A background-verification control covering scope, candidate notice, source, accuracy, criminal and employment checks, vendor contracts, adverse findings and retention.
Background verification should confirm role-relevant facts, not become an unlimited investigation into a candidate’s private life.
The DPDP framework is phased. The 14 November 2025 commencement notification brought specified institutional and enabling provisions into force immediately; Consent Manager-related provisions follow after one year; most operating duties and Rules follow eighteen months after Gazette publication. As of 22 June 2026, the control should distinguish current obligations from future-state DPDP readiness.
Employment-related legitimate use under the Act must be applied according to commencement and purpose; unnecessary processing is not justified merely because the person is a candidate.
Verification should be proportionate to role risk and permitted sources.
Vendors may introduce sub-processors, cross-border researchers and public-source scraping that the employer should understand.
| Check | What to examine |
|---|---|
| Role risk | Financial authority, safety, regulated access or ordinary role. |
| Check | Identity, education, employment, reference or criminal record. |
| Source | Candidate, institution, official database or public source. |
| Accuracy | Name matching, jurisdiction and disputed result. |
| Retention | Hiring decision, employment, dispute and vendor deletion. |
A common-name candidate is matched to an unrelated court record. The employer should pause the decision, verify identifiers and allow correction rather than treat the vendor score as final.
Create role-based check packages instead of ordering every check for every applicant.
Require vendors to provide source, confidence, correction process and deletion evidence.
Identify the people, data, systems, purpose, owner, processor, user journey and failure scenario. Review role risk, check and source together. A policy statement or vendor assurance cannot replace evidence of how the live product behaves.
Apply the 14 November 2025 commencement notification provision by provision. Continue complying with currently operative CERT-In, banking, telecom, insurance, employment, consumer, contract and criminal-law requirements. Build the scheduled DPDP workflow now, but do not describe a future provision as already enforceable.
Run the workflow in the live or controlled test environment. Preserve screenshots, approvals, logs, vendor responses, user communications, exceptions and remediation. Assign a named owner and completion date to every failed control so management can distinguish an operating safeguard from a policy intention.
Privacy and cyber maturity are visible in operating behaviour: what the organisation collects, who can use it, how vendors are controlled, how users exercise choices, how incidents are handled and whether evidence survives scrutiny.
Use the current official instrument, portal or regulator publication before acting. This panel separates the category authority from page-specific references.