October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
ATS

How to Assess ATS Integrations for Data Security and Candidate Privacy

Review an ATS integration as a data-sharing arrangement: map candidate information and recipients, verify permissions and safeguards, clarify responsibilities, and test deletion and revocation.

By TheFinanceBase Team 7 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Assess an applicant tracking system (ATS) integration by tracing every candidate-data flow, checking what the integration is authorized to do, and verifying how information is protected, retained, deleted, and handled when access ends. Treat the connection as a data-sharing arrangement—not simply a software feature—and record the evidence and unresolved risks before enabling or renewing it.

What should an ATS integration review establish?

A useful review record explains what information moves between systems, why it moves, who receives it, who can access it, and what happens to it over time. It should also identify who is responsible for each processing activity and what safeguards are supported by evidence rather than marketing claims.

Do not infer the data flow from an integration’s name. Depending on the connection, information may include candidate profiles, applications, CVs, screening answers, status feedback, job configuration, logs, or API credentials. LinkedIn’s Apply Connect documentation, for example, describes applications and resumes, screening answers, job data, and feedback; some activations also involve API client credentials. Indeed’s documentation illustrates that one integration may retrieve candidate records while another sends information from an ATS to Indeed.

The exact behavior depends on the product, configuration, and contract. Platform documentation can help describe a particular integration, but it does not establish that every customer setup is secure or compliant.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do you map the candidate-data flow?

Map each direction separately: ATS to connected platform, connected platform to ATS, and any onward flow to service providers. For every transfer, record the details below. Include one-time imports as well as ongoing synchronization; logs, error reports, and support access can expose information too.

  • Systems and parties: the sending system, receiving system, service providers or subprocessors, and any relevant storage locations.
  • Information: specific fields and record types, such as contact details, CVs, screening responses, application status, or credentials.
  • Movement: direction, trigger, frequency, and whether the transfer is a read, write, status update, or deletion.
  • Purpose: the business need for each field and transfer, and whether the same purpose could be met with less information.
  • Access: the people, service accounts, and vendor personnel who can see or act on the records.

Check whether CVs or screening answers could reveal sensitive information in your recruitment context. The Information Commissioner’s Office (ICO) describes data minimisation as keeping personal information “adequate, relevant, and limited to what you need for your purposes” in its Collecting and keeping employment records guidance.

How can you tell whether permissions are appropriately limited?

Request the integration’s permission list and tie each permission to a documented use. Establish whether the connection can read, create, edit, or delete records; which candidates or entities it can reach; and whether access is limited to the jobs or records needed for the stated purpose.

Rank #2
Sale
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
  • Ideal for Gifting
  • Ideal for a bookworm
  • Compact for travelling

Also identify the app identity or service account, who can authorize it, and how credentials are stored, restricted, monitored, rotated, and revoked. A permission change should trigger a fresh review. Microsoft’s ATS API setup, for example, calls for an application user with a security role granting access to the data entities used by the integration. Microsoft’s setup documentation also describes layered authentication: identity setup and data-role assignment both matter. LinkedIn describes a defined permission set and authorization through the ATS.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Look for a dedicated integration identity rather than an individual employee’s account, and ask what happens if the integration needs broader access later. The permissions shown in product documentation are not proof that a particular tenant has configured them narrowly.

What security evidence should you request?

Ask for evidence relevant to the candidate information, threats, and potential harm involved. Record the evidence’s scope and date, and distinguish controls that are contractually promised, independently assessed, technically configurable, or merely described in product materials.

  • Protection in transit and at rest: encryption details and which data stores or transfer paths they cover.
  • Access controls: how access is granted, restricted, reviewed, and removed, including access by vendor personnel.
  • Credentials and authentication: how secrets are stored and rotated, and whether authentication can be restricted or monitored.
  • Audit and monitoring: what events are logged, who can review logs, and how suspicious activity is detected.
  • Operational response: incident reporting and handling, vulnerability management, backups, and recovery practices.
  • Independent assurance: security reports or certifications, including which service, locations, and period they cover.

Indeed’s Additional API Terms and Guidelines expressly names access controls, encryption, and retention policies as expected practices. Treat such statements as a starting point for questions; compare them with the integration’s actual configuration and contractual commitments. The ICO’s security guidance also emphasizes protections appropriate to the information and risk, including restricting records to authorized people.

Who is responsible for privacy, notices, and contract terms?

Document who determines the purposes and means of each processing activity and who handles information on another party’s instructions. Roles can differ by data flow; do not assume a vendor has the same role for every feature or use.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Review the applicable data-processing agreement or other contract for documented instructions, confidentiality, security, subprocessors, assistance with candidate rights and incidents, deletion or return of data, audit support, and international transfers. Check that candidate-facing privacy information explains the relevant use and recipients, and that any required rights, consents, or other lawful basis are addressed for the actual processing.

For the UK context, the ICO says an employer acting as controller remains ultimately responsible for compliance involving employment records when it uses a processor, and should have written processor terms. Indeed’s partner guidance places responsibility on ATS partners for necessary rights or consents and candidate disclosures when candidate personal data is shared through its API. Applicable legal requirements vary by jurisdiction and by the processing involved; these examples do not establish a universal legal conclusion.

How should you assess retention, deletion, and disconnection?

For each category of data, write down its purpose, retention rationale, review date, and deletion or anonymisation action. Ask how deletion requests propagate to connected systems, backups, logs, and any systems used for support. Clarify any legal-hold process and what information, if any, remains after the integration is disconnected.

Where possible, test the workflow with a test candidate in a sandbox. Disconnect the integration, revoke its credentials, remove its access, and delete the test record; then confirm the outcome in both systems. Disconnecting a connection should not be treated as proof that data already transferred has been erased.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
  • It can be a gift option
  • Comes with secure packaging
  • Helpful in various ways

Retention periods should fit the purpose and type of record. The ICO’s employment-record guidance does not set one universal retention period and recommends schedules suited to the purpose and record type. A distinct Indeed example should not be mistaken for a general rule: its Send Candidates API guidance says opted-in ATS partners must send candidate data created in the last four years under the described integration requirements. That is a specific API requirement, not a legal retention rule for employers generally.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When should you consider a DPIA?

Screen the proposed processing for likely high risk by considering its nature, scope, context, and purpose, along with data sensitivity and volume, the people affected, use of novel technology, and the consequences of error or disclosure. The ICO says a data protection impact assessment (DPIA) must be carried out before processing likely to result in high risk. Even when that threshold is not met, a written flow map and safeguards record can make the decision and later review more accountable.

How can you compare two ATS integration options?

Use the same questions for each option so that differences are visible. Record the answer, evidence, and any open issue rather than relying on a feature label or a general security statement.

Review area What to compare Evidence to record
Data and purpose Fields and record types transferred, direction, triggers, frequency, and stated purpose Data-flow description and confirmation that each field is needed
Permissions Read, create, edit, or delete rights; accessible records; administrator authorization and revocation Permission list, app identity, role configuration, and authorization process
Safeguards Authentication, credential handling, encryption, access controls, logs, incident response, and recovery Current evidence with scope and date; whether each control is contractual, assessed, configurable, or descriptive
Privacy responsibilities Processing roles, instructions, subprocessors, locations, candidate notice, rights support, and applicable lawful basis Contract terms and candidate-facing privacy information
Lifecycle Retention, review dates, deletion propagation, backups and logs, and post-disconnect behavior Written retention and deletion process, plus test results where available
Operations Monitoring, support access, incident ownership, and who maintains the integration Named operational owners and documented escalation routes

Weight the findings according to your organization’s data, threat model, recruitment process, and jurisdiction. If an answer is unavailable, record it as unresolved rather than assuming the most favorable interpretation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should the approval record say?

Before enabling or renewing the connection, preserve a concise decision record that includes:

  • the business purpose and approved data fields;
  • a map of transfers, recipients, and access boundaries;
  • permission and credential controls, with an owner for revocation;
  • security evidence and its scope, date, and limitations;
  • privacy roles, contract terms, and candidate disclosure arrangements;
  • retention, deletion, and disconnection behavior;
  • any DPIA screening outcome and unresolved risks; and
  • the decision owner, review date, and conditions that would require reassessment.

The ICO’s employment-record guidance may be subject to change following legislative developments, and vendor documentation can change too. Confirm the current product behavior, contract, and applicable local law for the specific integration and organization being reviewed.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
Ideal for Gifting; Ideal for a bookworm; Compact for travelling
$10.99
SaleBestseller No. 5
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
It can be a gift option; Comes with secure packaging; Helpful in various ways
$9.15

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Money Desk

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.