Exporting Candidate Evidence Safely

A vendor-neutral guide to classifying, exporting, transferring and deleting candidate evidence with tests, recovery and stop conditions.

Exporting Candidate Evidence Safely

An export is a new copy of candidate evidence, not a harmless download. This vendor-neutral guide helps an IT reviewer move a minimum, traceable record between systems. It is a commercial investigation aid, not legal, privacy, security, employment or procurement advice. Keep unknown until a dated answer or test resolves it.

Define the export

Start with the business decision, source, destination, named recipients, retention trigger and owners. Write a field-level allowlist before selecting a route. Exclude unrelated content, secrets, hidden metadata and unapproved sensitive details. Label source observation, candidate statement, reviewer opinion and unknown separately.

ClassExamplesRequired question
Public contextURL, title, capture date, role-related signalCan the observation be retraced?
Candidate-providedCV, portfolio, contact detail, stated constraintWho may view it and why?
Internal reviewNote, rubric result, reviewer, next actionIs this fact, opinion or unknown?
RestrictedHealth, identity, financial or background detailIs separate approval and access required?
SecretsAPI key, token, password, signing materialExclude; rotate or revoke if exposed.

The ICO data-minimisation guidance (checked 2 September 2026) describes data as adequate, relevant and limited to what is necessary and recommends periodic deletion. This is a process prompt, not a legal conclusion.

Compare the route

Compare the complete path, including temporary files, logs, backups and destination copies. A file may be easier to inspect; an API adds scope, pagination and rate-limit risk; a link may hide forwarding and revocation risk.

RouteEvidence to requestTypical failure
File/API/connectorField map, format, version, IDs, pagination, limits, scopes, logs, rollbackMissing pages, fields or destination writes
Scheduled exchangeSchema, manifest, checksum, encryption, key owner, expiry and deletionStale or duplicate shared file
Share link/reportNamed identity, expiry, revocation, download and viewer auditForwarded link or inherited access
Manual/emailApproved destination, local-device handling, redaction and delivery proofUnowned copy with excess fields

Run the checks in order

1. Format and integrity

Choose machine-readable output for reconciliation and a human report only for review. Test encoding, delimiters, nulls, dates/time zones, Unicode, long text, attachments, links, page order and metadata. For CSV/JSON, test quotes, empty values and repeated IDs; for PDF, inspect extracted text and link targets. Require a manifest with export ID, source/version, count, schema, timestamps, filenames, checksum, redaction rule and owner.

2. Identity and authorisation

Record the initiating identity or service account, scopes, expiry, rotation and revocation path, plus the candidate objects it can access. Test object-level and function-level authorisation with a role-limited operator, a removed administrator and a second tenant. The OWASP API Security Top 10 (2023) is an awareness reference, not supplier certification.

3. Encryption and transfer

Ask for the exact in-transit and at-rest protocol, endpoint, storage layer, key owner, rotation, temporary-file, log, backup and support-access behaviour. NIST SP 800-57 Part 1 Rev. 5 (May 2020) is a key-management reference, not implementation proof. Confirm whether recipients can download plaintext. For an external or overseas recipient, record legal entity, location, onward access and transfer mechanism. The ICO international-transfer guide was updated 15 January 2026; a small file or expiring link is not automatically outside the transfer boundary.

4. Recipients and audit

Use named accounts or an approved group, least privilege, expiry and tested revocation. Keep an export ID linking the source record set, approval, field specification, redaction, files, checksum, delivery, recipient, access, corrections and deletion. Logs need access control and a retention period; they can contain candidate identifiers. If the product reports only "export complete", mark evidence partial and reconcile IDs and counts.

5. Retention and recovery

Set separate dates or triggers for source, destination, workspace, download, link, attachment, logs, snapshots and backups. Define legal-hold exceptions and what deletion means for active storage, backups and recipient copies. Test timeout, rate-limit, duplicate, truncation, checksum, wrong-recipient and deletion failures with synthetic or redacted records. Freeze downstream import, preserve the partial artifact and export ID, compare immutable IDs, then resume from a known cursor or last-known-good version. Use bounded backoff; do not retry uncertain writes blindly.

The EU GDPR is dated 27 April 2016; the NIST Privacy Framework 1.0 is voluntary guidance published January 2020; the NIST CSF 2.0 is dated 26 February 2024; and SP 800-61 Rev. 3 April 2025. Use them to assign owners, not to claim compliance.

Five-candidate dry run

This synthetic Hong Kong example moves five shortlisted candidates from a sourcing workspace to an ATS. Minimum package is candidate/role ID, source or supplied-file and date, job-related evidence, evidence type, criterion version, reviewer, unknowns and next action. Phone numbers, unrelated content, notes and hidden metadata are excluded.

The dry run finds a truncated CSV note, a PDF without source URL/criterion version and a folder inherited by all employees. The reviewer rejects it, fixes encoding/provenance, removes inherited access and retests. An external interviewer receives nothing until the privacy owner approves fields, route, retention and deletion. Unknown support or backup access is STOP.

Support, cost and stop controls

Request a dated, route-specific answer for formats/limits, mapping, authentication, encryption, locations, subprocessors, support, logs, retention/deletion, overage, implementation, renewal and exit. Record currency, term, usage, destination costs and review hours; an unpriced item is unknown, not zero.

Stop when purpose, allowlist, recipient, authorisation, transfer, encryption, reconciliation, recovery, deletion or ownership is unresolved; when retries can lose or duplicate records; or when support, cost or exit evidence is insufficient. Use PILOT WITH CONDITIONS only with an owner, deadline, compensating control and rollback trigger.

Where Talent Summoner fits

Talent Summoner is our product for candidate sourcing and ranking. The public candidate-sourcing page describes role-brief discovery and ranked public-source results; candidate-ranking describes supplied-CV ranking and shareable/PDF reports. These pages do not establish an ATS/API/SFTP connector or export-control contract. Treat any hand-off as the team's controlled process; the hiring team remains responsible for verification and decisions.

Is a PDF safer than an API?

No. Compare fields, provenance, authorisation, failure recovery and deletion across the full route.

What should be redacted?

Anything not necessary for the stated purpose, especially secrets, unrelated profile content and unapproved sensitive data. Redact before delivery.

How do we transfer to an external interviewer?

Name the legal entity and recipient, limit fields, confirm the route and retention, test revocation and obtain the responsible privacy owner's approval.

What if the export fails halfway?

Pause import, preserve the export ID and partial file, reconcile immutable IDs, then resume from a known cursor or last-known-good version.

Does Talent Summoner provide a secure ATS export?

Its public pages describe sourcing and CV ranking, not an ATS/API/SFTP export or deletion contract. Verify current terms directly and control the hand-off yourself.

Start with one synthetic five-candidate dry run, reconcile the package against the source and retain the approval record with every copy and owner. Then use candidate sourcing for approved discovery or candidate ranking for a supplied CV set.

Copyable export approval record

CANDIDATE EVIDENCE EXPORT RECORD

Decision and role:
Source system / workspace / environment:
Destination system / folder / environment:
Export owner and approving owner:
Privacy, security and procurement reviewers:
Export ID and source query or record-set version:
Dry-run date and live-export date:

SCOPE AND CLASSIFICATION
Purpose of this copy:
Candidate IDs / role IDs in scope:
Allowed fields and purpose for each:
Excluded or redacted fields:
Sensitive or restricted data decision:
Source URLs / supplied-file names and capture dates:

FORMAT AND INTEGRITY
Format, encoding, schema and timezone:
Record and attachment counts:
Manifest and checksum location:
Required links, timestamps, labels and criterion version:
Round-trip or rendered-output test result:

ACCESS AND TRANSFER
Initiating identity, scopes and expiry:
Recipient accounts, legal entities and locations:
Destination roles and download/forward settings:
Encryption route, key owner and rotation evidence:
Support, subprocessor, backup and onward-access boundary:
Transfer review and approval, if applicable:

AUDIT AND LIFECYCLE
Export, delivery and access log locations:
Correction and replacement path:
Source retention date or trigger:
Destination, temporary-file, link, log and backup retention:
Recipient deletion confirmation and date:
Legal hold or exception owner and release condition:

FAILURE AND DECISION
Count, pagination, duplicate, timeout and checksum tests:
Wrong-recipient and revocation tests:
Known failure, containment, owner and retest date:
Support route and response commitment:
Supplier charges, usage, implementation and exit assumptions:
Decision: PASS / PILOT WITH CONDITIONS / STOP:
Release authority and next review trigger:

All Posts