Consulting and recruiting
Who owns candidate data: the candidate, the agency or the client?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
No single party owns candidate data outright. The candidate keeps privacy rights over their personal information, the agency controls the records it compiles in its ATS subject to those rights, and the client controls what it creates or receives under its contract. The answer sits in privacy law and notices, the client agreement and the ATS vendor terms.
Key takeaways
- Ownership is the wrong frame for personal data; ask who controls which record, for which purpose, under which document.
- In recruiting contracts, candidate ownership usually means the right to a placement fee, not a right over the data.
- Client interview feedback and VMS submittal records are often client-controlled even when the agency introduced the candidate.
- ATS vendor terms can give the vendor rights to use aggregated customer data, so read the data-use clause.
- Any new use, such as AI tools or licensing, needs all three parties' positions checked first.
The short answer: three parties, different rights#
Candidate data is controlled in layers, and each party's rights come from a different source. Asking who owns it produces arguments; asking who controls a specific record, for what purpose, produces answers an agency can act on.
The table maps the usual position. Contracts can shift it in either direction, so treat it as the default to check against your own agreements.
A useful test for any single record is to ask who created it, under which document it was shared, and what the candidate was told at the time. A recruiter's screening note, a client's interview scorecard and a résumé downloaded from a job board can sit side by side in one ATS profile and still answer that test differently.
| Party | What it usually controls | Where the rights come from | Common limits |
|---|---|---|---|
| Candidate | Their personal information: contact details, work history, résumé content | Privacy laws, the notices they saw and any consents they gave | Rights to access, correct or delete apply where a law grants them, with exceptions |
| Agency | ATS records, recruiter notes, submittal history, assessments it ran, placement and assignment records | Its own work, its employment of recruiters, its ATS contract | Its privacy notices, client agreements, job board terms |
| Client | Requisitions, interview feedback, offer details, VMS records and anything in its own HR systems | The client agreement, VMS or MSP program terms, its own processes | Confidentiality duties to the agency and to the candidate |
| ATS or VMS vendor | Hosts and processes records for its customer | Its service agreement | Usually acts on customer instructions; data-use clauses may allow aggregated use |
Candidate ownership in recruiting contracts is about fees, not data#
Candidate ownership, in most agency terms of business, is a commercial rule about who earns a fee. It says that if a client hires a candidate the agency introduced within a defined period, the agency is owed its fee. It says nothing about who may store, reuse or share that candidate's information.
Confusing the two causes real errors. An agency may assume it can reuse a client's interview feedback because it owns the candidate, when the client agreement treats that feedback as client confidential. A client may assume it can demand every record about a candidate because it was first to interview them.
Keep the fee clause and the data clauses separate when reviewing a contract, and expect them to sit in different sections of the same agreement.
Contract clauses that decide who controls what#
The clauses that decide control are spread across several documents, and most agencies have never read them side by side. The table lists where to look and what to check in each.
Older agreements often lack a data protection schedule entirely. Where that is the case, the confidentiality clause and the agency's own notices carry the weight, and gaps are best closed at the next renewal rather than argued over during a dispute.
| Clause | Where it usually sits | What to check |
|---|---|---|
| Introduction and fee period | Terms of business or MSA | What counts as an introduction and how long it lasts |
| Confidentiality | MSA or NDA | Whether job details, bill rates and interview feedback are client confidential |
| Data protection | DPA or privacy schedule | The agency's role, permitted purposes and deletion on termination |
| VMS and MSP terms | Supplier agreement with the program | Who controls submittal records in the VMS and what can be exported |
| ATS vendor data use | Vendor service agreement | Whether the vendor may use customer data for its own AI features or benchmarks |
| Job board license | Board subscription terms | Whether downloaded profiles may be stored, kept or transferred |
| Recruiter agreement | Employment contract and handbook | Confidentiality and non-solicitation covering ATS records |
What privacy law adds to the contracts#
Privacy law gives candidates rights that no contract between agency and client can remove. Which laws apply depends on where candidates live and where the agency and client operate.
In the US, California's CCPA has applied to job applicant and employee data held by covered businesses since its employment exemption expired on January 1, 2023, and the California Privacy Protection Agency opened preliminary rulemaking on employee and applicant data in April 2026. Not every state law reaches candidates: the Colorado Attorney General states that Colorado's privacy law does not cover people acting in an employment context, such as job applicants. For candidates in the EU or UK, GDPR or UK GDPR may apply, with its own requirements on lawful basis, notice and transfers.
Anti-discrimination law also shapes what may be recorded about candidates and how it is used, whoever controls the record. In practice, privacy law points to three habits: tell candidates at collection what you will do with their information, use it only for those purposes or compatible ones, and be able to answer access and deletion requests.
Can candidate data be used for AI tools or licensing?#
Using candidate data for AI tools or licensing is where the three-party question becomes concrete, because it is a new purpose. Candidate profiles and résumés are rarely suitable for licensing at all. De-identified workflow records, such as the stages a requisition moved through and outcome categories with personal details removed, are more plausible and still need every check below.
- Did the privacy notice at collection describe this purpose, or one compatible with it?
- Do any client agreements treat submittal feedback, rates or interview notes as client confidential?
- Do VMS or MSP program terms restrict what the agency may keep or reuse?
- Do job board terms limit what can be done with downloaded profiles?
- Can personal details be removed while the workflow stays useful?
- Who signs off: the owner, the privacy lead or counsel, and any client whose material is involved?
Illustrative: an accounting staffing agency sorts out three requests#
Illustrative: a fictional accounting and finance staffing agency faced three requests in one quarter. A client whose program had ended asked for deletion of all interview feedback. A departing recruiter asked to export her candidates. The owner wanted to know whether the firm's ATS history could support AI tools.
The operations lead read the client agreements, the VMS terms and the recruiter contracts together. The ended program's MSA made feedback client confidential with deletion at termination, so the agency deleted it and logged the deletion. The recruiter's employment agreement covered ATS records, so the export was declined, while her own professional network was left alone.
For the AI question, the agency excluded clients whose VMS terms kept submittal records client-controlled and scoped any review to de-identified stage histories. The outcome was a one-page map of which party controls which record, now used at every client renewal.
How SourceX handles candidate data questions#
SourceX handles the three-party question in the Rights step of the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. Records controlled by clients, or covered by notices that do not support the use, are carved out before anything is prepared, and candidate profiles and résumés are not licensed.
For workflow records that do proceed, the SourceX Evidence Packet records provenance, licensing rights, permitted use, the privacy record and release authorization, so an agency can show a client or candidate exactly what was licensed and on which terms.
Frequently asked questions
Can a client demand that we delete candidates we submitted?
A client can usually require deletion of its own confidential information, such as interview feedback or requisition details, if the agreement says so. Candidate records the agency collected itself are generally governed by the agency's notices and applicable law rather than the client's request. Check the data protection terms and log what you delete.
Can a candidate ask us to delete their profile?
Where an applicable privacy law gives a deletion right, yes, subject to exceptions such as records you must keep for legal reasons. Many agencies honor deletion requests even where no law requires it. Keeping a minimal suppression entry can stop the same profile being re-imported from a job board.
Does our ATS vendor own our candidate data?
Typically no. Most ATS agreements state that the customer owns or controls its data and the vendor processes it to provide the service. Some agreements also let the vendor use aggregated or de-identified data to improve products or AI features, so read that clause and any opt-out settings.
Who controls candidate data in a split placement between two agencies?
Each agency generally controls the records it collected itself, and the split agreement or network rules govern what is shared between them. Data received from the partner agency should be used only for the purposes that agreement allows, and both agencies' notices still apply to the candidate.
Do recruiters own their professional networks?
A recruiter's personal professional connections are hard for any employer to claim. Records entered into the company ATS, including notes and submittal history, are generally treated as company records under employment agreements and trade secret law. The line varies by state and contract, so review it with employment counsel.
Sources
- The CCPA employee and business-to-business personal information exemptions expired on January 1, 2023 after the California legislature did not extend them. Source
- The California Privacy Protection Agency initiated preliminary rulemaking on April 20, 2026 focused on how the CCPA applies to personal information of employees, job applicants and independent contractors. Source
- The Colorado Attorney General states that the Colorado Privacy Act does not cover personal data of individuals acting in a commercial or employment context, such as a job applicant. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.