With the rapid growth of software usage and data processing, safeguarding user privacy has become more critical than ever. Businesses face increasing risks of unintentionally violating data privacy regulations due to insufficient compliance measures, which can lead to substantial fines and reputational damage.At Lever, our goal was to help customers protect their data while meeting compliance requirements.
Specifically, we aimed to:
Our solution delivered significant impact, retaining nearly $2 million in revenue during the MVP phase alone, while empowering customers to manage compliance efficiently and confidently.
In a world of increasing data regulations, the General Data Protection Regulation (GDPR) has emerged as a global gold standard for data privacy and protection. GDPR ensures that organizations manage and process personal data responsibly, with severe consequences for non-compliance.
Lever’s platform, widely used by enterprise organizations, faced a critical gap: it lacked functionality to help customers meet GDPR requirements, particularly around data retention and candidate privacy. Without tools to manage data in compliance with GDPR, customers—especially those with global operations—risked fines and operational inefficiencies.
Initially, this project was scoped by my design manager but transitioned to me due to organizational changes. My role was to design a scalable, self-serve solution that addressed customers’ GDPR needs while aligning with Lever’s broader business goals.
Our discovery phase involved extensive research into GDPR laws and best practices across customer jurisdictions. This groundwork allowed us to approach problem-solving with a clear, empathetic understanding of our customers' concerns and frustrations around GDPR compliance. By identifying pain points, we ensured our solution was deeply aligned with customer needs.
Our research centered on understanding what functionality mattered most to customers for maintaining GDPR compliance. We validated the importance of localizing data retention by job location and gained insights into customers' concerns with Lever's existing GDPR model. These insights formed the foundation for designing a solution tailored to their needs.
Through research, we found that Lever’s enterprise and strategic customers often operated in multiple job locations worldwide. These customers needed to manage compliance processes—collection, retention, and anonymization—separately for each location. This insight made it clear that supporting data retention by job location was not just a feature but a necessity.
For phase one, we prioritized Lever's enterprise and strategic customer base. Insights from customer success managers revealed a strong connection between GDPR compliance concerns and ongoing initiatives to prevent churn and improve conversion in our enterprise funnel. Addressing these concerns became key to delivering value for this high-impact audience.
We built a compliance management portal within the settings area, enabling customers to manage GDPR requirements across three key categories: collection, retention, and anonymization. Unlike the previous globally applied rules, the new portal introduced flexibility by allowing users to configure settings for each category independently. Additionally, we added functionality for managing data retention by job location, meeting a critical need for global enterprises.
The existing GDPR compliance page at Lever lacked scalability to support multiple regulations. As Lever continues to expand globally, additional compliance requirements from various jurisdictions would strain the performance and usability of the current page. A scalable settings page was essential to:
This insight highlighted the critical need to future-proof Lever's compliance capabilities, creating a foundation for efficient growth and flexibility.
Lever’s enterprise and strategic customers often operate across multiple global locations, each governed by local data privacy laws. These regulations dictate how long candidate data can be retained, and exceeding these limits poses significant risks, including penalties from regulatory bodies during audits.
Key takeaways from customer interviews emphasized the importance of localization:
Customer feedback revealed specific requirements for improving data retention settings:
The finalized designs introduced a robust and user-friendly portal for managing data retention, collection, and anonymization settings. Our approach prioritized flexibility and customization, ensuring a consistent, seamless experience for organizations operating across multiple jurisdictions, regardless of their size or complexity.
Recognizing that every company has unique preferences for complying with GDPR, we built a solution focused on choice and adaptability. Customers could define their data collection and retention preferences at various levels of granularity:
Retention settings were anchored around the concept of "lawful basis," which defines how organizations manage and store candidate data in their active pipelines. For example:
The portal also introduced advanced anonymization tools:
To enhance usability, we added features that allowed customers to:
This comprehensive approach not only addressed the immediate GDPR compliance challenges but also empowered organizations with scalable, future-proof tools for managing candidate data securely and efficiently.