Recruitment software can help you manage GDPR, but it cannot take responsibility for your hiring data. We recommend setting clear rules for data use, access and deletion before configuring your tools. That gives your team more control and helps reduce manual cleanup, hiring disruption and avoidable costs.
Our approach covers:
- Clear ownership: Assign responsibility for candidate data across your team and providers.
- Data rules: Document lawful use, privacy notices, retention periods and rights requests.
- Tool checks: Test security, AI screening, human review and deletion controls.
- Provider oversight: Check contracts, data transfers and access for embedded recruiters.
- Regular reviews: Keep records, train staff and test incident response and recovery.
Start with your hiring process, then check that every tool and provider supports it.

GDPR Compliance in Recruitment: Five Control Areas
Candidate journey map and GDPR
sbb-itb-a23bd6a
Set Rules for Lawful Processing, Notices, and Retention
Once responsibility is assigned, turn your obligations into written rules for each hiring workflow.
Before configuring workflows, document each activity’s purpose, required data, and retention period. Keep separate entries for CV parsing, matching, and interview scheduling when they serve different purposes. Then set required fields and controls to reduce duplicate records [3]. Good data hygiene stops unnecessary records from building up [1][2].
Choose a Lawful Basis for Each Hiring Activity
Assign a lawful basis to each hiring activity, record it in your hiring system, and limit processing to the stated purpose. For AI-supported tasks, define exactly what the tool does and keep human review in the process [3].
| Activity | Records to keep | What candidates need to know |
|---|---|---|
| Applications | Role and suitability criteria | How application data informs assessment |
| Sourcing | Data source and reason for contact | Why they were contacted |
| Talent pools | Scope of future use and review dates | How they may be considered for future roles |
| CV parsing, matching, and scheduling | Tool function and human-review record | Which AI tools are used and what they do [3] |
Set Up Privacy Notices and Retention Schedules
Your candidate notice and retention policy should reflect the processing rules you’ve set.
Privacy notices should explain how you use candidate data, which AI tools are involved, candidate rights, retention periods, security controls, and transfer safeguards. Include contact details for both your company contact and the data protection authority [3].
Set retention schedules in your system, rather than leaving deletion to individual recruiters. Use separate schedules for applications, interview notes, and talent-pool records so data is not kept longer than necessary. Automate deletion where possible and review the schedules regularly [1][2][3].
Manage Candidate Rights Requests
Clear notices and retention rules help your team handle rights requests faster.
Your recruitment systems should support access, correction, deletion where permitted, and human review of AI-supported decisions. Keep decision logs so recruiters can explain how a tool supported a hiring outcome [3].
| Candidate right | System capability needed | Responsible staff | Record kept |
|---|---|---|---|
| Access | Search and export data across connected systems | Recruiter and administrators | Search scope, disclosures, response date |
| Rectification | Correct data and update related records | Recruiter and administrators | Changes and recipient notifications |
| Erasure | Delete eligible records across systems | Recruiter and administrators | Deletions and retention reasons |
| Human review / explanation | Review AI-supported outcomes and allow challenges where applicable | Authorized reviewer | Decision details, outcome, response |
Assess Recruitment Tools, AI, and Providers
Test Security and Privacy Controls
Once you’ve set your lawful basis, notices, and retention rules, check that each tool can enforce them. ISO 27001 certification offers supporting evidence, but it cannot replace a company-specific audit of how the tool handles candidate data [1].
| Compliance goal | Capability to test | Verification step |
|---|---|---|
| Access control | Permissions and least privilege | Limit access to applications and interview notes to roles that need it. |
| Retention enforcement | Scheduled deletion | Confirm that expired candidate records are deleted on schedule. |
| Resilience | Disaster recovery | Test recovery of candidate records without restoring records deleted under retention rules or candidate deletion requests. |
| Accountability | Risk assessment | Document a risk assessment and address vulnerabilities affecting candidate data. |
Check Automated Screening and Sensitive Data Use
AI screening adds another layer of risk: model behavior and training data. Both can affect your hiring decisions.
Test models before launch and after changes. Run security and bias tests to check inaccurate inputs and biased screening outputs. Set strict access controls, and review how candidate data is stored, accessed, and shared.
Ask providers directly whether candidate data enters training datasets and how they control that use.
"As we explore the potential of AI, we are committed to safeguarding datasets from compromise." – Rent a Recruiter[2]
Review Provider Contracts and Data Transfers
Your contract must match the technical controls. Before signing, map where candidate data sits, which subprocessors handle it, and how it moves between locations. Audit subprocessors and confirm that their controls are documented.
Identify all international transfers, including access by U.S.-based support teams. Confirm the transfer mechanism for each recipient.
If you rely on EU-U.S. adequacy arrangements, check that the recipient’s certification is active and covers the data involved. If you use Standard Contractual Clauses, assess the transfer circumstances and any additional safeguards needed.
A U.S. address, EU hosting, or a certification badge alone does not complete your transfer review.
Manage GDPR Compliance in Daily Hiring
Once your policies and tool controls are in place, keep them current as hiring changes.
Assign Responsibilities and Keep Compliance Records
Give each privacy task a clear owner across leadership, IT, and recruiting.
Keep records of risk assessments, vendor reviews, training, deletion, and recovery tests. This helps your team spot control gaps before they turn into incidents.
Plan for Data Breaches and System Changes
Include incident response in your risk and recovery plans. Review those plans when hiring scales, systems change, or you switch providers.
Re-audit third-party tools when workflows change. Run recovery exercises to check that your team can maintain access and data integrity during disruption.
Delete candidate data you no longer need as early as possible. Update privacy and cyber awareness training when processes change.
Apply the same controls to embedded recruiters, who work inside your hiring team.
Set Privacy Rules for Embedded Recruiters
Rent a Recruiter places recruiters directly into an employer’s team. Your organization still owns GDPR and security controls.
Before granting access, conduct risk assessments, set tiered access permissions, and require recruiters to complete your security training. Keep candidate data in approved systems, with clear rules for storage, access, and sharing.
Conclusion: GDPR Compliance Checklist for Recruitment
Speed is not proof of compliance. Keep records that show risk assessments, vendor oversight, data cleanup, and disaster recovery tests for every recruitment system and vendor.
Check Controls at Each Hiring Stage
Before you launch or change a hiring process, check the controls already in place for each workflow, tool, and vendor. Assign a named owner and retain dated evidence for every check and open issue.
| Stage | Checks to complete | Owner / evidence |
|---|---|---|
| Planning | Map where data is stored, who can access it, and how it is shared. Record the risk assessment, remediation plan, and cleanup actions. | Privacy lead and hiring manager: risk assessment, remediation plan, cleanup notes. |
| System setup | Audit vendors and recruitment systems. Test security controls and document AI safeguards. | IT and privacy lead: vendor audits, security test results, AI safeguards. |
| Daily hiring | Monitor data storage and sharing. Keep security training current and log deletions. | Recruiting lead and privacy lead: training log, deletion records. |
| Provider reviews | Review vendor platforms for security and compliance. Update transfer records. | Procurement and privacy lead: audit findings, review notes, cross-border transfer records. |
| Offboarding or migration | Delete data you no longer need. Keep disaster recovery test records. | IT and contract owner: deletion confirmation, disaster recovery test records. |
FAQs
Does GDPR apply to my U.S.-based hiring team?
Yes. GDPR applies when U.S.-based hiring teams process EU residents’ personal data, regardless of where your company is headquartered [1]. Your team must meet requirements for collecting, storing, retaining, deleting, and transferring EU candidate data across borders [1].
You need clear data-handling processes and formal Data Processing Agreements, particularly when recruitment vendors also handle that data [1].
How long can I keep candidate data?
Under GDPR, candidate data should not be kept indefinitely. For unsuccessful candidates, retention typically ranges from 6 to 24 months.
Set fixed retention schedules and clear rules for renewing talent pool records. Your ATS or CRM should track deletion or anonymization when those periods expire, helping your team manage records without relying on manual checks.
Specific legal requirements, such as Colorado’s, may require you to retain certain records for up to three years. Align your internal data policies with the schedules that apply.
When does AI screening require a DPIA?
AI screening or scoring tools that rank, score, or filter candidates using automated logic require a Data Protection Impact Assessment (DPIA) before they go live. These tools can trigger concerns under Article 22, so you must complete the formal assessment before deployment. [1]



