GDPR in recruiting
Also called:GDPR for hiring, DSGVO for recruiting
The four rules that matter most in recruiting
GDPR is wide. The parts that touch recruiting day-to-day:
- Lawful basis: every candidate’s data has a documented basis for processing. For applicants, it’s “necessary for steps before entering a contract.” For talent pool members, it’s consent as the working default (only France’s CNIL accepts information plus a right to object instead, capped at two years).
- Data minimisation: collect only what the role requires. No date of birth on an application form unless the role legally requires it.
- Retention limits: candidate data has a stated retention period (typically 6-12 months after the search closes for rejected candidates, longer with consent). There is no EU-wide statutory number behind that practice; it anchors to national discrimination-claim windows.
- Candidate rights: right to access, right to delete, right to rectify. Build the workflow for these requests, don’t improvise on first contact.
Where SMBs commonly trip
The frequent failures:
- Pool members with no consent. Sourcing someone, having a call, putting them in the talent pool — without a recorded “may I keep your data for X months” consent. Technically a breach.
- Indefinite retention. “We keep all applications forever in case a future role opens.” Not GDPR-compliant.
- Required fields with no purpose. Date of birth, marital status, photo (in some markets) collected by default. Each requires a justified purpose.
What “consent” actually requires
Consent in GDPR is specific, informed, freely given, and withdrawable. A pre-ticked checkbox is not consent. A clause in a 30-page T&C is not consent. The clean pattern: a clear, short, separate consent at the moment data leaves the immediate hiring use case.
Where Join fits
Join records consent timestamp and basis per candidate, applies retention windows by configuration, and surfaces deletion-request workflows. See the privacy policy for how Join handles candidate data.
Frequently asked questions
How long can we keep a rejected candidate's CV?
The GDPR itself sets no fixed period; data may be kept no longer than its purpose requires. In practice, teams keep the hiring record through the window in which a rejected candidate could bring a discrimination claim, which varies by member state. France's CNIL advises a maximum of two years after the last contact unless the candidate formally agrees to longer. Pick a window on advice, state it to candidates, and apply it automatically.
Do talent pools need consent?
Treat consent as the default. An application only covers the role the candidate applied to, so a pool is a new purpose needing its own basis — and consent that is informed, specific, and freely given is the only one that works EU-wide. France is the notable exception: the CNIL accepts keeping an unsuccessful candidate's file for up to two years if the person is informed and can object. A pre-ticked box never qualifies, and withdrawing must be as easy as agreeing was.
Who is the controller when we use an ATS?
The employer. You decide why candidate data is processed and what happens to it, so you remain the controller; the ATS acts as your processor, on documented instructions, under a data processing agreement per Article 28. Candidate requests such as access or erasure are addressed to you, and the processor's job is to make answering them possible within the deadline.

