Consent or legitimate interest for candidate data under GDPR?
Why consent is usually the wrong GDPR legal basis for recruitment, and how to rely on legitimate interest (Art 6(1)(f)) with a documented LIA in 2026.
On this page
- Why is consent the wrong basis for most recruitment?
- When is legitimate interest the right basis instead?
- How do you run the three-part Legitimate Interests Assessment?
- When do you genuinely still need consent?
- How does special-category data change the legal basis?
- How do you document and disclose your legal basis?
- How Recruitifly helps
For active recruitment and sourcing, legitimate interest under Article 6(1)(f) of the GDPR is usually the correct legal basis, not consent, because consent can be withdrawn at any time and is rarely “freely given” given the power imbalance between an employer and an applicant. Consent has its place, but it is the wrong default for processing applications and sourcing candidates. This guide explains which basis to pick, how to document it, and where consent is genuinely required.
This article is practitioner guidance, not legal advice. National implementations differ; confirm specifics for your market with counsel.
Why is consent the wrong basis for most recruitment?
Consent is the wrong default because it is fragile, conditional, and hard to rely on in a hiring relationship. The GDPR (Regulation (EU) 2016/679) requires consent to be freely given, specific, informed, and unambiguous. The European Data Protection Board, in Guidelines 05/2020 on consent, is explicit that a clear imbalance of power exists between an employer and a job applicant, so an applicant cannot usually give consent without feeling pressure, which means the consent is not “freely given” and therefore not valid.
Three practical problems follow:
- Consent can be withdrawn at any time under Article 7(3), and it must be as easy to withdraw as it was to give. If a candidate withdraws halfway through a process, your basis for processing their application disappears.
- You carry the burden of proving consent was validly obtained, which means storing consent records for every candidate.
- A pre-ticked box, a buried clause in your privacy notice, or “by applying you agree” wording does not produce valid consent. Silence or inactivity never counts.
If you cannot proceed without the data, consent is the wrong tool, because consent only works where the candidate genuinely could say no without losing anything.
When is legitimate interest the right basis instead?
Legitimate interest under Article 6(1)(f) is the right basis for the core of recruitment: receiving and assessing applications, screening, shortlisting, interviewing, and sourcing professional candidates for a specific role. The logic is straightforward. A recruiter has a real and present interest in filling a vacancy, the candidate’s professional data is necessary to assess fit, and a candidate who applies or who is a public professional reasonably expects to be evaluated.
Recital 47 of the GDPR supports this: legitimate interest is strongest where there is a “relevant and appropriate relationship” between the controller and the data subject, and where processing happens in line with the candidate’s reasonable expectations. Someone who submits an application reasonably expects you to read, score, and store it for the duration of that hire.
The EDPB Guidelines 1/2024 on processing under Article 6(1)(f), released on 8 October 2024, confirm that commercial interests can qualify as legitimate, while tightening how the assessment must be done. So legitimate interest is not a free pass: it is a defensible basis only if you have actually worked through and recorded the three-part test below.
For deciding who runs the LIA and holds the record, see whether you are acting as a controller or a processor for candidate data, because the responsibility sits with the controller.
How do you run the three-part Legitimate Interests Assessment?
Run the three-part test before processing and write it down. An LIA has three parts, and you must pass all three.
| Test | Question it answers | What to record |
|---|---|---|
| Purpose test | Is there a real, specific, lawful interest? | The vacancy or sourcing goal, why it matters now, who benefits |
| Necessity test | Is the processing necessary, with no less intrusive route? | What data you use, why each field is needed, what you excluded |
| Balancing test | Do the candidate’s rights and expectations override your interest? | Reasonable expectations, sensitivity of data, safeguards, opt-outs |
A worked checklist for an application-processing LIA:
- State the interest precisely: assessing this candidate’s suitability for a named open role, not “general recruitment”.
- Confirm necessity: you need their CV, contact details, and work history to assess fit, and you are not collecting health, photos, or social media you do not need.
- Assess reasonable expectations: an applicant expects evaluation; a passive candidate sourced from a public profile expects a relevant approach, not bulk marketing.
- List safeguards: a clear privacy notice, defined retention, access controls, and an easy way to object under Article 21.
- Reach a conclusion and date it: record the named decision-maker and keep the LIA so you can demonstrate accountability under Article 5(2).
- Re-run the LIA if the purpose changes, for example if you later want to reuse the data for a different role.
The balancing test is where most assessments fail. If you would not be comfortable telling the candidate exactly what you are doing with their data, the balance probably tips against you.
When do you genuinely still need consent?
Consent is the right basis when you process candidate data in a way they would not reasonably expect, where they can genuinely decline without losing the role. The clearest example is keeping a candidate’s data after the vacancy they applied for has closed. Holding a CV in a talent pool for future, unrelated roles falls outside the original purpose and outside their reasonable expectation, so the cleaner basis is fresh, specific consent to be retained for future opportunities.
Situations where consent is usually the better or required basis:
- Talent-pool or “keep me on file” retention beyond the role applied for, where consent should be specific and time-bound.
- Some sourcing of passive candidates where your approach goes beyond a one-off relevant contact, for example adding them to a long-term marketing or nurture stream.
- Contacting referees the candidate did not nominate, or processing data from sources the candidate would not anticipate.
For how long you may hold data and when retention crosses into needing consent, see our guidance on how long to keep candidate CVs. Where you do rely on consent, build a one-click withdrawal and a record of when and how consent was captured, because under Article 7(3) it must be as easy to withdraw as to give.
How does special-category data change the legal basis?
Special-category data under Article 9 needs a second condition on top of your Article 6 basis, and for recruitment that usually means explicit consent. Article 9(2) of the GDPR covers data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data, health data, and data concerning sex life or sexual orientation.
Processing any of these requires both an Article 6 basis (often legitimate interest) and, separately, an Article 9(2) condition. The two most relevant in hiring are:
- Article 9(2)(a): the candidate has given explicit consent for one or more specified purposes. “Explicit” is a higher bar than ordinary consent, usually a signed statement or clear written confirmation.
- Article 9(2)(b): processing is necessary to carry out obligations in the field of employment and social-security law, where Union or national law provides for it, for example statutory diversity reporting or disability accommodation duties.
In practice, do not collect special-category data unless you have a concrete, lawful reason and a matching Article 9 condition documented in advance. Equality-monitoring data should be separated, voluntary, and kept apart from the hiring decision. For the wider picture of how legal basis fits alongside notices, retention, and candidate rights, start with our GDPR for recruiters guide.
How do you document and disclose your legal basis?
Document the basis before processing and disclose it in your privacy notice. Two records sit at the heart of accountability under Article 5(2): your Record of Processing Activities (Article 30) and your LIA where you rely on legitimate interest. The privacy notice you give candidates must, under Articles 13 and 14, name the legal basis, state the legitimate interest pursued where that is your basis, set out retention periods, and explain the right to object under Article 21 (for legitimate interest) or to withdraw consent under Article 7(3) (for consent).
A minimum documentation set:
- A processing record mapping each recruitment activity to its Article 6 basis, and any Article 9 condition.
- A completed, dated LIA for each legitimate-interest purpose, refreshed when purposes change.
- A candidate privacy notice published before or at the point of collection.
- Consent and withdrawal logs where consent is the basis, with timestamps.
How Recruitifly helps
Recruitifly is built EU and GDPR first, so legal basis is treated as a first-class field rather than an afterthought. The platform lets you record the basis and retention rule against candidate records, supports separate handling of special-category data away from the hiring decision, and gives candidates clear routes to object or withdraw, with retention timers that prompt action before data ages out. Posting compliance checks help keep vacancy adverts and data-collection wording aligned with what you actually disclose, and the Fly assistant can surface where a candidate’s basis, notice, or retention status needs attention. You can see the candidate-data controls on the features page.
Recruitifly is in private beta. If you want to handle candidate legal basis, LIAs, and retention without spreadsheets, talk to us and join the beta.
Frequently asked questions
Should recruiters use consent or legitimate interest for candidate data?
For active recruitment and sourcing, legitimate interest under Article 6(1)(f) of the GDPR (Regulation (EU) 2016/679) is usually the correct basis, not consent. The European Data Protection Board warns in Guidelines 05/2020 that consent is rarely freely given because of the employer-applicant power imbalance, so it is fragile and easily withdrawn.
What is a Legitimate Interests Assessment (LIA)?
An LIA is a documented record showing your processing meets the three-part test in Article 6(1)(f): a purpose test (a real, specific interest), a necessity test (no less intrusive way to achieve it), and a balancing test (your interest is not overridden by the candidate's rights). Complete it before processing and keep it on file.
When do recruiters actually need candidate consent?
Consent is appropriate for processing a candidate cannot reasonably expect, such as keeping a CV in a talent pool for future roles after a vacancy closes, or contacting referees they did not nominate. Special-category data under Article 9 usually needs explicit consent under Article 9(2)(a) unless an employment-law condition in 9(2)(b) applies.
Can a candidate withdraw consent and force deletion of their data?
If consent is your legal basis, yes. Under Article 7(3) of the GDPR, consent can be withdrawn at any time, and it must be as easy to withdraw as to give. That is why consent is poor for core hiring: relying on legitimate interest instead gives candidates an objection right under Article 21, not an automatic withdrawal.
Recruitifly Editorial
Editorial
Related reading
Adding LLM screening to your ATS without creating duplicate records
Layer LLM screening over your ATS without splitting your candidate data: one source of truth, stable ID sync, scores written back as fields, not copies.
Sourcing with adjacent job titles and skills
Searching one job title misses most of the market. A worked SRE example plus a repeatable method for mapping adjacent titles and skills for any role.
AI Act candidate disclosure: notice template
What to tell applicants when automated screening is used, under the EU AI Act and GDPR Articles 13, 14 and 22, plus a copy-paste disclosure notice template.
Want to see how this looks on your own data?
No hard promises. Just a straight conversation about exports, stages, and your current stack.
Contact us