HR Software

How does GDPR affect the recruiting software we choose?

Under GDPR your organisation is the controller and the software vendor is the processor, so you need a data processing agreement, a stated lawful basis for handling applicant data, a privacy notice candidates actually see, working mechanisms for access and deletion requests, and clarity on where data is stored and transferred. Confirm specifics with counsel.

What does GDPR require of a recruiting system?

Four capabilities, in practical terms. A privacy notice presented at the point of application, describing what you collect, why, how long you keep it and who else processes it. A defensible lawful basis for the processing, which for recruitment is commonly legitimate interests or steps taken before entering a contract rather than consent, since consent given by an applicant to a prospective employer is hard to call freely given. Working mechanisms for individual rights: access, correction, deletion and objection, executable within the product rather than through a support ticket. And records of what happens to the data, meaning where it is stored, which subprocessors handle it and how transfers outside the region are covered. Ask vendors to demonstrate each of these rather than to confirm compliance in general terms.

What is the controller and processor split?

You decide why and how candidate data is processed, which makes your organisation the controller and puts the legal accountability with you. The vendor processes data on your documented instructions, which makes them the processor. That relationship must be set out in a data processing agreement covering scope, duration, security measures, subprocessor approval, assistance with individual rights, breach notification and deletion at the end of the contract. Read it rather than filing it, and check it does not contradict the main terms. The clause worth particular attention is any permission for the vendor to use customer data for their own purposes, such as product improvement or model training, since that would place them outside a pure processor role for that activity and needs to be assessed separately.

Which questions should you ask vendors specifically?

Where is candidate data stored, and can the region be specified. Which subprocessors are involved, including parsing, email delivery, video hosting and any AI provider, and how are changes to that list notified. What transfer mechanism covers data leaving the region. How is a deletion request executed, and does it cover attachments, notes and email history. Can retention rules be configured per region. Is there an audit trail showing who viewed a candidate record. How quickly are breaches notified and to whom. Get written answers and keep them with your records, since your accountability obligation means you must be able to show why you considered the processor appropriate. These sit naturally alongside [the wider security questions you put to vendors](/ats), and most serious suppliers answer them routinely.

Where does AI screening complicate things?

Automated decision-making that produces legal or similarly significant effects on a person carries additional obligations, including informing candidates and providing a route to human review. Whether a given screening feature crosses that threshold depends on how it is used: a ranking that a recruiter reviews is treated differently from an automatic rejection with no human involvement. Ask vendors precisely what their AI features do, whether any decision is taken without a human, where the processing happens, and whether candidate data is used to train models. Then document your own use, since the obligation attaches to how you deploy the tool rather than to the tool itself. Where you rely on [AI-assisted screening](/resume-screening-software), keep a human decision point and record it, and have counsel review the arrangement before it goes live.

Want Pitch N Hire to handle this for your team?

Related glossary terms

Related roles to hire

Choosing your recruiting stack

Next step

FAQ

Frequently asked questions

Do we need candidate consent to use an ATS? +
Usually not as the lawful basis for processing an application, since legitimate interests or pre-contractual steps typically fit better and consent from an applicant is difficult to treat as freely given. Consent is more relevant for keeping someone in a talent pool for future roles. Confirm the analysis with counsel, since the assessment depends on your specific processing.
Does GDPR apply if we are based outside Europe? +
It can, where you process the data of people located in the EU or UK in connection with offering roles to them. Hiring internationally therefore brings the requirements into scope regardless of where your company sits. Where they apply, you may also need a representative in the region, which is a question for counsel rather than for your vendor.
Can candidate data be stored outside the EU? +
Yes, with an appropriate transfer mechanism and an assessment of the destination. What matters for vendor selection is whether the supplier can tell you exactly where data sits, whether region selection is available, and what covers transfers to their subprocessors. Vagueness here is a practical problem because your accountability obligation requires you to document it.
Who handles a candidate data request, us or the vendor? +
You do, as controller, and the vendor must assist. In practice that means the product should let your team find, export, correct and delete an individual's records without escalating to support. Test this during evaluation with a sample record, and note the turnaround, because your response deadline does not extend because a vendor is slow.
Built for recruiters & hiring teams

See how much faster your team could hire

Get a personalized walkthrough of Pitch N Hire on your own roles and workflow. No slides, no obligation.

Prefer to talk? Book a demo · View pricing

Free 1-user plan · No credit card · Talk to a real hiring expert

One Hiring Infrastructure.
Zero Tool Chaos.

Demos are consultative. We respect privacy and enterprise
governance. No lock-ins.

Start free Book demo