Why GDPR Matters for Recruitment
Recruitment teams collect significant volumes of personal data as a matter of routine: CVs, cover letters, interview notes, reference check details, assessment results, and all the email correspondence that surrounds a hiring process. Under GDPR - and, in the UK, the retained version known as UK GDPR - this data is subject to strict rules about how it is collected, stored, used, and ultimately deleted.
The practical stakes are real. The Information Commissioner's Office (ICO) in the UK and data protection authorities across the EU have the power to investigate complaints, require remedial action, and impose fines for non-compliance. Beyond regulatory risk, poor data handling damages candidate trust, and candidate experience is increasingly a factor in employer reputation.
The good news is that GDPR compliance in recruitment is achievable with clear policies, the right processes, and an ATS that supports data management. This guide covers the key requirements HR teams need to understand, written for practical application rather than legal theory.
The Six Principles of GDPR Applied to Recruitment
GDPR is built on six core data protection principles set out in Article 5. Each has direct implications for how you run a hiring process.
| Principle | What it means in recruitment |
|---|---|
| Lawful, fair, and transparent | Tell candidates what you collect and why; have a valid legal basis for every processing activity. |
| Purpose limitation | Collect CV data to assess an application - do not repurpose it for marketing or share it beyond the hiring process without a separate basis. |
| Data minimisation | Only ask for what you need at each stage. Do not request date of birth, marital status, or other data that is irrelevant to assessing the application. |
| Accuracy | Keep records current; let candidates correct or update their details if they request it. |
| Storage limitation | Delete or anonymise candidate data when you no longer have a legitimate need to keep it. Do not accumulate CV databases indefinitely. |
| Integrity and confidentiality | Secure storage, role-based access controls, and no sharing of candidate data without a proper basis. |
Lawful Basis for Processing Candidate Data
Article 6 Lawful Bases
Before processing any personal data you must identify a lawful basis under Article 6 GDPR. Three bases are most relevant to recruitment:
Article 6(1)(b) - Pre-contractual necessity. This covers processing that is necessary for steps taken at the candidate's request prior to entering a contract. In recruitment terms, it applies once you are actively evaluating someone for a specific role. This is the appropriate basis for assessing an active application, scoring a CV, conducting interviews, and making a selection decision. It does not require you to obtain consent for these activities, but you must still be transparent through a privacy notice.
Article 6(1)(f) - Legitimate interests. This basis applies where your interests (or a third party's) are not overridden by the candidate's rights and interests. In recruitment, it is commonly used for retaining data of promising candidates who were not right for the current role but may suit a future one, and for talent pool databases where candidates have not specifically consented to future contact. Legitimate interests requires you to conduct a Legitimate Interests Assessment (LIA) documenting why your interest prevails and what safeguards you have in place.
Article 6(1)(a) - Consent. Consent can be used in recruitment, but the ICO's guidance notes that it is rarely the right basis for processing an active application because consent must be capable of being withdrawn at any time - which is unworkable mid-process. Consent is appropriate for specific, bounded purposes: for example, adding a candidate to an opt-in talent pool newsletter, or retaining their data for longer than your standard retention period with their explicit agreement.
Do You Need Consent to Process a Job Application?
No. For an active application to a specific role, Article 6(1)(b) - pre-contractual necessity - is the correct lawful basis. Consent is not required and, for the reasons above, is not recommended as your primary basis for standard recruitment processing. What you must do is provide a clear, accessible privacy notice at the point of application so candidates understand exactly how their data will be used.
Job Applicant Privacy Notice: What Must It Include?
Under Article 13 GDPR, you must provide a privacy notice to individuals at the point you collect their data. For recruitment this means including one within your application form, the job posting, or a clearly linked page on your careers site. A compliant job applicant privacy notice must cover all of the following:
- Identity and contact details of the data controller (your organisation)
- Contact details of your Data Protection Officer (DPO), if you have one
- The categories of personal data you collect
- The legal basis for each processing activity
- The retention period, or the criteria used to determine it
- Third parties you share data with (job boards, background check providers, agencies, interview panel members)
- Any international data transfers and the safeguards in place
- Candidates' rights: access, erasure, rectification, restriction, portability, and the right to object
- The right to lodge a complaint with the ICO (UK) or the relevant supervisory authority (EU)
Keep the notice readable. A privacy notice that candidates actually read and understand is more effective than a lengthy legal document that gets skipped. Many organisations provide a short summary at the point of application with a link to a full policy.
Retention Periods: How Long Can You Keep CVs?
GDPR does not specify a fixed number of months for recruitment data. The storage limitation principle requires you to keep data only for as long as necessary for the purpose for which it was collected - and to document your reasoning.
In practice, the following approaches are widely adopted:
Unsuccessful candidates - approximately six months after the recruitment process concludes is a widely cited benchmark in UK practice. This period covers the three-month window in which a candidate could bring an employment tribunal claim for discriminatory selection, plus some additional buffer. The ICO's employment practices guidance acknowledges this as a common approach, though it does not set it as a mandatory legal rule. It is best practice, not a statutory requirement.
Longer retention - up to twelve months may be justifiable if you recruit frequently for similar roles and can document a legitimate interest in retaining a pool of reviewed candidates. The justification should be recorded in writing.
Talent pool data - where candidates have explicitly opted in to be considered for future roles - is subject to different considerations. Many organisations set a twelve to twenty-four month window and send a periodic re-consent email to confirm the candidate still wants to be included. Whatever period you set, record it in your retention schedule and configure your ATS to enforce it.
The key discipline is distinguishing between the active pipeline (a current process) and the talent pool (future consideration), applying appropriate retention rules to each, and actually deleting or anonymising records when the period expires rather than allowing databases to accumulate indefinitely.
GDPR Article 22: AI and Automated Decision-Making in Recruitment
Article 22 GDPR gives individuals the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects on them. In recruitment, a fully automated rejection - where a system removes a candidate from consideration without any human review - would likely engage Article 22 and require either explicit consent, a specific legal basis, or another permitted exception.
The practical implication is straightforward: AI screening and matching tools should be advisory. They can rank, score, and prioritise candidates for human review, helping recruiters manage high application volumes efficiently. But the decision to progress or reject a candidate should always involve a human recruiter exercising genuine judgment. This is both the legally safest position and generally the most effective one - algorithmic scoring surfaces patterns, while human review catches context that an algorithm would miss.
Treegarden's AI matching is designed on this basis. Scores are advisory indicators to help recruiters focus their attention; they do not trigger automatic progression or rejection. The final call always belongs to the recruiter.
Disclose AI use in your privacy notice
If you use AI-assisted screening tools in your hiring process, best practice under GDPR and the ICO's guidance is to disclose this in your job applicant privacy notice. Candidates should know that their data may be processed by automated tools as part of the initial review, and that final decisions involve human assessment.
Candidate Rights in the Recruitment Context
Right of Access (Subject Access Request)
A candidate can request all personal data you hold about them. You have 30 days to respond (extendable by a further two months for complex requests, with notice to the requester). Your response must include everything relevant: the CV, interview notes, assessment scores, email correspondence, and any other records. You cannot omit notes on the grounds that they are unflattering - you must disclose what you hold. If you hold data in multiple systems (an ATS, email, shared drives, paper notes), all of those are in scope.
Right to Erasure
A candidate can ask you to delete their data. If you no longer have a legitimate need to keep it - for example, the recruitment process has concluded, no employment tribunal risk exists, and the candidate is not in a talent pool they consented to - you must comply. Your ATS should have a documented deletion workflow so that when a request comes in, the response is systematic rather than ad hoc. You should also confirm to the candidate in writing that deletion has been completed.
Right to Data Portability
Candidates can request their data in a structured, commonly used, machine-readable format. In practice this typically means a CSV or JSON export of their profile and associated records. Most modern ATS platforms can generate this export on request.
Sharing Candidate Data with Third Parties
Recruitment almost always involves sharing candidate data with third parties, and each sharing relationship must be managed carefully under GDPR.
Job boards and recruitment agencies may have their own data sharing agreements. Review these carefully - when a candidate applies via a job board, data may flow between multiple parties. Your privacy notice should identify the third parties involved.
Background check and reference check providers (such as DBS check companies or specialist verification services) receive candidate data as part of the screening process. You must have a Data Processing Agreement (DPA) in place with each of these providers, and candidates must be informed in your privacy notice that their data will be shared for these purposes. Reference contact generally requires the candidate's prior consent.
Interview panel members and hiring managers accessing candidate data within your organisation should do so through your ATS, with appropriate role-based access controls, rather than via forwarded emails or shared file links that create uncontrolled copies.
International transfers - if you use a background check company, ATS vendor, or other service provider based outside the UK or EEA, you must ensure an appropriate transfer safeguard is in place. For UK organisations, this means an adequacy decision, International Data Transfer Agreement (IDTA), or equivalent mechanism. The UK and EU have mutual adequacy decisions, so transfers between them are generally permissible.
Avoid informal data sharing
A common compliance gap is the circulation of candidate data outside your ATS: CV screenshots shared on messaging apps, profiles forwarded via personal email, interview notes saved on local drives. Each of these creates uncontrolled copies that are difficult to track, update, or delete. Centralising recruitment data in an ATS reduces this risk significantly.
UK GDPR vs EU GDPR Post-Brexit
From 1 January 2021, the UK operates under UK GDPR - a version of the EU regulation retained in UK law following Brexit, with the same core principles but with the ICO as the UK's supervisory authority rather than an EU data protection authority. The UK is no longer subject to the European Data Protection Board (EDPB).
For most recruitment purposes, UK GDPR and EU GDPR impose substantively the same obligations. The key practical difference for UK organisations is that the ICO is your regulatory point of contact, and complaints are directed there. Organisations operating in both the UK and EU need to comply with both regimes, since EU GDPR applies to the processing of EU residents' personal data regardless of where the controller is based.
The UK and EU have granted each other adequacy decisions, meaning that personal data can flow between the UK and EU/EEA countries without additional transfer mechanisms in most circumstances. This is a significant practical convenience for organisations recruiting across both jurisdictions.
GDPR-Compliant ATS Features to Look For
When evaluating an ATS for GDPR compliance support, look for the following capabilities:
- Built-in retention policies with the ability to auto-flag or schedule deletion of expired records
- A documented data deletion workflow that can be triggered on candidate request
- Consent tracking for talent pool opt-ins, with the ability to record and evidence consent
- A full audit log of data access, changes, and communications for each candidate record
- Privacy notice delivery integrated with the application process
- Data export functionality to respond to Subject Access Requests
- Role-based access controls so only authorised staff can view candidate data
- A Data Processing Agreement (DPA) available from the ATS vendor covering their processing of your candidates' data
How Treegarden Supports GDPR Compliance
Treegarden is built with recruitment data management in mind. Configurable retention settings let you define how long candidate records are kept by pipeline stage. Role-based access controls ensure that only the people who need to see a candidate's data can access it. The audit log records every action taken on a candidate record - who viewed it, what was changed, and when. Deletion workflows support prompt, documented responses to erasure requests. Data Processing Agreements are available for organisations that require them.
It is important to note that an ATS supports your compliance obligations - it cannot replace a proper GDPR policy, legal review of your lawful bases, or staff training. The tools create the infrastructure; your organisation's policies and processes must complete the picture.
Book a demo to discuss how Treegarden handles recruitment data compliance and see the retention, access control, and audit features in practice.
Frequently Asked Questions
How long can you keep a rejected candidate's CV under GDPR?
GDPR does not prescribe a specific number of months, but widely adopted best practice in the UK is to delete unsuccessful candidates' data approximately six months after the recruitment process concludes. This period is considered proportionate because it covers the three-month window for a candidate to bring an employment tribunal claim for discriminatory selection, plus a reasonable buffer. Some organisations retain data for longer - up to twelve months - particularly if they recruit for similar roles frequently and have documented legitimate interests for the retention. Whatever period you choose, it should be set out in a written retention policy, communicated to candidates in your privacy notice, and actively enforced (ideally by configuring your ATS to flag or delete records when the retention period expires). Simply leaving data indefinitely because no one has complained is not compliant.
Do you need consent to process a job application?
No. For an active application to a specific role, consent is not the correct lawful basis under GDPR. Article 6(1)(b) - processing necessary for the performance of pre-contractual steps at the data subject's request - covers the processing needed to assess and progress a job application. The ICO's guidance specifically notes that consent is rarely appropriate as a lawful basis in employment contexts because the candidate-employer relationship creates an imbalance of power, and withdrawal of consent would need to be honoured (which would be unworkable mid-recruitment). You do, however, need to be transparent: provide a clear privacy notice when candidates apply, covering what data you collect, why, how long you keep it, and their rights.
What should a job applicant privacy notice include?
Under Article 13 GDPR, you must provide a privacy notice to individuals at the point you collect their data. For recruitment, this means making it available within the application form, job posting, or a linked page. It must cover: who you are (data controller); your DPO contact if you have one; what data you collect; the legal basis for each processing activity; who you share it with (agencies, background check providers, hiring panel); how long you keep it; any international data transfers and safeguards; and the candidate's rights - including access, erasure, restriction, portability, and the right to complain to the ICO or relevant supervisory authority. Keep it concise and readable - a privacy notice that candidates actually read and understand is more effective than a lengthy legal document they skip.
Does GDPR Article 22 prevent using AI to help with recruitment screening?
Article 22 GDPR restricts decisions based solely on automated processing that produce legal or similarly significant effects - such as a job rejection made entirely by a machine with no human review. It does not ban AI in recruitment; it restricts fully automated consequential decisions without human oversight. In practice, this means AI screening and matching tools should be advisory: they can rank, score, and prioritise candidates for human review, but a human recruiter should always make the decision to progress or reject. This is both the legally safest approach and generally the most effective one - AI scoring helps recruiters manage high volumes, while human judgment catches things an algorithm misses. Always disclose the use of AI-assisted screening in your privacy notice.