GDPR in recruitment: how to handle candidates’ data correctly

  • 26 Jun 2026
  • 6 minutes of reading

Processing personal data during recruitment is an obligation for every employer – yet GDPR in HR remains an area where companies often make mistakes. In this article, you will learn what data you process during recruitment, on what legal basis, how long you are permitted to retain it, and where problems most commonly arise.

What personal data of candidates do you process during recruitment?

The GDPR in recruitment sets out the rules for processing the personal data of job applicants . Employers must know what data they are processing, why they are processing it, how long they retain it and who has access to it. Properly established processes help to protect not only candidates but also the company itself from unnecessary risks.

The GDPR in recruitment applies to all personal data you come into contact with during the selection process. This covers a wider scope than most HR teams realise.

In a standard recruitment process, you typically process :

  • CVs and cover letters – name, address, date of birth, photograph, employment history,
  • test results and assessment centre results,
  • recruiter’s notes and the hiring manager’s assessment,
  • reference check results,
  • communication records – emails, messages, interview notes,
  • and, where applicable, video interview recordings.

TIP: If you use artificial intelligence in recruitment – for example, to create job adverts, process CVs or shortlist candidates – we recommend that you also familiarise yourself with the rules for its safe use. Read our article How to use AI safely in recruitment.

 

On what legal basis are you permitted to process candidates’ data?

Data protection in recruitment is not based on a single legal basis. It depends on which stage of the process you are at and what you plan to do with the data.

Situation

Legal basis

Candidate’s consent

Ongoing selection process

Preparation for a contract / legitimate interest

Not required

Active sourcing (LinkedIn, databases)

Legitimate interest

Not required, but the candidate must be informed

Talent pool following the conclusion of the recruitment process

Consent

Always required

The most common mistake in practice : HR teams automatically request the candidate’s consent at every point of contact. However, consent is only required for retaining data after the recruitment process has ended or for inclusion in a database. During the active recruitment process, a legitimate interest or preparation for a contract is sufficient.

 

How long are you allowed to retain the data of a rejected candidate?

The retention period for candidates’ personal data is one of the most frequently asked GDPR questions in HR. The exact timeframe depends on the specific situation.

  • Without the candidate’s consent: once the recruitment process has ended, the candidate’s personal data should be deleted unless you have their consent or another legal basis for continuing to retain it.
  • With valid consent for a talent pool: typically 1–2 years. The exact period must be specified directly in the consent form, and the candidate must be able to withdraw their consent at any time.
  • Successful candidates: their data is transferred to the HR system and is subject to different retention periods under employment law.

To set specific retention periods appropriate to your sector and processes, we recommend consulting your Data Protection Officer (DPO) or a lawyer specialising in data protection .

TIP: Datacruit’s recruitment software allows you to automate the management of consent and the monitoring of personal data retention periods . This means the HR team does not have to manually check which candidates’ consent is due to expire or when data needs to be deleted.

 

Where do HR teams most commonly go wrong when processing personal data in recruitment?

Most GDPR breaches in HR do not occur intentionally but are the result of everyday habits and processes that have gradually become a standard part of the recruitment process. It is precisely these seemingly minor details that can lead to a company processing personal data in breach of the GDPR.

  1. CVs are circulated unchecked via email within the company
    A recruiter forwards a CV to a hiring manager, who then sends it to their line manager. As a result, several people who are not involved in the selection process at all have access to the candidate’s data.
  2. Talent pools without valid consent
    Retaining a candidate’s data in a database for future roles without demonstrable and specific consent constitutes a breach of the GDPR in recruitment. Consent must be freely given, specific and must include information on the retention period.
    TIP: Datacruit keeps a record of the history of consents to the processing of personal data, including any withdrawals. This gives recruiters an overview of which candidates they can contact again and which have already withdrawn their consent.
  3. Data in Excel or on a shared drive without access controls
    Shared spreadsheets or folders accessible to the whole team do not ensure control over who is working with the data. Furthermore, when a request for erasure is made, you must delete the data from all locations – in such an environment, this is a difficult requirement to meet.
  4. Missing or outdated information obligations
    Candidates must be informed about who is processing their data, for what purpose, for how long, and what rights they have. If this information is missing from the careers page or the application form, this constitutes a breach of the GDPR in HR, regardless of how well the data is otherwise secured.
  5. No automatic deletion after the retention period expires
    Data accumulates because deleting it is not a specific task. After two or three years, the system may contain thousands of records that should not be there.
  6. Interview notes without access restrictions
    Candidate assessments, impressions from interviews or subjective comments constitute personal data. If these are visible to anyone with access to a shared system, this poses a problem from a GDPR perspective in HR.

 

How does an ATS system help with GDPR compliance in HR?

An ATS system helps ensure GDPR compliance in HR by automating consent management , controlling access to personal data, keeping a record of how candidate data is handled, and facilitating its deletion once the specified retention period has expired. This reduces the risk of human error and simplifies compliance with GDPR obligations.

TIP: If you’re not yet sure what an ATS system is and what it can do, read our article What is an ATS and why do you need it for your recruitment?. And if you’re still in the process of choosing an ATS system, we also recommend our practical guide How to choose an ATS system .

If you’re looking for an ATS system that handles GDPR compliance in recruitment for you, Datacruit ATS automates the management of candidates’ consents , monitors access rights based on roles, and allows you to set up automatic data deletion once the retention period has expired. All data remains within the system’s secure environment. You can find an overview of everything Datacruit can help you with here .

 

Do you want to keep GDPR compliance in recruitment under control? Try Datacruit for free

If you currently manage candidates via email, Excel or shared folders, complying with the GDPR tends to be unnecessarily complicated and prone to errors . A modern ATS system helps you keep personal data under control, automate consent management, manage access to data and simplify compliance with data protection obligations.

Try Datacruit free for 30 days or book a no-obligation online demo. Using specific examples, you’ll see how you can simplify candidate management and set up recruitment processes so that they’re clearer, more efficient and GDPR-compliant.

Try Datacruit for free   Get a no-obligation consultation

Podobné
články

System Datacruit is brought to you by Seyfor