Docs / Quick Start for Recruitment Agencies

Quick Start for Recruitment Agencies

Getting Started for Recruitment Businesses

Recruitment agencies hold extensive personal data on candidates, clients, and employees. This guide helps you set up SAR Portal to handle the unique challenges of recruitment DSARs.

Why Recruitment DSARs Are Complex

Recruitment agencies face unique challenges:

  1. Volume of data per candidate: CVs, interview notes, references, assessments, emails
  2. Client confidentiality: Client names and commercial terms must be protected
  3. Long retention periods: Candidate data often kept for years
  4. Multiple parties: Candidates, clients, references — all have rights
  5. Emotional context: Unsuccessful candidates may be frustrated

SAR Portal addresses each of these.

Step 1: Map Your Candidate Data (10 minutes)

Recruitment data sprawls across many systems:

SystemData Types
ATS (Applicant Tracking System)CVs, applications, stage history
EmailCorrespondence with candidates and clients
Consultant NotesInterview feedback, assessments
Reference ChecksReference requests and responses
Video Interview ToolsRecorded interviews
Shared DrivesReformatted CVs, spreadsheets
LinkedIn/Job BoardsSourcing history
Payroll (for contractors)Payment records
HR SystemFor internal employees

Action: Create a checklist of systems per data type.

Step 2: Configure SAR Portal (10 minutes)

Organisation Setup

  1. Settings > Organization (Settings is Admin-only)
    • Company name
    • Data Protection contact email
    • Business address

Public Portal

Many recruitment agencies prefer to receive DSARs by email rather than public portal, but having a portal:

Configure at Settings > Integrations.

Team Access

Typical recruitment setup:

Consultants shouldn’t see DSAR processing — it can create awkwardness if they handled the candidate.

Step 3: Set Up Your Workflow

Request Received
       ↓
Identity Verified (OTP)
       ↓
Data Collection Request to Consultants
(Email template: "Please export all data for [Name]")
       ↓
Gather from:
- ATS export
- Email search
- Shared drive search
- Interview notes
       ↓
Attach to the case (via Request Info / Submit Info / Close Case)
       ↓
Automatic scan → Review Detected PII (removes client info)
       ↓
Compliance Review
       ↓
Delivery to Candidate

Record Recruitment-Specific Details

SAR Portal captures the request type and a free-text Notes field on each case. Use the Notes field to record the reference details you need, for example:

Select the correct request type when creating the case so the workflow and deadlines are set correctly.

Step 4: Critical — Protecting Client Information

The most important part of recruitment DSARs: you must protect client data.

When sharing a candidate’s file, redact:

SAR Portal’s AI handles most of this automatically, but review the results for:

Example Redactions

Before:

“Submitted CV to Acme Corp on 15 Jan. Interviewed with John Smith (Hiring Manager) on 20 Jan. Feedback positive but client selected another candidate.”

After (AI redacted):

“Submitted CV to [REDACTED] on 15 Jan. Interviewed with [REDACTED] (Hiring Manager) on 20 Jan. Feedback positive but client selected another candidate.”

Step 5: Common Recruitment DSAR Scenarios

“Send me everything you have on me”

Process:

  1. Search ATS by name/email
  2. Search email for all correspondence
  3. Request consultant notes
  4. Check shared drives for CV versions
  5. Export and attach to the case via a case action (Request Info, Submit Info, or Close Case)
  6. Files are scanned automatically — redact client information on the Review Detected PII screen
  7. Review and deliver

“Delete all my data”

Erasure request process:

  1. Confirm identity
  2. Document what will be deleted
  3. Check retention requirements (some payroll data must be kept)
  4. Delete from all systems
  5. Confirm deletion to candidate
  6. Log in SAR Portal

“What did you tell the client about me?”

This is tricky because:

Approach:

Reference Requests from Third Parties

If another agency or employer asks for a reference:

Handling Difficult Situations

Upset Candidate

Unsuccessful candidates sometimes submit DSARs hoping to find evidence of discrimination or unfair treatment.

Do:

Don’t:

Placement Gone Wrong

Candidate placed, then terminated, now wants all data.

Provide:

Protect:

Very Old Data

Candidate from 5 years ago wants their file.

If you still have data:

If deleted under retention policy:

Retention Policy Recommendation

Implement a clear data retention policy:

Data TypeSuggested Retention
Unsuccessful candidates1-2 years
Placed candidates6 years (statutory minimum)
Contractor payroll6 years
Interview notesSame as candidate

With clear retention, you reduce future DSAR scope and demonstrate good practice.

Audit Trail for Agencies

Recruitment agencies receive more DSARs than many businesses. SAR Portal’s audit trail shows:

This evidence protects you if candidates complain to the DPC.

Getting Help

Recruitment-specific questions: support@sarportal.com

Complex scenarios: Consider consulting a privacy specialist experienced in recruitment.


Ready to handle recruitment DSARs properly? Open SAR Portal

New to SAR Portal? Start your free trial — be prepared for your next candidate request.