Recruitment Data Protection and Privacy · Lesson 3

Plan transparency, retention and requests

Course overview · 4 min reading + 12 min practice, estimated

Principles and method

People need appropriate information about how their data is used and a working route for requests. Retention should follow a justified policy, not indefinite storage by default. Define review and deletion triggers, including exports and supplier copies. Coordinate correction, access and deletion requests with the responsible team; legal exceptions and obligations depend on context. Do not promise immediate deletion from every backup if the system cannot do that. Keep an accurate record of what was done and what remains under a justified restriction. Course examples are operational planning exercises, not a substitute for legal advice.

Worked example

A candidate correction must update the ATS and a shortlist already sent to a panel. The request workflow identifies both locations and confirms the correction, rather than changing only the visible profile.

Put it into practice

Create a request-routing checklist and a retention-decision table with placeholders for approved periods.

Use fictional information and keep your work in your own notes.

Compare your approach: self-review guidance

Use purpose, owner, trigger and affected systems. Do not invent a universal retention period. Include verification of downstream copies and an escalation path for disputed or complex requests.

Download the course workbook

Sources and further reading

Original Academy teaching and fictional examples. These references provide context, not endorsement. Edition 2026.09; updated 2026-09-24.

How our learning is designed