Do you need a candidate's consent to keep their CV?
Not during an active application: legitimate interest covers that. Keeping a CV afterward for future roles needs explicit, recorded, withdrawable consent.
On this page
Not while the application is live: assessing someone who applied to your vacancy is covered by legitimate interest or pre-contract necessity, so you do not need consent to hold their CV during the process. Consent becomes necessary the moment you want to keep that CV after the process ends, for future roles or a talent pool. And it has to be real consent: specific, informed, withdrawable, and recorded with a timestamp, not a pre-ticked box.
This is practitioner guidance, not legal advice. For edge cases that could end up in front of a regulator, involve your counsel or privacy officer.
Why consent is the wrong basis during an application
GDPR offers six lawful bases for processing personal data, and consent is only one of them. For a live application it is also the weakest choice. Consent must be freely given, and a candidate who wants the job is not in a position to freely refuse; regulators read consent demanded as a condition of applying as invalid. It must also be withdrawable at any time, which would let a candidate pull the legal floor out from under their own application mid-process.
So recruiters rely on two other bases in practice. Pre-contract necessity covers steps taken at the candidate’s request before a possible employment contract: reading the CV, scoring the match, scheduling the interview. Legitimate interest covers the surrounding recruitment activity, provided you could justify the balance if asked. Say which one you use in your privacy notice, and save consent for the job it is actually good at: keeping people after the process ends.
When does storing a CV start to need consent?
The purpose that justified holding the CV is “assess this person for this vacancy”, and it expires when the vacancy closes or the candidate drops out. An application is not a subscription. Keeping the CV for roles that do not exist yet is a new purpose, and the realistic lawful basis for it is consent: a talent pool built on anything vaguer tends to collapse under the first serious audit.
| Situation | Usual lawful basis | What you need to do |
|---|---|---|
| Active application | Pre-contract necessity or legitimate interest | No consent needed; state the basis in your privacy notice |
| Keeping a rejected candidate for future roles | Consent | Ask explicitly, record scope and date |
| Talent pool entry | Consent | Same, plus renewal before the window lapses |
| Unsolicited CV | Legitimate interest, briefly | Assess, then ask for consent or delete |
| Profile sourced from a public platform | Legitimate interest plus transparency duties | Inform promptly; get consent to keep long term |
| Hired candidate | Employment contract and legal obligations | Move the data to the employee file |
How do you collect consent that actually holds up?
Four properties decide whether your consent survives scrutiny:
- Specific. Name the purpose and the scope: “keep my profile on file for future vacancies for twelve months”, not “we may retain your data”.
- Informed. Say how long you will keep the CV, what you will use it for, and how to withdraw.
- Freely given. An unticked box, separate from the application submit button. Refusing must have zero effect on the current application.
- Recorded. Store the timestamp, the exact wording shown, and the scope agreed to. Consent you cannot prove is consent you do not have.
Withdrawal deserves equal engineering. It must be as easy as granting, and it takes effect immediately: when a candidate withdraws in month three, the deletion clock starts in month three.
How long does consent last, and how does renewal work?
GDPR sets no expiry date on consent, but EU practice has converged on windows of 6 to 12 months for talent-pool retention. The widely cited Dutch guidance is the concrete version: delete application data within about four weeks of the process ending, or keep it around one year with consent. The exact timelines, including what happens to hired candidates, are in our guide to how long you can keep candidate CVs.
Renewal is where policies meet reality. A workable flow: shortly before the window closes, the system flags the record and you send a short re-confirmation message. An explicit yes restarts the window with a fresh timestamp; silence means deletion, not a quiet extension. In Recruitifly the consent date drives the retention clock, expiring records surface before the deadline, and the Fly assistant can draft the renewal outreach for you to approve. Whatever tool you use, the trigger must come from the system; calendar reminders and good intentions do not scale past about fifty profiles.
What about unsolicited CVs and sourced profiles?
The two cases the textbooks skip are the ones recruiters hit weekly.
Unsolicited CVs. Someone mails you their CV with no vacancy attached. Sending it is a strong signal of interest, but it is not documented consent with a scope and a window. Legitimate interest reasonably covers reading it and replying. If you want to keep it, that reply should ask for consent, named purpose and retention window included. No reply, or no consent: delete it.
Profiles sourced from public platforms. A public LinkedIn or GitHub profile is not consent, and “they posted it themselves” is not a lawful basis. Legitimate interest can cover sourcing for a concrete role, but it comes with transparency duties: the person must learn that you hold their data, normally within a month or at first contact, whichever comes first, and objecting must be easy. If you want a sourced profile in your pool long term, ask for explicit consent when you first reach out. The obligation sits with you as the controller, even when a sourcing tool found the profile for you.
How do you keep proof of consent audit-ready?
An auditor, or a corporate client’s privacy officer, will ask one question: show me who consented, to what, when, and what happens when they withdraw. The evidence that answers it is a timestamp, the wording shown, the scope, the channel it came through, plus withdrawal and deletion logs. Scattered across mailboxes and spreadsheet columns, that evidence technically exists but takes days to assemble. Inside the ATS, it should be one export.
Most established systems, Greenhouse, Workable, and Recruitee among them, ship some form of GDPR consent tooling, so compare on dimensions rather than checkbox lists: does it capture the wording and timestamp, automate renewal, cascade withdrawal into deletion, and export an audit trail? Recruitifly builds this into the platform: consent tracked per candidate, retention clocks enforced automatically with anonymization, and an audit trail of what happened when. The full buying checklist, processor agreements included, is in what makes an ATS GDPR-compliant.
Recruitifly is in private beta. If your consent records currently live in an email folder named “GDPR stuff”, talk to us and see what audit-ready looks like in practice.
Frequently asked questions
Can I keep a CV for future vacancies without asking?
Generally no. The lawful basis that covered the application expires with the process, and holding the CV for future roles is a new purpose that needs its own basis, which in practice means consent. The narrow exception is keeping a limited record for a defined window to defend against legal claims, and that belongs in your retention policy, not in your talent pool.
How long can I store a CV under GDPR?
GDPR sets no fixed number; you may keep a CV as long as the purpose requires. For an active process, that means until the process ends. Dutch guidance treats about four weeks after rejection as reasonable without consent, and around one year with it. Most EU teams set consent windows of 6 to 12 months, then renew or delete.
What counts as valid consent under GDPR?
A freely given, specific, informed, and unambiguous yes, given by a clear action such as ticking an unticked box. It must name the purpose and duration, be refusable without consequences for the current application, and be as easy to withdraw as to give. You also need to prove it later, so record the timestamp, the exact wording shown, and the scope.
Do I need consent for CVs I sourced from LinkedIn?
Not at the moment of sourcing: legitimate interest can cover finding and assessing a profile for a concrete role. A public profile is not consent, though. You must tell the person you hold their data, normally within a month or at first contact, and make objecting easy. To keep them in your talent pool long term, ask for explicit consent when you reach out.
Recruitifly Editorial
Editorial
Related reading
Adding LLM screening to your ATS without creating duplicate records
Layer LLM screening over your ATS without splitting your candidate data: one source of truth, stable ID sync, scores written back as fields, not copies.
Sourcing with adjacent job titles and skills
Searching one job title misses most of the market. A worked SRE example plus a repeatable method for mapping adjacent titles and skills for any role.
AI Act candidate disclosure: notice template
What to tell applicants when automated screening is used, under the EU AI Act and GDPR Articles 13, 14 and 22, plus a copy-paste disclosure notice template.
Want to see how this looks on your own data?
No hard promises. Just a straight conversation about exports, stages, and your current stack.
Contact us