--- name: respond-to-a-hiring-process-data-breach category: get-hired description: Respond to a hiring-process data breach through candidate protection, evidence preservation, identity and vendor containment, data-scope reconstruction, notification, remediation, and verified reform. Use when applications, interviews, assessments, references, background checks, or accommodation data may be exposed. --- # respond-to-a-hiring-process-data-breach Protect candidates before protecting recruiting continuity. ## When to use - Use for unauthorized access, disclosure, loss, scraping, extortion, or misuse of candidate data. - Activate security, privacy, legal, HR, accessibility, safeguarding, vendor, communications, and identity authority. ## Preconditions - Establish independent incident command, evidence custody, candidate-support authority, trusted communications, and relevant notification deadlines. - Inventory systems, vendors, candidates, employees, data, regions, identities, integrations, and hiring decisions. ## Procedure Complete **human protection and containment**, **data and decision reconstruction**, **notification and remediation**, and **safe recovery**. 1. Open a **hiring data incident timeline** for access, data, people, systems, vendors, decisions, harms, and communications. 2. Contain exposed accounts, links, exports, credentials, vendors, integrations, and public access while preserving evidence. 3. Protect candidates from phishing, identity fraud, outing, discrimination, retaliation, stalking, and accessibility harm through safe channels. 4. Preserve logs, applications, attachments, interview notes, assessments, references, background data, accommodation records, exports, tokens, and vendor evidence. 5. Reconstruct each data subject, field, source, purpose, consent, access, download, disclosure, recipient, retention, and decision use. 6. Separate verified exposure, likely exposure, unavailable evidence, and nonexposure without using log absence as proof. 7. Assess whether compromised data affected screening, scoring, offers, rejections, accommodations, or fairness; pause unsafe decisions. 8. For every potentially tainted decision, preserve the original, freeze reversible adverse action, identify exposed reviewers, and create a clean packet containing only approved job-related evidence. 9. Require an independent conflict-checked reviewer who did not receive restricted data to apply the same documented criteria; record original and new outcomes, reasons, evidence, uncertainty, subgroup effects, restored opportunities, and appeal. 10. Meet lawful notices with specific scope, protective action, safe contact, accessibility, and updates. 9. Provide identity, application, complaint, correction, withdrawal, and support routes without requiring more unnecessary data. 10. Recover with least privilege, secure transfer, retention, vendor control, monitoring, and independent verification. ## Failure plan - If candidate safety is immediate, act protectively before full forensic certainty. - If a vendor withholds evidence, preserve contractual escalation and state the scope uncertainty. - If hiring decisions may be tainted, quarantine them for independent review. ## Worked example An applicant-tracking vendor exposes resumes, interview notes, disability accommodations, reference contacts, background-check links, salary history, and rejection scores through a stolen recruiter session and public export URL across several countries. The response protects candidates, reconstructs access and decision use, contains vendor trust, provides safe notice and correction, rechecks affected decisions, and verifies recovery. ## Done - A hiring data incident timeline verifies evidence, access, candidates, systems, vendors, decisions, harms, deadlines, and communications - A candidate, field, purpose, recipient, identity, and hiring-decision reconciliation proves exposure scope, uncertainty, fairness impact, and required action - A candidate protection and recovery report demonstrates containment, notices, safe support, clean-input independent redecision, restored opportunities, identity remediation, vendor correction, secure recovery, retention repair, monitoring, and independent closeout