What does GDPR require from an ATS in 2026?
GDPR-compliant ATS use in 2026 requires: (1) explicit, granular consent for data processing at application time; (2) retention periods tied to legitimate purpose (typically 6 months for unsuccessful candidates, 2 years for talent pool with re-consent); (3) functional Subject Access Request (SAR) tooling that exports all candidate data within 30 days; (4) right to erasure within 30 days of request; (5) EU data residency or valid Standard Contractual Clauses; (6) audit logs for every data access. Fines up to €20M or 4% of global turnover apply for breaches.
- Standard candidate retention
- 6 months (unsuccessful) · 2 years (talent pool)
- SAR response window
- 30 days
- Maximum GDPR fine
- €20M or 4% global turnover
- Data residency requirement
- EU servers OR valid SCCs
- Required audit logs
- Every data access + every export
The Infrastructure vs Process Gap
Here is the misunderstanding that causes the most compliance problems: an ATS vendor that is “GDPR compliant” means the vendor’s own systems meet GDPR requirements. It does not mean your use of those systems is automatically compliant. The distinction between infrastructure compliance and process compliance is where most companies are exposed.
Your ATS vendor is responsible for: storing data securely on appropriately located servers, signing a Data Processing Agreement with you as required by Article 28 GDPR, ensuring that deletion requests to the platform system actually delete data from all stores, providing you with the tools to manage consent, retention periods, and subject access requests.
Your company is responsible for: capturing valid consent at the point of application, setting and enforcing data retention periods, responding to Subject Access Requests within 30 days, ensuring you are not processing candidate data beyond the purpose for which it was collected, training your HR team on what they can and cannot do with candidate data, and documenting your processing activities in a Record of Processing Activities (ROPA).
An ATS that is GDPR-native, built specifically with EU compliance architecture from the start, provides better tooling for the process side. But no ATS vendor can make your HR processes compliant; they can only provide the infrastructure and tools that make compliance achievable.
What GDPR Actually Requires for Candidate Data
Lawful basis for processing
You need a documented lawful basis for processing each candidate’s data. For direct applicants (people who responded to your job posting), the lawful basis is typically consent (captured at application) or legitimate interest (pursuing a business purpose). For sourced candidates (people your team identified and reached out to), the lawful basis is almost always legitimate interest. The lawful basis must be determined before processing starts and must be documented.
Consent capture at application
Your application form must present a privacy notice before or during the application, explain what data is collected and why, identify who data is shared with (including your ATS vendor), state how long data will be retained, and explain how candidates can exercise their rights. The candidate must actively confirm consent, a pre-ticked checkbox does not constitute valid consent under GDPR. The consent action must be timestamped and stored in a retrievable audit trail.
Data retention limits
Candidate data cannot be retained indefinitely. Common retention practices: 6 months for unsuccessful applicants who were not interviewed, 12 months for candidates who reached an interview stage, up to 24 months for candidates added to a talent pool who gave explicit consent for longer retention. These are guidelines, your specific retention periods should be documented in your privacy notice and enforced automatically by your ATS’s retention workflow, not managed manually.
Right to erasure
When a candidate requests deletion of their data, you must comply, typically within 30 days. The deletion must be genuine: all personal data fields removed from all data stores, including email logs, application records, and backups (typically within one backup cycle). The distinction between anonymisation and genuine deletion matters here: anonymisation leaves a record but removes identifying fields; genuine deletion removes the record entirely. Article 17 GDPR requires genuine deletion in most circumstances.
Subject Access Requests
A candidate can request all personal data you hold on them under Article 15 GDPR. You have 30 days to respond. The response must include all data you hold, the purposes of processing, who data is shared with, the retention period, and information about their rights. Your ATS should make it possible to export a complete candidate data package in response to a SAR in minutes, not hours.
Data residency and transfer restrictions
Data stored on servers outside the EU/EEA requires a transfer mechanism. EU data residency eliminates this requirement. If your ATS stores data in the US, verify the legal basis for the transfer, typically Standard Contractual Clauses or the EU-US Data Privacy Framework (adopted 2023, but historically challenged).
GDPR Enforcement in Recruitment: What the Fines Data Shows
GDPR enforcement against companies handling candidate and employee data has accelerated sharply. As of early 2026, EU regulators have issued over 2,800 fines totalling more than EUR 7.1 billion in penalties since May 2018, with 193 fines worth EUR 360.9 million targeting the employment sector specifically. The pace has increased: more fines were issued between January 2023 and March 2026 than in the preceding five years combined, and EUR 1.2 billion in penalties landed in 2025 alone, a 22% year-over-year increase.
The largest individual fines relevant to how companies handle people data illustrate the range of exposure. LinkedIn was fined EUR 310 million in October 2024 by the Irish Data Protection Commission for unlawful reliance on legitimate interest and contract performance to process member data for behavioural advertising. Uber received a EUR 290 million penalty in July 2024 for transferring driver and customer data to the US without adequate safeguards. Clearview AI has accumulated over EUR 30 million in fines across multiple EU jurisdictions for scraping biometric data without consent.
For hiring teams and ATS buyers, the enforcement pattern reveals three recurring gaps that regulators cite in decisions: no documented lawful basis for processing sourced candidates, retention periods set in policy but not enforced by any automated mechanism, and Subject Access Requests handled manually with incomplete data exports. The first two gaps are process failures; the third is a tooling failure. Both categories are addressable at the ATS selection stage.
Data breach notifications across Europe reached 443 per day in 2025. While not all involve candidate data, breaches involving recruitment systems are reportable within 72 hours to the relevant supervisory authority under Article 33 GDPR. An ATS without robust access logging makes the required notification harder to produce accurately and on time.
Article 30 ROPA: The Documentation Obligation Most ATS Buyers Overlook
Article 30 of the GDPR requires every controller to maintain a Record of Processing Activities (ROPA) - a documented inventory of every data processing activity the organisation runs. Recruitment is a mandatory entry. The Irish Data Protection Commission's guidance specifies that for recruitment processing, the ROPA entry must include: the purposes of processing, the lawful basis, the categories of data subjects (applicants, sourced candidates, referral contacts), the categories of personal data collected (name, CV content, assessment scores, interview notes), the recipients of data (hiring managers, external assessors, background check providers), the retention period, and the technical and organisational security measures in place.
Most companies treat the ROPA as a one-time legal exercise rather than a living document. Regulators have treated it differently: most CNIL sanctions in 2024-2025 cited ROPA gaps as an aggravating factor in fine calculations. A ROPA that does not reflect current processing - because a new ATS was added, a data processor changed, or a new recruitment channel was opened - is treated as evidence of inadequate data governance, not merely an administrative oversight.
What your ATS affects in the ROPA is substantial. When you change ATS vendors, every field in your recruitment ROPA entry potentially changes: the data processor (the ATS vendor), the sub-processors the vendor uses (cloud infrastructure, email delivery), the data residency location, the deletion mechanism, and the retention workflow. GDPR best practice requires updating the ROPA immediately on vendor change and reviewing it at minimum annually. An ATS that provides a transparent sub-processor list and signed DPA reduces the time cost of keeping your ROPA accurate.
Platform Comparison: GDPR Compliance Capabilities
| Platform | EU Data Residency | Genuine Deletion | Consent Capture | Auto Retention |
|---|---|---|---|---|
| Treegarden | Native (all plans) | Yes, full deletion | Built-in, timestamped | Configurable workflows |
| Pinpoint | EU residency option | Yes | Built-in | Available |
| Greenhouse | EU option (higher tiers) | Anonymisation default; deletion available | GDPR tools available | Configurable |
| Workable | EU option (higher plans) | Available | GDPR consent available | Available |
| Lever | Primarily US-based | Available | GDPR tools available | Limited |
GDPR ATS Evaluation Checklist
Before selecting an ATS for a company with EU hiring, verify each of these with the vendor:
- ☐ Where is candidate data stored? (EU servers preferred for EU companies)
- ☐ Can individual candidates be permanently deleted from all stores, including backups and email logs?
- ☐ Is GDPR consent captured at the point of application with a timestamp?
- ☐ Does the consent record store the privacy notice version shown to the candidate?
- ☐ Are automated data retention workflows available with configurable periods?
- ☐ Can you export a complete candidate data package for Subject Access Request response in under 10 minutes?
- ☐ Is there a signed Data Processing Agreement available without requiring a separate legal process?
- ☐ Are there re-consent workflows for dormant candidates approaching retention expiry?
- ☐ Can candidates access their own data through a self-service portal?
- ☐ Are audit trails of all data processing actions available for regulatory inspection?
The EU AI Act Adds a Second Compliance Layer for ATS Buyers
From 2 August 2026, any ATS that uses AI features to screen, rank, filter, or shortlist candidates falls into the EU AI Act's high-risk category under Annex III, Category 4. This covers CV parsers that score candidates, resume ranking algorithms, and automated shortlisting tools. The classification applies to the organisation deploying the tool (the employer), not just the vendor building it.
The practical implications for companies using an ATS with AI features are significant. From August 2026, deploying organisations must: conduct a conformity assessment of the AI system before use, maintain technical documentation of how the AI makes decisions, ensure a human reviews and can override every AI-assisted hiring decision, inform candidates that automated processing is being used and how, and retain logs of the AI system's outputs for a minimum of six months. These are obligations on the employer, not just the ATS vendor.
A smaller set of AI uses in hiring are already prohibited as of 2 February 2025 under the AI Act's unacceptable risk provisions: emotion recognition in candidate interviews or video assessments, AI systems that infer protected characteristics from biometric data, and predictive social scoring of candidates based on their online behaviour. Any ATS vendor offering these features cannot lawfully deploy them for EU hiring.
The connection to GDPR is direct. The AI Act's transparency requirements - informing candidates that automated processing is used and explaining the logic - overlap substantially with GDPR's Article 22 obligations on automated decision-making. Candidates have the right under Article 22 to not be subject to purely automated decisions that significantly affect them, the right to obtain human review, and the right to an explanation of the decision logic. An ATS that provides AI-assisted scoring without human review, without candidate disclosure, and without a documented basis for the algorithm is potentially in breach of both regimes simultaneously.
When evaluating an ATS, ask specifically: which features use AI or machine learning, are those features subject to the AI Act's high-risk category, what documentation does the vendor provide for conformity assessments, and does the vendor's roadmap reflect August 2026 compliance requirements. The answers separate vendors who are tracking EU regulatory developments from those who are not.
Treegarden’s GDPR Architecture
Treegarden was built as an EU-first platform. EU data residency is not a configuration option, it is the default. All candidate data is stored on servers within the EU. Genuine deletion (not anonymisation) is available from all plans. Consent capture with timestamping is built into the application form. Automated retention workflows are configurable. Data Processing Agreements are available immediately upon account creation. Candidate portals for self-service access to their own data are supported.
The practical significance: a Treegarden customer who receives a Subject Access Request from a candidate can generate a complete data export within minutes. A Treegarden customer who receives a deletion request can delete all candidate records with a single action and confirm the deletion with an audit trail. These are not edge cases, GDPR requests from candidates are a normal part of operating in the EU hiring market, and the time cost of handling them manually on a non-GDPR-native platform is non-trivial.
GDPR-native ATS for EU companies
EU data residency. Genuine deletion. Consent capture. Built in from day one. Startup $299/mo equivalent · Growth $499/mo equivalent · Scale $899/mo equivalent.
Book a demo →Frequently Asked Questions
What GDPR requirements apply to candidate data in an ATS?
The key GDPR requirements for candidate data are: a documented lawful basis for processing (Article 6), purpose limitation, data minimisation, storage limitation with enforced retention periods, right of access for Subject Access Requests within 30 days (Article 15), right to erasure with genuine deletion capability (Article 17), and data transfer restrictions for data moved outside the EU. Your ATS vendor handles infrastructure compliance; your HR team handles process compliance using the vendor’s tools.
Does EU data residency matter for GDPR ATS compliance?
EU data residency means candidate data is stored on servers within the EU, subject to EU jurisdiction, eliminating the need for a separate data transfer mechanism. It matters because transfers outside the EU require a valid legal basis (SCCs or adequacy decision) that can be legally challenged. EU data residency removes this transfer risk entirely. Treegarden stores all candidate data on EU servers by default.
What is the difference between anonymisation and deletion in an ATS?
Anonymisation replaces identifying fields with non-identifying values while keeping the record for analytics; deletion removes all records from all stores including backups. The GDPR right to erasure (Article 17) requires genuine deletion in most circumstances, not just anonymisation, when a candidate exercises deletion rights. Ask your ATS vendor specifically whether deletion removes personal data from all systems including analytics databases and backup systems.
How should an ATS handle GDPR consent capture for candidates?
Valid GDPR consent must be freely given, specific, informed, and unambiguous. This means your application form must show a privacy notice before or during application, require an active opt-in (no pre-ticked boxes), timestamp the consent with the privacy notice version, store the consent record retrievably, and support re-consent workflows when the privacy notice changes materially. An ATS that handles this correctly records consent timestamps that can be produced for regulatory audit.