GDPR for recruiters: the 2026 candidate data guide
A practitioner GDPR guide for recruiters: lawful basis, data minimisation, retention, candidate rights under Regulation (EU) 2016/679, and agency roles.
On this page
- What does GDPR actually require recruiters to do?
- What lawful basis applies to candidate data?
- How much candidate data can you collect, and what about sensitive data?
- What candidate rights do recruiters have to honour?
- How long should you keep candidate data, and what about transfers?
- Who is the controller when an agency and an employer share candidate data?
- How does the EU AI Act change recruitment data handling in 2026?
- How Recruitifly helps
GDPR governs candidate personal data across the entire hiring lifecycle, which means a recruiter needs a lawful basis to process each CV, must collect only what the role requires, has to set and honour a retention period, and must answer access, erasure, and objection requests within one month under Regulation (EU) 2016/679. Get those four mechanics right and most compliance follows.
This article is practitioner guidance, not legal advice. National implementations differ; confirm specifics for your market with counsel.
What does GDPR actually require recruiters to do?
GDPR (Regulation (EU) 2016/679) treats every candidate as a data subject with enforceable rights, and it holds you to the seven processing principles in Article 5: lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, and integrity and confidentiality. Article 5(2) adds accountability, meaning you must be able to demonstrate compliance, not just claim it.
For recruiters that translates into a short, practical loop:
- Pick and record a lawful basis before you process a CV.
- Tell the candidate what you do with their data (Articles 13 and 14).
- Collect only what the role genuinely needs.
- Set a retention period and delete on schedule.
- Be ready to handle access, erasure, and objection requests on time.
Enforcement is not theoretical. The employment sector has drawn a meaningful share of GDPR fines since 2018, so candidate-data practice is squarely on regulators’ radar.
What lawful basis applies to candidate data?
Legitimate interest under Article 6(1)(f) is the workhorse basis for active recruitment, because filling an open role is a recognised legitimate interest and processing a relevant professional CV is a proportionate way to pursue it. To rely on it you must run and document the three-part balancing test the EDPB set out in Guidelines 1/2024: identify the interest, show the processing is necessary, and weigh it against the candidate’s rights and reasonable expectations.
Consent under Article 6(1)(a) has a narrower job. Use it where the candidate’s expectation breaks down, most commonly when you want to keep someone in a talent pool after a specific role closes. Consent must be freely given, specific, and as easy to withdraw as to give.
For the deeper decision tree on when to choose each, see our guide to the legal basis for candidate data. Whichever basis you pick, record it; under accountability you must be able to show your reasoning.
How much candidate data can you collect, and what about sensitive data?
Collect only what the role requires. Data minimisation under Article 5(1)© means personal data must be adequate, relevant, and limited to what is necessary for the purpose. A salary-history field, a date of birth, or a photo on an application form is hard to justify for most roles and creates risk for no benefit.
Two categories carry extra duties:
| Data type | Governing article | Extra requirement |
|---|---|---|
| Standard personal data (name, contact, CV) | Article 6 | A lawful basis only |
| Special-category data (health, ethnicity, religion, trade-union, biometric) | Article 9 | Article 6 basis plus a separate Article 9 condition |
| Criminal-offence and conviction data | Article 10 | Processing only under official authority or where member-state law allows |
The cumulative rule trips people up: special-category data needs both a lawful basis under Article 6 and a separate condition under Article 9. Background screening, health questionnaires, and diversity monitoring all touch this. Diversity data, where you collect it at all, should usually be anonymised or aggregated and kept strictly apart from selection decisions, since member-state rules on Article 9 and Article 10 differ widely.
What candidate rights do recruiters have to honour?
Candidates can exercise the full set of data-subject rights, and you generally have one month to respond under Article 12(3), extendable by two further months for complex or high-volume requests if you tell the candidate within the first month. The three you will meet most often in recruitment are:
- Right of access (Article 15): the candidate can ask for a copy of their data and information about how it is used, including any automated decision logic.
- Right to erasure (Article 17): the candidate can ask you to delete their data, subject to exceptions such as a live legal claim. Our walkthrough on a candidate asking to delete their data covers the edge cases.
- Right to object (Article 21): where you process on legitimate interest, the candidate can object, and you must stop unless you show compelling overriding grounds.
A note on automated decisions: Article 22 gives candidates the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. In practice that means an automated CV filter or scoring tool needs a meaningful human review step before anyone is rejected on the strength of it.
How long should you keep candidate data, and what about transfers?
There is no fixed GDPR retention period; you set one under the storage-limitation principle in Article 5(1)(e) and justify it. Common regulator guidance lands around 6 to 12 months for unsuccessful applicants, frequently anchored to the national limitation period for discrimination or unfair-treatment claims, which is itself a member-state question. Anything longer, such as a talent pool, usually rests on consent. The mechanics, including how to delete on schedule, are in our candidate data retention guide.
International transfers are the other lifecycle pressure point. Articles 44 to 49 of Regulation (EU) 2016/679 restrict sending candidate data outside the EU and EEA unless a transfer mechanism applies. The main routes are an adequacy decision under Article 45 (the EU to US Data Privacy Framework adequacy decision took effect on 10 July 2023 for certified US recipients) or appropriate safeguards under Article 46, most often the Standard Contractual Clauses the European Commission adopted in 2021. Because adequacy can be challenged, many teams keep SCCs as a fallback and prefer EU-hosted tooling.
Who is the controller when an agency and an employer share candidate data?
It depends on who determines the purpose and means of the processing, and getting the role wrong undermines your whole compliance position. Three patterns recur:
- Separate controllers: an agency that sources and screens candidates into its own database, and the client employer, each act as independent controllers for their own processing. This is the most common pattern for agencies that build a candidate pool.
- Processor: an agency working strictly on one client’s documented instructions, with no independent use of the data, can be a processor under a written Article 28 agreement.
- Joint controllers: where the agency and client jointly determine purposes that are inextricably linked, Article 26 requires a transparent arrangement allocating who answers candidate requests and provides notices.
The agency model usually points to separate or joint controllership, not processor status. We unpack the test, with worked examples, in controller or processor for a recruitment agency.
How does the EU AI Act change recruitment data handling in 2026?
The EU AI Act (Regulation (EU) 2024/1689) sits on top of GDPR rather than replacing it, and it classifies AI systems used to recruit, filter applications, and evaluate candidates as high-risk under Annex III, point 4(a). Deployer obligations for these systems are scheduled to apply from 2 August 2026, though the European Commission’s Digital Omnibus package (published 19 November 2025) proposes to defer this to 2 December 2027, and EU legislators reached a provisional agreement on that deferral in May 2026. Because it is not yet formally adopted, the 2 August 2026 date still stands as written, so plan against it unless and until the deferral is enacted.
For recruiters using these tools, the practical additions include human oversight of high-risk outputs (Article 14), informing affected workers and their representatives before deployment, and giving candidates an explanation of the main factors in a decision. GDPR still governs the underlying candidate data throughout. Our EU AI Act recruitment checklist maps the deployer duties step by step.
How Recruitifly helps
Recruitifly is built EU-first, so GDPR mechanics are part of the workflow rather than a bolt-on. Candidate-data controls cover lawful-basis tagging, configurable retention with scheduled deletion, and access and erasure handling, so data-subject requests do not become fire drills. The Agency Hub keeps agency and client data appropriately scoped for separate or joint-controller setups, posting compliance checks flag risks in job ads before they go live, and EU data residency keeps candidate records inside the region. The Fly assistant supports recruiters with a human review step in the loop, in line with the human-oversight expectation for high-risk hiring tools. See features for detail.
Recruitifly is in private beta. If candidate-data compliance is a priority for your team, talk to us and join the beta.
Frequently asked questions
What lawful basis should recruiters use for candidate data under GDPR?
Most recruiters rely on legitimate interest under Article 6(1)(f) of Regulation (EU) 2016/679 for sourcing and assessing applicants, supported by a documented three-part balancing test. Consent under Article 6(1)(a) is used for talent-pool retention beyond a role. Special-category data under Article 9 needs a separate condition on top of the Article 6 basis.
How long can a recruiter keep an unsuccessful candidate's CV?
GDPR sets no fixed retention period. You must define one yourself under Article 5(1)(e) and justify it. Common regulator guidance points to roughly 6 to 12 months for unsuccessful applicants, often tied to the limitation period for discrimination claims, which varies by member state. Keeping a CV in a talent pool beyond that usually requires consent.
Is a recruitment agency a controller or a processor under GDPR?
It depends on who decides the purpose and means. An agency that sources, screens, and builds its own candidate pool is usually a controller. An agency acting strictly on a single client's instructions can be a processor. Where decisions are inextricably linked, the agency and client may be joint controllers under Article 26 and need a written arrangement.
Does GDPR or the EU AI Act govern AI hiring tools in 2026?
Both apply at once. GDPR (Regulation (EU) 2016/679) governs the candidate personal data the tool processes, including the Article 22 rules on automated decisions. The EU AI Act (Regulation (EU) 2024/1689) classifies recruitment and candidate-evaluation systems as high-risk under Annex III, with deployer obligations scheduled from 2 August 2026.
Recruitifly Editorial
Editorial
Related reading
Adding LLM screening to your ATS without creating duplicate records
Layer LLM screening over your ATS without splitting your candidate data: one source of truth, stable ID sync, scores written back as fields, not copies.
Sourcing with adjacent job titles and skills
Searching one job title misses most of the market. A worked SRE example plus a repeatable method for mapping adjacent titles and skills for any role.
AI Act candidate disclosure: notice template
What to tell applicants when automated screening is used, under the EU AI Act and GDPR Articles 13, 14 and 22, plus a copy-paste disclosure notice template.
Want to see how this looks on your own data?
No hard promises. Just a straight conversation about exports, stages, and your current stack.
Contact us