Quick answer
Recruitment compliance is the set of laws a staffing agency must follow when it sources, screens, and places candidates. It covers candidate data privacy, fair and non-discriminatory hiring, lawful background checks, correct treatment of contract staff, and responsible use of AI. In India, the law to plan around in 2026 is the Digital Personal Data Protection (DPDP) Act.
Key takeaways
- India’s DPDP Act treats every resume you hold as personal data, with penalties up to ₹250 crore for weak security.
- Agencies carry more risk than in-house HR because they hold data for many clients and automate at scale.
- Using AI to screen candidates is legal in India today, as long as you disclose it and keep a human reviewing rejections.
- Placing candidates abroad pulls in GDPR (up to €20M or 4% of turnover) and US rules like the FCRA and NYC’s bias-audit law.
- 2026 is a preparation year: the DPDP rules phase in through May 2027.
What is Recruitment Compliance?
Recruitment compliance means following the laws that govern how you find, assess, and place candidates. For an agency it comes down to five things: data privacy, fair hiring, lawful background checks, correct treatment of contract staff, and responsible AI use.
It is not a single law you can tick off. It is a stack of duties that sit on top of your normal work.
Strip away the jargon and it answers five questions:
- Are you allowed to hold this candidate’s data, and do they know about it?
- Is your process fair, with no candidate screening out by age, gender, caste, religion, or disability?
- Are background and reference checks done with permission and kept accurate?
- For temp or contract staff, are the labour registrations and dues in order?
- When a machine helps you screen, can you explain and defend the decision?
Why Do Staffing Agencies Face Bigger Compliance Risks than In-house HR Teams?
Because agencies hold personal data for thousands of candidates across many clients, often act as the legal employer for contract staff, automate screening at scale, and frequently operate across borders. Each of those multiplies the exposure a single in-house team never sees.
An internal HR team handles its own applicants. You handle everyone’s. That is the whole difference.
A few reasons it lands harder on agencies:
- You sit on a large, often old candidate database, and every stored resume is data you now have to justify.
- You process data on behalf of clients, which blurs who is responsible when something breaks.
- If you run temp or contract staffing, you are often the legal employer, which adds labour law on top of hiring law.
- You automate at scale, and AI screening tools are exactly what regulators now watch.
What Does India’s DPDP Act Require Recruiters to Do?
The DPDP Act requires you to tell candidates what data you collect and why, get consent to keep them in your database, let them withdraw easily, use the data only for the stated purpose, secure it, and delete it on a schedule. Fines run up to ₹250 crore for failing to protect personal data.
The Digital Personal Data Protection (DPDP) Act, passed in 2023 with detailed rules finalised in November 2025, is India’s first full data-privacy law. It treats every resume, number, and interview note you hold as personal data you own the risk for.
The rollout is phased. The consent-manager framework comes online around 13 November 2026, and full compliance is expected by 13 May 2027. For an agency sitting on years of data, 2026 is your prep year.
What it asks of a recruiter, in plain terms
- Tell candidates what you collect and why, in clear language and, where it fits, the languages they actually speak.
- Get consent to keep someone in your database, and make withdrawing it as easy as giving it.
- Use data only for what you said. Reusing a profile for an unrelated client role months later, with no basis, is what gets flagged.
- Set a retention period, delete on schedule, and remove anyone who asks.
- Secure it, and know who to notify if there is a breach.
There is breathing room: routine recruitment sits under a “legitimate use” reading, so you are not asking permission for every step. It does not cover reselling data or unrelated uses. See the official DPDP Act text for specifics.
Which Other Indian Laws Affect Recruitment Compliance?
Beyond data privacy, Indian agencies should watch equal-opportunity expectations in job ads and screening, the Contract Labour Act and state Shops and Establishments rules for temp placements, Provident Fund and ESI dues for deployed staff, and plain honesty in job postings.
Data is the headline, but the older rules still bite.
If you place contract or temp workers, the Contract Labour (Regulation and Abolition) Act can require licensing, and you may carry PF and ESI duties for the staff you deploy. Honest job ads, with real roles, pay, and locations, keep you clear of misrepresentation complaints.
Which Recruitment Compliance Laws Apply, at a Glance?
Indian staffing agencies answer mainly to the DPDP Act. If your candidates or clients sit abroad, GDPR, US anti-discrimination and background-check law, and regional AI rules apply on top. The table below is the fast version.
Law / region Applies to Core requirement Max penalty DPDP Act (India) All candidate data you hold in India Notice, consent, purpose limits, retention, security, deletion Up to ₹250 crore GDPR (EU / UK) Candidates based in Europe Lawful basis, transparency, access/erasure rights, limits on automated rejects Up to €20M or 4% of global turnover Title VII + FCRA (US) Candidates hired into the US Non-discriminatory screening; consent + adverse-action steps for background checks Damages, back pay, fines NYC Local Law 144 (US) Automated hiring tools used for NYC roles Annual bias audit + candidate notice $500–$1,500 per violation, per day EU AI Act Recruitment AI touching the EU “High-risk” duties (delayed to Dec 2027, not cancelled) Up to €35M or 7% of global turnover
What Compliance Rules Apply when You Place Candidates in the US or Europe?
When candidates or clients sit abroad, local law travels with them: GDPR in Europe, anti-discrimination law and the FCRA in the US, plus state AI rules like NYC’s bias audit, Illinois’ video-interview consent, and Colorado’s AI Act, which took effect on 30 June 2026.
This part matters only when you work across borders, so keep it light unless you do.
- Europe and the UK: candidates can see or delete their data, you need a lawful reason to hold it, and you cannot reject on a purely automated basis without a human review.
- United States: Title VII and related laws apply to your screening tools, AI included; the FCRA sets the script for background checks.
- US state AI rules: NYC requires a bias audit and notice, Illinois requires consent for AI-analysed video interviews, and Colorado’s AI Act is now in force.
- EU AI Act: recruitment AI is “high-risk,” but the strict duties were pushed to December 2027 in a mid-2026 decision. Coming, not cancelled.
Is It Legal to Use AI to Screen Candidates?
Yes, there is no ban on AI screening in India today. You must use it fairly, tell candidates when AI is involved, keep a human reviewing rejections, and hold a record you can show if a decision’s fairness is questioned.
AI is already the norm, not the exception. In one 2026 survey, 99% of US hiring managers said their company uses AI somewhere in recruitment (Insight Global). Regulators noticed.
Two habits cover most of the risk. Tell candidates when AI is part of the process, in one honest line. And keep a human reviewing anything a machine rejects, with a record of how the decision was made.
How Can a Staffing Company Stay Compliant?
Capture consent at intake, keep only the data you need and delete on schedule, secure it, document your screening logic, disclose AI use, agree data ownership with clients in writing, keep temp-staffing dues current, and give one person clear ownership of compliance.
Here is the whole thing boiled down to a whiteboard list:
- Ask for consent at intake, in plain language, and log it.
- Keep only what you need, set a delete-by date, and honour opt-outs quickly.
- Lock the data down: access controls, encryption, and a check on the vendors who touch it.
- Write down how your screening works, and keep a person reviewing machine rejections.
- Disclose AI use, and keep the audit trail that proves the process was fair.
- Agree in writing with each client who controls the shared candidate data.
- For temp and contract placements, keep licences, PF, and ESI current.
- Give one person ownership of compliance, and train recruiters once a year.
How Does Recruiting Automation Software Help with Compliance?
The right AI recruiting platform builds compliance into daily work: it captures consent at application, applies retention rules automatically, controls who sees what, and logs every AI-assisted decision, so the audit trail exists without anyone remembering to keep it.
Most of this gets easier when it lives in the system recruiters already use, not a spreadsheet someone forgets.
That is the approach we take at Hirin. Consent, retention, access, and audit trails sit inside the AI-powered ATS and the AI screening tools, so staying clean is the default, not a scramble before an audit.
Frequently Asked Questions about Recruitment Compliance
Is recruitment compliance the same as HR compliance?
No, recruitment compliance covers the hiring stage, sourcing, screening, background checks, and offers. HR compliance covers the wider employment relationship, like payroll, leave, and workplace conduct. Agencies live mostly in the recruitment side, plus labour rules for any contract staff they deploy.
Do we need candidate consent to store resumes in India?
As a rule, yes. Under the DPDP Act you should have a clear basis to keep a candidate in your database and an easy way for them to withdraw and be removed. Ask at intake, state how long you will keep the profile, and delete on schedule rather than storing everything forever.
What is the penalty for a data breach under the DPDP Act?
Failing to take reasonable security safeguards can draw a penalty of up to ₹250 crore per instance under the DPDP Act. Other breaches, like ignoring the rules on notice and consent, carry their own lower penalties set by the Data Protection Board.
Does the EU AI Act apply to an Indian recruitment agency?
It can, if your AI tools screen candidates for roles in the EU, the Act’s “high-risk” rules reach you, even from India. The strict obligations were delayed to December 2027, so you have time to prepare, but the exposure is real if you place into Europe.
Who is responsible for compliance, the agency or the client?
Both the staffing agency and client are, but in different roles. The client sets the hiring need, but the agency that collects and processes candidate data carries direct duties over that data. The cleanest fix is a written agreement spelling out who controls the data and who is responsible for what.
See Compliant Hiring in Action
See how Hirin helps with automated consent capture, retention rules, and AI-decision audit trails for you.