HR News | Employer's Guardian

Applicant Data: What Employers Need to Know

Written by Admin | Aug 18, 2026, 3:39:05 PM

Applicant data is the personal information an employer collects about candidates during recruiting: resumes, contact details, work history, interview notes, assessment results, references, and screening outcomes. It is one of the largest categories of personal data most employers hold, and it is almost always the least governed, because it accumulates from people the organization never employed and has no ongoing relationship with.

A company that hires forty people a year may hold data on four thousand candidates. Very few can say where all of it is or how long they intend to keep it.

Why it accumulates without oversight

Employee data has an obvious owner and a system of record. Applicant data has neither by default. It arrives through multiple channels — an applicant tracking system, direct email to hiring managers, referrals forwarded internally, resumes handed over at events — and each channel creates copies that no one is tracking.

Interview notes are a particular blind spot. They frequently live in personal notebooks, individual documents, and email threads rather than in any system, which means they are neither retained properly when needed nor deleted when they should be. They also constitute records that can become discoverable in a subsequent discrimination claim, which makes their informality a liability rather than a convenience.

The privacy obligations most employers miss

In California, the expiration of the employee and applicant exemption on January 1, 2023 brought candidates within the scope of the state's privacy law for covered businesses. That means applicants — including those never hired — may hold rights to know what data is held, to have it corrected, and to request deletion, subject to exceptions.

It also means a notice at collection is generally required at or before the point of collection, describing categories collected, purposes, and retention. Many employers still run career pages with no such notice, or with a customer-facing privacy policy that never contemplated candidates.

The practical difficulty is operational rather than legal. Responding to a deletion request requires knowing every place a candidate's data resides. An employer whose applicant data is scattered across an applicant tracking system, individual mailboxes, and shared drives cannot answer that request accurately, which is a compliance problem created by information architecture rather than by policy.

Retention: the unresolved question

Employers face genuinely competing pressures. Anti-discrimination record-keeping rules generally require retaining application records for defined periods, so immediate deletion is not available. Privacy principles push toward not keeping data longer than necessary. And recruiting teams want to retain candidates for future openings.

The reconciliation is a documented retention schedule that satisfies the mandatory minimum, defines an outer limit, and applies deletion automatically at that limit. Retaining candidates for future consideration is defensible, but it should be a decision with a stated period and ideally the candidate's awareness, not an accident of nobody ever deleting anything.

Indefinite retention is the weakest position. It maximizes breach exposure, makes deletion requests unanswerable, and is difficult to justify under any privacy framework.

Screening data deserves separate treatment

Background check results, credit information, and criminal history carry their own rules under federal fair credit reporting requirements and a range of state and local restrictions governing what may be considered and when it may be obtained. Many jurisdictions, California among them, restrict when criminal history may be requested and require a specific process before an adverse decision based on it.

This data should be segregated from general applicant records, with tighter access limits, because the population who needs it is much smaller than the population who touches recruiting files generally.

Security exposure

Applicant data is attractive to attackers and often less protected than employee data. A resume set contains names, addresses, phone numbers, employment history, and frequently more. Where screening has occurred, it may include Social Security numbers and dates of birth.

Recruiting is also a favored phishing target, because recruiters are professionally obliged to open attachments from strangers. A resume-shaped attachment is a near-ideal delivery mechanism, and it works against a role that cannot simply refuse to open files.

A practical control set

  • Route all applications into one system of record rather than accepting them across scattered channels
  • Publish a notice at collection on career pages and application forms
  • Set a retention schedule that meets mandatory minimums and enforces an outer limit automatically
  • Keep interview notes inside the system, and train interviewers on what belongs in a record
  • Segregate screening results with tighter access than general recruiting files
  • Restrict access to those with a current recruiting need, and remove it when the need ends
  • Define how a candidate rights request will be handled, and test that it can actually be fulfilled
  • Confirm the applicant tracking vendor's security posture and data deletion commitments

Employer's Guardian helps employers structure recruiting records, retention, and candidate documentation through onboarding documentation compliance, covering what to collect, how long to keep it, and how to keep the records defensible.

This article provides general educational information, not legal advice. Requirements vary by location and change over time. Consult qualified counsel before making compliance decisions.