Product / Knowledge Base / 13. Compliance, Consent, and GDPR

13. Compliance, Consent, and GDPR

User & Administration Guide — Version 1.0.3.29

Guide summary

Recruitment Desk builds fair-hiring and data-protection rules into the product: no automated rejection, no protected characteristics in scoring, blind scorecards, recorded consent, and a retention policy.

On this page

13.1 No automated rejection

A candidate can never be rejected by the system. Every terminal negative decision must carry the identity of a named person, and the app refuses to write a rejection that does not have one. The reject dialog also requires a written reason before it will complete.

In practice this means screening scores rank and highlight applications, but a human always makes and owns the decision to say no.

13.2 No protected characteristics in scoring

Screening rules can only be built from job-related attributes: years of experience, work mode, employment type, and tags. Protected characteristics are not offered as inputs, and that deliberately includes postal or ZIP code, which is a common proxy for demographic background.

13.3 Blind scorecard review

Interviewers cannot see each other's ratings until they have submitted their own. This removes the anchoring effect where the first strong opinion in the room pulls the rest of the panel along with it.

  • Consent is recorded on the candidate record with the date it was granted.
  • Consent is required before a candidate can be added to the talent pool.
  • Where consent collection is enabled on the application form, the candidate's answer is stored with the application.

13.5 Retention and erasure

Administrators configure data retention from Settings → Recruitment Compliance.

Setting Purpose
Enable retention policy Turns the retention rules on for the site
Retention period How long candidate data is kept, defaulting to 730 days
Anonymise on expiry Strip identifying details but keep the anonymised hiring statistics
Require consent on the portal Ask applicants to consent when they apply
  • Anonymising removes the identifying fields while leaving funnel and source reporting intact.
  • Full erasure removes the candidate record outright, for use when someone exercises a right to be forgotten.
  • Both actions are recorded in the audit log so you can evidence that a request was actioned.

13.6 Approval routing

The same settings tab controls requisition approvals: whether the approval workflow is enabled, whether approval is required before a requisition can open, and which role slugs are allowed to approve. Organization Admin and Hiring Manager are the defaults.

13.7 Accessibility

The interface is built against a WCAG 2.2 AA target, with keyboard navigation, visible focus states, and screen-reader labelling across the hiring modules.