The encyclopedia · Legal & Compliance · Legal decision · 2018–2019
Recruit scored students' odds of ghosting a job offer, sold the score to employers
Recruit Career's Rikunabi DMP Follow analysed students' browsing behaviour to score their likelihood of declining a job offer, then sold the score to employers.
Recruit Holdings · 2019-08-26
What happened
Recruit Career, a subsidiary of Recruit Holdings, ran a job-hunting platform called Rikunabi used by hundreds of thousands of Japanese students. A companion service, Rikunabi DMP Follow, analysed students' browsing activity on the platform and used it to calculate a probability score of how likely each student was to decline a job offer they had already informally accepted — then sold that score to the corporate clients who had made the offers.
The company had revised its privacy policy in March 2019 to cover this new data use, but Japan's Personal Information Protection Commission found the disclosure was incomplete across several versions of the sign-up flow: scores for 7,983 students were provided to employers without the required consent even under the revised policy, and the total group whose data reached employers without proper consent grew to 26,060 once the commission's review widened.
The service was suspended in July 2019 after the regulator began questioning it and discontinued permanently on 4 August 2019. On 26 August 2019 the commission issued Recruit Career its first-ever formal administrative recommendation under the data protection law, alongside guidance citing failures in both security-management obligations and third-party data disclosure, and Tokyo's labour bureau issued its own guidance days later over the practice's conflict with job-placement fairness rules.
Why it happened
- Scoring a student's likelihood of declining an offer and selling that score to the employer making the offer created a direct incentive conflict the students themselves never agreed to.
- A privacy-policy update rolled out unevenly across different versions of the sign-up screen, so consent was missing for thousands of users even after the company believed it had covered the new use.
- The data covered behavior on a platform students needed to use for job hunting, leaving them little practical way to opt out and still compete for the same jobs.
- Regulators treated the incomplete third-party consent as a security and disclosure failure serious enough to warrant the commission's first-ever formal recommendation under the law.
The lesson
A privacy policy update that doesn't reach every version of a sign-up flow leaves real users unconsented even after the company believes the paperwork is fixed.
Sources
spotted an error? The club wants to know.
More like this
A subcontractor's shared login let attackers leak 440,000 LINE items
HP India rigged government tenders through its resellers — ₹142.37 crore CCI fine
Amazon's €746M GDPR record fine was scrapped on a technicality
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.