Map where candidate data goes before buying AI recruitment software

Before uploading real CVs, map every candidate-data stage from collection through storage, AI processing, logs, support access, retention, and deletion. Require written evidence for each provider, purpose, location, access path, reuse rule, and deletion boundary rather than relying on a general privacy or EU-hosting claim.

A procurement checklist for tracing candidate data through storage, AI providers, logs, support, retention, and deletion before real CVs enter a system.

Data-flow checklist · 10 min readAuthored by: Skilltage OÜPublished: Updated: Reviewed by: Janus JektvikFacts reviewed:

Why a storage-region answer is not a data map

Candidate data can pass through more systems than the recruitment interface reveals. A CV may reach primary storage, an extraction service, a model provider, queues, logs, error diagnostics, support tools, backups, and exports. A vendor can therefore answer “Where is the database?” correctly while leaving most of the processing chain unexplained.

The GDPR requires controllers to use processors that provide sufficient guarantees and to govern processing through a contract. Its Article 28 also addresses documented instructions and additional processors. The EDPB controller-and-processor guidelines explain that roles depend on the real purposes and means of each processing operation, not merely the labels chosen by the parties.

This checklist turns those governance questions into an operational map. It does not decide whether a vendor or deployment is lawful.

Map the flow in eight stages

Create one row for every destination or processing operation. Do not merge several providers into a single “cloud” box.

  1. Collection and upload. Record which interface receives the CV, application answers, contact data, and recruiter notes. Identify validation, malware scanning, and temporary upload locations.
  2. Primary storage. Name the database and file-storage provider, primary region, tenant boundary, encryption posture, and people or service roles with access.
  3. Extraction and parsing. Record whether the full file or extracted text leaves primary storage, which service receives it, and what temporary copies or file IDs remain.
  4. AI-assisted analysis. List the model provider, input categories, generated outputs, configured retention mode, and whether inputs or outputs may be reused for training or service improvement.
  5. Recruiter review. Identify where parsed facts, requirement-level evidence, gaps, review state, and human decisions are stored. Separate AI output from authenticated human action.
  6. Operations and support. Include queues, logs, traces, error diagnostics, analytics, support access, incident investigation, and any customer-authorised troubleshooting path.
  7. Exports and integrations. List downloads, email, ATS connections, webhooks, manual copies, and downstream systems that create another retention and access boundary.
  8. Closure and deletion. Record the trigger, period, scope, frequency, backup treatment, provider deletion, contract-end process, and evidence available after completion.

The CNIL deployment Q&A recommends defining roles, contractual responsibilities, authorised access, transfers, and whether a provider may reuse supplied data. It also distinguishes deployment choices rather than treating every hosted or API service as equivalent.

Use one evidence matrix for every vendor

Skilltage guidance: request the same fields from each shortlisted vendor and mark the source of every answer.

FieldQuestion to answerEvidence to retain
PurposeWhy does this operation need candidate data?Product documentation and contract clause
DataWhich files, fields, prompts, outputs, metadata, and identifiers enter it?Data-flow diagram or completed vendor worksheet
RoleWho determines the purpose and essential means for this operation?DPA and role explanation
ProviderWhich legal entity performs it, and which subprocessors are involved?Current subprocessor register and notice terms
LocationWhere can the data be stored, accessed, supported, or transferred?Region configuration and transfer documentation
AccessWhich customer, vendor, support, and service roles can retrieve it?Access-control description and test evidence
ReuseIs data used for model training, service improvement, evaluation, or abuse monitoring?Product setting, contract, and provider policy
RetentionWhat starts and stops each retention period?Retention schedule covering primary and derived data
DeletionWhat is removed from storage, models, logs, backups, and downstream providers?Deletion procedure and completed test record
ChangeHow are new providers, purposes, regions, or terms communicated?Notice process, change log, and objection route

Do not treat a sales email as equivalent to a binding term or implemented setting. Record the strongest source and its review date.

Classify each answer before scoring it

Use three evidence states:

  • Observed: your team saw the setting, access boundary, or deletion result in an approved test environment.
  • Documented: a current contract, DPA, subprocessor notice, technical document, or provider policy supports the answer.
  • Unverified: the answer is asserted, planned, ambiguous, or unsupported by material available to the buyer.

An answer may need more than one state. For example, the team can observe that a file disappears from the user interface while backup deletion remains documented rather than directly observable. Do not silently upgrade either part to proven.

Worked example: follow one fictional CV

A small manufacturer is comparing two AI-assisted screening products. It creates a fictional Maintenance Planner CV and a role brief, then maps one complete run.

StageRecorded observationEvidence stateFollow-up
UploadPDF enters an organisation workspace and becomes visible only to workspace membersObservedAsk how tenant access is enforced in backend paths
ParsingVendor states that a model provider receives the PDF temporarilyDocumentedRequest provider name, configured retention mode, and deletion behavior
ReviewParsed facts and requirement-level evidence appear beside source materialObservedConfirm where outputs are stored and retained
DiagnosticsSales contact says logs contain no candidate textUnverifiedRequest logging policy and a representative redacted event shape
DeletionCandidate disappears after a test deletionObservedAsk what happens to files, derived rows, provider files, logs, and backups

The result is not a pass/fail privacy score. It is a list of known facts, unresolved questions, owners, and procurement conditions.

Test the map before uploading real CVs

  1. Use a from-scratch fictional CV and a fresh vendor-approved sandbox or demo workspace.
  2. Freeze the product version, configuration, date, and provider documentation used for the test.
  3. Follow the fixture through upload, processing, review, export, and deletion. Record visible identifiers and states without requesting confidential implementation material.
  4. Test two customer roles to confirm that ordinary users cannot cross the intended workspace or permission boundary.
  5. Ask the vendor to distinguish immediate deletion, scheduled cleanup, backup expiry, log retention, and any external-provider deletion.
  6. Reconcile observed behavior with the contract, DPA, subprocessor list, privacy documentation, and technical answers.
  7. Assign an owner and deadline to every unverified item. Do not upload real candidate data while a material, non-negotiable data path remains unexplained.

The EDPB opinion on AI models shows why a bare assertion that a model is anonymous is not enough: the assessment is fact-specific and requires evidence about extraction and outputs. The opinion does not turn this procurement test into an anonymity or compliance assessment.

Warning signs in a vendor answer

  • “EU hosted” describes one database but not model processing, support access, logs, or transfers.
  • “We do not store CVs” omits prompts, extracted text, outputs, file IDs, or abuse-monitoring retention.
  • “We are GDPR compliant” replaces a concrete explanation of roles, instructions, subprocessors, and deletion.
  • The vendor cannot distinguish customer content from telemetry or model-improvement data.
  • The subprocessor list has no purpose, location, change notice, or current review date.
  • Deletion means hiding a record in the interface, with no answer for storage objects, derived data, logs, backups, or providers.
  • Support personnel have broad access but the approval, audit, and expiry boundaries are unclear.

Skilltage's documented example

Skilltage guidance: Skilltage publishes its current provider purposes, regions, retention and training posture, and transfer framing on the subprocessor page. The documented flow separates Cloudflare-hosted interfaces, an AWS backend and asynchronous operations, Supabase authentication, database and file storage, and OpenAI-supported parsing and inference. It also identifies optional telemetry providers rather than collapsing them into the main application path.

Within the product workflow, authorised organisation users upload PDF CVs; parsed facts and requirement-level candidate evidence support human review; and recruiters remain responsible for status, progression, rejection, and candidate communication. Product records, human actions, AI trace metadata, and operational logs have different purposes and should not be described as one audit record.

The public disclosures and accepted contractual material—not this article—govern the current provider details. Recheck them when evaluating Skilltage because providers, settings, and terms can change. The case-closure retention guide explains the current evidence-cleanup boundary separately.

Limitations and decision boundaries

This worksheet is not a DPIA, transfer assessment, legal opinion, penetration test, contractual review, or security certification. It does not decide the lawful basis for recruitment, whether a processor provides sufficient guarantees, whether a model is anonymous, or whether a particular transfer is permitted.

A fictional test cannot reveal every backup, privileged access path, incident process, or future provider change. Qualified privacy, security, employment, and procurement specialists must assess the real organisation, jurisdiction, contract, intended use, and risk.

Next step

Choose one shortlisted vendor and draw the eight-stage map before the next sales call. Send the unresolved rows in advance and require a source for each answer. Then use the synthetic-CV vendor test to observe the workflow and the broader AI recruitment vendor checklist to evaluate evidence, human control, failure handling, and claims.

References

The sources above provide regulatory and operational context for processor relationships, AI deployment, data reuse, and evidence about AI models. Apply their current versions to the actual deployment; the matrix is a buyer-side evidence tool, not a compliance determination.

References and provenance

Related resources

This is practical information, not legal advice. Skilltage supports human-reviewed decision support, not automated hiring decisions.

Want to see the workflow?

Bring your data-handling questions and inspect the documented workflow, human review boundary, subprocessors, and deletion path.

Walk through Skilltage's candidate-data flow