What GDPR Means for Recruiting
The General Data Protection Regulation (GDPR) fundamentally changed how organizations handle personal data, including candidate information. Even if you're not based in the EU, GDPR likely affects you if you recruit EU residents.
Non-compliance risks are significant: fines up to 4% of global revenue or EUR 20 million, whichever is higher.
Key GDPR Principles for Recruiting
Lawful Basis for Processing
You need a legal basis to process candidate data:
Legitimate Interest: Most common for recruiting
- You have a genuine need to process data
- It's necessary for that purpose
- Candidate rights don't override your interest
Consent: Sometimes required
- Must be freely given, specific, informed
- Candidates can withdraw at any time
- Cannot be a condition of application
Data Minimization
Only collect what you need:
- Essential contact information
- Relevant qualifications
- Job-related history
- Nothing excessive or unnecessary
Purpose Limitation
Use data only for stated purposes:
- Recruiting for the specific role
- Legitimate related purposes
- Not for unrelated marketing
- Not sold to third parties
Storage Limitation
Don't keep data forever:
- Define retention periods
- Delete when no longer needed
- Document your retention policy
- Honor deletion requests
Accuracy
Keep data correct and current:
- Allow candidates to update information
- Correct errors promptly
- Don't make decisions on outdated data
Security
Protect candidate data:
- Technical safeguards
- Access controls
- Encryption
- Breach response plans
Practical Compliance Steps
1. Audit Your Current Practices
Understand what you're doing now:
- What data do you collect?
- Where is it stored?
- Who has access?
- How long do you keep it?
- What's your legal basis?
2. Update Your Privacy Notice
Candidates must be informed:
- Who you are (controller identity)
- What data you collect
- Why you collect it (purposes)
- Legal basis for processing
- Who you share data with
- How long you keep it
- Their rights
- How to complain
3. Implement Consent Mechanisms
Where consent is required:
- Clear, affirmative action
- Separate from other terms
- Easy to withdraw
- Documented
4. Establish Retention Policies
Define how long you keep data:
- Active candidates: Duration of process
- Unsuccessful candidates: 6-12 months typical
- Talent pools: With consent, defined period
- Hired employees: Transition to HR retention
5. Enable Data Subject Rights
Candidates can:
Access: Request copy of their data Rectification: Correct inaccuracies Erasure: Request deletion ("right to be forgotten") Restriction: Limit how data is used Portability: Receive data in usable format Object: Opt out of processing
You must respond within 30 days.
6. Secure Your Data
Implement appropriate measures:
- Access controls (who can see what)
- Encryption (data at rest and in transit)
- Pseudonymization where possible
- Regular security assessments
7. Manage Third Parties
Vendors who process candidate data:
- Must have Data Processing Agreements
- Must provide adequate safeguards
- You remain responsible for their compliance
Common Recruiting Scenarios
Talent Pools
Keeping candidates for future opportunities:
- Get explicit consent
- Be clear about the purpose
- Set a retention period
- Allow easy opt-out
- Refresh consent periodically
Employee Referrals
When employees refer candidates:
- Candidate must be informed
- Can't be added to systems without knowledge
- Referrer isn't the data controller
Social Media Sourcing
Using LinkedIn, etc.:
- Publicly available doesn't mean freely usable
- Contact must include privacy information
- Respect opt-out requests
- Don't scrape or store excessively
Background Checks
Additional requirements:
- Explicit consent typically required
- Clear about what's being checked
- Proportionate to the role
- Secure handling of results
International Transfers
Sending data outside EU:
- Adequacy decisions (some countries approved)
- Standard Contractual Clauses
- Binding Corporate Rules
- Other approved mechanisms
Documentation Requirements
Maintain records of:
- Processing activities
- Consent obtained
- Privacy notices provided
- Data subject requests and responses
- Data breaches and actions taken
- Third-party agreements
Breach Response
If candidate data is compromised:
- Contain the breach immediately
- Assess the risk to candidates
- Report to supervisory authority within 72 hours (if required)
- Notify affected candidates (if high risk)
- Document the incident and response
Training Your Team
Everyone handling candidate data needs to understand:
- Basic GDPR principles
- What data they can access
- How to handle requests
- When to escalate
- Security practices
Common Mistakes to Avoid
- Assuming GDPR doesn't apply: If you recruit EU residents, it does
- Keeping data forever: Define and enforce retention periods
- Ignoring subject requests: You must respond within 30 days
- Inadequate privacy notices: Be clear and comprehensive
- Unsecured data sharing: Protect candidate information
AcquireTM is designed with GDPR compliance built in, including consent management, retention policies, and data subject request handling. Learn more.


