely automated decisions. Say what the Act gives, not what a European reader expects.
The penalty provisions commence in mid-May 2027 and the Board had no members as of 1 August 2026. No Significant Data Fiduciary class has been notified. The penalty schedule is stated plainly here, once.
RULES NOTIFIED MID-NOV 2025 · CONSENT-MANAGER REGISTRATION OPENS MID-NOV 2026 · DUTIES, RIGHTS AND PENALTIES MID-MAY 2027 · DATES STATED AS THE NOTIFICATIONS STATE THEM
Everything below is live today and maps to shipped code — the same rule as every page on this site. Capabilities we are still building are not listed here.
Background verification, retention after rejection and sharing with a named vendor become specified purposes a candidate decides on separately; nothing is pre-ticked. Notices are versioned so a change forces re-consent and the old version stays on record; withdrawal is as easy as the grant, and each decision produces a receipt. The consent the vendor never collected has a record the employer can produce.
Live: purpose-by-purpose consent · versioned notices · PDF receiptsThe platform holds the processors you instruct — verification, payroll, screening — with each data-processing agreement tracked and scored. When a correction to a person’s data completes, every processor recorded against them is notified and a delivery record kept per processor. The ex-employer phone call is not a processor relationship and no tool papers it; we say so rather than imply otherwise.
Live: processor & DPA register · correction propagation with per-processor delivery evidenceEvery access and erasure request carries a response deadline computed when it is filed and an escalation ladder when it slips. Erasure is executed — a parameter-bound delete against the table and column you nominate, every object under the person’s prefix in object storage, deletion through connected CRM and support tools’ own APIs — and the destruction is recorded, not asserted. A resume that should no longer be inventory is one the platform can prove it removed.
Live: DSR orchestration · SLA tracking · erasure connectorsNotices and consent flows are rendered in twenty-two Indian languages by a self-hosted translation model — a workforce that spans states is served one versioned notice. Every consent, erasure, refusal and notice publication is a linked record bound to the one before it, periodically stamped by an independent timestamp authority. Anyone can check it.
Live: 22 Indian languages · tamper-evident audit trail · verifiable receipts