The Practice

A recruiter maintains a personal spreadsheet — stored in a personal cloud drive or on a local device — containing candidate names, contact numbers, salary expectations, interview feedback, and sourcing notes accumulated over multiple hiring cycles. This informal database is used as a first reference when new roles open, often without the knowledge of the organisation's HR leadership.

 

Questions Raised for Compliance Review

1. Does the maintenance of an informal candidate database by an individual recruiter constitute a DPDP compliance risk for the organisation?

2. What obligations does the organisation have toward candidates whose data is retained beyond the specific recruitment process for which it was collected?

3. What is the compliant approach to managing candidate data across hiring cycles?

 

Is This Permitted Under DPDP?

Yes — a significant one. The candidates in this spreadsheet provided their personal data for a specific recruitment process. Most of them were not informed that their data would be retained after that process concluded, carried forward into future hiring cycles, or held outside any organisational system. The recruiter's intent is operationally logical but is non-compliant under DPDP on multiple grounds.

 

Where the Breach Risks Sit

Data collected beyond its declared purpose — Candidate data is typically collected under the implicit or explicit understanding that it will be used for the role being applied for. Retaining it indefinitely for future openings is a purpose extension that requires either fresh consent or a separately declared retention purpose communicated at the time of collection.

Unregistered personal data store — A personal spreadsheet on a private cloud account or local device is outside the organisation's data governance framework entirely. It is not backed up under organisational security standards, not subject to access controls, and invisible to the DPO. From a DPDP accountability perspective, the organisation cannot demonstrate it knows where candidate data is held.

No deletion process — Candidates who were not selected, who withdrew, or who explicitly requested removal from consideration may still appear in this spreadsheet. DPDP gives data principals the right to erasure — a right the organisation cannot honour if it does not know the data exists.

Security exposure — Personal contact details, salary information, and interview assessments held on a personal device or personal cloud account are not protected by organisational security controls. A personal account compromise means a breach of candidate personal data — with no incident response process triggered because the organisation did not know the data was there.

 

The Ideal Compliant Approach

1. Mandate use of the organisational ATS. All candidate data must be captured, retained, and managed within the organisation's Applicant Tracking System (ATS) — not in personal spreadsheets or personal cloud drives. This ensures governance, access controls, and auditability.

2. Disclose retention intent at application. If the organisation wishes to retain candidate profiles for future opportunities, this must be communicated to candidates at the point of application, with a specific opt-in for talent pool inclusion and a defined retention period — typically six to twelve months.

3. Implement a talent pool management process. Candidates who opt into the talent pool should receive periodic reminders that their data is held, with an easy mechanism to update or withdraw. Candidates who do not respond to a defined re-consent cycle should be deleted from the pool.

4. Audit for shadow data stores. HR leadership should conduct a periodic audit to identify any candidate data held outside the ATS — by individual recruiters, in shared drives, or in personal accounts — and migrate or delete it accordingly.


 

DPDP Risk Summary

ElementStatusRecommended Action
Informal candidate spreadsheet outside ATSUnregistered data store, no governanceMigrate to ATS; delete personal copies
Retention beyond specific recruitment processNo declared purpose or consentObtain opt-in for talent pool; define retention period
No deletion process for rejected candidatesRight to erasure cannot be honouredImplement automated deletion at retention threshold
Personal device / cloud storage usedOutside organisational security controlsProhibit personal storage of candidate data by policy
Organisation unaware of data existenceAccountability failure under DPDPConduct shadow data audit across HR and recruitment teams