CERs Data Privacy & Candidate Information Security 2 — Questions and Answers
Question 1: What does 'purpose limitation' require of recruiters handling candidate data?
- Limiting the total number of open requisitions a recruiter can manage simultaneously
- Using candidate data only for the specific recruitment purpose for which it was originally collected (Correct answer)
- Setting restrictions on how many candidates can apply for a single position
- Prohibiting recruiters from contacting the same candidate more than once
Correct answer: Using candidate data only for the specific recruitment purpose for which it was originally collected
Purpose limitation is a GDPR principle stating that personal data collected for one specific purpose must not be reused for a different, incompatible purpose without new consent.
Question 2: A recruiter accidentally receives a candidate's unsolicited medical records. What is the most ethical course of action?
- Review the records since they were received and may contain relevant information
- Securely destroy or return the records and inform the sender that the transmission was an error (Correct answer)
- Store the records in a restricted folder but refrain from referencing them in decisions
- Forward the records to the hiring manager so they are aware of the situation
Correct answer: Securely destroy or return the records and inform the sender that the transmission was an error
Retaining unsolicited sensitive health data creates legal and ethical exposure; the correct action is to destroy or return the data and notify the sender of the mistake.
Question 3: Under GDPR's 'right to erasure' (right to be forgotten), what obligation does a recruiter have when a candidate formally requests deletion of their data?
- Archive the candidate's data and make it inaccessible but not permanently deleted
- Delete all of the candidate's personal data unless a legal obligation requires retention (Correct answer)
- Inform the candidate that deletion is not possible once data has been entered into the ATS
- Transfer the data to a third-party storage service before deleting the local copy
Correct answer: Delete all of the candidate's personal data unless a legal obligation requires retention
GDPR's right to erasure requires organizations to delete personal data upon request unless specific legal grounds — such as ongoing litigation or statutory retention requirements — justify keeping it.
Question 4: What is the primary purpose of a candidate-facing 'privacy notice' in the recruiting process?
- A warning to candidates who submit applications containing excessive personal detail
- A document informing candidates what personal data is collected, why it is processed, and how it will be used (Correct answer)
- An internal policy restricting recruiter access to applicant files without manager approval
- A legal liability waiver that candidates sign before participating in interviews
Correct answer: A document informing candidates what personal data is collected, why it is processed, and how it will be used
A privacy notice fulfills the GDPR transparency principle by giving candidates clear, upfront information about how their data will be handled before they provide it.
Question 5: Which categories of candidate information are classified as 'sensitive' or 'special category' data under most major privacy regulations?
- Prior work history, employment gaps, and professional references
- Educational qualifications, degrees earned, and professional certifications
- Race or ethnic origin, health status, religion, and biometric data (Correct answer)
- Contact details such as email address, phone number, and mailing address
Correct answer: Race or ethnic origin, health status, religion, and biometric data
Privacy regulations such as GDPR identify specific categories — including racial origin, health data, religious beliefs, and biometrics — as requiring heightened protection and explicit consent.
Question 6: When configuring an Applicant Tracking System (ATS) for a recruiting team, which data security measure is most critical to implement?
- Granting all recruiters unrestricted access to maximize team collaboration and speed
- Implementing role-based access controls so users can only view data relevant to their role (Correct answer)
- Storing all candidate data exclusively on local servers without cloud redundancy
- Disabling system audit logs to improve overall ATS performance
Correct answer: Implementing role-based access controls so users can only view data relevant to their role
Role-based access controls limit each user's exposure to only the data needed for their specific function, reducing the risk of accidental or intentional misuse of candidate information.
Question 7: What is the primary purpose of a Data Processing Agreement (DPA) executed between a recruiter's organization and a third-party background check vendor?
- To establish pricing and service-level terms for the background screening contract
- To ensure the vendor processes candidate personal data in compliance with applicable privacy laws (Correct answer)
- To transfer all legal liability for data breaches from the organization to the vendor
- To authorize the vendor to use candidate data for their own marketing and research purposes
Correct answer: To ensure the vendor processes candidate personal data in compliance with applicable privacy laws
A DPA, required under GDPR when using third-party processors, obligates the vendor to handle personal data according to the organization's instructions and applicable privacy regulations.
What does 'purpose limitation' require of recruiters handling candidate data?