Skip to content
English
  • There are no suggestions because the search field is empty.

Candidate data rights: export, deletion and consent

How to record a candidate's consent, export their data, and handle deletion requests and retention in Recruit.

How to record a candidate's consent, export their data, and handle deletion requests and retention in Recruit.

Candidate data rights are handled in three places. The Governance tab on a candidate's profile is where you record consent, download a copy of their data and raise a deletion request. Settings, then GDPR & Privacy, is where deletion requests are managed and retention rules are set. Your careers page controls which privacy policy candidates are shown. Only System Admins and HR users can use the first two.

Who can do what

  • System Admin and HR: record consent, export candidate data, request deletion, and manage everything under GDPR & Privacy.
  • Members, Agency users, hiring managers and interviewers: none of these actions. If they open the Governance tab, the consent card shows "Failed to load consent data." and exports and deletion requests are refused.
  • System Admin only: the privacy policy link on the careers page, and revealing a candidate whose identity an agency has hidden (see the export section below).

Group users granted access to a subsidiary organisation can do the same on its candidates, at Admin or HR level.

Recording and viewing consent

Open a candidate, select the Governance tab and find the GDPR Consent card. It lists three types of consent, each marked Consented or Not Consented:

  • Data Processing: required to process their application.
  • Marketing Communications: receive job alerts and updates.
  • Talent Pool Inclusion: keep their data for future opportunities.

Underneath, the card shows when the data processing consent was recorded and how: Application Form (the candidate ticked the consent box when applying), Email or Manual (recorded by a member of your team). A candidate with no consent records shows an empty card apart from the button.

  1. Select Record Consent. If consent has already been recorded, the button reads Edit Consent.
  2. Tick or untick each consent type in the Record GDPR Consent window.
  3. Select Save Consent. The message "Consent updated successfully." appears.

Changes made here are always saved as Manual. Only the types you actually changed are logged, each as given or withdrawn, with the date and the person who recorded it. Nothing is overwritten, so the full history is kept. That history appears in the data export, not on screen.

Consent that a candidate gives on the application form is recorded automatically. Candidates must tick the consent box to submit an application.

Exporting a candidate's data

  1. Open the candidate and select the Governance tab.
  2. In the Data Subject Rights card, select Export Candidate Data and choose PDF or Excel.

The file downloads straight away and is named after the candidate, for example jane-smith-dsar-export. The PDF carries your organisation's name, logo and colour. If the download fails you will see "Failed to export candidate data. Please try again." Exports are limited to ten a minute.

Both formats contain the same sections: the candidate's personal details, applications, video interviews, email history, the audit trail (their 100 most recent events), deletion requests and consent history. The Excel file has one sheet per section plus a Summary sheet with the export date and a count for each. In Excel, the applications sheet lists each application with its job, status and dates. Uploaded files such as a CV are not part of the export.

Every export is recorded in the audit log.

If an agency submitted the candidate with their identity hidden, the export is refused with "This candidate was submitted by an agency with their identity hidden. Reveal the candidate before exporting their data." A System Admin has to reveal the candidate first. After that the export works as normal.

Requesting deletion

  1. Open the candidate, select the Governance tab and go to the Data Subject Rights card.
  2. Select Request Deletion.
  3. Confirm with Submit Deletion Request.

The message "Deletion request submitted successfully." appears and the button changes to Pending Deletion. A request made here always covers all of the candidate's applications. Nothing is removed yet. If a request is already open for the candidate you will see "A deletion request is already in progress for this candidate."

Candidates can also ask for deletion themselves from the manage link for their application. That request covers only the application they opened it from. Either way, the request appears in the queue described next.

Managing the queue

Go to Settings, then GDPR & Privacy. Three tiles at the top show Pending Deletion Requests, Retention Warnings and Active Policies. The Deletion Requests tab lists each request with the candidate, email, request date, Status, Scope (all applications, or a single application with its job title) and Scheduled Deletion.

Statuses are Pending, In Progress, Completed, Rejected and Cancelled. A pending request is processed automatically seven days after it was made, and that date is shown in Scheduled Deletion. There is no approval step. To stop a request, select Cancel on its row before that date, add an optional Cancellation Reason and confirm. Only pending requests can be cancelled. If you need deletion later, raise a new request.

When a candidate raises a request themselves, System Admins and HR users get an email with the date it will be actioned, provided their Data deletion request notification is on. They also get an email if an automatic deletion fails and needs a manual look.

What deletion does

Deletion anonymises the candidate. The record stays in place, so applications, pipeline history and reports still count, but nothing identifies the person any more. The name becomes "Deleted User", the email becomes a placeholder address, and the phone number, address, location, LinkedIn link, notes, tags and CV link are cleared. Also cleared or removed are:

  • application answers, form responses, work and education history
  • emails, text messages and their delivery records
  • notes, comments, interview feedback, scorecards and shortlisting scores
  • video interview answers, references and referee details, offers and onboarding answers
  • right to work details and stored files, including the CV
  • the candidate's details inside audit log entries

Consent records are kept, because they are your evidence of the lawful basis for holding the data. This cannot be undone. Once a request is completed, the data cannot be restored from Recruit.

If a stored file cannot be removed on the first attempt, the rest of the record is still anonymised and Recruit retries the erasure each night until it finishes.

The items above are what Deletion covers. If you need to confirm exactly what personal data remains for a particular request, contact HireRoad support.

Retention policies

Retention policies delete candidate data automatically after a set time. Go to Settings, then GDPR & Privacy, then the Retention Policies tab, and select New Policy.

  • Policy Name: required, up to 255 characters.
  • Retention Period (days): from 1 to 3,650. It starts at 365.
  • Applies To: All Candidates, Rejected Candidates, Withdrawn Candidates or Audit Logs. The rejected and withdrawn options only match candidates whose applications are all rejected, or all withdrawn.
  • Auto-Delete: off by default. With it off, no candidate is deleted.

Use Edit on a policy to change it, or the bin icon to delete it. Deleting a policy stops future deletions under it but does not restore anyone already anonymised.

Recruit checks every policy each night. A candidate is due once their last activity is older than the retention period. Last activity is the most recent update to any of their applications, or the date the candidate was created if they have none. Due candidates are anonymised in the way described above, but only where Auto-Delete is on.

Audit logs work differently. An Audit Logs policy removes audit entries older than its retention period. If you have no such policy, audit entries older than 365 days are removed anyway.

Warnings

The Warnings tab lists candidates who will reach the limit within 30 days, with the days remaining and the policy that applies. Each row has two buttons: Export, which downloads that candidate's data as a raw data file, and Delete, which raises a deletion request. For the PDF or Excel version, use the export on the candidate's Governance tab instead.

If Auto-Delete is on, candidates in that window are also emailed once, ahead of deletion, using the Retention Warning email template. That email is only sent when the template exists in your organisation's templates. Without one, candidates are not warned, though deletion still goes ahead.

Consent also expires. Candidates whose consent is close to 12 months old are emailed using the Consent Expiry template. It is a reminder only. Their data is not deleted because of it.

Privacy settings on the careers page

By default, candidates are linked to HireRoad's privacy policy. A System Admin can point them to your own under Settings, then Company, then Careers Page, in the Legal section. The Privacy Policy URL is used in the careers page footer, in the consent box on the application form and in the cookie banner on the careers page. Hide privacy policy link in footer removes only the footer link. The consent box still links to a policy, so candidates always see one before agreeing. The full setup, and how the cookie banner works, is covered in the article Cookies and consent.

For an overview of where these settings sit alongside the others, see the article GDPR and privacy.