Browse topics
GDPR & Data

Set data retention rules for candidates

Set data retention rules for candidates

Retention rules help you keep candidate data only as long as you need it. You set a default retention period, and Crumblelead flags candidates for review as they reach it, so nothing lingers by accident.

Set your retention period

  1. Go to Settings, then Data Retention.
  2. In the Retention policy section, choose a Default retention period: 6, 12, 18 or 24 months. This is counted from when a candidate's data was first captured.
  3. Save your changes.

Changing the period applies to new candidates only. Existing candidates keep their current expiry date unless you extend them manually. Candidates with an active placement are always exempt and never appear in the review queue.

Review candidates as they age

The Candidates requiring review section groups people into Overdue, Due in 30 days and Within policy. For each candidate you can:

  • Mark reviewed — confirm you have checked the record and it is fine to keep.
  • Extend — keep the record for another 6, 12 or 18 months, with a reason logged for your records.
  • Request consent — ask the candidate to agree to you keeping their data, if your workspace uses consent. See Send GDPR consent requests to candidates.

You can also act on several candidates at once using the selection bar.

What happens when a candidate passes the limit

Candidates past their retention date appear in the review queue so you can decide what to do. If a candidate is left unreviewed well beyond the limit, has no active placement and no live application, Crumblelead automatically flags them and anonymises their record after a short grace period. Erasing means the personal details are removed while anonymised application and placement history is kept for reporting. To erase someone yourself, see Erase a candidate's data (right to erasure).

Retention reminders

The Expiry digest sends the workspace owner a quarterly summary of candidates that are overdue or due soon. It is only sent when there is something to act on. You can choose which month and day it lands, in the same section.

Roles and limits

  • The Data Retention settings are admin only.
  • The retention period is workspace-wide. Individual candidates can be extended.
  • The expiry digest goes to the workspace owner and is sent quarterly.

FAQs

Does changing the period update everyone?
No. It applies to new candidates. Existing candidates keep their current date unless you extend them.

What about candidates I have placed?
Anyone with an active placement is exempt and will not appear in the review queue.

Will data be deleted automatically?
Records left unreviewed long after their limit are automatically flagged and anonymised after a grace period. Reviewing or extending a candidate keeps them.

Related articles