Why a storage-region answer is not a data map
Candidate data can pass through more systems than the recruitment interface reveals. A CV may reach primary storage, an extraction service, a model provider, queues, logs, error diagnostics, support tools, backups, and exports. A vendor can therefore answer “Where is the database?” correctly while leaving most of the processing chain unexplained.
The GDPR requires controllers to use processors that provide sufficient guarantees and to govern processing through a contract. Its Article 28 also addresses documented instructions and additional processors. The EDPB controller-and-processor guidelines explain that roles depend on the real purposes and means of each processing operation, not merely the labels chosen by the parties.
This checklist turns those governance questions into an operational map. It does not decide whether a vendor or deployment is lawful.
Map the flow in eight stages
Create one row for every destination or processing operation. Do not merge several providers into a single “cloud” box.
- Collection and upload. Record which interface receives the CV, application answers, contact data, and recruiter notes. Identify validation, malware scanning, and temporary upload locations.
- Primary storage. Name the database and file-storage provider, primary region, tenant boundary, encryption posture, and people or service roles with access.
- Extraction and parsing. Record whether the full file or extracted text leaves primary storage, which service receives it, and what temporary copies or file IDs remain.
- AI-assisted analysis. List the model provider, input categories, generated outputs, configured retention mode, and whether inputs or outputs may be reused for training or service improvement.
- Recruiter review. Identify where parsed facts, requirement-level evidence, gaps, review state, and human decisions are stored. Separate AI output from authenticated human action.
- Operations and support. Include queues, logs, traces, error diagnostics, analytics, support access, incident investigation, and any customer-authorised troubleshooting path.
- Exports and integrations. List downloads, email, ATS connections, webhooks, manual copies, and downstream systems that create another retention and access boundary.
- Closure and deletion. Record the trigger, period, scope, frequency, backup treatment, provider deletion, contract-end process, and evidence available after completion.
The CNIL deployment Q&A recommends defining roles, contractual responsibilities, authorised access, transfers, and whether a provider may reuse supplied data. It also distinguishes deployment choices rather than treating every hosted or API service as equivalent.
Use one evidence matrix for every vendor
Skilltage guidance: request the same fields from each shortlisted vendor and mark the source of every answer.
| Field | Question to answer | Evidence to retain |
|---|---|---|
| Purpose | Why does this operation need candidate data? | Product documentation and contract clause |
| Data | Which files, fields, prompts, outputs, metadata, and identifiers enter it? | Data-flow diagram or completed vendor worksheet |
| Role | Who determines the purpose and essential means for this operation? | DPA and role explanation |
| Provider | Which legal entity performs it, and which subprocessors are involved? | Current subprocessor register and notice terms |
| Location | Where can the data be stored, accessed, supported, or transferred? | Region configuration and transfer documentation |
| Access | Which customer, vendor, support, and service roles can retrieve it? | Access-control description and test evidence |
| Reuse | Is data used for model training, service improvement, evaluation, or abuse monitoring? | Product setting, contract, and provider policy |
| Retention | What starts and stops each retention period? | Retention schedule covering primary and derived data |
| Deletion | What is removed from storage, models, logs, backups, and downstream providers? | Deletion procedure and completed test record |
| Change | How are new providers, purposes, regions, or terms communicated? | Notice process, change log, and objection route |
Do not treat a sales email as equivalent to a binding term or implemented setting. Record the strongest source and its review date.
Classify each answer before scoring it
Use three evidence states:
- Observed: your team saw the setting, access boundary, or deletion result in an approved test environment.
- Documented: a current contract, DPA, subprocessor notice, technical document, or provider policy supports the answer.
- Unverified: the answer is asserted, planned, ambiguous, or unsupported by material available to the buyer.
An answer may need more than one state. For example, the team can observe that a file disappears from the user interface while backup deletion remains documented rather than directly observable. Do not silently upgrade either part to proven.
Worked example: follow one fictional CV
A small manufacturer is comparing two AI-assisted screening products. It creates a fictional Maintenance Planner CV and a role brief, then maps one complete run.
| Stage | Recorded observation | Evidence state | Follow-up |
|---|---|---|---|
| Upload | PDF enters an organisation workspace and becomes visible only to workspace members | Observed | Ask how tenant access is enforced in backend paths |
| Parsing | Vendor states that a model provider receives the PDF temporarily | Documented | Request provider name, configured retention mode, and deletion behavior |
| Review | Parsed facts and requirement-level evidence appear beside source material | Observed | Confirm where outputs are stored and retained |
| Diagnostics | Sales contact says logs contain no candidate text | Unverified | Request logging policy and a representative redacted event shape |
| Deletion | Candidate disappears after a test deletion | Observed | Ask what happens to files, derived rows, provider files, logs, and backups |
The result is not a pass/fail privacy score. It is a list of known facts, unresolved questions, owners, and procurement conditions.
Test the map before uploading real CVs
- Use a from-scratch fictional CV and a fresh vendor-approved sandbox or demo workspace.
- Freeze the product version, configuration, date, and provider documentation used for the test.
- Follow the fixture through upload, processing, review, export, and deletion. Record visible identifiers and states without requesting confidential implementation material.
- Test two customer roles to confirm that ordinary users cannot cross the intended workspace or permission boundary.
- Ask the vendor to distinguish immediate deletion, scheduled cleanup, backup expiry, log retention, and any external-provider deletion.
- Reconcile observed behavior with the contract, DPA, subprocessor list, privacy documentation, and technical answers.
- Assign an owner and deadline to every unverified item. Do not upload real candidate data while a material, non-negotiable data path remains unexplained.
The EDPB opinion on AI models shows why a bare assertion that a model is anonymous is not enough: the assessment is fact-specific and requires evidence about extraction and outputs. The opinion does not turn this procurement test into an anonymity or compliance assessment.
Warning signs in a vendor answer
- “EU hosted” describes one database but not model processing, support access, logs, or transfers.
- “We do not store CVs” omits prompts, extracted text, outputs, file IDs, or abuse-monitoring retention.
- “We are GDPR compliant” replaces a concrete explanation of roles, instructions, subprocessors, and deletion.
- The vendor cannot distinguish customer content from telemetry or model-improvement data.
- The subprocessor list has no purpose, location, change notice, or current review date.
- Deletion means hiding a record in the interface, with no answer for storage objects, derived data, logs, backups, or providers.
- Support personnel have broad access but the approval, audit, and expiry boundaries are unclear.
Skilltage's documented example
Skilltage guidance: Skilltage publishes its current provider purposes, regions, retention and training posture, and transfer framing on the subprocessor page. The documented flow separates Cloudflare-hosted interfaces, an AWS backend and asynchronous operations, Supabase authentication, database and file storage, and OpenAI-supported parsing and inference. It also identifies optional telemetry providers rather than collapsing them into the main application path.
Within the product workflow, authorised organisation users upload PDF CVs; parsed facts and requirement-level candidate evidence support human review; and recruiters remain responsible for status, progression, rejection, and candidate communication. Product records, human actions, AI trace metadata, and operational logs have different purposes and should not be described as one audit record.
The public disclosures and accepted contractual material—not this article—govern the current provider details. Recheck them when evaluating Skilltage because providers, settings, and terms can change. The case-closure retention guide explains the current evidence-cleanup boundary separately.
Limitations and decision boundaries
This worksheet is not a DPIA, transfer assessment, legal opinion, penetration test, contractual review, or security certification. It does not decide the lawful basis for recruitment, whether a processor provides sufficient guarantees, whether a model is anonymous, or whether a particular transfer is permitted.
A fictional test cannot reveal every backup, privileged access path, incident process, or future provider change. Qualified privacy, security, employment, and procurement specialists must assess the real organisation, jurisdiction, contract, intended use, and risk.
Next step
Choose one shortlisted vendor and draw the eight-stage map before the next sales call. Send the unresolved rows in advance and require a source for each answer. Then use the synthetic-CV vendor test to observe the workflow and the broader AI recruitment vendor checklist to evaluate evidence, human control, failure handling, and claims.
References
The sources above provide regulatory and operational context for processor relationships, AI deployment, data reuse, and evidence about AI models. Apply their current versions to the actual deployment; the matrix is a buyer-side evidence tool, not a compliance determination.