Naukri.com, one of India’s biggest job portals, is facing fresh questions after an undercover investigation claimed that its recruiter subscription can be used to access and download the personal information of job seekers for purposes other than hiring.
The allegations have started a wider discussion about data privacy, user consent, and how recruitment platforms protect the information of millions of professionals. The issue has also gained attention because India is preparing to fully enforce the Digital Personal Data Protection (DPDP) Rules in 2027.
At the same time, Naukri’s parent company, Info Edge, continues to report strong business growth and is investing heavily in artificial intelligence (AI). However, the latest claims have put its data protection practices under the spotlight.
Entrackr Investigation Claims Recruiter Access Was Used to View Candidate Data
According to an undercover investigation by Entrackr, one of its journalists contacted a Naukri sales executive while pretending to be a customer. During the conversation, the journalist clearly said that the goal was to get contact details of CXOs and senior professionals, not to hire employees.
Despite this, the report claims that the sales executive continued with a live demo. Within a few minutes, profiles of senior employees working at companies like Zomato and OYO were shown. The journalist was reportedly able to see details such as phone numbers, salary information, and complete resumes.
The investigation also claimed that the sales executive suggested removing certain search filters so that more candidate profiles could be accessed.
According to the report, recruiter plans start from around Rs 2,500 for one month or Rs 9,000 for six months, allowing users to view a limited number of resumes. Larger enterprise plans offer thousands of profile credits for bigger companies.
The report further alleged that downloaded resumes can be exported into Excel files, making it difficult for the platform to control how that information is used later.
Entrackr also claimed that some companies outside the hiring industry, including telecom firms, used-car businesses, and real estate companies, purchase recruiter subscriptions mainly to collect verified contact details of potential customers instead of recruiting employees.
The investigation further alleged that the sales executive admitted that part of his salary depended on meeting sales targets. The report also claimed he suggested telling candidates that their contact details came through a “referral” if they ever asked how the information was obtained.
Info Edge Rejects Allegations and Explains Its Safety Measures
Info Edge, the parent company of Naukri.com, has denied that it allows the sale or misuse of candidate data for non-recruitment purposes.
The company said that recruiter subscriptions are meant only for hiring. Every customer must accept Naukri’s Terms and Conditions and Privacy Policy, which clearly ban data resale, automated scraping, and marketing activities unrelated to recruitment.
Info Edge also said that recruiter plans have fixed usage limits to prevent large-scale data collection.
The company added that every paid recruiter account goes through Know Your Customer (KYC) verification. The level of verification depends on the size of the customer and the type of subscription. According to Info Edge, simple verification is important because many small businesses and startups across India also use Naukri to hire employees.
To improve security, Naukri has introduced another protection feature. If the system detects bulk resume downloads or unusual activity, users must enter a six-digit authorisation code sent to their registered email and mobile number before they can continue.
The company also said it refuses customers if it becomes clear that they want access for reasons other than recruitment. It added that accounts found breaking its policies can be suspended or permanently blocked.
New DPDP Rules Could Make Data Protection Even More Important
The controversy comes at a time when India is preparing to fully implement the Digital Personal Data Protection (DPDP) Rules from May 13, 2027.
The new law will give people more control over their personal information and place stricter responsibilities on companies that collect and process user data. Businesses could face penalties of up to Rs 250 crore for failing to protect personal data or for not reporting major data breaches.
Unlike the European Union’s GDPR, India’s DPDP law generally requires companies to obtain clear consent before using personal data for commercial purposes such as marketing. Users will also have the right to access their data, correct mistakes, withdraw consent, and request deletion of information once it is no longer needed.
At the same time, the Telecom Regulatory Authority of India (TRAI) is introducing stronger rules to reduce spam calls and promotional messages through improved consent management systems.
Cybersecurity experts also recommend a method called database seeding or “honey tokens.” This involves adding fake but traceable records to databases. If someone contacts those fake records, companies can quickly identify that their database has been leaked or misused.
Despite the controversy, Info Edge remains one of India’s leading internet companies. The company recently reported strong financial results, supported by steady growth in its recruitment business and gains from startup investments. It is also expanding its AI products and has increased its presence in the education technology sector after acquiring a major stake in Coding Ninjas.
As India moves towards stricter data privacy rules, the debate around recruiter access and the protection of candidate information is likely to continue. The issue has also raised a larger question about how recruitment platforms can balance easy hiring with the responsibility of keeping users’ personal data safe.
