The RGPD requires strict management of the personal data collected. Let's take a look at your obligations in this area.
What are your obligations towards the RGPD regarding candidate data?If Beetween, as an ATS software, has obligations to secure your data, you, for your part, have the obligation to manage the modification and deletion of candidate data. Let's take stock.
Transparency and the right to modify
As a recruiter, you have a duty of transparency towards candidates, giving them the opportunity to consult, modify and delete the data you hold on them. You must also inform them of the purpose for which this information will be used.
As far as the principle of finality is concerned, you don't have to do anything except your career site. Indeed, when a candidate fills in an application form, it goes without saying that his or her personal information will be used to contact him or her again and study the application. However, don't forget to include a personal data processing policy page on your career site, and to specify on the forms that the candidate subscribes to the said policy when sending the form. All job boards specify this fact to validate the application.
Rights of access, modification and deletion can be exercised in various ways. You are under no obligation to give candidates direct access to their data. With Beetween, when a candidate applies, they automatically receive a (customizable) acknowledgement of receipt of their application, including a contact email address for exercising their personal data rights. By default, this is your account email. However, you can easily customize it by going to Settings & Auto Answer.
RGPD message content:In accordance with the provisions of the RGPD regulation of May 25, 2018, you have the right to access, communicate, rectify, update and delete your personal data at any time. Please send your request to [indiquer adresse].
Data retention
In addition to being transparent and respecting candidates' wishes regarding their personal data, you also have a duty to keep said data only for a "reasonable period". Based on case law, we can estimate this timeframe at around 24 months from the date of last activity (this timeframe is subject to change). At the end of this period, candidate data must be deleted.
All operations on a candidate file do not modify the last activity date. In fact, it's not a good idea to change the deadline if you simply want to leave a comment in the history.
Therefore, only the following actions will affect the last activity date:
- Merge the file with one or more other files
- Add, modify or delete documents (CV, cover letter...)
- Add, modify or delete a brief note or detailed note (history notes are excluded)
- Adding, modifying or deleting a tag
- Modification of the "star" rating
- Reply to a manager notification generating a PDF document
- Response to the candidate questionnaire
- Modification of contact details in the applicant form
Beetween sets up an automatic deletion at the end of this period. However, you can also delete candidate profiles manually.