DPDP Act 2023 for Healthcare Employers — What Candidate Data Rules Actually Require
The DPDP Act 2023 fundamentally changed what healthcare employers can do with candidate data. Most Indian hospitals collecting candidate data in 2026 are non-compliant in ways that carry regulatory and reputational risk. This article breaks down what the Act requires from healthcare recruiters and how DPDP-native architecture actually works.
No pitch. Written root-cause diagnosis. AI-powered, healthcare only.
Direct answer
The DPDP Act 2023 fundamentally changed what healthcare employers can do with candidate data. Most Indian hospitals collecting candidate data in 2026 are non-compliant in ways that carry regulatory and reputational risk. This article breaks down what the Act requires from healthc...
TL;DR
The Digital Personal Data Protection Act 2023 (DPDP Act) fundamentally changed what healthcare employers can and cannot do with candidate data. And yet, the majority of Indian hospitals and clinics collecting candidate data in 2026 are non-compliant in ways that carry both regulatory risk and reputational risk. This article breaks down what the DPDP Act requires specifically from healthcare recruiters, what the compliance workflow looks like in practice, and how ICG Workforce Solutions operates under DPDP-native architecture.
What the DPDP Act 2023 requires from healthcare employers
The core DPDP obligations that apply to any healthcare organisation collecting candidate personal data:
- Consent — Explicit, informed, and specific consent must be obtained before collecting personal data. Blanket "we collect your data" statements do not qualify.
- Purpose limitation — Data collected for one purpose (e.g. hiring evaluation) cannot be reused for another purpose (e.g. marketing communications) without additional consent.
- Data minimisation — Only collect data that is genuinely necessary for the stated purpose.
- Retention periods — Data cannot be retained indefinitely. Reasonable retention periods must be defined and enforced.
- Data subject rights — Candidates have the right to access, correct, and delete their personal data.
- Third-party sharing — Sharing candidate data with third parties (background verification services, TPAs, insurers, recruitment agencies) requires specific consent.
- Data breach notification — Breaches affecting personal data must be reported to the Data Protection Board and affected individuals.
- Grievance redressal — Data subjects must have a documented mechanism to raise concerns.
What consent looks like in the recruitment context
Compliant consent for healthcare recruitment has these characteristics:
- Specific — states what data is being collected (name, contact, qualifications, current CTC, expected CTC, employment history, health information if relevant)
- Purpose-bounded — states what the data will be used for (evaluation for this specific role, or for future roles matching the candidate's stated preferences)
- Third-party disclosure — names the third parties who may receive data (background verification services, insurance TPAs where relevant, recruitment agencies)
- Retention specified — states how long data will be retained if the candidate is not hired
- Rights disclosure — informs the candidate of their right to access, correct, and delete their data
- Timestamped — captured with date, time, and IP address of consent event
A signed application form saying "I consent to collection and processing of my data" is NOT compliant on its own. The consent must be specific to the above dimensions.
Retention periods — how long can healthcare employers keep candidate data
The DPDP Act does not specify exact retention periods. Reasonable industry practice for healthcare recruitment:
- Successful hires — data retained as part of employee records (subject to employment record retention requirements, typically 7-10 years post-separation)
- Unsuccessful candidates (interviewed, not hired) — 24 months from last contact for future role matching, then deletion
- Rejected at screening stage — 12 months
- Background verification data — as short as practically possible; typically 30 days post-hiring decision
Facilities that operate manual paper-based candidate files often fail retention compliance because they never delete anything. Digital data management with automated retention rules resolves this.
Third-party sharing — the most common compliance gap
The most common DPDP compliance gap in healthcare recruitment is unauthorised sharing with third parties. Specific problem areas:
- Background verification services — sharing candidate data with BGV firms requires specific consent naming the BGV firm and the data being shared. Blanket "we may verify your background" statements are insufficient.
- Recruitment agencies — if a hospital shares a candidate's profile with a recruitment agency, this is third-party sharing requiring consent.
- Reference checks — contacting the candidate's previous employers for reference checks requires disclosure that this will happen and consent to it.
- Insurance TPAs — where recruitment involves insurance panel evaluation, sharing candidate data with TPAs requires consent.
Candidate rights — what employers must honour
Under DPDP, candidates have specific rights that healthcare employers must honour:
- Right to access — the candidate can request a copy of all personal data the employer holds about them. Employers must respond within reasonable time (industry norm: 30 days).
- Right to correct — the candidate can request corrections to inaccurate data.
- Right to delete — the candidate can request deletion of their personal data. Employers must comply unless there is a specific legal or contractual reason to retain (e.g. active application, employment record).
- Right to withdraw consent — a candidate can withdraw consent at any time. Once consent is withdrawn, further processing (including retention beyond legally-required periods) must stop.
- Right to grievance redressal — the candidate must have a documented mechanism to raise DPDP concerns with the employer.
Penalties for non-compliance
The DPDP Act 2023 provides for significant financial penalties for non-compliance:
- Data breach without adequate safeguards — up to ₹250 crore
- Failure to notify data breach — up to ₹200 crore
- Failure to comply with data subject rights — up to ₹200 crore
- Failure to fulfil consent requirements — up to ₹150 crore
These are maximum penalties and would apply for large-scale enforcement cases. Smaller enforcement actions are more common. But the reputational risk for healthcare organisations from any DPDP enforcement action is disproportionate to the immediate financial penalty.
How ICG Workforce operates under DPDP-native architecture
ICG Workforce Solutions was designed from day 1 with DPDP-native architecture:
- Explicit, specific, timestamped consent captured at every touchpoint (candidate registration, resume upload, profile sharing with employers)
- Purpose limitation enforced — candidate data collected for matching is not used for marketing without additional consent
- Retention rules automated in the database — profiles inactive for 24 months trigger automated deletion review
- Third-party sharing (background verification, employer profile sharing) requires additional consent captured at the moment of sharing
- Candidate data access, correction, and deletion requests handled through documented workflows with SLA
- Data breach detection and notification procedures documented
- Grievance redressal mechanism published on the workforce site
For healthcare employers, engaging ICG Workforce for recruitment offloads a significant portion of DPDP compliance burden — because the candidate side data is managed under ICG's DPDP-native architecture, and only the employer-side data (job requirements, screening notes) needs to be managed under the employer's own DPDP framework.
Related reading
Book a free 30-minute Brand & Growth Diagnostic.
It's a working session, not a sales pitch — you leave with a written root-cause analysis you can act on, whether or not you engage ICG.
Questions readers ask
about this topic.
The three platforms
behind every ICG engagement.
Beacon
CAPI middleware that fixes Event Match Quality, translates CRM statuses to Meta-standard events, dedups across channels.
Agency OS
Live client dashboard. GSC, GA4, Google Ads, Meta Ads, IVR calls in one view. Login anytime, not monthly.
Phoenix
Clinic revenue intelligence over your PMS. Daily action queue: Prevent Loss, Maintain & Engage, Grow Revenue. 46-centre rollout.
Or book a free 30-min audit to see all three in action on your account.
Healthcare brands
that already run on ICG.
A representative slice of the 150+ healthcare brands ICG has delivered for across India. Most engagements remain under NDA.
What ICG clients say · on video.
"Scale up of organic channels and business consulting. ICG has absolute domain authority in their field."
"Working with ICG transformed how we acquire IVF patients in Gurgaon. They understand the fertility journey from inquiry to consult..."
"What Ichelon accomplished — they got all my ideas and worked over 3-4 months to create an amazing, super-customised website."
Need help operationalising this?
Every ICG service is healthcare-only, NMC + DPDP-aware, and built around the patient-research patterns that drive Indian healthcare growth in 2026.
More from
ICG.
Healthcare AIO is the discipline of getting your clinic or hospital cited inside Google AI Overviews, ChatGPT and Perplexity answers — not j...
Conversational-search advertising places brand messages inside AI chat answers — ChatGPT, Perplexity, Copilot — rather than beside a results...
NABH digital compliance means every claim, image and testimonial your hospital publishes online matches what an accreditation surveyor can v...
Stop guessing.
Book a Diagnostic.
30 minutes. Free. With the AI-powered healthcare-only marketing agency 150+ brands already run on. No slides, no pitch, no hard close.