Do Not Give Every Candidate File the Same Deletion Date
A UK workflow for retaining and deleting CVs, interview recordings, AI scores, training copies, backups and vendor-held candidate data.

UK position checked 24 September 2026.
There is no universal UK retention period for AI recruitment data. The UK GDPR does not prescribe a number of months or years for candidate records. It requires an employer to keep identifiable personal data no longer than necessary for its stated purpose—and to be able to justify the period it chooses (ICO storage-limitation guidance).
That means “delete the applicant record after 12 months” is not a complete policy. One application can produce a CV, interview recording, transcript, competency scores, ranking, recruiter notes, equality-monitoring data, audit logs, model-development copies and backups. Each may have a different purpose, owner and deletion route.
Build the schedule around data and purpose
Use a row for each data category rather than one row for the candidate.
| Data category | Retention decision to document | Common control mistake |
|---|---|---|
| CV and application answers | Keep through selection, then only for a defined follow-up purpose such as handling a recruitment challenge. Treat future-vacancy matching as a separate purpose with its own period and privacy information. | Retaining every rejected application indefinitely in a searchable talent pool. |
| Interview audio or video | Decide whether the original recording is still needed after transcription, scoring and any quality-review window. If not, delete it before the rest of the application record. | Keeping high-volume recordings merely because storage is cheap. |
| Transcript | Give it its own period. Deleting the video does not delete the transcript; a transcript that relates to an identifiable candidate remains personal data. | Treating a transcript as anonymous because the candidate’s image is gone. |
| Derived features, scores and rankings | Keep candidate-linked outputs only while needed for the hiring decision, review, accuracy check or a documented dispute. | Deleting the visible application while leaving the candidate’s feature vector and score in an analytics table. |
| Recruiter notes and decision record | Preserve the minimum record needed to explain the decision or address a reasonably anticipated claim; remove irrelevant free-text comments. | Keeping the entire digital file because one small part may be relevant later. |
| Equality-monitoring or bias-testing data | Define a separate purpose, access model, lawful basis and, where applicable, special-category condition. Consider retaining genuinely anonymised aggregate results instead of candidate-level data. | Reusing demographic data for selection, or assuming pseudonymisation takes it outside data-protection law. |
| Training, testing and validation copies | Treat model development as a distinct purpose. Decide who is controller for it, document the basis, and delete datasets when no longer required. | Assuming a vendor may reuse applications to improve a shared model because it also processes them for recruitment. |
| Vendor, sub-processor and backup copies | Apply the relevant expiry trigger throughout the supply chain, with a defined backup overwrite cycle and evidence of completion. | Deleting the ATS record but leaving copies in an assessment platform, support tool, data warehouse or backup. |
The ICO’s November 2024 audit found that providers commonly let recruiters set retention at one or two years after a requisition closed. That was an observation, not a regulator-approved default. The report recommended recording how long the provider keeps each category, why it is kept and what happens at expiry. It also identified a service whose retention clock restarted whenever a profile was updated, leaving most profiles retained indefinitely in practice (ICO AI recruitment audit report).
Turn the schedule into an enforceable decision
1. Map every copy and assign roles by purpose
Trace data from the application form through the ATS, interview or assessment provider, analytics warehouse, support system, sub-processors and backups. For each purpose, record whether each organisation acts as controller, joint controller or processor.
A vendor acting only on documented instructions may be a processor for scoring an employer’s candidates. If it combines customers’ candidate data to train a shared product for its own purposes, the ICO’s audit says it is the controller for that separate processing. A contract label does not settle the factual role.
This data-flow work belongs in the recruitment AI DPIA, not only in a procurement spreadsheet.
2. Give each period a trigger, purpose and end action
A usable, illustrative entry might say:
Interview video: retained from submission until 30 days after the hiring decision to support transcription checks and candidate review; then securely deleted from live storage and placed beyond use until the next scheduled backup overwrite.
Thirty days is an example, not a legal default. The employer must choose and justify the period. “Retain for one year” is weaker because it does not identify when the year begins, why the data remains necessary or what deletion means. Possible triggers include application withdrawal, hiring decision, requisition closure, expiry of a defined challenge period or termination of the vendor contract.
If legal-claims defence is the reason, have UK employment counsel identify the applicable limitation period and preserve only potentially relevant material. The ICO says unsuccessful-candidate records should not ordinarily remain beyond the statutory claim period without a clear business reason; information that could not be relevant to a claim can still be deleted (ICO storage-limitation guidance). “Possible litigation” should not become a permanent hold on every recording and score.
3. Separate hiring from talent pooling and model improvement
Keeping a CV for the role applied for does not automatically justify retaining it for future vacancies. Reusing a candidate’s interview, transcript or score to train a shared model is also a distinct purpose requiring its own role analysis, lawful basis, transparency and retention decision.
A privacy notice is not itself permission. It must accurately describe the processing and basis; see candidate consent versus privacy notice. The ICO says privacy information must state either the retention period or the criteria used to determine it. It must also cover recipients and, where applicable, solely automated decision-making and profiling (ICO privacy-information guidance).
4. Make vendor deletion testable
For a processor, Article 28 contract terms must cover the processing duration. At contract end, the processor must return or delete the personal data at the controller’s choice and delete existing copies unless UK law requires storage. Sub-processors need equivalent protections. The ICO recognises that backups may not be erased immediately if the data is put beyond use, protected and deleted on an appropriate cycle (ICO processor-contract guidance).
Ask the vendor to demonstrate:
- category-specific deletion rules, not just account deletion;
- propagation to indexes, candidate-linked feature stores and sub-processors;
- the backup overwrite period and “beyond use” controls;
- treatment of support exports and disaster-recovery copies;
- deletion logs, exception reports and failed-job escalation; and
- what happens to training copies where the vendor is a separate controller.
Run a sample deletion and inspect the evidence. A contractual promise without an operating control does not establish that deletion occurred.
What candidates can ask for
A candidate can make a subject access request to the employer for confirmation that it processes their personal information and a copy of that information. This can cover candidate-linked application materials, recordings, transcripts and AI-derived scores. The supplementary information includes the purposes, retention period or criteria, recipients, data source and relevant information about automated decision-making. Controllers remain responsible for the response and must be able to retrieve personal information held by their processors (ICO right-of-access guidance, updated 8 December 2025). Exemptions may limit what must be disclosed in a particular case.
Candidates may also request erasure, but that right is not absolute. An organisation may retain data where processing is necessary for a legal obligation or the establishment, exercise or defence of legal claims. It must assess the request rather than apply a blanket refusal. If a valid request applies, the employer may also have to notify recipients and address backups; data awaiting scheduled overwrite must be put beyond use (ICO right-to-erasure guidance).
The operational test is straightforward: for every candidate-data copy, the employer should be able to name its purpose, responsible party, expiry trigger, end action and evidence that the action occurred. If one of those fields is blank, the retention decision is not finished.
Several ICO pages cited here say they are under review following the Data (Use and Access) Act. This article is informational, not legal or employment advice; confirm the current UK rules and claim periods for the particular recruitment process.