Playbook, recruitment agency

Erasure requests from candidates, and where they have to land

A recruitment database is a large holding of other people's personal data: CVs, identity documents, references, interview notes, and whatever candidates volunteered in between. Data protection regimes in most jurisdictions give rights of access and erasure over all of it with response deadlines attached, which makes this the one request on a recruitment site that must not sit in a chat log. The assistant's job is to get it into a real inbox with enough detail to be actioned.

Why this is not the general answer

The handling pattern for data deletion requests holds across every trade. What follows is the part that does not.

  • The holding here is unusually rich and often years old, so the person asking may have registered under a different email or a different name, and the request needs enough detail to find them.
  • Most of these requests are triggered by unwanted contact rather than by a concern about storage, so separating an unsubscribe from an erasure resolves a good share of them faster and correctly.
  • The records include material third parties supplied, such as references, which is not the candidate's to delete in the way their own CV is.
  • A response deadline attaches to the request in most regimes, so the failure mode is a request that is politely acknowledged and never routed, which is worse than a refusal.

How it arrives

  • can you take me off your database
  • please delete my cv
  • stop sending me job alerts
  • how long do you keep candidate records for
  • what information do you hold about me
  • i registered years ago can you remove everything

What has to be indexed for this to work

Material behind this answer
Your data retention and removal policyHow long you keep a candidate record, what you use it for, the basis for holding it, and how somebody asks to be removed. Data protection law in most jurisdictions gives candidates rights over this, and a recruitment database is exactly the kind of holding those rights were written for.
Where a request has to go, and what you need with itThe inbox or named contact, the identifying details you need to locate a record, and the period within which you respond. The assistant can collect those details, which is the difference between a routed request and a lost one.
How marketing preferences are handled separatelyHow somebody stops job alerts or marketing without asking for erasure, and how quickly that takes effect. A large share of these enquiries are only ever about the emails, and saying so up front is faster for everybody.
What you may still hold, and whyRecords connected to placements, payroll or a legal obligation that survive a general erasure request. State it honestly and in general terms, because an unqualified promise followed by a partial refusal in writing is the version that becomes a complaint.

The reply

A reply worth copying
You can ask us to remove your record, and the request goes to the team that handles data requests so it is dealt with within the response period rather than sitting here. It helps if you tell us the email address you originally registered with, since records can be years old and under a previous address. If it is only the job alerts you want stopped, that is a separate and much quicker request and I can pass that on instead. Leave your name and the email we hold and I will send it over today.

It confirms the right first and names a real destination, because vagueness about where the request goes is what candidates distrust. Asking for the original email address is the practical detail that makes the request actionable, and no other question resolves as many of these. Offering the unsubscribe route separately catches the large group who never wanted erasure at all.

Where it stops

The trigger. Any request to delete, restrict, correct or see personal data, including one attached casually to a question about job alerts.

The handover, worded
This needs to go to the team that handles data requests, because there is a deadline attached to it. Leave your name and the email address you registered with and I will pass it on today.

It stops answering before it guesses, says who will pick it up, and asks for the one thing that makes a reply possible. Nothing about it reads as a dead end.

Never say this here

Out of bounds

  • Never confirm that a record exists, or that anything has been deleted.
  • Never say what information the agency holds about the person asking.
  • Never say a record has been removed when only marketing has been stopped.
  • Never state a retention period that is not in your published policy.

Questions

Can it delete the record itself?
No. It has no access to any system and cannot write into one. It captures the request, sends it to the address you nominate and stores it, which matters here because the deadline attached to these requests means a lost email is a real problem.
Why ask which email they registered with?
Because candidate records go back years and people change addresses and names. A request that arrives without a way to find the record turns into a chain of emails, and asking one question in the chat prevents that.
Some records we cannot delete. Should it say so?
In general terms, drawn from your own policy. Records tied to a placement, to payroll or to a legal obligation may have to be kept, and a candidate told that up front is far less aggrieved than one told yes and then partly refused two weeks later.

Keep reading

Try it on your own material

Upload a document or point it at your site, paste one line of HTML, then ask it something only your business could answer.