The Recruiter's Guide to Reading Consent Language in Monitoring Tools
Every interview monitoring vendor says they are "privacy-first" somewhere on their homepage. That phrase alone tells you nothing. The actual answer is buried in what the consent notice says, which data category it names, and what the retention policy admits to. This is a checklist for reading that language before you sign, not after.
Short answer
Ignore the adjectives and read for four things: a field-level list of what is captured, an explicit statement of what is not, a collection window tied to the session, and a retention period with a deletion mechanism.
If any of those is described in general language rather than specifics, that vagueness is the vendor's answer. Marketing copy describes keystroke timing and keystroke logging almost identically, so the distinction has to come from the contract.
On this page
Start with what is actually captured
Ask for a data field list. Not a description of capabilities, not a privacy summary: the actual fields written to storage. A vendor with a metadata-only design can produce this in a page and is usually pleased to. A vendor whose collection is broader will tend to answer with adjectives.
| Field | Metadata-only design | Content-capturing design |
|---|---|---|
| Clipboard | Event occurred, byte count, target surface. | The pasted text itself. |
| Keyboard | Interval between events. | Which characters were typed. |
| Screen | Which window has focus, and its attributes. | Pixels, screenshots or video. |
| Camera and mic | Which devices exist and their drivers. | The audio and video streams. |
| Processes | Names and lifetimes. | Names plus window titles or contents. |
Window titles deserve a specific mention, because they sit in a grey zone vendors exploit. A title is technically metadata and frequently contains content: document names, customer names, the subject of an email. Ask whether titles are stored, and if so, whether they are hashed or truncated.
Translating vendor phrasing
| What the notice says | What to ask next |
|---|---|
| "Behavioural signals" | Which signals, as fields? Does this include keystroke content? |
| "Session data" | Does session data include screen captures or window titles? |
| "Including but not limited to" | What is the complete list? This phrase means the list is not one. |
| "Device information" | Device identifiers, or device contents? Is anything persistent stored? |
| "Retained as long as necessary" | Necessary for what, and what is the maximum in days? |
| "May be used to improve our services" | Does this include training models on candidate data? Get a no in writing. |
| "Shared with trusted partners" | Which partners, for what purpose, under what terms? |
Red flags worth pausing on
Good signs
- An explicit negative list of what is never collected.
- Collection bounded to the session, with a visible indicator.
- A stated retention period in days or months.
- A written commitment to human review before adverse decisions.
- Willingness to put the field list in the contract.
Red flags
- Scope-expanding phrases: "including but not limited to", "and related data".
- Retention with no defined period.
- Any right to train models on candidate data.
- Background collection outside the interview window.
- A score that can drive an outcome with no human step.
- Refusal to commit the negative list to writing.
Reading the retention terms
Retention is where otherwise reasonable products quietly become liabilities, and it is the section procurement most often skims.
- Is there a number?"As long as necessary" is not a retention policy. Ask for days or months, and for what purpose defines the period.
- Is deletion enforced or intended?A scheduled job that deletes at expiry is a control. A sentence in a policy is a hope. Ask which one exists.
- Are clean sessions treated differently?Sessions with no findings should go early. Retaining evidence of nothing creates obligations with no offsetting value.
- Does the consent record outlive the report?It should. A report you can still produce, with no record of the consent that justified collecting it, is the worst of both.
- What happens on contract termination?Ask for the deletion timeline and whether you get an export first.
Six questions to ask directly
- Exactly which fields do you collect? Ask for the list, and ask for it in the contract or a technical annex.
- Is any content ever captured? Screen pixels, keystroke characters, clipboard contents, audio, video. Get an explicit no, or find out what the exceptions are.
- When does collection start and stop? It should be bounded to the session, with an indicator the candidate can see.
- How long is data retained, and how is deletion enforced? A number and a mechanism.
- Can the system produce an adverse outcome without a human? The right answer is no, and it matters for automated-decision rules as well as for fairness.
- Is candidate data ever used to train models or shared with third parties? Get this in writing regardless of what the sales conversation suggested.
Key takeaways
- "Privacy-first" is marketing. A field-level list in the contract is the actual commitment.
- Ask specifically about window titles, which are technically metadata and frequently contain content.
- Scope-expanding phrases like "including but not limited to" mean the list you were given is incomplete.
- Retention needs a number and an enforced deletion mechanism, not a stated intention.
- Get a written no on training models with candidate data.
- Recruiters usually read this language before legal does, which makes this a recruiting skill.
Why this matters beyond compliance
The compliance case is obvious. The one recruiters feel sooner is candidate experience. The consent notice is frequently the first substantive thing a candidate reads about how your company operates, and a broad, vague notice reads as an organisation that has not thought carefully about people. Strong candidates notice, and some decline.
There is also a practical reason this lands on recruiting rather than legal. Recruiters see the notice in the scheduling flow long before anyone reviews a contract renewal, which means recruiting is the function best placed to catch a mismatch between what the vendor promised and what the candidate is actually shown. That makes reading this language a recruiting skill, not only a legal one.
For the wording side, see consent-first interview monitoring, and for clause-level text our policy template.
Frequently asked questions
What should a recruiter look for in a monitoring vendor's consent notice?
Four things. A specific list of what is captured, expressed as data fields rather than adjectives. An explicit statement of what is not captured. A defined collection window tied to the session. And a retention period with a deletion mechanism, not just a stated intent.
If any of those is described in general language rather than specifics, treat that as the vendor's answer and price the risk accordingly.
What are the red flags in interview monitoring consent language?
Phrases that expand scope without naming it: "including but not limited to", "such as", "and related data", "for product improvement", or "may be shared with trusted partners".
Also watch for retention described as "as long as necessary" with no stated period, any right to use candidate data to train models, and the absence of a human-review commitment before adverse decisions. Each converts a bounded product into an open-ended data relationship.
How can you tell whether a vendor captures content or only metadata?
Ask them to state it as a field list and to confirm in writing that screen pixels, keystroke characters, clipboard contents, audio and video are never captured.
Marketing copy describes keystroke timing and keystroke logging in almost identical language, so the distinction has to come from the contract or a technical annex. A vendor that will not commit to the negative list in writing is telling you something.
Does a signed consent form make monitoring compliant?
No. Consent is one lawful basis among several, and in employment contexts it is often the weakest because the power imbalance makes freely given consent hard to establish.
Compliance depends on the lawful basis you actually rely on, the notice you give, data minimisation, retention, candidate rights and whether decisions are solely automated. A consent form is evidence that you asked, not proof that the processing was lawful.
What retention terms are reasonable for interview monitoring data?
A defined period tied to a purpose, typically the dispute window relevant to your jurisdiction, commonly around twelve months, with automated deletion at expiry.
Sessions producing no findings should be deleted sooner, because retaining evidence of nothing creates obligations without value. Indefinite retention, or retention "as long as necessary" with no definition, should not pass review.
Which questions should you ask every monitoring vendor directly?
Six: exactly which fields are collected; whether any content is captured and under what circumstances; when collection starts and stops; how long data is retained and how deletion is enforced; whether the system can produce an adverse outcome without a human; and whether candidate data is ever used to train models or shared with third parties.
Get all six answered in writing before signing.
References
- Consent-first interview monitoring, for lawful basis and notice design.
- Interview integrity policy template, for clause-level wording.
- InterviewWatch privacy policy and security, for our own answers to these six questions.
- What interview integrity monitoring is, for the vendor evaluation checklist.
Ask us these questions directly
We will answer all six in writing, including the field list and the negative list. That is the point of a metadata-only design.