What to do when a candidate asks you to delete their data
Verify identity, erase every copy within one month, keep only a documented legal minimum, and pass the request on to any client you shared the CV with.
On this page
When a candidate asks you to delete their data, verify the request really comes from them, erase every copy you hold within one month, and confirm in writing what you did. “Every copy” means the ATS record plus your inbox, exports, message threads and anything you sent to clients. You may keep a small, documented minimum where another law requires it or where you genuinely need it to defend a legal claim. Everything else goes.
The deadline: how the one-month clock works
The clock starts the day the request arrives, not the day it reaches the right inbox or the day you finish checking identity. It counts on any channel: a reply to your outreach email, a WhatsApp message, a LinkedIn DM saying “please remove my details” is a valid erasure request under GDPR Article 17. No form, no magic words.
You then have one month to act and respond. For genuinely complex cases, or a pile of simultaneous requests, you may extend by up to two further months, but only if you tell the candidate within the first month that you are extending and why. A late answer after silence is a breach even if the deletion itself was done properly. Handling the request is free except in manifestly unfounded or excessive cases, and those are rarer than busy recruiters hope.
The practical implication: route these requests somewhere watched. If an erasure mail can sit in a recruiter’s personal inbox during their holiday, the clock runs anyway.
What are the exact steps, in order?
- Acknowledge and verify. Confirm receipt the same week. Check the request comes from the data subject; a reply from the email address on file is usually enough. Do not demand a passport copy for a routine deletion, because collecting ID you do not need is its own GDPR problem.
- Map every copy. ATS profile and documents, inbox threads and attachments, exported spreadsheets, WhatsApp and LinkedIn conversations, calendar invites, assessment tools, and every client you submitted the CV to. Write the list down; it becomes your evidence.
- Decide what you must keep, and record the reason next to each item.
- Erase the rest everywhere, including archived and recently deleted states in your tooling.
- Notify recipients. Tell each client or partner you shared the data with that the candidate has requested erasure.
- Confirm in writing to the candidate: what you deleted, what you kept and on which legal ground, and their right to complain to the supervisory authority (in the Netherlands, the Autoriteit Persoonsgegevens).
What may you keep, and how do you document it?
Erasure is not absolute. GDPR Article 17(3) lets you retain data you need to comply with a legal obligation or to establish, exercise or defend legal claims. For a recruiting desk that translates into a short list:
| You hold | Default action | Why |
|---|---|---|
| CV, parsed profile, notes, scores, messages | Erase | No exception covers ordinary pipeline data |
| Emails and attachments about the candidate | Erase | Personal data counts wherever it sits |
| Contract, payroll and invoice records of a placed candidate | Keep for the statutory period | Tax and employment law override erasure |
| Minimal application record: name, role, dates, outcome | Keep only while a claim is realistic | Defence against, say, a discrimination claim |
| The erasure request and your confirmation | Keep | Proof of compliance is itself a legal need |
| Rotating backups | Erase on the normal cycle | Document the cycle; never restore erased records |
Two disciplines make this defensible. Keep the minimum, not the convenient: a one-line record that someone applied for role X and was rejected on date Y defends a claim; their full CV does not need to. And write down the why and the until-when at the moment you decide, because “we kept it just in case” convinces no regulator. How long records should live in the first place is covered in our guide to candidate data retention.
Which copies do recruiters forget?
The ATS record is the easy part. Erasure requests go wrong in the places nobody indexes:
- Email attachments: the original application, plus every forward to a hiring manager.
- WhatsApp and LinkedIn threads on recruiters’ phones, including photos of CVs.
- Spreadsheets and exports: the shortlist built for a client meeting, the CSV from your last migration.
- Client submissions: the CV now sitting in three client inboxes.
- Calendar invites with the CV attached for interviewers.
- Assessment and screening tools that hold their own copy of the candidate.
A useful habit follows: every time you send a candidate’s data somewhere, you are creating a future deletion task. Systems that track where a profile has been shared make that task findable later.
How does an ATS turn this into a button?
In software built for GDPR, most of the checklist collapses: open the candidate, choose delete, and the system removes the profile, documents, parsed data and message history together, records the request, and applies retention rules so most data expires before anyone has to ask. Most established systems, Greenhouse, Workable and Recruitee included, ship some form of deletion or anonymisation workflow. The differences worth probing are how far the deletion reaches (synced email and attachments, or just the profile), whether it leaves an audit trail you could show a regulator, and whether automatic retention stops the backlog from growing back. Our guide on what to look for in a GDPR-compliant ATS turns those into vendor questions.
Recruitifly includes GDPR tooling on every tier: consent tracking, retention rules, and deletion that takes the profile, documents and message history in one action, with each deletion request recorded. You can also hand the job to the Fly assistant (“delete Jan Jansen and tell me what we hold”); it proposes the deletion and waits for your confirmation, so nothing is erased silently. Teams with heavier obligations can add the Compliance Engine (EUR 25 per month to unlock) for GDPR automation and country rule packs. The features overview shows how the pieces fit together.
Passing the request on to clients
Agency recruiters share CVs by design, and GDPR Article 19 closes the loop: when you erase data, you must tell every recipient you disclosed it to, unless that is impossible or a disproportionate effort. For a normal desk, emailing the three clients who received the CV is neither.
Send each client a short written notice: the candidate has exercised their right to erasure, please delete the CV and profile we sent on this date, and confirm when done. You cannot reach into a client’s inbox, and their obligations are their own once notified, but the notification duty is yours, and the candidate may ask you to name the recipients. File the notices with the rest of your erasure record.
Recruitifly is in private beta at the moment. If deletion requests currently mean an afternoon of archaeology across inboxes and spreadsheets, talk to us and we will show you what the one-button version looks like on your own data.
Frequently asked questions
How long do I have to answer a GDPR deletion request?
One month from the day the request arrives, on any channel. You can extend by up to two further months for complex cases or many simultaneous requests, but only if you tell the candidate about the extension, with reasons, within the first month. The response is free of charge in almost all cases.
Can I refuse to delete a candidate's data?
Only on narrow grounds. You may keep data a law obliges you to keep, such as payroll records for placed candidates, plus a documented minimum needed to defend against a legal claim. Manifestly unfounded or excessive requests can be refused entirely. In every case you must explain your reasons in writing and point the candidate to the supervisory authority.
Do I have to delete emails from a candidate?
Yes. GDPR applies to personal data wherever it lives, and an inbox full of CV attachments and interview threads counts. Search your mail for the candidate's name and address, delete the threads and attachments, and remember forwards to hiring managers, which are copies too.
Must I tell clients to delete a shared CV?
Yes, unless it is impossible or takes disproportionate effort, which is rare for a handful of client submissions. GDPR Article 19 requires you to inform every recipient of the data about the erasure. Send a short written notice per client, keep proof you sent it, and name the recipients if the candidate asks.
Recruitifly Editorial
Editorial
Related reading
Adding LLM screening to your ATS without creating duplicate records
Layer LLM screening over your ATS without splitting your candidate data: one source of truth, stable ID sync, scores written back as fields, not copies.
Sourcing with adjacent job titles and skills
Searching one job title misses most of the market. A worked SRE example plus a repeatable method for mapping adjacent titles and skills for any role.
AI Act candidate disclosure: notice template
What to tell applicants when automated screening is used, under the EU AI Act and GDPR Articles 13, 14 and 22, plus a copy-paste disclosure notice template.
Want to see how this looks on your own data?
No hard promises. Just a straight conversation about exports, stages, and your current stack.
Contact us