All insights
Compliance

GDPR-compliant ATS: what to look for

A GDPR-compliant ATS covers consent tracking, scheduled retention, data-subject requests, and a watertight processor agreement. What to check before buying.

RE
Recruitifly Editorial
Editorial
2026-06-11·4 min read
On this page

A GDPR-compliant ATS gives every candidate record a lawful basis, tracks consent, deletes data on a schedule, answers access and erasure requests quickly, and comes with a signed data processing agreement. The software cannot make you compliant by itself, but the right one makes compliance the default instead of a quarterly cleanup project.

This is practical guidance for recruiters, not legal advice. For decisions that depend on your specific situation, involve your counsel or privacy officer.

What are the GDPR requirements for an ATS?

GDPR never mentions applicant tracking systems. It sets principles for anyone processing personal data, and recruitment is personal data processing from the first CV onward. An ATS earns the “GDPR-compliant” label when its features map cleanly onto those principles:

GDPR principle What the ATS must support
Lawful basis Record why you hold each candidate: active application, consent, or legitimate interest
Purpose limitation Keep talent-pool data separate from active processes, with separate clocks
Data minimization Configurable fields, so you collect what the role needs and nothing extra
Storage limitation Retention periods per purpose, enforced automatically
Integrity and security Encryption, role-based access, audit logs of who saw and changed what
Accountability Exportable evidence that all of the above actually happened

Two structural points matter as much as features. First, you are the controller and the vendor is your processor, so their duties only bind through a contract, covered below. Second, where the vendor stores and processes data decides whether you also inherit international transfer obligations. EU data residency is a separate question that deserves its own checks.

Consent is not the default basis for an active application; assessing someone who applied is normally covered by pre-contract necessity or legitimate interest. Consent becomes central the moment you want to keep someone for a future role, a talent pool, or a different client. A compliant ATS should:

  1. Capture consent with a timestamp, the exact wording shown, and the scope agreed to.
  2. Distinguish scopes: application processing, talent-pool retention, reference checks.
  3. Make withdrawal as easy as granting, and act on it without manual digging.
  4. Trigger renewal or deletion when consent ages past your policy.

If consent lives in an email thread or a spreadsheet column, you do not have consent management. You have evidence scattered across systems that a regulator may one day ask you to assemble in a hurry.

What retention features does a GDPR-compliant ATS need?

Storage limitation is where recruitment teams quietly fail, because deletion is nobody’s favorite task. Look for retention schedules attached to purposes, not just to records: a rejected applicant’s clock differs from a consented talent-pool profile, which differs from a placed candidate whose data feeds invoicing. The system should delete or anonymize on schedule without a human remembering, and log what it did. Anonymization matters because it lets your funnel metrics survive after the person is gone. Common timelines, including the widely cited Dutch four-week and one-year guidance, are covered in our guide to how long you can keep candidate CVs.

How does an ATS handle data-subject access requests?

Candidates can ask what you hold on them, demand corrections, and request erasure, and you generally have one month to respond. Without tooling, a single request means trawling mailboxes, spreadsheets, and chat logs. With proper tooling, it is an export button and a deletion action with an audit entry. Check that erasure cascades: notes, messages, interview feedback, parsed CV data, and uploaded files should all go, not just the profile row. Ask the vendor to demonstrate a request end to end before you sign; it is the fastest way to separate marketing claims from working software.

What should the processor agreement cover?

The data processing agreement (DPA) is where compliance becomes enforceable. Under Article 28 it must bind the vendor to documented instructions, confidentiality, appropriate security, sub-processor approval, assistance with data-subject requests and breaches, deletion or return of data at contract end, and audit rights. Practical extras worth checking: a published sub-processor list with change notifications, breach notification timelines that leave you room to meet your own 72-hour duty to the authority, and clarity on where support staff access data from. A vendor that hesitates to share its DPA is telling you something.

A short vendor checklist

  1. Consent tracking with scope, timestamp, and easy withdrawal.
  2. Retention schedules with automatic deletion and anonymization.
  3. One-action data export and cascading erasure for data-subject requests.
  4. Role-based access and audit trails.
  5. A signed DPA with a published sub-processor list.
  6. EU hosting, or a clearly documented transfer mechanism.

Running a desk for several clients adds wrinkles of its own, from candidate ownership to client-side data sharing; our guide to GDPR duties when recruiting for clients covers those.

Recruitifly was built with this baseline included rather than bolted on: consent tracking, scheduled retention and anonymization, data-subject request handling, and audit trails are part of the core feature set, and the platform’s data, cache, and storage are all EU-hosted.

Recruitifly is currently in private beta. If you would rather have compliance as a default than as a side project, talk to us and join the beta.

Frequently asked questions

Does using a GDPR-compliant ATS make my agency GDPR-compliant?

No. The ATS is a processor; you remain the controller who decides why and how candidate data is used. A good ATS automates retention, consent, and request handling, but you still need your own lawful bases, privacy notice, processing records, and working habits that match what the software promises.

Do I need consent to process every CV?

No. For an active application you can usually rely on pre-contract necessity or legitimate interest. Consent becomes the right basis when you want to keep a candidate after the process ends, for example in a talent pool. Whatever basis you use, record it and explain it in your privacy notice.

What is a data processing agreement and do I need one with my ATS?

Yes. Under GDPR Article 28, any vendor that processes personal data on your behalf must be bound by a written agreement covering instructions, confidentiality, security, sub-processors, breach support, and deletion when the contract ends. Reputable ATS vendors offer a standard DPA; if a vendor cannot produce one, walk away.

How fast must I answer a candidate's access or deletion request?

Within one month of receiving it, in most cases. You can extend by two further months for complex requests, but you must tell the candidate within the first month. An ATS that exports a candidate's full record and deletes or anonymizes it in one action turns this from a project into a task.

RE

Recruitifly Editorial

Editorial

Related reading

Want to see how this looks on your own data?

No hard promises. Just a straight conversation about exports, stages, and your current stack.

Contact us