Skip to content
HR & Recruitment calendar_today Updated: 28 August 2026 schedule 4 min read

The Most Common GDPR Mistakes in Recruitment

verified Last reviewed 31 August 2026 · GDPRWise legal team

Fourteen recruitment privacy mistakes employers make most often, from keeping every CV forever to pasting candidate data into AI tools, and what to do instead.

summarize Key Takeaways
  • check_circle Recruitment data should not be collected or kept "just in case".
  • check_circle Consent is not the answer to every recruitment processing activity.
  • check_circle Informal tools and copies are often where retention and security fail.
  • check_circle New recruitment technology should be assessed before real candidate data is used.

Most recruitment privacy problems are not caused by sophisticated technology. They come from ordinary habits: old CVs in inboxes, unnecessary questions, informal social media searches and candidate data copied into new tools without anyone checking the consequences.

Here are the mistakes employers should look for first.

1. Keeping every CV forever

An inbox containing ten years of applications is not a talent pool.

Define why applicant data is retained and for how long. When the purpose and justified retention period end, delete the data. If you have never set the periods, work out how long you can keep a candidate’s CV before anything else.

2. Asking for too much information

Application forms often accumulate questions over time.

If nobody can explain why a piece of information is necessary for the recruitment decision, remove the question.

Data minimisation starts before the candidate clicks “Submit”.

Consent is one GDPR legal basis, not a universal recruitment checkbox.

Parts of the recruitment process may rely on steps taken at the candidate’s request before entering into a contract, legitimate interests, legal obligations or another appropriate basis.

Choose the legal basis according to the purpose. The six GDPR legal bases each fit different parts of a hiring process.

4. Having no candidate privacy notice

A website privacy statement about customers and cookies does not explain recruitment.

Candidates need relevant information about how their application data is processed, which is what a dedicated candidate privacy notice is for.

5. Creating an accidental talent pool

Keeping rejected candidates because “we might call them someday” creates an additional processing purpose.

If you want a talent pool, create one deliberately with a legal basis, transparency, retention period and deletion process.

6. Searching every candidate on social media

Public does not mean unprotected.

Social media searches can expose hiring managers to sensitive and irrelevant information and create both privacy and discrimination risks.

Limit online checks to situations where they are justified and job-relevant. The same reasoning applies to screening applicants’ social media profiles.

7. Letting CVs spread everywhere

A candidate sends one CV. A week later it exists in six email inboxes, two downloads folders and a shared drive.

Use controlled systems and limit unnecessary copies.

8. Forgetting recruitment agencies and software

Candidate data may be processed by recruiters, applicant tracking systems, assessment providers, cloud services and other suppliers.

Know who receives the data and put the appropriate arrangements in place, starting with a data processing agreement where the provider acts as your processor.

9. Pasting CVs into AI tools without checking

Generative AI makes it extremely easy to upload personal data to a new provider.

Before using real CVs, understand the provider’s terms, retention, training practices, security, transfers and deletion options. The questions to ask are the same ones covered in using ChatGPT or AI tools to review CVs.

10. Treating AI scores as objective facts

An algorithmic score is an output, not a guarantee of truth or fairness.

Check accuracy, relevance, bias and the role of human decision-makers. Fully automated significant decisions may trigger specific GDPR rules on automated decision-making.

11. Moving the entire recruitment file into HR

Once the candidate becomes an employee, review what information is still needed.

Do not automatically keep every interview note, assessment and old recruitment record for the duration of employment.

12. Writing a retention policy but never deleting anything

A policy that says “CVs are deleted after X months” does not help if no system or person actually performs the deletion.

Test the process.

13. Giving too many people access

Not everyone in the organisation needs access to every application.

Use role-based access and review permissions when recruitment ends.

14. Ignoring candidate rights

Applicants are data subjects too.

Your organisation should be able to deal with access, rectification, erasure, objection and other applicable GDPR requests relating to recruitment data.

Turn good intentions into a process

Most recruitment GDPR mistakes are manageable once recruitment is treated as a defined processing activity rather than a collection of emails and informal habits.

GDPRWise helps organisations document recruitment, retention, providers and privacy information in one structured compliance process.

auto_awesome Which of these mistakes is in your process?

GDPRWise documents your recruitment processing, retention periods and providers so the informal habits that cause these mistakes become a controlled process.

Share share LinkedIn mail Email
GW
GDPRWise Editorial

This article was written by the GDPRWise team and reviewed by our privacy experts. We regularly review our content for accuracy and legal correctness.