Fixing the ghost data problem in candidate sourcing
Most ATS platforms are full of illegal candidate records that create massive liability for your recruiting team.

The hidden liability in your talent pool
Recruiting leaders often view their Applicant Tracking System (ATS) as a proprietary gold mine. They believe that more data equals better hiring outcomes. This logic leads sourcing teams to scrape LinkedIn profiles, buy contact lists, and store resumes for years without a specific hiring goal.
In the European Union and the United Kingdom, this practice violates the General Data Protection Regulation (GDPR). In North America, while laws like the California Consumer Privacy Act (CCPA) are less restrictive regarding initial collection, the trend is moving toward stricter data minimization requirements.
The problem is ghost data. These are records of people who never applied to your company, never gave consent for you to store their phone numbers, and have no idea your organization is tracking their career progression. If a candidate files a Subject Access Request (SAR) and you cannot explain why you have their data or how you obtained it, your company faces significant fines and reputational damage.
Why sourcing is different from applying
When a candidate applies for a job on your career page, they agree to your privacy policy. You have a clear legal basis for processing their data: the performance of a contract or legitimate interest in evaluating them for a role. This data has an expiration date, usually six to twelve months depending on your local jurisdiction and internal policy.
Sourcing is different. When a recruiter finds a profile on a third party site and adds it to the ATS, that individual has not interacted with your brand. Under GDPR Article 14, you must inform the person that you are processing their data within one month of collecting it. Most recruiting teams skip this step because they do not want to alert a passive candidate before they are ready to reach out. This silence is a direct compliance failure.
The failure of the keep everything mindset
Many HR managers argue that they need this data for future roles. They treat the ATS as a historical record. However, data accuracy is a core principle of GDPR. A resume from 2019 is likely inaccurate. Keeping it does not help your hiring speed; it clutter your search results and creates a trail of unmanaged personal information.
If your team is sourcing 500 candidates a month and only 10% respond to outreach, you are accumulating 450 illegal records every 30 days. Over two years, that is over 10,000 records that have no consent and no business justification.
Implementing a 30 day purge cycle
To fix this, you must shift from a library mindset to a flow mindset. Sourcing should be a temporary activity, not a permanent storage solution.
First, configure your ATS to tag candidates by source. Distinguish between 'Applied' and 'Sourced'. For any record tagged as Sourced, set an automated hard deletion trigger for 30 days. This aligns with the GDPR requirement to notify the data subject. If your recruiter has not contacted the candidate and received a response within those 30 days, the data must be removed.
If the candidate responds and expresses interest, you move them to an 'Active' status. At this point, you send your standard privacy notice and obtain consent to keep their data for the duration of the hiring process. This turns a cold lead into a compliant record.
Managing the third party tools
Your compliance risk extends to the browser extensions and sourcing tools your team uses. Many of these tools sync data automatically. If a recruiter uses a tool to find a personal email address and that address is pulled into your ATS, you are now responsible for that data.
Audit your recruiting tech stack. Ask your vendors specifically how they handle data deletion when a profile is removed from their platform. If the tool does not allow you to bulk delete sourced candidates who did not convert to applicants, it is a liability. You should prioritize tools that offer automated expiration dates for sourced profiles.
Documentation and the SAR process
A Subject Access Request is the ultimate test of your compliance. When a person asks to see all the data you have on them, you must provide the source of the data, the purpose of storage, and who has accessed it.
In a messy ATS, a SAR might reveal internal notes from five years ago that the candidate was never meant to see. Or worse, it might reveal that you bought their data from a vendor with questionable scraping practices. By cleaning your database and sticking to a 30 day sourcing window, you ensure that any data you do hold is fresh, relevant, and legally defensible.
Training the team on data hygiene
Recruiters are measured on pipeline volume, which incentivizes bad data behavior. You must change the performance metrics. Instead of rewarding a large database, reward a high conversion rate from sourced lead to active applicant.
Train your team to understand that a resume is not an asset; it is a liability with an expiration date. Conduct quarterly audits where recruiters must justify the presence of any sourced candidate who has been in the system for more than 90 days without an active interview stage.
The North American perspective
While European companies face immediate pressure, North American HR leaders should not wait for federal legislation to act. States like California, Colorado, and Virginia are passing laws that mirror European standards. Building a compliant sourcing workflow now prevents a massive manual cleanup later. Also, a clean database improves the efficiency of your AI matching tools, which struggle when fed old, inaccurate resumes.
Compliance is not a barrier to sourcing; it is a filter that forces your team to focus on high quality, engaged talent rather than hoarding names in a digital file cabinet.