Field Notes
AI recruiting & automation Jul 2026 11 min read

Is candidate data safe with AI screening tools? A privacy checklist

A plain-language checklist for evaluating whether any AI candidate screening tool, including Truffle, handles your candidates' data safely. No legal team required.

Is candidate data safe with AI screening tools? A privacy checklist
AI summary
  • Candidate data safety comes down to five checkable vendor habits, not a compliance program or a lawyer's review: what gets collected, how the vendor makes money, who can see a file inside your team, what leaves your team when you share a candidate, and whether there's a straight answer on retention.
  • US law already covers parts of this. California's CCPA has extended notice, access, and deletion rights to job applicants since January 1, 2023, NYC's Local Law 144 requires bias audits and advance notice for scoring tools, and Illinois requires consent and 30-day deletion for AI-analyzed video interviews.
  • The checklist applies to any vendor, including Truffle, and works the same way whether you're hiring for one role or running screening across a book of staffing clients.

Ask about the vendor, not just the AI

Is candidate data safe with AI screening tools? Safety here comes down to the vendor’s habits, not the technology itself, and you can check those habits yourself before you pay for anything.

Most of what gets written about this topic is aimed at a reader who doesn’t exist in a five-person hiring process: a security team with a vendor risk questionnaire, a legal department that reviews data processing agreements, a procurement cycle that takes weeks. If you’re the owner running hiring yourself for a coordinator role, none of that describes your Tuesday. You have a stack of resumes, a role to fill, and a card you’re about to put a monthly charge on.

This is also a different question from whether an AI screening tool’s scoring is fair, which has its own answer in the full framework for defensible AI use in hiring. You don’t need a compliance program to answer the data question. You need five things you can check yourself, in the time it takes to read a pricing page or send one support email. That’s what this is.

What’s actually in the pile you just handed over

An AI screening tool touches more of a candidate’s personal information than most owners expect going in. A resume alone carries a name, phone number, email, home address or general location, and a full work history. Add a one-way video interview and you’ve added someone’s face, voice, and the way they speak about their last employer. Add an assessment and you’ve added responses about how they think and work under pressure.

None of that is unusual for hiring. A recruiter or a hiring manager collects the same things during a normal process. What changes is where it lives. Instead of a folder on someone’s laptop, it sits in a vendor’s system, and that vendor’s habits determine what happens to it next.

That’s worth taking seriously on its own, not because AI makes hiring dangerous, but because any system holding personal data is a target. The global average cost of a data breach hit $4.44 million in 2025, according to IBM’s Cost of a Data Breach Report, down slightly from the year before as detection got faster. You’re not running a $4.44 million operation, but the number is a useful reminder that “just some resumes” is exactly the kind of data breaches are built around. The size of your business doesn’t shrink the value of what a vendor is holding on your behalf.

Five habits that separate a safe vendor from a risky one

Skip the SOC 2 report and the sixty-page data processing agreement. Ask about these five things instead, and judge the answer, not the paperwork.

It collects only what the role needs

A tool built around your role’s actual criteria, must-haves, must-not-haves, screening questions, asks for exactly that. A tool that wants broad access to systems it doesn’t need, or collects fields with no bearing on the hire, is collecting more than it should. More data sitting around is more data that can leak, get subpoenaed, or get misused later. Ask what gets stored and why, and if the answer is vague, that’s the answer.

It makes money from your subscription, not your candidates’ data

Self-serve screening tools mostly run on a paid plan: a monthly fee for a set number of screenings. That’s a different business than one built on aggregating personal data to sell or license elsewhere. Ask directly: does this company’s revenue depend on my subscription, or on what it can do with the data I hand it? A vendor that hedges on this question is telling you something.

It limits who inside your own team can see a file

Not every hire needs every hiring manager to see every candidate’s full profile. A tool worth using lets you set roles, so a collaborator can review and rate candidates without touching billing or account settings, and a viewer can see only the roles they’re assigned to. If everyone on your team automatically sees everything, that’s not a convenience. It’s a lack of controls.

It limits what leaves your team when you share a candidate outside it

At some point you’ll want a second opinion from someone who doesn’t use the tool: a business partner, a client, a franchise owner down the road. Look at what actually leaves your account when that happens. A link that exposes a candidate’s full contact details and raw resume to anyone who clicks it is a different risk than a link that shares the summary and interview highlights while keeping personal contact information hidden, expires on its own, and can be shut off the moment you don’t need it anymore.

It has a straight answer for how long it keeps things

Ask what happens to a candidate’s file after you fill the role or close the posting. A vendor with a real answer will tell you plainly: whether data is deleted, archived, or kept accessible for your own future reference, and what you’d need to do to change that. A vendor without an answer hasn’t thought about it, which means neither have you until something goes wrong.

What the law already requires, and where it stops

You don’t need to memorize regulation to run this checklist, but it helps to know what’s already required so you’re not guessing at your own exposure.

California: the CCPA covers job applicants

If you have California job applicants, the CCPA has covered them since January 1, 2023. California employees and applicants gained the right to be notified what’s collected and why, to access it, correct it, delete it, and opt out of its sale or sharing, with violations running $2,500 each and $7,500 for an intentional one.

New York City: Local Law 144 covers scoring tools

If you’re hiring for a role based in or associated with New York City and using a tool that scores or ranks candidates, Local Law 144 requires an independent bias audit renewed annually, a public report of the results, and advance notice to candidates at least ten business days before you use the tool, disclosing what data feeds it and how long it’s kept.

Illinois: the AI Video Interview Act covers analyzed video

If you’re in Illinois and using AI to analyze video interview responses, the Artificial Intelligence Video Interview Act has required notice, a plain explanation of how the AI works, and consent before the interview since 2020, and it requires deleting a candidate’s interview within 30 days if they ask.

Three different laws, three different triggers, and most small businesses hiring outside California, New York City, or Illinois aren’t directly covered by any of them yet. That’s not a loophole to relax into. It’s exactly why the five habits above matter regardless of where you’re hiring.

If you want the deeper detail on interview recording consent specifically, or on how the EU AI Act treats hiring tools for teams with candidates abroad, those are worth reading on their own. This piece is about the data itself, not the recording or the region.

Running the checklist on a real screening workflow

Here’s what those five habits look like when you run them against an actual screening flow instead of a policy document. Truffle is a candidate screening platform that combines resume screening, one-way video interviews, and talent assessments, built for small businesses hiring without a recruiter, so it’s a fair stand-in for what to look for anywhere.

What the intake step collects, and what it skips

When you set up a role in Truffle, the intake step asks for what the role actually needs: must-haves, nice-to-haves, and the qualification questions you choose to ask. That’s what gets scored, not an open-ended data grab. If a role doesn’t need a certification question, you don’t add one, and Truffle doesn’t invent one on your behalf. Truffle’s business is the plan you’re subscribed to, priced by the number of screenings you run each month, not by what can be extracted from candidate profiles.

Who can see a candidate’s file inside your account

Organization Roles and Job Roles control who sees what. An Owner or Admin can see everything. A Collaborator on a single role can review and rate candidates for that role without touching your billing or your other open positions. A Viewer sees only what they’re assigned to, so if you bring on a second manager for one role, they don’t automatically get a look at every candidate you’ve ever screened.

What leaves your account when you share a candidate

When you need a second opinion from someone outside Truffle entirely, Candidate Sharing generates a read-only link that shows the AI summary, Candidate Shorts, and AI Match score, while contact information and the raw resume stay hidden. You can password-protect it, and it expires after 75 days on its own or the moment you revoke it, whichever comes first.

What happens after you close the role

Closing a position stops new candidates from applying, and the candidates you already screened stay accessible in your account for your own reference rather than disappearing. If you need something removed on a candidate’s request, that’s worth raising directly with support rather than assuming it happens automatically, and that’s true of any vendor you ask, not only this one.

Run the same five questions against whatever tool you’re evaluating, including the one you’re already using. A checklist that only holds up when you point it at someone else isn’t one you can trust.

The same checklist works whether you’re hiring once or running it for a dozen clients

If you run a small staffing agency, the stakes look slightly different but the checklist doesn’t change. You’re not just protecting one company’s candidates. You’re holding candidate data for every client whose roles you’re screening at once, and the failure mode you’re really guarding against is one client’s candidate showing up somewhere a different client can see it.

The same five habits answer that. Minimization means each client’s role only pulls in what that role needs. Access limits mean a recruiter working one client’s book doesn’t automatically see another’s. Sharing controls mean the link you send a client shows that client’s candidates, not your whole pipeline.

None of this requires a bigger or more complicated tool, just the same five checks, run once per client relationship instead of once per hire. The regulations covering all this will keep shifting, city by city and state by state, and keeping track of which law applies to which hire isn’t a fight you signed up for. The five habits don’t move with the map. They’re yours to check on any vendor, in any state, on whichever tool actually fits your hiring, for as long as you’re the one running it.

Frequently asked questions about candidate data privacy in AI screening

Is it safe to use AI to screen resumes?

It can be, but safety depends on the vendor’s habits, not on the fact that AI is involved. Check what data gets collected, who can see it inside and outside your team, and whether the vendor has a clear answer on retention before you upload anything.

Do AI screening tools sell candidate data?

Some data brokers do build a business around aggregating personal information, which is a different model from a subscription-based screening tool. Ask any vendor directly whether its revenue depends on your monthly plan or on what it can do with candidate data, and treat a vague answer as your answer.

How long do AI screening tools keep candidate resumes or video?

It varies by vendor, and a good one will tell you plainly. Some keep data accessible after a role closes so you can refer back to it, others delete or archive it on a schedule. Ask before you commit, not after you need to know.

Can a candidate ask a company to delete their screening data?

In some places, yes, by law. California’s CCPA gives job applicants a right to request deletion, and Illinois requires deleting an AI-analyzed interview within 30 days of a candidate’s request. Even outside those jurisdictions, it’s worth confirming directly with any vendor how a deletion request gets handled.

End of dispatch

Founder, Truffle

Sean began his career in leadership at Best Buy Canada before scaling SimpleTexting from $1MM to $40MM ARR. As COO at Sinch, he led 750+ people and $300MM ARR. A marathoner and sun-chaser, he thrives on big challenges.

More from Field Notes

Truffle is candidate screening software built for the AI age

Start free trial

7 days · 30 credits · no card required

Start typing to search 300+ pages on hiretruffle.com.