DPDP Act and AI Voice Screening: The Compliance Checklist HR Teams Need Before 2027
DPDP Act and AI Voice Screening: The Compliance Checklist HR Teams Need Before 2027
India’s Digital Personal Data Protection Rules, 2025 were notified on November 13, 2025, and most TA teams we talk to still treat this as a legal-department problem, not an HR-operations one. It isn’t. If your AI screening vendor records a candidate’s voice, transcribes it, scores it, and stores the recording, that recording is personal data under the DPDP Act — and the compliance clock on how you handle it is now running.
What’s actually changing, and when
The rollout is phased, not a single deadline. The Data Protection Board of India became operational immediately on notification. Provisions covering consent managers — the intermediaries who will let candidates track and revoke consent across services — come into force November 13, 2026. The bulk of the substantive obligations that matter to HR — valid consent, privacy notices, a candidate’s right to access and erase their own data, and breach notification — become enforceable May 13, 2027 (PIB notification).
Eighteen months sounds like a long runway. It isn’t, once you look at what “compliant” actually requires for a screening workflow that’s already running thousands of candidates through voice interviews every hiring season.
Why AI voice screening sits squarely in scope
A resume is data. A voice recording of a candidate answering a structured interview question is a different category of data — it captures far more than the words: accent, tone, pace, sometimes background context from wherever the candidate took the call. Under the Act, a data fiduciary (the employer, in most vendor arrangements) is responsible for how that recording is collected, processed, stored, and eventually deleted, even when a third-party vendor is running the actual interview.
That responsibility doesn’t disappear because you outsourced the interview to an AI platform. If anything, it gets sharper: you now have to be able to answer, for any candidate who asks, where their recording sits, who has processed it, how long it’s retained, and how to delete it. Most TA teams we’ve spoken with can’t currently answer any of those four questions about their existing screening stack.
Penalties for getting this wrong aren’t symbolic. The Data Protection Board can levy fines up to ₹250 crore for inadequate security safeguards around personal data, and up to ₹200 crore separately for failing to notify a breach — and a single lapse can trigger both (overview of Section 33 penalties). That’s not a fine an HR budget absorbs quietly.
The checklist before your next campus drive
Four questions to put in front of any AI screening vendor, including us, before your next campaign:
Where does the audio live, and for how long? Get a specific retention window in writing, not “we store it securely.” If a candidate is rejected in round one, there’s no operational reason to keep their voice recording indefinitely.
Is consent captured before the interview starts, not buried in a signup form? A candidate should know, in plain language, that the call is recorded, why, and what happens to the recording, before they say a word into the microphone.
Can a candidate actually get their data deleted on request? Not “we’ll look into it” — an actual documented process, with a turnaround time you can quote back to legal.
Who processes the recording, and where? If your vendor uses a sub-processor for transcription or scoring, you need to know that too. Your compliance exposure doesn’t stop at your primary vendor’s front door.
The part most vendors won’t tell you
Here’s the contrarian take: waiting until May 2027 to build this is the wrong sequencing. Consent and retention practices are far easier to bolt onto a screening workflow when you’re designing the campaign than to retrofit after two years of running drives the old way. We’ve written before about what your legal team will actually ask when they get looped into an AI hiring rollout — DPDP compliance is now the specific, dated version of that same conversation, and it has a statutory clock attached.
The honest complication is that most India-market AI screening vendors, including newer voice-AI entrants, haven’t published clear answers to the four questions above. That’s not because the answers are bad — it’s because most of these products were built before the DPDP Rules had a notified compliance date, and retrofitting a privacy notice into an existing consent flow is genuinely more work than writing one from scratch.
What to do this quarter
You don’t need to wait for a legal mandate to start asking vendors these questions. Build the retention and consent language into your next campus drive’s screening brief now, while the campaign is still being scoped, not after candidates have already gone through the call. If you’re evaluating an AI interview platform for the first time, make the DPDP checklist part of the demo, not an afterthought you raise after signing.
The deadline is 2027. The habit of asking the right questions should start with your next drive.
See HireQwik in action
Book a 30-minute demo — bring a live JD and we'll screen your own candidates against it.