Every candidate record is personal information you chose to keep. The duties start when you store it, not when you contact anyone — and they apply to the spreadsheet as much as to the proper system.
A reason to hold it, and a date to delete it
You need both.
For people who applied, the reason is usually obvious: you need their details to consider them. For people you found yourself, it is normally "legitimate interest" — which means you have to have genuinely weighed your interest against their rights, and be able to show that you did.
Keeping data beyond the immediate process needs its own reason and its own deadline. "Indefinitely" is not a deadline. Common practice runs from a few months to a couple of years depending on where you are and why. What matters is that you chose it deliberately, wrote it down, and it happens automatically.
Automatic is the part that fails. A deletion policy nobody implemented is worse than none, because you have written down a standard you are visibly not meeting.
The rights you have to be able to honour
| Right | What it means in practice |
|---|---|
| See their data | Produce everything you hold — including recruiter notes and scorecards |
| Correct it | Fix wrong information, which includes badly read CV fields |
| Delete it | Remove it everywhere, not just from the main system |
| Object, or withdraw | Stop processing, and stop contacting them |
| Understand an automated decision | Explain in plain words what the software did and what a person did |
The first one catches people out. Interview notes and scorecards about a candidate are generally their personal data. So write every note as though the person will read it — because sometimes they will. That also happens to improve the notes.
Where candidate data hides
Deleting is only as good as your list of places to look. In a typical setup, candidate details end up in:
- The main hiring system — the one place everyone remembers.
- The sourcing tool's own database, and whatever data provider sits behind it.
- Email, including attachments.
- Chat channels, where someone pasted the details into an approval message.
- Transcription and note-taking tools, with their own deletion settings.
- Spreadsheets and exports on individual laptops.
- The AI provider's logs, depending on your contract and settings.
That last one deserves a specific check. Find out whether your suppliers' terms let them train on your data, how long they keep it, and whether you can turn that off. This is a contract question, and the time to raise it is before signing.
What to check in a supplier's terms
- Who is responsible for what, legally.
- Which other companies they pass data to, and whether they tell you when that changes.
- Where the data is stored and where it travels.
- Whether your data is used to improve their product.
- How long they keep it, and what happens when you leave.
- How quickly they tell you about a breach.
- Whether they will help you answer a request to see or delete data.
Test it now
Pick one candidate. Could you find and delete every copy of their data today, across every system and every person?
Most teams cannot, and the gap is nearly always the sourcing tool and somebody's spreadsheet.