HR Software

How long should we keep candidate data in our ATS?

Set a written retention period tied to a purpose rather than keeping records indefinitely. Most organisations retain unsuccessful applicant data for a defined window covering legal claim periods and future consideration, then delete or anonymise automatically. Confirm the exact period with legal counsel for each jurisdiction you hire in, and configure the system to enforce it.

Why does retention need a policy at all?

Because keeping candidate data requires a justification, and the justification expires. Privacy regimes in Europe, the United Kingdom, India, Brazil and several US states share a common expectation: personal data is kept only as long as necessary for the purpose it was collected for, and that purpose has to be stated. An applicant tracking system makes indefinite retention effortless, which is exactly why it needs deliberate limits. There is also a practical argument. A database full of five-year-old applications produces poor search results, misleading pipeline reporting and awkward outreach to people who no longer remember applying. Retention discipline improves the usefulness of the system as well as its compliance posture, which is a rare case where the legal and operational incentives point the same way.

How do you choose a retention period?

Work from purposes rather than picking a round number. There are usually three. First, defending against a claim relating to the recruitment decision, which sets a floor based on the limitation period in each jurisdiction. Second, considering the person for future roles, which requires their awareness and, in some jurisdictions, consent, and should have its own shorter clock that resets on genuine engagement rather than on any system activity. Third, aggregate reporting, which can normally be satisfied with anonymised data instead of identifiable records. Write a period for each category, document the reasoning, and have counsel confirm it per jurisdiction, since the answer differs by country and sometimes by state. Then apply the shortest period that satisfies the purposes rather than the longest that is defensible.

How should the ATS enforce it?

Automatically, on a schedule, with a record of what was done. Check during evaluation whether the system supports retention rules by record type and by region, whether deletion is genuine removal or a hidden flag, whether anonymisation is offered as an alternative that preserves reporting, and whether attachments and interview recordings are covered as well as the candidate record. Ask how a manual deletion request from an individual is executed and whether a recruiter can perform it without a support ticket. Also confirm what happens in backups, since a record deleted from the live system may persist for a defined period afterwards. These questions belong on your security list alongside [the other data questions you ask vendors](/ats), because retention is where policy meets product capability.

What does good practice look like day to day?

Tell candidates the retention period at the point of application, in plain language on the application form or privacy notice. Separate the talent pool from the applicant record, so people you want to contact again have knowingly opted into that rather than being retained by default. Run the deletion job on a schedule and keep a log. Review the policy annually, and review it whenever you start hiring in a new country. Give one person ownership, usually in HR operations, so requests do not sit unanswered. None of this is burdensome once configured, and it removes a category of risk that tends to surface at the worst moment, typically during a candidate complaint or a customer security review of your own organisation.

Want Pitch N Hire to handle this for your team?

Related glossary terms

Related roles to hire

Next step

FAQ

Frequently asked questions

Can we keep candidate data forever if we get consent? +
Consent is not a permanent licence. It must be specific, freely given and withdrawable, and indefinite retention is difficult to justify as necessary even with consent. A more defensible approach is a stated period with a clear renewal point, where you contact the person before expiry and keep the record only if they confirm continued interest.
Does deleting candidate data break our hiring reports? +
Not if you anonymise rather than delete outright. Removing names, contact details and identifying attributes while retaining stage timestamps, source and outcome preserves funnel and time-to-hire reporting. Check that your system supports anonymisation as a distinct action, since some products offer only full deletion, which does remove historical records from reports.
What about candidates who ask us to delete their data? +
Handle it as a defined process with an owner and a target turnaround, since most privacy regimes set a response deadline. Confirm in the product how deletion is performed, whether it covers attachments, notes and email history, and what confirmation the candidate receives. Test this during evaluation rather than discovering the limitations when the first request arrives.
Do retention rules differ for employees versus candidates? +
Yes, substantially. Employment records typically carry longer statutory retention obligations relating to payroll, tax and employment law, and they usually sit in an HRIS rather than the recruiting system. Keep the two policies separate, and make sure the handoff at hire transfers the record into the system governed by the correct rules.
Built for recruiters & hiring teams

See how much faster your team could hire

Get a personalized walkthrough of Pitch N Hire on your own roles and workflow. No slides, no obligation.

Prefer to talk? Book a demo · View pricing

Free 1-user plan · No credit card · Talk to a real hiring expert

One Hiring Infrastructure.
Zero Tool Chaos.

Demos are consultative. We respect privacy and enterprise
governance. No lock-ins.

Start free Book demo