Relevant for: Recruiters
How do I set up candidate data retention?
Set up retention policies in 'Settings' > 'Recruiting' > 'Candidate data retention'. Leapsome then anonymizes candidates automatically once all their applications have been closed for longer than the retention period. Hired candidates are kept unless you choose otherwise. Add your privacy policy link in 'Settings' > 'Recruiting' > 'Career portal'.
These settings help you meet your data protection duties for candidate data: inform applicants, keep their data only as long as needed, and show what you did. A nightly run anonymizes old candidate records for you, so you don't need to clean up manually. You can set different retention periods per work location.
Table of Contents:
- How do I add the privacy policy to my application forms?
- What's on the 'Candidate data retention' page?
- How do I create a retention policy?
- How do I keep or remove one candidate's data at a different time?
- When are candidates anonymized automatically?
- Who can manage data retention?
How do I add the privacy policy to my application forms?
- Go to 'Settings' > 'Recruiting' > 'Career portal' and expand 'Privacy policy'.
- Enter the 'Policy URL'.
- Click 'Update settings'.
The link appears as a privacy notice on every application form. Leapsome stores the notice and the time of submission with the candidate. You need a valid privacy policy URL to activate your career portal and keep it active.
To learn more, see Setting up, branding, and embedding your career portal.
What's on the 'Candidate data retention' page?
- 'Retention policies': Rules for automatic anonymization. Until a policy is active, candidate data is only removed manually.
- 'Data subject requests': Find a candidate to export, retain, or anonymize their data. To learn more, see Handling candidate data requests.
- 'Compliance log': A permanent record of anonymizations, legal holds, overrides, rule changes, retention runs, and data exports.
How do I create a retention policy?
- Go to 'Settings' > 'Recruiting' > 'Candidate data retention' > 'Retention policies' and click 'Add policy'.
- Choose the work location the policy applies to, or 'All other work locations (default)'. The work location comes from the job profile the candidate applied to.
- Set the 'Retention period after archiving (days)'. Leapsome suggests a starting value for the location.
- Under 'Anonymize hired candidates after…', keep 'Keep hired candidates (default)' or choose a separate period.
- Select 'Policy is active' if the policy should run.
- Click 'Review impact' to see how many candidates would be anonymized now and in the next 30 days, with a sample list.
- Confirm the policy. New policies start after a 7-day review period. To skip it, select 'Apply to already archived candidates immediately'.
- Each work location can have one policy. The default policy only applies to work locations without their own policy.
- Deactivating or deleting a policy stops future anonymization for its work locations. Candidates who were already anonymized stay anonymized.
Note: Anonymizing a hired candidate also voids their offer letter and deletes the signed PDF. If you need signed contracts, keep them as employee documents.
How do I keep or remove one candidate's data at a different time?
Open 'Data retention' from the '...' menu on the candidate profile, or from 'Data subject requests'. Under 'Current retention state', you see the 'Policy-based anonymization date' and the 'Effective anonymization date'.
- 'Place legal hold': Excludes the candidate from automatic and manual anonymization until you lift the hold, e.g., during a legal dispute.
- 'Override auto-anonymization date': Sets a specific date, tomorrow or later, that replaces the policy date. Choose the date and click 'Set date'. This also works without an active policy.
Both actions need a reason, which is saved in the 'Compliance log'. Don't enter personal data in the reason. A legal hold always wins, even over an override date.
When are candidates anonymized automatically?
- Only when every application of the candidate is closed (archived or hired) and past its retention period. A candidate with any open application isn't anonymized.
- If a candidate has applications under different policies, the longest retention period applies.
- If no policy matches and there's no default policy, the candidate isn't anonymized automatically.
- Closing a job doesn't archive its open applications. Those candidates are only covered once their applications are archived.
- Retention always anonymizes data. Records aren't deleted completely.
Admins and super admins with the 'Manage ATS data compliance' permission get an in-app summary after each automatic run.
Who can manage data retention?
- The 'Candidate data retention' page, policies, legal holds, and overrides require the 'Manage ATS data compliance' permission.
- Career portal settings require the 'Manage career page settings' permission.
For details, see Hiring team roles and permissions.