Back to Blog
candidate subject access requestATS candidate data exportrecruitment agency GDPRright of access recruitingrecruiting CRM governance

Candidate Subject Access Requests in Agency ATS 2026

Handle candidate access requests across ATS notes, email, exports and client records. Find the right data, protect others and prove each secure response.

Janis Kolomenskis

15 min read
Share

A candidate writes six ordinary words: “Send me everything you hold.” The consultant forwards the email to operations, exports one ATS profile and marks the task complete. Meanwhile, interview notes sit in email, a client has two CV versions, and a sourcer’s spreadsheet contains a rather different assessment. The request is small. The search job isn’t.

How should an agency handle a candidate access request?

Treat any clear request for the person’s own information as a possible access request, regardless of whether it says “Article 15” or uses a formal template. Log receipt, confirm the responsible organisation, preserve relevant records, search every agreed system, review information about other people, provide the candidate’s data securely and keep evidence of the response.

An ATS export is a useful starting point, not the whole answer. Candidate information can live in call notes, inboxes, client submissions, assessment tools, spreadsheets, enrichment records and archived searches. The agency needs a repeatable search map rather than relying on whoever remembers the case.

This is an operational workflow, not a universal legal conclusion. UK GDPR, EU GDPR, national law, exemptions and the respective roles of agency and client can change what must be supplied. Give the accountable privacy owner the evidence needed to make those decisions.

Recognise the request before it gets lost in a recruiter’s inbox

The first control is teaching every client-facing colleague what an access request can sound like.

Candidates rarely write like lawyers. “What notes have you made about me?”, “Show me what the client saw” and “I want a copy of my file” can all signal the right of access. The request may arrive by email, messaging app, phone or social media. Route it promptly instead of asking the person to start again on a special form.

Record the original wording, channel, time received and staff member who received it. Do not silently narrow “everything about me” to the active vacancy. Equally, do not promise every document in the firm before checking whether each document contains the candidate’s personal data and whether other people’s rights are involved.

Give recruiters a visible escalation button and a short acknowledgement script. The useful message is simple: the request has been received, a responsible owner is handling it, and the agency will clarify scope only where that genuinely helps locate the information. No defensive debate. No improvised deadline.

  • Original request and reliable receipt timestamp.
  • Candidate identifiers and searches or clients already known.
  • Named response owner and internal contributors.
  • Any clarification, identity check or extension decision with its reason.

Identify who controls each part of the recruiting record

A shared recruitment process can contain agency-controlled data, client-controlled data and processor-held copies.

Map the relationship before sending instructions. The agency may decide why and how it maintains its talent network, while a client may control interview records created for its own hiring decision. A testing provider may process information on documented instructions. Job titles do not settle those roles; the real purposes and decisions do.

If the request reaches the wrong participant, do not bounce the candidate around without explanation. Record what the agency holds, identify records that belong to another response process and coordinate where the contract and law require it. The candidate should not have to reconstruct the vendor diagram from scratch.

Keep a role note by data category: sourcing record, agency assessment, client feedback, interview scheduling, reference material and communication history. That note becomes especially valuable when the same candidate has appeared in several mandates with different clients and different responsibilities.

Build a search map wider than the ATS profile page

Search by systems and record categories, then document what was checked and by whom.

Start with the ATS and recruiting CRM: profile fields, parsed CVs, source history, activities, tags, matching scores, recruiter notes, attachments, suppression fields and audit events. Then follow integrations. Calendar entries, email sync, call transcription, assessments, client portals and exported reports may each hold personal information that does not appear in the standard profile export.

Search shared drives and approved local working files. Consultants often create a shortlist workbook for one client or download a CV to prepare a presentation. Use proportionate identifiers such as email, telephone number, previous names and candidate ID. A name-only search can miss records or collect information about the wrong person.

Do not tell every employee to forward uncontrolled copies to one inbox. Use a restricted collection space, search instructions and a completion checklist. Contributors should identify locations and context; the response owner should decide what belongs in the review set.

  1. List systems, integrations, mailboxes, workspaces and known recipients.
  2. Assign each location to a person who understands its records.
  3. Capture search terms, date range, result count and unresolved gaps.
  4. Reconcile collected items against the candidate’s mandate history.

Preserve source context and explain generated data

A readable response needs more than a dump of field values with no origin or meaning.

Keep the original CV beside parsed fields so the candidate can see what was supplied and what the system extracted. Identify data gathered from public sources or approved providers, the available origin information and the purposes attached to it. If a field was inferred by a recruiter or generated by a matching tool, label that distinction.

Internal status codes need translation. “A3”, “silver” or “do not progress” means little outside the team. Explain the relevant category in plain language without creating a new justification after the event. If the code is inaccurate, route a correction separately rather than editing history to make the access response look tidy.

An access workflow should expose brittle data practices. Unsupported personality labels, copied health details and vague “culture” comments become difficult to defend because they were poor records in the first place. Fix the recording policy, not just the export format.

If a note is too embarrassing to show the candidate, the first question is usually why it was recorded—not how to hide it.

Review third-party information without erasing the candidate’s story

Separate and assess information about referees, client contacts and other candidates before disclosure.

Recruitment records are relational. A client email can contain the candidate’s assessment and a manager’s personal details. A reference note can include the referee’s views and information about colleagues. A comparison grid may identify other shortlisted people. The response owner needs a line-by-line review where interests overlap.

Blanking every name is not automatically the right answer, and sending the raw document is not automatically safe. Consider whether the information is the requester’s personal data, whether another person can be identified, whether consent is appropriate, and whether disclosure is reasonable under the applicable rules. Record the decision and its basis.

Keep a working copy and a release copy with version control. Redaction must be irreversible in the final format; drawing a black box over editable text is not enough. Re-open the exported file as a recipient would and test search, comments, layers and document properties.

Deliver securely and keep a defensible response record

The transfer method should match the sensitivity of the candidate file and the identity risk.

Confirm identity proportionately when there is reasonable doubt, but do not collect a passport by default for someone already authenticated in a candidate portal. Use existing account knowledge, a controlled verification step or limited additional information. Store verification material only as long as justified.

Package the information in an accessible, searchable format with a short index. Explain purposes, categories, sources, recipients, retention logic and relevant rights alongside the data where required. If the file is encrypted, send the secret through a separate channel and avoid placing both in the same email thread.

Retain the request, search log, review decisions, final package reference, delivery proof and follow-up. Do not keep an extra unrestricted archive of every collected document “just in case.” The response record should prove the work without creating a new permanent candidate dossier.

Use each request to test the agency’s data architecture

A difficult access response usually reveals a retrieval, ownership or note-quality problem worth fixing.

Measure where the team spent time. Was candidate history fragmented across personal inboxes? Could the portal show who viewed a profile? Did the ATS export omit source and recipient data? Turn those gaps into product requirements and operating controls rather than accepting another manual fire drill.

Run a tabletop request twice a year using a fictional candidate who appears in several searches. Ask operations to trace sources, exports, client sharing, assessments and deletions. The goal is not speed alone. Completeness, secure review and clear ownership matter more than producing a fast but partial ZIP file.

Train consultants on note quality after the exercise. Factual observations, source labels and candidate corrections make recruitment records more useful day to day—and far easier to explain when the person asks to see them.

Candidate access-request control record

One case record keeps the search, review and delivery process accountable without mixing it into ordinary recruiting activity.

Control fieldEvidence to keepOperational question
Receipt and scopeOriginal wording, time, channel and clarificationsWhat is the person actually asking for?
RolesController or processor assessment by record categoryWho decides and who assists?
Search mapSystems, owners, terms, dates and completion statusCould a relevant copy still be missing?
ReviewThird-party, exemption, redaction and explanation decisionsCan the release be understood and shared safely?
DeliveryIdentity step, file version, secure channel and confirmationDid the correct person receive the correct package?
LearningRetrieval gaps, note issues and assigned fixesWhat becomes easier before the next request?

What an ATS export cannot decide

Software can gather fields and preserve an audit trail, but it cannot determine controller roles, exemptions, third-party disclosure or the proper scope of a contested request. Those questions need accountable legal and privacy judgement.

This guide combines EU and UK operational principles and is not legal advice. Apply the law governing the agency, client and candidate, including current national rules and regulatory guidance.

Candidate access-request questions

These answers cover the points that most often cause an agency response to become incomplete or insecure.

Is the ATS profile export enough for a candidate access request?

Usually it is only one source. Search connected email, notes, client sharing, assessments, exports and approved working files according to the request’s scope and the organisation’s role.

Can an agency ask the candidate to narrow the request?

Clarification can help locate information, especially in a long relationship, but it should not be used to delay or force the person to surrender the wider request. Record the clarification and continue preserving relevant records.

Should recruiter opinions appear in the response?

An opinion can still be personal data about the candidate. Whether and how it is disclosed may require review for context, third-party rights and applicable restrictions; calling it “internal” does not settle the issue.

Can the client answer for the agency?

Not automatically. Agency and client may control different records or purposes. Map the real roles, coordinate assistance where required and tell the candidate clearly which organisation is handling which information.

Official access-right sources

The regulation and current regulator guidance explain recognition, search, scope, secure delivery and information about other people.

Strengthen the surrounding candidate-data controls

Document candidate-data provenance · Prove candidate-data deletion work · Merge duplicate candidate records safely · Review Yena’s recruiting CRM

Make candidate records searchable before a request arrives

Yena keeps candidate history, source context, mandate activity and reviewable records together so your team can retrieve evidence without rebuilding the relationship from scattered files.

Explore the recruiting CRM

Janis Kolomenskis

August 26, 2026

Share
Yena

Turn a role brief into a qualified shortlist.

Describe who you need. Yena finds and ranks candidates, explains why they fit, surfaces available contact details for review, and keeps outreach in the same recruiting workspace.