Data Protection & DPDP Act Compliance
How KaaryaSatya Verify — operated by Prathibha's Make My Designz LLP ("PriveSecure") — processes personal data, and how that practice maps to India's Digital Personal Data Protection Act, 2023.
Last updated: 29 September 2026. This page describes PriveSecure's own data protection practice and is not itself a contract; where a signed services agreement between PriveSecure and a customer addresses the same subject matter, that agreement governs as between the parties. For the general policy covering all users of the Service, see the Privacy & Security Policy — this page goes further, mapping that same practice against the specific provisions of the DPDP Act for customers who need that level of detail.
Where the DPDP Act stands today
The Digital Personal Data Protection Act, 2023 ("DPDP Act" or "the Act") received Presidential assent in August 2023. The Digital Personal Data Protection Rules, 2025 ("the Rules") were notified in November 2025, together with the establishment of the Data Protection Board of India. Commencement of the Act and Rules is staggered across three dates, not a single go-live:
| Date | What comes into force |
|---|---|
| 13–14 November 2025 | The Act's foundational and definitional provisions, and establishment and functioning of the Data Protection Board of India. No substantive obligations on data fiduciaries — notice, consent, breach reporting, data-principal-rights handling — are yet legally mandated by this stage. |
| 14 November 2026 | Registration of Consent Managers under the Act (Section 6(9)) and the Board's related powers. Still no operative obligation on data fiduciaries generally. |
| 14 May 2027 | The Act's core operative provisions come into force: notice and consent requirements (Sections 5–6), data fiduciary obligations (Sections 7–8), data principal rights (Sections 11–14), children's-data provisions (Section 9), breach notification, cross-border transfer rules, and the associated penalty provisions, alongside the corresponding Rules governing notice content, security safeguards, retention and erasure, and breach intimation. |
PriveSecure has not waited for 14 May 2027. Every practice described on this page — a hard-enforced consent gate, itemised notice, data masking by default, and a defined process for exercising data-principal rights — is already built into KaaryaSatya Verify and in active use today, ahead of the Act's mandatory commencement date. This page describes that present-day practice, mapped against the Act's actual provisions, rather than claiming a compliance status the law itself does not yet require or a certification scheme that does not exist for this Act.
Roles: who is the Data Fiduciary
In KaaryaSatya Verify's standard operating model, the recruiting organisation using the Service (the "Customer") determines why a candidate's data is being processed — screening that named candidate for a specific hiring decision — and is the Data Fiduciary in respect of that candidate's personal data, consistent with Section 2(i) of the Act. PriveSecure processes personal data solely on the Customer's documented instructions, for the purpose of providing the Service, and does not process it for any independent purpose of its own.
Where a candidate registers directly with KaaryaSatya Verify — for example through a recruiting organisation's shareable self-service link, before formal association with a specific engagement is complete — PriveSecure holds that data as steward pending consent and association with a Customer, and does not use it for any purpose beyond enabling that association and the screening it is submitted for.
Notice & consent
No verification check is submitted or processed by KaaryaSatya Verify without a recorded, valid consent from the candidate. This is enforced in the Service itself, not only as a written policy — a verification request against a candidate with no granted consent record is rejected by the system.
Consent is captured under one of two modes, consistent with the itemised-notice principle in Section 5 and the consent standard in Section 6 (specific, informed, unconditional, and capable of being as easily withdrawn as given):
- Customer-captured consent — the recruiting organisation has already obtained the candidate's consent through its own hiring process and supplies a reference (a unique identifier, timestamp, and the version of the consent text shown) with each submission.
- PriveSecure-captured consent — KaaryaSatya Verify sends the candidate a plain-language, itemised request identifying the data source, the purpose, and the retention period, confirmed by a one-time code or a typed confirmation. Declines and non-responses are recorded and are not processed further.
The notice presented to a candidate states, in plain language: what is being collected, why, which sources are checked, how long the data is intended to be kept, and how to withdraw consent. Re-verification of a previously-checked individual requires a fresh consent — an old consent is not reused for a new check.
Data we process
To be specific rather than general: the personal data categories KaaryaSatya Verify processes are —
- Name, postal address, phone number, and email address, as declared by or on behalf of the candidate.
- Aadhaar number — masked by default; see the Security safeguards section below for exactly what is and is not stored.
- Universal Account Number (UAN), where supplied, used to cross-check employment history against EPFO-linked records.
- The content of an uploaded resume or supporting document, and the structured employment/education details extracted from it (employer names, dates, institutions).
- Verification results — the outcome and supporting detail of each identity and employment check performed.
- Consent records — mode, status, timestamp, and (where applicable) the evidence file attached to a consent.
- Where identity verification is completed through a DigiLocker-based flow, the confirmation data returned by that flow (a verified name and a masked Aadhaar reference) — the raw Aadhaar number is never handled by PriveSecure in that path; see below.
This is a working set of data, not an incidental one — the resume content and extracted history are what the Service is verifying, and are retained as part of providing that function, subject to the retention practice described further down this page.
Purpose limitation & data minimisation
Data collected through KaaryaSatya Verify is used only for the pre-employment screening purpose it was submitted for, consistent with Section 5's purpose-limitation principle. The clearest concrete example of minimisation-by-design in the Service is Aadhaar handling:
- If an Aadhaar number is entered directly (by a recruiting organisation, on a candidate's behalf), it is masked immediately on receipt — only the last four digits and a one-way cryptographic hash are ever written to the database. The full number is processed only transiently, for the single request in which it was submitted, and is not persisted anywhere.
- Where identity verification instead runs through a DigiLocker-based flow, the candidate authenticates directly with that government-linked system, and PriveSecure never receives or handles the raw Aadhaar number at all — only a verified, masked confirmation is returned to the Service.
Where a customer's engagement calls for a lighter-weight check, KaaryaSatya Verify's plan tiers gate how much detail is even generated or shown — a lower tier produces a verdict without the richer explanatory detail a higher tier includes, rather than collecting the same data and simply hiding it.
Security safeguards
Consistent with the "reasonable security safeguards" obligation in Section 8(5), the following are in place in KaaryaSatya Verify today:
- Mandatory multi-factor authentication. Every account — candidate, recruiting-organisation, and administrator alike — must complete TOTP-based two-factor authentication before it can be used. There is no bypass for any role.
- Encryption in transit. All traffic to and from the Service is carried over HTTPS; plain HTTP requests are rejected and redirected.
- Encryption at rest. Data at rest is encrypted by the managed database platform as a standard, always-on feature.
- Aadhaar masking by default, as described above.
- Application-level tenant isolation, so one recruiting organisation cannot see another's candidates, enforced on every request, with database-level access restrictions enabled as an additional defensive layer.
- Role-based access, so a candidate sees only their own record, a recruiting organisation sees only its own candidates, and administrative access is provisioned through a controlled internal process rather than public sign-up.
PriveSecure maintains a written information security programme describing these and related controls in more detail, available to customers on request.
Your rights as a Data Principal
Ahead of the Act's own commencement of Sections 11–14, KaaryaSatya Verify already supports the substance of these rights for any candidate whose data it holds:
- Right to access information — a summary of what personal data is held and how it has been processed.
- Right to correction and updating — inaccurate or outdated personal data can be corrected on request.
- Right to erasure — a candidate may request deletion of their personal data where it is no longer necessary for the purpose it was collected for, subject to any legal or contractual retention requirement that overrides the request (for example, a record a recruiting organisation is separately required to keep).
- Right to withdraw consent — at any time, which stops any further check from running on that data; withdrawal does not undo a check already completed.
- Right to grievance redressal — see Contact, below, for how to raise one, and the Data Protection Board section for escalation once that avenue is operative.
- Right to nominate — a candidate may nominate another individual to exercise these rights on their behalf in the event of death or incapacity.
PriveSecure aims to acknowledge a rights request within 5 business days and resolve it within 30 days, sooner where practicable. Where a request concerns a check performed for a specific recruiting organisation, PriveSecure may need to confirm the request with that organisation, as the Data Fiduciary responsible for the underlying hiring decision, before acting on it.
Retention & erasure
PriveSecure's stated retention target is 180 days after a candidate's verification is completed, or immediate deletion on withdrawal of consent, whichever is earlier — communicated to every candidate as part of the notice they are shown before consenting. A recruiting organisation may request a different retention period for its own engagement, and PriveSecure will act on that instruction.
In progress Automated enforcement of this target is being built. Today, a retention or deletion request is fulfilled directly by PriveSecure on receipt rather than by a fully automated schedule. Being transparent about that distinction matters more to PriveSecure than describing a more finished-sounding system than currently exists — the commitment and the process for acting on a request are real; the automation of the 180-day clock itself is a near-term build item, not yet complete as of the date at the top of this page.
Breach notification
If PriveSecure becomes aware of a confirmed personal data breach affecting data processed through KaaryaSatya Verify, it will notify affected recruiting-organisation customers without undue delay, and in any event within 72 hours of becoming aware of the confirmed incident, together with the information reasonably available at that time to help the customer meet its own notification obligations. This is the same standard PriveSecure has committed to in its customer agreements, offered here as a general practice rather than a promise limited to any one customer. PriveSecure maintains a written security incident response plan describing the containment, assessment, notification, and remediation steps this triggers internally.
Cross-border processing
Section 16 of the Act takes a permissive approach to cross-border transfer: personal data may be transferred outside India except to a country the Central Government specifically restricts by notification. No such restriction currently applies to the jurisdictions in which PriveSecure's infrastructure providers operate.
In progress Being direct about current state: KaaryaSatya Verify's application layer runs today on cloud infrastructure located outside India, while PriveSecure works toward hosting every component of the Service within India, consistent with the data-localisation commitments it makes to individual customers. This page will be updated once that work is complete. In the interim, all data in transit is encrypted, and the safeguards described above apply regardless of the infrastructure's physical location.
Sub-processors we engage
PriveSecure engages licensed third-party providers to perform identity verification (through a DigiLocker-based aggregator) and employment verification (through an EPFO/UAN-linked aggregator), and a managed cloud database, application-hosting, and content-delivery provider to operate the Service itself. PriveSecure remains responsible for the acts and omissions of these providers in connection with the Service, does not use candidate data for any purpose outside providing the Service, and does not use it to train generalised models (see "How AI is used in the Service," below). A current list of named sub-processors is available to customers on request.
How AI is used in the Service
KaaryaSatya Verify's identity and employment verdicts — Green/Amber/Red/Grey and the score behind them — are produced by deterministic, rules-based logic against the data returned by licensed verification providers. That scoring is not a trained machine-learning model, and is not influenced by any AI system.
A large-language-model API (Anthropic's Claude, via its commercial API) is used only to assist parsing resumes into structured fields when deterministic extraction alone is insufficient — for example, recognising an unusually formatted employment section. Anthropic's commercial API terms state that customer inputs and outputs submitted through the API are not used to train Anthropic's models, by default and not subject to an opt-in or opt-out toggle — see Anthropic's own statement on this. Separately, PriveSecure's own policy is not to use candidate data for training any model, generalised or otherwise, for any purpose beyond providing the Service.
Children's data
KaaryaSatya Verify is designed for pre-employment screening of adult job candidates and is not directed at, marketed to, or intended for use by children. PriveSecure does not knowingly process the personal data of a child through the Service. If PriveSecure becomes aware that it has done so, it will delete that data promptly.
Significant Data Fiduciary status
The Act allows the Central Government to notify certain data fiduciaries as "Significant Data Fiduciaries" (Section 10), triggering additional obligations — appointment of a Data Protection Officer based in India, an independent data auditor, and periodic data protection impact assessments. PriveSecure has not been notified as a Significant Data Fiduciary. Should that designation apply in future, PriveSecure will implement the obligations that follow from it.
Data Protection Board & grievance escalation
The Data Protection Board of India has been established and is operational for its constituted functions as of the commencement dates described above. Once the Board's complaint-handling functions relevant to individual grievances are fully operative, a candidate who is not satisfied with PriveSecure's response to a rights request under this page will be able to escalate to the Board. Until then, the contact route below is the direct path for raising and resolving a request.
Exercising your rights / contact us
To exercise any of the rights described above, request a copy of PriveSecure's information security programme or sub-processor list, or raise any other data-protection question, contact:
privacy@privesecure.com
Please include enough detail to identify the record in question (for example, the name and phone or email number used when the check was submitted, and the recruiting organisation involved, if known).
Changes to this page
This page is reviewed at least annually, and whenever a material change is made to how KaaryaSatya Verify processes personal data or to the applicable law. The date at the top of this page reflects the last review.
This page describes PriveSecure's data protection practice in good faith and is not a substitute for independent legal advice. A recruiting organisation evaluating KaaryaSatya Verify for its own compliance purposes should have its own counsel review this page and the applicable services agreement.
