{"id":1668,"date":"2026-08-12T10:09:06","date_gmt":"2026-08-12T10:09:06","guid":{"rendered":"https:\/\/hirium.com\/blog\/?p=1668"},"modified":"2026-08-12T10:09:06","modified_gmt":"2026-08-12T10:09:06","slug":"candidate-database-compliance","status":"publish","type":"post","link":"https:\/\/hirium.com\/blog\/candidate-database-compliance\/","title":{"rendered":"Candidate Database Compliance: GDPR and DPDP Act Checklist"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Most recruitment teams are sitting on a legal liability they haven&#8217;t priced in. European regulators processed an average of <\/span><a href=\"https:\/\/www.kiteworks.com\/gdpr-compliance\/gdpr-fines-data-privacy-enforcement-2026\/\" target=\"_blank\" rel=\"noopener\"><b>443 personal data<\/b><\/a><span style=\"font-weight: 400;\"> breach notifications every single day in the twelve months to January 2026, a 22% jump from the year before, and fines issued under GDPR since 2018 have now crossed \u20ac7.1 billion.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Recruitment databases, full of resumes, phone numbers, salary history, and interview notes, sit squarely inside the scope of that enforcement wave.<\/span><\/p>\n<p><b>Candidate database compliance<\/b><span style=\"font-weight: 400;\"> isn&#8217;t a legal footnote anymore. It&#8217;s an operational requirement that touches every stage of hiring from the moment a resume lands in your inbox to the day (which should be defined, not indefinite) that data gets deleted.\u00a0<\/span><\/p>\n<p><b>Two frameworks now govern this for most global and India-facing companies<\/b><span style=\"font-weight: 400;\">: the EU&#8217;s General Data Protection Regulation (GDPR) and India&#8217;s Digital Personal Data Protection (DPDP) Act, 2023, now backed by the DPDP Rules, 2025.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The two regimes overlap in spirit; both are consent-driven, both grant individuals rights over their own data, but they diverge in specifics: retention expectations, breach notification timing, and penalty structure are not identical. A hiring team that assumes &#8220;GDPR-compliant&#8221; automatically means &#8220;DPDP-compliant&#8221; is making an expensive assumption.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This piece breaks down what both laws actually require for candidate data, how long you can legally hold on to a resume, what a working consent process looks like, and a checklist you can run against your own <\/span><b>candidate database management<\/b><span style=\"font-weight: 400;\"> setup today.<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1669\" src=\"https:\/\/hirium.com\/blog\/wp-content\/uploads\/2026\/08\/img1_breach_notifications1.png\" alt=\"GDPR data breach notifications chart\" width=\"1979\" height=\"1388\" srcset=\"https:\/\/hirium.com\/blog\/wp-content\/uploads\/2026\/08\/img1_breach_notifications1.png 1979w, https:\/\/hirium.com\/blog\/wp-content\/uploads\/2026\/08\/img1_breach_notifications1-300x210.png 300w, https:\/\/hirium.com\/blog\/wp-content\/uploads\/2026\/08\/img1_breach_notifications1-1024x718.png 1024w, https:\/\/hirium.com\/blog\/wp-content\/uploads\/2026\/08\/img1_breach_notifications1-768x539.png 768w, https:\/\/hirium.com\/blog\/wp-content\/uploads\/2026\/08\/img1_breach_notifications1-1536x1077.png 1536w\" sizes=\"auto, (max-width: 1979px) 100vw, 1979px\" \/><\/p>\n<h2><b>What Is Candidate Database Compliance?<\/b><\/h2>\n<p><b>Candidate database compliance<\/b><span style=\"font-weight: 400;\"> is the practice of collecting, storing, processing, and deleting job applicant data in line with applicable data protection law, primarily GDPR for EU-connected data and the DPDP Act for India-connected data.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It covers lawful basis for collection, defined retention periods, candidate rights (access, correction, deletion), and breach reporting obligations for any system that stores resumes, contact details, or interview records.<\/span><\/p>\n<h2><b>The Core Problem: Recruitment Databases Are Compliance Blind Spots<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Recruitment data has a specific problem that most other business data doesn&#8217;t: it keeps arriving on autopilot and rarely gets cleaned up. A mid-sized company running 40 open roles a year through<\/span><a href=\"https:\/\/hirium.com\/features\/job-posting-software\"> <b>job posting software<\/b><\/a><span style=\"font-weight: 400;\"> can accumulate 8,000\u201312,000 candidate records in 24 months, most of which are unsuccessful applicants whose data has no defined expiry date.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Industry audits of European recruitment databases have repeatedly found that somewhere between 40% and 70% of stored candidate profiles are past any reasonable retention window, not because anyone decided to keep them, but because no one set a deletion clock in the first place.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">That&#8217;s not a minor housekeeping issue. Under GDPR, indefinite retention without a stated purpose is treated as a violation on its own, independent of whether a breach ever occurs.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The DPDP Act compounds this for India-facing hiring teams. Since the <\/span><b>DPDP Rules, 2025<\/b><span style=\"font-weight: 400;\"> were notified on November 13, 2025, and began phased enforcement with further phases scheduled through November 2026 and full penalty enforcement by May 2027, companies hiring in India can no longer treat data protection as a &#8220;we&#8217;ll deal with it later&#8221; item.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Penalties under the Act can reach \u20b9250 crore (roughly $30 million) for serious violations, and unlike GDPR&#8217;s percentage-of-turnover model, DPDP penalties are set in absolute rupee terms per violation category, which can hit smaller companies disproportionately hard.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Most teams underestimate the size of this exposure by 3\u20134x, because they&#8217;re counting active job openings, not the accumulated backlog sitting in old spreadsheets, email threads, and abandoned <\/span><b>candidate database management<\/b><span style=\"font-weight: 400;\"> tools from a previous ATS.<\/span><\/p>\n<h2><b>Where Compliance Risk Actually Hides in the Hiring Stack<\/b><\/h2>\n<p><b>Candidate database compliance<\/b><span style=\"font-weight: 400;\"> doesn&#8217;t live in one tool; it&#8217;s spread across every point where a candidate&#8217;s data gets touched, copied, or forwarded. Mapping those points is usually more revealing than reading the regulation itself.<\/span><\/p>\n<h3><b>Job Posting Software and the Data Collection Moment<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Compliance starts before a candidate ever reaches your database at the job posting stage. <\/span><b>Job posting software<\/b><span style=\"font-weight: 400;\"> that pushes listings to multiple boards often pulls applicant responses back through different integrations, each with its own data handling terms.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If your careers page, LinkedIn Easy Apply, and a third-party job board all feed into the same <\/span><b>candidate database management<\/b><span style=\"font-weight: 400;\"> system, you have three separate consent capture points to audit, not one.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A common failure mode: the careers page has a compliant consent checkbox, but the job-board integration imports applicants without ever showing them that language, because the board&#8217;s own form is what candidates actually filled out.<\/span><\/p>\n<h3><b>AI Interview Scheduling and Assessment Tools<\/b><\/h3>\n<p><a href=\"https:\/\/hirium.com\/features\/ai-interview-scheduling\"><b>AI interview scheduling<\/b><\/a><span style=\"font-weight: 400;\"> and screening tools introduce a second layer of exposure: they usually process candidate data on a separate vendor&#8217;s infrastructure, which means every scheduling link, video interview recording, or automated assessment result is a cross-border or third-party transfer question waiting to be asked.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Under GDPR, this triggers a data processing agreement requirement with the vendor. Under the DPDP Act, it raises a &#8220;Significant Data Fiduciary&#8221; question if volumes are large enough, since heightened obligations, including mandatory audits, apply once an organization crosses thresholds the government designates for that category.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Before enabling an <\/span><b>AI screening<\/b><span style=\"font-weight: 400;\"> feature, it&#8217;s worth confirming the vendor deletes interview recordings and transcripts on the same schedule your own retention policy specifies, rather than keeping a separate copy indefinitely on their side.<\/span><\/p>\n<h3><b>Recruitment Email Templates and Consent Language<\/b><\/h3>\n<p><a href=\"https:\/\/hirium.com\/features\/automated-recruitment-email-templates\"><b>Recruitment email templates<\/b><\/a><span style=\"font-weight: 400;\"> are an underrated compliance surface. Auto-rejection emails, talent-pool invitations, and re-engagement campaigns all involve processing stored candidate data for a new purpose each time they&#8217;re sent.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A rejection template that also pitches &#8220;we&#8217;ll keep your resume on file&#8221; is quietly expanding the original consent scope unless that talent-pool language was part of the original application form.\u00a0<\/span><\/p>\n<p><b>The fix is straightforward:<\/b><span style=\"font-weight: 400;\"> separate the transactional rejection message from any request to extend retention, and make the extension request an explicit yes\/no choice rather than an assumed default.<\/span><\/p>\n<h2><b>GDPR and DPDP Requirements for Candidate Data: A Deep Dive<\/b><\/h2>\n<h3><b>Lawful Basis: Why &#8220;We Need It to Hire&#8221; Isn&#8217;t Always Enough<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Under GDPR, every piece of candidate data you touch needs a documented lawful basis, typically <\/span><b>consent<\/b><span style=\"font-weight: 400;\"> or <\/span><b>legitimate interest<\/b><span style=\"font-weight: 400;\"> for active applicants, and <\/span><b>contract necessity<\/b><span style=\"font-weight: 400;\"> once someone is hired.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The DPDP Act takes a narrower, more consent-centric approach: data can be processed either with explicit, informed consent from the candidate (a &#8220;Data Principal&#8221; in DPDP terminology) or under a defined &#8220;legitimate use,&#8221; which includes employment-related purposes but is more tightly scoped than GDPR&#8217;s legitimate interest test.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Practically, this means your application form language matters. A checkbox that says &#8220;By applying, you agree to our terms&#8221; doesn&#8217;t meet the specificity bar either law expects.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Consent needs to state what data is collected, why, how long it&#8217;s kept, and who it might be shared with (background check vendors, <\/span><b>AI interview scheduling<\/b><span style=\"font-weight: 400;\"> tools, assessment platforms).<\/span><\/p>\n<h3><b>Data Retention: How Long Can You Actually Keep a Resume?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">This is the single most common compliance gap in recruitment. Neither GDPR nor the DPDP Act sets one universal retention number; both require you to define a <\/span><b>purpose-based retention period<\/b><span style=\"font-weight: 400;\"> and justify it.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">But regulatory guidance gives usable benchmarks:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Unsuccessful candidates (GDPR):<\/b><span style=\"font-weight: 400;\"> UK ICO and EDPB guidance points to 6\u201312 months as reasonable, unless the candidate has separately consented to a longer &#8220;talent pool&#8221; retention.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Talent pool retention (GDPR):<\/b><span style=\"font-weight: 400;\"> French CNIL guidance permits up to 2 years for candidates who&#8217;ve explicitly opted into future-opportunity contact, but this requires a fresh consent capture, not a silent carry-over.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Hired candidates:<\/b><span style=\"font-weight: 400;\"> Once someone becomes an employee, their data moves out of &#8220;candidate&#8221; retention rules and into standard HR\/payroll retention schedules, which are typically longer and governed by employment and tax law.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>DPDP Act:<\/b><span style=\"font-weight: 400;\"> The Act doesn&#8217;t prescribe a fixed number of months for candidate data specifically. Instead, it requires that data be erased once the purpose for collecting it has been fulfilled, unless retention is required for legal compliance, placing the burden on the employer to define and document that window.<\/span><\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1671\" src=\"https:\/\/hirium.com\/blog\/wp-content\/uploads\/2026\/08\/img3_data_lifecycle1-scaled.png\" alt=\"Candidate data lifecycle timeline diagram\" width=\"2560\" height=\"1094\" srcset=\"https:\/\/hirium.com\/blog\/wp-content\/uploads\/2026\/08\/img3_data_lifecycle1-scaled.png 2560w, https:\/\/hirium.com\/blog\/wp-content\/uploads\/2026\/08\/img3_data_lifecycle1-300x128.png 300w, https:\/\/hirium.com\/blog\/wp-content\/uploads\/2026\/08\/img3_data_lifecycle1-1024x438.png 1024w, https:\/\/hirium.com\/blog\/wp-content\/uploads\/2026\/08\/img3_data_lifecycle1-768x328.png 768w, https:\/\/hirium.com\/blog\/wp-content\/uploads\/2026\/08\/img3_data_lifecycle1-1536x656.png 1536w, https:\/\/hirium.com\/blog\/wp-content\/uploads\/2026\/08\/img3_data_lifecycle1-2048x875.png 2048w\" sizes=\"auto, (max-width: 2560px) 100vw, 2560px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">A workable <\/span><b>data retention<\/b><span style=\"font-weight: 400;\"> policy, in practice, looks like this:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Classify<\/b><span style=\"font-weight: 400;\"> candidate records by stage: active applicant, rejected applicant, talent pool, hired employee.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Assign a retention window<\/b><span style=\"font-weight: 400;\"> to each category (e.g., 9 months for rejected applicants, 24 months for opted-in talent pool).<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Automate expiry<\/b><span style=\"font-weight: 400;\"> inside your ATS so records are flagged or deleted on schedule rather than relying on manual review.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Re-capture consent<\/b><span style=\"font-weight: 400;\"> before extending retention beyond the original stated period.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Log deletions<\/b><span style=\"font-weight: 400;\"> so you can demonstrate compliance if a candidate or regulator asks.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Audit quarterly<\/b><span style=\"font-weight: 400;\"> for records that have silently exceeded their window; this is where most violations are actually found.<\/span><\/li>\n<\/ol>\n<h3><b>Consent Management Basics<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Consent isn&#8217;t a one-time checkbox event; it&#8217;s a state that needs to be tracked, refreshed, and revocable.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A functional <\/span><b>consent management<\/b><span style=\"font-weight: 400;\"> setup should let a candidate see what data you hold, withdraw consent, and trigger a deletion request without needing to email HR and wait a week for a manual response.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Under GDPR, access and deletion requests generally need a response within 30 days; the DPDP Rules similarly require Data Fiduciaries to respond to Data Principal requests within a defined timeframe set by the Rules.<\/span><\/p>\n<h3><b>Security and Breach Notification<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Both frameworks assume breaches will happen and focus regulation on response speed. GDPR requires notifying the relevant supervisory authority within 72 hours of becoming aware of a breach involving personal data, where feasible.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The DPDP Rules, 2025 introduce comparable urgency for Indian data fiduciaries, requiring prompt notification to both the Data Protection Board of India and affected individuals once a breach is identified, reinforcing why <\/span><a href=\"https:\/\/hirium.com\/features\/candidate-database-management\"><b>candidate database management<\/b> <\/a><span style=\"font-weight: 400;\">systems need built-in access logging and encryption, not just password protection.<\/span><\/p>\n<h3><b>Cross-Border Data Transfer<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">If your <\/span><b>AI interview scheduling<\/b><span style=\"font-weight: 400;\"> tool, resume parser, or assessment vendor is hosted outside the candidate&#8217;s home jurisdiction, cross-border transfer rules apply.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">GDPR requires an approved transfer mechanism (Standard Contractual Clauses, or reliance on frameworks like the EU-US Data Privacy Framework, upheld by the European General Court in September 2025).\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The DPDP Act&#8217;s cross-border transfer restrictions remain subject to further government notification as of mid-2026, meaning companies hiring in India should watch this space rather than assume the current lighter-touch position is permanent.<\/span><\/p>\n<h3><b>Documenting Your Compliance Position<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Both frameworks reward organizations that can show their reasoning, not just their outcome.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A Data Protection Impact Assessment (DPIA), effectively mandatory under GDPR for any high-volume automated screening and increasingly expected practice under DPDP for AI-driven hiring tools, doesn&#8217;t need to be a 40-page document.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For most startups and SMBs, a working DPIA covers four things: what data is collected, why, what the risk of misuse or breach looks like, and what controls reduce that risk.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Keeping this as a living document, reviewed each time a new hiring tool is added to the stack, does more for <\/span><b>candidate database compliance<\/b><span style=\"font-weight: 400;\"> than any one-off legal review.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Vendor and Sub-Processor Accountability<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Every additional vendor in your hiring stack background check providers, skills assessment platforms, reference-check tools is technically a sub-processor of candidate data, and both GDPR and DPDP place responsibility on the primary organization (the Data Fiduciary, in DPDP terms) to ensure those vendors meet the same standard.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This means your vendor contracts should specify retention limits, breach notification timelines, and deletion procedures that mirror your own policy, not whatever the vendor&#8217;s default terms happen to say.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Skipping this step is one of the more common reasons a compliant-looking internal process still fails an external audit.<\/span><\/p>\n<h2><b>Case Studies: Compliance in Practice<\/b><\/h2>\n<h3><b>Case 1: A Series B SaaS company (120 employees, hiring across EU and India).<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">An internal audit found 14 months of candidate data sitting in a legacy spreadsheet with no retention tags, alongside their ATS.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">After consolidating into a single <\/span><b>candidate database management<\/b><span style=\"font-weight: 400;\"> system with automated retention rules, the team cut its &#8220;orphaned record&#8221; count by 78% in one quarter and closed a gap that would otherwise have surfaced during a Series C data protection review.<\/span><\/p>\n<h3><b>Case 2: A staffing agency handling 3,000+ applications annually.\u00a0<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Rejected-candidate data was being retained indefinitely &#8220;in case a role reopened.&#8221;<\/span><\/p>\n<p><span style=\"font-weight: 400;\">After implementing a 9-month auto-delete window with an opt-in talent pool extension, the agency reduced its stored candidate volume by roughly 55% while retaining every candidate who had actively chosen to stay reachable, turning a compliance risk into a cleaner, more relevant pipeline.<\/span><\/p>\n<h3><b>Case 3: A fintech startup hiring simultaneously in the EU and India.<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The team was running two separate consent processes: a GDPR-style form for EU roles and a generic form for Indian roles that hadn&#8217;t been updated since before the DPDP Rules took effect.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">After the November 2025 notification, they rebuilt a single <\/span><b>candidate database compliance<\/b><span style=\"font-weight: 400;\"> workflow that applied the stricter of the two frameworks&#8217; requirements by default, rather than maintaining parallel policies.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The consolidation took roughly three weeks and eliminated the risk of an Indian candidate&#8217;s data being processed under EU-only assumptions that didn&#8217;t reflect DPDP&#8217;s consent-specific rules.<\/span><\/p>\n<h2><b>Comparison: Evaluating Your Compliance Approach<\/b><\/h2>\n<table>\n<tbody>\n<tr>\n<td><b>Approach<\/b><\/td>\n<td><b>Retention Control<\/b><\/td>\n<td><b>Consent Tracking<\/b><\/td>\n<td><b>Breach Response Readiness<\/b><\/td>\n<td><b>Best Fit<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Manual spreadsheets\/email<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Weak\u00a0 no automated expiry<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Rarely logged<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Slow, undocumented<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Very early-stage teams only<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Legacy ATS without compliance features<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Partial\u00a0 manual deletion<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Basic form capture<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Moderate<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Teams outgrowing spreadsheets<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Modern ATS with built-in retention rules<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Strong\u00a0 automated<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Centralized, auditable<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Fast, logged<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Startups\/SMBs scaling hiring volume<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Custom-built in-house system<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Depends entirely on build quality<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Depends on engineering investment<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Depends on maintenance<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Larger orgs with dedicated data teams<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">The clearest signal a system is working: you can answer &#8220;how long have we held this candidate&#8217;s data, and why&#8221; in under a minute, for any record, without opening five different tools.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Cost is often the deciding factor teams weigh against these options, and it&#8217;s worth being specific rather than vague about it.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Building even a basic in-house retention and consent layer typically runs \u20b98\u201315 lakhs in initial engineering time for a small team, plus ongoing maintenance as regulations shift; the DPDP Rules&#8217; phased rollout through May 2027 alone guarantees at least two more rounds of required updates.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A modern ATS with compliance features built in shifts that cost into a subscription, which is usually the better trade for teams under 200 employees that don&#8217;t have a dedicated data engineering function to maintain custom tooling indefinitely.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The migration question also matters more than teams expect.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Switching <\/span><b>candidate database management<\/b><span style=\"font-weight: 400;\"> systems mid-year, without a plan for the data sitting in the old tool, is how orphaned records end up outside any retention policy in the first place.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A clean migration should include an audit of what&#8217;s being carried over, an explicit decision on what gets left behind (and deleted, not just abandoned), and a fresh consent check for any records older than your defined retention window.<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1673\" src=\"https:\/\/hirium.com\/blog\/wp-content\/uploads\/2026\/08\/img4_gdpr_vs_dpdp1.png\" alt=\"GDPR versus DPDP Act comparison\" width=\"2379\" height=\"1679\" srcset=\"https:\/\/hirium.com\/blog\/wp-content\/uploads\/2026\/08\/img4_gdpr_vs_dpdp1.png 2379w, https:\/\/hirium.com\/blog\/wp-content\/uploads\/2026\/08\/img4_gdpr_vs_dpdp1-300x212.png 300w, https:\/\/hirium.com\/blog\/wp-content\/uploads\/2026\/08\/img4_gdpr_vs_dpdp1-1024x723.png 1024w, https:\/\/hirium.com\/blog\/wp-content\/uploads\/2026\/08\/img4_gdpr_vs_dpdp1-768x542.png 768w, https:\/\/hirium.com\/blog\/wp-content\/uploads\/2026\/08\/img4_gdpr_vs_dpdp1-1536x1084.png 1536w, https:\/\/hirium.com\/blog\/wp-content\/uploads\/2026\/08\/img4_gdpr_vs_dpdp1-2048x1445.png 2048w\" sizes=\"auto, (max-width: 2379px) 100vw, 2379px\" \/><\/p>\n<h2><b>What Most Teams Get Wrong<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The most common mistake isn&#8217;t ignoring compliance; it&#8217;s treating it as a one-time policy document rather than an operating habit.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Teams write a retention policy, store it in a shared drive, and never connect it to the actual <\/span><b>candidate database management<\/b><span style=\"font-weight: 400;\"> system doing the storing. The policy and the software drift apart within two hiring cycles.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The second mistake is conflating consent for the <\/span><i><span style=\"font-weight: 400;\">application<\/span><\/i><span style=\"font-weight: 400;\"> with consent for <\/span><i><span style=\"font-weight: 400;\">ongoing contact<\/span><\/i><span style=\"font-weight: 400;\">.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A candidate who applied to one role did not agree to be in your database for the next three years of open positions that require a separate, explicit opt-in, and treating it as implied is one of the more frequently cited GDPR violations in HR-sector enforcement.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The third and most avoidable mistake is assuming a tool&#8217;s marketing claim of &#8220;GDPR-ready&#8221; substitutes for an actual internal audit.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Software can provide the mechanism for retention limits and deletion logs; it cannot decide what your retention periods should be or make sure your team is actually using the feature.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Compliance is a process the software supports, not a checkbox the software ticks on your behalf.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A fourth pattern worth naming: treating <\/span><b>candidate database compliance<\/b><span style=\"font-weight: 400;\"> as solely a legal or HR responsibility, with no input from whoever actually configures the ATS or job board integrations.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In practice, the person setting up an application form&#8217;s fields and the person writing the privacy policy are often different people who never compared notes.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">That gap is where consent language and actual data collection quietly drift apart: the form asks for more than the policy discloses, or the policy promises a retention window the system was never configured to enforce.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Closing that gap takes one recurring meeting between recruiting operations and whoever owns data governance, not a new piece of software.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">None of this is unique to large enterprises. If anything, smaller recruiting teams are more exposed, because they&#8217;re less likely to have a dedicated compliance function catching these gaps before a candidate complaint or an audit does.<\/span><\/p>\n<h2><b>Building a Repeatable Compliance Checklist<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">A one-time audit fixes today&#8217;s problem but not next quarter&#8217;s. The teams that stay ahead of both frameworks tend to run the same short checklist on a fixed cadence rather than reacting to a specific incident or renewal date:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confirm every active data collection point careers page, job boards, referral forms displays consent language that matches your actual retention policy, not a generic placeholder.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reconcile retention windows across every category of candidate record, and confirm your ATS is actually enforcing them rather than just displaying them in a settings page.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Review vendor contracts for AI screening, background checks, and assessment tools against current breach-notification and deletion-timeline standards, since these terms often lag behind the platforms&#8217; own compliance claims.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Re-run consent for any<\/span><a href=\"https:\/\/hirium.com\/blog\/ai-resume-parser-for-talent-pools\/\"> <b>talent-pool candidates <\/b><\/a><span style=\"font-weight: 400;\">approaching the end of their original stated window.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log every deletion and access request response, with timestamps, so a demonstrated compliance history exists before it&#8217;s ever needed.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Run this quarterly, and <\/span><a href=\"https:\/\/hirium.com\/blog\/best-ways-to-manage-candidate-database\/\"><b>candidate database<\/b><\/a><span style=\"font-weight: 400;\"> compliance stops being a project with a deadline and becomes a background process that just runs, which is the actual goal, since neither GDPR nor the DPDP Act rewards a one-time fix over a maintained standard.<\/span><\/p>\n<h2><b>Frequently Asked Questions<\/b><\/h2>\n<h3><b>1. How long can a company legally store candidate resumes?\u00a0<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">There&#8217;s no single fixed number under GDPR or the DPDP Act. GDPR guidance from EU regulators typically points to 6\u201312 months for unsuccessful candidates unless they&#8217;ve separately consented to talent-pool retention (up to 2 years in some jurisdictions). The DPDP Act requires deletion once the purpose is fulfilled, with the exact window defined by the employer&#8217;s documented policy.<\/span><\/p>\n<h3><b>2. Does India&#8217;s DPDP Act apply to recruitment data?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Yes. The DPDP Act, 2023, and the DPDP Rules, 2025 (notified November 2025) apply to any digital personal data connected to India, which includes resumes, contact details, and assessment records collected from Indian candidates or processed by companies operating in India, regardless of where the hiring company is headquartered.<\/span><\/p>\n<h3><b>3. What is the difference between GDPR and DPDP Act obligations?\u00a0<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">GDPR allows multiple lawful bases for processing, including legitimate interest, and sets fine amounts as a percentage of global turnover. The DPDP Act leans more heavily on explicit consent or narrowly defined &#8220;legitimate uses,&#8221; and sets fines in fixed rupee amounts up to \u20b9250 crore per violation category rather than a turnover percentage.<\/span><\/p>\n<h3><b>4. Do recruiters need candidate consent to store CVs?\u00a0<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Generally, yes, either explicit consent or a clearly documented legitimate basis is required under both frameworks. Storing a resume without informing the candidate what it will be used for, or for how long, is a common compliance gap that regulators have flagged in HR-sector audits.<\/span><\/p>\n<h3><b>5. What happens if an ATS is not compliant with data protection law?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The company using the ATS remains legally responsible for the data, regardless of the tool&#8217;s own compliance posture. Non-compliant retention or consent handling can result in fines, mandatory data deletion orders, and reputational damage from candidate complaints, which are the most common trigger for recruitment-sector investigations.<\/span><\/p>\n<h3><b>6. Can candidate data be reused for future job openings?<\/b><span style=\"font-weight: 400;\">\u00a0<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Only if the candidate has given separate, explicit consent to be considered for future roles beyond the original application. Reusing rejected-candidate data for a new opening without that consent is treated as a new, unauthorized processing activity under both GDPR and the DPDP Act.<\/span><\/p>\n<h3><b>7. Should startups build compliance features in-house or rely on their ATS?<\/b><span style=\"font-weight: 400;\">\u00a0<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">For most startups and SMBs, relying on an ATS with built-in retention automation, consent logging, and access controls is more reliable than building and maintaining custom compliance tooling, provided the internal team still owns the policy decisions (retention windows, consent language) rather than assuming the software makes them automatically.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you&#8217;re weighing this trade-off before committing to a platform, it&#8217;s worth pressure-testing your current <\/span><b>recruitment email templates<\/b><span style=\"font-weight: 400;\">, consent forms, and retention settings against both frameworks first.<\/span><\/p>\n<h3><b>8. Is a Data Protection Impact Assessment mandatory for hiring tools?\u00a0<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Under GDPR, a DPIA is generally required when using automated decision-making or profiling at scale, which covers many <\/span><b>AI interview scheduling<\/b><span style=\"font-weight: 400;\"> and screening tools.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The DPDP Rules don&#8217;t use identical terminology, but Significant Data Fiduciaries face comparable audit and assessment obligations once they cross volume thresholds set by the government, making an internal risk assessment good practice even where it isn&#8217;t strictly named as mandatory.<\/span><\/p>\n<h2><b>Getting Your Candidate Database Audit-Ready<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Compliance isn&#8217;t a single fix; it&#8217;s a recurring discipline of classification, consent tracking, and scheduled deletion, applied consistently across every hiring cycle. Start with a basic audit: pull every place candidate data currently lives, tag each record&#8217;s age and consent status, and flag anything past a defined retention window.<\/span><\/p>\n<p><a href=\"https:\/\/hirium.com\/\"><b>Hirium&#8217;<\/b><\/a><span style=\"font-weight: 400;\">s centralized candidate database structure, with real-time tracking and automated status workflows, is built to make that audit a five-minute task rather than a two-week project, but the audit itself is worth doing regardless of which system you run it on.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Most recruitment teams are sitting on a legal liability they haven&#8217;t priced in. European regulators processed an average of 443 personal data breach notifications every single day in the twelve months to January 2026, a 22% jump from the year before, and fines issued under GDPR since 2018 have now crossed \u20ac7.1 billion.\u00a0 Recruitment databases, [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":1674,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[],"class_list":["post-1668","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-in-recruitment"],"_links":{"self":[{"href":"https:\/\/hirium.com\/blog\/wp-json\/wp\/v2\/posts\/1668","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hirium.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hirium.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hirium.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/hirium.com\/blog\/wp-json\/wp\/v2\/comments?post=1668"}],"version-history":[{"count":1,"href":"https:\/\/hirium.com\/blog\/wp-json\/wp\/v2\/posts\/1668\/revisions"}],"predecessor-version":[{"id":1675,"href":"https:\/\/hirium.com\/blog\/wp-json\/wp\/v2\/posts\/1668\/revisions\/1675"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hirium.com\/blog\/wp-json\/wp\/v2\/media\/1674"}],"wp:attachment":[{"href":"https:\/\/hirium.com\/blog\/wp-json\/wp\/v2\/media?parent=1668"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hirium.com\/blog\/wp-json\/wp\/v2\/categories?post=1668"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hirium.com\/blog\/wp-json\/wp\/v2\/tags?post=1668"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}