Skip to main content

GDPR and data subject requests

RecSphere holds a lot of personal data: CVs, contact details, right-to-work documents, references, payroll history. This article covers the day-to-day GDPR mechanics in RecSphere: subject access requests, the right to erasure, and configuring data retention.

Where your data is held​

Your workspace data is hosted in the UK by default for UK customers and in Australia for AU customers. Data does not cross borders without your explicit configuration. The hosting region is fixed at signup and shown under Settings > Company.

Subject access requests​

A candidate, client contact or any data subject can ask for a copy of the personal data you hold on them. RecSphere makes this a one-action export.

  1. Open the data subject's record (candidate or client contact).
  2. Open the Actions menu and choose Export personal data.
  3. Choose the format (CSV bundle or PDF report).
  4. Download the file. You can also email it directly to the subject from the same dialog.

The export includes every field on the record, attached documents, message history across channels, the audit trail of changes, and any compliance items. The export itself is logged in the audit log for accountability.

Right to erasure​

When a data subject requests erasure, you have two options in RecSphere.

  • Anonymise the record. Personal identifiers (name, email, phone, address, government IDs, bank details) are replaced with neutral placeholders. Operational history (a placement was made on this date with these hours) is retained but anonymised. Choose this when you need to keep operational records for tax or audit purposes.
  • Hard delete the record. Removes all data tied to the subject. Choose this only when no legal obligation requires retention.
  1. Open the record.
  2. Open the Actions menu and choose Erase personal data.
  3. Select Anonymise or Hard delete.
  4. Confirm. The action is irreversible.
Tax retention rules

Many jurisdictions require you to retain payroll-related personal data for several years for tax purposes. Hard-deleting a candidate with active payroll history may breach those rules. When in doubt, anonymise.

Data retention windows​

Configure how long RecSphere keeps records that are no longer active.

  1. Open Settings > Company > Data retention.
  2. Set the retention window for each record type: inactive candidates, archived vacancies, closed contracts, expired compliance documents.
  3. Save.

Records older than the configured window are flagged for review on a weekly digest. You decide whether to anonymise, hard-delete or extend retention.

Audit log for GDPR actions​

Every GDPR action (export, anonymise, delete, retention change) is recorded in the audit log with the user, the subject, the action and the timestamp. Filter the audit log by action type to produce a compliance report on demand.

Sub-processors​

RecSphere relies on several sub-processors for hosting, email delivery, payments and messaging. The current list is published at recsphere.co.uk/legal/sub-processors and updated when changes happen.

Where consent is the legal basis for processing (for example, marketing email opt-in), RecSphere stores the consent event itself: timestamp, IP address, and the form or screen that captured consent. Export consent records the same way as any other personal data.