DPDP Rules, 2025 are now in effect. See where your business stands, in 3–5 minutes.Find out — free →
Where your data travels · Recruitment

One candidate. Many systems. One business responsibility.

Follow a single resume as it moves through job portals, email, WhatsApp, ATS platforms, spreadsheets, clients, vendors, AI tools and backups - and count every place it ends up, and where you lose control of it.

Show the journey for:
10 stages
  1. 1

    Candidate sourcing

    +6 places · 6 so far

    Profiles arrive from job portals, LinkedIn, referrals, walk-ins and old databases - often before the candidate has spoken to anyone.

    Moving hereIdentity data (new at this stage)Contact data (new at this stage)Professional data (new at this stage)Device & technical data (new at this stage)

    DPDPATell the candidate what you collect and why, at or before collection.

  2. 2

    Registration & consent control breaks

    +1 place · 7 so far

    A profile is created in the ATS. Notice shown, consent captured - including whether the CV may be shared with clients.

    Where control breaks: Old profiles kept forever 'for future roles'

    Moving hereIdentity dataContact dataProfessional dataDevice & technical data

    DPDPAKeep evidence of what the candidate agreed to, and make withdrawal as easy as consent.

  3. 3

    Resume screening control breaks

    +4 places · 11 so far

    Recruiters download, shortlist and enrich profiles - notes, scores and AI summaries are added, and copies land in trackers and laptops.

    Where control breaks: Shared Excel tracker duplicates the pipeline · Unapproved AI tool ingests CVs · Laptop downloads outlive the recruiter

    Moving hereFinancial data (new at this stage)Derived & inferred data (new at this stage)Identity dataContact dataProfessional data

    DPDPAUse the profile only for the hiring purpose it was collected for.

  4. 4

    Candidate engagement control breaks

    +1 place · 12 so far

    Calls, email and WhatsApp: salary expectations, notice periods and documents move through chat threads and inboxes.

    Where control breaks: Personal WhatsApp holds candidate documents

    Moving hereCommunication data (new at this stage)Identity dataContact dataProfessional dataFinancial data

    DPDPACandidate data on personal devices is still your responsibility - keep it in managed systems.

  5. 5

    Assessment

    +2 places · 14 so far

    Tests and recorded video interviews run on vendor platforms - scores, recordings and proctoring logs are created outside your systems.

    Moving hereAssessment data (new at this stage)Identity dataContact dataCommunication dataDevice & technical dataDerived & inferred data

    DPDPAVendors processing candidate data need clear responsibilities and limits.

  6. 6

    Client submission control breaks

    +3 places · 17 so far

    CVs, salary details and recruiter notes go to client HR by email, portal upload or WhatsApp - and get forwarded inside the client.

    Where control breaks: Client email attachments leave your control

    Moving hereIdentity dataContact dataProfessional dataFinancial dataDerived & inferred data

    DPDPAShare only what the client needs, after the candidate has agreed to be submitted.

  7. 7

    Interview management

    +1 place · 18 so far

    Scheduling, panel feedback and recordings - subjective comments and evaluations accumulate against the profile.

    Moving hereContact dataAssessment dataCommunication dataDerived & inferred data

    DPDPAInterview notes are the candidate's personal data too - keep them professional and correctable.

  8. 8

    Background verification control breaks

    +2 places · 20 so far

    PAN, ID documents, payslips and certificates flow to BGV vendors, who contact past employers and institutions.

    Where control breaks: Identity documents emailed to the BGV vendor

    Moving hereEducation data (new at this stage)Verification data (new at this stage)Identity dataProfessional dataFinancial data

    DPDPAHigh-impact identity and financial documents need a clear basis, minimum copies and protected transfer.

  9. 9

    Offer management

    +1 place · 21 so far

    Offer letters, bank details and joining documents move through e-sign tools, email and shared drives.

    Moving hereIdentity dataContact dataFinancial data

    DPDPACollect joining documents only when the offer is real, and review what you keep if the candidate declines.

  10. 10

    Archive, retention & deletion

    +3 places · 24 so far

    Copies remain in ATS archives, mailboxes, drives, laptops, backups and print - long after the hiring purpose has ended.

    Moving hereIdentity dataProfessional dataFinancial dataAssessment dataVerification dataCommunication data

    DPDPAWhen the purpose ends, review retention - and be able to erase every copy when asked.

In this reference model, one candidate's data ends up in 24 distinct places across 10 stages, with 7 places where control breaks.

Top risk hotspots - where control usually breaks

The seven places recruitment agencies most often lose track of candidate data. Each links to the matching check in the readiness assessment.

  1. Hotspot 1 Critical risk

    CVs, ID documents and salary chats sit on recruiters' personal phones, auto-downloaded and backed up to personal cloud accounts.

    Why this matters

    The agency cannot find, protect or delete these copies - an erasure request cannot reach a personal phone backup.

    Fix: Move to an official business account, stop exchanging identity documents in chat, and record key interactions in the ATS.

    Check this in the assessment
  2. Hotspot 2 High risk

    The whole candidate pipeline - names, mobiles, salaries, status - lives in a spreadsheet copied per recruiter and shared onward.

    Why this matters

    One file leaks the entire candidate list; there is no access control, no audit trail and no deletion.

    Fix: Keep master data in the ATS, restrict tracker access, and set a deletion rule for exports.

    Check this in the assessment
  3. Hotspot 3 High risk

    CVs with salary expectations and recruiter notes are emailed to client HR - then forwarded and stored inside the client indefinitely.

    Why this matters

    After submission the agency has zero visibility or control, yet remains responsible for the candidate relationship.

    Fix: Confirm candidate willingness first, send only necessary fields, and agree client handling expectations in the contract.

    Check this in the assessment
  4. Hotspot 4 Critical risk

    Recruiters paste CVs into free AI tools for summaries and rankings - no contract, unknown retention, possible model-training use.

    Why this matters

    Candidate data leaves the organisation into a tool nobody vetted, and AI-generated scores flow back into decisions unexplained.

    Fix: Establish an approved-tool list, review provider terms, and never upload identity or financial documents.

    Check this in the assessment
  5. Hotspot 5 High risk

    Downloads folders accumulate CVs and document packs locally - invisible to any system, surviving employee exits.

    Why this matters

    Local copies are the ones nobody can enumerate when a candidate asks 'delete my data'.

    Fix: Work inside the ATS where possible, and wipe candidate files from devices at offboarding.

    Check this in the assessment
  6. Hotspot 6 High risk

    Every profile ever registered stays in the pool and shared drives, reused for new mandates years later without a fresh notice.

    Why this matters

    Purpose ended long ago; indefinite retention of rejected and inactive profiles is the single most common DPDPA gap.

    Fix: Segment active vs inactive profiles, define a future-opportunity period, and delete stale records with evidence.

    Check this in the assessment
  7. Hotspot 7 High risk

    PAN, ID proofs, payslips and certificates are forwarded to verification vendors as plain email attachments.

    Why this matters

    The heaviest identity-document bundle in the flow travels unprotected and is retained by the vendor on unknown terms.

    Fix: Use protected transfer, send the minimum document set, and agree vendor retention and deletion contractually.

    Check this in the assessment

How to read this journey

The places add up

Each stage shows the new places the data reaches - inboxes, spreadsheets, laptops, vendor tools, backups. Every place is counted once, so the running counter always matches the systems listed above it.

When it leaves you

A violet left edge and a tag mark systems outside your agency - clients, vendors, public sources and third parties. Once data lands there your control is indirect: it runs through your contract and your instructions, not your admin panel. Risk is shown separately, as an amber or red fill - so an outside system can be low risk, and an in-house one can be high risk.

Where control breaks

Red flags mark the hotspots - the stages where agencies most often lose track of candidate data. Tap any system to see what it holds and how to fix it.

Now check whether your controls hold up

The map shows where candidate data travels in a typical agency. The 3-minute readiness scan checks whether your agency has the controls that matter at each hotspot - and the Discovery tool builds your own data inventory.

Educational reference model - not legal advice, and not a scan of your actual systems.