Hands-On Project: Audit a Recruiting Process for Privacy Risks
Follow Theo, a talent ops lead at a 400-person SaaS company, as he maps the candidate data lifecycle, finds resumes retained five years past rejection with no legal basis, and builds a retention schedule that holds up under GDPR and CCPA.
Theo leads talent operations for a 400-person SaaS company with candidates in both the United States and the European Union, and for years he assumed his recruiting data was somebody else's problem. The applicant tracking system was secure, the vendor was reputable, and that was that. Then a rejected candidate in Berlin sent a one-line email exercising her right to erasure under GDPR, asking the company to delete everything it held about her. Theo went looking for "everything," and the search took him three days. Her resume was in the ATS, but it was also in two hiring managers' email inboxes, in an exported spreadsheet on a shared drive, in a team chat thread, and in a screening assessment vendor's system he had no visibility into. He could not honestly confirm deletion because he could not even confirm where the data lived. That request did not create a privacy problem. It revealed one that had been there the whole time. This project is the audit Theo wishes he had run a year earlier: a systematic walk through the candidate data lifecycle to find out what you collect, where it goes, who can reach it, how long you keep it, and what risk that exposes.
What a Privacy Audit Actually Does
A privacy audit is not a legal opinion and it does not require a consultant. It is a disciplined inventory: you map the data a candidate generates from application through closure, follow each piece to every place it lands, record who can access it and how long it survives, and then rate the risk of what you find. The output is two things at once, a clear picture of your current state and a roadmap for fixing it, and that documentation is also your evidence, if a regulator or a candidate ever asks, that you took privacy seriously.
The discipline behind the audit comes from a small set of data-protection principles that GDPR and CCPA share. Data minimization says collect only what you actually need for the decision. Purpose limitation says use data only for the reason you collected it. Storage limitation, or retention limits, says keep it only as long as that purpose requires. And both regimes give candidates rights over their data, including, under GDPR, the right to erasure that started Theo's whole ordeal. An audit is just these principles turned into a checklist you run against your real process.
The work is not complicated, but it demands thoroughness, and that is the whole trade. Most recruiting teams have no clear picture of what they collect, where it lives, who touches it, how long they keep it, or what risk that creates, and the reason is rarely negligence. It is that nobody has ever sat down and traced it end to end. When you do, the picture stops being a feeling and becomes a document you can act on.
Phase 1: Map the Candidate Data Lifecycle
Theo starts by drawing the process end to end, because you cannot protect data you have not located. The stages are familiar: a candidate applies, a recruiter reviews, the candidate completes an assessment, interviews happen, an offer is made, the offer is accepted or declined, and the file is either moved to onboarding or closed. At each stage he writes down what data is created. The application stage captures a resume, contact details, work history, and any demographic data collected for EEO reporting. The assessment stage captures test results and, because his vendor uses recorded video screens, video files. The interview stage captures panel feedback and, for some roles, background-check results. The offer stage captures tax forms and the signed acceptance or the recorded decline.
The key move is to inventory intermediate data, not just the data that drives the final decision. A pipeline that produces ten data points for the actual hiring call might generate fifty along the way, and every one of those fifty is something the company now holds and is responsible for. The forgotten forty are usually where the risk hides.
Phase 2: Track Storage, Access, and Transmission
For each data element, Theo answers three questions. Where does it live? Who can reach it? How does it move? The first question forces him past the comfortable answer of "the ATS." A resume in the ATS is also, in practice, in the inboxes of everyone it was forwarded to, in any spreadsheet it was exported into, on any shared drive or local laptop that copy landed on, and in any chat channel where it was discussed. The second question separates scoped access from open access: can a hiring manager see only their assigned candidates, or can anyone with a login browse the entire pipeline? The third question traces transmission, and this is where the unencrypted email forwards and the casual chat shares surface.
When Theo runs this on his own process, the access map is the part that unsettles him. Interview notes for one engineering role were being posted in a general hiring chat channel that thirty people could read, far more than the four who needed them. The principle being violated is purpose limitation: data collected to make one hiring decision had become casually visible to a third of the company. Mapping it is what made it fixable.
Phase 3: Assess Retention and Deletion
This is where most teams discover their largest exposure, and Theo is no exception. He asks the uncomfortable questions. How long do you keep rejected candidates' data? When you hire someone, what happens to the competing candidates' files? What becomes of background-check results after a hire? The honest answer at his company is the answer at most companies: nothing is ever deleted. Everything is kept indefinitely, by default, because no one decided otherwise.
Indefinite retention is not a neutral convenience. It is a direct violation of the storage-limitation principle, and every record kept past its purpose is standing liability with no offsetting benefit. The fix is an explicit, written retention schedule with a defensible basis for each timeline. Theo's draft reads: rejected-candidate data retained for twelve months to cover the window for discrimination claims, then deleted; background-check results, which carry their own legal retention obligations, retained per that legal hold and then deleted; offer decisions documented and retained for one year, then purged from the recruiting system. The first step is simply to document the current state, because "we keep everything indefinitely" is itself a finding worth writing down.
Phase 4: Identify and Rate the Risks
With the maps of flow, storage, access, and retention in hand, Theo names the risks and rates each one High, meaning act now; Medium, meaning address soon; or Low, meaning monitor. Six categories cover most of what he finds. Unauthorized access: resumes in shared drives and personal inboxes that anyone can open, which candidates never consented to. Unnecessary collection: demographic fields the company gathers but never uses, age inferred from a graduation date, or social profiles nobody will look at, all straight violations of data minimization. Inadequate security: candidate data moving over unencrypted email, sitting on a laptop with no password, or held on a device that is never backed up. Unclear retention: the indefinite-retention finding from Phase 3, which he rates High, because data with no deletion date is liability with no end date. Vendor risk: his assessment, video, and background-check vendors hold candidate data under contracts no one has read closely, so their practices, not his, may define his actual privacy posture. And cross-border transfer: because he has EU candidates, GDPR applies, and any transfer of their data to the United States needs a lawful basis he has not yet confirmed.
Phase 5: A Worked Finding and Its Remediation
The clearest finding from Theo's audit is also the one that demonstrates the whole method. Tracing the resume data element through its lifecycle, he discovers that the ATS had been configured to never auto-purge, so rejected candidates' resumes were sitting in the system roughly five years past the rejection date. He checks each principle against that fact. Purpose limitation: the purpose, evaluating those candidates for specific roles, ended years ago. Storage limitation: there is no retention schedule justifying five years. Legal basis: there is none; the only legal hold that would justify multi-year retention applies to background-check records, not resumes. The finding writes itself: roughly 4,000 rejected-candidate resumes retained about five years past rejection with no legal basis, a violation of both GDPR storage limitation and CCPA's expectation of deletion on request, rated High.
The remediation is just as concrete. Theo configures an automated purge in the ATS to delete rejected-candidate records twelve months after rejection, runs a one-time cleanup of the existing five-year backlog, builds a documented process to honor erasure and deletion requests across every system the audit surfaced, not just the ATS, and assigns the work. Owner: Theo, with Legal reviewing the twelve-month basis. Timeline: cleanup within two weeks, automated purge within one month. The finding moves from a paragraph in a report to a closed item with a date and a name attached, which is the only kind of finding that actually reduces risk.
Phase 6: Recommendations and the Action Plan
Every risk becomes a recommendation that is specific, assigned, and timed, because a recommendation without an owner and a date is a wish. Resumes in personal email move to the ATS with access controls, owned by the recruiting manager, within two weeks. Unused demographic fields come off the application form, owned by HR, within one week. The missing retention policy becomes a written schedule, owned jointly by Legal and HR, within one month. Then Theo prioritizes: highest risk and easiest first, so the indefinite-retention fix and the access-control cleanup lead, while the cross-border transfer question, which needs legal review, runs in parallel on a longer track. Some items he can do the same afternoon, some wait on a vendor, and some cannot move until counsel weighs in, so the plan carries a realistic timeline rather than a wish list of due dates. He sets a monthly check-in to track progress, because the most common way an audit fails is the one covered next.
Phase 7: Write the Audit Report
The last phase is the one people skip, and it is the phase that converts weeks of tracing into something durable. Theo writes a single report that pulls together everything the earlier phases produced: the current-state process map, the data inventory, the access map, the retention timeline, the identified risks with their severity ratings, the recommendations with their owners and deadlines, and the action plan with its progress tracking. Nothing in the report is new work. It is the assembly of what he already found, organized so that someone who was not in the room can follow it.
That document does double duty. It is your compliance foundation, the artifact you hand to a regulator, an auditor, or opposing counsel to show that privacy was a deliberate consideration rather than an accident, and it is simultaneously your roadmap, the thing you reopen next quarter to see what closed and what did not. Write it once, keep it current, and the next audit becomes an update rather than a rebuild.
Anti-Patterns That Waste the Audit
Three failure modes undo an otherwise solid audit. The first is audit without action: you map everything, write the report, file it, and change nothing, so the risks survive intact while you feel productive. This happens because the audit starts to feel like the destination rather than the starting line, and the consequence is that nothing improves and no liability goes away. The defense is to plan the action plan before you start and to budget time and resources for fixing findings, not just naming them. The second is auditing only the technology and not the process: you confirm the ATS has access controls and overlook that interview notes live in a chat channel and resumes ride around in email. Technology is visible and processes are assumed, which is exactly why the biggest exposures are almost always in the manual handling outside the formal systems, so the map has to include every human step. The third is ignoring vendor risk: you discipline your own retention while your assessment vendor keeps candidate video forever, which makes their policy your real policy. Contracts exist but nobody rereads them, so the defense is to audit the contracts specifically for what each vendor keeps, for how long, who can access it, and what security wraps it.
Fitting the Audit to Your Own Organization
The method is the same everywhere, but what you can realistically achieve is not, and five contextual factors decide how far you get. Your organizational maturity comes first: a startup may be building basic systems for the first time while a larger company is optimizing ones it already has, and an audit plan that ignores the difference sets a target nobody can hit. Understand your starting point and pick what is achievable from there.
Your competitive context matters next. In a tight labor market where competitors are not doing this work, being first with fair, disciplined practice widens the talent pool you can credibly reach, and if you are competing on cost you will need to show a return on the effort rather than assert one. Your candidate population matters too. International candidates often arrive with different privacy expectations than domestic ones, entry-level candidates have different communication preferences than senior ones, and timelines differ across both, so design the practice around the people you actually recruit. Your technology context can constrain you outright: if your current ATS cannot support the access controls or automated purges the audit recommends, the fix is a system change with a budget line, not a policy memo. And your people context decides whether any of it sticks, because your team's skills, experience, and willingness to change determine adoption. Invest in training and support alongside the systems, or you will have built capability on paper only.
Defining What Success Means
Success from this work looks different in different organizations. For some it shows up as improved hiring diversity, for others as better quality of hire or faster time to fill, and for others as a stronger candidate experience or reduced legal risk. Decide which of those outcomes actually matter to your organization before you start measuring, then choose the metrics that would show whether you achieved them.
Then track those metrics over time rather than expecting an immediate verdict. Some changes take several hiring cycles before a pattern is visible, so patience and persistence are part of the method. Theo's monthly check-in exists for exactly this reason: it keeps a slow-moving improvement visible instead of letting it disappear between quarterly reviews.
Keeping the Practice Alive
Nothing in this project is a final answer. Recruiting practice keeps evolving, AI capabilities keep improving, and legal requirements keep changing, so what works today may not work in five years. The durable asset is not the report; it is the habit of looking. Stay curious about what is working and what is not, try new approaches, learn from the results, share what you learn with your team and with colleagues across the industry, and stay honest about what you do not yet know. That mindset is what turns recruiting from a static process into a practice that improves on purpose, and it is why privacy compliance is best understood as iterative: map the current state, fix the highest risks, then audit again.
Practice
Work these against your own process rather than a hypothetical one, because the value of this project comes entirely from what you find in your own systems.
- Map your current process. Document your recruiting process step by step, and for each stage record what data is collected, where it is stored, and how it is transmitted.
- Run an access audit. For each data element, write down who has access, whether they can reach only their assigned candidates or the whole pipeline, and whether that access is restricted or effectively open.
- Draft a retention policy. Establish what your current retention timeline actually is and whether it exists in writing or only in habit, then draft the written policy you wish you already had.
- Identify your top risks. List the five largest privacy risks in your process, and for each one assess the impact, the probability, and the combined severity that tells you where to start.
- Review your vendor contracts. Pull the contracts for your recruiting system, assessment tools, and video platform, and work out what data handling each one actually requires and where the gaps are.
Reflection
Before you close this project, sit with a few questions that are harder to answer than they look.
- What would a privacy audit of your recruiting process reveal that you would rather not know?
- Where do you currently keep candidate data, and is it genuinely secured with controlled access, or only assumed to be?
- What is your current retention timeline, and does a written policy exist behind it?
- Which privacy risks do you already know exist and have not yet acted on?
- If you conducted this audit tomorrow, which findings would surprise your leadership most?
Glossary
- Access control. Limiting who can reach candidate data, so that, for example, only the recruiting team can see all candidates while hiring managers see only the ones assigned to them.
- Data minimization. Collecting only the candidate data that is necessary for recruiting decisions, and deleting what is not.
- Privacy audit. A systematic review of data collection, storage, access, transmission, and retention practices, run to identify risks and compliance gaps.
- Retention timeline. How long data is kept before deletion, such as rejected candidates' data held for six months and then deleted.
- Risk assessment. Evaluating the likelihood and impact of privacy risks so you can prioritize which to address first.
- Vendor risk. The risk that comes from third parties handling candidate data on your behalf, including the recruiting system, the assessment platform, and the background-check company.
Related Lessons
This project pulls together threads from several earlier lessons, and revisiting them will sharpen what you find in your own audit.
- Data Privacy Fundamentals: GDPR, CCPA, FCRA, and Regional Requirements supplies the regulatory grounding behind the principles this audit tests, so the erasure request that started Theo's search stops being a surprise and becomes an expected obligation.
- Data Minimization: Collecting Only What's Necessary is the direct source of the Phase 4 finding about demographic fields nobody uses, and it gives you the reasoning for deciding which application questions to cut.
- Retention and Deletion: Reasonable Timelines and Clean Data Practices extends Phase 3 into a working schedule, which is what turns "we keep everything" from a habit into a documented policy with defensible timelines.
- Third-Party Tools and Vendors: Due Diligence and Contracts is where the vendor-risk category of this audit gets its depth, because reading a contract for retention, access, and security terms is a skill in itself.
- Privacy as a Candidate Right and Organizational Responsibility reframes the whole exercise from compliance chore to obligation owed to the person whose resume you are holding, which is the mindset that keeps an audit honest.
Closing
Privacy audits are the foundation of privacy compliance, and without one you are flying blind. You may be holding significant risks you have never named, keeping data far longer than you should, collecting information you will never use, or carrying vendor exposure you have not considered. The audit is what brings all of it into the light, and the encouraging part is that it is genuinely doable. You do not need consultants and you do not need complex tooling. You need systematic thinking and the patience to be thorough. Map the process, document the data flow, identify the risks, recommend the fixes, and then actually implement them. What comes out the other side is a dramatically improved privacy posture and materially less compliance risk, which is how a privacy audit transforms recruiting from ad-hoc handling into practice that is compliant and secure.
Key Takeaways
- You cannot protect data you have not mapped. Walk the candidate lifecycle from application to closure, inventory the intermediate data and not just the final decision data, and follow each element to every place it actually lands.
- The principles are the checklist. Data minimization, purpose limitation, and storage limitation from GDPR and CCPA turn directly into audit questions: do you collect only what you need, use it only for that purpose, and keep it only as long as that purpose requires?
- Indefinite retention is the default and the largest exposure. Most teams keep everything because no one decided otherwise. Replace the default with a written retention schedule that has a defensible basis for each timeline.
- The worked finding shows the method. Resumes retained roughly five years past rejection with no legal basis is a High-severity violation of storage limitation, and the fix is an automated twelve-month purge plus a one-time backlog cleanup, with an owner and a date.
- Manual handling outside the systems is where breaches happen. Email sharing, spreadsheets, personal devices, and chat channels carry more real risk than the ATS, so a technology-only audit is an incomplete audit.
- Honor the candidate's rights across every system. A GDPR erasure or CCPA deletion request must reach the email inboxes, spreadsheets, chat threads, and vendor systems the audit surfaced, not just the ATS.
- Vendors define your real privacy posture. Audit the contracts for what each third party retains, for how long, who can access it, and what security applies, because their practices become yours.
- Documentation is both protection and roadmap. The audit report is your evidence that you took privacy seriously and your prioritized plan for closing the gaps, reviewed on a regular cadence rather than filed and forgotten.
Skill.re