One candidate. Many systems. One business responsibility.
Follow a single resume as it moves through job portals, email, WhatsApp, ATS platforms, spreadsheets, clients, vendors, AI tools and backups - and count every place it ends up, and where you lose control of it.
- 1
Candidate sourcing
+6 places · 6 so farProfiles arrive from job portals, LinkedIn, referrals, walk-ins and old databases - often before the candidate has spoken to anyone.
Moving hereIdentity data (new at this stage)Contact data (new at this stage)Professional data (new at this stage)Device & technical data (new at this stage)DPDPATell the candidate what you collect and why, at or before collection.
- 2
Registration & consent control breaks
+1 place · 7 so farA profile is created in the ATS. Notice shown, consent captured - including whether the CV may be shared with clients.
Where control breaks: Old profiles kept forever 'for future roles'
Moving hereIdentity dataContact dataProfessional dataDevice & technical dataDPDPAKeep evidence of what the candidate agreed to, and make withdrawal as easy as consent.
- 3
Resume screening control breaks
+4 places · 11 so farRecruiters download, shortlist and enrich profiles - notes, scores and AI summaries are added, and copies land in trackers and laptops.
Where control breaks: Shared Excel tracker duplicates the pipeline · Unapproved AI tool ingests CVs · Laptop downloads outlive the recruiter
Moving hereFinancial data (new at this stage)Derived & inferred data (new at this stage)Identity dataContact dataProfessional dataDPDPAUse the profile only for the hiring purpose it was collected for.
- 4
Candidate engagement control breaks
+1 place · 12 so farCalls, email and WhatsApp: salary expectations, notice periods and documents move through chat threads and inboxes.
Where control breaks: Personal WhatsApp holds candidate documents
Moving hereCommunication data (new at this stage)Identity dataContact dataProfessional dataFinancial dataDPDPACandidate data on personal devices is still your responsibility - keep it in managed systems.
- 5
Assessment
+2 places · 14 so farTests and recorded video interviews run on vendor platforms - scores, recordings and proctoring logs are created outside your systems.
Moving hereAssessment data (new at this stage)Identity dataContact dataCommunication dataDevice & technical dataDerived & inferred dataDPDPAVendors processing candidate data need clear responsibilities and limits.
- 6
Client submission control breaks
+3 places · 17 so farCVs, salary details and recruiter notes go to client HR by email, portal upload or WhatsApp - and get forwarded inside the client.
Where control breaks: Client email attachments leave your control
Moving hereIdentity dataContact dataProfessional dataFinancial dataDerived & inferred dataDPDPAShare only what the client needs, after the candidate has agreed to be submitted.
- 7
Interview management
+1 place · 18 so farScheduling, panel feedback and recordings - subjective comments and evaluations accumulate against the profile.
Moving hereContact dataAssessment dataCommunication dataDerived & inferred dataDPDPAInterview notes are the candidate's personal data too - keep them professional and correctable.
- 8
Background verification control breaks
+2 places · 20 so farPAN, ID documents, payslips and certificates flow to BGV vendors, who contact past employers and institutions.
Where control breaks: Identity documents emailed to the BGV vendor
Moving hereEducation data (new at this stage)Verification data (new at this stage)Identity dataProfessional dataFinancial dataDPDPAHigh-impact identity and financial documents need a clear basis, minimum copies and protected transfer.
- 9
Offer management
+1 place · 21 so farOffer letters, bank details and joining documents move through e-sign tools, email and shared drives.
Moving hereIdentity dataContact dataFinancial dataDPDPACollect joining documents only when the offer is real, and review what you keep if the candidate declines.
- 10
Archive, retention & deletion
+3 places · 24 so farCopies remain in ATS archives, mailboxes, drives, laptops, backups and print - long after the hiring purpose has ended.
Moving hereIdentity dataProfessional dataFinancial dataAssessment dataVerification dataCommunication dataDPDPAWhen the purpose ends, review retention - and be able to erase every copy when asked.
Top risk hotspots - where control usually breaks
The seven places recruitment agencies most often lose track of candidate data. Each links to the matching check in the readiness assessment.
- Hotspot 1 Critical risk
CVs, ID documents and salary chats sit on recruiters' personal phones, auto-downloaded and backed up to personal cloud accounts.
Why this matters
The agency cannot find, protect or delete these copies - an erasure request cannot reach a personal phone backup.
Fix: Move to an official business account, stop exchanging identity documents in chat, and record key interactions in the ATS.
Check this in the assessment - Hotspot 2 High risk
The whole candidate pipeline - names, mobiles, salaries, status - lives in a spreadsheet copied per recruiter and shared onward.
Why this matters
One file leaks the entire candidate list; there is no access control, no audit trail and no deletion.
Fix: Keep master data in the ATS, restrict tracker access, and set a deletion rule for exports.
Check this in the assessment - Hotspot 3 High risk
CVs with salary expectations and recruiter notes are emailed to client HR - then forwarded and stored inside the client indefinitely.
Why this matters
After submission the agency has zero visibility or control, yet remains responsible for the candidate relationship.
Fix: Confirm candidate willingness first, send only necessary fields, and agree client handling expectations in the contract.
Check this in the assessment - Hotspot 4 Critical risk
Recruiters paste CVs into free AI tools for summaries and rankings - no contract, unknown retention, possible model-training use.
Why this matters
Candidate data leaves the organisation into a tool nobody vetted, and AI-generated scores flow back into decisions unexplained.
Fix: Establish an approved-tool list, review provider terms, and never upload identity or financial documents.
Check this in the assessment - Hotspot 5 High risk
Downloads folders accumulate CVs and document packs locally - invisible to any system, surviving employee exits.
Why this matters
Local copies are the ones nobody can enumerate when a candidate asks 'delete my data'.
Fix: Work inside the ATS where possible, and wipe candidate files from devices at offboarding.
Check this in the assessment - Hotspot 6 High risk
Every profile ever registered stays in the pool and shared drives, reused for new mandates years later without a fresh notice.
Why this matters
Purpose ended long ago; indefinite retention of rejected and inactive profiles is the single most common DPDPA gap.
Fix: Segment active vs inactive profiles, define a future-opportunity period, and delete stale records with evidence.
Check this in the assessment - Hotspot 7 High risk
PAN, ID proofs, payslips and certificates are forwarded to verification vendors as plain email attachments.
Why this matters
The heaviest identity-document bundle in the flow travels unprotected and is retained by the vendor on unknown terms.
Fix: Use protected transfer, send the minimum document set, and agree vendor retention and deletion contractually.
Check this in the assessment
How to read this journey
The places add up
Each stage shows the new places the data reaches - inboxes, spreadsheets, laptops, vendor tools, backups. Every place is counted once, so the running counter always matches the systems listed above it.
When it leaves you
A violet left edge and a tag mark systems outside your agency - clients, vendors, public sources and third parties. Once data lands there your control is indirect: it runs through your contract and your instructions, not your admin panel. Risk is shown separately, as an amber or red fill - so an outside system can be low risk, and an in-house one can be high risk.
Where control breaks
Red flags mark the hotspots - the stages where agencies most often lose track of candidate data. Tap any system to see what it holds and how to fix it.
Now check whether your controls hold up
The map shows where candidate data travels in a typical agency. The 3-minute readiness scan checks whether your agency has the controls that matter at each hotspot - and the Discovery tool builds your own data inventory.
Educational reference model - not legal advice, and not a scan of your actual systems.