ATS & Resumes14 min read

    What Happens to Your Data After You Apply for a Job: Retention Rules, Access Rights, and How to Request Your File

    Quick answer

    Your application does not disappear when you are rejected. Federal equal-employment rules require most US employers to preserve application records for at least one year, and most federal contractors for two years, including resumes and interview notes. No federal law sets a maximum, so files commonly sit in an applicant tracking system for years afterward. Whether you can see that file depends almost entirely on geography: of the twenty comprehensive state privacy laws now in effect, only California's covers job applicants, giving California residents a right to know, correct, and delete with a 45-day response deadline. Applicants to UK and EU employers can file a subject access request and are owed a response within one month. Everyone else still has narrower levers, including Illinois's 30-day deletion right for AI video interviews and New York City's advance-notice rule for certain automated screening tools.

    Key takeaways

    • US retention rules are floors, not ceilings. 29 CFR 1602.14 requires employers to keep application records for one year, and 41 CFR 60-1.12 requires most federal contractors to keep them for two, explicitly including resumes, interview notes, and internal resume databases. Nothing in federal law requires anyone to delete them afterward.
    • Only California gives job applicants real access rights. The CCPA's carve-out for HR and applicant data expired at the end of 2022, and every other state's comprehensive privacy law still exempts it. Your rights are decided by where you live, not by where you applied.
    • The first enforcement action to name applicant data landed in September 2025, when California's privacy regulator fined Tractor Supply $1.35 million. Part of the finding was that its job applicant privacy notice described what the company collected but never told applicants they had rights.
    • The file is bigger than your resume. Alongside the document you uploaded sit parsed field values, screening-question answers, source tags, interview scorecards, free-text recruiter notes, and a disposition code recording why you were rejected.
    • Your file's security is the vendor's problem, not yours. One recruiting software firm left roughly 26 million CV files in a publicly readable cloud container, complete with home addresses and full employment histories.

    Most job seekers can describe the first sixty seconds after they hit submit with reasonable accuracy. The file gets parsed, fields get mapped, keywords get matched, a score or a rank appears somewhere. I have written a fair amount about that part, because it is the part you can influence. What almost nobody can describe is the next five years.

    That gap bothered me enough to go looking, so I spent a few weeks reading the actual rules: the federal recordkeeping regulations that decide how long your application has to be preserved, the state privacy statutes that decide whether you are allowed to look at it, and the enforcement actions that have started to test both. What I found is a system with a strange asymmetry at its center. There are detailed, enforceable rules requiring employers to keep your data. There are almost no rules requiring them to delete it, and in 49 states there is no general mechanism for you to ask what is in it.

    1 year
    minimum an employer must preserve your application after rejecting you, under federal EEO rules
    2 years
    minimum for most federal contractors, covering resumes and interview notes
    1 of 20
    state privacy laws in effect that give job applicants access rights (California)
    26M
    CV files exposed by one misconfigured cloud container at a single recruiting software vendor

    Rejection is a status change, not a deletion

    The instinct that a rejection closes the loop is understandable and completely wrong. In an applicant tracking system, rejecting you is a status change on a record that continues to exist, and in the United States it usually has to. Under 29 CFR 1602.14, the recordkeeping rule that sits under Title VII and the ADA, employers must preserve personnel and employment records, application forms explicitly included, for one year from the date the record was made or the personnel action occurred, whichever is later. If someone files a discrimination charge, the clock stops entirely: relevant records must be kept until the charge reaches final disposition.

    Federal contractors are held to a longer standard. 41 CFR 60-1.12 sets two years as the general retention period, dropping to one year only for smaller contractors (fewer than 150 employees, or a contract worth less than $150,000). The list of what counts is unusually specific, and worth reading closely if you have ever assumed your resume is the only artifact: applications, resumes, interview notes, compensation data, and, in the regulation's own language, expressions of interest through the internet or related electronic data technologies, including online resumes and internal resume databases. Where possible, the contractor is also required to record the gender, race, and ethnicity attached to each of those records.

    The asymmetry that runs through all of this

    Every number in the paragraphs above is a minimum. US federal law tells employers how long they must keep your application. It does not tell them when they have to get rid of it. A retention policy that says 'indefinitely' violates nothing, which is why the practical answer to 'how long do they keep it' is usually 'until somebody decides to run a cleanup job,' and cleanup jobs are nobody's priority.

    What is actually in the file

    When people picture their candidate record they picture the PDF they uploaded. The PDF is the smallest part of it. The record that a recruiter opens is a composite, and most of its fields were written about you rather than by you.

    • The parsed version of your resume: your work history broken into structured fields, which is what actually gets searched and scored. This is where a two-column layout or a job title inside a header quietly becomes a wrong value in a database.
    • Your answers to the screening questions, stored as discrete values rather than prose. Work authorization, salary expectation, years of experience, willingness to relocate, notice period.
    • A source tag recording how you arrived: job board, referral, career site, agency, sourced by a recruiter. This one has a long memory and can affect agency fees years later.
    • Interview scorecards and structured feedback, one per interviewer, usually on a fixed scale with a free-text box underneath.
    • Free-text recruiter and hiring manager notes, which are written for an internal audience and read very differently when quoted back.
    • A disposition or rejection reason code: the dropdown someone selected when they closed you out. Not a paragraph, a category, and a category is what gets counted and reported later.
    • Assessment results, coding-test output, and, in some processes, recorded video interviews and whatever a vendor's model scored them at.
    • Equal employment opportunity self-identification data, which is normally stored separately from the hiring record and shielded from decision-makers, precisely so it can be reported without being used.

    Two of these deserve more attention than they get. The disposition code is the field that turns a hiring process into statistics, and it is also the field a regulator or a plaintiff's lawyer would look at first, because a pattern in dropdown selections is far easier to analyze than a pattern in prose. The free-text note is the opposite: it is the least structured thing in the file and the most revealing. If you have ever wondered how much of a hiring decision is legible after the fact, the honest answer is that it depends entirely on how disciplined that particular recruiting team was about writing things down.

    California is the exception, and it is a big one

    Here is the part that surprises nearly everyone I explain it to. Almost every US state privacy law that has passed in the last five years exempts employment data. Employees, job applicants, contractors, and the people connected to them are carved out of the definition of a protected consumer. Twenty comprehensive state privacy laws were in effect as of early 2026, with Indiana, Kentucky, and Rhode Island joining on January 1, and with the single exception of California, they all exclude data about you in your capacity as a job applicant.

    California is the exception because its exemption was written with an expiry date and the legislature let it lapse. The CCPA originally carved out HR and applicant data on a temporary basis. That carve-out expired on December 31, 2022, and since January 1, 2023 a California resident who applies for a job has held the same core rights as a retail customer: the right to know what was collected and from where, the right to a copy, the right to correct inaccurate information, the right to request deletion, and the right to opt out of sale or sharing.

    The mechanics are the useful part. A business has 45 days to respond to a verifiable request, and may take one further 45-day extension only if it tells you inside the first window and explains why. Verifying your identity does not pause that clock. The default disclosure covers the preceding 12 months, but you can ask for more: a business must go back further on request, as far as January 1, 2022, for anything collected on or after that date. For an applicant, that difference matters, because the interesting material is rarely from the last twelve months.

    The enforcement action that turned this from theory into practice

    For the first few years after the exemption lapsed, applicant rights in California were real on paper and largely untested. That changed on September 30, 2025, when the California Privacy Protection Agency announced a $1.35 million settlement with Tractor Supply Company, the largest penalty the agency had issued at that point and, more importantly here, the first enforcement action to address workforce disclosures.

    The specific finding on the applicant side is worth quoting in substance, because it is so mundane. The company had a California section in its job applicant notice. That section described what data it processed. It never told applicants that they had rights under the CCPA. The rest of the order covered failures most people associate with consumer websites rather than careers pages: no effective opt-out mechanism for the selling and sharing of personal information, and disclosures to service providers, contractors, and third parties without the contractual privacy terms the statute requires. The agency also enforced a subpoena during the investigation, which is a signal about how it intends to work rather than a detail about this company.

    Why a notice failure is the most useful possible finding

    A regulator's first workforce case being about a missing rights disclosure tells you something about the state of the field: the problem is not that employers are refusing applicant requests, it is that most applicants have never been told a request is possible. The gap is awareness, on both sides of the table. That also means the request you send may be the first one a given recruiting team has ever received, so expect a slow, confused, but usually good-faith response rather than a wall.

    What you can ask for, and where

    Your leverage is a function of three things: where you live, where the employer operates, and what technology it used on you. Those are separate questions and they stack. A California resident who did an AI-scored video interview with a company that also hires in the UK has three different levers, and they are governed by three different laws with three different deadlines.

    Where applicant data rights currently exist, and what each one actually gets you
    JurisdictionWhat you can ask forResponse window
    California (CCPA/CPRA)Full access, correction, and deletion rights for job applicants, plus the categories, sources, purposes, and third-party recipients45 days, one 45-day extension permitted with notice
    Other US states with privacy lawsGenerally nothing: applicant and employee data is expressly exemptedNot applicable
    UK and EU (GDPR)A subject access request covering all personal data held about you, interview notes includedOne month, extendable by two more for complex requests
    Illinois (AI Video Interview Act)Deletion of an AI-analyzed video interview, including copies held by vendors and backups30 days from your request
    New York City (Local Law 144)Advance notice that an automated employment decision tool will be used, plus a published bias audit summaryNotice is owed before use, not on request
    Colorado (from January 1, 2027)Post-decision explanation of the role automated tooling played, correction of inaccurate data, and human reconsideration30 days after an adverse decision

    Two rows there deserve a footnote. Illinois's Artificial Intelligence Video Interview Act obliges an employer, within 30 days of your request, to delete your video interview and to instruct everyone else who received a copy to do the same, backups included. It applies whether or not you were hired, and it is one of the few US rights in this space that produces a concrete, verifiable outcome rather than a document.

    Colorado's row is dated because the rules moved. The Colorado AI Act was set to take effect on June 30, 2026, and then Governor Polis signed SB 189 on May 14, 2026, rewriting it and pushing the effective date to January 1, 2027. The rewritten version substantially reduced what employers have to do, but it kept the parts that matter to an applicant: clear notice that automated decision-making technology was used, a plain-language description within 30 days of an adverse decision explaining the role that technology played, a right to request correction of inaccurate personal data, and a right to ask for meaningful human review. It also requires deployers to retain records for not less than three years after a consequential decision, which is a useful reminder that new applicant rights and longer retention periods tend to arrive in the same bill.

    If you applied to a UK or EU employer, you have the strongest rights of anyone

    A subject access request under the GDPR is not limited to a copy of your resume. It covers personal data held about you, and UK guidance is explicit that this includes interview notes: a candidate asking for their interview notes is making a valid, if narrow, request. The response window is one calendar month from receipt, counted from the day the request arrives even if that is not a working day, and it can be extended by up to two further months only where the request is genuinely complex.

    There is a second, less obvious use for this. The UK regulator's recruitment and selection guidance tells employers that, absent a clear business reason, they should not keep recruitment records for unsuccessful applicants beyond the statutory period in which a claim arising from that process could be brought, which is six months under the Equality Act. Compare that with the American position, where the same six-month mark is barely halfway through a mandatory retention floor, and you get a clean picture of two systems built on opposite defaults: one treats retention as an exposure to be minimized, the other treats it as evidence to be preserved.

    Why this is worth ten minutes of your attention

    There is a version of this article that is purely about risk, and it would not be wrong. In 2025, researchers found that the applicant tracking software maker TalentHook had left a misconfigured Azure Blob storage container open to anyone who knew its address, exposing close to 26 million CV files. The exposed fields were the ones you would least want in a phishing kit: full names, home addresses, email addresses, phone numbers, education, and complete employment histories. Not one of those 26 million people chose that vendor, and almost none of them knew it held their file. That is the structural point. You choose the employer. The employer chooses the system, and the system chooses its cloud configuration.

    But the same persistence that creates the risk also creates an opportunity, and it is the reason I do not think the right response is to demand deletion everywhere. Recruiting vendors selling talent-rediscovery products claim that roughly 44% of strong hires are already sitting in a company's own applicant tracking system and that around 75% of the candidates in those databases are never contacted again after their first application. Treat vendor figures as marketing arithmetic rather than research, because they are, but the underlying mechanic is real and easy to verify from the recruiter's side: rediscovery search is a standard feature of every major ATS, and a past applicant is cheaper to reach than a cold prospect. Your two-year-old rejected application is a lottery ticket someone else is holding.

    That reframes the practical question. It is not 'how do I get deleted.' It is 'what does the version of me stored in there actually say, and is it accurate?' If a parsing error dropped your most relevant job, or a screening answer recorded a salary expectation you gave three years and two promotions ago, that is the record a rediscovery search will run against.

    How to send the request

    The process is duller than it sounds and takes about ten minutes. The most common reason a request fails is that it goes to a recruiter's personal inbox instead of the address a company has designated for privacy requests.

    1. 1Find the right destination. Look for a privacy policy link in the footer of the company's careers site, or a 'California applicant privacy notice' or 'candidate privacy notice' page, which will usually name a dedicated email address or web form. A generic 'contact us' form is a last resort, not a first choice.
    2. 2Say which law you are invoking. 'I am a California resident submitting a request to know under the CCPA' or 'This is a subject access request under Article 15 of the UK GDPR' is what routes your message to the person who handles them, and it starts the statutory clock.
    3. 3Be specific about the categories you want, not just 'everything.' Ask for the personal information collected, its sources, the business purpose, the categories of third parties it was disclosed to, and, where the law allows it, a copy of the specific pieces. Naming interview notes, assessment results, and screening-question answers explicitly makes them harder to overlook.
    4. 4Ask for the extended period if you are in California. State that you are requesting information collected beyond the preceding 12 months, back to January 1, 2022. If you do not ask, you will get twelve months.
    5. 5Give them what they need to verify you. Include the email address and phone number you applied with, the approximate dates, and the roles or requisition numbers if you have them. Verification does not extend their deadline, but a request they cannot match to a record will simply fail.
    6. 6Note the date you sent it and diarize the deadline: 45 days for California, one month for the UK and EU, 30 days for an Illinois video deletion. A polite reminder on the day it expires resolves most of the delays that happen.

    One sentence worth adding at the end

    'If any of the information you hold about me is inaccurate, please treat this as a request to correct it under the same law.' In California, correction is a separate right from access, and asking for both in one message saves you a second 45-day cycle. It also quietly signals that you know the difference, which tends to improve the quality of the response.

    What to do with whatever comes back

    Set your expectations for the format first. You are unlikely to receive a beautifully collated dossier. Most responses are a spreadsheet export, a set of category descriptions, and, if you are lucky, the free-text fields. Read it for three things.

    1. 1Parsing accuracy. Compare the structured version of your history against what you actually submitted. Missing employers, merged roles, mangled dates, and a job title that landed in the wrong field are all common, all correctable, and all invisible from the outside. This is the single most actionable thing in the response.
    2. 2Stale answers. Salary expectations, notice periods, and location preferences are captured once and rarely revisited. If your file says something that stopped being true two promotions ago, correct it in writing.
    3. 3Anything you cannot account for. A source tag naming an agency you never spoke to, a duplicate profile under an old email address, or an application you have no memory of submitting are all worth a follow-up question. Duplicate profiles in particular are a quiet cause of confusion, because a recruiter searching the database may open the wrong one.

    What you should not expect is an explanation of why you were rejected. No US access right currently obliges an employer to give you one, and outside Colorado's rules from 2027 no forthcoming one does either. If you want the honest version of why applications go quiet, the mechanics are covered in why you never heard back after a great interview and, for the postings that were never real to begin with, in how to spot a ghost job posting.

    The upstream fix

    Everything above is downstream work, and downstream work has a low ceiling. You can correct a record after the fact, but you cannot un-store the version a recruiter read in the eleven seconds that mattered. The higher-leverage move is to control what enters the system in the first place, because the stored copy is a parsed copy: whatever the parser gets wrong becomes the durable truth about you inside that company for at least a year, and quite possibly for a decade.

    In practice that means the boring formatting discipline I keep writing about, for a reason that goes beyond this week's application. Single-column layout, real headings rather than styled text, contact details in the body rather than the header, dates in a consistent format, and the claims that matter attached to evidence rather than adjectives. If you want the full version, how an ATS actually works covers the parsing mechanics and the ATS-friendly resume format checklist covers the layout rules. It is also the whole design premise of Resume Leap, which scores the parsed version of your resume rather than the pretty one, on the theory that the parsed version is the one that persists.

    The broader legal picture is moving in one direction, slowly. The Tractor Supply order established that applicant disclosures are now enforceable rather than aspirational, the Workday litigation is testing whether a screening vendor can be liable for outcomes directly (we covered that case in detail here), and Colorado's 2027 rules will be the first US law to require an explanation of an automated hiring decision after the fact. None of that helps you this quarter. Knowing what is in your file, and that you are allowed to ask, does.

    Key takeaway

    Applying for a job creates a durable record that federal rules require an employer to keep for at least a year, that no federal rule requires anyone to delete, and that contains substantially more about you than the document you uploaded. If you live in California, or you applied to a UK or EU employer, you can ask for a copy and get one on a statutory deadline. If you did an AI-scored video interview in Illinois, you can have it deleted within 30 days. Everyone else is operating without a window, which makes the upstream fix (a resume that parses cleanly, and screening answers you would still stand behind in three years) the part actually worth your time.

    Frequently asked questions

    DC

    About the author

    Daniel Cho

    ATS & Data Analyst · B.S. Computer Science · Resume-parsing background

    Daniel studies how Applicant Tracking Systems parse and score resumes. With a computer science background and years working with resume-parsing data, he breaks down the mechanics — keyword weighting, parsing failures, and match scoring — into plain-English guidance you can act on. His goal is to demystify the 'black box' so candidates stop guessing and start optimizing.

    More from Daniel

    Put this into practice

    Resume Leap tailors your résumé to any job, scores it against the ATS, and exports a clean PDF — automatically.

    Try it free

    Keep reading