GDPR and privacy
Keeping candidate data handling compliant with data protection requirements.
Keeping candidate data handling compliant with data protection requirements.
Data protection settings are managed under Settings > GDPR & Privacy, across three tabs.
Deletion requests
This tab lists deletion requests against candidate data, showing the candidate, when it was requested, its current status, and its scope, either a single application or all of a candidate's data.
Select Approve to process the request, or Reject if it shouldn't proceed. Approving is permanent, the candidate's personal data is removed from their record, so make sure it's a genuine request before confirming.
Retention policies
Set how long candidate data is kept before action is taken. Select New Policy and choose:
- A Policy Name.
- A Retention Period, in days.
- What it Applies To: all candidates, rejected candidates, withdrawn candidates, or audit logs.
- Whether it should Auto-Delete once the period ends, and whether it's your Default Policy.
Warnings
This tab lists candidates approaching their retention limit, with how many days they have left. From here you can Export a candidate's data as a data subject access request (DSAR) file, or select Delete to raise a deletion request for them directly.