Can we keep sourced candidates who never applied?
Sometimes, and it turns on the lawful basis you can point to for holding and contacting them rather than on what the software allows. A sourced profile has no application behind it, so the purpose you record is your own outreach. What that requires differs by jurisdiction and changes, so confirm your position with counsel.
Why a sourced record is a different question from an applicant record
An applicant handed you their details for a stated purpose, and that act is the anchor most retention policies are built on. A sourced profile has no such act behind it. The person may not know the record exists, has not asked to be considered, and in many cases has never heard of you. That changes what you are relying on to hold the record, what you can honestly say the purpose is, and what happens when they ask. Software rarely draws this line for you β a pool holds both kinds of record identically β so the distinction has to exist in your policy rather than in the interface.
What the honest answer depends on
Where the person is, where you are, how the profile was obtained, and what you intend to do with it. Rules on holding and using personal information for recruitment purposes differ by jurisdiction, are not uniform across the regions many teams source from, and change. That is why no page, including this one, can responsibly tell you the answer for your situation. What a page can do is name the questions worth putting to counsel: what basis you are relying on, whether the person has to be told and by when, how long you may hold the record for that purpose, and what changes if you source across a border. Treat any vendor who answers those definitively as making a claim they are not positioned to make.
What to write down before the pool grows
A short internal note answering four things, agreed with whoever advises you. Where sourced profiles may come from and which sources are off limits. What you tell the person, and at what point β first contact is the usual answer and the one most often skipped. How long a sourced record is held when the person never responds, which is the population that quietly becomes most of the database. And who may act on a deletion request without escalating it. Writing this before the pool is large is the difference between applying a policy and reconstructing one across thousands of records after somebody asks a question you cannot answer.
What the software should be able to do
Distinguish how a record entered β sourced, applied, referred, event β as a field rather than a note, because every later decision depends on that distinction. Store contact preference as structured data, not free text. Delete or anonymise a record on request across the pool and any campaign audience, rather than in one place. And show you when a record last had any genuine activity, since a sourced profile nobody has touched since it was created is the clearest candidate for removal. A candidate relationship tool that treats every record as equivalent makes a policy hard to apply even when the policy is sound.
Handling a request to be removed
Have a route that does not depend on somebody's goodwill or memory. The practical failures are consistent: the request reaches a recruiter's inbox and never becomes an action, or the record is removed from the pool while a copy persists in an email tool, a spreadsheet somebody exported, or an old campaign audience. Decide in advance who handles these, what the acknowledgement says, where you have to look, and how the outcome is recorded. Whether a given request must be honoured, and within what period, is a legal question for your jurisdiction β but having no process at all is a problem in every jurisdiction, and it is the one you can fix without advice.
Where this is genuinely not a software decision
The uncomfortable part is that most of the risk sits in judgement rather than configuration. A tool can enforce a retention period you set, but not decide what period is defensible. It can hold a consent field, but not tell you whether consent was validly obtained. It can export the record, but not determine whether you should have held it. Buyers sometimes read a vendor's compliance certifications as answering these, and they do not: those describe how the vendor secures and operates the system, which is a real and different question. Ask your own counsel about the holding and use of the data, and ask the vendor about the security of it.
Related roles to hire
Next step
Frequently asked questions
Does a public profile mean we can store and contact someone?
Is a sourced profile treated the same as an applicant record?
What should we ask a vendor about this?
How long can we keep a sourced profile nobody replied to?
Do these questions change when we source across borders?
See how this works in a real applicant tracking system
Pitch N Hire is an applicant tracking system built for recruiters and hiring teams. If this answer described something you want to run properly, the ATS is where it lives.
Free for 1 user Β· No credit card Β· Talk to a real hiring expert
See how much faster your team could hire
Get a personalized walkthrough of Pitch N Hire on your own roles and workflow. No slides, no obligation.
Prefer to talk? Book a demo Talk to sales View pricing
Free 1-user plan Β· No credit card Β· Talk to a real hiring expert