11 min readElise Fontaine

Updated on

Candidate data you should not be keeping

Your application tracking system holds ten years of rejected applicants and expired roles. The regulatory window to clean it up closes next quarter.

Candidate data you should not be keeping

Recruiting teams accumulate personal data faster than any other corporate function. Sales organizations scrub their contact systems to maintain deliverability metrics. Marketing teams delete inactive subscribers to improve conversion rates. Recruiting teams leave their applicant tracking systems to expand indefinitely. The standard software defaults encourage this behavior. Vendors design platforms to ingest applications easily. They make deletion require deliberate configuration. Millions of rejected applications sit in cloud servers untouched. These files contain resumes from a decade ago. They hold interview notes for jobs that closed in 2019. The storage costs increase annually. The legal liabilities compound daily.

The legal environment is tightening around this exact repository. Regulators in Europe and North America view the dormant candidate database as a severe compliance failure. An applicant who applied in 2018 did not consent to a permanent archive. They agreed to be considered for a specific role at a specific time. Keeping their data indefinitely violates core privacy principles.

The changing regulatory map for next quarter

The regulatory map requires immediate attention from talent leaders. Enforcement bodies are shifting from sending warning letters to conducting structural audits. The European Union Artificial Intelligence Act entered into force on August 1, 2024. Systems used for recruitment and candidate evaluation fall strictly under the high risk classification. Employers have until 2026 to achieve full compliance. The foundational data governance requirements force action this year. You cannot audit an algorithmic screening tool if the training data contains ten years of unmanaged applicant files.

In North America, the California Privacy Rights Act removed the historical employment exemption. California residents possess the right to know what personal information you hold. They possess the explicit right to request deletion. A candidate in San Francisco has the same data rights as a consumer shopping online.

Quebec introduced Law 25 across a staggered timeline. The legislation enforces strict automated decision disclosure. It mandates that organizations destroy personal information once the original purpose is achieved. The final enforcement phase of Law 25 takes effect in September 2024.

Colorado passed its own Artificial Intelligence Act targeting algorithmic discrimination in employment decisions. The Colorado law takes effect on February 1, 2026. You must update your data retention policies to survive this regulatory web. You need specific numeric thresholds mapped to specific jurisdictions.

Hard numbers for retention schedules

A retention schedule is a functional matrix of deadlines. You keep personal data only as long as a legitimate business reason exists. Once the window for a discrimination claim closes, the business reason expires. You must map these deadlines precisely across your operating regions.

In the United Kingdom, the Information Commissioner sets a clear standard for employers. You should keep recruitment records for six months after an unsuccessful application. An applicant has three months to bring a discrimination claim to an employment tribunal. The six month limit provides a safety buffer. Keeping the data longer requires a highly specific legal justification.

Germany operates on a tighter legal schedule. The General Equal Treatment Act requires candidates to assert claims in writing within two months of receiving a rejection. Most German legal advisors recommend deleting applicant data after three to six months maximum. Keeping candidate data for a year in Germany invites aggressive regulatory scrutiny.

The United States presents a conflicting picture for employers. The Equal Employment Opportunity Commission requires employers to keep all personnel and employment records for one year. The California Civil Rights Department requires employers to preserve application records for four years. A candidate in California can still submit a privacy deletion request before the four year mark. You must weigh the state preservation requirement against the privacy request. Legal counsel usually advises retaining the bare minimum audit trail to satisfy the state. You then delete the resume, the portfolio, and the interview notes to satisfy the applicant.

Canada aligns closer to the European privacy model. The Personal Information Protection and Electronic Documents Act relies on reasonable purpose. Once a role is closed, you should not keep the applicant data longer than twelve months.

Configuring the application tracking system

Policy documents achieve nothing if the software ignores them. You must configure your application tracking system to enforce your retention schedule automatically. Most modern systems include data privacy modules. Talent teams rarely configure them correctly. The implementation phase usually skips these settings to launch faster.

Greenhouse includes a dedicated data retention and deletion feature. You can set rules based directly on the candidate rejection date. You can configure Greenhouse to email candidates after twelve months. The system asks them to renew their consent to stay in your talent database. If the candidate ignores the email, the software anonymizes their profile automatically. Anonymization removes the identifying information while keeping the aggregate data for your hiring metrics. You retain the knowledge that an engineer applied in the third quarter. You lose their name and contact details completely.

Workday handles recruiting data within its broader administrative architecture. You must use the designated purge processes to maintain compliance. You build a custom report to identify external candidates who have no active job applications. You filter for candidates whose last activity occurred over a year ago. You schedule the purge process to run monthly against this specific report. This requires coordination with your central human resources technology team.

Lever offers a similar automated compliance toolset. You define the exact number of days a candidate remains in the system after their last interaction. You can map different rules to different geographic locations. A candidate located in Berlin triggers the six month deletion rule automatically. A candidate in Texas triggers a distinct rule based on your specific company policy.

SmartRecruiters allows administrators to build detailed compliance policies by country. You establish a specific consent period for talent pool members. The system tracks the exact date of consent. It flags profiles that exceed the legal threshold. The platform will block recruiters from emailing candidates whose consent has expired.

The severe danger of interview notes

Interview notes represent the highest liability within your recruitment database. Recruiters and hiring managers type rapid observations during phone screens. These notes often contain subjective assessments and careless language. They capture assumptions that have no place in a professional evaluation.

Under the General Data Protection Regulation, interview notes are personal data. A candidate can submit a subject access request at any time. They have the legal right to see exactly what your hiring managers wrote about them. California residents have similar access rights under state privacy laws.

If a manager writes that a candidate sounded too old for a fast paced team, you have documented an age discrimination violation. If a recruiter notes a candidate mentioned their family plans, you possess illegal demographic data. A subject access request will uncover these statements immediately. The resulting financial penalties and reputational damage are entirely avoidable.

You must train your teams to write objective interview feedback today. They should document factual evidence of skills and competencies. They must avoid commentary on personality or appearance. They should score candidates against a predefined rubric.

Interview notes must follow the same deletion clock as the application itself. When a candidate is rejected, the notes should expire within six months. There is no legitimate reason to retain a hiring manager subjective thoughts from five years ago.

Recruiters love building massive talent pools. The traditional idea is to collect a database of qualified candidates who might fit a future role. This concept fails entirely in a strict privacy environment. A static database is a compliance burden.

Consent degrades rapidly over time. A candidate who agreed to join your talent pool in 2021 did so under specific life circumstances. They were actively looking for a new position. Sending them a recruitment email in 2025 using their 2021 consent violates basic privacy principles. Regulators do not view indefinite consent as valid.

You must build a mechanical renewal process for your talent pools. Set a hard limit of two years for any candidate profile. Before the two year mark, send an automated system message. Ask the candidate if they want to remain in your database. If they click yes, reset the clock for another cycle. If they do not respond, you must delete or anonymize their profile immediately.

This practice actually improves your sourcing metrics. A talent pool of one thousand candidates who recently confirmed their interest holds massive value. It outperforms a stagnant database of fifty thousand dead email addresses. Your open rates will increase predictably. Your spam complaints will drop to zero.

Removing unnecessary data collection

The simplest way to manage candidate data is to stop collecting it. Every field on your application form creates a new compliance obligation. If you do not need a piece of information to evaluate a candidate, remove the field. Every data point you decline to collect is a data point you never have to secure.

Stop asking for physical home addresses. A city and country are sufficient for tax planning and legal routing. You do not need a street name or apartment number until you generate an employment contract.

Never ask for a photograph during the application stage. In many European jurisdictions, requesting a photograph violates strict anti discrimination laws. In the United States, it introduces immediate bias risk into the evaluation process.

Remove requests for current salary or compensation history. Several state and local jurisdictions ban salary history questions entirely. New York City, California, and Washington State enforce strict prohibitions on these fields. The European Union Pay Transparency Directive also bans employers from asking about pay history. The directive takes full effect in June 2026. The data collection should stop today.

Audit your custom fields closely. A recruiting operations team might add a drop down menu to track a temporary initiative. The initiative ends after three months. The field remains on the application form for five years. You are collecting arbitrary data without a legal purpose.

Managing data deletion requests

Data deletion requests remain rare until a public controversy triggers a sudden wave of them. You cannot treat these requests as unexpected edge cases. You need a documented and highly repeatable procedure in place next quarter. The first request should not create a panic.

Define clearly who owns the request process. The privacy team usually receives the initial email. The recruiting operations manager must execute the actual deletion. Establish a service level agreement between these internal teams. The European privacy rules mandate a formal response within thirty days. You should aim to complete the internal process in seven days.

Map every single software system where candidate data lives. The primary application tracking system is the main database. It is rarely the only one. Recruiters export spreadsheets to share with executives. Hiring managers take notes in shared cloud documents. Technical screening platforms like HackerRank or CoderByte hold code snippets and test scores. Background check vendors hold highly sensitive reports.

When you receive a deletion request, you must trace the candidate across all these connected systems. Deleting the primary profile is insufficient if a hiring manager has the resume sitting in a personal folder. Use modern automation tools to scan connected systems and purge the records simultaneously.

Algorithmic transparency requirements

Automated screening introduces severe data governance challenges for talent leaders. If you use software to score candidates or parse resumes, you operate in a high risk regulatory zone. The days of using black box algorithms are over.

New York City Local Law 144 requires employers to conduct annual independent bias audits. This applies to any automated employment decision tools you deploy. The law went into effect on July 5, 2023. You must publish the results of these audits publicly on your career site. To pass the audit, you must know exactly what data the system analyzes. You cannot run an audit on a system filled with expired data.

The new European laws require human oversight of automated recruitment systems. A human operator must be able to override the algorithmic decision at any time. You must inform candidates actively that an artificial intelligence system is evaluating their application.

Quebec enforces similar transparency rules today. If an algorithm filters out a candidate, the candidate has the right to know the reasons. They can demand the principal factors that led to the rejection decision.

If your software vendor treats their algorithm as a proprietary secret, you face a compliance crisis. You cannot explain the decision to a rejected candidate. You cannot prove to a regulator that the system is fair. Ask your vendors to detail their data models immediately. If they refuse to provide documentation, find a new vendor next quarter.

Preparing for the next quarter

You must shift your recruiting operations from data hoarding to active data lifecycle management. The window for treating the applicant tracking system as an infinite archive has closed. Regulators have the tools and the legal frameworks to penalize negligent data practices. The technical solutions exist within your current software stack. You just need the operational discipline to turn them on.

Next quarter requires focused execution. Do not draft a theoretical privacy policy. Implement practical data controls.

Practical next steps

  1. Schedule a meeting with your software administrator to locate the automated deletion module in your primary tracking system.
  2. Configure the system to anonymize rejected candidate profiles after twelve months globally.
  3. Set a specific rule to delete rejected candidate data after six months for candidates located in the United Kingdom or Germany.
  4. Run a manual purge script on all open requisitions that have seen no candidate activity since December 2023.
  5. Audit the career site application form and permanently delete fields for physical street address and salary history.
  6. Draft a standard operating procedure for handling a candidate deletion request.
  7. Set a maximum internal turnaround time of fourteen days for processing any privacy request.
  8. Email your automated screening and video interview vendors to request their latest bias audit reports and explainability documentation.

Sources

  1. 01Regulation (EU) 2016/679 (GDPR)EUR-Lex
  2. 02Guidelines on data minimisation and purpose limitationEuropean Data Protection Board
  3. 03CCPA regulationsCalifornia Privacy Protection Agency
  4. 04PIPEDA in briefOffice of the Privacy Commissioner of Canada
ShareLinkedInXEmail

Read next in hr compliance

The newsletter

One edition roughly every two weeks: new articles, and what changed in hiring that is worth your time.

Back to all articles