Privacy Boundaries: Data Sharing, Tool Selection, and Compliance
Overview
Lecture URL: https://skill.re/learn/recruiting/privacy-boundaries-data-sharing-tool-selection-and-compliance.php
TRANSCRIPT: Privacy Boundaries: Data Sharing, Tool Selection, and Compliance
Course: AI for Recruiters - Professional Credential
Module: Level 2: Hands-On Foundations
Section: Chapter 10 -- Guardrails and Supervised Use
Theme: guardrails-and-supervised-use
Lecture: 10.3
Duration: 60 min
Format: Workshop + Hands-On
Audience: Recruiters beginning to use AI tools
Prerequisites: L1 Certification
What you will learn: You'll navigate privacy concerns in AI-assisted recruiting: what candidate
data you can share, how to evaluate tool compliance, and managing privacy risks. By the end, you'll
have a framework for protecting candidate privacy while using AI.
INTRODUCTION
Candidate privacy isn't optional. It's a legal requirement and an ethical obligation. When you use
AI in recruiting, you're handling sensitive data: names, employment history, contact information,
sometimes even interview recordings.
Your responsibility: protect that data. Today, we're learning how.
WHAT CANDIDATE DATA CAN YOU SHARE WITH AI?
Different AI tools have different privacy implications. Here's what you need to know:
SENSITIVE DATA (Be careful about sharing):
- Candidate names (can identify individuals)
- Contact information (email, phone)
- Specific locations or addresses
- Family situation or personal circumstances
- Salary history
- Medical information
- Demographic information
- Interview recordings/transcripts (can include personal information)
LESS SENSITIVE DATA (Generally okay to share):
- General background ("5 years backend engineering")
- Technologies and skills (no identifiers)
- Job titles and companies
- Years of experience
- Education (without specific names or dates)
GENERAL RULE: If sharing the information could identify the candidate or expose personal details,
be careful.
EVALUATING AI TOOL COMPLIANCE
Before using an AI tool:
STEP 1: CHECK DATA HANDLING PRACTICES
Ask the vendor: Where does my data go? How long is it retained? Who can access it? Is it used to
train the model?
Red flags:
- Data is used to improve the model (means your candidate data trains their AI)
- Data is shared with third parties
- No encryption in transit
- Data is retained indefinitely
- No option to request deletion
STEP 2: CHECK COMPLIANCE CERTIFICATIONS
Look for:
- GDPR compliance (if applicable)
- SOC 2 certification
- Data processing agreements
- Privacy policy clarity
STEP 3: EVALUATE DATA MINIMIZATION
Does the tool ask for MORE data than it needs? If it asks for names, email, address when it only
needs resume content, that's bad practice.
STEP 4: ASSESS YOUR COMPANY'S POLICY
What does your company policy say about sharing candidate data? Are you compliant?
STEP 5: GET COMPLIANCE APPROVAL
For sensitive use cases, have legal or compliance review the tool before you use it at scale.
BEST PRACTICES FOR DATA MINIMIZATION
When using AI tools:
PRACTICE 1: DE-IDENTIFY WHERE POSSIBLE
team."
PRACTICE 2: USE PSEUDONYMS
"Candidate A, Candidate B" instead of names.
PRACTICE 3: LIMIT TO WHAT'S NEEDED
Don't share personal phone number if email works. Don't share full address if city works. Don't
share interview recording if transcript works.
PRACTICE 4: DOCUMENT WHAT YOU'RE SHARING
Keep a record: "For sourcing research, we share resume content only (no names or contact info)."
PRACTICE 5: HAVE A DELETION POLICY
When candidate is hired or rejected, what happens to their data in the AI tool? Plan for deletion.
ANTI-PATTERNS
ANTI-PATTERN 1: SHARING UNNECESSARY DATA
Description: Sharing candidate names, email, phone with AI tools when you don't need to.
Why it fails: Unnecessary exposure of personal information.
How to avoid: De-identify where possible. Share only what you need.
ANTI-PATTERN 2: NOT VETTING TOOLS FOR COMPLIANCE
Description: Using popular AI tools without checking privacy practices.
Why it fails: You might be exposing candidate data or violating regulations.
How to avoid: Check data handling before using at scale.
ANTI-PATTERN 3: ASSUMING PUBLIC INFORMATION IS SAFE TO SHARE
Description: Thinking LinkedIn or GitHub profiles are safe to share because they're public.
Why it fails: Sharing data via a third-party AI tool is different than candidates choosing to
share publicly. You're aggregating and processing their information.
How to avoid: Even public information should go through your privacy framework.
PRACTICE PROMPTS
Exercise 1: Audit Your Current Tool Usage
For each AI tool you use: What data are you sharing? Is it necessary? Could you de-identify?
Exercise 2: Evaluate a New Tool
You want to use a new AI tool. Check: data handling practices, compliance certifications, data
minimization approach. Would you recommend it?
Exercise 3: Create Your Data Sharing Policy
For your team: What candidate data can be shared with AI tools? When? With what tools?
Exercise 4: Test De-identification
Take a candidate profile. Rewrite it sharing only job-relevant information without identifying
details. How much information do you lose?
Exercise 5: Build Your Tool Evaluation Checklist
Create a checklist for evaluating AI tools: data handling, compliance, retention, deletion,
encryption. Use it before approving tools.
KEY TAKEAWAYS
- Be careful about sharing: names, contact info, locations, personal circumstances, medical info,
demographics, recordings.
- Evaluate tools for: data handling, compliance certifications, data retention, third-party access,
model training use.
- Practice data minimization: de-identify when possible, limit to what you need, document what
you're sharing.
- Have a data deletion policy: when candidate is hired/rejected, what happens to their data?
- Even public information (LinkedIn, GitHub) shouldn't be shared casually via third-party tools.
- Get compliance approval before using sensitive tools at scale.
GLOSSARY
Data Minimization: Sharing only the data necessary for the task, nothing more.
De-identification: Removing information that could identify a specific individual.
GDPR: General Data Protection Regulation (EU privacy law, applies broadly).
SOC 2: Security and organizational controls certification.
Data Processing Agreement: Contract specifying how vendor handles your data.
SYNTHESIS AND APPLICATION
Privacy isn't a checkbox. It's an ongoing practice. As you use AI, regularly audit: What data are
you sharing? Is it necessary? Is it protected?
This week, audit the AI tools you use. Document what data you're sharing. Identify any unnecessary
sharing and change it.
REFLECTION EXERCISE
- What's the most sensitive data you currently share with AI tools? Do you need to?
- If a candidate asked what data you shared about them, what would you say?
- What would change about your AI use if you prioritized privacy more?
CLOSING REMARKS
Candidate trust depends on protecting their privacy. Responsible privacy practices are competitive
advantages. In the next session, we're building feedback systems that continuously improve your
responsible AI practices.
AI for Recruiters Certification Program
Level 2: Hands-On Foundations | Guardrails and Supervised Use | Lecture 10.3
A SkillsClinic initiative.
Duration: ~60 minutes | Word Count: ~2,380
Skill.re