2.6 Detailed case studies
2.7 Case study 1: Recruitment data retained indefinitely
A company retains unsuccessful applicants’ CVs, interview recordings, background reports and AI scores indefinitely. Its recruitment vendor also uses the information to improve a cross-client matching product.
A Board proceeding begins after an applicant complains.
A meaningful undertaking may require the company to:
-
stop indefinite retention;
-
identify completed recruitment exercises;
-
delete records without a continuing lawful purpose;
-
impose a defined retention schedule;
-
cause its recruitment processors to delete copies;
-
separately address the vendor’s independent use;
-
prevent further AI training;
-
revise applicant notices;
-
establish a correction and erasure channel;
-
audit prior deletions; and
-
submit evidence to the Board.
A promise to “review retention practices” would be insufficient because it does not require an outcome.
2.8 Case study 2: Processor security failure
A cloud-hosted payroll system exposes employee salary, PAN and bank details because administrator accounts lacked multifactor authentication.
The employer proposes an undertaking to:
-
complete all required breach notifications;
-
reset affected credentials immediately;
-
implement multifactor authentication;
-
review privileged access;
-
encrypt specified exports;
-
retain and review security logs;
-
revise the processor contract;
-
test incident-response procedures;
-
conduct independent security testing; and
-
report completion to the Board.
Acceptance may bar further proceedings concerning the matters covered, but it would not automatically prevent proceedings if the employer conceals another affected system or later fails to follow the undertaking.
2.9 Case study 3: Marketing after withdrawal
A retailer continues marketing to thousands of customers after withdrawal because each marketing channel maintains a separate suppression list.
The undertaking may require:
-
immediate suspension of the affected campaigns;
-
reconciliation of withdrawal records;
-
centralised suppression;
-
processor correction;
-
direct communication to affected persons;
-
testing across email, SMS and advertising platforms;
-
periodic assurance; and
-
prohibition on reactivation without a valid ground.
This is more effective than resolving only the complaints of the first few customers who approached the Board.
2.10 Case study 4: Inaccurate AI risk scores
A lender uses an AI system that incorrectly classifies customers as high-risk because it relies on outdated employment and income information.
An undertaking may require the lender to:
-
stop using the affected model for adverse decisions;
-
identify persons assessed during the affected period;
-
correct the source data;
-
reassess affected applications;
-
notify relevant applicants;
-
review the model and thresholds;
-
implement human review;
-
establish a challenge process;
-
test data quality and model performance; and
-
submit an independent report.
The undertaking should address decisions already made as well as future model governance.