To set up data retention rules for your business, review the notes in this article. At the bottom of this article, click the button to download the data retention workbook. Once completed, send this to [email protected]
Candidate Records (Never Hired)
Scope
If enabled, applies only where a person:
Never converted to an employee, and
Has all applications archived
Trigger
Application archiving - the retention period starts from the most recent archived application date.
Data Destruction
The entire candidate record, including all their details (name, phone, etc), all applications for that candidate and all compliance records and documents.
Employee Records (Terminated / Archived)
Scope
If enabled, applies to people:
Who were employed and later terminated or archived.
Have all applications archived (if any).
Are past the defined retention period for candidate records (if they have applications)
Trigger
Employee archived or lifecycle changed to terminated - The retention period starts from the employee archived date or termination date (whichever is earlier).
Data Destruction
The destruction scope is always the entire employee record, including all their details (name, phone, etc), all applications attached to that employee and all compliance records and documents.
Requirement-Level Data
Scope
Applies to individual compliance records for candidates and employees.
Trigger
The retention period starts when a requirement reaches a finalised status (ie. Approved, Exempted, Rejected)
Configuration
Select whether deletion applies to:
the entire requirement, or
documents only
Note: If the entire requirement is destroyed, and it is currently required for compliance, the employee will become non-compliant.
Data Destruction
Entire requirement - All compliance records for this requirement are removed. All entries in the activity log are removed. All documents are deleted.
Documents only - Documents are deleted, including any AI data. Field data for the requirement is retained.
To allow for processing checks and accounting for any admin errors, we strongly recommend keeping data for at least 2 weeks.
Additional Notes
Zipline may opt to keep the minimum de-identified data needed for billing and reporting.
Should a specific aspect of data being destroyed be required for a certain use, please extract a report before it is deleted.
All data destruction occurs at the person or requirement level. If you want to consider document types, consider the types of documents requested for specific requirements and the purpose of these documents in meeting the requirements.
