Data Retention Questions for ATS Vendors
A vendor-neutral ATS data-retention questionnaire covering purpose, deletion, backups, exports, access, subprocessors, incidents, cost and exit tests.

An ATS can hold applications, CVs, notes, assessments, messages, audit events and integration copies. “Deleted from the account” does not say when each class leaves primary storage, indexes, logs, replicas, backups, exports or support records. Ask for the lifecycle in writing, test it with synthetic records and mark unresolved answers unknown.
This vendor-neutral guide teaches a product owner how to run the evidence review; it is not legal advice or a certification. Confirm requirements with privacy, legal and security owners.
Put the ATS in the right tool taxonomy
Name the job, source of truth and every connected copy before comparing vendors.
| Tool or service | Typical purpose | Retention question to add |
|---|---|---|
| ATS | Applications and stages | Which records, attachments, indexes and audit events are stored, and when does each clock start? |
| Sourcing/ranking | Discover or compare candidates | Is a result temporary, saved or exported, and who removes it? |
| Outreach/assessment/HRIS | Messages, specialist steps or employee records | What copies exist and which system owns correction or deletion? |
Send a fixed scenario and request evidence
Give each vendor the role, candidate count, classes, countries, reviewers, integrations and exit date. Require answers labelled default, configurable, contractual, tested or unknown.
For this candidate lifecycle, what data do you store, for what purpose, where is it processed, when does each clock start and end, and how can we verify deletion across live systems, indexes, logs, replicas, backups, exports, subprocessors and support records?
Request dated source.
Ask about classes, purposes and clocks
Enumerate identity/application fields, CVs/attachments, notes/scorecards, communications, decisions/audit, analytics/derived data, access/support records, queues and exports. For each class ask purpose, trigger, unit, time zone, reset/pause behaviour, lifecycle treatment, deletion/anonymisation result and due/held/expired reporting. Ask whether free-text or attachments contain sensitive information; pause and route unexpected classes through approved process.
| Data class | Evidence to request |
|---|---|
| Identity, application, CV and notes | Data dictionary, object map, attachment/parser lifecycle, required fields and object-level deletion test |
| Communications, decisions and audit | Channel map, audit schema, permissions, retention schedule and export sample |
| Analytics, indexes and derived data | Purpose statement, derived-data map and deletion propagation test |
| Access, support, queues and exports | Support-data classes, flow diagram, queue/log retention and copy owner |
The ICO storage-limitation guidance (checked 5 September 2026) says UK GDPR does not set one universal period; justify the period and erase or anonymise data when no longer needed. The GDPR, adopted 27 April 2016, contains storage limitation in Article 5(1)(e) and erasure rights in Article 17. EDPB Guidelines 07/2020, final version adopted 7 July 2021, help frame controller/processor questions. These are general prompts, not a legal conclusion or contract number.
Ask about holds and real deletion
Require a scoped, authorised, reviewed and releasable hold for a complaint, access request, investigation, litigation hold or regulatory inquiry. Record scope, reason, actor, dates and release owner; do not preserve everything by default.
Demonstrate administrator deletion, automated expiry and account cancellation for one synthetic candidate, attachment and audit event. Test every surface:
| Surface | Questions and evidence |
|---|---|
| Primary, search and derived data | Is the object removed or hidden? When do indexes, caches, recommendations and representations update? Run a distinctive-string search. |
| Audit and support | What minimum event remains, can it identify the person, and are tickets, screenshots, logs or recordings in scope? |
| Integrations and subprocessors | Are webhooks, retries, file drops, connector caches and downstream providers deleted or stopped? Request flow-specific acknowledgement. |
| Replicas and backups | When do active replicas and backup sets expire? How are restore, access control and residual data handled? |
| Anonymisation | Which fields remain and can the result reasonably be linked back? Request method and re-identification rationale. |
Record completion as target, default or contractual. Require retry/alert/quarantine/manual remediation, notification, owner and request ID for failures. The ICO access guidance (updated 4 November 2025) says archived or backed-up information still needs retrieval procedures. NIST SP 800-88 Rev. 2, published September 2025, is media-sanitisation guidance, not proof of an ATS control.
Ask about export, access and location
Before cancellation, test an authorised export of applications, CVs, notes, scorecards, communications, decisions, audit history, files, IDs, relationships and hold/deletion state. Ask about metadata, timestamps, history, limits, fees, lead time, correction and post-cancellation access. Store it in an approved location with an owner, expiry and deletion date.
Map customer/vendor roles, privileged support access, production/DR/support/analytics/parsing/search locations, backups, subprocessors and transfers for the actual plan and region. Request role matrix, access audit, subprocessor list, data-flow diagram, regional commitment, transfer terms and change/objection process. Mark marketing-only answers unknown.
Ask about audit, incidents, support and cost
Require logs for candidate, admin, API, export, permission, deletion, hold and support events with actor, object, action, result, time and request ID. Ask how logs are immutable, searchable, exported, retained and deleted. Request an incident plan covering detection, recovery, contact, notification, failed-deletion escalation and temporary copies; run a synthetic-record tabletop.
| Cost or support item | Evidence to record |
|---|---|
| Configuration, holds, deletion and export | Quoted plan, settings, request route, limits, fees, SLA and sample result |
| Support, integrations and cancellation | Severity/channel, escalation, partner-copy cleanup, renewal, lock, grace period and final deletion date |
| Internal work | Owner, hours, access reviews, requests, exports, incident response and manual fallback |
Request a dated, plan-specific quote. Do not invent pricing; unpriced work is an assumption, not zero cost.
Run the product-owner operator runbook
- Name scope and owners. Record role, workspace, plan, regions, classes, integrations, reviewers and decision date.
- Map the lifecycle. Mark collection, review, decision, talent pool, hire, withdrawal, hold, export, cancellation, deletion and copies.
- Date answers and use synthetic records. Label each answer and include a distinctive CV string, attachment, note, scorecard, message and audit event.
- Test and verify. Run correction, withdrawal, hold, expiry, deletion, failed deletion, export, cancellation and restore tests across views, APIs, indexes, queues, logs, support, subprocessors, replicas and backups; record IDs, times and results.
- Price and decide. Include configuration, requests, exports, support, cleanup, incidents, internal time and exit. Choose PASS, PILOT WITH CONDITIONS or STOP, with owner, due date and evidence for each condition.
Worked hiring scenario
A fictional 80-person company receives 120 applications for one product-designer role, with six interviewers, a mailbox connector and a talent-pool option. It uses no real candidate data in the pilot. It records application fields, CVs, notes, scorecards, email events, audit logs, exports, queues and support tickets separately. A vendor says profile deletion leaves a redacted audit event and backups expire on schedule; the team requests dated evidence for indexes, connector, support ticket and export. The answer remains unknown until the synthetic CV string disappears from search or a documented residual exception is verified.
Stop conditions
Stop when the vendor cannot identify classes/purposes, clocks, copy owners, hold release, deletion evidence, export/access, privileged access, subprocessors/locations, incident ownership, escalation or a priced exit. Also stop for unavailable logs, indefinite backups, incomplete exports or no lifecycle monitor. Any exception must name the gap, classes, risk owner, action, due date and stop trigger.
Where Talent Summoner fits
Talent Summoner is our product for candidate sourcing and supplied-CV ranking, not an ATS or records-retention system. Candidate sourcing starts from a role brief and discovers public professional profiles for human review; candidate ranking compares supplied CVs and returns a ranked report. Neither replaces ATS stages, interview records, inbox, holds, exports, deletion schedules or hiring decisions. Keep outputs and downstream ATS records in your approved lifecycle, verify the hand-off and retain human ownership.
What is the first data-retention question to ask an ATS vendor?
Ask for every data class, purpose, clock trigger, location, deletion behavior and evidence across primary storage, indexes, backups, exports and subprocessors.
Is a vendor's default retention period enough?
No. It may be configurable, plan-limited or renewed by activity and cover only one system. Test the setting and every relevant copy.
Does deleting a candidate delete backups?
Not necessarily. Ask when replicas and backups expire, how restore handles deleted data and what evidence confirms the schedule.
What should an ATS export include before cancellation?
Agree fields, attachments, notes, scorecards, communications, relationships, timestamps, audit history and hold/deletion state. Test completeness, fees, lead time and post-cancellation access.
How should we handle a legal hold during deletion?
Pause only the scoped records and classes required by the approved process, record authority and review/release details, and route conflicts to your privacy or legal owner.
Is Talent Summoner an ATS or retention system?
No. Talent Summoner supports candidate sourcing and supplied-CV ranking. Your team owns ATS records, retention, deletion and the final decision.
What is a good stop condition for an ATS evaluation?
Stop when the vendor cannot identify a clock, copy, access route, export, deletion test, subprocessor, incident owner or priced exit path. Record any authorised, time-bound exception.
Take one realistic hiring lifecycle to each vendor, preserve dated answers and raw test evidence, then choose PASS, PILOT WITH CONDITIONS or STOP. Start with candidate sourcing for approved discovery and move to candidate ranking for supplied CVs; keep ATS retention and deletion ownership explicit at the hand-off.


