A candidate asks whether their details were deleted. The ATS shows “profile removed.” Meanwhile an interview pack remains in a shared folder, an old sequence can recreate the contact and nobody knows what the external processor confirmed. One green tick is not an answer.
What counts as candidate data deletion proof?
Candidate data deletion proof is a proportionate record showing the request or retention trigger, verified scope, systems checked, action taken, responsible owner, completion time, recipient or processor follow-up, justified exceptions and controls that prevent accidental reappearance.
The proof should be minimal. Recording a deletion decision does not mean retaining the candidate’s entire CV forever; where a protective suppression marker is necessary, document its purpose, limited contents, access and review period.
Treat erasure and routine retention cleanup as related but distinct events. An individual request may require identity checks, exception analysis, communication and recipient notification that a scheduled disposal task does not.
Define the deletion trigger and response owner
Start by recording why the agency is acting and who is accountable for the decision.
A trigger may be a candidate’s request, withdrawn consent, a successful objection, expiry of an agreed retention period or the end of a processing purpose. Capture the date received, request channel and responsible case owner. Verify identity proportionately without demanding unnecessary new personal information.
The EDPB explains that controllers normally respond to data-subject requests within one month and must communicate a justified extension within that original period. This is a response framework, not a promise that every deletion request has identical scope or that every item must disappear regardless of applicable exceptions.
Map everywhere the candidate record travelled
The operational scope includes systems, copies and recipients—not only the visible ATS profile.
List the candidate database, recruiting CRM, email or calendar sync, document storage, assessment tools, client portals, exported spreadsheets, messaging workflows and authorised processors. Identify which repositories actually received the person’s data and who controls each copy. Do not assume that a general integration inventory proves a specific transfer occurred.
Check linked records carefully. A placement invoice, contractual evidence or active legal matter may have a separate lawful reason for limited retention. Keep the minimum information required for that purpose and restrict it rather than preserving an entire recruiter history because one small element remains necessary.
Record actions and outcomes by system
Each system needs a clear status, accountable owner and evidence appropriate to its role.
Useful outcomes include deleted, anonymised, restricted pending review, not present, processor confirmation awaited or retained under a documented exception. Record when the action completed and what was checked. A screenshot or supplier confirmation may help, but avoid collecting more candidate information solely to make the evidence look impressive.
Distinguish controller and processor responsibilities. The agency may need a supplier to complete part of the work, but delegating a technical task does not remove the need to coordinate the request. Where data was shared with other recipients, assess the obligation to communicate the outcome and record the action taken.
- Identify the specific system or recipient and the responsible contact.
- Record the deletion, restriction, anonymisation or justified non-applicability.
- Retain completion timing and enough evidence to explain the decision.
- Capture unresolved exceptions and their next review date.
Handle backups and restored copies honestly
Backup treatment must match the technical design, supplier contract and risk—not an invented promise of immediate physical erasure everywhere.
Ask whether deleted production data remains inside restricted disaster-recovery backups, when those backups rotate and who can restore them. A backup copy should not remain available for normal recruitment activity. Document the actual arrangement instead of claiming a person was removed from every historical medium when the agency cannot substantiate that statement.
Test the restore scenario. If a recovery operation brings back an old candidate record, current deletion decisions and suppression controls must be re-applied before the data is used or outreach resumes. Assign an owner to verify the restored state; a policy document without a rehearsal is only an intention.
Distinguish justified retention from convenience
An exception needs a real purpose, limited scope, owner and review point.
Possible retention needs depend on applicable law, contractual obligations, current disputes and the specific processing context. Document the reason without presenting one country’s limitation period as an EU-wide rule. Keep only the portion genuinely required and remove or restrict the rest.
The UK ICO explicitly notes that recruitment-record retention is not governed by a universal fixed period and that the possibility of a claim does not justify indefinite storage. EU agencies must assess their own jurisdiction separately; UK regulator guidance is useful context, not a substitute for local legal advice.
Prevent re-import, enrichment and outreach resurrection
Deletion is incomplete operationally if another workflow can recreate the same contact without review.
Inspect CSV imports, recruiter email sync, resume parsers, browser capture, enrichment jobs, campaign lists and disaster recovery. Decide whether a minimal protective marker is necessary to prevent a deleted person from being reintroduced. Restrict access to that marker and document why keeping it is proportionate.
Run a negative test with authorised synthetic data: delete the profile, attempt an old import and trigger an outreach sequence. The expected result is blocked recreation or a restricted review state—not a fresh contactable record. Record the test separately from the candidate’s real personal information.
A deletion log is useful only when the next import, parser job or restored backup cannot silently undo the recorded decision.
Close the case with a truthful candidate response
Explain completed action, meaningful exceptions and response timing without promising controls the agency does not have.
Respond in clear language through an appropriate channel. State whether the request was completed, whether any information must remain for a specific reason and how the person can raise questions or challenge the decision. Avoid broad statements such as “all information has been erased everywhere” unless the agency can actually verify them.
Keep a limited internal case record, closure decision and owner. Review overdue processor confirmations, recurring failure points and restore-test results periodically. A sensible executive-search team needs traceability and human judgement, not an elaborate monitoring product or a permanent archive of deleted CVs.
Candidate deletion evidence matrix
A focused evidence record should show what happened in each relevant system while avoiding unnecessary duplication of personal data.
| Control or location | Required decision | Proportionate evidence |
|---|---|---|
| Request or retention trigger | Confirm reason, scope, owner and response deadline | Case reference, received date and decision owner |
| ATS and recruiting CRM | Delete, anonymise or restrict relevant profile data | System event and completion timestamp |
| Documents and shared drives | Remove linked CVs, interview packs and unnecessary exports | Repository owner confirmation and scoped checklist |
| Client and processor copies | Assess onward notification and supplier responsibilities | Recipient request and completion response |
| Legal or contractual exception | Retain only data needed for the stated reason | Restricted exception rationale and review date |
| Backups and restore | Document access limits, rotation and restore handling | Backup policy plus restoration control test |
| Re-import prevention | Block unsafe recreation by sync, parser or enrichment | Synthetic negative test and restricted marker policy |
| Candidate communication | Provide a clear and accurate outcome | Reply date, response channel and limited closure note |
What deletion evidence cannot prove
A processor confirmation, audit event or completed checklist cannot establish that no unauthorised external copy exists. Evidence describes the systems and actions the organisation can reasonably identify and control.
Erasure obligations, lawful exceptions and retention periods depend on jurisdiction and facts. This operational framework is not legal advice and does not replace counsel, the agency’s data-protection lead or the actual processor agreement.
Candidate deletion proof FAQ
These answers address the difference between a deleted interface record and a defensible, limited erasure process.
Does GDPR require one standard deletion certificate?
No single universal certificate format applies to every agency workflow. Maintain proportionate evidence of the trigger, decision, affected systems, actions, exceptions and communication that fits your responsibilities.
Must a candidate disappear from every backup immediately?
Assess the actual backup design, restricted access, supplier commitments and rotation. Prevent restored data from re-entering active recruiting and describe the real arrangement accurately.
Can we keep a suppression marker after deletion?
A limited marker may be appropriate when genuinely necessary to prevent unwanted re-import or contact. Document its purpose, data minimisation, restricted access and review period rather than retaining the whole profile.
How long do we have to answer an erasure request?
The EDPB states that controllers normally respond within one month. A justified extension can be available in qualifying circumstances, but the person must be informed within the initial month.
Official candidate rights and retention guidance
The EDPB explains EU data-subject rights. The UK ICO source is explicitly UK guidance and should not be treated as binding across all European jurisdictions.
- European Data Protection Board: Respect individuals’ rights
- UK Information Commissioner’s Office: Keeping recruitment records
- EUR-Lex: General Data Protection Regulation, including accuracy, storage limitation and data-subject rights
Build accountable candidate-data workflows
Run a candidate-data and CRM audit · Review recruitment agency software requirements · Plan a safe ATS migration and data export · See Yena pricing and agency fit
Review candidate data handling with real agency scenarios
Use a realistic candidate request to inspect permissions, history, contact restrictions and the evidence your recruiting team can actually retrieve.
Explore Yena pricing and workflows