All insights
Compliance

What to do when a candidate asks you to delete their data

Verify identity, erase every copy within one month, keep only a documented legal minimum, and pass the request on to any client you shared the CV with.

RE
Recruitifly Editorial
Editorial
2026-06-12·6 min read
On this page

When a candidate asks you to delete their data, verify the request really comes from them, erase every copy you hold within one month, and confirm in writing what you did. “Every copy” means the ATS record plus your inbox, exports, message threads and anything you sent to clients. You may keep a small, documented minimum where another law requires it or where you genuinely need it to defend a legal claim. Everything else goes.

The deadline: how the one-month clock works

The clock starts the day the request arrives, not the day it reaches the right inbox or the day you finish checking identity. It counts on any channel: a reply to your outreach email, a WhatsApp message, a LinkedIn DM saying “please remove my details” is a valid erasure request under GDPR Article 17. No form, no magic words.

You then have one month to act and respond. For genuinely complex cases, or a pile of simultaneous requests, you may extend by up to two further months, but only if you tell the candidate within the first month that you are extending and why. A late answer after silence is a breach even if the deletion itself was done properly. Handling the request is free except in manifestly unfounded or excessive cases, and those are rarer than busy recruiters hope.

The practical implication: route these requests somewhere watched. If an erasure mail can sit in a recruiter’s personal inbox during their holiday, the clock runs anyway.

What are the exact steps, in order?

  1. Acknowledge and verify. Confirm receipt the same week. Check the request comes from the data subject; a reply from the email address on file is usually enough. Do not demand a passport copy for a routine deletion, because collecting ID you do not need is its own GDPR problem.
  2. Map every copy. ATS profile and documents, inbox threads and attachments, exported spreadsheets, WhatsApp and LinkedIn conversations, calendar invites, assessment tools, and every client you submitted the CV to. Write the list down; it becomes your evidence.
  3. Decide what you must keep, and record the reason next to each item.
  4. Erase the rest everywhere, including archived and recently deleted states in your tooling.
  5. Notify recipients. Tell each client or partner you shared the data with that the candidate has requested erasure.
  6. Confirm in writing to the candidate: what you deleted, what you kept and on which legal ground, and their right to complain to the supervisory authority (in the Netherlands, the Autoriteit Persoonsgegevens).

What may you keep, and how do you document it?

Erasure is not absolute. GDPR Article 17(3) lets you retain data you need to comply with a legal obligation or to establish, exercise or defend legal claims. For a recruiting desk that translates into a short list:

You hold Default action Why
CV, parsed profile, notes, scores, messages Erase No exception covers ordinary pipeline data
Emails and attachments about the candidate Erase Personal data counts wherever it sits
Contract, payroll and invoice records of a placed candidate Keep for the statutory period Tax and employment law override erasure
Minimal application record: name, role, dates, outcome Keep only while a claim is realistic Defence against, say, a discrimination claim
The erasure request and your confirmation Keep Proof of compliance is itself a legal need
Rotating backups Erase on the normal cycle Document the cycle; never restore erased records

Two disciplines make this defensible. Keep the minimum, not the convenient: a one-line record that someone applied for role X and was rejected on date Y defends a claim; their full CV does not need to. And write down the why and the until-when at the moment you decide, because “we kept it just in case” convinces no regulator. How long records should live in the first place is covered in our guide to candidate data retention.

Which copies do recruiters forget?

The ATS record is the easy part. Erasure requests go wrong in the places nobody indexes:

  • Email attachments: the original application, plus every forward to a hiring manager.
  • WhatsApp and LinkedIn threads on recruiters’ phones, including photos of CVs.
  • Spreadsheets and exports: the shortlist built for a client meeting, the CSV from your last migration.
  • Client submissions: the CV now sitting in three client inboxes.
  • Calendar invites with the CV attached for interviewers.
  • Assessment and screening tools that hold their own copy of the candidate.

A useful habit follows: every time you send a candidate’s data somewhere, you are creating a future deletion task. Systems that track where a profile has been shared make that task findable later.

How does an ATS turn this into a button?

In software built for GDPR, most of the checklist collapses: open the candidate, choose delete, and the system removes the profile, documents, parsed data and message history together, records the request, and applies retention rules so most data expires before anyone has to ask. Most established systems, Greenhouse, Workable and Recruitee included, ship some form of deletion or anonymisation workflow. The differences worth probing are how far the deletion reaches (synced email and attachments, or just the profile), whether it leaves an audit trail you could show a regulator, and whether automatic retention stops the backlog from growing back. Our guide on what to look for in a GDPR-compliant ATS turns those into vendor questions.

Recruitifly includes GDPR tooling on every tier: consent tracking, retention rules, and deletion that takes the profile, documents and message history in one action, with each deletion request recorded. You can also hand the job to the Fly assistant (“delete Jan Jansen and tell me what we hold”); it proposes the deletion and waits for your confirmation, so nothing is erased silently. Teams with heavier obligations can add the Compliance Engine (EUR 25 per month to unlock) for GDPR automation and country rule packs. The features overview shows how the pieces fit together.

Passing the request on to clients

Agency recruiters share CVs by design, and GDPR Article 19 closes the loop: when you erase data, you must tell every recipient you disclosed it to, unless that is impossible or a disproportionate effort. For a normal desk, emailing the three clients who received the CV is neither.

Send each client a short written notice: the candidate has exercised their right to erasure, please delete the CV and profile we sent on this date, and confirm when done. You cannot reach into a client’s inbox, and their obligations are their own once notified, but the notification duty is yours, and the candidate may ask you to name the recipients. File the notices with the rest of your erasure record.

Recruitifly is in private beta at the moment. If deletion requests currently mean an afternoon of archaeology across inboxes and spreadsheets, talk to us and we will show you what the one-button version looks like on your own data.

Frequently asked questions

How long do I have to answer a GDPR deletion request?

One month from the day the request arrives, on any channel. You can extend by up to two further months for complex cases or many simultaneous requests, but only if you tell the candidate about the extension, with reasons, within the first month. The response is free of charge in almost all cases.

Can I refuse to delete a candidate's data?

Only on narrow grounds. You may keep data a law obliges you to keep, such as payroll records for placed candidates, plus a documented minimum needed to defend against a legal claim. Manifestly unfounded or excessive requests can be refused entirely. In every case you must explain your reasons in writing and point the candidate to the supervisory authority.

Do I have to delete emails from a candidate?

Yes. GDPR applies to personal data wherever it lives, and an inbox full of CV attachments and interview threads counts. Search your mail for the candidate's name and address, delete the threads and attachments, and remember forwards to hiring managers, which are copies too.

Must I tell clients to delete a shared CV?

Yes, unless it is impossible or takes disproportionate effort, which is rare for a handful of client submissions. GDPR Article 19 requires you to inform every recipient of the data about the erasure. Send a short written notice per client, keep proof you sent it, and name the recipients if the candidate asks.

RE

Recruitifly Editorial

Editorial

Related reading

Want to see how this looks on your own data?

No hard promises. Just a straight conversation about exports, stages, and your current stack.

Contact us