What is candidate consent management, and how do I set it up?
Last updated: October 7, 2026
Candidate consent management lets you collect, track, and manage candidates' consent to process their personal data — something privacy laws like GDPR require — directly inside Kula, instead of handling it outside the ATS.
Who can do this: Super Admin.
Where to find it: Settings → Privacy and compliance → Candidate consent.
Turning it on and setting your privacy policy
Go to Settings → Privacy and compliance → Candidate consent.
Turn on Enable candidate consent.
Under Organization's privacy policy, add your policy as a URL, an Upload (up to 10 MB), or pasted Text.
Click Save.
Your privacy policy appears to candidates on the Kula careers page, alongside a data-processing disclaimer. Make sure it covers your use of AI and states how long consent remains valid — Kula won't check this for you, and the consent validity period you set in the next section needs to actually match what your policy promises candidates.
Setting up consent rules
A consent rule controls how Kula collects consent for one or more offices, and how long that consent lasts.
Under Consent rules, click Add rule.
Give it a Name of rule.
Choose which Office(s) it applies to, or select All offices. You can't add an office-specific rule while an "All offices" rule exists — remove the "All offices" rule first if you need per-office rules instead.
Set Consent validity: a number from 1–999 plus a unit (Days, Months, or Years), or turn on Never expires. This should match what your privacy policy states.
Configure the Consent request email — sent to sourced candidates, and to anyone who applied through a non-Kula surface, to collect their consent. Turn on Send automatically to have Kula send it on its own, a set number of days/months/years after the candidate is sourced; leave it off to send requests manually instead.
Configure the Consent extension email — sent to candidates whose consent is about to expire, inviting them to extend it and stay on file. It has its own Send automatically toggle and offset, timed before the expiry date.
Optionally, turn on Auto-anonymization to have Kula automatically anonymize candidates whose consent has expired or been declined, a set number of days/months/years afterwards. This is destructive and permanent — type ANONYMIZE into the confirmation field to turn it on.
Click Create rule (or turn on Create additional rules to keep the drawer open for the next one).
Deleting a rule stops consent being tracked — and expired consent being renewed — for every candidate it currently applies to. Kula tells you how many candidates that affects before you confirm.
The consent summary digest
Turn on Consent summary to get a recurring email summarising consent status across every candidate in your account. Set Recipients (users, roles, or email addresses), and How often — Daily, Weekly, or Monthly on a day you choose.
What candidates see
A candidate who needs to consent gets an email with a link to a dedicated consent page, where they can grant or decline. If they decline three times in a row, Kula stops asking — their consent is treated as permanently declined.
Good to know
A declined or withdrawn consent blocks further processing on that candidate. Actions elsewhere in Kula — like moving them through a pipeline — show dimmed with a "This action needs the candidate's consent" tooltip until the consent is resolved. An expired (not declined) consent does not block anything — it just needs a reminder or renewal.
A candidate who declines three times is permanently blocked. At that point, the only action left for that candidate is Anonymise.
Kula sends up to 3 reminder emails for an outstanding consent request before "Send reminder" stops being offered.
A consent is flagged "about to expire" starting 30 days before its expiry date, so recruiters get an early heads-up rather than finding out when it's already lapsed.
Anonymising a candidate is permanent and can't be undone — whether it happens automatically via a rule or you do it manually. Their personal data is erased from Kula entirely; they stay linked to jobs, flows, and projects for reporting purposes, but can no longer be viewed or edited.
Need help?
If you have questions or need assistance, reach out to us at support@kula.ai or use the in-app chat.