The data protection and privacy features include the ability to report on the personal data available within SAP SuccessFactors Recruiting, and any changes that have been made to subject data. Customers can also set the timeframe to systematically purge from inactive Talent Community members. If desired, a Content Security Policy can be enabled to prevent cross-site scripting attacks.
Remember that the Data Privacy Consent Statement is configured in Admin Center for customers using SAP SuccessFactors Recruiting.
It is the customer’s responsibility to adopt the features that they deem appropriate. More information can be found on the SAP Help Portal.
Data Protection
Use the settings from Settings→Data Privacy & Security Settings→Data Protection to control user data for Career Site Builder (CSB). This page is used for both CSB and non-CSB sites. For CSB customers, do not enable the Data Privacy Consent Statement here.
The setting Allow Manual Public User Creation allows customers to control how users can be added if there are concerns over data privacy and workflows for obtaining consent. Selecting OFF prevents the ability to manually add Talent Community members via the Talent Community Member API. In this case, Talent Community members can only be added through the public site workflows.

Data Retention Management
The Data Retention Management (DRM) configuration allows the customer to set the timeframe to systematically purge inactive candidates (Talent Community members) and Client Admins (Recruiting users who were added manually).
The CSB DRM setting only purges users who are not connected to an account in SAP SuccessFactors Recruiting. Users may be connected through the front-end workflows for Candidate Account Simplification.
Connected users will be purged from CSB when they are purged from the ATS via DRM settings and updates to the Recruiter Sync file (when the recruiter is no longer included).
Use the sliders to set the activity threshold in days for anonymization of candidate and client admin data.
Hint
Once the threshold is set, user data is anonymized if there hasn't been any user activity in the specified number of days.




