AI adoption in hiring has crossed 90% of GCCs.
That speed of adoption is creating operational gaps that many GCCs are still working to close, and data privacy is only one of four risks that expanding AI use is forcing into the open.
The others are bias, candidate experience, and a quieter constraint that most compliance conversations to skip entirely: access economics, the usage of credits, token limits, and license caps that determine whether an AI hiring system can scale.
DPDP sits inside this larger picture. It’s the risk with the clearest legal deadline attached to it, which is why this guide treats it as the anchor.
But the underlying discipline GCCs need, deciding where AI acts, what data it touches, and where a human takes over, is the same discipline that governs all four risks. The report’s own framing of it is direct: agents run execution; humans run decisions.
This guide is based on Taggd’s GCC Report 2026. It is not legal advice.
DPDP compliance depends on your specific data flows, vendor contracts, and entity structure. Consult your legal and data protection counsel before making compliance decisions.
Get the full data: Download the GCC Talent Lab Report 2026 for the complete findings on AI adoption, governance, and hiring risk.
Does the DPDP Act apply to GCC AI hiring?
| Scenario | DPDP implication |
| Processing personal data of Data Principals not within India, under a qualifying contract with a person outside India | Certain provisions are exempt under Section 17(1)(d) |
| Processing Indian candidate or employee data | Applicable DPDP obligations need to be assessed |
| AI hiring tool processes Indian candidate data | The workflow falls within the DPDP framework, and applicable obligations need to be assessed |
| Core operational provisions | Take effect on an 18-month commencement timeline following notification of the 2025 Rules |
When do DPDP obligations take effect on GCCs?
The DPDP Act dates to 2023, but the operational clock started later. The DPDP Rules were notified on 13 November 2025, with several core operational provisions taking effect on 13 May 2027.
Because different provisions have different commencement dates, GCCs should assess the exact timeline applicable to each obligation with legal counsel.
Does the DPDP Outsourcing Exemption Apply to GCC Recruitment?
The DPDP Act provides an exemption, under Section 17(1)(d), for processing personal data of Data Principals who are not within India, where that processing is carried out pursuant to a contract entered into with a person outside India by a person based in India.
GCCs should have their specific contractual and data-flow arrangements reviewed to determine whether this exemption applies to a given hiring workflow.
This exemption does not automatically extend to Indian candidate data. For GCCs processing Indian employee or candidate data, an increasingly common scenario as India operations scale, the applicable DPDP obligations need to be separately assessed.
For GCCs processing Indian candidate data, the applicable DPDP obligations therefore need to be assessed separately. That makes resumes, assessment results, interview recordings and other candidate information important inputs into the organization’s AI-hiring data map.
Where Does AI Hiring Create Candidate Data Exposure?
AI adoption spans nearly the whole hiring funnel: resume screening (69%), JD creation (64%), assessment (56%), sourcing (50%), interview scheduling (36%), and, more cautiously, candidate outreach (21%) and offer rollout (21%).
AI hiring tools that process Indian candidates’ personal data need to be assessed against the applicable DPDP obligations once the relevant provisions take effect, regardless of which stage of the funnel they operate in.

As the DPDP framework takes shape, what data is collected, where it’s stored, and who can access it are converting from open questions into firm compliance obligations.
That’s three separate questions a GCC needs an answer for each AI hiring tool in its stack, not one general compliance posture.
AI Hiring has Four Risks GCCs Need to Govern
DPDP is the sharpest of four risks the report identifies as AI moves deeper into hiring, not a standalone compliance problem.
| Risk | What GCCs need to govern |
| Bias | Where human review enters the AI decision chain, especially at assessment and shortlisting |
| Data privacy | What data AI accesses, where it’s stored, and who can access it |
| Candidate experience | Where automation ends and human interaction begins |
| Access economics | Usage credits, token limits, licenses, and AI capacity planning |
Responsible AI in recruitment and bias become particularly important as AI moves beyond resume screening into assessment and shortlisting.
Pattern-matching algorithms can inadvertently penalize non-traditional career paths, and “cultural fit” risks getting proxied through language patterns no one designed for.
This makes structured, consistently evaluated hiring processes increasingly important alongside AI-enabled screening. See CHRO’s Guide to the Modern Hiring Process for the broader hiring process framework.
The guardrail isn’t turning the model off. It’s deciding where AI acts, what data it can access, and where human judgment takes over, keeping human judgment in the loop at the exact point a shortlist gets finalized, so an algorithmic pattern still gets a human read before the final call.
Data privacy is DPDP’s territory, covered above.
Candidate experience and access economics are covered in their own sections below, since both deserve more than a one-line summary.
Among these four, DPDP carries the clearest legal urgency, because it’s the one with an enforceable deadline attached.
Bias, candidate experience, and access economics are all operational risks a GCC manages continuously. DPDP is a compliance obligation with a fixed commencement timeline.
How Should GCCs Scope AI hiring Tools Safely?
The report’s core recommendation is to partner with talent solutions providers whose AI systems embed data governance and strict security guardrails by design, ensuring the AI agent’s access is safely scoped from day one.
In practice, that’s an architecture and vendor decision, not just a policy one.
Limit AI access to the hiring task. A tool built for resume screening shouldn’t have standing access to full candidate profiles, compensation history, or downstream hiring stages it doesn’t need for its function.
Build data governance into the AI architecture. Retrofitting compliance onto a tool that wasn’t designed with data governance in mind is harder and less reliable than choosing tools built with it from the start.
Evaluate data controls during vendor selection. “Does this vendor’s system embed data governance by design” belong in the same evaluation as accuracy, cost, and integration, not as a follow-up question after the tool is already in production.
Why does human-in-the-loop Governance Still Matters?
GCCs building AI hiring responsibly aren’t choosing between speed and judgment. They’re building systems where AI handles the volume and a human-in-loop, whether recruiter or hiring manager, still owns the decisions that matter.
Agents run execution. Humans run decisions. This is the core principle behind agentic AI in HR: AI handles execution at scale while recruiters and hiring managers retain judgment and decision authority.
AI agents can screen, source, schedule, follow up, and coordinate at scale.
Recruiters and hiring managers retain control over decisions that require context, judgment, and trust.
Data governance fits the same model.
AI access gets scoped to the task it’s performing, while human owners retain control over how candidate data is used.
That’s the same principle showing up twice, once as a bias guardrail, once as a compliance discipline, because it’s the actual operating model this report points GCCs toward, not a separate rule for each risk.
How should GCCs balance AI hiring with candidate experience?
Candidate experience is one of the more subtle risks of AI-led hiring.
AI can improve responsiveness by handling scheduling, follow-ups, and status updates when recruiters aren’t available around the clock.
At the same time, excessive automation in high-stakes moments can weaken the personal engagement that builds trust and commitment.
Candidate perspectives are evolving, and some initial hesitation around AI-led hiring is natural as more job seekers encounter these formats for the first time.
The practical distinction is where human intervention remains essential: let AI manage execution, scheduling, follow-ups, and status updates.
Keep humans in the moments that influence trust and commitment, the offer conversation, negotiation, and close.
How can Access Economics Limit AI Hiring at Scale?
A practical constraint gets less attention than bias or privacy but matters just as much. Enterprise AI tools run on usage credits, token limits, and license caps.
As recruiters lean on AI for sourcing, screening, and market intelligence all at once, demand can quickly outstrip what’s been provisioned.
No amount of guardrail design fixes this; it’s a budgeting and capacity decision GCCs must make deliberately.
To manage these costs, GCCs can work with specialized talent solutions partners that provide fully managed, human-centric AI ecosystems, sharing the infrastructure load while maintaining service delivery.
This is worth naming alongside bias and privacy because a GCC that solves its governance model but runs out of provisioned AI capacity mid-cycle ends up with the same outcome: an inconsistent, under-resourced hiring process.
Why Responsible AI Hiring Matters to India’s GCC Growth?
As AI moves deeper into hiring, responsible deployment is becoming part of the broader GCC value proposition. GCCs that build AI-in-the-loop hiring with human judgment intact are demonstrating that sophisticated AI systems can be operated responsibly and at scale.
That matters as India’s GCC ecosystem moves beyond execution-led work toward increasingly complex global mandates. Data governance, human oversight, and responsible AI use aren’t only operational considerations within recruitment.
They’re part of the capabilities GCCs are building for the next stage of their global role.
DPDP compliance checklist for GCC HR and TA teams
- Map your AI hiring tools against the exemption. For each tool, assess whether it processes foreign candidate data under a qualifying contract that falls under Section 17(1)(d), or Indian candidate/employee data that requires a fuller DPDP obligations assessment.
- Ask vendors directly about data governance architecture. Where is data stored, who can access it, and is access scoped to the specific hiring task, not the full candidate record.
- Confirm the exact commencement dates with legal counsel. Different provisions phase in on different schedules under the 2025 Rules; don’t treat the framework as a single fixed deadline.
- Apply the same scoping discipline to bias and access economics, not just privacy. Where does human review enter the decision chain, and is AI capacity provisioned for actual demand, not just pilot-stage usage.
- Loop in legal and data protection counsel before selecting or renewing AI hiring vendors. This guide describes the compliance landscape the report identifies; it doesn’t replace a legal review of your specific contracts and data flows.
FAQs
When does the DPDP Act become applicable to AI hiring in India?
The DPDP Rules were notified in November 2025, with core operational provisions phasing in over an 18-month commencement schedule. Different provisions take effect on different dates under the Rules, so GCCs should confirm the exact applicable timeline with legal counsel rather than treating it as one fixed date.
Does the DPDP outsourcing exemption apply to GCC recruitment?
Section 17(1)(d) exempts processing of personal data belonging to Data Principals not within India, where that processing happens under a contract with a person outside India. This can apply to some foreign-candidate hiring workflows, but it does not automatically cover Indian candidate or employee data, and each arrangement needs its own review.
Are AI hiring tools like resume screeners covered by the DPDP Act?
AI hiring tools that process Indian candidates’ personal data, including resume screening, assessment, and sourcing tools, need to be assessed against applicable DPDP obligations once the relevant provisions take effect, regardless of which stage of the hiring funnel they operate in.
Is data privacy the only risk in AI hiring?
No. The report identifies four: bias, data privacy, candidate experience, and access economics. DPDP compliance addresses the data privacy risk specifically, but bias and access economics require separate governance decisions, and candidate experience requires a separate line between automated and human-led interactions.
What does “agents run execution, humans run decisions” mean in AI hiring?
It’s the governance principle this report points GCCs toward: AI handles high-volume tasks like screening, sourcing, and scheduling, while a human, recruiter or hiring manager, retains control over decisions that require judgment, context, or trust, including where a shortlist gets finalized and how candidate data is accessed.
For the complete findings on AI adoption, governance, and hiring risk across India’s GCC ecosystem: Download the GCC Talent Lab Report 2026