Recruitment does not need a separate privacy department. But employers do need a repeatable process for handling CVs, interviews, recruitment platforms, talent pools and candidate rights.
Use this checklist to review your recruitment process from the first application to final deletion.
Before opening the vacancy
- Define which applicant data is actually necessary.
- Remove unnecessary questions from application forms.
- Identify the purposes of the processing.
- Identify the appropriate legal basis for each purpose.
- Check whether special category or criminal-offence data may be involved.
- Make sure recruitment is included in your record of processing activities.
- Define retention periods.
If you are unsure where the line sits, start with what personal data you can collect from job applicants and record the result in your record of processing activities.
Candidate privacy information
- Have a candidate privacy notice.
- Make it available when personal data is collected.
- Explain the purposes and legal bases.
- Explain relevant data sources.
- Identify recipients or categories of recipients.
- Explain retention periods.
- Cover international transfers where relevant.
- Explain candidate rights.
- Cover relevant automated decision-making where applicable.
The structure of a candidate privacy notice follows directly from these points.
During recruitment
- Limit access to people involved in the recruitment process.
- Store applications in approved systems.
- Avoid unnecessary copies of CVs.
- Keep interview notes professional and relevant.
- Verify important information rather than relying on assumptions.
- Avoid collecting sensitive information without a lawful and necessary reason.
- Have a process for candidate GDPR requests.
Applicants can exercise the same data subject rights as anyone else, so the handling process has to cover recruitment data.
Recruitment agencies and software
- Identify all recruitment providers.
- Determine their privacy role.
- Put required data protection terms in place.
- Check where candidate data is processed.
- Review international transfers.
- Check security and access controls.
- Know how data can be deleted when retention periods expire.
Where a provider acts as your processor, a data processing agreement with the mandatory elements is required.
LinkedIn and social media
- Define whether online screening is permitted.
- Limit checks to relevant sources and information.
- Avoid unnecessary investigation of candidates’ private lives.
- Do not seek access to deliberately private profiles.
- Tell candidates about external data sources where required.
- Avoid recording irrelevant sensitive information.
The rules differ between checking a candidate’s LinkedIn profile and broader social media screening, so decide in advance which is allowed in your process.
Talent pools
- Treat future recruitment as a defined purpose.
- Choose and document the appropriate legal basis.
- Tell candidates how the talent pool works.
- Set a retention period.
- Keep information accurate.
- Make opting out or withdrawing consent easy where applicable.
- Delete expired records.
Building a GDPR compliant talent pool deliberately is far easier than trying to justify one after the fact.
AI in recruitment
- Approve AI tools before candidate data is uploaded.
- Check what the provider does with submitted data.
- Minimise or pseudonymise data where possible.
- Assess automated decision-making risks.
- Check whether the AI Act applies and whether the system is high-risk.
- Ensure human oversight is meaningful.
- Consider whether a DPIA is required.
- Test outputs for accuracy and potential bias.
Both AI in recruitment and the DPIA requirement deserve a proper look before a tool goes live.
When the candidate is hired
- Review the recruitment file.
- Transfer only information that remains necessary.
- Apply appropriate employment retention rules.
- Delete unnecessary recruitment data.
- Update access rights.
- Provide staff privacy information.
This is the moment to work out what happens to applicant data when a candidate becomes an employee and to hand over your employee privacy policy.
When the recruitment procedure ends
- Start the relevant retention period.
- Delete information when the period expires.
- Include email inboxes and local copies.
- Remove data from external systems where required.
- Keep talent-pool data separate from ordinary rejected applications.
- Periodically test whether deletion actually happens.
If you have not fixed the periods yet, decide how long you can keep a candidate’s CV first.
Make the checklist repeatable
GDPR compliance works best when these steps are built into the recruitment process rather than checked once a year.
GDPRWise helps employers map recruitment and other HR processing activities, document retention and legal bases, manage providers and generate the privacy documentation that supports a repeatable compliance process.
GDPRWise maps your recruitment processing, records legal bases and retention periods, and generates the candidate privacy documentation that goes with them.