All insights
Compliance

Does GDPR apply to freelance recruiters?

Yes. Even a one-person desk is a data controller under GDPR and the Dutch AVG. The minimum setup: lawful basis, privacy notice, retention, deletion handling.

RE
Recruitifly Editorial
Editorial
2026-06-12·6 min read
On this page

Yes. GDPR applies to a freelance recruiter exactly as it applies to a 200-seat agency: the moment a CV lands in your inbox, you are a data controller with the full set of obligations. In the Netherlands the AVG, which is simply the GDPR under its Dutch name, makes no exception for company size either. The workable news is that the compliant setup for a one-person desk is small: a lawful basis for each candidate, a privacy notice, a retention schedule, and a way to honor deletion requests.

This is practitioner guidance, not legal advice. For decisions that hinge on your specific situation, involve counsel or a privacy professional.

Why does GDPR apply to a desk of one?

GDPR applies to anyone who processes personal data in the course of business, and recruitment is personal data processing from end to end. A CV, your screening notes, a WhatsApp thread with a candidate, a shortlist email to a client: all of it is personal data, and you decide why it is collected and what happens to it. That decision-making role is what makes you a controller. The household exemption covers purely private activity like your own address book and stops the moment you recruit for money.

Registering as a ZZP’er or sole trader changes nothing. The AVG, enforced by the Autoriteit Persoonsgegevens, attaches obligations to the processing, not the headcount. A desk of one has the same duties as a desk of fifty, just fewer hands to carry them: an argument for a minimal, automated setup, not for skipping it.

What is the minimum compliant setup?

Four pieces, none of which require a lawyer on retainer:

  1. A lawful basis per candidate. An active application is normally covered by pre-contract necessity or legitimate interest. Keeping someone on file after the process ends runs on consent. Know which applies to each record and write it down.
  2. A privacy notice. A page on your site, linked when you first receive or approach a candidate: what you collect, why, how long, who you share it with, and how to exercise rights. Candidates you source cold must be told too, within a month.
  3. A retention schedule. The widely used Dutch norm is four weeks after a process ends, or about one year with consent; the numbers and their caveats are in our guide on how long to keep CVs. What matters is having a schedule and actually deleting on it.
  4. A way to honor requests. Candidates can ask what you hold, demand corrections or erasure, and you generally have one month to respond. You need to find everything about one person, export it, and delete it, including notes and forwarded copies.

That is the floor. A simple register of processing activities is cheap insurance on top: recruitment is regular processing, so the record-keeping exemption for small businesses is narrower than most freelancers assume.

Which mistakes catch freelance recruiters most often?

  • CVs living in email and cloud drives forever. A mailbox has no retention clock, and search-by-attachment is not a deletion workflow. Five years of CVs in your inbox is liability you cannot even enumerate.
  • No retention policy at all. “I keep everything in case a role comes up” is a purpose without a limit, which is exactly what the storage-limitation principle forbids.
  • Sharing CVs without the candidate knowing. Sending someone’s profile to a client they never agreed to be introduced to is the most complained-about habit in the trade. Tell candidates which company a role is with before their CV travels.
  • Consent that would not survive a question. A pre-ticked box, or a verbal “sure, keep me on file” with no record of when and for what, is evidence you would not want to present.

Are you a controller or a processor for client work?

Both roles exist in freelance recruiting, and your contract should say which one you are playing for each engagement, because the duties differ.

How you work Your role What the contract should cover
Your own talent pool; you decide who to approach and put forward Controller in your own right That you process candidate data independently, with your own notice and retention
The client hands you their applicants to screen by their instructions Processor for the client A processor agreement (GDPR Article 28): instructions, security, deletion at contract end
You introduce candidates; the client runs its own process after Two separate controllers Who informs the candidate, when responsibility hands over, who deletes what

For a typical freelance headhunter the first or third row is the reality: you are a controller, not a supplier of paper. Clients sometimes push a processor agreement at you because their template says so; signing one that mislabels the relationship muddies who must answer when a candidate exercises rights. A paragraph in your terms settles it.

What can an ATS automate for you?

The setup above is mostly discipline, which is exactly what software is for. A decent system gives every record a retention timer tied to its situation, stores consent with a timestamp and scope, answers an access request with an export, and makes erasure cascade through notes, messages, and files instead of leaving copies behind. Whether you pick Recruitifly, Recruitee, Teamtailor, or anything else, test those four behaviors on a trial before trusting them; our checklist for a GDPR-compliant ATS walks through what to verify.

Recruitifly ships GDPR tooling in every tier rather than as an enterprise add-on: the Freelancer tier at EUR 70 per month (EUR 58 billed annually) includes retention rules, consent records, and deletion workflows on EU infrastructure, alongside the pipeline and posting features on the features page. The Fly assistant handles routine parts, like deleting a candidate on request or drafting the confirmation reply, and proposes every change for you to confirm. Whether a solo desk needs a system at all is a fair prior question; we wrote do I need an ATS as an independent recruiter for exactly that. No tool makes you compliant by itself: the lawful bases and the notice remain yours to own.

What is the realistic risk for a solo recruiter?

Not a regulator knocking unannounced. The realistic sequence: a candidate asks where their CV went or why a strange client called, gets a vague answer, and files a complaint with the Autoriteit Persoonsgegevens, a web form away. The authority then asks you to demonstrate the basics: basis, notice, retention, request handling. Fines scale with severity, not with your size, but the common first-line outcomes are warnings and orders, and the real costs are weeks of attention and a client watching you handle it badly.

Obligations do not shrink with company size; effort can. A one-person desk that keeps candidate data in one system with the timers running is in better shape than many mid-sized agencies. Recruitifly is in private beta at the moment; if you want to see the retention and deletion workflows running on your own desk, talk to us and bring one live role.

Frequently asked questions

Am I a data controller as a freelance recruiter?

Yes, in almost every setup. You decide which candidates to approach, what to record about them, and which clients see them, and deciding the purpose and means of processing is the definition of a controller. Working alone, part-time, or through a personal BV changes nothing. You only act as a processor when a client hands you their data and dictates exactly how you handle it.

Can I keep CVs in my email under GDPR?

Email storage is not banned, but a mailbox fails the practical tests: no retention clock, weak access control, and deletion that never reaches forwarded copies. If a CV arrives by email, move it into one system of record and delete the attachment. Treat the inbox as a doorway, not an archive, and apply the same rule to cloud-drive folders.

Do I need a privacy policy as a solo recruiter?

Yes. GDPR's transparency duty applies to controllers of any size, so candidates must be told what you collect, why, how long you keep it, who receives it, and how to exercise their rights. A clear page on your website, referenced when you first receive or approach a candidate, covers it. Candidates you source cold must get the same information within a month.

What happens if a candidate complains about my data handling?

They can complain directly to the supervisory authority, in the Netherlands the Autoriteit Persoonsgegevens, without warning you first. The authority can then ask you to demonstrate the basics: lawful basis, privacy notice, retention practice, and how you handled their request. Outcomes range from advice and orders to fines in serious cases. The practical damage is usually time, stress, and a client watching it unfold.

RE

Recruitifly Editorial

Editorial

Related reading

Want to see how this looks on your own data?

No hard promises. Just a straight conversation about exports, stages, and your current stack.

Contact us