What Is Data Privacy?
Data privacy is the practice of handling personal information according to defined purposes, individual rights, legal duties, and reasonable expectations. In recruiting, it covers how candidate and contact data is collected, obtained, used, shared, stored, corrected, retained, deleted, and processed by people or technology.
Recruitment data can include contact details, resumes, employment history, interview notes, references, communications, assessment results, work authorization information, recordings, and inferred data. Some records contain sensitive information subject to added restrictions.
Privacy rules differ across jurisdictions and relationships. A recruiting firm, client, sourcing provider, assessment vendor, and recruitment platform may hold different legal roles and duties for the same candidate record.
Legal note: This page provides operational education and is not legal advice.
Data Privacy at a Glance
- Define why each category of personal information is needed.
- Give people clear information about collection, use, sharing, retention, and rights.
- Collect data that is relevant to the stated recruiting purpose.
- Keep records accurate and connected to their source.
- Limit access and disclosure to approved people and purposes.
- Set retention and deletion rules for each record type and jurisdiction.
- Provide a process for access, correction, deletion, restriction, objection, or other applicable requests.
- Review vendors, integrations, automation, and AI before personal information enters them.
How Data Privacy Works in Recruiting
Map the Data
List the information handled across sourcing, applications, interviews, assessments, checks, submissions, offers, placements, and talent pools. Record its source, storage, access, movement, and removal.
Define Purpose and Legal Basis
State the recruiting purpose for each processing activity and identify the applicable legal basis or authorization. Consent is one possible basis in some regimes, not a universal answer for every recruiting activity.
Provide Privacy Information
Privacy notices should explain the organization, data categories, sources, purposes, legal basis where applicable, recipients, transfers, retention, rights, and relevant automated processing. Rules can apply to data from public sources or third parties.
Minimize and Separate Data
Collect data needed for the role or relationship. Keep sensitive information, monitoring data, background material, and decision notes in restricted locations.
Control Access and Sharing
Use role-based access and approved sharing methods, confidentiality settings, and documented vendor relationships. Confirm what a client needs before sending candidate information.
Maintain Accuracy and Retention
Provide a process to correct outdated records. Apply retention schedules by purpose, record type, legal requirement, relationship, and jurisdiction.
Handle Individual Requests
Route requests to a trained owner. Verify identity proportionately, search connected systems, record decisions, and apply the relevant deadline and exceptions.
Prepare for Incidents
Staff should report misplaced resumes, unintended disclosures, compromised accounts, exports, and vendor incidents through a defined response path.
Example from a Recruiting Firm Workflow
A recruitment firm sources a finance director from a public professional profile. The recruiter creates a candidate record with the source URL, current role, business contact details, and reason for potential relevance. The firm sends the candidate its recruiting privacy information at the appropriate point under its process and applicable law.
After the candidate expresses interest, the recruiter adds a resume, compensation expectations, location preferences, and interview notes. Access to the record is limited to the search team. The client receives an approved candidate submission rather than the firm’s complete internal record.
The candidate later asks what information the firm holds. The firm verifies the requester, gathers connected records, applies the relevant rights and exceptions, records the response, and updates future-contact status.
The firm retains information required for documented obligations and removes material with no continuing purpose. It treats withdrawal, deletion, and communication opt-out as different actions.
In executive search, confidentiality may require tighter visibility for a confidential executive-search longlist, named target list, client strategy, or off-limits relationship. Privacy duties still apply to the people represented in those records.
Data Privacy Versus Security and Confidentiality
| Point | Data privacy | Data security | Confidentiality |
|---|---|---|---|
| Main question | Is personal information handled for proper purposes and with applicable rights and duties? | Is information protected against unauthorized access, alteration, loss, or disruption? | Is information disclosed to approved people under agreed restrictions? |
| Typical controls | Notices, purpose records, legal basis, minimization, retention, request handling, vendor terms | Authentication, access control, encryption, backups, monitoring, incident response | Need-to-know access, restricted searches, client terms, internal handling rules |
| Recruiting example | Deciding whether and how long to keep a sourced profile | Preventing an unauthorized login from exporting candidate records | Restricting a confidential executive-search longlist to the search team |
The concepts overlap. Strong security does not make an unjustified collection private, and a valid recruiting purpose does not remove the need for security.
Jurisdiction and Scope
The European Union General Data Protection Regulation sets principles for lawful, fair, transparent, limited, accurate, secure, and accountable processing. It can apply outside the European Union under its territorial rules. The UK has its own regime and recruitment guidance from the Information Commissioner’s Office.
California privacy law can cover applicant information when a business falls within scope. A September 2025 California Privacy Protection Agency enforcement decision addressed applicant notices and rights. Other jurisdictions set different rules.
Legal counsel or a qualified privacy professional should confirm the rules for the organization, candidate location, client, data source, processing purpose, and cross-border transfer.
How to Measure Privacy Operations
- Source completeness: Sourced records with a documented origin divided by sourced records reviewed.
- Retention coverage: Record categories assigned an approved retention rule divided by record categories identified.
- Overdue deletion rate: Records past an approved deletion or review date divided by records due for action.
- Request response time: Elapsed time from verified request receipt to completed response.
- Incident reporting time: Elapsed time from discovery to internal escalation.
- Vendor review coverage: Relevant vendors with a current privacy review divided by such vendors in use.
Targets should reflect applicable law and operating risk.
Common Mistakes
Treating Public Information as Unrestricted
Public visibility does not erase privacy duties. Record source, purpose, notice approach, and relevance.
Using Consent as the Default Explanation
Map the correct legal basis or authorization for each activity. Do not misstate how withdrawal works.
Sharing Complete Internal Records with Clients
Send information needed for the client’s defined step. Keep internal notes, protected data, and unrelated history separate.
Keeping Every Profile Forever
Set retention by purpose and record type. Review stale profiles, applications, interview material, checks, and submissions.
Deleting One System and Missing the Rest
Candidate information may exist in email, files, exports, recordings, assessments, messages, backups, and portals. Define the system scope for requests.
AI and Automation Impact
AI tools may summarize resumes, infer attributes and rank profiles, transcribe interviews, enrich records, or recommend outreach. Each use can create new data, purposes, recipients, and retention questions.
Teams should document inputs, outputs, vendor use, access, retention, human review, notices, and rights. The UK Information Commissioner’s Office reported in November 2024 that audits of AI recruitment providers led to recommendations on fairness, minimization, transparency, retention, and inferred information.
Automation can apply retention actions, restrict exports, route requests, record notice delivery, and flag sensitive fields. Automated deletion or disclosure should have tested rules, exception handling, and an auditable approval path.
Recruiterflow’s privacy policy describes how it processes platform data on customer instructions and directs individuals seeking changes to contact the relevant customer as data controller.
Editorial note: Product Marketing and legal counsel should confirm any page-level product or contractual statement before publication.
Practical Checklist
- Inventory data, sources, systems, recipients, and transfers.
- Document purpose and applicable legal basis or authorization.
- Provide current privacy information at the right time.
- Separate sensitive and restricted data from general recruiting notes.
- Review access by role, client, job, and integration.
- Set retention, review, deletion, and opt-out rules.
- Review vendors, transfers, AI uses, and subprocessors.
- Test access, correction, deletion, restriction, and objection workflows.
- Train recruiters on notes, exports, sharing, and incidents.
Questions Recruiters Ask
Is Candidate Consent Always Required?
No universal rule applies. The correct basis depends on the jurisdiction, purpose, relationship, data type, and activity. Consent may be required or appropriate in some cases, and another lawful basis may apply in others.
Can Recruiters Store Information from Public Profiles?
Public availability does not settle the privacy analysis. Assess purpose, relevance, transparency, rights, source accuracy, retention, and local law.
Is Deleting a Candidate the Same as Unsubscribing Them?
No. Unsubscribing stops defined communications. Deletion removes data within the applicable scope and exceptions. A limited suppression record may support a future contact objection.
Who Is Responsible When a Recruiting Firm Uses Recruiting Software?
Responsibility depends on roles and contracts. A recruiting firm may act as controller, processor, or share responsibilities with a client. A software provider may act under customer instructions.
Recruitment