Draft a Candidate Data Privacy Notice
When to use it
Explain to candidates what you do with their data, in language a person can read, before someone asks you to prove you did.
The prompt
Draft a candidate-facing privacy notice for {{Company Name}}'s hiring process. WHERE WE HIRE: {{countries or regions}} WHAT WE COLLECT: {{applications, CVs, sourced profiles, interview notes, assessment results, references, right-to-work documents, background checks}} WHERE IT GOES: {{ATS, sourcing tools, assessment platforms, any AI tooling — name them, and say where they store data}} HOW LONG WE KEEP IT: {{current policy, or "we need to decide"}} DO WE ADD SOURCED CANDIDATES WHO NEVER APPLIED: {{yes / no}} DO WE KEEP UNSUCCESSFUL CANDIDATES FOR FUTURE ROLES: {{yes / no}} Write it so a candidate can actually read it: short sections, plain sentences, no defined-term thickets. Cover what we collect, where it comes from, why, who inside and outside the company sees it, how long we keep it, and how someone exercises their rights — including how to ask for deletion and roughly how long that takes. Then, separately from the notice: 1. The questions in my inputs I couldn't answer properly, which need a policy decision before this can be published. 2. Where our practice as described looks like it may already be a problem, so I can raise it. 3. Which parts vary by jurisdiction and need a local review. This is a starting point for legal review, not legal advice — say so.
Tip
The sourced-candidate answer is where most companies quietly have a problem. Adding someone to an ATS because you found their profile is the practice least likely to match what your published notice says.
How to use it
Paste the prompt into ChatGPT, Claude or whichever assistant you use, then replace every {{bracketed}} part with your own detail. The more specific and messier your input, the better the output — a model given raw notes has more to work with than one given a tidy summary you wrote first.
More Compliance prompts
Open the full tool for all 87 prompts, the glossary, and the JD decoder.