Recruitment Data Protection and Privacy · Lesson 4

Check suppliers and test the controls

Course overview · 4 min reading + 12 min practice, estimated

Principles and method

Before introducing a supplier, understand what information leaves your system, where it is handled, who can access it and how it is returned or removed. Review contractual and security arrangements with the appropriate specialists. Ask whether inputs are used for model training and whether settings and contracts actually support the intended restriction. Test export, correction and deletion using fictional data. Maintain an incident route for misdirected information or unauthorised access. A privacy review is incomplete if the team cannot operate the agreed controls during ordinary work or supplier exit.

Worked example

A demo account offers a delete button but leaves data in exported evaluation files. The buyer asks for an end-to-end deletion procedure and tests it with synthetic records before approval.

Put it into practice

Write six supplier questions and a fictional deletion test with expected results.

Use fictional information and keep your work in your own notes.

Compare your approach: self-review guidance

Include secondary copies, subprocessors, access, training use, retention and exit. Record what is evidenced versus merely asserted by the supplier and route unresolved issues to the accountable owner.

Download the course workbook

Sources and further reading

Original Academy teaching and fictional examples. These references provide context, not endorsement. Edition 2026.09; updated 2026-09-24.

How our learning is designed