Skip to content
Surhires

California

What California consumers can ask of a recruitment database

California treats job applicants as consumers with rights over their records, and a recruitment database is exactly the kind of collection those rights were written for.

Under the CCPA as amended by the CPRA, California job applicants and candidates hold consumer rights over the records you keep about them. Surhires supports notice at collection, access, deletion, correction and opt-out handling against candidate records in your tenant. You remain the business responsible for answering. No compliance is claimed on your behalf.

By Surhires Editorial · Published · Reviewed

What this page is, and who the responsible party is

This is a plain-English explanation of how the product supports California consumer rights against candidate records. It is not a compliance statement, not the privacy policy and not legal advice. The binding documents are the privacy policy published on this site as it currently stands, the executed agreement and the data processing addendum. Where they differ from this page, they govern.

The responsible party is your firm. In California terms you are the business that determines the purposes and means of processing candidate personal information, and Soor LLC is your service provider processing it on your behalf under written terms that restrict what may be done with it. That allocation is what makes the rights answerable, and it is written into the addendum rather than assumed.

Whether the CCPA applies to your firm at all depends on thresholds and facts a website cannot assess. That question, and the question of how your obligations interact with your client contracts, belongs to counsel who knows your business.

Applicants and candidates are consumers, and that changed the shape of the work

The exemptions that once kept employment and applicant data outside the main body of the CCPA have expired. Job applicants, candidates in a sourcing database and former employees hold consumer rights over their records: to know what is collected, to access it, to have it deleted, to have it corrected, and to limit certain uses.

For a recruitment firm that is a bigger change than it looks, because a candidate database is largely made of people who never applied. They were sourced, forwarded, imported or bought in a list, and none of those origins removes the rights. A firm that can answer for its applicants but not for its sourced records has answered half the question.

The practical consequence is that the database has to be searchable by person rather than by pipeline. A request arrives as a name, an email address or a phone number, and the answer has to find every record that person appears in, including duplicates created by three recruiters importing the same list.

  • Applicants, candidates and former employees hold consumer rights
  • Sourced and imported records carry the same rights as applications
  • Requests arrive as an identity, not as a record identifier
  • Duplicate records have to be found and answered together
  • Answering half the database is not answering the request

Notice at collection has to be given at or before collection

The notice tells the person what categories are collected and why, at or before the point of collection. For an application form that is straightforward: the notice sits with the form and the version shown is recorded. For sourced candidates it is harder, because the collection happened before any contact, and the practical moment is the first message you send.

The product supports attaching notice text to outreach templates, recording which version was shown against the record, and giving a route into a candidate-facing view of what is held. What it does not do is write your notice. The categories have to match what your firm actually collects, and a generic paragraph copied from another company describes their practice rather than yours.

Where candidates come from a job board, a client or a list vendor, the origin belongs in the notice. Vagueness about provenance is the part candidates notice, and it is the part a regulator asks about first.

The sale and sharing question, answered directly

Recruitment software should not be selling candidate personal information, and Surhires does not. Candidate data in your tenant is not sold, rented, licensed or made available to other customers, and there is no shared talent pool behind the tenant boundary. Sharing for cross-context behavioural advertising does not happen either, because candidate records are not fed into advertising systems.

The reason to state that plainly is that the definitions are broader than most people expect. Sale covers disclosure for valuable consideration, not just for cash, and sharing has a specific advertising meaning. Arrangements that feel like partnerships or data enrichment can fall inside the definitions, which is why the answer here is a flat no rather than a qualified one.

Your own practices are a separate matter. If your firm sends candidate data to a partner agency, a list broker or an advertising platform, that is your disclosure to assess and your opt-out to honour. The product gives you an opt-out flag on the record and suppression that survives re-import; the assessment of whether your arrangement is a sale is yours.

  • No sale, rent, licence or cross-tenant pooling of candidate data
  • No sharing of candidate records for behavioural advertising
  • Sale covers valuable consideration, not only money changing hands
  • Your own onward disclosures remain yours to assess and disclose
  • Opt-out flags and import-proof suppression available on the record

Access, deletion and correction, served from the record

An access request is answered by the same export that serves subject access elsewhere: the structured profile, parsed resume text, custom fields, notes, message history, call and interview records, stage and disposition history and consent events, as CSV for a person and JSON for a system. It runs from the record without a support ticket in the path.

Deletion removes the profile, custom fields, notes, messages, the original uploaded file, the extracted text and the search representation together, and keeps a fulfilment record, which is the fact of the request rather than the data it concerned. Where a completed placement created financial records that statute requires you to keep, the workflow separates what can go from what must stay and produces a summary of the exception.

Correction is editing the record with an audit trail, and the candidate portal lets people fix their own details. Verification of the requester sits with you and is a real obligation: releasing a candidate's file to whoever emails is its own breach, and the product logs who ran the export and when so your verification step has something to attach to.

Sensitive information, retention and the parts recruiters get wrong

Recruitment collects categories California treats as sensitive more often than most industries realise: government identifiers on right-to-work documents, immigration and visa status, health information volunteered during an accommodation conversation, and demographic answers collected for equal-opportunity reporting. Each has a narrower permitted-use expectation than a job title.

The product keeps demographic data in a separate table with its own access control, invisible to recruiters and excluded from every model payload. Documents carrying identifiers are stored as documents with restricted access rather than being parsed into searchable fields. Those are structural controls, and they are more reliable than a policy asking recruiters to be careful.

Retention disclosure is the other commonly missed item. You have to be able to say how long each category is kept, which requires having decided. The product's retention windows, measured from last meaningful contact and configurable per record type, are what turn that disclosure into something true rather than aspirational.

Building the process so a request does not become a fire drill

Most firms discover their request process during the first request, which is the expensive way to find out. The parts worth deciding in advance are who receives requests, how identity is verified, who runs the export, who reviews it for third-party content, who signs off a deletion, and where the record of all that is kept.

The product supplies the mechanical half: identity search across duplicates, one-action export, deletion that reaches the file and the index, an audit record of who did what, and suppression that survives the next import. The judgement half stays with you, particularly redaction, because notes naming a referee, a client contact or another candidate are flagged for review rather than released blindly.

Written down once, this is a half-page procedure. Discovered under a statutory deadline, it is a week of somebody's life. That is the whole argument for doing it during onboarding rather than later.

  • Decide the receiving route and the verification step in advance
  • Search by identity, not by record, so duplicates are caught
  • Review third-party content in notes before anything is released
  • Keep the audit record of who exported or erased, and when
  • Set suppression so an opted-out person does not return by import

What you get

Service provider terms

Processing restricted by written terms in the addendum, with your firm as the responsible business.

Identity-based search

Requests resolved by name, email or phone across duplicate records rather than one profile.

Notice at collection support

Notice text attachable to forms and outreach, with the version shown recorded on the record.

No sale of candidate data

Candidate records are not sold, rented, licensed or pooled across customer tenants.

No advertising sharing

Candidate records are not fed to advertising platforms for cross-context behavioural advertising.

Opt-out flag

A record-level opt-out for onward disclosure decisions your own firm makes.

Import-proof suppression

An opted-out person stays suppressed when the same list is imported again next quarter.

Self-service access export

Structured record, notes, messages and history as CSV and JSON, run without a support ticket.

Deletion to the file

Profile, notes, messages, original document, extracted text and search index removed together.

Named retention exceptions

Financial records from a completed placement kept under a stated reason, summarised for the requester.

Portal correction

Candidates correct their own details directly, with the change recorded on the record.

Sensitive data separation

Demographic fields held apart with their own access control and excluded from model payloads.

Document handling

Identity documents stored as restricted documents rather than parsed into searchable fields.

Request audit trail

Who ran an export or an erasure, and when, kept so your verification step has evidence attached.

Questions recruiters ask

Do California rights really apply to job applicants?

The exemptions that once kept applicant and employee data outside the main body of the law have expired, so applicants, candidates and former employees hold consumer rights over their records. For recruitment firms the harder half is sourced candidates who never applied, since the rights attach regardless of how the record arrived in the database.

Does Surhires sell candidate data?

No. Candidate records in your tenant are not sold, rented, licensed or shared with other customers, and there is no cross-tenant talent pool. They are not fed to advertising platforms either. The definitions are broad enough to catch arrangements that do not involve money, which is why the answer is flat rather than qualified.

Who verifies that a request really came from the candidate?

You do, and it matters. Releasing a candidate file to whoever emails is its own breach. The product supports the mechanical side, including identity search across duplicates and an audit record of who ran an export and when, so your verification step has evidence attached to it. The verification judgement itself remains a business decision.

What if a deletion request covers a candidate we placed?

A completed placement usually creates financial records you are required to keep. The workflow separates personal data that can be erased from the financial record that must stay, erases the first, retains the second under a named reason, and produces a summary of what was kept and why so the requester gets a straight answer rather than silence.

Can we prevent an opted-out candidate returning through a new import?

Yes, and it is the failure that catches most firms. Suppression is held against the identity rather than the record, so re-importing the same list next quarter does not resurrect the person into an outreach sequence. Without that, an opt-out honoured in March quietly stops being honoured in July and nobody notices until a complaint arrives.

Does this page make our firm CCPA compliant?

No. It explains what the product supports so you can build a process that works. Whether the law applies to your firm, and whether your notices, verification, retention and disclosures satisfy it, depends on facts this page cannot see. Those questions belong to your counsel, with your actual data flows and client contracts in front of them.

See it against your own reqs

Bring one live role and three resumes. In twenty minutes you will see the match scores, the shortlist and the placement invoice that comes out the other end.