Candidate Privacy and Data Requests
Manage candidate privacy settings and respond to copy, correction, deletion, and retention requests.
The recruiting application gives candidates a public Privacy area on the careers site. Candidates can use it to review the information connected to their email address, request a private copy, ask for deletion, request a correction, and manage any optional choice to keep their profile available for future opportunities.
Administrators use Data privacy and Candidate privacy reviews to publish the notice candidates see, define retention review settings, send notices to sourced candidates, and make decisions about verified deletion or anonymization requests.
Prerequisites
Before you configure or review candidate privacy, make sure that:
- You can sign in to the recruiting application.
- You are working inside the correct company workspace.
- You are a company administrator. Privacy settings and privacy reviews are shared workspace controls.
- You know the legal company name, privacy contact email, supported careers-site languages, and the retention policy your organization wants to communicate.
- You understand that deletion and anonymization decisions can permanently remove candidate information and should follow your organization’s approved process.
Visual guide: the Data privacy settings
How candidate privacy works
The workflow has four parts:
- You prepare and publish a privacy notice in Data privacy.
- Candidates read the notice when they apply or visit Privacy on the careers site.
- Candidates use a secure, one-time link to access their own information and submit requests.
- You review the resulting work in Candidate privacy reviews and record the appropriate decision.
The application keeps these steps separate. A candidate’s request is not an automatic instruction to delete data, and an inactivity date creates a review item rather than deleting a record automatically.
Set up the privacy notice
- Open Settings > Data privacy.
- Select the language you want to edit under Privacy notice language.
- Complete the notice fields:
- Legal company name
- Privacy contact email
- Notice title
- Privacy policy text
- Review the Data retention choices.
- Select Save changes.
- Repeat the process for every enabled language.
Each language can show a status such as Published, Ready, Draft changes, Needs attention, or Incomplete. Review every language before enabling the privacy workflow. The notice shown to a candidate follows the language of the careers site and application experience where that version is available.
Configure data retention
Use Inactivity review to set the Inactivity period. This flags inactive candidate records for administrator review after the approved period when valid retention consent is not available. It does not delete or anonymize the record by itself.
Use Extended retention when candidates should be able to choose to keep their profile available after a hiring process ends. When enabled, complete:
- Retention period
- Retention choice label
- Retention choice explanation
The explanation should tell candidates what the choice means and how long the additional period lasts.
If your account includes more than one company workspace, Require consent for cross-company sharing can prevent candidate data from being copied to another company until a current consent grant exists.
Activate the privacy workflow
The GDPR compliance control activates the saved notices and related privacy and retention workflows.
- Complete the required Legal company name.
- Set the Inactivity period.
- Complete the notice for every required language.
- Save the changes.
- Enable GDPR compliance.
If the control is unavailable, the page identifies the missing requirement. Disabling the control preserves existing privacy records but stops the active workflow from being used for new processing.
Configure privacy communications
Open Settings > Email templates to review the candidate-facing application confirmation and privacy messages. Review each available language so candidates receive clear instructions and the correct privacy contact.
The same area includes Sourced candidate notice. Choose a Sending mode:
- Manual lets you review each candidate added outside the application form and choose Send notice.
- Automatic queues the published notice for every newly sourced candidate. Existing sourced candidates remain in the review list.
Automatic is available only after the default-language privacy notice is complete and published. Save the selected mode before relying on it for new sourced candidates.
Review privacy work in the workspace
- Open Candidates.
- Select Open privacy reviews.
- Review the section that matches the work you need to complete.
The Candidate privacy reviews page includes:
Sourced candidate notices
Use this section for candidates added outside the application form.
- Review whether a notice is Not sent, Notice queued, Delivery failed, or Needs a fresh notice.
- Select Send notice when a published notice and a valid candidate email are available.
- Open Recent notice activity to check recent manual or automatic deliveries.
If the candidate has no email address, or the default-language notice is not published, the application keeps the action unavailable until the missing requirement is fixed.
Consent expiring soon
This section shows optional retention consent ending in the next 30 days. Requests are not sent automatically.
- Confirm the candidate email address.
- Select Send request.
- Check for Queued, Sent, or Retry request status.
The candidate can then decide whether to extend the optional retention period from the Privacy area.
Needs retention review
This section shows inactive records that reached the approved review date. Nothing is anonymized automatically.
- Review the candidate and the Last activity and review due dates.
- Select Review anonymization.
- Review the candidate’s hiring impact and the current retention decision.
- Approve anonymization only when the organization’s approved process allows it, or place the review on hold with a reason.
Deletion and anonymization requests
This section lists verified candidate requests and retention reviews waiting for an administrator decision.
- Review required means the request is ready for review.
- Review on hold means a recorded legal obligation or approved hold currently prevents a decision.
Select the item to review the candidate, applications, active applications, documents, internal notes, and generated exports affected by the decision.
Visual guide: the Candidate privacy reviews page
Review a deletion or anonymization request
On the request page, read Candidate and impact and Review decision before taking action.
Approve a request
- Confirm that there is no approved reason to retain the record.
- Review the number of applications and active applications affected.
- If active applications exist, read and confirm the additional warning that the candidate’s participation will end.
- Select the action that matches the request:
- Approve permanent deletion for a verified deletion request.
- Approve anonymization for a retention review without active participation to end.
- End participation and anonymize when a retention review includes active applications and you have explicitly confirmed that impact.
- Review the confirmation message and decision history.
Approval is permanent. Candidate personal data and the account-owned application information described on the review page are removed or anonymized according to the selected action. Use the impact summary before approving.
Decline or hold a request
If the request should not be approved:
- Select the reason under Do not delete because for a deletion request, or Do not anonymize because for a retention review.
- Choose the appropriate reason, such as Legal obligation or approved hold or Identity could not be confirmed when that choice is available.
- Select Record decision for a deletion request or Place on hold for a retention review.
For a request on hold, select Release legal hold only after the approved hold no longer applies. Review the Decision history before making a new decision.
Explain the candidate Privacy area
Candidates open Privacy from the candidate-facing careers site. If they have not verified their email in this browser:
- They enter Email address.
- They select Email me a secure link.
- They open the email and use the link in the same browser.
- They review and manage their information.
The link works once and gives that browser access for one hour. The request message is intentionally the same whether or not a matching candidate record exists.
After verification, candidates can see:
- Your information, including name, email, phone, and headline when available.
- Your activity, including applications and their current candidate-facing status.
- Optional retention, where they can select Withdraw consent.
- Keep your profile available, where they can agree to an offered extension with Extend consent.
- Your data requests, with Request a copy and Request deletion.
- Request a correction, which opens an email to the configured privacy contact.
Candidates can withdraw a later extension with Withdraw extension. A deletion request is sent to the company for review; it is not completed automatically.
Visual guide: the candidate Privacy area
Typical privacy workflow
- An administrator opens Data privacy and completes the notice for each enabled language.
- The administrator sets the Inactivity period and, if needed, enables Extended retention with clear candidate-facing wording.
- The administrator selects Save changes and enables GDPR compliance after all requirements are complete.
- The administrator reviews Email templates and chooses Manual or Automatic for Sourced candidate notice.
- Candidates read the published notice when they apply or use Privacy on the careers site.
- A candidate requests a copy, deletion, correction, or a change to optional retention.
- The candidate completes email verification through the secure link.
- The administrator opens Candidates > Open privacy reviews.
- The administrator sends any queued sourced-candidate or retention-consent notice, reviews deletion or anonymization work, and records the outcome.
- The administrator checks the Decision history and communicates any follow-up through the configured privacy contact.
Role-aware access
| Role or access level | Candidate privacy access you can typically expect |
|---|---|
| Company administrator | Configure Data privacy, Email templates, and retention settings; open Candidate privacy reviews; send notices and consent requests; and decide deletion, anonymization, or holds. |
| Content editor | Careers-site content access does not include shared privacy administration or privacy-review decisions. |
| Team member, dedicated team member, limited team member, or reviewer | Candidate and application access follows the assigned job or scope, but shared privacy settings and review decisions are not included. |
| External recruiter | Use the separate External recruiter workspace. Candidate privacy administration remains with the company workspace administrators. |
| Candidate | Use the public Privacy area to verify identity, view personal information and applications, request a copy or deletion, request a correction, and manage optional retention choices. |
The candidate-facing Privacy area is available only when the relevant careers site and published notice are available. Internal access is also limited to the active company workspace.
Common issues
You are in the wrong company workspace
Privacy settings and review queues belong to the active company workspace. Switch to the correct company before reviewing a request or editing a notice.
You do not see Data privacy or Open privacy reviews
These are administrator controls. Ask a company administrator to confirm your role or perform the action. Changing a candidate’s job access does not grant shared privacy administration.
GDPR compliance cannot be enabled
Complete the legal company name, set the inactivity period, and finish the privacy notice for every required language. Save each language before trying again.
A sourced-candidate notice cannot be sent
Confirm that the candidate has a valid email, the default-language privacy notice is published, and another notice is not already queued or sent. A failed or canceled delivery may show Needs a fresh notice or Retry request.
A retention request is unavailable
The candidate must have an email address, and the published notice must include an active retention choice. Requests for expiring consent are sent only when you select Send request.
A candidate’s secure link expired or does not work
The link works once, in the browser that requested it, for one hour. Return to Privacy, enter the email address again, and select Email me a secure link to request a new link.
The candidate cannot find a matching record
The portal intentionally avoids confirming whether an email address matches a record. Ask the candidate to verify the email address used for the application and request a new secure link.
A request needs legal review or includes active applications
Do not approve it until the organization’s approved process is complete. Review the impact summary, use the active-application confirmation when required, or select Place on hold / Record decision with the appropriate reason.
A retention review closed without changing data
The candidate’s policy, activity, application state, or retention choice may have changed before approval. Return to the review list and check whether a new review item is available.
Last updated on
Was this article helpful?
Your response helps us keep the Help Center useful.