Cookies on this site
Strictly necessary cookies keep the site working. Our analytics and advertising tags — Microsoft Clarity and Google Tag Manager — stay switched off, and write no cookie, until you accept them. Privacy Policy
Cookie preferences
Choose which categories may run. Your choice is stored on this device and is remembered for six months. You can change it at any time from the “Cookie preferences” link in the footer.
Security, session integrity, your light/dark theme choice, and this cookie preference itself. The site cannot work without these, so they cannot be switched off.
Microsoft Clarity (session replay and heatmaps) and Google Analytics via Google Tag Manager. Used to see which pages help and which confuse. Off by default.
Google advertising tags via Google Tag Manager, used to measure which campaigns lead to a demo booking and to show relevant ads. Off by default.
Set a written retention period tied to a purpose rather than keeping records indefinitely. Most organisations retain unsuccessful applicant data for a defined window covering legal claim periods and future consideration, then delete or anonymise automatically. Confirm the exact period with legal counsel for each jurisdiction you hire in, and configure the system to enforce it.
Because keeping candidate data requires a justification, and the justification expires. Privacy regimes in Europe, the United Kingdom, India, Brazil and several US states share a common expectation: personal data is kept only as long as necessary for the purpose it was collected for, and that purpose has to be stated. An applicant tracking system makes indefinite retention effortless, which is exactly why it needs deliberate limits. There is also a practical argument. A database full of five-year-old applications produces poor search results, misleading pipeline reporting and awkward outreach to people who no longer remember applying. Retention discipline improves the usefulness of the system as well as its compliance posture, which is a rare case where the legal and operational incentives point the same way.
Work from purposes rather than picking a round number. There are usually three. First, defending against a claim relating to the recruitment decision, which sets a floor based on the limitation period in each jurisdiction. Second, considering the person for future roles, which requires their awareness and, in some jurisdictions, consent, and should have its own shorter clock that resets on genuine engagement rather than on any system activity. Third, aggregate reporting, which can normally be satisfied with anonymised data instead of identifiable records. Write a period for each category, document the reasoning, and have counsel confirm it per jurisdiction, since the answer differs by country and sometimes by state. Then apply the shortest period that satisfies the purposes rather than the longest that is defensible.
Automatically, on a schedule, with a record of what was done. Check during evaluation whether the system supports retention rules by record type and by region, whether deletion is genuine removal or a hidden flag, whether anonymisation is offered as an alternative that preserves reporting, and whether attachments and interview recordings are covered as well as the candidate record. Ask how a manual deletion request from an individual is executed and whether a recruiter can perform it without a support ticket. Also confirm what happens in backups, since a record deleted from the live system may persist for a defined period afterwards. These questions belong on your security list alongside the other data questions you ask vendors, because retention is where policy meets product capability.
Tell candidates the retention period at the point of application, in plain language on the application form or privacy notice. Separate the talent pool from the applicant record, so people you want to contact again have knowingly opted into that rather than being retained by default. Run the deletion job on a schedule and keep a log. Review the policy annually, and review it whenever you start hiring in a new country. Give one person ownership, usually in HR operations, so requests do not sit unanswered. None of this is burdensome once configured, and it removes a category of risk that tends to surface at the worst moment, typically during a candidate complaint or a customer security review of your own organisation.
Pitch N Hire is an applicant tracking system built for recruiters and hiring teams. If this answer described something you want to run properly, the ATS is where it lives.
Free for 1 user Β· No credit card Β· Talk to a real hiring expert
Get a personalized walkthrough of Pitch N Hire on your own roles and workflow. No slides, no obligation.
Prefer to talk? Book a demo Β· Talk to sales Β· View pricing
Free 1-user plan Β· No credit card Β· Talk to a real hiring expert
See your true cost-per-hire and how much Pitch N Hire could save you β our free Recruitment ROI Calculator gives you the numbers in under a minute. No signup required.
Open the free ROI calculatorPrefer a tailored walkthrough on your real roles? Drop your work email:
β Free 1-user plan Β· No spam Β· Talk to a real hiring expert
Free 1-user plan Β· No credit card Β· Real person replies in 1 business day