Skip to content
HR & Recruitment calendar_today Updated: 28 August 2026 schedule 4 min read

What Personal Data Can You Collect from Job Applicants?

verified Last reviewed 31 August 2026 · GDPRWise legal team

Under the GDPR, applicant data must be relevant and necessary for recruitment. This article explains what you may ask candidates, what to avoid, and how to design an application form around necessity.

summarize Key Takeaways
  • check_circle You may collect personal data that is relevant and necessary for recruitment
  • check_circle Avoid asking for sensitive or private information unless there is a clear legal reason
  • check_circle Publicly available information is still personal data and remains protected by the GDPR
  • check_circle Review application forms regularly and remove questions you cannot justify

Recruitment naturally requires information about candidates. But that does not mean an employer can collect any information that might be interesting or useful. Under the GDPR, applicant data must be relevant and necessary for the recruitment process.

The basic rule is simple: only collect what you genuinely need to assess the candidate and manage the application.

What information do employers normally need?

For most vacancies, an employer will need fairly standard information, such as:

  • Name and contact details
  • Employment history
  • Education and qualifications
  • Professional skills and experience
  • Languages
  • Information contained in a CV or cover letter
  • Interview notes and assessments
  • Availability and, where relevant, salary expectations

The exact information you need depends on the position.

A driving licence may be relevant for a delivery driver. It is probably not relevant for an office job where driving is never required.

This is the GDPR principle of data minimisation in practice.

Can you ask for any information that might help you choose?

No.

Recruitment can easily become a process of collecting information “just in case”. The GDPR requires a more disciplined approach.

Before requesting information, ask:

Do we genuinely need this information to assess whether the candidate is suitable for this position or to comply with a legal requirement?

If the answer is no, don’t collect it.

Be careful with sensitive information

Some personal data receives additional protection under the GDPR. This includes information about:

  • Health
  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic data
  • Certain biometric data
  • Sex life or sexual orientation

Processing this information generally requires an additional legal justification on top of one of the six legal bases.

In ordinary recruitment, employers should therefore avoid requesting sensitive information unless it is genuinely necessary and legally permitted.

Information about criminal convictions and offences is also subject to specific restrictions.

What about photographs?

A photograph is personal data when a person can be identified from it.

Before making a photograph mandatory, consider whether seeing the candidate is actually necessary for assessing their ability to perform the job.

In many recruitment processes, it is not.

Requiring unnecessary photographs can also increase the risk that irrelevant characteristics influence recruitment decisions.

What if candidates provide too much information themselves?

Candidates sometimes include information you never requested: marital status, children, hobbies, photographs, medical information or other private details.

You do not automatically need to use that information simply because the candidate supplied it.

Keep the recruitment decision focused on information relevant to the vacancy.

Can you collect information from other sources?

Applicant data does not always come directly from the applicant.

You may receive information from:

  • Recruitment agencies
  • Professional networking platforms
  • References
  • Public professional registers
  • Assessment providers
  • Background-check providers

The GDPR still applies.

You must have a lawful reason for collecting and using the information and, where required, tell the candidate that you obtained personal data from another source. Your candidate privacy notice is the natural place to explain this.

Design your application process around necessity

A useful exercise is to review every field in your application form.

For each question, ask:

  1. Why do we ask this?
  2. Do we actually use the answer?
  3. Is it necessary at this stage?
  4. Could we request it later if the candidate is selected?

Information needed to prepare an employment contract, for example, belongs at the offer stage rather than on the application form every candidate fills in.

Document what you collect and why

Do not decide what candidate data to collect on a case-by-case basis without documenting it. Your organisation should have a clear overview of the personal data used in recruitment, the purpose for which each type of data is collected, the applicable legal basis, who has access to it and how long it is retained.

We recommend documenting this as part of your records of processing activities. This should include your recruitment processing activities and the individual data items you use. Once a candidate becomes an employee, this should connect with your staff dossier and Staff Privacy Policy, which cover the broader processing of personal data during employment.

Keep recruitment data under control

Collecting less information makes GDPR compliance easier. It also reduces the amount of personal data that can be lost, misused or accessed by the wrong person.

GDPRWise helps organisations document recruitment and other HR processing activities, including the categories of personal data they use and the reasons for processing them.

auto_awesome Not sure which applicant data you actually need?

GDPRWise maps your recruitment processing activities and shows you which personal data, legal basis and retention period apply to each step.

Share share LinkedIn mail Email
GW
GDPRWise Editorial

This article was written by the GDPRWise team and reviewed by our privacy experts. We regularly review our content for accuracy and legal correctness.