ResumeWorld

Compliance & ethics9 min read

GDPR for Recruitment Data: What You Can Keep, and For How Long

Applicant data is personal data. What lawful basis applies to hiring, how long you may keep rejected candidates, and why consent is usually the wrong choice.

RWThe Resume World Team
9 min read
GDPR for Recruitment Data: What You Can Keep, and For How Long — Resume World

General guidance, not legal advice. Retention periods and limitation periods vary by jurisdiction; confirm yours with counsel.

A resume is dense personal data — name, contact details, employment history, education, often nationality or work authorisation, sometimes health or disability information volunteered in an adjustments question. Recruitment is one of the higher-risk processing activities most organisations run, and it is frequently among the least governed.

The instinct is to ask candidates to tick a box. In recruitment this is usually the wrong choice, for two reasons.

Consent must be freely given. Regulators have consistently taken the view that the imbalance between an employer and a job applicant undermines this. An applicant does not feel free to refuse.

Consent can be withdrawn at any time. If your basis is consent and a candidate withdraws it mid-process, you must stop processing — including the processing needed to evaluate the application they submitted.

The two bases that fit better:

Necessary for steps prior to entering a contract, at the data subject's request. Someone applying for a job is asking you to take steps toward a possible employment contract. Clean fit for processing the live application.

Legitimate interests. Broader, and the usual basis for keeping data after the decision — for a talent pool, or to defend a potential claim. It requires a documented balancing test weighing your interest against the candidate's rights, and candidates must be able to object.

Consent remains appropriate for genuinely optional extras: joining a talent pool, being contacted about unrelated future roles, keeping data beyond your standard retention period.

Retention: pick a period and enforce it

GDPR does not specify a number. It requires that you keep data no longer than necessary and can justify the period.

A defensible structure:

DataTypical periodReasoning
Unsuccessful applicant6–12 months post-decisionLimitation period for discrimination claims
Talent pool (opted in)12–24 months, then re-consentBeyond this the data is stale anyway
Successful hireMoves to employee recordDifferent basis, different schedule
Interview notes and scoresSame as applicant recordPart of the decision evidence
Assessment resultsSame as applicant recordSame

Two implementation points matter more than the numbers:

Deletion must be automatic. A policy that depends on someone remembering is not a retention policy. If your system cannot enforce a schedule, that is a procurement question — ask it before you buy. See choosing screening software.

Deletion must be real. Confirm whether your vendor's delete is an actual erasure or a hidden flag, and whether it propagates to backups on a defined cycle. Ask, and get the answer in writing.

Article 22 and automated rejection

This is where recruitment technology and data protection meet directly.

Article 22 gives individuals the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Rejection from a job generally clears the "similarly significant" bar.

"Solely" is the operative word. The standard route to staying outside the restriction is meaningful human involvement — and regulators have been clear that this means genuine review by someone with the authority and the information to reach a different conclusion. A recruiter clicking through a ranked list without seeing why anyone scored as they did is not meaningful involvement, whatever the process diagram says.

Practically:

  • Keep a human in every rejection that a human would recognise as a rejection.
  • Give that human the reasoning, not just the score.
  • Record that the review happened, and what was decided.
  • Where you rely on automation more heavily, provide the safeguards: information about the logic involved, and a route to contest.

This aligns closely with what the EU AI Act and NYC Local Law 144 require, which is convenient — one control satisfies several regimes.

Candidate rights you will actually receive

Access. A candidate may request everything you hold on them. This includes interview notes and screening scores. Interviewers who write things they would not want read back should be told this — once, clearly, and preferably before the first interview.

Erasure. Not absolute, but strong once a process has concluded and you have no continuing basis. If you are relying on legitimate interests to retain, be ready to state that interest.

Rectification. Usually trivial — a corrected date or title.

Objection. Where you rely on legitimate interests, a candidate may object, and you must stop unless you can show compelling grounds that override their rights.

Have a route for these that does not depend on the recruiter who happens to receive the email. A single monitored address and a documented process is enough for most organisations.

Special category data

Some of what arrives in a resume is special category data — health, disability, religion, trade union membership — often volunteered without being asked. Diversity monitoring and adjustment requests bring it deliberately.

Two rules: separate it from the assessment record so it plays no part in the decision, and apply a stricter basis and shorter retention. Diversity monitoring data should be aggregated and detached from individual records as soon as it can be.

A short baseline

  1. Publish a candidate privacy notice, and link it from the application form itself.
  2. State your lawful basis, and document the balancing test where it is legitimate interests.
  3. Set retention periods, and enforce them automatically.
  4. Keep meaningful human review in every rejection.
  5. Give candidates a working route to exercise their rights.
  6. Confirm vendor hosting region, retention behaviour, deletion semantics, and whether applicant data trains shared models — in writing.
  7. Keep special category data out of the assessment record.

None of this is expensive. Most of it is a decision, written down, and a setting configured once.

Frequently Asked Questions

Common inquiries regarding this topic.

Usually legitimate interests, or necessity for steps taken at the request of the data subject prior to entering a contract. Consent is generally a poor fit in recruitment because of the imbalance of power between employer and applicant, and because consent can be withdrawn at any time — which would leave you unable to process an active application.

RW

The Resume World Team

Verified

Product & hiring research, Resume World

About Engine

We build the screening engine behind Resume World. Everything here comes out of working on resume parsing, scoring and hiring workflows day to day — including the parts that turned out harder than expected.

ResumeWorld Intelligence

See more than just keywords.

Resume World extracts verifiable evidence from every applicant against role criteria and delivers an explained, ranked shortlist. 100% free to start with zero card required.

Related Research

Keep reading in this cluster