GDPR & data export
Export candidate data for access requests, audits, migration, or approved analysis.
Use the organization data export to collect candidate profiles, assessment results, and analytics snapshots for an approved access request, audit, backup, migration, or analysis.
Exports may contain sensitive personal information. Downloading data does not by itself complete a GDPR or other data subject request, and InsightHire does not determine your legal response obligations.
Before you begin
- Confirm that you are an Org Admin authorized to export candidate data.
- Define the purpose, scope, date range, and format you need.
- For a legal or data subject request, confirm the person's identity and the response process under your organization's policy.
- Choose an encrypted, access-controlled location for the downloaded files.
- Decide when the working copy will be deleted.
This optional tool may not be enabled for every organization.
Export organization data
- Open the data export area in InsightHire.
- Choose the available candidate, assessment, or analytics data.
- Select CSV for spreadsheet use or JSON for an approved data or migration workflow.
- Apply the narrowest available scope that meets the request.
- Start the export.
- Download the file to the approved secure location.
- Open and inspect the file before sharing it.
CSV is a spreadsheet-compatible format. JSON is a structured data format usually used by technical teams. Ask your privacy or data team which format is appropriate.
Handle a request for one candidate
The export is organization-wide or broadly scoped. For a request concerning one person:
- Use an available filter if it produces the required scope.
- Check all identifiers carefully before sharing the result.
- Remove unrelated people's information from the response copy.
- If your policy requires a certified or fully scoped extract, contact InsightHire support.
- Record what was provided and when under your request-handling process.
External reporting access
Some organizations can create read-only keys for approved reporting tools. If this option is available:
- Create a separate key for each tool or purpose.
- Give it only to the authorized owner.
- Store it in an approved secrets manager.
- Rotate it if exposure is suspected.
- Revoke it when the tool or purpose is retired.
See Custom reports for the supported reporting workflow.
Retention and deletion
InsightHire supports organization-initiated exports. Data deletion and retention depend on your contract, configuration, subprocessors, and legal obligations.
Coordinate deletion with privacy and legal staff before removing production data. An export can create an additional copy that must also be tracked and deleted under your policy.
Security checklist
- Restrict export access to authorized Org Admins.
- Encrypt files at rest and in transit.
- Do not place exports in public links, source control, or broadly shared drives.
- Verify recipients before sharing.
- Keep an access and disclosure record when required.
- Delete temporary copies when the approved purpose is complete.
