Title: Privacy and PII Handling Version: 1.0 Owner: [TENANT_CONFIGURATION_REQUIRED — Privacy/Compliance] Status: Draft Last reviewed: 2026-09-07 Next review: [TENANT_CONFIGURATION_REQUIRED] Reviewers: Legal, Security, HR
Defines how candidate and employee PII is minimized, protected, and handled throughout the workflow. Legal requirements referenced here are placeholders — [LEGAL_REVIEW_REQUIRED] before go-live.
| Field category | Examples | Classification | Encryption |
|---|---|---|---|
| Contact PII | Name, email, phone | Confidential | Column-level encryption at rest |
| Identity documents | Government ID numbers | Restricted | Column-level encryption, restricted access role |
| Employment/education history | Prior employer, dates, qualifications | Confidential | Standard at-rest encryption |
| Interview feedback | Panelist notes/scores | Confidential | Standard at-rest encryption, access limited to recruiter/HR |
| Compensation | Offer compensation reference | Confidential/Restricted | Referenced by ID only, never stored as platform-native free text |
Process for access, correction, and erasure requests is [LEGAL_REVIEW_REQUIRED]. At minimum, the platform must support: locating all records for a data subject across entities (candidate, application, interview feedback, Green Form, documents), and executing a deletion or anonymization consistent with data-classification-and-retention.md and any active legal hold.
Data residency and cross-border transfer constraints are [LEGAL_REVIEW_REQUIRED] and [TENANT_CONFIGURATION_REQUIRED] per deployment region.
Candidate-facing notice of data collection/processing purpose is [LEGAL_REVIEW_REQUIRED] content, to be surfaced at CV submission and Green Form issuance.
| Version | Date | Author | Change |
|---|---|---|---|
| 1.0 | 2026-09-07 | Documentation package generation | Initial creation |