How does GDPR affect the recruiting software we choose?
Under GDPR your organisation is the controller and the software vendor is the processor, so you need a data processing agreement, a stated lawful basis for handling applicant data, a privacy notice candidates actually see, working mechanisms for access and deletion requests, and clarity on where data is stored and transferred. Confirm specifics with counsel.
What does GDPR require of a recruiting system?
Four capabilities, in practical terms. A privacy notice presented at the point of application, describing what you collect, why, how long you keep it and who else processes it. A defensible lawful basis for the processing, which for recruitment is commonly legitimate interests or steps taken before entering a contract rather than consent, since consent given by an applicant to a prospective employer is hard to call freely given. Working mechanisms for individual rights: access, correction, deletion and objection, executable within the product rather than through a support ticket. And records of what happens to the data, meaning where it is stored, which subprocessors handle it and how transfers outside the region are covered. Ask vendors to demonstrate each of these rather than to confirm compliance in general terms.
What is the controller and processor split?
You decide why and how candidate data is processed, which makes your organisation the controller and puts the legal accountability with you. The vendor processes data on your documented instructions, which makes them the processor. That relationship must be set out in a data processing agreement covering scope, duration, security measures, subprocessor approval, assistance with individual rights, breach notification and deletion at the end of the contract. Read it rather than filing it, and check it does not contradict the main terms. The clause worth particular attention is any permission for the vendor to use customer data for their own purposes, such as product improvement or model training, since that would place them outside a pure processor role for that activity and needs to be assessed separately.
Which questions should you ask vendors specifically?
Where is candidate data stored, and can the region be specified. Which subprocessors are involved, including parsing, email delivery, video hosting and any AI provider, and how are changes to that list notified. What transfer mechanism covers data leaving the region. How is a deletion request executed, and does it cover attachments, notes and email history. Can retention rules be configured per region. Is there an audit trail showing who viewed a candidate record. How quickly are breaches notified and to whom. Get written answers and keep them with your records, since your accountability obligation means you must be able to show why you considered the processor appropriate. These sit naturally alongside the wider security questions you put to vendors, and most serious suppliers answer them routinely.
Where does AI screening complicate things?
Automated decision-making that produces legal or similarly significant effects on a person carries additional obligations, including informing candidates and providing a route to human review. Whether a given screening feature crosses that threshold depends on how it is used: a ranking that a recruiter reviews is treated differently from an automatic rejection with no human involvement. Ask vendors precisely what their AI features do, whether any decision is taken without a human, where the processing happens, and whether candidate data is used to train models. Then document your own use, since the obligation attaches to how you deploy the tool rather than to the tool itself. Where you rely on AI-assisted screening, keep a human decision point and record it, and have counsel review the arrangement before it goes live.
Related glossary terms
Related roles to hire
Choosing your recruiting stack
Next step
Frequently asked questions
Do we need candidate consent to use an ATS?
Does GDPR apply if we are based outside Europe?
Can candidate data be stored outside the EU?
Who handles a candidate data request, us or the vendor?
See how this works in a real applicant tracking system
Pitch N Hire is an applicant tracking system built for recruiters and hiring teams. If this answer described something you want to run properly, the ATS is where it lives.
Free for 1 user Β· No credit card Β· Talk to a real hiring expert
See how much faster your team could hire
Get a personalized walkthrough of Pitch N Hire on your own roles and workflow. No slides, no obligation.
Prefer to talk? Book a demo Talk to sales View pricing
Free 1-user plan Β· No credit card Β· Talk to a real hiring expert