Skip to content

Consulting and recruiting

Recruiter leaving with the candidate database: what the law says

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

When a recruiter takes the candidate database, a staffing firm's strongest claims usually rest on trade secret law and the recruiter's signed agreements, and both depend on proof that the firm kept the data confidential. Act quickly: preserve ATS export logs, revoke access and involve counsel before contacting the recruiter or the new employer.

Key takeaways

  • A candidate database can qualify as a trade secret only if the firm took reasonable steps to keep it secret.
  • Export logs, access records and signed confidentiality agreements are the evidence that decides most disputes.
  • Non-solicit and non-compete enforceability varies sharply by state, and some states limit them heavily.
  • An export containing Social Security or license numbers may also need a breach analysis under state law.
  • Prevention costs less than litigation: restrict exports, log activity and offboard the same day.

Is a candidate database a trade secret?#

A candidate database can be a trade secret when it derives value from not being generally known and the firm took reasonable measures to keep it secret. The federal Defend Trade Secrets Act, signed on May 11, 2016, created a federal civil claim for misappropriation and defines a trade secret in 18 U.S.C. § 1839(3) using that two-part test. State trade secret statutes, most of them modeled on the Uniform Trade Secrets Act, use versions of the same test.

Courts look at what the compilation adds beyond public information. A bare list of names that anyone could rebuild from professional networking sites is weak. A database with recruiter notes on availability, pay expectations, interview feedback, client preferences and placement history is stronger, because that knowledge took years of calls to assemble.

Reasonable measures is where many firms lose. Department of Justice guidance says protective measures need not be absolute but must be reasonable, citing steps such as telling employees the information is secret, limiting access to those who need it and requiring confidentiality agreements. Shared logins, unrestricted exports, no confidentiality agreement and recruiters syncing contacts to personal phones all suggest the firm did not treat the data as secret.

What claims can a staffing firm bring?#

A staffing firm whose recruiter takes the candidate database usually has several possible claims, and counsel chooses among them based on the evidence and the state.

  • Trade secret misappropriation under federal or state law, which can support injunctions and damages.
  • Breach of contract, based on confidentiality, non-solicit, return-of-property or assignment clauses the recruiter signed.
  • Breach of the duty of loyalty, where the recruiter diverted business while still employed.
  • Claims against a new employer that knowingly uses the data, such as misappropriation or interference with contracts.
  • Computer access claims, which courts have often read narrowly when the employee had authorized access, making them a weaker fit.

Common departure scenarios and how they play out#

Departure scenarios differ mainly in what left, how it left and what the recruiter signed. The table gives the usual legal theory and the evidence that decides each one; outcomes always depend on state law and the facts.

Remedies can include a temporary restraining order, an order to return and delete data, forensic inspection of devices and damages. Delay weakens any request for urgent relief, because it suggests the harm was not urgent.

Common departure scenarios and how they play out
ScenarioLikely legal theoryEvidence that mattersFirst move
Bulk ATS export emailed to a personal account before resigningTrade secret misappropriation and breach of the confidentiality agreementExport logs, email forwarding records, timing against the resignationPreserve logs, image the laptop, have counsel send a demand
Contacts synced to a personal phone or networking accountDepends on policy and whether the data is readily ascertainableDevice policy, signed acknowledgments, which fields were copiedRequest return and certification under the signed agreement
Recruiter solicits clients or placed contractors after leavingNon-solicit clause, where enforceable in that stateClient emails, job orders moving, contractors switchingCounsel assesses enforceability before any letter goes out
Recruiter relies only on memory and public profilesUsually weak, since general skill and knowledge stay with the personWhether specific confidential details are being usedMonitor, document and avoid overreaching claims
New employer's ATS shows records imported from your firmMisappropriation, plus claims against the new employerRecord metadata, import dates, matching notesCounsel notifies the new employer and requests preservation
Former recruiter still logs in after departureUnauthorized access, plus an internal control failureSingle sign-on and ATS login logsRevoke access, rotate shared credentials, review activity

Do non-solicit agreements hold up?#

Non-solicit agreements hold up in some states and fail in others, and the same clause can be enforced in one state and voided in the next. Some states, California among them, sharply limit restrictive covenants for employees, while others enforce reasonable non-solicits tied to clients or candidates the recruiter actually worked with.

Courts tend to favor narrow clauses: a defined set of clients or candidates, a limited time and a clear business interest. A clause that bars a recruiter from working in staffing anywhere is more likely to be struck down. Federal and state rules on restrictive covenants keep shifting, so have counsel review templates before relying on them.

Even where a non-solicit fails, confidentiality and trade secret obligations usually survive. That is why many firms lean on data protection rather than restrictive covenants.

The privacy problem inside a stolen database#

A stolen candidate database is also a privacy incident, because it holds personal information about people who never agreed to the recruiter taking it. If the export included data elements covered by state breach notification laws, such as Social Security or driver's license numbers from onboarding files, the firm may have to assess whether notice to individuals or regulators is required.

Candidates in California have rights under the CCPA, including a private right of action for certain data breaches, and some client contracts require you to report unauthorized disclosure of their workers' data. Run the privacy assessment alongside the trade secret response, with the same counsel coordinating, so statements to a court and to candidates stay consistent.

Prevention checklist: access, logs and offboarding#

Prevention rests on three controls: limit who can export, record what was exported, and close access the moment someone leaves. Each control also becomes evidence of reasonable secrecy measures if a dispute comes later.

  • Set ATS permissions by role so recruiters see and export only their own pipeline, and require admin approval for bulk exports.
  • Turn on export and report logging in the ATS, and alert a manager when a large export or mass email runs.
  • Have every recruiter sign a confidentiality and return-of-property agreement, and refresh acknowledgments when policies change.
  • Include the whistleblower immunity notice required by 18 U.S.C. 1833(b) in those agreements, or cross-reference a policy that contains it; without it, a firm may lose exemplary damages and attorney fees under the Defend Trade Secrets Act against that recruiter.
  • Use company-managed devices or mobile device management, and block contact sync from the ATS to personal phones.
  • Hold recruiting platform seats under a company contract, and decide in writing what happens to projects and messages when someone leaves.
  • On resignation, revoke single sign-on, ATS, email and texting access the same day, and collect devices.
  • Review the recruiter's recent export and download activity before the exit meeting, and ask for a signed return certification.

Illustrative: a firm catches an export before the recruiter moves on#

Illustrative: a fictional accounting and finance staffing firm learns that a senior recruiter is joining a competitor. Its Bullhorn administrator pulls the export log and finds a large candidate report generated after hours shortly before the resignation.

Because exports beyond a recruiter's own records need manager approval, the report covers only that recruiter's pipeline, not the full database. Counsel sends a demand for return and deletion, the recruiter signs a certification and hands back a USB drive, and the firm adds automatic alerts for after-hours exports. Signed agreements and logs, rather than a lawsuit, settle the matter.

How SourceX looks at candidate databases#

SourceX looks at a candidate database as a record set with heavy personal-information and rights constraints, so candidate profiles are generally excluded from licensing reviews. The same controls that protect a database from a departing recruiter, such as role-based access, export logs and documented ownership, are what the Supply and Rights steps of the SourceX five-step transaction check first.

When a firm does hold licensable process records, such as job order workflows or placement stage histories with personal details removed, the SourceX Evidence Packet records their provenance and the firm's release authorization. Clear provenance is far easier to show when the firm already knows who exported what, and when.

Frequently asked questions

Can we pursue the new employer as well as the recruiter?

Possibly. If the new employer knew or should have known it was receiving misappropriated data, trade secret law and related claims may reach it. Many disputes resolve once counsel notifies the new employer, which usually has its own reasons to quarantine imported records. Your counsel decides whether and how to approach it.

Does a recruiter own their professional network connections?

Ownership of a personal professional network is unsettled and fact-specific. Firms reduce disputes by setting rules in advance: company-held recruiting seats, a policy on adding firm candidates as personal connections, and agreements covering firm data at departure. Without a written policy, claims over a personal network are much harder to bring.

Should a departing recruiter keep system access during the notice period?

Many firms end system access at resignation and pay out the notice period instead, because the highest-risk window falls between resignation and the last day. Whether that suits you depends on client handover needs and on employment law in your state, so agree the approach with counsel in advance.

How quickly do we need to act?

Act as soon as you suspect data left. Logs may roll off under your ATS or email retention settings, and courts weigh delay when deciding whether urgent relief is justified. Preserve evidence first, then decide on legal steps with counsel rather than confronting the recruiter informally.

Does this apply to contract recruiters?

Contract recruiters raise the same issues, but the paperwork differs. Their consulting agreement should cover confidentiality, return of data and system access, and the firm should apply the same access controls it uses for employees. Contractor classification and restrictive covenant rules vary by state, so review templates with counsel.

Sources

  • The DTSA, signed May 11, 2016, created a federal civil claim; under 18 U.S.C. 1839(3) a trade secret requires reasonable secrecy measures and independent economic value from not being generally known. Source
  • Protective measures need not be absolute but must be reasonable, such as advising employees, limiting access and requiring confidentiality agreements. Source
  • 18 U.S.C. 1833(b) requires employers to give notice of whistleblower immunity in employee contracts governing trade secrets or confidential information. Source
  • An employer that fails to give the 1833(b) notice may not recover exemplary damages or attorney fees against an employee who did not receive it. Source
  • The CCPA private right of action for data breaches applies to employee and applicant data. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify