RISC CURIS CONSULTING PRIVATE LIMITED | CEO INSIGHTS
Executive Summary & Context
India’s Digital Personal Data Protection (DPDP) Act, 2023 has permanently replaced passive, informal HR data gathering with a strict, consent-first governance regime. For corporate employers (acting as Data Fiduciaries) and background screening agencies (acting as Data Processors), implicit pre-employment checks, catch-all consent waivers, and blanket screening are now major regulatory liabilities punishable by fines up to ₹250 Crore. This article outlines the revised legal framework, candidate consent requirements, and essential client safeguards.
1. The Paradigm Shift: Background Screening Under the DPDP Act
For decades, workplace screening in India operated in a regulatory grey area governed by fragmented guidelines under the Information Technology Act, 2000. Onboarding teams frequently used bundled consent disclosures buried deep within 40-page employment contracts or offer letters, authorizing “any background verification deemed necessary.”
The enactment of the DPDP Act 2023 and its operational rules fundamentally dismantles this legacy model. Personal data—encompassing government IDs, educational transcripts, employment histories, court record searches, and address checks—is protected under strict statutory principles:
- Data Principal: The job candidate or employee whose credentials are being verified.
- Data Fiduciary: The employer determining the necessity and scope of background verification.
- Data Processor: The specialized background screening firm (such as Risc Curis Consulting Private Limited) executing checks on behalf of the employer.
The “Employment Legitimate Use” Trap (Section 7 vs. Section 6)
A common misconception among HR leadership is that Section 7 (“Legitimate Use for Employment Purposes”) exempts prospective candidate screening from consent requirements. Section 7 applies strictly to existing employment relationships (e.g., statutory filings, payroll, performance management). Because a job candidate is not yet an employee, pre-employment background verification requires explicit, affirmative consent under Section 6. Relying on Section 7 for candidate screening exposes organizations to significant legal risk.
2. Re-engineering Candidate Consent: The 6 Pillars of Valid Consent
Under Section 6 of the DPDP Act, informal, implicit, or pre-checked consent is legally void. To withstand regulatory scrutiny by the Data Protection Board (DPB), candidate consent for background verification must strictly fulfill six core requirements:
| # | Consent Pillar | DPDP Regulatory Requirement | Operational Impact on BGV Workflows |
|---|---|---|---|
| 1. | Free & Voluntary | Cannot be coerced, disguised, or made a forced condition beyond job relevance. | Candidates must be given transparent notice without coercive “take-it-or-leave-it” pressure. |
| 2. | Itemized & Specific | Must itemize every single check component. Universal “catch-all” waivers are void. | Consent notices must explicitly list individual checks (e.g., e-Courts search, PAN verification, prior employment). |
| 3. | Informed & Transparent | Must disclose the specific purpose, identity of Data Processor, and retention period. | The notice must name Risc Curis Consulting Pvt. Ltd. as the contracted Data Processor executing the checks. |
| 4. | Unambiguous Opt-In | Requires explicit affirmative action. Pre- ticked boxes are illegal. | Digital consent must be captured via active OTP confirmation, e-signature, or distinct checkbox triggers. |
| 5. | Revocable | Candidates must have an accessible mechanism to withdraw consent at any time. | Workflows must include clear opt-out mechanisms, detailing implications on the evaluation process. |
| 6. | Auditable & Recorded | The Data Fiduciary must prove valid consent was obtained prior to processing. | Automated, timestamped digital audit logs containing exact notice text and IP/device metadata must be archived. |
Furthermore, Section 6 requires that consent notices be available in English and all 22 scheduled regional languages upon the candidate’s request, requiring screening portals to support multilingual user interfaces.
3. Fundamental Principles Changing Day-to-Day Operations
A. Data Minimization & Role-Risk Matrices
Section 6 codifies data minimization: employers may only collect personal data strictly necessary for the specified role. Running deep criminal record checks or financial intelligence screenings on every candidate regardless of seniority is no longer compliant.
Best Practice: Establish a written Role-Risk Matrix mapping job tiers to authorized screening levels:
- Low-Risk Roles (e.g., Entry-Level Admin): Government ID verification, Highest Degree education check, Court record database search.
- Medium-Risk Roles (e.g., IT Systems, Finance): ID, Education, 5-Year Employment verification, Court record search + local police station verification.
- High-Risk Roles (e.g., C-Suite, BFSI, Healthcare): Full credential verification, direct prior employer reference checks, regulatory/sanctions screening, court record + police verification, and direct credit risk check (where legally applicable).
B. Purpose Limitation & The Re-Screening Rule
Data collected during onboarding cannot be repurposed for periodic annual re-screening or promotion audits without
fresh, timestamped consent. Each screening iteration requires a standalone consent event.
C. Prohibited Screening Practices
The DPDP Act severely penalizes unauthorized intrusive checks. Employers must immediately eliminate:
- Informal “off-the-record” neighbor or social acquaintance inquiries.
- Unauthorized social media scraping or deep personal profiling.
- Collection of candidate family history, religion, caste, or political affiliations.
- Mandatory collection of Aadhaar physical copies without offering alternative government ID choices (PAN, Passport, Voter ID).
“At Risc Curis, we view the DPDP Act not as a compliance burden, but as a catalyst for trust and operational maturity. Background verification is no longer about gathering maximum data—it is about obtaining precise, legitimate intelligence with absolute candidate respect and flawless data governance.”
— Ravi R., CEO, Risc Curis Consulting Private Limited
4. Client Safeguards: What Employers Must Implement Immediately
As Data Fiduciaries, corporate clients bear primary legal liability under the DPDP Act. To insulate your organization
from regulatory penalties and reputational fallout, implement these five structural safeguards:
- Decouple Consent Notices from Employment Contracts
Transition immediately to standalone, digital consent notices. Ensure consent is collected prior to initiating any screening activity and that candidate opt-ins are stored in an immutable, auditable log. - Execute Legally Binding Data Processing Agreements (DPA)
Ensure your agreement with background verification partners includes rigid DPDP clauses: purpose binding, mandatory 72-hour breach notification, prohibition of unauthorized sub-processing, and guaranteed data deletion post-retention window. - Establish Candidate Rights Mechanisms (Data Principal Access & Correction)
Candidates have the legal right to access summary verification reports, correct inaccurate records, and request data erasure once the hiring lifecycle ends. Build a clear SLA (30-day response window) with your screening vendor to handle candidate inquiries. - Enforce Data Retention & Destruction Protocols
Establish explicit retention periods (e.g., 180 days for rejected candidates; duration of employment + statutory period for hired staff). Demand a formal Certificate of Data Destruction from your vendor upon expiry. - Audit Security Infrastructure & Certifications
Verify that your background screening vendor maintains robust cybersecurity protocols, including end-to-end AES-256 encryption, ISO 27001 certification, and SOC 2 Type II compliance.
5. How Risc Curis Empowers Your Compliance Journey
At Risc Curis Consulting Private Limited, we have re-architected our screening workflows to deliver native, zero-
friction DPDP compliance for our corporate clients across India.
- Automated Consent Workflows: Mobile-first, multi-language consent notices with instant digital audit trails and OTP verification.
- Role-Based Dynamic Check Routing: Automated role-risk matrix templates that ensure strict adherence to data minimization.
- Data Governance & Privacy-by-Design: ISO 27001 certified architecture, encrypted candidate communication, and automated retention/erasure management.
- Dispute Resolution Portal: Integrated candidate portal allowing seamless report review, correction requests, and transparent dispute handling.
Partner with Risc Curis for DPDP-Compliant Screening
Ensure your organization’s background verification framework is secure, legally compliant, and aligned with
DPDP standards. Speak with our screening specialists or reach out directly to our sales leadership team via
Call or WhatsApp at +91 99585 45599 or email sales@risccuris.com .
0 Comments