Compliance
DPDP-compliant AI hiring in India: what actually changes in your process
Last updated Reviewed by Hab Business Solutions
India's Digital Personal Data Protection Act turns candidate data into regulated personal data. Most AI screening tools were designed before that mattered. Here is what compliance requires in practice, and how a hiring decision system is built to survive an audit.
Short answer
What does DPDP compliance require from an AI hiring tool?
Personal data does not stop being personal because an AI read it
The common misreading of the DPDP Act is that it governs storage. It governs processing, and running a resume through a model is processing. The moment an AI ranks a candidate, you have made an automated evaluation of a person using their personal data, and you need to be able to say why.
This is where most AI screening tools become a liability rather than an asset. A tool that returns a single opaque percentage cannot tell you why a candidate scored 61 rather than 74. If a candidate asks, and under DPDP they may, you have no answer, and neither does your vendor.
CandidRanker was built the other way round. Every score decomposes into eight named dimensions: skills, tools, experience, education, certifications, projects, title similarity and semantic similarity. Each dimension opens into the evidence behind it, including why a dimension scored zero. That is not a reporting feature bolted on afterwards; it is the reason the ranking is defensible.
Determinism is a compliance property, not a technical detail
If the same resume against the same job description produces a different score on Tuesday than it did on Monday, you cannot defend either result. Non-determinism is fine in a chat assistant and disqualifying in a hiring decision.
CandidRanker produces the same score for the same inputs on every run. That single property is what makes the audit trail meaningful. A recorded decision from three months ago can be reproduced today, which is exactly what a regulator or a tribunal will ask for.
The human in the loop is the control, not the courtesy
Hab Business Solutions develops the systems with governance, including a human in the loop, always. In hiring that has a precise meaning: the system ranks and explains, and a person on your team decides. No candidate is ever auto-rejected.
Every decision carries four explicit states: shortlist, select, reject and clear. Each one records who made it and why. When someone asks how a shortlist was produced, the answer is a document, not a recollection.
The same pattern applies outside hiring. When Hab implements document processing or an approvals workflow, AI handles the routine volume and humans handle exceptions and sign-off, with the same audit trail underneath.
Where the data lives
Customer data for MinMaxHR and CandidRanker is stored and processed in India, on Google Cloud asia-south1. Uploads are malware-scanned before entering the pipeline, workspaces are isolated with row-level security, API keys are held as SHA-256 hashes rather than recoverable secrets, and support access is explicit, read-only unless otherwise granted, and expires within 24 hours.
Residency alone is not compliance, but it removes one of the harder questions from your DPIA, and it is the first thing a procurement team asks about.
Frequently asked
Does DPDP prohibit AI screening entirely?
No. It requires a lawful basis, a stated purpose, and the ability to explain and contest automated evaluations. AI screening that ranks and explains, with a human making the decision, fits comfortably inside that. Screening that silently rejects people does not.
Do we need candidate consent to run resumes through CandidRanker?
You need consent and a stated purpose for processing candidate data, which most organisations already collect at application. What changes is that the purpose has to cover automated evaluation, and the candidate has to be able to get a meaningful answer about the outcome.
What happens to a candidate who scores badly?
Nothing automatic. The system ranks and attaches evidence; a named person on your team decides, records the decision and the reason, and that record is retained. There is no configuration in which the software rejects a candidate on its own.
Can Hab implement this alongside our existing ATS?
Yes, and that is the normal case. MinMaxHR is a decision layer that sits next to an applicant tracking system rather than replacing it. Hab Business Solutions handles the integration, the training and the governance documentation as part of the implementation.
Want this running on your next role?
Bring one job description and its applicants. You will see the ranked pool and the evidence behind it before the call ends.
No retainers to start · Pilot-first · Human-in-the-loop governance
