“Please tick this box to consent to us processing your CV.” Many recruitment forms use wording like this. But under the GDPR, consent is not automatically required every time you process applicant data.
In fact, asking for consent when another legal basis is more appropriate can make your recruitment process unnecessarily complicated.
Processing the current application
A candidate sends you a CV because they want you to consider them for a job.
Processing information necessary to take steps at the candidate’s request before entering into an employment contract may provide the relevant legal basis for parts of the recruitment process.
Other activities may rely on another legal basis, such as legitimate interests or a legal obligation. The six legal bases in the GDPR each carry their own conditions, so it pays to compare them before you decide.
The point is that GDPR compliance does not mean asking for consent for everything.
Why can unnecessary consent be a problem?
Consent has strict requirements.
It must be:
- Freely given
- Specific
- Informed
- Unambiguous
It must also be possible to withdraw consent.
If you tell a candidate that processing their CV is based on consent but you could not realistically continue the recruitment procedure after they withdraw that consent, you should ask whether consent was really the appropriate basis in the first place.
What about keeping the CV after rejection?
Two different things happen after a rejection, and they need separating.
Short retention tied to the procedure itself. You may keep certain information for a limited period to deal with questions or claims arising from the recruitment decision. That rests on your legitimate interest in defending claims, and it runs for as long as such a claim is realistically possible, not indefinitely. See how long you can keep a CV.
Keeping the CV to approach the candidate about future vacancies. This is a new purpose, unrelated to the job they applied for, and it needs its own legal basis.
The two routes for a talent pool
There are two legal bases that work here. The European Data Protection Board accepts both, depending on the circumstances. Pick one deliberately and write it down.
Route 1: consent
Usually the simplest option for an SME. At the point of rejection you ask the candidate a plain question: may we keep your details to contact you about future vacancies?
What makes it work:
- The candidate can say no at no cost, because the procedure they applied for is over. That is what makes the consent freely given, which is often hard to achieve elsewhere in an employment context.
- Ask separately from anything else, with no pre-ticked box, and record the answer and its date.
- Article 7(3) requires withdrawal to be as easy as giving consent. An unsubscribe link or a named mailbox in every message is enough; a written request to head office is not.
- When consent is withdrawn, the basis for keeping the record disappears. Delete it.
Route 2: legitimate interests
Equally available under Article 6(1)(f), and often the better fit if you recruit continuously and want to build a real pool rather than chase individual permissions.
What it requires:
- A balancing assessment, carried out before you start and written down: your interest in filling future roles efficiently, whether keeping the data is necessary to do that, and whether it overrides the candidate’s interests and reasonable expectations.
- Clear information at the point of rejection that you intend to keep their details, why, and for how long.
- A working route to object under Article 21. An objection to this processing has to be honoured; there is no balancing exercise left to run once someone says no.
- Restraint on scope. A recent applicant for a role you recruit for regularly sits comfortably inside their expectations. A five-year-old CV used to send unrelated openings does not.
Choosing between them
| Consent | Legitimate interests | |
|---|---|---|
| Best for | Occasional hiring, small candidate volumes | Continuous recruitment, a maintained pool |
| Work up front | A clear question and a record of the answer | A documented balancing assessment |
| Candidate control | Withdrawal, which ends the processing | Objection, which you must honour |
| Main risk | People decline, so the pool stays small | The assessment was never actually done |
Neither route survives the thing employers do most often, which is to keep the CV and decide later.
If you ask for consent, do it properly
Avoid:
- Pre-ticked boxes
- Consent hidden inside general terms
- Combining several unrelated purposes into one consent
- Saying that consent cannot be withdrawn
- Keeping the data indefinitely after consent
Explain the talent-pool purpose separately from the application itself, and give the candidate a clear yes or no.
Withdrawal must work in practice
If a candidate withdraws consent, deleting them from one mailing list may not be enough.
Check whether their information also exists in:
- Your applicant tracking system
- HR inboxes
- Shared folders
- Recruitment spreadsheets
- External recruitment platforms
Your process should ensure the withdrawal reaches the systems concerned. The same discipline applies when someone asks you to erase their data altogether.
Choose the legal basis before writing the privacy notice
Do not start with a consent checkbox and work backwards.
First identify the processing activity and purpose. Then determine the appropriate legal basis. Then make sure your candidate privacy notice accurately explains it.
GDPRWise helps organisations document the purposes and legal bases behind HR and recruitment processing, making it easier to avoid “consent for everything” compliance.
GDPRWise maps each recruitment purpose to an appropriate legal basis, so you only ask for consent where consent genuinely belongs.