Compliance Memorandum
TO: Surya Mettupalli, Founder
FROM: Legal Department
DATE: December 5, 2025
RE: Global Legal Compliance Framework for PraxJobs AI Platform Operations (India, EU, US-California, and other key jurisdictions)
EXECUTIVE SUMMARY
This memorandum outlines the key legal compliance requirements and recommendations for PraxJobs' AI-powered job search platform operations globally. The analysis covers India-specific rules (Digital Personal Data Protection Act, 2023; Information Technology Act, 2000 and allied rules), EU/EEA and UK data protection (GDPR/UK GDPR), US privacy and consumer protection (including California CCPA/CPRA), and other major frameworks (Brazil LGPD, Canada PIPEDA, Singapore PDPA, Australia Privacy Act). It also addresses cross-border data transfers, AI governance and transparency, employment and non-discrimination, consumer protection and advertising, subscription billing, intellectual property and intermediary obligations (e.g., EU Digital Services Act; US DMCA), and security/breach response requirements.
I. DATA PROTECTION AND PRIVACY COMPLIANCE
A. Personal Information Processing
User Data Categories: Resume content, career history, contact information, job preferences, interview recordings, LinkedIn profile data
Lawful Basis and Notices by Region:
- India (DPDP Act, 2023): Obtain and document valid, informed consent; make withdrawal as easy as giving consent. Provide clear notices describing purposes, categories of personal data, user rights, grievance redressal details, and DPO contact (if appointed). Collect only data necessary for stated purposes.
- EU/UK (GDPR/UK GDPR): Identify and document appropriate lawful bases (e.g., performance of contract for core service delivery, consent for optional features/marketing, legitimate interests subject to balancing test). Address special category data (e.g., biometric/voice data from interview recordings) with an Article 9 condition if processed. Provide Article 13/14 notices, maintain Records of Processing (Art. 30), and apply data minimization and purpose limitation.
- US-California (CCPA/CPRA): Provide “notice at collection” (categories, purposes, retention), disclose whether data is “sold” or “shared,” offer a “Do Not Sell or Share My Personal Information” control and honor Global Privacy Control (GPC) signals, and provide a “Limit the Use of My Sensitive Personal Information” control where applicable. Use compliant Service Provider/Contractor agreements with purpose, retention, and prohibition on cross-use clauses.
- Other Key Regimes (high level): Brazil (LGPD) lawful bases (consent, contract, legitimate interest), transparency and DPO (“DPO/Encarregado”) where appointed; Canada (PIPEDA) consent and reasonableness, accuracy and access; Singapore (PDPA) consent, deemed consent, and legitimate interests with assessment; Australia (Privacy Act/APPs) collection, use, disclosure and APP privacy policy requirements.
Children’s Data (Global):
- The service targets adults, but implement age-gating and safeguards.
- India: treat under 18 as children and obtain verifiable parental consent before processing; avoid tracking/targeted ads to children.
- EU/UK: obtain verifiable parental consent for information society services directed at children where Member State/UK age of digital consent applies (13–16).
- US: avoid knowingly collecting data from children under 13 without verifiable parental consent (COPPA); for CPRA, obtain opt-in consent for sale/share of data of users under 16.
Retention and Deletion: Define and publish retention schedules by data category consistent with purpose limitation and storage minimization (GDPR/UK GDPR), DPDP Act requirements, and CPRA “retention disclosure” expectations. Delete or anonymize upon purpose completion or consent withdrawal, subject to legal holds and statutory retention.
B. Cross-Border Data Transfers
- India (DPDP/IT Act): Treat PraxJobs as a “Data Fiduciary” for Indian users. Cross-border transfers generally permitted except to countries restricted by Central Government notification. Use contractual safeguards with processors/sub-processors and conduct risk assessments. No general localization under DPDP; comply with sectoral localization (e.g., RBI payment data). Maintain logs for at least 180 days and ensure availability in India per CERT-In Directions, 2022.
- EU/EEA, UK, and Switzerland: Use an appropriate transfer mechanism for personal data exported to third countries: adequacy decisions (including EU–US Data Privacy Framework and UK/Swiss extensions where applicable), EU Standard Contractual Clauses (SCCs) with Transfer Impact Assessments and supplementary measures, UK IDTA/Addendum, and Swiss SCCs. Implement purpose limitation, security, and audit provisions in processor contracts.
- United States (California) perspective: No cross-border transfer mechanism required under CCPA/CPRA, but maintain compliant Service Provider/Contractor agreements and avoid processing that would constitute a “sale”/“share” without offering opt-outs. When receiving EU/UK/Swiss data in the US, rely on the applicable GDPR/UK/Swiss transfer mechanism.
- Other jurisdictions: Monitor and implement applicable transfer/localization rules (e.g., Brazil LGPD safeguards; Singapore PDPA transfer obligations and comparable protection; Australia APP 8; and any country-specific restrictions).
C. User Rights Implementation
- India (DPDP): Provide mechanisms for users (Data Principals) to confirm processing and access their personal data; enable correction and erasure when purposes are fulfilled or consent is withdrawn; allow consent withdrawal; provide nomination; and implement grievance redressal with India Grievance Officer contact, acknowledging within 24 hours and resolving within 15 days (IT Rules, 2021).
- EU/UK (GDPR/UK GDPR): Support rights of access, rectification, erasure, restriction, portability, objection (including to direct marketing and profiling), and the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects (with meaningful information about logic involved). Provide easy-to-use self-service portals and verification workflows.
- US-California (CCPA/CPRA): Support rights to know/access, delete, correct, opt-out of sale/share, limit use/disclosure of sensitive personal information, and non-discrimination. Honor browser-based opt-out signals such as GPC. Provide at least two request methods and verify requests appropriately.
- Other key regimes: Brazil (LGPD) rights to confirmation of processing, access, correction, anonymization/blocking/deletion, portability, information about sharing, consent withdrawal, and review of automated decisions; Canada (PIPEDA) access and correction; Singapore (PDPA) access and correction; Australia (Privacy Act) access and correction.
- Data Export/Portability: Provide machine-readable export functionality (e.g., JSON/CSV/PDF) covering core profile, resume versions, and application pipeline data to meet GDPR portability and as a global best practice.
II. AI SYSTEM GOVERNANCE AND TRANSPARENCY
A. Algorithmic Transparency
- AI Decision-Making: Provide clear, user-facing explanations of how AI systems analyze resumes and generate recommendations, including key inputs, outputs, and relevant factors. Offer user controls to adjust preferences and review inputs.
- Bias Mitigation and Risk Management: Implement regular testing for discriminatory bias in AI matching algorithms; document methodology, metrics, datasets, and mitigation steps. Align governance with recognized frameworks (e.g., NIST AI Risk Management Framework, ISO/IEC 42001 AI Management System).
- Human Oversight: Maintain human-in-the-loop review for AI-generated materials and recommendations; provide appeal/feedback channels for users to challenge or refine outputs.
- Regulatory Readiness: Monitor and prepare for emerging AI-specific rules affecting employment contexts (e.g., EU AI Act requirements for high-risk systems used in employment, US EEOC guidance on algorithmic tools, and jurisdiction-specific audit/notice requirements such as NYC Local Law 144 for Automated Employment Decision Tools when applicable to employer use).
B. AI Content Disclosure
- Generated Content Labeling: Clearly label AI-generated cover letters, resume content, and interview prep outputs; provide provenance indicators/watermarks where feasible and maintain logs of generation events.
- Accuracy Disclaimers: Include prominent disclaimers about limitations of AI-generated career advice and job matching; encourage user review and customization before use.
- User Education: Offer contextual guidance and tips on reviewing, editing, and responsibly using AI outputs; surface information on data sources and update cadence.
- Emerging Transparency Obligations: Track and implement transparency requirements relevant to AI-generated content (e.g., forthcoming EU AI Act disclosures for synthetic/deepfake content) and any sectoral standards.
III. EMPLOYMENT AND LABOR LAW CONSIDERATIONS
A. Non-Discrimination Compliance
- Protected Characteristics (Global): Ensure AI algorithms and platform practices do not directly or indirectly discriminate based on protected characteristics. Align with India (e.g., caste, religion, sex, sexual orientation, gender identity, disability, age, marital status), EU/UK (Equality Directives; UK Equality Act 2010), and US (Title VII, ADA, ADEA, state laws).
- Equal Opportunity and Job Ads: Maintain neutrality in job matching and career advice; prevent or flag discriminatory job postings unless a bona fide occupational qualification applies and is legally justified in the relevant jurisdiction.
- Audit Requirements: Conduct regular bias audits of AI recommendation systems; document methodology, findings, and mitigation steps. Where applicable to employer-facing tools, support compliance with local audit/notice rules (e.g., NYC Local Law 144).
- Accessibility: Follow accessibility standards (e.g., WCAG 2.1 AA) and reasonable accommodation practices to avoid disparate impact on persons with disabilities.
B. Career Services Regulation
- Scope and Positioning: Clearly present PraxJobs as a technology platform providing AI-enabled tools and research, not an employer or recruitment/placement agent, unless separately licensed and engaged as such.
- India: If facilitating recruitment for overseas employment, comply with the Emigration Act, 1983 and rules; register as a Recruiting Agent where required and do not charge prohibited fees to candidates. Comply with any state-specific rules governing private employment agencies and general business registrations (e.g., Shops and Establishments).
- United States: Review and comply with state and local employment agency/placement service licensing and fee rules where applicable (e.g., New York employment agency laws; other state/local analogs). Avoid unfair or deceptive practices under FTC Act and state UDAP statutes.
- United Kingdom/EU: In the UK, comply with the Employment Agencies Act 1973 and the Conduct of Employment Agencies and Employment Businesses Regulations 2003; do not charge prohibited fees to work-seekers. Monitor EU Member State-specific rules for private employment agencies.
- Professional Liability: Use clear disclaimers that outcomes are not guaranteed; avoid representations that could be construed as employment promises or assured placements.
IV. CONSUMER PROTECTION AND ADVERTISING
A. Marketing Claims Verification
- Performance Claims: Substantiate claims such as "3x more interviews" and "50% reduction in job search time" with robust, contemporaneous evidence; maintain claim substantiation files and update periodically.
- Testimonials/Endorsements: Ensure compliance with India ASCI Code; US FTC Endorsement Guides (disclose material connections, typicality); EU/UK CAP/BCAP and UCPD transparency rules; obtain and retain consent and evidence.
- Outcome Disclaimers and Fairness: Include clear disclaimers that results may vary; avoid unfair or deceptive practices under India Consumer Protection Act, 2019 (and CCPA Authority guidance), US FTC Act and state UDAP laws, and EU Unfair Commercial Practices Directive.
B. Subscription and Billing Compliance
- India (RBI e-mandate): For recurring card/UPI payments, comply with RBI e-mandate requirements (explicit opt-in, pre-debit notifications, easy cancellation, failure management).
- United States: Comply with the federal Restore Online Shoppers’ Confidence Act (ROSCA) and state auto-renewal laws (e.g., California ARL): clear and conspicuous disclosures, affirmative consent, post-purchase acknowledgment, easy online cancellation (for online sign-ups), renewal reminders, and pro-rata refunds where required.
- EU/UK: Provide pre-contract information and clear subscription terms; honor the right of withdrawal under the EU Consumer Rights Directive/UK Consumer Contracts Regulations (with digital content exceptions when performance begins with consent); provide easy, online cancellation and avoid subscription “traps” per EU Omnibus Directive and UK CMA guidance.
- Cancellation and Refunds: Provide simple, self-serve cancellation and fair refund practices; display refund timelines and any proration logic.
- Price Transparency and Dark Patterns: Display total price inclusive of applicable taxes (e.g., GST/VAT); disclose taxes/fees upfront; avoid drip pricing and manipulative “dark patterns” per Indian CCPA Authority guidance, US FTC/state guidance, and EU/UK enforcement trends.
V. INTELLECTUAL PROPERTY PROTECTION
A. User-Generated Content
- Content Ownership: Confirm that users retain ownership of resumes and career information (e.g., Indian Copyright Act, 1957; and analogous copyright laws globally).
- Platform License: Obtain a non-exclusive, worldwide, revocable license to use and process user content solely to provide and improve services, subject to privacy commitments.
- Intermediary/Safe Harbour: Maintain notice-and-takedown and due diligence processes to avail safe harbour under India IT Act Section 79 and IT Rules, 2021; implement US DMCA (17 U.S.C. § 512) notice-and-takedown with a designated agent; and meet EU/UK notice-and-action and transparency obligations under the EU Digital Services Act/UK equivalents.
B. AI Training Data
- Data Sourcing: Use appropriately licensed sources for job descriptions and company information; respect website terms of use and robots.txt; avoid unauthorized scraping or circumvention of technical measures.
- Exceptions and Text/Data Mining: India “fair dealing” exceptions are narrow for commercial TDM—obtain permissions or licenses. In the EU, comply with DSM Directive text and data mining rules (Articles 3 and 4) and honor machine-readable TDM reservations; assess database rights implications. In the US, perform careful fair use analyses; fair use is fact-specific and not guaranteed for commercial TDM.
- Proprietary Algorithms and Know-How: Protect matching systems and models through confidentiality, access controls, and contractual restrictions; register trademarks and maintain trade secret policies.
VI. OPERATIONAL COMPLIANCE REQUIREMENTS
A. Terms of Service and User Agreements
- Clear Terms (Global): Publish clear Terms of Use, Privacy Policy, and user guidelines tailored for each market. For India, prohibit unlawful content and display contact details of the India Grievance Officer (IT Rules, 2021). For EU/UK, include GDPR/UK GDPR notices and contact points; comply with EU Digital Services Act transparency requirements applicable to the service category (e.g., notice-and-action, moderation standards).
- Regional Links and Controls: Provide CPRA-compliant “Do Not Sell or Share” and “Limit Use of Sensitive Personal Information” links and honor Global Privacy Control signals for California users. Provide cookie consent banners in the EU/UK that meet ePrivacy/GDPR requirements.
- Representatives and DPO: Where required, appoint and disclose EU/UK GDPR Article 27 representatives for markets where PraxJobs is not established but offers services, and appoint a Data Protection Officer if trigger criteria are met (e.g., large-scale monitoring or special category data processing).
- Regular Updates: Implement procedures for terms/policy updates and user notification without employing unfair “dark patterns”; record user assent where required.
- Dispute Resolution: Specify governing law and jurisdiction appropriate to user location; consider arbitration where lawful and appropriate (e.g., India Arbitration and Conciliation Act, 1996). Do not restrict statutory consumer rights (e.g., EU consumer forums, US state rights).
B. Security and Data Breach Response
- Cybersecurity Standards: Implement “reasonable security practices” (India IT Act Section 43A/SPDI Rules, DPDP Act safeguards) and globally recognized frameworks (ISO/IEC 27001, SOC 2 Type II). Employ risk-based controls: access management, encryption in transit/at rest, secure SDLC, vulnerability management, vendor risk management, and logging/monitoring.
- Breach Notification (Global):
- India: Notify the Data Protection Board of India and affected users as prescribed by DPDP; notify CERT-In within 6 hours of becoming aware of reportable incidents; retain logs for at least 180 days; synchronize time with trusted NTP servers.
- EU/UK: Notify the competent supervisory authority within 72 hours of becoming aware of a personal data breach under GDPR/UK GDPR when required; notify affected individuals without undue delay where high risk exists; maintain breach registers.
- US (including California): Comply with state breach notification laws; assess CPRA implications (statutory damages for certain breaches) and provide notices to consumers and regulators where required.
- Canada, Australia, Brazil, Singapore: Follow mandatory reporting schemes where applicable (e.g., PIPEDA significant harm reporting to OPC; Australia NDB within 30 days; LGPD notifications to ANPD within a reasonable time; Singapore PDPA reporting for significant harm/volume thresholds).
- Incident Response: Maintain and test incident response playbooks tailored to the above regimes, including roles, escalation paths, external counsel and forensics, regulator/user communications, and post-incident remediation.
VII. RECOMMENDATIONS AND NEXT STEPS
Immediate Actions Required:
- Perform a global privacy/data mapping exercise and DPIAs where required (GDPR/UK GDPR) alongside a DPDP-readiness assessment for India; maintain Records of Processing (GDPR Art. 30).
- Implement AI bias testing protocols aligned to NIST AI RMF/ISO 42001; document mitigation; scope NYC AEDT considerations if offering employer-facing tools in NYC.
- Update privacy notices and consent/opt-out mechanisms to meet GDPR/UK GDPR, DPDP, and CPRA (notice at collection, Do Not Sell/Share, Limit Sensitive PI, GPC) requirements; implement EU/UK cookie consent controls.
- Establish retention and deletion schedules consistent with GDPR storage limitation, DPDP, CPRA retention disclosures, and CERT-In log retention; implement legal hold procedures.
Ongoing Compliance Monitoring:
- Track regulatory developments across India (DPDP rules/SDF thresholds, IT Rules, CERT-In, RBI), EU/UK (GDPR guidance, Digital Services Act implementation), US (CPRA regulations, state privacy laws, FTC actions), and other key markets (LGPD, PIPEDA, PDPA, Australia reforms).
- Conduct periodic AI algorithm bias testing with audit trails; monitor evolving AI regulations (EU AI Act timelines, US EEOC guidance, local audit/disclosure rules).
- Keep user agreements and policies updated to reflect IT Rules due diligence, EU DSA transparency, CPRA opt-outs, and cookie/ePrivacy requirements.
- Review vendor contracts, data processing agreements, and cross-border transfer mechanisms (SCCs/IDTA/DPF); monitor India country-restriction notifications under DPDP.
Risk Mitigation Priorities:
- Strengthen data security controls and certifications aligned with DPDP/IT Act, GDPR/UK GDPR expectations, CERT-In, and global best practices (ISO 27001/SOC 2); enhance vendor risk management.
- Enhance AI transparency, explainability, and human oversight with jurisdiction-specific non-discrimination safeguards; prepare for EU AI Act compliance where applicable.
- Maintain appropriate professional liability, media/IP, and cyber insurance with global coverage.
- Ensure payments, subscription, and marketing practices comply with RBI e-mandate, US ROSCA/California ARL, EU/UK consumer laws, and dark pattern guidance (India CCPA Authority, US FTC, EU/UK enforcement).
This memorandum provides general guidance and should be supplemented with jurisdiction-specific legal advice. Regular legal review is recommended as the platform evolves and regulatory landscapes change.