How to protect candidate data during remote hiring
Remote hiring multiplies the places candidate data can leak. Here's how recruiters lock it down without adding friction to the process.

To protect candidate data during remote hiring, collect only what the current hiring decision needs, give each person access to only the records their task requires, put multi-factor authentication on every account that touches those records, check what each hiring vendor does with the data, and delete each record on a schedule you can defend. The controls are ordinary. The hard part is knowing where the data already is.
That is the gap most teams have. A remote hire moves a CV, an ID document, a salary expectation, an assessment result and an interview recording through 5 or 6 systems before anyone signs anything, and nobody owns the whole chain. The human element showed up in 62% of breaches in Verizon's 2026 Data Breach Investigations Report, with social engineering alone behind 16% of them. Those are not exotic attacks. They are a recruiter clicking a link, or a spreadsheet of candidates sitting in a downloads folder.
TL;DR
- Map the candidate data journey first. You cannot protect records you have not located, and most teams find at least one copy they forgot about.
- Collect for the decision in front of you. Salary history, date of birth and ID documents rarely belong at the application stage.
- Access should follow the task, not the job title. Temporary interviewers get an expiry date.
- Your vendors are part of your attack surface. Ask where data sits, who sub-processes it and how deletion actually works.
- Retention is a policy decision, not a storage decision. Set a different clock for hired, rejected and talent-pool records.
- Tell candidates what you hold and for how long. It is a legal duty in the UK and EU, and it reduces data-access requests later.
What counts as candidate data?
Candidate data is any information that identifies a person applying for a role, plus anything you generate about them along the way. That includes the obvious records (name, contact details, CV, right-to-work documents) and the ones teams forget: interview notes, assessment scores, proctoring flags, video recordings, recruiter comments in a chat thread, and the rejection reason someone typed into a free-text box.
The forgettable half is usually the risky half. A CV is a document the candidate chose to send you. A recruiter's note guessing at someone's family situation is a record the candidate never saw, cannot correct, and would be entitled to read if they asked.

Where does candidate data actually go?
Write down every place candidate information enters your process, then every place it leaves. Careers page, job boards, referral forms, email inboxes, the hiring platform, assessment software, video interviews, background-check providers, and the spreadsheet somebody built to compare finalists. For each one, record what data it holds, who can reach it, and what event should trigger deletion.
This exercise takes an afternoon and it is the only step on this list that finds problems you did not already suspect. It belongs alongside the operational problems remote teams hit, because a data map is also a process map. The usual discovery is a duplicate: application emails with full CVs attached sitting in a shared inbox that four people can read, years after the role closed.
Stage | Data it holds | Who genuinely needs it | Delete trigger |
|---|---|---|---|
Application | CV, contact details, work eligibility answer | Recruiter, hiring manager | End of the legal claim window after rejection |
Screening call | Notes, salary expectation, notice period | Recruiter only | With the application record |
Assessment | Scores, answers, proctoring evidence, ID photo | Reviewers on that role | Vendor retention clock, set per record type |
Interview | Structured scores, notes, recordings | Panel members on that role | With the application record |
Offer stage | Bank details, ID documents, references | HR or finance, not the panel | Moves to the employee file, or deleted on decline |
Talent pool | CV and contact details only | Recruiter | 12-month review date with a fresh consent check |
What data should you not collect?
Anything the current stage does not need. Data minimization is written into Article 5 of the GDPR, which requires personal data to be adequate, relevant and limited to what is necessary, and kept no longer than needed. In practice that means moving fields later in the process rather than asking for everything up front.
The application form is where most teams overcollect. Date of birth, home address, national ID number, photographs, salary history and emergency contacts almost never help you decide who to screen, and several of them are restricted or banned in specific jurisdictions. Ask for them when they become relevant, which is usually at offer, and ask the smallest version of the question that works. You rarely need a scan of a passport when a right-to-work answer plus a later verification step does the job.
Optional demographic data deserves its own rule. Collect it separately from the hiring record, keep it anonymous, and keep it away from anyone making a decision. If a hiring manager can see it next to a score, it is not a fairness measure any more.
Who should be able to open a candidate file?
Only the people working that role, for as long as they are working it. Give everyone full access and you get an audit trail that proves nothing, because the answer to "who could have seen this record" is always "everyone".
Use role-based permissions in the hiring platform and review them when responsibilities change. Set an expiry date on temporary interviewers. Agency recruiters, contractors and external assessors should see only the records for their part of the process. Shared logins break the whole model: activity logs only mean something when every action ties back to a named person.
Removal matters more than granting. Most teams are careful about who gets added and careless about who gets removed, so access quietly accumulates. Put an access review on the same calendar as your quarterly hiring review and treat it as a 2-minute job rather than a project.
Pro Tip: Run one test before you trust your permissions. Ask a colleague who is not on the hiring panel to open a live candidate record. If they can read the interview notes, your roles are decorative.
How do you secure remote recruiter accounts?
Put multi-factor authentication on the email account, the hiring platform and the assessment tool, then check which kind of MFA you turned on. NIST Special Publication 800-63B, the federal digital identity guidelines, is clear that one-time passcodes, including SMS and push notifications, are not phishing-resistant, because a convincing fake login page captures them just as easily as a password. Hardware keys and passkeys are.
Email deserves the strongest protection you have, since it resets everything else. A compromised recruiter mailbox hands over the CVs already sitting in it and the ability to reset the applicant tracking system behind it.
For devices, the basics hold: supported operating system, automatic updates, disk encryption, screen lock. Keep candidate files inside approved systems instead of letting them collect in downloads folders. A company-managed VPN can protect traffic on a network you do not control, which matters for recruiters working from cafes and shared offices, but be honest about what it does. It encrypts a connection. It does not fix excessive access, stop a recruiter emailing a CV to the wrong person, or decide how long a record lives.
What should you ask a hiring vendor?
There are 4 questions worth asking, and you want specifics rather than a certificate. What candidate data does the product receive? Where is it stored, and in which country? Which sub-processors touch it? When we delete a candidate, what actually gets deleted, and how long does it take?
Third parties are not a footnote in your risk picture. The global average cost of a data breach reached $4.99 million in IBM's 2026 Cost of a Data Breach Report, a 12% rise and a record high. For a company under 200 people with no full-time privacy lead, the relevant part of that number is not the total. It is that the cost lands on whoever collected the data, regardless of which vendor lost it.
A SOC 2 report or an ISO 27001 certificate is useful evidence that a vendor runs a security program. It does not tell you whether your recruiters can export a full candidate list to CSV, or whether an assessment link stays live for 6 months after you send it. Ask about the workflow, not just the badge.
How long should you keep candidate data?
Keep each record for as long as there is a reason for it, and set the clock differently for hired, rejected and talent-pool candidates. The UK's Information Commissioner's Office is direct about the rule in its recruitment records guidance: you "must not keep information for longer than you need to", and records for unsuccessful candidates should not outlive the statutory period in which someone could bring a claim arising from that recruitment process.
That gives you a defensible structure. Rejected candidates: keep the file until the claim window in your jurisdiction closes, then delete it. Hired candidates: move what remains relevant into the employee file and securely destroy the rest, which the same guidance requires. Talent pool: this one needs active consent rather than assumed consent, and a review date no more than 12 months out. Someone who agreed to be contacted about future roles 2 years ago did not agree to be in your database forever.
Write the periods down. An undocumented retention rule is not a rule, and it is the first thing a regulator asks to see.
Tell candidates what happens to their data
A privacy notice written for candidates, linked from the application form, in language a person can read. What you collect, why, who sees it, how long you keep it, and how to ask for a copy or a deletion. The ICO's recruitment and selection guidance treats this transparency as a baseline obligation, not a nice touch, and it sits with the rest of your obligations when hiring across borders.
Two things are worth saying plainly in that notice, because candidates ask about both. First, whether any automated scoring or AI assistance is used in the process, and whether a human reviews the outcome. Second, what happens to video and voice recordings, and say it before the interview rather than after somebody asks.
There is a quiet commercial upside here, and it is the reason this section is not just compliance hygiene. A clear notice answers the "what are you doing with my data" question once, in writing, instead of one email at a time, and it is one of the few trust signals a candidate sees before deciding whether to finish your application at all.
Where assessments sit in the data chain
Skills assessments concentrate more candidate data than any other stage, which is exactly why they deserve specific controls rather than general reassurance. A single assessment can hold answers, scores, an ID photo, webcam snapshots, a screen recording and a voice or video response. Identity checks make that pile bigger, which is the tension at the heart of stopping someone sitting an assessment for a candidate: you verify a person by collecting more of their data, so the retention rules matter more here than anywhere else.
The Testlify Assessment Integrity Framework covers this ground: it protects the trustworthiness of assessment results through identity checks, proctoring controls, AI-assistance detection, suspicious-behavior signals and reviewable evidence, while keeping the final judgment human-led. Applied to data protection, it means every piece of evidence you collect is there to support a human decision, and nothing is collected that no human will look at.
What that looks like in practice on a remote hiring workflow: face-verification data is deleted after 30 days and candidates can withdraw consent at any time. Video and audio responses are removed after 6 months, with warnings 2 days and 1 day beforehand. Screen and camera recordings are stored for a number of days you configure. Candidates sign up with explicit data-processing consent and a 6-digit email code. Optional diversity data is anonymous and is never shared with employers.
The access side matters just as much. Custom roles carry granular permission bundles covering single sign-on, two-factor authentication, audit logs and data retention, set per module rather than per person. Shareable candidate reports have individual toggles for candidate details, proctoring detail and AI insights, so a hiring manager gets the score without the identity documents. Audit logs export the last 90 days and stream to a security monitoring system in real time. Testlify holds SOC 2 Type II and ISO 27001, and supports GDPR and CCPA obligations. And if you already run an applicant tracking system, Testlify integrates with it and leaves it as your system of record rather than becoming a second place candidate data lives.
One honest caveat: none of this configures itself. The defaults are sensible, but retention windows, report visibility and role permissions are settings someone on your side has to choose. Budget an hour for that during setup and it stays right for years. Skip it, and you have bought good controls you are not using.
Hire remotely without a trail of candidate data
If your assessment stage is where the most sensitive candidate data collects, start there. Testlify runs skills assessments and interviews with configurable retention windows, granular report permissions and proctoring evidence built for human review, so the evidence you keep matches the decision you are making. Book a demo and bring your retention questions, or start a free trial and set the controls yourself before you invite a single candidate.
Key takeaways
- Mapping beats buying. The data journey exercise finds duplicate copies of candidate records that no tool would flag, because the tool does not know the shared inbox exists. Do this before you spend money on controls, or you will protect the systems you remember and leave the ones you forgot wide open.
- Overcollection is the default failure. Application forms ask for date of birth, address and salary history because someone copied a template years ago. Every field you remove is a field that cannot leak, cannot be requested in a subject access request, and cannot sit in a breach report.
- Access granting is easy, access removal is the discipline. Permissions accumulate silently as people join panels and leave them, so put a recurring review on the calendar. Without it, your audit trail records who acted but proves nothing about who could have.
- Not all MFA is equal. SMS codes and push notifications stop password reuse but not a convincing fake login page, which is why NIST 800-63B separates phishing-resistant authenticators from the rest. Protect the recruiter mailbox first, because it resets every other account.
- Vendor answers matter more than vendor certificates. A certification proves a security program exists. Only specific questions about storage location, sub-processors and deletion timing tell you what happens to your candidates' records on a Tuesday.
- Retention is a decision you write down. Different clocks for hired, rejected and talent-pool candidates, each tied to a real reason and a real date. An undocumented retention period is the gap a regulator finds first, and the one a candidate's deletion request exposes fastest.
FAQs
Wordpress Developer
Yash Patel is a Wordpress and SEO Specialist at Testlify with 3+ years of experience in technical SEO, on-page optimization, and content strategy. He works on improving Testlify's organic presence and produces content focused on hiring, talent assessment, and HR technology.
LinkedInRelated resources
View all
Skill assessment
What skills-based hiring data shows beyond the US and UK

HR & recruitment
AI across all stages of the hiring process in 2026

AI in recruitment
Best practices for hiring data analysts using assessments?

Candidate assessment
What tools support voice responses for language proficiency testing?

Candidate assessment
How do ATS-integrated assessments streamline hiring workflows?

Candidate assessment
How to assess financial modeling and accounting skills pre-hire?
Get started.
Hire on proof, not resumes.
Run your first skills-based assessment free — no credit card required.