Private equity and portfolios
Staffing roll-ups: ATS histories, candidate privacy and AI
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Staffing roll-ups hold years of ATS history, but candidate personal data is the highest-risk part and usually stays out of any license. What can be prepared is the business workflow around it: job orders, client requirement notes, submittal-to-placement stages and recruiter reasoning, with names, contact details and identifiers removed. Decide record by record, with counsel.
Key takeaways
- Candidate personal data, from resumes to background checks, is the highest-risk content in a staffing firm's ATS and is excluded by default.
- Job orders, requirement notes and de-identified placement workflows are the records most likely to be prepared.
- Automated PII detection helps but cannot be relied on alone for candidate records; human review is part of preparation.
- Each add-on collected candidate data under its own privacy notice and job board terms, so rights differ across the roll-up.
- Consolidating ATS instances can resurface records an add-on had already deleted at a candidate's request.
What sits inside a staffing firm's ATS history?#
A staffing firm's ATS history holds two kinds of records that are tightly linked: records about people looking for work, and records about the business of filling jobs. Systems such as Bullhorn, JobDiva or Avionte store candidates, client contacts, companies, job orders, submittals, interviews, placements, notes, emails and, in many firms, timesheets and pay records.
For an operating partner, the useful question is not how many candidates the database holds. It is which records describe how recruiters and account managers made decisions, and whether those decisions can be separated from the identities of the people involved.
| Record | Risk level | Default position |
|---|---|---|
| Job orders and client requirements | Moderate: client confidentiality | Can be prepared with client names removed |
| Submittal, interview and placement stages | Moderate once de-identified | Can be prepared as event sequences |
| Recruiter and account manager notes | High: may describe individuals | Reviewed line by line; many excluded |
| Candidate profiles and resumes | Very high: identity and work history | Excluded by default |
| Background checks, drug screens, I-9 records | Very high: regulated and sensitive | Always excluded |
| EEO self-identification and accommodation records | Very high: protected characteristics | Always excluded |
| Pay and bill rates tied to people | High: personal and commercial | Excluded or aggregated |
Why candidate personal data is high-risk#
Candidate personal data is high-risk because it is detailed, identifying and often sensitive. A resume combined with a work history can identify a person even after the name is removed. ATS records can also hold Social Security numbers, immigration documents, background check reports under the FCRA, drug screen results and notes about health or family circumstances.
Candidates also relate to the firm differently than customers do. They applied for work, often through a job board, under a privacy notice they may not remember reading. State privacy laws such as the CCPA, and the GDPR for candidates in Europe, may apply to these records. Which rules apply, and what they require, is assessed deal by deal with counsel.
Rules for what can be prepared and what stays out#
The rules below set a conservative starting position for a staffing package. Counsel and the supplier can narrow them further, but they should not be loosened without a specific legal basis and a clear buyer need.
- Rule 1: identity never travels. Names, contact details, identifiers, photos and social profile links are removed, or the record is excluded.
- Rule 2: regulated screening records stay out entirely, including background checks, drug screens, I-9 and immigration documents, medical and accommodation records, and EEO self-identification.
- Rule 3: resumes stay out by default, because work histories are hard to de-identify reliably.
- Rule 4: job orders and requirement notes can be prepared once client names and confidential commercial terms are removed.
- Rule 5: submittal, interview, offer, placement and fall-off stages can be prepared as de-identified event sequences.
- Rule 6: recruiter notes are reviewed line by line, and any note that comments on age, health, family, origin or other protected characteristics is excluded.
- Rule 7: pay and bill rates tied to individuals stay out; aggregated ranges are used only if the license needs them and counsel agrees.
Why automated scanning is not enough on its own#
Automated scanning is a necessary first pass on ATS notes and emails, but candidate records need human review as well. Recruiter notes mix shorthand, nicknames, employer names and personal details in ways that pattern matching misses.
Tool makers say as much themselves. The documentation for Presidio, an open-source tool for identifying and anonymizing personal information, warns that because it uses automated detection there is no guarantee it will find all sensitive information, and that additional systems and protections should be employed. A staffing package should plan for reviewer time from the start.
How a roll-up compounds the problem#
A roll-up compounds the problem because each add-on brings its own ATS, its own privacy notice and its own history of candidate requests. Merging those databases is an integration goal, but it can create privacy issues that did not exist in any single firm.
Start with the paper trail. Collect each add-on's career site privacy notice, candidate application terms and job board agreements as they stood when records were created, and store them with the inventory. Without those documents, nobody can later show what a given candidate was told, and records from that add-on are usually held out of scope.
Retention settings also differ by system. Greenhouse Recruiting, for example, lets Site Admins set data retention rules per office for rejected and hired candidates, with deletion then carried out manually, and Greenhouse advises getting legal counsel before configuring them. Record each add-on's settings before migration so the consolidated ATS does not keep candidates longer than their original policy allowed.
| Consolidation issue | Why it matters | What to do |
|---|---|---|
| Duplicate candidates across add-ons | Merged profiles combine data collected under different notices | Keep the source firm and notice version on every record |
| Deletion and opt-out requests | A request honored in one ATS may not reach the merged one | Carry suppression lists into the consolidated system |
| Job board sourced resumes | Job board terms may restrict reuse of downloaded resumes | Tag resumes by source and check each board's terms |
| Different retention settings | One add-on purged old candidates, another kept everything | Apply the platform retention policy before any review |
| Shared client accounts | Two add-ons served the same client under different agreements | Scope job orders by the agreement that governed them |
Illustrative: a light industrial and IT staffing platform#
Illustrative: a fictional staffing platform owns a light industrial firm on Bullhorn and acquires two add-ons, an IT staffing firm on JobDiva and a small accounting placement firm on a spreadsheet-based tracker. The operating partner wants to know whether any of the history could support a data license.
Counsel and the platform's privacy lead agree the conservative rules above. Candidate profiles, resumes and screening records are excluded across all three firms. The IT firm's job orders, technical requirement notes and de-identified submittal-to-placement sequences are scoped for preparation, because they show how recruiters match skills to requirements and why candidates fall off. The light industrial firm's records are parked until its suppression list is reconciled after consolidation. The accounting firm's tracker is too thin to proceed.
How SourceX approaches staffing records#
SourceX starts staffing reviews from the exclusions. In the SourceX five-step transaction, Supply, Rights, Preparation, Approval and Delivery, the Rights step maps each add-on's privacy notices, client agreements and job board terms, and the Preparation step removes personal details with automated tools and human review.
The supplier approves the final scope before anything is delivered. The SourceX Evidence Packet records provenance by source firm, licensing rights, permitted use, the privacy record and release authorization, so the platform can show exactly which candidate-related records were excluded and why.
Frequently asked questions
Can de-identified resumes be licensed?
Usually not. A work history listing specific employers, titles and dates can identify a person even without a name, and reliable de-identification of resumes is hard. Most staffing packages leave resumes out and focus on job orders and workflow records instead. Counsel should review any proposal to include them.
Do we need candidate consent to license workflow records?
It depends on what each add-on's privacy notice said, which laws apply to the candidates involved and how thoroughly records are de-identified. Some packages built only from job orders and de-identified stages may not involve candidate personal data at all. Counsel assesses this deal by deal.
Are client job orders confidential?
Often, at least in part. Client agreements may treat job descriptions, rates and hiring plans as confidential. Removing client names and commercial terms addresses much of this, but check each client agreement, especially for large accounts with their own vendor paper.
What about recruiter emails and call recordings?
Both are high-risk. Emails mix candidate and client details freely, and call recordings raise additional consent questions under recording laws that vary by state. Most packages exclude recordings entirely and treat emails as out of scope unless a narrow, reviewed subset is justified.
Does consolidating onto one ATS make licensing easier?
It can make later preparation simpler, but only if source labels, notice versions and suppression lists survive the migration. A consolidation that drops those fields makes it harder to show where each record came from and what each candidate was told.
Sources
- Presidio's own documentation warns that "because it is using automated detection mechanisms, there is no guarantee that Presidio will find all sensitive information. Consequently, additional systems and protections should be employed." Source
- Presidio is an open-source, MIT-licensed SDK for PII identification and anonymization in text and images. Source
- Greenhouse Recruiting lets Site Admins set data retention rules per office, separately for rejected and hired candidates, with candidate personal data then deleted manually; Greenhouse advises getting legal counsel before configuring. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.