← Back to glossary index

Recruitment Glossary

GDPR compliance

GDPR compliance in recruitment means handling personal data in line with the European Union General Data Protection Regulation and the laws that apply it. Recruitment records can include identity, contact, employment, assessment, interview, communication, equality, health, background, and inferred data, so compliance must cover the full lifecycle rather than a consent checkbox.

Recruiter Focus

Recruiters need a defined controller and processor model, lawful purpose and legal basis, clear privacy information, data minimisation, secure access, retention and deletion rules, rights-handling routes, vendor controls, breach procedures, and governance for sensitive data, international transfers, monitoring, and automated decisions. Local advice is necessary because the EU GDPR, UK GDPR, and other privacy regimes are not interchangeable.

Why GDPR compliance Matters

Candidates cannot participate meaningfully if they do not understand who uses their information and why. Poor controls can expose sensitive histories, retain unsuccessful applicants indefinitely, repurpose profiles without justification, deny statutory rights, or allow an opaque tool to affect employment without suitable safeguards.

Terms Recruiters Commonly Compare

Consent

Consent is one possible legal basis under defined conditions; it is not a synonym for GDPR compliance. Recruitment processing may use another basis, and all other principles and rights still apply.

Data security

Security protects confidentiality, integrity, availability, and resilience. GDPR compliance also includes fairness, transparency, purpose limitation, minimisation, accuracy, retention, rights, and accountability.

UK GDPR

The UK GDPR is part of the United Kingdom’s post-EU data-protection framework. It closely reflects the EU GDPR but is a separate regime with UK institutions and amendments, so territorial scope must be checked.

Recruitment Example

An EU employer introduces a CV-parsing and ranking service. Before launch it documents purposes and lawful bases, reduces fields, assesses automated-decision and bias risks, completes vendor and transfer checks, updates the candidate notice, restricts access, sets deletion rules, establishes human review, and gives candidates a route to exercise rights or challenge an outcome.

A practical recruitment data map

A data map makes accountability operational. It should follow information from first discovery or application through assessment, sharing, placement, talent-pool use, reporting, archive, and deletion.

  • Who collected the information and whether it came directly from the candidate
  • Why each field is needed and the lawful basis for that purpose
  • Which internal roles, clients, suppliers, and countries receive it
  • When the record is reviewed, corrected, restricted, archived, or deleted
  • Who handles rights requests, incidents, objections, and automated-decision challenges

Implementation Playbook

  • Create a recruitment data map covering collection source, field, purpose, legal basis, user, system, recipient, location, retention, and deletion owner.
  • Give privacy information at the appropriate time, including when personal data was obtained from another source.
  • Collect only information necessary for the current stage and apply additional controls to special-category and criminal-offence data.
  • Use role-based access, secure transfer, audit records, tested incident response, and reliable deletion across primary systems and exports.
  • Put processor instructions, confidentiality, security, subprocessor, assistance, return or deletion, and audit obligations into vendor agreements.
  • Assess high-risk technology and automated decision-making before deployment, with meaningful human review and an accessible challenge route.
  • Train recruiters to recognise access, correction, objection, restriction, portability, erasure, and complaint requests and route them promptly.

Common Mistakes

  • Using consent as the default basis for every recruitment activity without assessing whether it is freely given and appropriate.
  • Keeping every candidate forever because they might suit a future vacancy.
  • Assuming a vendor’s compliance statement transfers the organisation’s controller responsibilities.
  • Exporting CVs, interview notes, or diversity information to personal devices and uncontrolled spreadsheets.
  • Treating a recruiter’s opinion, inferred score, or public-profile research as outside data-protection law.

Metrics to Track

Candidate rights requests completed on time Records deleted under schedule Vendor reviews current Recruitment data incidents

Questions Recruiters Ask

Do recruiters always need candidate consent under GDPR?

No. The organisation must identify an appropriate legal basis for each purpose. Consent is valid only when its specific conditions are met and may be unsuitable where there is a power imbalance or no genuine choice.

How long can candidate data be retained?

There is no universal recruitment period. Set and justify periods by purpose, legal need, limitation periods, candidate expectation, and local requirements, then make deletion effective in connected systems and exports.

Can recruiters keep a CV for future vacancies?

Potentially, if the organisation has a valid purpose and legal basis, tells the person clearly, offers relevant rights, limits access and duration, keeps information accurate, and removes it when no longer needed.

Does GDPR apply to a recruitment agency and its client?

It can apply to both. Their roles may be separate or joint controllers for some activities, with processors supporting them. Responsibilities follow actual decisions about purposes and means, not a label in a generic contract.

Sources and Review

ATZ CRM Recruitment Editorial Review · Reviewed 2026-08-05

Put GDPR compliance Into Practice with ATZ CRM

Use ATZ CRM to convert glossary concepts into daily recruiter workflows with sourcing pipelines, automation, scorecards, and reporting built for staffing and recruitment teams.