Data Privacy Fundamentals: GDPR, CCPA, FCRA, and Regional Requirements
Maya runs talent acquisition at Northbridge Analytics, a 700-person software company headquartered in Austin that hires across California, the European Union, and the United Kingdom. On a single Tuesday she opens three candidate files: a data scientist in Munich, a sales engineer in Sacramento, and a finance manager in Manchester. Each is the same kind of human being doing the same kind of job search. But the moment their resumes land in her applicant tracking system, three different bodies of privacy law attach to their data, and Maya is now legally accountable for handling each one correctly. The skill this lesson builds is not memorizing statutes. It is learning to look at any candidate and instantly ask the right question: which law governs this person's data, what is my lawful basis, and what do I owe them at each step?
Why a Recruiter Faces Three Laws at Once
Privacy law is territorial, but it follows the person, not your office. The General Data Protection Regulation (GDPR) protects people whose data is processed in the context of offering them goods or services or monitoring them in the EU and European Economic Area, regardless of where your company sits. Maya's Munich candidate is covered even though Northbridge has no German office. The UK runs its own post-Brexit version, the UK GDPR, sitting alongside the Data Protection Act 2018, so her Manchester candidate is covered by a near-identical but separately enforced regime. California's privacy law protects California residents, and since January 2023 that explicitly includes job applicants and employees, so her Sacramento candidate is in scope. And if any of these three eventually reaches a background check run through a third-party screening company, the federal Fair Credit Reporting Act (FCRA) attaches on top.
The practical consequence is that Maya cannot run one universal process. She runs one disciplined process built around the strictest applicable law and then layers the jurisdiction-specific requirements on top. GDPR is generally the strictest, so building to GDPR and adding FCRA for background checks covers most of the ground. But "mostly compliant" is not a defense, so the details matter. The regulations overlap, they sometimes contradict each other, and they change constantly. The goal of this lesson is not legal advice, which belongs with your legal team, but practical working knowledge: what applies to you, what it requires of you, and where the risk actually sits.
The Privacy Law Landscape
Before mapping any one statute in detail, it helps to see the shape of the field. Privacy regulations affecting recruiting fall into three broad categories, and knowing which category a law belongs to tells you roughly how it will behave. Global regulations attach because of where the candidate is, not where you are. US federal law attaches because of what you are doing, most often running a background check. State-level law attaches because of residency, and it is the fastest-moving layer of the three.
| Category | Regulation | When it applies to recruiting |
|---|---|---|
| Global | GDPR (General Data Protection Regulation) | Applies if you recruit people in the EU or EEA. Strict, with high fines. |
| LGPD (Brazil) | Similar to GDPR in structure. Applies to Brazilian candidate data. | |
| POPIA (South Africa) | A privacy law with direct recruiting implications. | |
| US federal | FCRA (Fair Credit Reporting Act) | Applies to background checks run through a consumer reporting agency. |
| Title VII | Anti-discrimination law, with data privacy implications for what you collect and how you use it. | |
| US state | CCPA (California), VCCPA (Virginia), Colorado and others | Applies based on the candidate's residency, including to job applicants. |
The Concepts Every Recruiter Must Internalize
Underneath the acronyms, the same handful of ideas recur across nearly every privacy regime. Learn these and the laws stop feeling like trivia, because you can predict what a new statute will probably require before you read it.
Lawful basis. You may not process personal data just because you have it; you need a legal reason. Under GDPR you need one of six lawful bases, and for recruiting the realistic choices are consent, legitimate interest, or steps taken to enter a contract. Most recruiting runs on legitimate interest, because consent in a hiring relationship is hard to make genuinely free and a candidate can withdraw it at any time. The other regimes phrase this differently: CCPA is built around consumer opt-in or an applicable exemption, and FCRA requires specific disclosures before you may act at all.
Data subject rights. The person whose data you hold can act on it. Under GDPR these rights are strong: candidates have the right to be informed (Articles 13 and 14), the right of access to a copy of their data (Article 15), rectification, erasure under the right to be forgotten (Article 17), restriction, portability so they receive their data in a machine-readable format, and the right to object to processing. Each of these needs a real internal process with a named owner, not a good intention. Under US laws the equivalent rights are weaker but growing. CCPA and CPRA grant California applicants the right to know, delete, correct, and opt out.
Consent versus legitimate interest. These are two different lawful bases, not synonyms, and confusing them is the most common conceptual error recruiters make. Consent must be a specific, informed, freely given, unambiguous opt-in that the person can withdraw. Legitimate interest lets you process without an opt-in when your interest in evaluating an applicant is balanced against, and not overridden by, their privacy rights. The trade-off is real: legitimate interest requires you to document a balancing assessment, while consent requires you to honor withdrawal instantly. If a candidate tells you they do not consent, legitimate interest is typically the basis you need in order to proceed at all.
Purpose limitation. Data collected for one purpose cannot be quietly repurposed for another without a fresh basis. A resume submitted for a specific engineering role cannot be fed to an unrelated marketing list or sold onward because it happened to be in your system.
Data security. Whatever you hold, you must protect with reasonable technical and organizational measures. What counts as "reasonable" varies by regulation, which is precisely why the standard has to be documented rather than assumed.
Retention limits. You cannot keep candidate data indefinitely, and different regulations set different limits. You may keep data only as long as you have a purpose for it. Once a candidate is not hired, the recruiting purpose ends. A defensible practice is to delete a rejected candidate's data after a defined window, commonly 6 to 12 months, long enough to defend a discrimination claim, unless they have given separate consent to stay in a talent pool.
Cross-border transfer. Moving EU or UK candidate data to the United States, for instance to a US-hosted applicant tracking system, is a restricted transfer. You need a valid mechanism: Standard Contractual Clauses, or reliance on an adequacy decision such as the EU-US Data Privacy Framework where your US vendor is certified.
GDPR in Depth: Six Bases, Four Duties
GDPR applies if you recruit people in the EU or EEA even when your company is not in Europe, and it is both strict and expensive to violate. Beyond honoring the data subject rights described above, four requirements carry most of the operational weight for a recruiter.
Establish a lawful basis and document it. Most recruiting relies on consent or legitimate interest. Consent is risky, because candidates can withdraw it and you must then stop processing. Legitimate interest requires you to balance your interest in hiring against the candidate's privacy rights. In practice, legitimate interest usually survives scrutiny for ordinary recruiting activity, but only if you have written the balancing assessment down before anyone asks for it. An undocumented legitimate interest is functionally the same as no basis at all when a regulator comes calling.
Be transparent. You must tell candidates what data you are collecting, why, how long you will keep it, and what rights they have. Most GDPR-compliant organizations do this with a privacy notice delivered at the start of the recruiting relationship rather than buried in a later step. Transparency is the foundation the rest of the regime rests on, because rights a candidate does not know they have are rights they cannot exercise.
Run a Data Protection Impact Assessment for risky processing. If you are doing anything high-risk, and automated decision-making, large-scale processing, and processing of sensitive data all qualify, you should document your risk analysis before you start. For recruiters, this is the requirement that most directly touches AI: a tool that scores or ranks applicants at scale is exactly the kind of processing a DPIA is designed for. The assessment is also the artifact that demonstrates you thought about the risk rather than discovering it after a complaint.
Get cross-border transfers right. If you transfer candidate data out of the EU, to the United States for example, you need a legal mechanism. Standard Contractual Clauses are common, but the legal landscape here shifted recently and continues to move, so this is a question to put to legal counsel rather than settle from memory or from a vendor's marketing page.
The reason all of this gets attention at the executive level is the penalty exposure. GDPR fines can reach up to 4 percent of global revenue or 20 million euros. That figure is what turns privacy from a recruiting-team preference into a board-level concern.
GDPR, Mapped to Maya's Munich Candidate
Maya's data scientist, Lena, applies through Northbridge's careers page. Here is what GDPR requires at each step, and what Maya actually does.
At collection. Before or at the point Lena submits her resume, Articles 13 and 14 require a privacy notice telling her who the controller is, what data is collected, the purpose, the lawful basis, the retention period, the rights she has, and whether her data will be transferred outside the EEA. Maya's notice states the lawful basis as legitimate interest for assessing applications, backed by a documented balancing test on file. Because Northbridge runs an AI-assisted first-pass screen at volume, a Data Protection Impact Assessment for that processing also sits in the same folder.
During the process. Lena emails to ask what data Northbridge holds on her. That is an Article 15 access request, and Maya must respond within one month, providing a copy of the data and the processing details. Northbridge's applicant tracking system is hosted in the US, so the transfer of Lena's data relies on the vendor's Data Privacy Framework certification, documented in the vendor agreement rather than assumed from a sales conversation.
After a decision. Lena is not selected. The recruiting purpose has ended. Northbridge's retention schedule deletes non-hired EU candidate data after 12 months, the window legal counsel set to cover potential claims. Before deletion Maya offers Lena a separate, optional consent to remain in the talent pool for future roles; only if Lena opts in does her data survive past the window, and she can withdraw that consent anytime. Had Lena instead sent an Article 17 erasure request earlier, Maya would have deleted her data promptly absent a legal reason to retain it.
CCPA, CPRA, and the US State Patchwork
The California Consumer Privacy Act applies if you collect the data of California residents, and similar laws now exist in Virginia, Colorado, and a growing list of other states. The structure differs from GDPR in an important way: California's regime is built primarily on disclosure and opt-out rather than on establishing a lawful basis up front. Four requirements matter most for recruiting.
Notice. You must disclose what personal information you collect, why you collect it, how long you keep it, and what you do with it. Consumer rights. These parallel GDPR but run weaker: consumers can request disclosure of what you hold, request deletion, request correction, and opt out of sale, where "sale" carries a specific statutory definition that is broader than the everyday meaning of the word. Opt-in or opt-out. CCPA is mostly an opt-out regime, meaning you may process data unless someone asks you to stop, while newer state laws are getting stricter and often require opt-in for sensitive processing. Non-discrimination. You may not discriminate against a consumer who exercises their privacy rights, which in a hiring context means you cannot treat a candidate worse because they filed a request.
Penalties under CCPA are less severe than GDPR's but far from trivial: civil penalties run to 2,500 dollars per violation and 7,500 dollars for each intentional violation. Because those are assessed per consumer, the exposure scales quickly across an applicant pool of any size.
CCPA and CPRA, Mapped to the Sacramento Candidate
Marcus, the Sacramento sales engineer, is a California resident, so the California Consumer Privacy Act as amended by the California Privacy Rights Act applies to him as a job applicant. At or before the point Northbridge collects his information, it must give a notice at collection listing the categories of personal information collected, the purposes, and the retention period for each category. If Northbridge collects sensitive personal information, defined to include data such as government identifiers, precise geolocation, or racial or ethnic origin, that category must be called out, and Marcus has the right to limit its use to what is necessary.
In practice, Marcus can submit a request to know what Northbridge has collected and a request to delete it, and Maya must verify his identity and respond within 45 days, extendable once. He can request correction of inaccurate data. He also cannot be retaliated against for exercising these rights, so Maya cannot quietly drop a candidate for filing a request, and she cannot let a request influence how the hiring team scores him.
FCRA: The Background Check Regime
FCRA is the US federal law regulating background checks, and it attaches the moment a third-party screening company, a consumer reporting agency in the statute's language, is involved. Six requirements define the regime.
Disclosure and authorization. Before running a background check, you must disclose in writing that you may obtain a consumer report, and you must obtain written authorization from the candidate. Adverse action. If you are going to reject someone based wholly or partly on background check information, you must provide them the report and a chance to dispute it. You cannot simply reject them without letting them respond. Dispute rights. Candidates can dispute inaccurate information on the report, and that right is meaningless unless the timing of your process leaves room for it. Accuracy responsibility. You, the employer, are responsible for inaccuracy in the reports you use. Outsourcing the search does not outsource the accountability. Scope limits. Different states limit how far back you can look for criminal history; seven years is a common ceiling, though there are exceptions. Ban-the-box. Many jurisdictions have "ban the box" laws restricting when you may ask about criminal history at all, usually not until after an initial interview.
Four violations account for most of the litigation in this area, and all four are procedural rather than substantive, which means they are entirely avoidable with a disciplined process: running background checks without written authorization; not disclosing that you will use a background check; taking adverse action without giving the candidate a chance to dispute; and using information such as criminal history in a way that runs contrary to the applicable regulations. None of them require bad intent; they happen when a recruiter treats a background check as routine administration rather than a regulated sequence.
FCRA, When a Background Check Enters the Picture
Maya's finance manager finalist, Priya in Manchester, will sit in a US-facing role and Northbridge wants a background check through a consumer reporting agency. The instant a third-party screening company is involved, FCRA governs the US side of that check, and its sequence is rigid.
Standalone disclosure. Before the check, Northbridge must give Priya a clear, conspicuous disclosure, in a document that consists solely of that disclosure, stating a consumer report may be obtained for employment purposes. Courts have repeatedly held that burying this disclosure inside an application or padding it with extra waivers violates the standalone requirement.
Written authorization. Priya must then give written authorization before the report is requested. No authorization, no report.
Pre-adverse and adverse action. Suppose the report surfaces something concerning. Before rejecting Priya based wholly or partly on it, Maya must send a pre-adverse action notice that includes a copy of the report and a summary of the candidate's FCRA rights, then wait a reasonable period, commonly around five business days, so Priya can dispute inaccuracies. Only after that, if the decision stands, does Maya send the adverse action notice naming the agency and confirming the agency did not make the decision. Skipping the pre-adverse step is one of the most litigated FCRA violations in hiring, and it is usually skipped because the team was in a hurry to close the role.
Beyond the Big Three: Regional Requirements
GDPR, CCPA, and FCRA cover most of the ground for a US company hiring in Europe and California, but recruiters with a wider footprint meet several more regimes. None of them require memorization; what they require is the reflex to check before you post a role into a new market.
| Region | Regime | What to expect |
|---|---|---|
| Canada | PIPEDA, plus provincial privacy laws | Similar to GDPR in philosophy, less prescriptive in practice. |
| United Kingdom | UK GDPR | After Brexit, GDPR still applies but with some UK-specific modifications. |
| Australia | Privacy Act | Less strict than GDPR, but requires reasonable protections. |
| Japan | APPI (Act on Protection of Personal Information) | Recent updates increased protections. |
| Brazil | LGPD | Similar to GDPR; applies to Brazilian candidate data. |
| South Africa | POPIA | A privacy law with direct recruiting implications. |
One Candidate, Tracing Every Layer
To see how the layers stack, follow a single candidate, Priya, all the way through. She applies from Manchester, so UK GDPR attaches: she gets an Article 13 notice at collection, Northbridge processes on documented legitimate interest, and her data moving to the US applicant tracking system relies on a Standard Contractual Clauses agreement with the vendor. She progresses to finalist, and because the role touches US operations Northbridge orders a background check, so FCRA now attaches on top of UK GDPR: standalone disclosure, written authorization, and the pre-adverse and adverse action sequence if anything turns up. Had Priya instead been the Sacramento candidate, CCPA and CPRA would have replaced UK GDPR at the front of the journey, with a notice at collection and a 45-day response window for any right-to-know or deletion request, while FCRA attached identically at the background-check stage.
The candidate journey is the same shape every time. What changes is which front-end privacy regime governs collection and rights, while FCRA bolts on consistently the moment a consumer reporting agency is used. Maya's job is not to be a lawyer. It is to recognize the pattern, run the strictest-applicable-law process by default, document her lawful basis and retention schedule, and escalate the genuinely hard calls to legal counsel.
An Eight-Step Compliance Framework
If you recruit across regions, the following sequence turns the preceding material into a working program. It is deliberately ordered, because several of the steps are impossible to do well before the ones above them are finished.
- Map your jurisdictions. Where are your candidates actually located, and which regulations follow from that? This is the question every later step depends on.
- Identify the most restrictive regime. GDPR is generally the most restrictive, and if you comply with GDPR you are mostly compliant elsewhere. "Mostly" is doing real work in that sentence, so still check the specific state laws that apply to you.
- Document your legal basis. For each region, write down what your basis for processing candidate data is: consent, legitimate interest, or contractual necessity. Undocumented reasoning is not a basis.
- Implement privacy practices. The privacy notice, the data security measures, the retention schedule, and the consent mechanisms are the operational output of the steps above.
- Train your team. Recruiters are the people who actually collect, share, and delete candidate data day to day, so a policy no recruiter has read protects nobody.
- Manage your vendors. If you use recruiting tools, background check providers, or assessment platforms, confirm they comply and sign appropriate agreements. Their processing is still your accountability.
- Handle candidate requests. Build a real process for access, deletion, correction, and portability requests, and note that the timelines differ by regime: GDPR is 30 days, CCPA is 45.
- Stay updated. Privacy law is evolving rapidly. Subscribe to updates and consult legal counsel on a regular cadence rather than only in a crisis.
One theme runs through all eight steps: privacy compliance is not only a legal obligation, it is brand protection. When candidates trust that their data is handled responsibly, your reputation improves and you attract better candidates.
Three Anti-Patterns
Compliance theater. The team has privacy policies and consent checkboxes that satisfy the letter of the law and none of its spirit. Candidates click "I agree" without understanding what they are agreeing to. It happens because compliance feels like checking a box, and a checked box produces documented consent that looks reassuring in an audit folder. What goes wrong is that regulators are not fooled: consent that is not meaningful does not meet the legal standard for consent, and a defense built on it collapses under inspection. The fix is genuine transparency and genuine consent mechanisms rather than compliance decoration, which usually means shorter notices in plain language and a real choice attached to them.
Background check neglect. The team runs background checks without proper disclosure, or rejects candidates on report contents without giving them a chance to dispute. It happens because background checks feel routine and administrative, so everyone assumes the vendor's workflow is handling FCRA for them. What goes wrong is that FCRA violations lead to lawsuits, and candidates can sue directly. The fix is procedural and non-negotiable: always obtain written authorization before running a check, and always send the pre-adverse action notice with a copy of the report and a real window to dispute before any adverse decision is finalized.
The international assumption. The team assumes US privacy rules apply globally, or assumes GDPR cannot apply to a company with no European office. It happens because international recruiting feels complex and simplified rules are more comfortable than accurate ones. What goes wrong is straightforward exposure to fines under GDPR or a regional law. The fix is to map candidate locations, consult legal counsel on which regulations apply, and implement the most restrictive rules universally, so that a candidate arriving from an unexpected jurisdiction does not become an incident.
Practice
- Map your regulations. Write down where your candidates are geographically located over the past year. Which regulations apply as a result: GDPR, CCPA, other state laws, FCRA?
- Audit your legal basis. For your main recruiting activities, document the basis you are relying on. Consent, legitimate interest, or contract? Are you comfortable defending that choice in writing, and does a written balancing assessment exist?
- Review your privacy notice. Do you provide one to candidates? Does it explain what data you collect, why, how long you keep it, and what rights they have? Hand it to a non-lawyer and ask them to explain it back to you.
- Audit your background check process. Document each step: do you disclose in writing, obtain written authorization, send a pre-adverse action notice, and give candidates a real chance to dispute before the decision is final?
- Review your vendor agreements. List every recruiting tool, background check provider, and assessment vendor that touches candidate data. Do the agreements include data protection clauses, and when were they last reviewed?
Reflection
- Which regulations apply to your candidate pool right now, and are you genuinely clear on the answer or working from an assumption?
- What is your current legal basis for processing candidate data, and could you defend it to a regulator with the documentation you have today?
- Do you have documented processes for handling candidate privacy requests for access, deletion, and correction, including who owns the response clock?
- If you use background checks, is your disclosure genuinely standalone, and does your timeline leave real room for a candidate to dispute before you decide?
- Are your vendor agreements adequate for data protection, and when did you last read one?
Glossary
- GDPR. General Data Protection Regulation. Applies to EU and EEA candidates. Strict, with high fines.
- CCPA. California Consumer Privacy Act. Applies to California residents, including job applicants. Less strict than GDPR, but growing.
- FCRA. Fair Credit Reporting Act. US federal law regulating background checks run through consumer reporting agencies.
- Legal basis. The legal justification for processing candidate data. GDPR requires one of six: consent, contract, legal obligation, vital interests, public task, or legitimate interest.
- Data subject rights. Candidate rights regarding their own data: access, correction, deletion, portability, and objection.
- Adverse action notice. The FCRA requirement to notify candidates when you are rejecting them based on background check information.
- Ban the box. Laws restricting when you may ask about criminal history, usually not until after an initial interview.
- Data Protection Impact Assessment. A required risk analysis for high-risk processing, especially processing involving automated decision-making.
- Standard Contractual Clauses. A legal mechanism for transferring EU candidate data outside the EU.
Related Lessons
- Consent and Transparency: What Candidates Need to Know goes deeper on the notice and consent mechanics this lesson treats as a single requirement.
- Data Minimization: Collecting Only What's Necessary works the purpose-limitation principle into concrete decisions about what to collect in the first place.
- Retention and Deletion: Reasonable Timelines and Clean Data Practices turns the retention-window question into an operational schedule.
- Third-Party Tools and Vendors: Due Diligence and Contracts covers the vendor management step of the compliance framework in depth, including data protection clauses.
- Compliance and Legal Review: Documentation for FCRA, EEO, and GDPR maps what your documentation has to prove in each regulatory regime.
- Hands-On Project: Audit a Recruiting Process for Privacy Risks is where you apply this framework end to end against your own funnel.
Closing
Privacy compliance protects candidates and it protects your organization, and the practical approach is the same either way: know which regulations apply to you, implement practices that genuinely comply with them rather than gesture at compliance, and document what you did. Consult legal counsel, stay updated, and train your team, because privacy compliance is an ongoing practice rather than a one-time project. Maya's Tuesday morning is not unusual; it is what modern recruiting looks like, and the recruiters who handle it well are the ones who built the reflex of asking, for every candidate, which law follows this person and what do I owe them at each step.
Key Takeaways
- The law follows the candidate, not your office. GDPR covers EU and EEA candidates wherever your company sits, UK GDPR covers UK candidates, CCPA and CPRA cover California residents including job applicants since 2023, and FCRA attaches the moment a consumer reporting agency runs a background check. Compliance varies significantly by regulation, GDPR is the most restrictive, and hiring across regions means several regimes apply to the same workflow at once.
- Lawful basis comes before processing, and legitimate interest is usually the right one for recruiting. Consent in a hiring context is hard to make freely given and can be withdrawn, so most GDPR recruiting relies on a documented legitimate-interest balancing assessment rather than an opt-in checkbox. Do not assume checkboxes equal compliance.
- Transparency is the foundation. Candidates need to understand what data you are collecting and why, which is what a privacy notice delivered at the start of the process is for.
- Data subject rights are operational, not theoretical. GDPR access requests under Article 15 get a one-month response and erasure requests under Article 17 must be honored absent a legal reason to retain; CCPA know and delete requests get 45 days. Build a process to verify identity and respond on time.
- Document risky processing before you start it. Automated decision-making, large-scale processing, and sensitive data all call for a Data Protection Impact Assessment, which is the requirement AI-assisted screening most directly triggers.
- Retention has an end date and security has a standard. When a candidate is not hired the purpose ends, so delete after a defined window, commonly 6 to 12 months, unless the candidate gives separate withdrawable consent to a talent pool. Protect what you hold with reasonable measures, and document what "reasonable" means for you.
- FCRA's background-check sequence is rigid, and the employer owns the outcome. Standalone disclosure, written authorization, pre-adverse action notice with a copy of the report and a chance to dispute, then the adverse action notice. You are responsible for inaccuracy in reports you use, state scope limits apply to criminal history lookback, and ban-the-box laws govern when you may ask at all.
- Cross-border transfer needs a mechanism. Moving EU or UK data to a US system requires Standard Contractual Clauses or reliance on the EU-US Data Privacy Framework with a certified vendor. Confirm it in the vendor agreement, do not assume it.
- Run the strictest applicable law by default and escalate the hard calls. Map jurisdictions, document your basis and retention, train the team, manage vendors, build a request-handling process, and send genuinely difficult questions to legal counsel. Privacy law changes fast, so this is a standing practice.
Frequently Asked Questions
Our company has no European office. Does GDPR really apply to us? It can, and assuming otherwise is one of the three anti-patterns in this lesson. GDPR follows the person, protecting people whose data is processed in the context of offering them goods or services or monitoring them in the EU and EEA, regardless of where the processing organization sits. If you accept applications from candidates in the EU, assume you are in scope and confirm with counsel rather than the reverse.
Should we rely on consent or legitimate interest for candidate data under GDPR? Most recruiting relies on legitimate interest, because consent in a hiring relationship is difficult to make genuinely free and a candidate can withdraw it at any moment, at which point you must stop processing. It usually survives scrutiny for ordinary recruiting activity, but requires a documented balancing assessment weighing your interest in evaluating applicants against the candidate's privacy rights. If a candidate explicitly says they do not consent, legitimate interest is typically the basis you need in order to continue at all.
The background check vendor handles the FCRA paperwork. Is that enough? No. FCRA places accuracy responsibility on the employer for reports it uses, and the disclosure, authorization, and adverse action steps are your obligations even when a vendor supplies the templates. The most litigated failure in hiring is skipping the pre-adverse action notice, which no vendor can do for you because it is tied to your decision. Verify the sequence yourself, and confirm your vendor agreement includes data protection clauses.
Do the response deadlines differ between regimes? Yes, and this is a common operational trap. GDPR access requests carry a one-month response window, generally described as 30 days, while CCPA requests to know or delete carry 45 days, extendable once. A single shared inbox running one universal service-level target will eventually miss a deadline in one regime or the other, so route requests by the law that governs the candidate.
Skill.re