All insights
Compliance

The ATS compliance checklist for 2026

A practical seven-point compliance checklist for your ATS in 2026: lawful basis, retention, consent, deletion, suppression, AI Act duties and pay transparency.

RE
Recruitifly Editorial
Editorial
2026-06-13·6 min read
On this page

An ATS compliance checklist for 2026 has seven items: a documented lawful basis for every candidate record, retention windows the system actually enforces, consent tracking wherever consent is the basis, a deletion process that completes within a month, a suppression list that keeps deleted candidates from coming back, EU AI Act duties for any tool that scores or ranks people, and pay transparency in every job ad. Each item below comes with a short pass test and a link to the deep dive. The first five are GDPR housekeeping; the last two are the deadlines that make 2026 different.

Why is 2026 the year to run this checklist?

Two regimes converge. The EU AI Act’s obligations for high-risk systems, a category that explicitly includes AI used to recruit and select people, apply from August 2026. And the EU Pay Transparency Directive’s transposition deadline passed in June 2026, which means national salary-disclosure laws are now landing, each with its own details. Neither is a future problem anymore, and a structured pass over your ATS now is far cheaper than retrofitting under enforcement pressure.

The checklist at a glance

Run it quarterly; each item gets a short section below.

# Check Driven by You pass when
1 Lawful basis GDPR Every record, including sourced profiles, names its basis
2 Retention windows GDPR storage limitation Expired records are deleted or flagged automatically
3 Consent tracking GDPR You can show who agreed, when, to what, and withdrawal works
4 Deletion requests GDPR right to erasure A request completes everywhere within one month
5 Suppression list GDPR opt-outs Deleted candidates cannot silently re-enter the system
6 AI scoring duties EU AI Act (from August 2026) Human oversight, logging and candidate notice are in place
7 Pay transparency EU directive plus national laws Ads and pre-interview info include a real salary range

1. Does every candidate record have a lawful basis?

Active applicants are the easy case: processing their data to run the process they applied to is usually covered by legitimate interest or pre-contract necessity. The records that fail audits are the other ones: sourced profiles, referrals, and candidates left over from roles that closed years ago.

  • Every record states which basis applies, including imports and sourced profiles.
  • Sourced candidates are informed that you hold their data within a month of collection.
  • Talent-pool records have their own basis; they do not inherit one from a long-finished application.

The system-level requirements behind this are in what to look for in a GDPR-compliant ATS.

2. Are retention windows enforced, not just written down?

Storage limitation is the principle: keep candidate data only as long as the purpose justifies, then delete it. The failure mode is rarely the policy document, it is enforcement.

  • A window is defined per record type and jurisdiction, and the clock starts when the process ends, not when someone remembers.
  • Expiry triggers something automatic: deletion, anonymisation, or at minimum a review queue.
  • Exports and shared spreadsheets fall under the same rule, because they are the same data.

How long is reasonable per country, and what to do with the awkward edge cases, is covered in how long to keep CVs.

Consent is the right basis for exactly one common recruiting scenario: keeping a candidate’s data beyond the process for future roles. If you rely on it, you must be able to prove it.

  • Each consent has a timestamp, the exact wording shown, and the scope agreed to.
  • Withdrawing is as easy as giving: one click or one reply, not a support ticket.
  • Nothing is pre-ticked, and silence never counts as a yes.
  • Long retention gets renewed, not assumed; a consent from 2021 does not cover 2026.

4. Can you execute a deletion request end to end?

A candidate writes “please delete my data.” GDPR gives you a month, and the request covers everywhere the data lives: the ATS, your inbox, exported shortlists, the hiring manager’s downloads folder.

  • Requests are logged with a deadline the moment they arrive.
  • You verify identity proportionately, then delete from every system, not just the profile screen.
  • The candidate gets a confirmation, and the deletion itself is recorded without keeping the deleted data.

The step-by-step playbook, including the narrow cases where you may refuse, is in what to do when a candidate asks to delete their data.

5. Will deleted candidates stay deleted?

Full deletion has a trap: once the data is gone, nothing stops the same person from being re-imported by a sourcing tool or a fresh CV upload six months later, after which you contact someone who explicitly opted out. The fix is a suppression list.

  • Every deletion with an opt-out writes a minimal identifier, ideally hashed, to the list.
  • Sourcing, imports and bulk uploads are checked against it before any record is created.
  • The list stores only what matching requires; it is an exception to deletion, so keep it lean.

6. Are your scoring and ranking tools ready for the AI Act?

Any AI that filters applications or scores, ranks or shortlists candidates is high-risk under the EU AI Act, and the duties for deployers of such systems apply from August 2026. You do not need to be the vendor to have obligations.

  • You know which features in your stack legally count as AI-driven selection.
  • A named human can understand, question and overrule each automated score; tools that propose while a recruiter decides are the compliant shape.
  • Logs exist, candidates are told an AI system is in use, and the vendor’s instructions for use are on file.

The full breakdown of who owes what, vendor versus deployer, is in the EU AI Act and recruitment software.

7. Do your job ads meet pay transparency rules?

The EU Pay Transparency Directive gives applicants the right to know the initial pay or pay range before the interview, bans asking candidates about their salary history, and several member states are requiring the range in the ad itself. National transposition laws are arriving through 2026, so check the specific countries you hire in.

  • Every job record carries a real, defensible salary range, not a placeholder wide enough to mean nothing.
  • The range flows automatically to every board you post to, so no channel quietly drops it.
  • Screening scripts no longer ask what candidates currently earn.

The obligations, timelines and ad-level details are in the EU pay transparency directive and job ads.

Where does Recruitifly fit?

Recruitifly was built in the EU with this checklist in mind rather than retrofitted to it. Data stays resident in the EU, and the GDPR items above (retention windows, consent tracking, deletion requests and suppression lists) are standard tooling rather than an enterprise upsell; a Compliance Engine add-on exists for teams that need to go further. On the AI Act item, the design position matters most: our assistant Fly scores, ranks and drafts, but every write is propose-then-confirm, so a recruiter approves each change before it happens. That is not a limitation we apologise for; for hiring AI, supervised is the correct design.

The honest note: we are in private beta. If you want to walk this checklist against a live system rather than a slide deck, talk to us.

Frequently asked questions

What should an ATS compliance checklist cover in 2026?

Seven areas: a lawful basis for every candidate record, retention windows that are enforced rather than merely documented, consent tracking where you rely on consent, a deletion process that completes within a month, a suppression list so deleted candidates are not re-added, EU AI Act duties for any tool that scores or ranks people, and pay transparency in job ads. Most teams pass the first three on paper and fail the last four in practice.

How long can a recruiter keep candidate CVs?

There is no single EU-wide number. The GDPR principle is storage limitation: keep data only as long as the purpose justifies. Common practice is to delete unsuccessful applicants' data within months of closing the process unless the candidate consents to longer talent-pool retention. Some national regulators publish concrete guidance; the Dutch authority, for example, suggests four weeks after the process, or one year with consent. Set the window per record and let the system enforce it.

Does the EU AI Act apply to recruitment software?

Yes, directly. AI systems used to recruit or select people, including tools that filter applications or score and rank candidates, are classified as high-risk under the Act. If you deploy one, you have duties: use it per the vendor's instructions, keep a human meaningfully in the loop, monitor its operation and tell candidates it is in use. The core obligations for these systems apply from August 2026, so this is the year to verify your stack.

What is a suppression list and why does an ATS need one?

A suppression list stores a minimal identifier, typically a hashed email address, for people who asked to be deleted or never contacted again. Without it, full deletion creates a trap: six months later a sourcing tool or a new CV import re-adds the same person, and you contact someone who explicitly opted out. The list lets you honor the request permanently while still deleting the actual profile data.

RE

Recruitifly Editorial

Editorial

Related reading

Want to see how this looks on your own data?

No hard promises. Just a straight conversation about exports, stages, and your current stack.

Contact us