Private equity and portfolios
Staffing roll-ups: consolidating ATS data across add-on acquisitions
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Staffing roll-up ATS consolidation works best when each acquired database is treated as its own rights question before any merge. Check the notices candidates received and the client terms on job orders, dedupe with a crosswalk that keeps legacy IDs and the strictest consent flag, then migrate active records and archive the rest in full.
Key takeaways
- Each acquired ATS database carries the notices, job board terms and client contracts it was built under, and those terms do not reset at closing.
- When duplicate candidate records merge, keep the most restrictive communication preference and every legacy record ID.
- Migrate the records recruiters will use, and archive full history, including attachments and activity notes, before the old instance is switched off.
- EEO self-identification, background checks and drug screen results belong in segregated storage, never in a merged search index or a data license.
What makes ATS consolidation different in a staffing roll-up?#
ATS consolidation in a staffing roll-up differs from other system integrations because the core records describe people, not products or jobs. Candidate profiles, resumes, submittal histories and placement records were collected by different firms under different privacy notices, job board agreements and client contracts, and the platform inherits all of those terms.
Operating partners usually push for one instance quickly so recruiters can search a single talent pool and cross-sell across brands. That goal is sound, but merging databases before checking their terms can move a candidate who agreed to hear from one specialist firm into outreach from every brand, and can expose client rate cards to brands that never signed that client's MSA.
Step one: run a rights check on each acquired database#
A rights check on each acquired database answers one question: what did this firm promise candidates, clients and vendors about how these records would be used? The answers set the boundaries for merging, outreach and any later licensing.
Where a notice is missing or vague, record the database as restricted rather than guessing. A restricted database can still be archived and used for compliance, but it should not feed cross-brand campaigns until counsel has reviewed it.
| Source of terms | What to read | What it can restrict |
|---|---|---|
| Candidate privacy notice | The version in force when records were collected, plus any updates sent to candidates | Sharing across brands, new uses, retention |
| Job board and resume database terms | License terms for resumes sourced from paid boards | Copying sourced resumes into another firm's ATS |
| Client MSAs and VMS program terms | Confidentiality, data handling and non-solicitation clauses | Use of job orders, bill rates and client contact data |
| ATS vendor agreement | Data ownership, export rights and termination terms for each instance | Format and timing of the final export |
| Purchase agreement | Which entity bought which records, and the seller's data reps | Whether records transferred at all in an asset deal |
Step two: dedupe candidates and contacts without losing history#
Deduplication across ATS instances should match records conservatively and preserve every legacy identifier. A crosswalk table that maps each old candidate and contact ID to the new one lets you trace any merged record back to its source database and its consent basis.
In Bullhorn-to-Bullhorn consolidations, custom fields often differ between instances, so map them explicitly. A field called status in one brand may mean pipeline stage, while another brand used the same field for availability.
- Match on verified email first, then phone, then name plus location; send uncertain matches to a recruiter for review rather than auto-merging.
- Keep the strictest communication preference from any source record, so an opt-out at one brand survives the merge.
- Carry the source brand and original creation date onto the merged record.
- Keep placement and assignment history tagged with the brand it came from rather than collapsing two histories into one timeline.
- Treat hiring managers and client contacts separately from candidates, because client terms govern them.
What should migrate and what should stay in the archive?#
The migrate-or-archive decision should follow use: migrate what recruiters will actively search and update, and archive everything else in full, with its original structure intact. An archive is not a lesser copy; it is the record of what each firm held and why.
Archive each legacy instance before its subscription ends, export attachments as well as database tables, and test that a sample of resumes and notes open. Many ATS vendors limit what can be exported once an account lapses, so confirm the process in writing while the contract is live.
| Record type | Migrate | Archive | Notes |
|---|---|---|---|
| Active candidates with recent activity | Yes | Yes, full history | Carry consent flags and source brand |
| Dormant candidates | Only if the notice supports the new brand's use | Yes | The retention schedule may call for deletion instead |
| Placements and assignments | Key fields | Yes, with timesheets and rates | Needed for payroll, tax and claims questions |
| Job orders and submittals | Open orders only | Yes | Client confidentiality applies to closed orders too |
| Email, SMS and call logs | Recent threads only | Yes | Often the richest record of recruiter judgment |
| EEO, background and drug screen data | No, keep segregated | In restricted storage | Access limited to compliance staff |
Which consent and privacy rules may apply?#
The consent and privacy rules that may apply to a consolidated ATS depend on where candidates live, what they were told and what the platform now plans to do with their records. State privacy laws such as the CCPA can reach applicant and employee data, GDPR may apply to candidates in Europe, and the FCRA governs consumer reports used in hiring decisions.
Counsel assesses these deal by deal. In practice, the platform needs a record of which notice each candidate received, a way to honor deletion and opt-out requests across the merged database, and a clear line between data used for placements and data used for anything new.
Automated tools help find personal details in resumes and notes, but they miss things. The open-source Presidio project's own documentation warns that its automated detection gives no guarantee of finding all sensitive information, which is why human review stays in any de-identification process.
Illustrative: a staffing platform with four brands and two ATS products#
Illustrative: a fictional staffing platform owns a light industrial brand, an IT contract brand, an accounting and finance brand and a skilled trades brand. Three run separate Bullhorn instances; the trades brand runs an older ATS whose vendor is ending support.
The rights check shows the IT brand's notice allowed sharing across affiliates, the trades brand's notice did not, and the finance brand sourced many resumes from a job board whose terms limit copying. The platform migrates active candidates from the IT and finance brands, keeps board-sourced resumes in the finance brand's partition, and archives the trades ATS in full before support ends.
When the operating partner later asks about licensing, the answer is narrow: candidate personal data is out. What remains in scope for review is de-identified job order intake and submittal-to-placement workflow from brands whose client terms allow it, with every name, contact detail and employer removed.
How SourceX approaches staffing records#
SourceX approaches staffing records with caution because so much of their value sits next to candidate personal data. In the Supply and Rights steps of the SourceX five-step transaction, each acquired database is assessed on its own notices and client terms, and candidate-identifying data, EEO data and screening results are excluded from scope.
Where a workflow package proceeds, the SourceX Evidence Packet records the source brand, the governing notice version, what was removed in Preparation and who signed the release authorization. Many staffing databases will not qualify, and the fit check says so before any file is shared.
Frequently asked questions
Can we merge candidate databases from acquired staffing firms right after closing?
You can usually consolidate them technically, but outreach and new uses should wait for the rights check. Each firm's notices and job board terms travel with its records. Merging into one search index is safer when every record keeps its source brand and consent flags.
Should we keep both records when two brands hold the same candidate?
Keep one merged active record plus the full archive of each source instance. The crosswalk links them, so you can show where any data point came from and honor an opt-out recorded at either brand, even after recruiters have edited the merged profile.
How long should legacy ATS archives be kept?
Retention depends on payroll, tax, employment and record-keeping rules in the states where you operate, plus client contract terms. Set a written retention schedule with counsel, apply it to the archive as well as the live system, and log deletions so you can show the schedule was followed.
Do job board resumes belong to the staffing firm?
Often not in a simple sense. Resumes accessed through a paid board are usually licensed for the subscriber's recruiting use, and copying them into another firm's system or using them for new purposes may be restricted. Read each board's terms for the account that sourced them.
Who should own the consolidated ATS after the roll-up?
A single platform data owner, usually in operations or IT, should own the merged instance, with brand leaders accountable for their source records. Compliance owns segregated EEO and screening data. Written ownership prevents the drift where nobody can approve an export or a deletion request.
Sources
- Presidio's own documentation warns that because it uses automated detection mechanisms, there is no guarantee that Presidio will find all sensitive information, and additional systems and protections should be employed. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.