15 MIN READ

Security & Compliance

ATS Security &
Compliance
Guide

You're storing sensitive candidate data. Here's how to protect it—and avoid costly compliance violations.

Updated Dec 2025 GDPR • CCPA • EEOC

Your ATS holds names, addresses, social security numbers, resumes, interview notes, and rejection reasons. A breach isn't just embarrassing—it can cost you millions in fines and destroy your employer brand.

Security isn't optional. Compliance isn't optional. And if you're evaluating an ATS that treats these as afterthoughts, run.

This guide covers everything you need to know: what security features matter, which compliance regulations apply, and how to evaluate whether an ATS vendor is trustworthy.

01

Essential Security Features

These are the baseline. If an ATS doesn't have these, it's not enterprise-ready.

Data Encryption

Data should be encrypted both in transit (when moving between systems) and at rest (when stored in databases).

What to Verify:

  • TLS/SSL encryption for all data in transit (HTTPS everywhere)
  • AES-256 encryption for data at rest (industry standard)
  • Encrypted backups with separate key management
  • No plain-text passwords stored anywhere

SOC 2 Type II Certification

SOC 2 is an independent audit that verifies a company's security controls. Type II means they've been tested over time (6+ months), not just on one day.

Why It Matters:

  • Third-party auditors verify security practices
  • Tests security over time, not just at one moment
  • Required by many enterprise customers
  • Shows vendor takes security seriously

Red Flag:

"We're SOC 2 compliant" without providing the actual report. Always ask for proof.

Two-Factor Authentication (2FA)

Passwords alone aren't enough. 2FA adds a second layer of protection against account takeovers.

Must Support:

  • SMS codes (basic, but better than nothing)
  • Authenticator apps (Google Authenticator, Authy)
  • Enforced for all users (not just optional)

Role-Based Access Control (RBAC)

Not everyone on your team needs to see everything. RBAC lets you control who can view, edit, or delete candidate data.

Examples:

  • Hiring Manager: Can view candidates for their department only
  • Recruiter: Can view all candidates, edit stages, send emails
  • Interviewer: Can view assigned candidates, add feedback
  • Admin: Full access including settings and exports

Audit Logs

Track who accessed what data and when. Critical for compliance and investigating potential breaches.

Should Log:

  • • User logins and failed login attempts
  • • Data exports (who downloaded candidate data?)
  • • Permission changes
  • • Candidate data edits and deletions
  • • Integration access
02

Compliance Requirements

Depending on where you hire and what industry you're in, these regulations may apply to you.

Regulation Who It Applies To Key Requirements
GDPR Any company hiring EU residents Right to access, delete, and export data; explicit consent required
CCPA Companies hiring California residents Right to know what data is collected; right to delete; opt-out of sale
EEOC US employers with 15+ employees No discrimination; keep hiring records 1 year; adverse action documentation
OFCCP Federal contractors ($50k+ contracts) Affirmative action; adverse impact analysis; 2-year record retention
HIPAA Healthcare industry hiring Protected health info security; limited access; breach notification

Deep Dive: GDPR Compliance

If you hire anyone in the EU—even remote workers—GDPR applies. Non-compliance can cost up to 4% of global revenue.

Your ATS Must Support:

  • ✓ Data export on request
  • ✓ Complete data deletion
  • ✓ Explicit consent tracking
  • ✓ Processing purpose logs

You Must Provide:

  • → Privacy policy on careers page
  • → Consent checkbox on applications
  • → Data retention policy
  • → Process to handle requests

Deep Dive: EEOC Compliance

The Equal Employment Opportunity Commission requires you to keep hiring records and avoid discriminatory practices.

Record Retention Requirements:

  • • Keep all applicant records for 1 year
  • • Keep hired employee records for duration + 1 year
  • • Federal contractors: 2 years minimum

Watch Out For:

  • • Resume screening keywords that could be discriminatory
  • • Interview questions about age, religion, marital status
  • • Lack of documentation for rejection reasons
  • • Adverse impact in hiring decisions
SOC 2 CERTIFIED

Security Built In, Not Bolted On

EasyApply is SOC 2 Type II certified with enterprise-grade security. GDPR and CCPA compliant out of the box.

Start Free Trial →
03

Data Retention Policies

How long should you keep candidate data? Too short and you violate EEOC. Too long and you violate GDPR.

Recommended Retention Schedule

Active Candidates

Keep until rejected, withdrawn, or hired

Rejected Candidates (US)

1 year from rejection (EEOC requirement)

Rejected Candidates (EU)

6 months unless candidate consents to longer

Hired Employees

Duration of employment + 1 year (EEOC) or up to 7 years (some states)

Talent Pool / Pipeline

Explicit opt-in required; honor unsubscribe immediately

ATS Must-Have:

Automated data retention policies that delete candidate data after your specified period. Manual deletion doesn't scale and creates compliance risk.

Ask your ATS vendor: "Can you automatically delete candidate data after 1 year per EEOC requirements?"

04

Evaluating ATS Security

Don't just take a vendor's word for it. Here's how to verify their security claims.

Questions to Ask in Sales Demos:

Q1: "Can I see your SOC 2 Type II report?"
Q2: "Where is candidate data physically stored?"
Q3: "How do you handle GDPR data deletion requests?"
Q4: "What's your breach notification policy?"
Q5: "Can you enforce 2FA for all users, not just admins?"
Q6: "Do you have role-based access control?"
Q7: "Can I export all data in a machine-readable format?"
05

Security Red Flags

Run—don't walk—if you encounter any of these:

  • 🚩
    "We take security seriously" without providing proof (SOC 2, penetration test results, etc.)
  • 🚩
    No 2FA option or 2FA only for admins
  • 🚩
    "GDPR compliant" but can't explain how they handle deletion requests
  • 🚩
    Unclear data ownership in terms of service
  • 🚩
    No data export or export costs extra
  • 🚩
    Vague answers about where data is stored
  • 🚩
    No audit logs or logs only retained for 30 days
$4.45M

Average cost of a data breach in 2023

Source: IBM

20M€

Maximum GDPR fine (or 4% global revenue)

Whichever is higher

277 days

Average time to identify and contain a breach

Source: IBM

Enterprise Security, Startup Simplicity

EasyApply is SOC 2 Type II certified with GDPR and CCPA compliance built in. Bank-level encryption, 2FA, role-based access—all standard.

No credit card required. SOC 2 report available on request.

Related Articles