Assessment Summary
Business: GhostRecruit, Inc.
Processing activity: Automated ranking of applicants for employer customers.
Purpose: Help recruiters prioritize applicants whose submitted experience and skills appear relevant to a posted role.
Trigger: Use of ADMT in an employment-related significant decision.
Decision: Proceed only with the safeguards and human-review conditions documented below.
Assessment owner: Privacy and Product Risk Lead.
Approver: Chief Operating Officer, who participates in the decision to launch the processing.
The summary appears first because a reader should be able to understand the processing, trigger, major risks, safeguards, and decision before reading the supporting detail. A company's regulatory submission to CalPrivacy is a separate summary-information process described at the end of this example.
Meet GhostRecruit
GhostRecruit sells recruiting software to employers. The fictional product imports resumes and application responses, extracts job-related information, and assigns a relevance score. Recruiters can sort applicants by that score before deciding whom to advance.
The marketing team originally proposed the slogan “We find the candidates you would have found if you had infinite time.” Legal suggested everyone take the afternoon off and reconsider.
Processing and Purpose CCPA required
Specific purpose: reduce the time recruiters spend manually sorting applications by identifying applicants whose submitted qualifications appear relevant to the employer's published job criteria.
Categories of personal information:
- name and contact information;
- employment and education history;
- skills, certifications, and application responses;
- job applied for and application metadata;
- inferences about job relevance produced by the ranking model; and
- recruiter actions associated with the recommendation.
Minimum information necessary: the ranking service does not need photographs, birth dates, home addresses, or unrelated demographic fields to calculate job relevance. Those fields are excluded from model inputs.
Collection and sources: applicants provide information through the employer's application process. Employer customers provide job descriptions and selection criteria. GhostRecruit creates the relevance score and supporting explanation.
Use and disclosure: GhostRecruit processes the information for the employer customer. Authorized recruiters receive the score and explanation. Contracted infrastructure providers process information only as needed to provide the service.
Retention: applicant records follow the customer's configured retention period and applicable contractual requirements. Model-evaluation records are retained separately when needed to demonstrate testing and monitoring.
Scale and consumer interaction: the feature may evaluate thousands of applicants across multiple employer customers. Applicants interact primarily with the employer rather than directly with GhostRecruit.
Notice: employer customers must present applicable privacy and ADMT notices before covered processing. GhostRecruit provides customers with implementation documentation describing the feature and data use.
Benefits CCPA required
GhostRecruit documents specific expected benefits rather than writing “improve hiring,” which would tell a risk assessor very little.
- Applicants: qualified applications may be surfaced more consistently when applicant volume is high.
- Employer customers: recruiters may spend less time on initial sorting and more time reviewing candidates.
- GhostRecruit: the feature makes the SaaS product more useful to recruiting teams.
- Other stakeholders: hiring teams may receive a more structured first-pass review of job-related qualifications.
Negative Impacts CCPA required
The assessment identifies negative impacts and the sources that could create those impacts.
- Unfair exclusion: historical patterns or proxy variables could systematically rank some groups lower.
- Incorrect inference: resume parsing may misunderstand nontraditional experience, career gaps, credentials, or job titles.
- Automation bias: recruiters may treat a score as a decision rather than one input.
- Lack of meaningful notice: applicants may not understand that automated processing influenced review.
- Security or access risk: centralized applicant records could expose sensitive employment information if safeguards fail.
- Purpose expansion: a customer could attempt to reuse the score for a purpose that was not evaluated.
Safeguards CCPA required
- exclude age, photograph, home address, and unrelated demographic fields from ranking inputs;
- test model performance across relevant groups before launch and after material changes;
- provide recruiters with job-related reasons supporting a ranking rather than a score alone;
- require a recruiter to review applicant information before an adverse hiring decision;
- monitor overrides, outcome patterns, complaints, and unexpected performance changes;
- restrict customer configuration to documented employment-related purposes;
- apply role-based access, encryption, logging, and retention controls; and
- update this assessment when a material change affects risks or safeguards.
ADMT Details CCPA required for this scenario
Logic: the system converts application information into structured job-related features and compares those features with employer-defined criteria. The system produces a relevance score and supporting factors.
Output: a ranked applicant list, relevance score, and explanation of the job-related factors that contributed to the score.
Use in the decision: recruiters use the ranking to prioritize review. The score does not automatically reject an applicant.
Assumptions and limitations:
- resume language accurately represents an applicant's relevant experience;
- employer criteria are genuinely related to the role;
- unusual career paths and nonstandard titles may be interpreted poorly;
- model performance may change as applicant populations and job requirements change; and
- human reviewers may over-rely on automated recommendations even when policy prohibits automatic rejection.
Participants and Approval CCPA required
Employees who participate in the processing provide information relevant to the assessment. GhostRecruit records input from:
- product management on intended use and customer workflow;
- engineering on model logic, inputs, outputs, and monitoring;
- privacy and legal on notices and regulatory requirements;
- security on access, logging, and data-protection safeguards;
- customer success on recruiter workflows and complaints; and
- the executive approver on whether the processing should proceed.
Approval decision: proceed with conditions. Launch requires documented validation of the safeguards above. The Chief Operating Officer approves the assessment on September 25, 2026.
Useful Extras Not required by CCPA Article 10
GhostRecruit also chooses to document several items that can improve the quality of judgment without being presented here as additional CCPA Article 10 requirements:
- Data-flow diagram: maps applicant data from collection through scoring, customer access, vendors, storage, and deletion.
- DIMSF: includes Diverse Inputs and Multi-Stakeholder Feedback from applicants, recruiters, employment experts, and people who understand disparate impacts.
- Traceability: links each material risk to the safeguard, owner, evidence source, and monitoring activity intended to address the risk.
- Privacy Impact Assessment: maintains a broader PIA covering the full processing lifecycle.
These additions reflect concepts used in the ForHumanity CCPA Certification Scheme. The extra work can look cumbersome. The objective is to empower the people making the risk decision with better information. A diagram may reveal a forgotten disclosure. Stakeholder input may reveal a harm the product team did not anticipate. Traceability may show that a promised safeguard never reached production.
This Company Is Fake. The Risk Is Not.
GhostRecruit is fictional, but automated hiring discrimination is not. In 2023, the U.S. Equal Employment Opportunity Commission announced a settlement with iTutorGroup after alleging that the company's application software automatically rejected female applicants age 55 or older and male applicants age 60 or older. The settlement required $365,000 in payments and other relief.
The lesson is not that every hiring algorithm discriminates. The case shows why a risk assessment should force a business to ask who can be harmed, how automated logic affects a consequential decision, and what evidence supports the safeguards. Read the EEOC's iTutorGroup settlement announcement.
Use the Example, Then Keep the Full Record
Use GhostRecruit as a structural template rather than copying the conclusions. Replace the fictional purpose, data, risks, safeguards, participants, and decision with facts about the actual processing. Confirm every applicable requirement against the current regulation.
Businesses generally submit specified summary information about risk assessments to the California Privacy Protection Agency rather than routinely filing each complete assessment. The Agency or the Attorney General may require a business to provide the full risk-assessment report. When formally requested under Article 10, the report must be provided within 30 calendar days.
The fictional summary at the top is therefore useful for orientation, but the organization still needs the underlying assessment. A summary cannot substitute for the evidence and reasoning that support the decision.
Primary sources
Check the Source
California CCPA statute and regulations effective January 1, 2026
EEOC: iTutorGroup to Pay $365,000 to Settle Discriminatory Hiring Suit