To comply with GDPR, you can select specific candidate data to be deleted when requested by the candidate or after a candidate has been rejected from all applications, at a time specified by you and your legal team.
Greenhouse Recruiting allows your organization to control the data retention timeframe, data to be deleted, and notifications on a per office basis with our Data Retention Rules.
In this article:
To configure a data retention rule, click the Configure icon in the upper right-hand corner and select Privacy & Compliance on the left-hand panel.
From the subsequent page, navigate to the General Data Protection Regulation (GDPR) panel and click Configure.
Navigate to the Data Retention Rules panel and click Add a Rule.
Configure data retention period
From the subsequent Add a Rule panel, use the provided field to input how long (in days) your organization wishes to retain candidate personal data after they have been rejected on all applications.
The data retention timer will start from when a candidate is rejected on all job applications and will be applied retroactively to all rejected candidates. You will receive an email immediately for existing rejected candidates in your system if those candidates exceed the data retention period
Configure data retention rule offices
Select the office(s) that will be impacted by this rule by clicking the checkbox inline with the office name.
Configure data to be deleted
Use the Data to be Deleted table to select what candidate personal data will be deleted for candidates.
Configure data retention rule notifications
Since deleting candidate personal data is a destructive process, it is not automated and must be done manually. Once the data retention timer has lapsed for candidates rejected on all job applications someone will be notified that they should manually delete the data. To configure the notification to delete candidate personal data, navigate to the Notifications to Delete Data section.
From the subsequent fields, select user(s) who should be notified of candidates who need their personal data deleted. Select the time, time zone, and on what day(s) you would like notifications to be sent out.
When you have finished, click Save to save to Data Retention Rule.
Recipients will be notified on the day and time selected that the data retention period for certain rejected candidates is over and the candidates' personal data should be deleted.
Your new data retention rule will be added to your GDPR configuration. Repeat this process to add additional rules to your organization.