Skip to content
HRaizon Subscribe

Trace Candidate Data Before Approving Recruitment AI

Check recruitment AI subprocessors, overseas access, transfer mechanisms, secondary data use and contract evidence before approving a UK supplier.

Share X in f
Priya Ellison

A UK employer should not accept “UK hosted” as proof that candidate data stays in the UK. Keep approval on hold until every recipient, overseas access route, processing purpose and onward transfer is mapped to a legal role, transfer basis and verifiable control.

A recruitment AI supplier may host its main application in the UK while allowing overseas companies to provide cloud infrastructure, support, messaging, security monitoring or model services. Storage location is only one part of the assessment. This is general information, not legal advice.

Set the three approval gates; the result shows whether the supplier can move forward.

Supplier Approval Gate

Choose the evidence currently available. “Yes” means the evidence has been checked, not merely promised.

DecisionHold approval

Obtain and reconcile the missing evidence before the supplier proceeds.

Evidence needed for a “Yes” answer
  • Named legal entities, purposes, data categories, storage regions and remote-access countries.
  • Applicable transfer mechanisms, parties, onward transfers and transfer assessments.
  • Purpose-by-purpose roles, model or analytics uses, retention periods and deletion treatment.
  • Agreement across the data-flow register, DPA, transfer records and candidate privacy information.

Basis: UK GDPR Article 28 and ICO guidance on international transfers and AI in recruitment, as cited in the accompanying article.

Build A Data-Flow Register Before Reviewing Suppliers

Ask the supplier to complete one row for every recipient and processing activity. A list of supplier names without the associated data, purpose and access locations cannot show whether all transfers are covered.

Field Required Answer
Recipient Full legal entity, not only a product or group name
Service and purpose Hosting, transcription, scoring, support, analytics, security, model API or another defined function
Data CV fields, answers, recordings, transcripts, scores, inferred attributes, identifiers, logs and metadata
Role Controller, joint controller, processor or subprocessor for that activity
Location Storage region and every country from which another organisation can access the data
Onward disclosure Any further recipient used by that organisation
Retention Live-system, model, log, support-ticket and backup periods
Transfer basis Adequacy regulations, an appropriate safeguard or a specified exception
Evidence Contract term, transfer assessment, architecture record, audit report or deletion record

The recruitment supply chain can involve several organisations and sensitive information such as health, diversity and criminal-conviction data. The ICO’s draft recruitment guidance confirms both points. The guidance page also says it is under review following the Data (Use and Access) Act.

Do not limit the map to a CV database. Follow raw inputs and derived data. An interview recording may become a transcript, competency score, system log or support ticket. Establish whether any copy enters analytics, benchmarking, testing or model-development environments.

Eight Checks Turn Supplier Claims Into Evidence

Name Every Legal Entity Receiving Candidate Data

A brand-level answer is insufficient. Ask for the contracting company, its subprocessors and every affiliate permitted to access production data. For each entity, require a description of its purpose and the candidate-data categories it receives.

Verify the answer against a current subprocessor register and system data-flow diagram. Compare both with the data processing agreement (DPA), security documentation and enabled product configuration. A subprocessor listed for an optional feature should not be treated as an active recipient without checking whether that feature is enabled.

Assign Roles Purpose By Purpose

A supplier may be a processor when scoring candidates on an employer’s instructions but a controller for a separate activity it determines, such as building its own candidate database or reusing records to develop products. A label in the contract does not settle the factual role for every activity.

The ICO’s November 2024 audit found several cases in which recruitment AI providers incorrectly characterised themselves as processors rather than controllers. It also reported contracts that omitted providers’ reuse of candidate information to develop AI tools or other products (ICO audit outcomes report).

Require a purpose-by-purpose role table and a written answer to: “Do you use our candidates’ data for any purpose not set in our instructions?” If the answer is yes, require the supplier to identify the data, purpose, role, lawful basis, retention and candidate information supporting that activity.

Confirm Subprocessor Authorisation And Change Rights

Under UK GDPR Article 28, a processor needs the controller’s prior specific or general written authorisation before appointing another processor. Under general authorisation, the processor must notify the controller of intended additions or replacements and allow an opportunity to object.

Equivalent Article 28 obligations must flow down to the subprocessor. The initial processor remains liable to the controller for the subprocessor’s performance (current Article 28 text).

Check the authorisation clause, change-notice period, objection process and dated subprocessor list. Establish what happens operationally after an objection: whether the affected feature can be disabled, another provider can be used or termination is the only option.

“We use industry-standard providers” is not an adequate answer when it omits their legal names and functions.

Separate Storage Regions From Access Locations

Storage and access locations are different questions. The ICO’s international-transfer guide, updated on 15 January 2026, says a restricted transfer can occur when information is made accessible to a separate organisation outside the UK. Its example treats remote access by an Indian support provider as a transfer even though the information is not sent to that provider (ICO international-transfer guide).

Ask for production and backup regions, support-team locations, privileged-access controls and access logs. The supplier should identify every country from which remote access by a separate legal entity is permitted, rather than answering only with the primary cloud region.

Match A Mechanism To Every Restricted Transfer

For each transfer path, determine whether the supplier relies on UK adequacy regulations, an appropriate safeguard such as the International Data Transfer Agreement or UK Addendum, or an Article 49 exception. Where an appropriate safeguard is used, a transfer risk assessment—called a “data protection test” in current legislation—must also be completed (ICO transfer guidance index).

The evidence should name the mechanism, parties, countries, covered data and activities, execution date, assessment owner and review trigger. A DPA alone does not prove that an applicable mechanism covers each restricted transfer and onward transfer.

Check the parties carefully. A mechanism naming the main supplier does not necessarily cover a separate support affiliate or model provider merely because both appear on a subprocessor page.

Test Every Claim About Secondary Use

Ask separately whether candidate data is used to train, tune, test or benchmark customer-specific models, shared models or other products. Include evaluation datasets, product analytics and human review in the question.

“We do not train on your data” leaves open testing, benchmarking, prompt logging and provider abuse monitoring. Require contractual purpose restrictions, relevant configuration settings, data lineage, retention periods and deletion treatment for model-development copies.

Record the answer in the recruitment AI DPIA, not only in procurement notes. The DPIA, contract and candidate information should describe the same processing rather than presenting different versions of what the system does.

Test Rights Requests, Incidents And Deletion

Article 28 contracts must address assistance with individual rights, security, personal-data breaches, DPIAs, deletion or return at contract end, and audits. These obligations need to work through the processing chain rather than stopping with the main supplier.

The ICO recognises that immediate backup deletion may be impractical if copies are put beyond use and deleted on an appropriate cycle (ICO contract requirements). That does not justify an unspecified or unlimited backup period.

Check response times, responsibility assignments, backup deletion cycles and results from a sample export-and-delete test. Align the supplier’s answer with your candidate-data retention schedule. Include transcripts, scores, logs, support tickets and model-development copies rather than testing deletion only from the candidate profile.

Verify That Controls Operate In The Purchased Service

A certification can support assurance, but its scope may exclude the recruitment product, relevant region or subprocessors. Establish which systems, legal entities, locations and dates the evidence covers.

Review recent independent-assurance reports, penetration-test summaries, access reviews, incident exercises, subprocessor due-diligence records and remediation status. Evidence may be reviewed under confidentiality. It still needs to exist, be current and match the service and configuration being purchased.

Approval Requires Four Consistent Records

Do not approve the tool until HR, procurement, security and privacy owners can reconcile four artifacts:

  1. the data-flow register;
  2. the DPA and subprocessor terms;
  3. the transfer mechanisms and assessments; and
  4. the candidate privacy information.

Treat a mismatch as a condition to resolve, not a footnote. Examples include a US support provider missing from the data map, model improvement allowed by the contract but absent from the candidate notice, or a deletion promise that excludes logs and backups.

Approval should also identify who owns each unresolved condition and what evidence will close it. A supplier assertion is not equivalent to a contract term, completed assessment, configuration record or test result.

Assign an owner to recheck the register whenever the supplier changes a subprocessor, processing purpose, model, storage region or support arrangement. The ICO’s recruitment AI audit recommends periodic contract reviews and routine evidence that suppliers and subprocessors follow their instructions, rather than relying on a one-time questionnaire.

A supplier does not need a zero-subprocessor architecture. It does need to tell the employer who receives candidate data, why they receive it, where they can access it, which role and transfer mechanism apply, and what evidence supports those claims. Until those answers reconcile across the four records, the defensible decision is to hold approval.