Greenhouse · Greenhouse Privacy Policy · View original document ↗

Sensitive Information Opt-In Consent Requirement

Low severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Greenhouse changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Greenhouse Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that Greenhouse requires affirmative express consent before disclosing or repurposing sensitive categories of personal information, including health conditions, racial or ethnic origin, political opinions, religious beliefs, trade union membership, and sexual life data.

This analysis describes what Greenhouse's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes an opt-in consent requirement for sensitive personal information that applies regardless of geographic jurisdiction, providing a baseline protection for sensitive data categories that aligns with GDPR Article 9 requirements and extends a similar protection to non-EEA users.

Consumer impact (what this means for users)

Under this clause, Greenhouse requires affirmative express consent before disclosing or using sensitive personal information such as health data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, or sexual life information for purposes beyond those originally collected. This protection applies to data received from third parties where that third party has identified it as sensitive.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Submit a request via the Greenhouse Data Subject Request Portal to request deletion or restriction of processing of any sensitive personal information Greenhouse may hold about you.

Cross-platform context

See how other platforms handle Sensitive Information Opt-In Consent Requirement and similar clauses.

Compare across platforms →

Monitoring

Greenhouse has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
In any event, unless Greenhouse has affirmative express consent from you, Greenhouse will not (i) disclose sensitive information (i.e., personal information specifying medical or health conditions, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership or information specifying the sex life of the individual), or (ii) use sensitive personal information for a purpose other than those for which it was originally collected or subsequently authorized by you through the exercise of opt-in-choice. Greenhouse will treat as sensitive any Personal Information received from a third party where the third party identifies and treats it as sensitive.

Excerpt from Greenhouse's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision directly reflects GDPR Article 9 special category data protections and is consistent with equivalent provisions under UK GDPR and CPRA's sensitive personal information framework. The explicit enumeration of categories mirrors GDPR Article 9(1) categories, and the opt-in consent requirement reflects GDPR Article 9(2)(a). The FTC's general consumer protection authority is also relevant. 2. GOVERNANCE EXPOSURE: Low. The provision establishes protections consistent with or exceeding applicable legal requirements for sensitive data categories. The extension of sensitive data treatment to third-party-sourced data where the third party identifies it as sensitive is a proactive data governance practice that reduces regulatory exposure. 3. JURISDICTION FLAGS: EEA and UK users benefit from GDPR and UK GDPR enforcement of these protections. California residents benefit from CPRA's sensitive personal information framework. The policy's extension of these protections globally, not limited to specific jurisdictions, reduces differentiated compliance risk across Greenhouse's user base. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers who transmit sensitive category data to Greenhouse through recruiting workflows should ensure that their Data Processing Addenda and candidate consent mechanisms account for this provision. Vendors providing Greenhouse with data from third-party sources should be contractually required to flag sensitive data consistent with this policy's stated practice. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should confirm that consent capture mechanisms for sensitive data are documented and auditable, particularly for any recruitment use cases where health, disability, or demographic data may be submitted by candidates. Data mapping should identify all inbound data flows from third parties that may include sensitive categories to ensure the flagging and treatment obligations described in this provision are operationally implemented.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC has consumer protection authority over Greenhouse's data practices, including compliance with stated sensitive data consent requirements.
    File a complaint →

Provision details

Document information
Document
Greenhouse Privacy Policy
Entity
Greenhouse
Document last updated
July 5, 2026
Tracking information
First tracked
July 6, 2026
Last verified
July 9, 2026
Record ID
CA-P-015549
Document ID
CA-D-00918
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
8eed11ab4b13cf36349d959508396725d190ee2515f43b08f6e7be1f429e377d
Analysis generated
July 6, 2026 15:44 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Greenhouse
Document: Greenhouse Privacy Policy
Record ID: CA-P-015549
Captured: 2026-07-06 15:44:37 UTC
SHA-256: 8eed11ab4b13cf36…
URL: https://conductatlas.com/platform/greenhouse/greenhouse-privacy-policy/provision/CA-P-015549/sensitive-information-opt-in-consent-requirement/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Greenhouse's Sensitive Information Opt-In Consent Requirement clause do?

This provision establishes an opt-in consent requirement for sensitive personal information that applies regardless of geographic jurisdiction, providing a baseline protection for sensitive data categories that aligns with GDPR Article 9 requirements and extends a similar protection to non-EEA users.

How does this clause affect you?

Under this clause, Greenhouse requires affirmative express consent before disclosing or using sensitive personal information such as health data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, or sexual life information for purposes beyond those originally collected. This protection applies to data received from third parties where that third party has identified it as sensitive.

Is ConductAtlas affiliated with Greenhouse?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Greenhouse.