CERs Data Privacy & Candidate Information Security 1 — Questions and Answers
Question 1: According to GDPR storage limitation principles, how long should candidate personal data be retained after a position is filled?
- Only as long as necessary for the original recruitment purpose (Correct answer)
- For a minimum of 5 years for compliance documentation
- Indefinitely, provided the candidate gave initial consent to apply
- Until the candidate formally requests deletion, regardless of business need
Correct answer: Only as long as necessary for the original recruitment purpose
GDPR's storage limitation principle requires that personal data be kept no longer than necessary for the purpose for which it was collected.
Question 2: Which US federal law primarily governs the use of background check data in recruitment and requires written candidate consent before conducting a consumer report?
- Americans with Disabilities Act (ADA)
- Fair Credit Reporting Act (FCRA) (Correct answer)
- Title VII of the Civil Rights Act
- The Privacy Act of 1974
Correct answer: Fair Credit Reporting Act (FCRA)
The FCRA requires employers to obtain written consent from candidates before ordering a consumer report and to follow adverse action procedures if the report is used to deny employment.
Question 3: What does 'data minimization' mean in the context of ethical recruiting?
- Reducing the digital file size of candidate resumes to save storage costs
- Collecting only the personal data that is strictly necessary for the recruitment process (Correct answer)
- Limiting the total number of candidates stored in the ATS at one time
- Using data encryption to minimize the risk of unauthorized access
Correct answer: Collecting only the personal data that is strictly necessary for the recruitment process
Data minimization is a GDPR principle requiring organizations to collect only the personal data that is adequate, relevant, and limited to what is necessary for the stated purpose.
Question 4: Under the California Consumer Privacy Act (CCPA), which right do job candidates have regarding their personal data collected by a recruiter?
- The right to request that their personal data not be sold to third parties (Correct answer)
- The right to demand monetary compensation for providing their personal data
- The right to access only their publicly available information held by the employer
- The right to prevent all data collection during the application process
Correct answer: The right to request that their personal data not be sold to third parties
The CCPA grants California consumers, including job applicants, the right to opt out of the sale of their personal information to third parties.
Question 5: What constitutes valid 'consent' for candidate data collection under modern privacy regulations?
- The employer's internal policy that authorizes data collection on all applicants
- A verbal agreement made during the initial phone screen with the recruiter
- Explicit, informed agreement from the candidate before their personal data is collected and used (Correct answer)
- Automatic consent assumed when a candidate submits an online job application
Correct answer: Explicit, informed agreement from the candidate before their personal data is collected and used
Valid consent under GDPR and similar frameworks must be freely given, specific, informed, and unambiguous — candidates must actively agree before data is collected.
Question 6: When storing candidate resumes in a shared recruiting environment, which security measure is most critical?
- Sharing resumes freely among all HR team members to maximize collaboration efficiency
- Storing resumes on personal laptops for convenient remote access
- Implementing access controls so only authorized personnel can view candidate personal information (Correct answer)
- Printing resumes and storing physical copies in a locked filing cabinet
Correct answer: Implementing access controls so only authorized personnel can view candidate personal information
Role-based access controls ensure that candidate personal information is viewed only by those with a legitimate need, reducing the risk of unauthorized access or misuse.
Question 7: What is the ethically correct immediate action when a recruiter discovers a data breach involving candidate personal information?
- Quietly remediate the breach internally without notifying candidates to avoid reputational damage
- Notify affected candidates and relevant regulatory authorities promptly, as required by law (Correct answer)
- Delete all candidate data immediately to prevent any further exposure
- Notify candidates only if the breach specifically involved their financial information
Correct answer: Notify affected candidates and relevant regulatory authorities promptly, as required by law
Privacy laws such as GDPR and various US state laws require timely notification of data breaches to affected individuals and, in many cases, to regulatory bodies.
According to GDPR storage limitation principles, how long should candidate personal data be retained after a position is filled?