Workforce Data Checklist: System Inventory and Classification, Automated Decision Screening, Bias Audit Records, Vendor and Subprocessor Terms, and Employee Rights Handling
By Casey Scott McKay ·
This checklist audits an organisation's workforce data estate in the order the work has to happen, beginning with the inventory because every later determination depends on it and almost no organisation has one. It then screens each system against four triggers, classifies scoring tools against the automated decision rules with recorded reasoning, tests the bias audit file for independence and population, and walks the consumer reporting sequence that cannot be reconstructed after a decision. Later phases cover biometric releases and published retention schedules, the vendor and subprocessor terms where most exposure originates, monitoring purpose discipline, employee rights requests with third-party interests, and the procurement intake gate that prevents recurrence. Gate items mark where deployment should stop.
IP and Technology > Privacy Data Security | Checklist | Published 8 July 2024 - Updated 18 December 2025 | Casey Scott McKay - marksy.us
Summary. This checklist audits a workforce data estate in the order the work must happen: the inventory first, because everything depends on it and almost nobody has one. It screens systems against four triggers, classifies scoring tools with recorded reasoning, tests the bias audit file for independence and population, and walks the consumer reporting sequence that cannot be rebuilt after the fact. Later phases cover biometric releases and published schedules, the vendor terms where exposure originates, monitoring purpose discipline, rights requests with third-party interests, and the procurement gate that prevents recurrence. Gate items mark where deployment stops.
Keywords: workforce data inventory · system classification · automated decision screening · bias audit file · consumer reporting analysis · adverse action evidence · biometric release · retention schedule · monitoring purpose review · vendor terms · subprocessor register · employee rights requests · litigation hold · procurement intake gate · third-party interests
How to use this checklist
| Phase | What it produces | Who runs it | Gate | |---|---|---|---| | 1. Inventory | A system register with named owners | Counsel and HR ops | Finance records reconciled | | 2. Triggers | Four flags per system | Counsel | Every system flagged | | 3. Classification | A reasoned memorandum per scoring tool | Counsel | Workflow described, not asserted | | 4. Audit | An audit file | Counsel and an independent auditor | Independence and population confirmed | | 5. Screening | A timestamped workflow | Counsel and HR ops | Standalone disclosure verified | | 6. Biometrics | Release, published policy, schedule | Counsel and facilities | Nothing deploys without all three | | 7. Vendors | Negotiated terms and a register | Counsel and procurement | Cap carve-outs obtained | | 8. Monitoring | A purpose register | Counsel and security | Repurposing reviewed | | 9. Rights | A runbook | Counsel | Third-party rules decided in advance | | 10. Retention | An implemented schedule | Counsel and IT | Hold check wired in | | 11. Intake | A gate and a named reviewer | Counsel | Installed before remediation completes |
The matter. A four-thousand-person employer across several jurisdictions, with an applicant tracking system that has never deleted anything, a screening vendor and three unclassified sourcing tools, a video interview product bought during a hiring surge, fingerprint time clocks at eleven sites, a security telemetry feed that has become a management dashboard, and no register of any of it.
Phase 1. Build the inventory
-
[ ] Interview rather than survey, because a questionnaire returns the systems with owners and the problems live in the systems without.
-
[ ] Interview recruiting, HR operations, benefits, security, facilities, and IT, separately, about workflow rather than about tools.
-
[ ] Pull the vendor payment records from finance, which is the most complete list of software in the organisation that exists anywhere.
-
[ ] Include browser extensions, free tiers, and trials, which are procured without contracts and process real data.
-
[ ] Record per system: name, owner, purchaser, data held, data subjects, retention, contractual basis, hosting location, and subprocessors.
-
[ ] Record former employees and unsuccessful applicants as data subject categories, since both are frequently forgotten and both have rights where the exemption has lapsed.
-
[ ] Name an owner for every row, and escalate the rows where nobody will accept ownership, since those are the highest-risk systems in the estate.
-
[ ] Expect two to four times as many systems as predicted, and budget four to eight weeks.
-
[ ] [Gate] No policy is drafted before the register exists.
Phase 2. Apply the four triggers
-
[ ] Does it score or rank people? This routes to Phase 3 and potentially to Phase 4.
-
[ ] Does it draw on third-party data about people? This routes to Phase 5.
-
[ ] Does it capture a physiological characteristic? This routes to Phase 6.
-
[ ] Does it record a communication? This routes to Phase 8.
-
[ ] Flag every system against all four, including the ones that appear administrative, since scheduling tools have contained assessment modules and security agents have produced activity scores.
-
[ ] Record a no as deliberately as a yes, with the basis, since an unexamined no is the most common defect found later.
-
[ ] [Gate] Every register row carries four answers.
Phase 3. Classify the scoring tools
-
[ ] Ask whether the output affects who advances, and test the answer against how the recruiter actually works rather than against the policy.
-
[ ] Ask what human review consists of, since a human reviewing the top ten of two hundred has not exercised judgment about the other one hundred and ninety.
-
[ ] Distinguish scoring from knockout criteria, since a lawful licence requirement filter is a different instrument from a fit model.
-
[ ] Describe the workflow in the memorandum, because a conclusion without a workflow is an assertion.
-
[ ] Date it and name the person who confirmed it, since the position will be tested and contemporaneity matters.
-
[ ] Run the second analysis regardless, since disparate impact under 42 U.S.C. § 2000e-2 and Griggs v. Duke Power Co. does not require a technology statute to exist.
-
[ ] Check for hidden medical inquiry under 42 U.S.C. § 12112, since assessments sometimes measure characteristics correlated with disability.
-
[ ] Check for genetic information exposure under 42 U.S.C. § 2000ff where family history is anywhere in the intake.
-
[ ] Re-run the classification when the vendor changes the product, since the version deployed at review is not the version deployed a year later.
-
[ ] [Gate] No scoring tool operates without a dated, reasoned classification.
Phase 4. Test the audit file
-
[ ] Confirm independence. The auditor is not the vendor, did not build the tool, and has no contingent interest in the result.
-
[ ] Confirm the population. The audit ran on your applicants, not on the vendor's aggregate, because two employers using the same tool on different pools get different ratios.
-
[ ] Confirm the data completeness disclosure, stating how many applicants had demographic data, in which categories, and what was assumed about the rest.
-
[ ] Confirm intersectional analysis where the formulation requires category combinations, since single-axis ratios will not satisfy it.
-
[ ] Confirm the selection rate and impact ratio methodology against the validation vocabulary in 29 CFR 1607 and the treatment of scored and subjective criteria in Watson v. Fort Worth Bank & Trust.
-
[ ] Confirm the validation position where the tool is defended on job relatedness, per Albemarle Paper Co. v. Moody.
-
[ ] Confirm the remediation position was agreed before results were known, since discarding results afterwards carries its own exposure under Ricci v. DeStefano.
-
[ ] Confirm the notice to candidates was given before use and states the qualifications assessed.
-
[ ] Confirm the published summary is accurate and consistent with external statements, since inconsistency between a published audit and a careers-page claim engages 15 U.S.C. § 45.
-
[ ] Diary the re-audit, since the requirement is periodic and the tool changes.
-
[ ] [Gate] No covered tool operates on a vendor-supplied audit.
Phase 5. Walk the screening sequence
-
[ ] Run the definitional analysis under 15 U.S.C. § 1681a against every vendor whose output influences a decision, not only the one labelled "background check."
-
[ ] Include the sourcing tool, the social media screening product, the identity service, and the insights platform, since a vendor's self-description is not the test.
-
[ ] Verify the disclosure is standalone under 15 U.S.C. § 1681b, consisting solely of the disclosure, in the document the candidate actually signs.
-
[ ] Verify written authorisation on the same document and nothing else.
-
[ ] Verify certification of permissible purpose to the agency.
-
[ ] Verify the pre-adverse-action notice with the report and the summary of rights, sent before the decision, with a reasonable dispute period.
-
[ ] Verify the adverse action notice after that period, identifying the agency and stating it did not make the decision, per 15 U.S.C. § 1681m.
-
[ ] Verify accuracy expectations on the agency under 15 U.S.C. § 1681e are reflected in the vendor contract.
-
[ ] Instrument the workflow with system timestamps, since the wilfulness inquiry under 15 U.S.C. § 1681n turns on whether a process existed and recollection is not evidence of one.
-
[ ] Note the standing position under Spokeo v. Robins and TransUnion LLC v. Ramirez, which determines the forum rather than the merits.
-
[ ] Check local timing and inquiry restrictions, since criminal history and salary history rules vary by state and municipality and are configured in the applicant tracking system rather than in a policy.
-
[ ] [Gate] No decision is taken before the pre-adverse-action period has run.
Phase 6. Close out biometric collection
-
[ ] Obtain the vendor's technical documentation, not the datasheet, and determine what is actually stored.
-
[ ] Draft a standalone written release, specific to the biometric collection, separate from the onboarding packet.
-
[ ] Re-paper existing employees, which is a mail merge and a reminder rather than a project, and which removes the most common defect.
-
[ ] Publish a retention and destruction policy, publicly available, with a schedule.
-
[ ] Implement the schedule, since a published policy that is not followed proves knowledge.
-
[ ] Tie destruction to end of employment plus a short defined period.
-
[ ] Contract for vendor deletion and certification, prohibit vendor use for its own purposes, and prohibit disclosure.
-
[ ] Negotiate the liability cap specifically for this product, since per-violation statutory damages across a workforce are not addressed by a cap at fees paid.
-
[ ] Cover the adjacent products: voice authentication, facial access control, and analysed video interviews.
-
[ ] Handle video interview obligations separately: notice that analysis may be used, an explanation of characteristics evaluated, consent, sharing limits, and destruction on request.
-
[ ] [Gate] Nothing that touches a body deploys without release, published policy, and implemented schedule.
Phase 7. Fix the vendor terms
-
[ ] Obtain uncapped or super-capped liability for confidentiality breach, data protection breach, and statutory violations arising from the vendor's processing.
-
[ ] Remove or scope the product improvement licence, and record the answer to the unwind question, which is usually that a trained model cannot be untrained.
-
[ ] Define and limit derived and aggregate data, and prohibit benchmark products that re-identify the organisation or its people.
-
[ ] Obtain a named subprocessor list at signature, notice with a right to object, and specific flow-down obligations rather than "equivalent terms."
-
[ ] Obtain deletion on termination with a period, a certification, an honest backup carve-out with an expiry, and express coverage of derived data.
-
[ ] Obtain assistance obligations for rights requests, regulatory inquiries, litigation holds, and the audit commissioned in Phase 4.
-
[ ] Obtain security commitments with a defined standard and a breach notification period you can meet downstream.
-
[ ] Obtain express status representations where the product creates a regulatory status, rather than a general compliance clause.
-
[ ] Record the negotiated position once and reuse it, since the estate is thirty products and the same six clauses matter in all of them.
-
[ ] Maintain a vendor register with terms, subprocessors, deletion mechanism, cap, and exit plan.
-
[ ] [Gate] If only two positions can be won, take the cap carve-outs and the training rights.
Phase 8. Impose monitoring purpose discipline
-
[ ] List every collection point: endpoint telemetry, network and VPN logs, badge data, message metadata, call and meeting recording, screen capture, and location.
-
[ ] State a specific purpose for each, since "security" is a category and "detecting exfiltration of customer data" is a purpose.
-
[ ] Match the notice to the collection, in a document employees actually receive, and reissue it when the collection changes.
-
[ ] Design the recording consent architecture for all-party consent jurisdictions, since 18 U.S.C. § 2511 and its state analogues are not satisfied by a policy statement alone.
-
[ ] Separate work accounts from personal accounts on work devices, since access engages 18 U.S.C. § 2701 and 18 U.S.C. § 2702 differently.
-
[ ] Review policy language against 29 U.S.C. § 157 before restricting discussion of terms and conditions of employment.
-
[ ] Treat any repurposing as a new collection, requiring the same review, notice, and — where it will influence employment decisions — the Phase 3 classification.
-
[ ] Stop management dashboards built on unvalidated security metrics, since a metric influencing decisions is a selection procedure.
-
[ ] Cut retention, since the data accumulates by default and is discoverable under FRCP 26.
-
[ ] Note the narrowed federal position on exceeding authorised access in Van Buren v. United States when drafting acceptable use terms and planning responses to misuse.
-
[ ] Run an annual purpose review, comparing disclosed purpose against actual use.
-
[ ] [Gate] No security feed becomes a management metric without review.
Phase 9. Build the rights request runbook
-
[ ] Map the systems to be searched, filtered from the Phase 1 register.
-
[ ] Adopt a defensible unstructured search methodology for mailboxes, drives, and chat, rather than an exhaustive one.
-
[ ] Decide third-party interest rules in advance for references, complainant statements, and witness accounts.
-
[ ] Decide the manager notes position consistently rather than per request.
-
[ ] Prepare deletion refusal bases: employment, tax, benefits, verification under 8 U.S.C. § 1324a, and litigation holds.
-
[ ] Wire in the hold check, since preservation under FRCP 37 overrides both deletion schedules and deletion requests.
-
[ ] Check the health data position where a wellness arrangement is covered by 45 CFR 164, and confirm segregation.
-
[ ] Build verification steps that do not themselves collect more data than the request.
-
[ ] Set internal deadlines shorter than statutory ones, since unstructured search takes longer than estimated.
-
[ ] Expect the first request from someone already in dispute, and design accordingly.
-
[ ] [Gate] No request is answered before the third-party rules are written down.
Phase 10. Set and automate retention
-
[ ] Applications and interview notes. Set a period; this is the largest and least justified retention in the estate.
-
[ ] Employment records. Driven by employment, tax, benefits, and verification obligations, which are long rather than infinite.
-
[ ] Screening reports. Short, since utility ends with the decision and sensitivity does not.
-
[ ] Biometric templates. Per the published schedule.
-
[ ] Monitoring data. Short by default, extended only for identified investigations.
-
[ ] Wellness and health data. Segregated, restricted, short, with the covered-arrangement analysis recorded.
-
[ ] Analytics outputs and benchmark datasets. Access-controlled, which serves both the trade secret position under 18 U.S.C. § 1839 and the privacy position.
-
[ ] Automate it, since a schedule that depends on a person remembering will be found not to have been implemented.
-
[ ] Record the implementing configuration per system, since the policy is not the evidence — the configuration is.
-
[ ] [Gate] No deletion runs against data under hold.
Phase 11. Install the intake gate
-
[ ] Route every HR technology purchase through four questions: does it score people, does it use third-party data about people, does it touch a body, does it record a communication.
-
[ ] Name a reviewer and commit to a turnaround, since a two-day service level buys more cooperation than a policy.
-
[ ] Use a three-outcome decision template: proceed, proceed with contract changes, escalate for assessment.
-
[ ] Require register updates at signature, not at renewal.
-
[ ] Add works council and employee representative consultation to the gate where applicable, since that timeline is measured in months and is the most common cause of a signed deployment being stopped.
-
[ ] Add the cross-border transfer question, since global HR systems consolidate data and the mechanism is usually available while the assessment is usually missing.
-
[ ] Train the note writers, in thirty minutes, on recording the criterion and the evidence rather than the impression.
-
[ ] Brief the sponsor on the demographic data limitation, so nobody believes the audit is a certificate.
-
[ ] [Gate] The gate is installed before remediation finishes, because it is the only step that stops the problem growing.
The first ten days, for a practitioner with other work
-
[ ] Day one: install the gate. One email to procurement and HR leadership with the four questions and a named reviewer. An hour, and it stops the problem growing.
-
[ ] Day two: pull the vendor payment records. One request to finance produces the skeleton of the inventory faster than any other source.
-
[ ] Days three to five: find the biometric deployments. Highest per-head exposure, most self-contained remediation. Check for a published retention policy immediately.
-
[ ] Days six to seven: list every vendor touching a hiring decision, by asking recruiters to describe workflow rather than to list tools, and run the consumer reporting analysis against the result.
-
[ ] Day eight: look at the actual disclosure document the candidate signs. If it contains anything else, that is a one-day fix to a heavily litigated defect.
-
[ ] Day nine: check whether applications are ever deleted. The answer is usually no, and the fix is a configuration change.
-
[ ] Day ten: write the one-page brief — found, fixed, needs budget, and what the demographic data limitation means — and send it to the sponsor before anyone else describes the position to them.
Cross-jurisdiction handling
-
[ ] Build to the strictest standard globally for notice quality, retention discipline, purpose specificity, vendor terms, and inventory completeness, since these cost nothing extra and remove the tracking burden.
-
[ ] Use local instruments for consent, since all-party recording consent, standalone biometric releases, and video interview consent have formal requirements that a global document satisfies badly.
-
[ ] Maintain a short matrix for the questions that genuinely differ: whether employees are within the comprehensive privacy statute, whether a monitoring practice is permitted, and what an automated decision requires.
-
[ ] Address transfer mechanisms and assessments where a global system consolidates regionally.
-
[ ] Confirm what the applicant tracking system actually asks in each location, since default configurations ask everything everywhere and local inquiry restrictions are configuration rather than policy.
-
[ ] Keep the output to two pages, since a fifty-page global policy is not maintainable and will not be read.
Where audits of this estate find problems
-
[ ] The register is a questionnaire result, so the ownerless systems are missing.
-
[ ] A classification exists with a conclusion and no workflow description.
-
[ ] The audit came from the vendor, or ran on the vendor's aggregate population.
-
[ ] The demographic data gap is unstated, producing a confident ratio on a self-selected minority of applicants.
-
[ ] The consumer reporting question was asked of one vendor and not of the three others whose output shapes decisions.
-
[ ] The disclosure is a paragraph in the application form.
-
[ ] The biometric release is in the onboarding packet, and no retention policy is published.
-
[ ] The contract was signed two years ago on the vendor's paper with a cap at fees paid.
-
[ ] Security telemetry has become a management metric without notice, validation, or review.
-
[ ] Nothing is ever deleted, and there is no hold check to stop deletion when it finally starts.
-
[ ] The rights request process is invented on receipt, and the first response discloses a complainant.
System-by-system notes
The applicant tracking system. The largest data store in the estate and the one with the weakest governance. It holds every application ever submitted, including from people with no relationship to the organisation, together with manager notes written without any expectation of being read by outsiders. Retention is almost always infinite because nobody configured it otherwise. Check three things: the configured retention period, whether the disclosure documents served through it are standalone, and whether local inquiry restrictions are configured per location or applied globally by default.
The screening vendor. The oldest regulated category and, precisely because it is well understood, rarely the source of the problem. The problem sits in the vendors nobody classified alongside it. Check that the contract reflects agency accuracy obligations, that reports are deleted on a short schedule, and that the two-notice sequence is instrumented rather than manual.
The sourcing and insights tools. The highest-probability unclassified consumer reporting agencies in the estate. Bought on cards, procured without contracts, describing themselves as sourcing products. Run the definitional analysis against each and record it.
The interview and assessment layer. Simultaneously an automated decision question, a video interview statute question, a biometric question, and potentially a medical inquiry question. Obtain the technical documentation. Recruiting teams routinely believe a "communication score" derives from a transcript when the documentation describes analysis of visual and vocal features.
The HRIS. Holds the employment record and, frequently, accommodation records that should be segregated and are not. Check the segregation, the access model, and whether benefits data crosses into a covered arrangement.
The time and access layer. Fingerprint terminals, facial access control, and voice authentication. The highest per-head exposure in the estate. Release, published policy, implemented schedule, vendor terms — in that order, before deployment.
The monitoring stack. The least inventoried and the fastest growing. Its risk is not the collection but the drift: security data becoming management data without a decision. Check what feeds the dashboards.
Learning, engagement, and wellness. Surveys promised to be anonymous that are not, training records that are performance evidence, and health data whose covered status was never analysed. Check the granularity of aggregate reports at small sites, where three responses are identifiable.
Contractor and contingent workforce systems. Frequently outside every process above because the people are not employees, while holding the same categories of data about them. Confirm which obligations follow the data rather than the employment status.
The documents an audit should be able to produce on request
-
[ ] The system register, current, with an owner per row and the four trigger answers.
-
[ ] A classification memorandum for each scoring tool, dated, describing the workflow, naming the confirming person, and recording the disparate impact analysis separately from the covered-tool analysis.
-
[ ] The audit engagement letter, showing scope, independence, and the population used.
-
[ ] The audit report, with completeness disclosure, single-axis and intersectional ratios, and methodology.
-
[ ] The published audit summary, as published, with its date.
-
[ ] The candidate notice as actually served, with the qualifications assessed.
-
[ ] The remediation decision, recorded before the results were known.
-
[ ] The standalone disclosure and authorisation documents, as served, not as drafted.
-
[ ] A sample adverse action audit trail from the system, with timestamps for the pre-adverse notice, the dispute window, and the final notice.
-
[ ] The consumer reporting classification for every decision-influencing vendor, including the negative determinations and their reasoning.
-
[ ] The biometric release template and evidence of signature coverage across the affected population, including re-papered existing employees.
-
[ ] The published biometric retention policy and evidence the schedule runs.
-
[ ] The vendor register with cap position, carve-outs, training rights, derived data terms, subprocessor list, and deletion mechanism per vendor.
-
[ ] The monitoring register with collection point, purpose, notice, access, and retention.
-
[ ] The annual monitoring purpose review, with any repurposing decisions and their basis.
-
[ ] The rights request runbook, with third-party rules, exemption positions, and the hold check.
-
[ ] A completed rights request file, showing the systems searched, the methodology for unstructured sources, the redactions applied, and the retention bases for anything not deleted.
-
[ ] The retention schedule and, per system, the configuration that implements it.
-
[ ] The litigation hold register and evidence that holds suspend deletion automatically rather than by instruction.
-
[ ] The intake gate, the decision template, and a sample of completed reviews.
-
[ ] The note-writing training material and completion records.
-
[ ] The jurisdiction matrix, two pages, showing global standards, local instruments, and genuinely divergent analyses.
If a programme can produce all twenty-two, it is functioning. If it can produce the register, the classifications, and the intake gate, it is on the way. If it can produce only a policy document, it has not started.
Three deployments run against this checklist
A hiring platform with a fit score. Phase 3 classifies it as covered, because recruiters interview from the top of a ranked list and there is no meaningful review of the tail. Phase 4 commissions an independent audit on the employer's own applicants, discloses that demographic data was available for fifty-eight per cent of them, and reports one category below the conventional threshold. Because the remediation position was agreed before results were known, two inputs are reweighted and the tool is re-audited rather than discarded, which avoids the problem Ricci v. DeStefano identifies. Phase 7 removes the training licence and adds an audit assistance obligation. Elapsed time eleven weeks, most of it waiting for the auditor.
A monitoring stack that grew sideways. Phase 1 finds seven collection points, four with no owner. Phase 8 finds two feeds consumed by an operations dashboard as productivity metrics; the repurposing is stopped, because a metric influencing employment decisions is a selection procedure carrying 42 U.S.C. § 2000e-2 and Griggs with no validation behind it. Recording consent is rebuilt for all-party jurisdictions. Telemetry retention drops from indefinite to ninety days with an investigation extension. Two policy clauses are narrowed against 29 U.S.C. § 157. The argument that persuades the operations leader is discovery exposure under FRCP 26, not the discrimination analysis, because it is concrete and immediate.
Fingerprint terminals across eleven sites. Caught at Phase 2 before rollout, which is the good outcome. Vendor technical documentation obtained rather than the datasheet. Standalone releases drafted and signed across four thousand employees. Retention and destruction policy published, tied to end of employment plus thirty days, and implemented. Phase 7 obtains deletion certification, a prohibition on vendor use, and a carve-out from the general cap for statutory claims arising from biometric processing. The finance objection to the carve-out is answered with the comparison: per-violation damages across four thousand employees against one year of subscription fees. Rollout proceeds three months late and with roughly one per cent of the exposure it would otherwise have carried.
Handling the people who own the systems
-
[ ] Recruiting objects to friction. Answer with a service level: a two-day turnaround on procurement review buys more cooperation than a policy document, and the fear you are addressing — a tool switched off mid-cycle — is one they already have.
-
[ ] HR operations objects to workload. Do the drafting yourself and hand over finished documents. Be specific about volume: re-papering four thousand consents is a mail merge and two reminders.
-
[ ] Security objects to being asked to collect less. They are not being asked to. The ask is purpose discipline and retention, and the argument that lands is that they will be the ones producing the data in litigation.
-
[ ] Finance objects to the liability carve-out. Answer with the arithmetic rather than the statutory structure: per-violation exposure across the affected population set against the annual subscription.
-
[ ] The sponsor risks misunderstanding the audit. Brief the limits the first time — what it measured, on what population, with what missing — so nobody treats a published summary as a certificate of non-discrimination.
-
[ ] Employment litigation counsel is the most useful ally and is consulted last. They know which records get produced and which note-writing habits generate cases. Bring them into the training design.
-
[ ] Works councils and representative bodies are not a formality. Where consultation is required, the timeline is months and it belongs in the intake gate rather than in the deployment plan.
Notes, references, and the free-text field
-
[ ] Treat interview and performance notes as records, since they are discoverable, may be responsive to rights requests, and are the most common source of evidence that a decision rested on an impermissible basis.
-
[ ] Understand why they read badly, which is usually not that the manager held an impermissible view but that a phrase written in thirty seconds is read at leisure by someone looking for one.
-
[ ] Do not stop the notes, since they are also the best evidence that a decision rested on legitimate grounds and their absence is itself adverse.
-
[ ] Structure the field so the note records the criterion and the evidence rather than the impression, which improves both the decision and the record.
-
[ ] Set a retention period for notes matching the application retention, and delete on schedule rather than keeping them because deletion takes effort.
-
[ ] Treat references given in confidence and investigation files as third-party data, since disclosing them to their subject can identify a complainant and chill future reporting.
-
[ ] Decide the redaction approach in advance, not on receipt of a request from someone already in dispute.
-
[ ] Check the free-text fields nobody thinks about: rejection reason dropdowns with an "other" box, scheduling notes, and internal chat about candidates.
-
[ ] [Gate] The training happens before the audit, since improving what gets written is cheaper than managing what was.
-
[ ] Audit a sample of live notes before designing the training, since the actual failure mode in one organisation is rarely the one in another, and a session built on real examples changes behaviour where a generic one does not.
-
[ ] Delete the sample afterwards, and record that you did, since a collection of the organisation's worst notes assembled by counsel is not a document anyone wants to explain later.
-
[ ] Extend the same discipline to rejection reason codes, since a dropdown list written by a vendor for general use frequently contains options that no employer would choose to have produced in a discrimination case, and editing the list is a configuration change rather than a negotiation.
-
[ ] Check who can see the notes, since a field visible to every recruiter across every requisition is a different record from one visible to the hiring panel.
- [ ] Confirm the export path, since notes that can be downloaded in bulk to a spreadsheet leave the system's access controls entirely and reappear in mailboxes.
- [ ] Ask the vendor whether notes are included in the data it uses for product improvement, since the answer is sometimes yes and is almost never volunteered.
Key Authorities at a Glance
| Authority | Phase | |---|---| | 42 U.S.C. § 2000e-2 | 3, 8 — impact analysis with or without an audit statute | | Griggs v. Duke Power | 3 — the foundation of the second analysis | | Watson v. Fort Worth Bank | 4 — scored and subjective criteria in scope | | Albemarle Paper v. Moody | 4 — validation expectations | | McDonnell Douglas v. Green | 3 — the treatment framework alongside impact | | Ricci v. DeStefano | 4 — decide remediation before results | | 29 CFR 1607 | 4 — validation vocabulary | | 15 U.S.C. § 1681a | 5 — is the vendor a reporting agency | | 15 U.S.C. § 1681b | 5 — standalone disclosure and authorisation | | 15 U.S.C. § 1681e | 5 — agency accuracy obligations | | 15 U.S.C. § 1681m | 5 — the two-notice sequence | | 15 U.S.C. § 1681n | 5 — wilfulness and statutory damages | | 15 U.S.C. § 1681o | 5 — negligent violation liability | | Spokeo v. Robins | 5 — standing for procedural violations | | TransUnion v. Ramirez | 5 — forum consequences | | 18 U.S.C. § 2511 | 8 — recording and consent | | 18 U.S.C. § 2701 | 8 — stored communications | | 18 U.S.C. § 2702 | 8 — disclosure by providers | | Van Buren v. United States | 8 — authorised access narrowed | | 18 U.S.C. § 1030 | 8 — the underlying access statute | | 29 U.S.C. § 157 | 8 — concerted activity limits | | 42 U.S.C. § 12112 | 3, 6 — medical inquiry inside assessments | | 42 U.S.C. § 2000ff | 3 — genetic information | | 29 U.S.C. § 623 | 3 — age in selection tools | | 8 U.S.C. § 1324a | 9, 10 — verification records | | 8 U.S.C. § 1324b | 9 — verification anti-discrimination | | 45 CFR 164 | 9, 10 — covered wellness arrangements | | 15 U.S.C. § 45 | 4 — external statement consistency | | 16 CFR 314 | 7 — vendor diligence vocabulary | | 18 U.S.C. § 1839 | 10 — analytics outputs as assets | | FRCP 26 | 8, 10 — discoverability | | FRCP 37 | 9, 10 — holds override deletion |
Search the underlying materials directly for workforce data inventory methodology, automated employment decision tool notice, pre-adverse action notice timing, biometric retention policy publication, and employee monitoring notice requirements.
Related Documents
The doctrinal companion is Everything the Application Knows, and the operational sequence is Deploying Recruitment and Workforce Technology. The assembled reference set is the Recruitment and Workforce Data Toolkit.
Phase 6 depends on Your Face as Data, Building a Biometric Compliance Program, the Biometric Data Checklist, and the Biometric and Sensitive Data Toolkit.
Phases 9 and 10 draw on The State Privacy Wave, Standing Up a Multi-State Privacy Compliance Program, the State Privacy Law Applicability and Readiness Checklist, and the State Privacy Compliance Toolkit.
Phase 7 is the workforce application of Negotiating an AI Vendor Agreement, Buying a Model, the AI Procurement Checklist, the AI Procurement and Governance Toolkit, and the Software Continuity and Escrow Toolkit.
On the ownership and mobility questions alongside this estate, see Who Owns the Work?, Where an Employee Can Go, the Employee, Founder, and Mobility IP Toolkit, Building a Trade Secret Program That Survives Litigation, and the Cybersecurity Governance and Disclosure Toolkit.
Marksy is not a law firm and this checklist is not legal advice. It is a working instrument for an estate whose applicable regimes vary by jurisdiction and by product, and whose classification frequently turns on facts about a vendor's processing that its marketing does not disclose.