GDPR

GDPR and recruiting: best practices for recruiters

CVDesignPro·August 20, 2026·6 min read
GDPRCVDesignPro

GDPR governs how candidates' personal data is processed — CVs, contact details, interview notes, scorecards. It's not abstract paperwork: three habits cover most of a recruiter's day-to-day obligations.

1. A limited retention period

A CV can't sit indefinitely in a database "just in case." The generally accepted practice is 2 years after the last contact with the candidate (application, interview, exchange), unless the candidate explicitly agreed to being kept longer in a talent pool. After that, the data must be deleted or anonymized.

2. Consent, tracked

Applying to a posting counts as consent for that hiring process. Keeping the profile for other future opportunities requires a separate, explicit opt-in from the candidate — not a pre-checked box. That consent needs to be dated and traceable, not just assumed.

3. The right to access, correct, and be forgotten

A candidate can ask at any time: what data is held about them, to correct it, or to have it fully deleted. The request must be handled within a reasonable timeframe (one month is the usual benchmark). An unjustified refusal exposes the company, not just the individual recruiter.

What this means concretely in the pipeline

  • Track the consent date and retention deadline for each candidate, not just their stage in the process.
  • Only share CVs and notes with people actually involved in this hiring process — not the whole HR team out of habit.
  • Systematically anonymize or delete rejected candidates' profiles once the retention period lapses, rather than waiting for a request.
  • Document rejections with a factual, professional reason — useful if challenged, and never based on protected characteristics (origin, age, family status…).

In CVDesignPro

Every candidate record under the GDPR tab shows the consent date and retention deadline, with an alert as the deadline approaches — so these three habits happen without extra thought on every application.

Not a hiring bottleneck

Handled well, GDPR compliance is a trust signal to candidates, who are increasingly attentive to how their data is handled — especially in sensitive sectors (finance, healthcare, public sector) where the question regularly comes up in interviews.

Put these practices to work

Pipeline, distribution, calendar, evaluations: your whole hiring process in one place.

Open my recruiter workspace