DPDP Rules, 2025 are now in effect. See where your business stands, in 3–5 minutes.Find out — free →
Where your data travels · Recruitment

One candidate. Many systems. One business responsibility.

Follow a single resume as it moves through job portals, email, WhatsApp, ATS platforms, spreadsheets, clients, vendors, AI tools and backups - and count every place it ends up, and where you lose control of it.

Show the journey for:
10 stages
  1. 1

    Candidate sourcing control breaks

    +7 places · 7 so far

    Profiles arrive from job portals, LinkedIn, referrals, walk-ins and old databases - often before the candidate has spoken to anyone.

    Where control breaks: Laptop downloads outlive the recruiter

    Moving hereIdentity data (new at this stage)Contact data (new at this stage)Professional data (new at this stage)Device & technical data (new at this stage)

    DPDPATell the candidate what you collect and why, at or before collection.

  2. 2

    Registration & consent control breaks

    +1 place · 8 so far

    A profile is created in the ATS. Notice shown, consent captured - including whether the CV may be shared with clients.

    Where control breaks: Old profiles kept forever 'for future roles'

    Moving hereIdentity dataContact dataProfessional dataDevice & technical data

    DPDPAKeep evidence of what the candidate agreed to, and make withdrawal as easy as consent.

  3. 3

    Resume screening control breaks

    +2 places · 10 so far

    Recruiters download, shortlist and enrich profiles - notes, scores and AI summaries are added, and copies land in trackers and laptops.

    Where control breaks: Unapproved AI tool ingests CVs

    Moving hereFinancial data (new at this stage)Derived & inferred data (new at this stage)Identity dataContact dataProfessional data

    DPDPAUse the profile only for the hiring purpose it was collected for.

  4. 4

    Candidate engagement control breaks

    +1 place · 11 so far

    Calls, email and WhatsApp: salary expectations, notice periods and documents move through chat threads and inboxes.

    Where control breaks: Personal WhatsApp holds candidate documents

    Moving hereCommunication data (new at this stage)Identity dataContact dataProfessional dataFinancial data

    DPDPACandidate data on personal devices is still your responsibility - keep it in managed systems.

  5. 5

    Assessment control breaks

    +3 places · 14 so far

    Tests and recorded video interviews run on vendor platforms - scores, recordings and proctoring logs are created outside your systems.

    Where control breaks: Shared Excel tracker duplicates the pipeline

    Moving hereAssessment data (new at this stage)Identity dataContact dataCommunication dataDevice & technical dataDerived & inferred data

    DPDPAVendors processing candidate data need clear responsibilities and limits.

  6. 6

    Client submission control breaks

    +3 places · 17 so far

    CVs, salary details and recruiter notes go to client HR by email, portal upload or WhatsApp - and get forwarded inside the client.

    Where control breaks: Client email attachments leave your control

    Moving hereIdentity dataContact dataProfessional dataFinancial dataDerived & inferred data

    DPDPAShare only what the client needs, after the candidate has agreed to be submitted.

  7. 7

    Interview management

    +1 place · 18 so far

    Scheduling, panel feedback and recordings - subjective comments and evaluations accumulate against the profile.

    Moving hereContact dataAssessment dataCommunication dataDerived & inferred data

    DPDPAInterview notes are the candidate's personal data too - keep them professional and correctable.

  8. 8

    Background verification control breaks

    +2 places · 20 so far

    PAN, ID documents, payslips and certificates flow to BGV vendors, who contact past employers and institutions.

    Where control breaks: Identity documents emailed to the BGV vendor

    Moving hereEducation data (new at this stage)Verification data (new at this stage)Identity dataProfessional dataFinancial data

    DPDPAHigh-impact identity and financial documents need a clear basis, minimum copies and protected transfer.

  9. 9

    Offer management

    +1 place · 21 so far

    Offer letters, bank details and joining documents move through e-sign tools, email and shared drives.

    Moving hereIdentity dataContact dataFinancial data

    DPDPACollect joining documents only when the offer is real, and review what you keep if the candidate declines.

  10. 10

    Archive, retention & deletion

    +3 places · 24 so far

    Copies remain in ATS archives, mailboxes, drives, laptops, backups and print - long after the hiring purpose has ended.

    Moving hereIdentity dataProfessional dataFinancial dataAssessment dataVerification dataCommunication data

    DPDPAWhen the purpose ends, review retention - and be able to erase every copy when asked.

In this reference model, one candidate's data ends up in 24 distinct places across 10 stages, with 7 places where control breaks.

Top risk hotspots - where control usually breaks

The 7 places candidate data most often slips out of your control. Each links to the matching check in the readiness assessment.

  1. Hotspot 1 Critical risk

    CVs, ID documents and salary chats sit on recruiters' personal phones, auto-downloaded and backed up to personal cloud accounts.

    Why this matters

    The agency cannot find, protect or delete these copies - an erasure request cannot reach a personal phone backup.

    Fix: Move to an official business account, stop exchanging identity documents in chat, and record key interactions in the ATS.

    Check this in the assessment
  2. Hotspot 2 High risk

    The whole candidate pipeline - names, mobiles, salaries, status - lives in a spreadsheet copied per recruiter and shared onward.

    Why this matters

    One file leaks the entire candidate list; there is no access control, no audit trail and no deletion.

    Fix: Keep master data in the ATS, restrict tracker access, and set a deletion rule for exports.

    Check this in the assessment
  3. Hotspot 3 High risk

    CVs with salary expectations and recruiter notes are emailed to client HR - then forwarded and stored inside the client indefinitely.

    Why this matters

    After submission the agency has zero visibility or control, yet remains responsible for the candidate relationship.

    Fix: Confirm candidate willingness first, send only necessary fields, and agree client handling expectations in the contract.

    Check this in the assessment
  4. Hotspot 4 Critical risk

    Recruiters paste CVs into free AI tools for summaries and rankings - no contract, unknown retention, possible model-training use.

    Why this matters

    Candidate data leaves the organisation into a tool nobody vetted, and AI-generated scores flow back into decisions unexplained.

    Fix: Establish an approved-tool list, review provider terms, and never upload identity or financial documents.

    Check this in the assessment
  5. Hotspot 5 High risk

    Downloads folders accumulate CVs and document packs locally - invisible to any system, surviving employee exits.

    Why this matters

    Local copies are the ones nobody can enumerate when a candidate asks 'delete my data'.

    Fix: Work inside the ATS where possible, and wipe candidate files from devices at offboarding.

    Check this in the assessment
  6. Hotspot 6 High risk

    Every profile ever registered stays in the pool and shared drives, reused for new mandates years later without a fresh notice.

    Why this matters

    Purpose ended long ago; indefinite retention of rejected and inactive profiles is the single most common DPDPA gap.

    Fix: Segment active vs inactive profiles, define a future-opportunity period, and delete stale records with evidence.

    Check this in the assessment
  7. Hotspot 7 High risk

    PAN, ID proofs, payslips and certificates are forwarded to verification vendors as plain email attachments.

    Why this matters

    The heaviest identity-document bundle in the flow travels unprotected and is retained by the vendor on unknown terms.

    Fix: Use protected transfer, send the minimum document set, and agree vendor retention and deletion contractually.

    Check this in the assessment

What happens when someone asks

The map above shows where candidate data ends up. This is what that means the day someone asks you to find it, fix it or remove it - including the places a request realistically cannot reach.

Who asks: A candidate - very often one who was rejected years ago and has just been contacted again.

Where you have to look

  • ATS / recruitment CRMYour agency
  • Old candidate databaseYour agency
  • Shared Excel trackerYour agency
  • Google Drive / OneDriveYour agency
  • Calendar / schedulerYour agency
  • Recruiter emailYour agency
  • Email archiveYour agency
  • Printed CV filesYour agency

Where this usually cannot reach

  • Recruiter WhatsAppYour agency
  • Recruiter laptop downloadsYour agency
  • Cloud backupYour agency
  • Client ATS / portalClient
  • Background verification vendorVendor
  • Unapproved AI resume toolVendor

What has to happen

  1. Resolve the candidate across duplicates - the same person is usually in the database three times from three applications.
  2. Pull the CV, application history, interview notes and the record of which roles they were considered for.
  3. Include what the agency CREATED rather than collected: recruiter comments, suitability ratings, salary expectations noted from a call, any score a tool produced.
  4. Include the assessment and video-interview records if those tools were used.
  5. Name every client their profile was sent to, and the vendors involved - assessment, background verification, e-signature.
  6. Say plainly which places you could not search, and why.

The part that usually fails: Recruiter commentary. The most consequential things written about a candidate - 'not a culture fit', 'seemed underconfident', a salary figure inferred from a conversation - live in ATS free-text, a spreadsheet column and WhatsApp threads. Candidates almost never know these exist, and they are usually the reason they stopped hearing back.

Check whether you could answer this today

When it has already gone wrong

An operational response reference for the incidents this sector actually has - what to do in the first hour, what to put right afterwards, and the control that stops a repeat. Whether an incident needs to be reported is a decision to take with your own advisers.

Severe

How you find out: The candidate calls in distress - or does not call, because they found out when their manager raised it.

Systems involved

  • Recruiter emailYour agency
  • Client HR emailClient
  • ATS / recruitment CRMYour agency
  • Shared Excel trackerYour agency

First - stop it spreading

  1. Establish exactly what was sent, to whom, and whether the recipient is connected to the candidate's employer.
  2. Ask the recipient to delete it and confirm, and withdraw the submission formally.
  3. Stop any further submission of that candidate until they tell you what they want.

Then - correct it and record it

  1. Speak to the candidate first and honestly - their job may be at risk, and how the agency behaves now is the whole relationship.
  2. Work out the cause: a blind mass-submission, a client contact who moved companies, a CV forwarded without checking.
  3. Introduce a rule that a candidate confirms each client before submission, and that do-not-submit employers are recorded.
  4. Log it as a serious incident, because for the candidate it is.

The control that prevents a repeat: Per-role, per-client candidate permission before any submission, a recorded do-not-submit list on every profile, and no CV leaving a recruiter's mailbox without that check.

How to read this journey

The places add up

Each stage shows the new places the data reaches - inboxes, spreadsheets, laptops, vendor tools, backups. Every place is counted once, so the running counter always matches the systems listed above it.

When it leaves you

A violet left edge and a tag mark systems outside your agency - clients, vendors, public sources and third parties. Once data lands there your control is indirect: it runs through your contract and your instructions, not your admin panel. Risk is shown separately, as an amber or red fill - so an outside system can be low risk, and an in-house one can be high risk.

Where control breaks

Red flags mark the hotspots - the stages where agencies most often lose track of candidate data. Tap any system to see what it holds and how to fix it.

Now check whether your controls hold up

The map shows where candidate data travels in a typical agency. The 3-minute readiness scan checks whether your agency has the controls that matter at each hotspot - and the Discovery tool builds your own data inventory.

Educational reference model - not legal advice, and not a scan of your actual systems.