The UK's Information Commissioner's Office audited AI recruitment tool providers and published the outcomes on 6 November 2024. Among the findings: providers were collecting more personal information than they needed and retaining it indefinitely, building large databases of potential candidates without those candidates knowing. Candidate data privacy in hiring is the set of legal obligations an employer holds over every recording, transcript, score and note produced while assessing an applicant, including the ones a vendor generates and stores on the employer's behalf. Those obligations stay with the employer. They do not travel with the file.
That is the part procurement decks tend to skip.
What actually happens to a candidate's recording, transcript and score?
A one-way video interview produces more artefacts than most buyers realise. The browser uploads audio and video in chunks to object storage. A speech-to-text service — often a third-party API, not the vendor's own model — turns the audio into a transcript. A scoring model reads that transcript against your rubric and writes per-question ratings into a database row keyed to the candidate. The system also produces thumbnails, logs, an audit trail and often an embedding of the transcript for search.
Count the copies. Raw media in one bucket, transcript in another, score record in the primary database, all three in nightly backups with their own rotation window. Often a copy in the analytics warehouse behind the vendor's usage dashboards. A copy at the speech-to-text sub-processor, which may hold input audio on its own clock. Then the copies your team makes: a CSV on someone's laptop, a transcript pasted into a hiring manager's email, a shortlist synced into your ATS.
Here is the detail that catches people out. When a candidate asks for deletion and the vendor confirms it, what usually gets deleted is the database row. The object-storage media, the warehouse copy, the backups and the CSV on a recruiter's machine are often untouched. Ask a vendor to describe deletion as a sequence of systems rather than a checkbox in the admin panel, and you will learn more in five minutes than a SOC 2 report tells you in forty pages.
The second thing worth asking about is people. Vendor support and engineering staff can normally view any interview in the tenant. That is not sinister — it is how debugging works — but it should be logged, time-bound and reviewable. If a vendor cannot tell you how many of its employees opened a named candidate's recording last quarter, the access logging does not really exist. Video interview data security is mostly that: who can see the file, from where, and whether anyone would know.
Who is responsible for candidate data privacy in hiring, the employer or the vendor?
Under the GDPR, the employer is the controller — it decides why candidates are assessed and how — and the interview platform is the processor, acting on documented instructions under an Article 28 contract. India's DPDP Act 2023 uses different words for a similar split: the employer is the Data Fiduciary, the platform a Data Processor, and the Act places responsibility for compliance on the fiduciary, including for processing carried out by a processor on its behalf.
A processor that starts using candidate data for its own purposes — improving its models, enriching a talent database it sells to other clients — becomes a controller for that processing, with its own liability, and the employer now has a contractual breach and a transparency problem. The ICO's audit found exactly this pattern. The candidate who feels wronged, meanwhile, does not write to the vendor. They write to the employer, or to a regulator about the employer.
Under the DPDP Act, penalties reach up to ₹250 crore for a failure to take reasonable security safeguards, and no clause shifts that to a supplier. Accountability for candidate data privacy in hiring is not a thing you can buy out of.
How long can you keep candidate data before it becomes a liability?
France's CNIL, whose HR guidance is the most-cited reference framework in Europe, recommends keeping an unsuccessful candidate's data in the active database for a maximum of two years from last contact, with intermediate archiving beyond that where there is a genuine evidentiary need in discrimination disputes. That is the practical shape of GDPR candidate data retention: a short active window, a longer restricted-access archive, a documented reason for each.
US federal rules pull the other way. Under 29 CFR 1602.14, application forms and other hiring records must be preserved for one year from the date of the record or the personnel action, whichever is later — and once a discrimination charge is filed, all relevant personnel records must be kept until final disposition.
India sits in between. The DPDP Rules 2025, notified on 13 November 2025, do include a three-year erasure clock, but the Third Schedule applies it to specified classes of fiduciary — large e-commerce platforms, online gaming intermediaries and social media intermediaries above user thresholds — not to employers generally. Indian employers have to set their own defensible period rather than inherit one.
"Keep everything forever" is the worst available answer. Every retained interview is breach surface, subject-access workload and, if you are ever sued, discoverable material. Mobley v. Workday is the cautionary case: the Northern District of California granted conditional certification of a nationwide ADEA collective on 16 May 2025, over applications going back years, with filings referencing more than a billion applications rejected through the platform.
A workable default: raw video and audio deleted at 90 days, transcripts, scores and the decision record kept for the limitation period applying to employment claims in your jurisdiction, everything expiring automatically. Retention that depends on someone remembering to run a script is not a policy. It is an aspiration.
What rights do candidates have, and how do GDPR and the DPDP Act differ?
| Candidate right | GDPR (EU/UK) | DPDP Act 2023 (India) |
|---|---|---|
| Access a copy of their data | Yes, Article 15 | Yes, summary of data and processing |
| Correction | Yes | Yes |
| Erasure | Yes, Article 17 | Yes, and on withdrawal of consent |
| Object to processing | Yes, Article 21 | Not provided |
| Data portability | Yes, Article 20 | Not provided |
| Contest a solely automated decision | Yes, Article 22 | Not provided |
| Complain to a regulator | Yes | Yes, via grievance redressal then the Data Protection Board |
The gap in the right-hand column is the practical difference. An Indian candidate rejected by an automated score has no statutory right to demand human review. A candidate in Frankfurt does — and after the Court of Justice's ruling in SCHUFA (C-634/21) on 7 December 2023, the score itself can qualify as an automated decision where the recipient draws heavily on it, even though the score-provider was not the one who said no. If a low score ends the process in nearly every instance, Article 22 is engaged, whatever your process document claims.
Lawful basis diverges too. The DPDP Act has no legitimate-interests basis; it offers consent plus a narrow list of "legitimate uses". Section 7(i) covers processing for the purposes of employment, but Indian practitioners have flagged that it is drafted around employees rather than applicants, so careful employers rely instead on the candidate's voluntary provision of data for a stated purpose, backed by a clear notice.
Two US rules travel further than their geography suggests, because vendors build to them. Illinois's Artificial Intelligence Video Interview Act, effective 1 January 2020, requires notice that AI may evaluate the interview, an explanation of the characteristics assessed, consent before assessment, limits on sharing the video, and destruction of all copies within 30 days of a candidate's request. New York City's Local Law 144, enforced from 5 July 2023, requires an annual independent bias audit of an automated employment decision tool, a published summary of results, and 10 business days' notice to candidates before use.
See Xara AI interview a candidate live
Structured questions, adaptive follow-ups, a transcript and a scorecard your team can argue with. Book a 30-minute demo — no slides.
Book a demo →What does the EU AI Act require of recruitment AI right now?
Recruitment and candidate-selection systems are classified as high-risk under Annex III. The Digital Omnibus on AI, now law, deferred most stand-alone Annex III obligations from 2 August 2026 to 2 December 2027, and Annex I product-embedded systems to 2 August 2028. What did apply from 2 August 2026 is Article 50 transparency — people must be told when they are interacting with an AI system — along with the Article 4 AI literacy duty.
One item is already live and routinely missed in EU AI Act recruitment planning. The Article 5 prohibitions, in force since February 2025, ban emotion recognition in the workplace, and the European Commission's guidelines on prohibited practices state that hiring processes fall within the workplace context. A tool that claims to infer enthusiasm, confidence or stress from a candidate's face or voice is not a 2027 problem in the EU. It is prohibited today.
Does the vendor train its models on candidate interviews?
Ask directly, and ask in writing, because "we don't train on customer data" does a lot of work in sales conversations. It can mean the vendor doesn't fine-tune a foundation model on your recordings while still using transcripts for "product improvement", human annotation or benchmarking. It says nothing about sub-processors either: if the speech-to-text layer is a third-party API on a consumer tier, its terms may permit exactly what the vendor disclaims. Get the training position as a contractual warranty, not a page on a website.
Residency deserves the same scepticism. The GDPR still requires a Chapter V transfer mechanism for data leaving the EEA. India took a lighter route: Rule 15 of the DPDP Rules permits transfer outside India subject to requirements the Central Government may specify by order — a negative-list model rather than a localisation mandate, with no restricted-jurisdiction list published so far. Data stored in Mumbai but administered by an engineer in Austin has not really stayed in India. Ask where the data sits and, separately, where staff reach it from.
Twelve questions to ask an AI interview vendor before you sign
- List every system holding a candidate's recording, transcript, score or metadata, including backups, analytics stores and sub-processors.
- Name every sub-processor, what each receives, and how long each retains it.
- When a candidate requests deletion, which of those systems are purged, in what order, within how many days?
- What is the backup rotation window, and does deleted data survive in backups after the confirmation email?
- Do you use candidate data to train, fine-tune, evaluate or improve any model, including through human review?
- Which of your employees can view a recording, and can you produce a log naming who opened a specific interview?
- In which countries is the data stored, and from which countries can your staff and sub-processors access it?
- Can retention be configured per data type, so raw media expires sooner than transcripts?
- Do you infer or score anything from face, voice tone or emotional state? If yes, we cannot use this in the EU.
- Can we export a full candidate record — transcript, per-question score, rubric version — in machine-readable form for an access request?
- What is your breach notification timeline to us, and how does it map to our regulatory clocks?
- Will you support a bias audit, and have you had one? Provide the most recent report and its methodology.
If a vendor answers ten of these crisply and stumbles on deletion and access logging, that is still useful. If they route you to a trust page instead of answering, treat the silence as the answer.
A candidate disclosure you can adapt
Plain language, shown before the interview starts rather than buried in a privacy policy:
"This interview is recorded and assessed with help from an AI system. We record video and audio, produce a written transcript, and generate scores against the criteria for this role. A named member of our hiring team reviews the transcript and scores before any decision; no rejection is issued by the system alone. Your recording is stored by [vendor] and deleted after [90] days. Your transcript and scores are kept for [period] so we can answer questions about the decision. [Vendor] does not use your interview to train its models. You can ask us for a copy of your transcript and scores, ask us to correct or delete them, or ask for a human interview instead. Write to [email] and we will reply within [15] days."
Vendors vary in how much of that you can honestly say. Some platforms, Xakal's Xara AI Interviews among them, surface the transcript alongside the score in the candidate record, which is the minimum needed to answer an access request without a support ticket — worth checking on any tool you shortlist, at thexakal.com or elsewhere.
Most of this work is unglamorous. Knowing where the copies are. Deciding how long they live and making the deletion actually run. Writing the notice in words a candidate can read. Handled at procurement, DPDP Act HR data obligations and GDPR duties are a design constraint; handled after a complaint, they become a remediation project, and AI hiring compliance stops being an internal matter the moment a regulator asks who was responsible. Candidate data privacy in hiring comes down to a person who trusted you with a recording of themselves answering hard questions, and who has no way of knowing what you did with it.