Relevant for: Recruiters
How do I handle a candidate's data request?
Go to 'Settings' > 'Recruiting' > 'Candidate data retention' > 'Data subject requests', search for the candidate by name or email, and choose 'Export data', 'Data retention', or 'Anonymize candidate'. You'll find the same actions in the '...' menu on the candidate profile.
- Access requests: When a candidate asks what data you hold about them, you can answer with one structured export instead of collecting data from different pages.
- Erasure requests: When a candidate asks you to delete their data, you can anonymize them right away, without waiting for your retention policy.
- Legal holds: When your legal team needs to pause deletion, e.g., for a dispute, use 'Data retention'. To learn more, see Candidate data retention and privacy settings.
Table of Contents:
- How do I find a candidate?
- How do I export a candidate's data?
- How do I anonymize a candidate?
- What happens when I anonymize a candidate?
- Who can handle data requests?
How do I find a candidate?
- Go to 'Settings' > 'Recruiting' > 'Candidate data retention' and open the 'Data subject requests' tab.
- Enter at least two characters of the candidate's name or email and click 'Search'.
- Each result shows the email, the number of applications, and the retention status: 'Anonymized', 'On legal hold', or the date the candidate will be anonymized.
- Open the '...' menu on the row to export the data, manage retention, or anonymize the candidate.
How do I export a candidate's data?
- Choose 'Export data'.
- Optional: select 'Include internal notes', 'Include written interview feedback', or 'Include the pay rationale written for offers'. All three are off by default.
- Click 'Export'.
The export is a JSON file. It includes the profile, applications and form answers, offers, interviews, emails, activity, custom recruiting fields, a list of uploaded files, how the candidate was added to Leapsome, and the privacy notice history.
- Uploaded files are listed but not included. Download them from the candidate profile.
- Data about other people is removed or replaced by their role, e.g., "interviewer" instead of a name.
How do I anonymize a candidate?
- Choose 'Anonymize candidate', either in the '...' menu on the candidate profile or in the search results.
- Under 'This will affect', check what changes: applications, open applications that will be archived, files and emails that will be deleted, scorecards that lose their written feedback, and merged duplicate records.
- Enter a reason without personal data, e.g., "Erasure request by the candidate".
- Select 'I understand that this action is irreversible' and click 'Anonymize permanently'.
Note: You can't undo an anonymization. You also can't anonymize a candidate who is on legal hold until the hold is lifted.
What happens when I anonymize a candidate?
- Removed: Name, contact details, resumes and attachments, emails, notes, written interview feedback, custom recruiting field values, offer letters (generated and signed PDFs), import references, and booking links. Leapsome also tries to withdraw open calendar invitations.
- Kept: Stage history, timestamps, numeric ratings, and your reason labels.
- Open applications are archived with the reason "Anonymized".
- The candidate shows an 'Anonymized' badge and becomes read-only. Nobody can edit their applications, offers, interviews, or scorecards. You can't find them by name or email anymore.
- Linked employees: If the candidate was converted to an employee, the link is removed. The employee profile itself doesn't change.
An anonymized candidate can apply again later. This creates a new candidate profile.
To learn more about the candidate profile, see The candidate list and candidate profile.
Who can handle data requests?
- Searching, 'Export data', and 'Data retention' require the 'Manage ATS data compliance' permission.
- 'Anonymize candidate' requires the 'Anonymize candidates' permission and access to Recruiting. Admins have this by default. Give it to recruiters only if they should be able to anonymize any candidate, since it isn't limited to their jobs.
- Both permissions cover every candidate in your company, whatever their hiring team, so requests can always be handled.
- Companies in read-only mode can search and export, but not anonymize.
For details, see Hiring team roles and permissions.