Recruitment naturally requires information about candidates. But that does not mean an employer can collect any information that might be interesting or useful. Under the GDPR, applicant data must be relevant and necessary for the recruitment process.
The basic rule is simple: only collect what you genuinely need to assess the candidate and manage the application.
What information do employers normally need?
For most vacancies, an employer will need fairly standard information, such as:
- Name and contact details
- Employment history
- Education and qualifications
- Professional skills and experience
- Languages
- Information contained in a CV or cover letter
- Interview notes and assessments
- Availability and, where relevant, salary expectations
The exact information you need depends on the position.
A driving licence may be relevant for a delivery driver. It is probably not relevant for an office job where driving is never required.
This is the GDPR principle of data minimisation in practice.
Can you ask for any information that might help you choose?
No.
Recruitment can easily become a process of collecting information “just in case”. The GDPR requires a more disciplined approach.
Before requesting information, ask:
Do we genuinely need this information to assess whether the candidate is suitable for this position or to comply with a legal requirement?
If the answer is no, don’t collect it.
Be careful with sensitive information
Some personal data receives additional protection under the GDPR. This includes information about:
- Health
- Racial or ethnic origin
- Political opinions
- Religious or philosophical beliefs
- Trade union membership
- Genetic data
- Certain biometric data
- Sex life or sexual orientation
Processing this information generally requires an additional legal justification on top of one of the six legal bases.
In ordinary recruitment, employers should therefore avoid requesting sensitive information unless it is genuinely necessary and legally permitted.
Information about criminal convictions and offences is also subject to specific restrictions.
What about photographs?
A photograph is personal data when a person can be identified from it.
Before making a photograph mandatory, consider whether seeing the candidate is actually necessary for assessing their ability to perform the job.
In many recruitment processes, it is not.
Requiring unnecessary photographs can also increase the risk that irrelevant characteristics influence recruitment decisions.
What if candidates provide too much information themselves?
Candidates sometimes include information you never requested: marital status, children, hobbies, photographs, medical information or other private details.
You do not automatically need to use that information simply because the candidate supplied it.
Keep the recruitment decision focused on information relevant to the vacancy.
Can you collect information from other sources?
Applicant data does not always come directly from the applicant.
You may receive information from:
- Recruitment agencies
- Professional networking platforms
- References
- Public professional registers
- Assessment providers
- Background-check providers
The GDPR still applies.
You must have a lawful reason for collecting and using the information and, where required, tell the candidate that you obtained personal data from another source. Your candidate privacy notice is the natural place to explain this.
Design your application process around necessity
A useful exercise is to review every field in your application form.
For each question, ask:
- Why do we ask this?
- Do we actually use the answer?
- Is it necessary at this stage?
- Could we request it later if the candidate is selected?
Information needed to prepare an employment contract, for example, belongs at the offer stage rather than on the application form every candidate fills in.
Document what you collect and why
Do not decide what candidate data to collect on a case-by-case basis without documenting it. Your organisation should have a clear overview of the personal data used in recruitment, the purpose for which each type of data is collected, the applicable legal basis, who has access to it and how long it is retained.
We recommend documenting this as part of your records of processing activities. This should include your recruitment processing activities and the individual data items you use. Once a candidate becomes an employee, this should connect with your staff dossier and Staff Privacy Policy, which cover the broader processing of personal data during employment.
Keep recruitment data under control
Collecting less information makes GDPR compliance easier. It also reduces the amount of personal data that can be lost, misused or accessed by the wrong person.
GDPRWise helps organisations document recruitment and other HR processing activities, including the categories of personal data they use and the reasons for processing them.
GDPRWise maps your recruitment processing activities and shows you which personal data, legal basis and retention period apply to each step.