Skip to content
Surhires

India

Notice, consent and purpose limits under India's DPDP Act

India's data protection law is built around notice and consent, which lands directly on a recruitment database full of people who were never asked.

Under India's Digital Personal Data Protection Act your firm is the data fiduciary for candidate data and Surhires is a data processor acting on your instructions. The product supports itemised notice, dated consent records, purpose tagging, withdrawal, portability export and erasure. Compliance depends on your notices and processes, and none is claimed on your behalf.

By Surhires Editorial · Published · Reviewed

What this page is, and the role your firm holds

This is a plain-English explanation of how the product supports obligations under India's Digital Personal Data Protection Act. It is not a compliance statement, not the privacy policy and not legal advice. The binding documents are the privacy policy published on this site, the executed agreement and the data processing addendum. Where this page differs from them, they govern.

Your firm is the data fiduciary for the candidate data in your tenant, because your firm determines why it is held and for how long. Soor LLC is a data processor acting on your instructions under the addendum. Where a staffing firm is delivering for a client who directs the processing, the chain runs one step further and your client contract decides the allocation, which is a question for your counsel.

Rules under the Act continue to develop, including on the operational detail of consent managers, breach reporting and children's data. Any explanation written today describes the position as it currently stands rather than as it will finally settle, and that is worth remembering when a client audit quotes a page back at you.

The Act builds on consent that is free, specific, informed, unconditional and unambiguous, given by clear affirmative action, and limited to the personal data necessary for the stated purpose. Recruitment strains that at every point, because a single candidate record supports several distinct purposes: matching to a live role, submitting to a named client, keeping on file for future roles, and running background verification.

Bundling those into one tick box is the failure mode. Consent to be submitted to one client is not consent to sit in a database for three years, and consent to be considered for a role is not consent to a verification check. The product supports purpose tagging on the consent record so the purposes are held separately rather than merged.

Where consent is withdrawn for one purpose it stays valid for the others, and the record shows which is which. That is more work at capture and considerably less work at the moment somebody asks what exactly they agreed to.

  • Consent recorded per purpose rather than bundled into one flag
  • Matching, submittal, retention and verification held as distinct purposes
  • Withdrawal applied to a purpose without collapsing the others
  • Clear affirmative action recorded, not an inferred acceptance
  • The wording shown at capture stored with the consent event

Itemised notice, in the language the person can read

Notice under the Act is itemised: what personal data, for what specified purpose, how to exercise rights, and how to complain to the Board. It must be available in English and in the languages listed in the Eighth Schedule to the Constitution, which for an Indian staffing firm working blue-collar or regional desks is not a formality. A notice nobody can read has not been given.

The product supports attaching notice text to application forms and outreach templates, holding multiple language variants, and recording which version and which language was shown against the consent event. That last field is what turns a claim into a record. Being able to say the person saw this exact wording, on this date, in this language, is the difference between evidence and assertion.

The wording is yours. It names your firm as fiduciary, describes your actual purposes, and gives your grievance route. Copying another firm's notice describes their practice, and if it does not match yours it is worse than a short notice that does.

The Act contemplates consent managers: registered intermediaries through which a person can give, manage, review and withdraw consent, with an interoperable and accessible interface. The ecosystem is still developing, and the honest position is that no product should describe integration with a framework whose operational detail is not finished.

What the product does today is hold consent in a way that fits the concept rather than fighting it: consent as dated events with purpose, wording, language, channel and capturer recorded; withdrawal as its own event; and a candidate-facing view where a person can see what they agreed to and withdraw without emailing a recruiter. Those are the mechanics a consent manager relationship would need on the fiduciary side.

Where registered consent managers become operationally available and integration is expected, that is roadmap work rather than something shipping today, and it is written that way here on purpose. Claiming readiness for a framework that has not settled is exactly the kind of statement that ages into a misrepresentation.

Purpose limitation and erasure once the purpose is done

The Act is direct about this: personal data is kept for the specified purpose and erased when the purpose is served and retention is no longer required by law. For a recruitment database that is a sharper instruction than most firms operate under. A candidate submitted to one role two years ago, never placed and never contacted since, is holding data whose purpose expired a long time ago.

Retention windows in the product run from the last meaningful contact rather than from record creation, and expiry raises a review queue rather than deleting on a timer. The queue carries the basis, the last contact and three options: extend with a recorded justification, contact the candidate to refresh consent, or erase. The decision is written with an actor and a date.

Erasure removes the profile, custom fields, notes, messages, the original uploaded document, the extracted text and the search representation together, and keeps a fulfilment record which is the fact of the request rather than the data it concerned. Retention required by law, typically financial records from a completed placement, is separated and kept under a stated reason rather than quietly retained.

  • Retention measured from real contact, not from record creation
  • Expiry produces a decision with an owner and a date
  • Erasure reaches the document, the extracted text and the index
  • Legally required retention separated and named rather than hidden
  • Fulfilment records kept after the underlying data has gone

What an Indian staffing firm actually needs to be able to show

Client audits and any future regulatory contact tend to ask the same set of questions, and none of them are about software. Which purposes do you collect for. What notice did this person see, in which language, on what date. What did they consent to and what have they withdrawn. How long do you keep each category and why. How is a grievance received and answered, and within what time.

The product supplies the evidence for most of those: dated consent events with wording and language, purpose tags, retention windows and their decisions, export and erasure with an audit trail, and a searchable identity view so a request about one person resolves across duplicate records. What it cannot supply is the grievance process, the retention policy or the appointment of the people who answer.

There is also a scale consideration worth naming. Firms designated as significant data fiduciaries carry extra obligations, including a data protection officer based in India, independent audits and impact assessments. Whether that designation reaches your firm is not a question a vendor page can answer, and it should be asked before it is answered for you.

Cross-border processing, and where the data actually sits

Primary processing is in the United States on AWS us-east-1, with encrypted backups. For an Indian firm that is a cross-border transfer, and the Act permits transfer other than to territories restricted by government notification. The restriction list is a moving object rather than a settled one, which is a fact about the regime rather than an evasion.

The practical position is that your assessment has to be current rather than made once at signature. The subprocessor register states where each category processes, which is the field to read when a residency question arises, and the notice and objection route in the addendum is the mechanism for acting on what you find.

Firms with a contractual requirement for Indian residency should raise it during procurement rather than after. It is a real constraint that the primary region does not meet today, and saying so directly is more useful to a buyer than a paragraph implying flexibility that does not exist.

What you get

Fiduciary and processor split

Your firm determines purpose and retention; Soor LLC processes on instructions under the addendum.

Per-purpose consent

Matching, submittal, retention and verification recorded as separate purposes rather than bundled.

Wording captured

The exact notice text shown at capture stored with the consent event, not referenced loosely.

Language recorded

Which language variant the person was shown, held against the consent event as evidence.

Multi-language notices

Notice variants attachable to forms and outreach for regional and blue-collar desks.

Withdrawal as an event

Withdrawal recorded with its own timestamp and scope, leaving other purposes intact.

Candidate self-view

A route for a person to see what they agreed to and withdraw without emailing a recruiter.

Purpose tags on records

Records carry the purposes they are held for, so expiry can be assessed purpose by purpose.

Last-contact retention

Windows measured from a contact the candidate took part in, configurable per record type.

Review queue at expiry

Extend, refresh or erase, with the decision written against the record and its owner.

Portability export

Structured export of the candidate record as CSV and JSON, run without a support ticket.

Erasure to the document

Original file, extracted text and search representation removed alongside the profile and notes.

Identity-level search

One request resolved across duplicate records created by different recruiters or imports.

Stated residency position

Primary processing in the United States, named plainly so a residency requirement surfaces early.

Questions recruiters ask

Is Surhires DPDP compliant?

No product is. Your firm is the data fiduciary for the candidate data it holds, and compliance depends on your notices, your purposes, your retention decisions and your grievance process. The product supports notice and consent records against candidate profiles and portability export. That is a capability statement, and it is the accurate way to describe what software can do here.

Do you integrate with a registered consent manager?

Not today. The consent manager ecosystem is still developing and claiming readiness for a framework whose operational detail has not settled would be misleading. What exists now is consent held as dated events with purpose, wording, language and channel, plus a candidate-facing view for review and withdrawal, which is the fiduciary-side structure such a relationship would require.

Do notices really need to be in regional languages?

The Act contemplates notice being available in English and in the languages listed in the Eighth Schedule. For firms running blue-collar or regional desks that is a practical requirement rather than a formality, because a notice the person cannot read has not informed them. The product holds language variants and records which one was shown.

Can one consent cover the whole candidate relationship?

It should not. Consent to be submitted to a named client is not consent to sit in a database for three years, and neither is consent to a verification check. Purposes are recorded separately so withdrawal of one leaves the others intact, which costs a little more at capture and saves a great deal when somebody asks what they agreed to.

Our client requires Indian data residency. Can that be met?

Not on the primary region today, which processes in the United States on AWS us-east-1 with encrypted backups. That is a real constraint and it is better raised during procurement than discovered later. The subprocessor register states where each category processes, and Enterprise conversations are the right place to test what alternatives, if any, are available.

What should we be able to show if a client audits us?

Which purposes you collect for, what notice each person saw with its language and date, what they consented to and what they have withdrawn, how long each category is kept and why, and how grievances are received and answered. The product evidences most of the first set; the retention policy and the grievance process are yours to write.

See it against your own reqs

Bring one live role and three resumes. In twenty minutes you will see the match scores, the shortlist and the placement invoice that comes out the other end.