TalentLucid Help
Recruiting workspaceManage your workspace

Candidate Privacy and Data Requests

Manage candidate privacy settings and respond to copy, correction, deletion, and retention requests.

The recruiting application gives candidates a public Privacy area on the careers site. Candidates can use it to review the information connected to their email address, request a private copy, ask for deletion, request a correction, and manage any optional choice to keep their profile available for future opportunities.

Administrators use Data privacy and Candidate privacy reviews to publish the notice candidates see, define retention review settings, send notices to sourced candidates, and make decisions about verified deletion or anonymization requests.

Prerequisites

Before you configure or review candidate privacy, make sure that:

  1. You can sign in to the recruiting application.
  2. You are working inside the correct company workspace.
  3. You are a company administrator. Privacy settings and privacy reviews are shared workspace controls.
  4. You know the legal company name, privacy contact email, supported careers-site languages, and the retention policy your organization wants to communicate.
  5. You understand that deletion and anonymization decisions can permanently remove candidate information and should follow your organization’s approved process.

Visual guide: the Data privacy settings

How candidate privacy works

The workflow has four parts:

  1. You prepare and publish a privacy notice in Data privacy.
  2. Candidates read the notice when they apply or visit Privacy on the careers site.
  3. Candidates use a secure, one-time link to access their own information and submit requests.
  4. You review the resulting work in Candidate privacy reviews and record the appropriate decision.

The application keeps these steps separate. A candidate’s request is not an automatic instruction to delete data, and an inactivity date creates a review item rather than deleting a record automatically.

Set up the privacy notice

  1. Open Settings > Data privacy.
  2. Select the language you want to edit under Privacy notice language.
  3. Complete the notice fields:
    • Legal company name
    • Privacy contact email
    • Notice title
    • Privacy policy text
  4. Review the Data retention choices.
  5. Select Save changes.
  6. Repeat the process for every enabled language.

Each language can show a status such as Published, Ready, Draft changes, Needs attention, or Incomplete. Review every language before enabling the privacy workflow. The notice shown to a candidate follows the language of the careers site and application experience where that version is available.

Configure data retention

Use Inactivity review to set the Inactivity period. This flags inactive candidate records for administrator review after the approved period when valid retention consent is not available. It does not delete or anonymize the record by itself.

Use Extended retention when candidates should be able to choose to keep their profile available after a hiring process ends. When enabled, complete:

  • Retention period
  • Retention choice label
  • Retention choice explanation

The explanation should tell candidates what the choice means and how long the additional period lasts.

If your account includes more than one company workspace, Require consent for cross-company sharing can prevent candidate data from being copied to another company until a current consent grant exists.

Activate the privacy workflow

The GDPR compliance control activates the saved notices and related privacy and retention workflows.

  1. Complete the required Legal company name.
  2. Set the Inactivity period.
  3. Complete the notice for every required language.
  4. Save the changes.
  5. Enable GDPR compliance.

If the control is unavailable, the page identifies the missing requirement. Disabling the control preserves existing privacy records but stops the active workflow from being used for new processing.

Configure privacy communications

Open Settings > Email templates to review the candidate-facing application confirmation and privacy messages. Review each available language so candidates receive clear instructions and the correct privacy contact.

The same area includes Sourced candidate notice. Choose a Sending mode:

  • Manual lets you review each candidate added outside the application form and choose Send notice.
  • Automatic queues the published notice for every newly sourced candidate. Existing sourced candidates remain in the review list.

Automatic is available only after the default-language privacy notice is complete and published. Save the selected mode before relying on it for new sourced candidates.

Review privacy work in the workspace

  1. Open Candidates.
  2. Select Open privacy reviews.
  3. Review the section that matches the work you need to complete.

The Candidate privacy reviews page includes:

Sourced candidate notices

Use this section for candidates added outside the application form.

  • Review whether a notice is Not sent, Notice queued, Delivery failed, or Needs a fresh notice.
  • Select Send notice when a published notice and a valid candidate email are available.
  • Open Recent notice activity to check recent manual or automatic deliveries.

If the candidate has no email address, or the default-language notice is not published, the application keeps the action unavailable until the missing requirement is fixed.

This section shows optional retention consent ending in the next 30 days. Requests are not sent automatically.

  1. Confirm the candidate email address.
  2. Select Send request.
  3. Check for Queued, Sent, or Retry request status.

The candidate can then decide whether to extend the optional retention period from the Privacy area.

Needs retention review

This section shows inactive records that reached the approved review date. Nothing is anonymized automatically.

  1. Review the candidate and the Last activity and review due dates.
  2. Select Review anonymization.
  3. Review the candidate’s hiring impact and the current retention decision.
  4. Approve anonymization only when the organization’s approved process allows it, or place the review on hold with a reason.

Deletion and anonymization requests

This section lists verified candidate requests and retention reviews waiting for an administrator decision.

  • Review required means the request is ready for review.
  • Review on hold means a recorded legal obligation or approved hold currently prevents a decision.

Select the item to review the candidate, applications, active applications, documents, internal notes, and generated exports affected by the decision.

Visual guide: the Candidate privacy reviews page

Review a deletion or anonymization request

On the request page, read Candidate and impact and Review decision before taking action.

Approve a request

  1. Confirm that there is no approved reason to retain the record.
  2. Review the number of applications and active applications affected.
  3. If active applications exist, read and confirm the additional warning that the candidate’s participation will end.
  4. Select the action that matches the request:
    • Approve permanent deletion for a verified deletion request.
    • Approve anonymization for a retention review without active participation to end.
    • End participation and anonymize when a retention review includes active applications and you have explicitly confirmed that impact.
  5. Review the confirmation message and decision history.

Approval is permanent. Candidate personal data and the account-owned application information described on the review page are removed or anonymized according to the selected action. Use the impact summary before approving.

Decline or hold a request

If the request should not be approved:

  1. Select the reason under Do not delete because for a deletion request, or Do not anonymize because for a retention review.
  2. Choose the appropriate reason, such as Legal obligation or approved hold or Identity could not be confirmed when that choice is available.
  3. Select Record decision for a deletion request or Place on hold for a retention review.

For a request on hold, select Release legal hold only after the approved hold no longer applies. Review the Decision history before making a new decision.

Explain the candidate Privacy area

Candidates open Privacy from the candidate-facing careers site. If they have not verified their email in this browser:

  1. They enter Email address.
  2. They select Email me a secure link.
  3. They open the email and use the link in the same browser.
  4. They review and manage their information.

The link works once and gives that browser access for one hour. The request message is intentionally the same whether or not a matching candidate record exists.

After verification, candidates can see:

  • Your information, including name, email, phone, and headline when available.
  • Your activity, including applications and their current candidate-facing status.
  • Optional retention, where they can select Withdraw consent.
  • Keep your profile available, where they can agree to an offered extension with Extend consent.
  • Your data requests, with Request a copy and Request deletion.
  • Request a correction, which opens an email to the configured privacy contact.

Candidates can withdraw a later extension with Withdraw extension. A deletion request is sent to the company for review; it is not completed automatically.

Visual guide: the candidate Privacy area

Typical privacy workflow

  1. An administrator opens Data privacy and completes the notice for each enabled language.
  2. The administrator sets the Inactivity period and, if needed, enables Extended retention with clear candidate-facing wording.
  3. The administrator selects Save changes and enables GDPR compliance after all requirements are complete.
  4. The administrator reviews Email templates and chooses Manual or Automatic for Sourced candidate notice.
  5. Candidates read the published notice when they apply or use Privacy on the careers site.
  6. A candidate requests a copy, deletion, correction, or a change to optional retention.
  7. The candidate completes email verification through the secure link.
  8. The administrator opens Candidates > Open privacy reviews.
  9. The administrator sends any queued sourced-candidate or retention-consent notice, reviews deletion or anonymization work, and records the outcome.
  10. The administrator checks the Decision history and communicates any follow-up through the configured privacy contact.

Role-aware access

Role or access levelCandidate privacy access you can typically expect
Company administratorConfigure Data privacy, Email templates, and retention settings; open Candidate privacy reviews; send notices and consent requests; and decide deletion, anonymization, or holds.
Content editorCareers-site content access does not include shared privacy administration or privacy-review decisions.
Team member, dedicated team member, limited team member, or reviewerCandidate and application access follows the assigned job or scope, but shared privacy settings and review decisions are not included.
External recruiterUse the separate External recruiter workspace. Candidate privacy administration remains with the company workspace administrators.
CandidateUse the public Privacy area to verify identity, view personal information and applications, request a copy or deletion, request a correction, and manage optional retention choices.

The candidate-facing Privacy area is available only when the relevant careers site and published notice are available. Internal access is also limited to the active company workspace.

Common issues

You are in the wrong company workspace

Privacy settings and review queues belong to the active company workspace. Switch to the correct company before reviewing a request or editing a notice.

You do not see Data privacy or Open privacy reviews

These are administrator controls. Ask a company administrator to confirm your role or perform the action. Changing a candidate’s job access does not grant shared privacy administration.

GDPR compliance cannot be enabled

Complete the legal company name, set the inactivity period, and finish the privacy notice for every required language. Save each language before trying again.

A sourced-candidate notice cannot be sent

Confirm that the candidate has a valid email, the default-language privacy notice is published, and another notice is not already queued or sent. A failed or canceled delivery may show Needs a fresh notice or Retry request.

A retention request is unavailable

The candidate must have an email address, and the published notice must include an active retention choice. Requests for expiring consent are sent only when you select Send request.

The link works once, in the browser that requested it, for one hour. Return to Privacy, enter the email address again, and select Email me a secure link to request a new link.

The candidate cannot find a matching record

The portal intentionally avoids confirming whether an email address matches a record. Ask the candidate to verify the email address used for the application and request a new secure link.

Do not approve it until the organization’s approved process is complete. Review the impact summary, use the active-application confirmation when required, or select Place on hold / Record decision with the appropriate reason.

A retention review closed without changing data

The candidate’s policy, activity, application state, or retention choice may have changed before approval. Return to the review list and check whether a new review item is available.

Last updated on

Was this article helpful?

Your response helps us keep the Help Center useful.

On this page