How long can you keep candidate CVs under GDPR?
GDPR sets no fixed CV retention period. Practical timelines, the Dutch four-weeks or one-year-with-consent guidance, and how automated deletion works.
On this page
GDPR sets no fixed retention period for CVs; it requires that you keep them no longer than needed for the purpose. In practice, common guidance in the Netherlands is four weeks after the process ends, or up to one year with the candidate’s consent. Longer retention needs fresh consent or a clear legal reason.
This is practitioner guidance, not legal advice. Retention numbers vary by country and situation; confirm yours with counsel or your privacy officer.
What does GDPR actually say about keeping CVs?
GDPR’s storage-limitation principle says personal data may be kept no longer than necessary for the purpose it was collected for. For a CV, that purpose is usually “assess this person for this vacancy”, and it ends when the process ends. After that point you need either a new purpose with its own lawful basis, in practice the candidate’s consent to stay on file, or a defensible legal reason to retain. GDPR deliberately avoids fixed numbers; regulators and national practice fill them in.
How long do recruiters keep CVs in practice?
| Situation | Common practice |
|---|---|
| Active application | For the duration of the hiring process |
| Rejected, no consent | Deleted within about four weeks of the process ending |
| Rejected, consented to stay on file | Kept around one year, then renewed or deleted |
| Hired | Moved to the employee file, governed by employment-record rules |
| Agency placement administration | Contract and invoicing data kept per commercial and tax obligations; the CV itself still follows recruitment timelines |
These are working norms rather than statutes. The four-week and one-year figures come from guidance published by the Dutch regulator and are widely used as a rule of thumb beyond the Netherlands, but member states differ, and some employers keep application records longer where local rules around discrimination claims justify it. Treat the table as a starting point, not a verdict. Agencies juggling client-side copies of the same CV carry extra duties; see whether you are controller or processor in client work.
The Dutch guidance: four weeks, or one year with consent
The commonly cited Dutch position is refreshingly concrete: delete application data within four weeks after the procedure ends, unless the candidate consents to longer retention, in which case about one year is considered reasonable before you ask again. Two details get missed in practice. The consent must be a genuine choice, not a pre-ticked box buried in the application form. And the year is not a free pass: if the candidate withdraws consent in month three, the clock stops in month three. Recruiters working the Dutch market will find more in our guide on what ATS Dutch recruiters should use.
What about talent pools and keeping candidates on file?
A talent pool is simply retention with a new purpose, which means it runs on consent in most setups. Ask for it explicitly, record the scope and date, make leaving effortless, and renew before the period lapses. A pool full of profiles nobody re-consented is not an asset. It is a liability with search filters.
How scheduled deletion and anonymization work in an ATS
Modern systems attach a retention clock to each record based on its situation: rejection date, consent date, placement date. When a clock runs out, the system deletes the record or anonymizes it, stripping the name, contact details, documents, and free-text notes while keeping non-identifying pipeline data so your reporting survives. An audit trail records what happened and when, which is the evidence you want if a regulator ever asks.
Recruitifly automates exactly this: consent tracking per candidate, scheduled retention with anonymization, data-subject request handling, and audit trails are built into the platform. The wider compliance picture, from processor agreements to access requests, is covered in what makes an ATS GDPR-compliant.
A retention policy you can actually follow
- List your purposes: active process, talent pool, placement administration.
- Set a period per purpose and write one sentence of justification for each.
- Decide deletion versus anonymization per purpose.
- Automate enforcement in your ATS, with audit trails, so the policy runs without willpower.
- Review yearly, and whenever you enter a new market.
Recruitifly is in private beta. If your retention policy currently lives in a calendar reminder, talk to us; the platform does the remembering for you.
Frequently asked questions
How long can I keep a rejected candidate's CV?
Common guidance, notably from the Dutch regulator, is to delete within about four weeks of the process ending unless the candidate agrees to longer retention. With explicit consent, keeping the profile for around a year for future roles is widely treated as reasonable. Your own policy and local law decide the exact number.
Can I keep CVs in case a candidate later claims discrimination?
Some employers retain application records for a defined window because claims can arrive after rejection, and limitation periods differ by country. If you rely on that reason, write it into your retention policy, scope it to what you genuinely need, and delete when the window closes. Ask counsel for the right period in your jurisdiction.
What is the difference between deleting and anonymizing a candidate?
Deletion removes the record entirely. Anonymization strips everything that identifies the person while keeping non-identifying data, so funnel metrics and reporting survive. Once data is truly anonymous it falls outside GDPR. Anonymization done badly, where the person remains identifiable, still counts as keeping personal data.
Does Recruitifly delete candidate data automatically?
Yes. You set retention rules per purpose and the platform schedules the work: records reaching the end of their retention period are deleted or anonymized on schedule, with consent tracked per candidate and an audit trail of what happened. Data-subject requests such as erasure are handled from the candidate record.
Recruitifly Editorial
Editorial
Related reading
Adding LLM screening to your ATS without creating duplicate records
Layer LLM screening over your ATS without splitting your candidate data: one source of truth, stable ID sync, scores written back as fields, not copies.
Sourcing with adjacent job titles and skills
Searching one job title misses most of the market. A worked SRE example plus a repeatable method for mapping adjacent titles and skills for any role.
AI Act candidate disclosure: notice template
What to tell applicants when automated screening is used, under the EU AI Act and GDPR Articles 13, 14 and 22, plus a copy-paste disclosure notice template.
Want to see how this looks on your own data?
No hard promises. Just a straight conversation about exports, stages, and your current stack.
Contact us