Recruiting Basics

Candidate Data Consent (GDPR)

Candidate data consent is a freely given, informed and revocable agreement from an applicant that their personal data may be processed for a stated recruiting purpose. Under GDPR it is one lawful basis among several rather than the only route. Rules differ across jurisdictions and frameworks, so confirm which basis applies with qualified legal counsel.

What makes candidate consent valid?

Valid consent is a positive choice the person could have refused without penalty and can withdraw afterwards. In recruiting that means telling the applicant who is collecting the data, what will be done with it, how long it will be held, who else may see it and how to change their mind, expressed in language an ordinary reader understands rather than buried in a policy link nobody opens. Pre-ticked boxes and agreement bundled into a mandatory step are weak, because no genuine option existed. Consent also has to be recorded, including the wording displayed, the timestamp and the version of the notice in force at the time. Frameworks describe these conditions differently and enforcement varies, so treat this as the general shape and let qualified counsel confirm specifics for your markets.

Is consent the right lawful basis for recruiting data?

Frequently it is not, which surprises teams who assume consent is the safe default. GDPR sets out several lawful bases and consent is only one of them; processing necessary to take steps at the candidate's request before entering a contract, or a properly documented legitimate interest, often fits an application better. Consent is fragile by design. It can be withdrawn at any moment, at which point the processing must stop, and the burden of proving it was ever given rests with the employer. A talent pool assembled on consent that cannot be evidenced years later is a pool you may not be able to use. Selecting a basis is a legal judgment, not a product setting, so confirm it with counsel instead of copying another company's privacy notice.

What does consent hygiene look like for a talent pool?

Treat the record as part of the data rather than as paperwork. Store the timestamp, the exact wording accepted, the purpose it covered and the channel it arrived through, so reusing a profile two years later becomes a decision you can defend. Reuse is where most teams slip. Someone who agreed to be considered for one role has not necessarily agreed to sit in a general pool indefinitely, and a short re-permission message before a new campaign is both safer and better received than silence. Keep withdrawal immediate and easy, including a path that genuinely stops sourcing outreach rather than only marketing email. Any [candidate sourcing tool](/candidate-sourcing-software) connected to the hiring system must honour the same flags, because a suppression living in one place is not a suppression.

How should you handle deletion and access requests?

Name an owner and define the route before the first request arrives, since the clock starts when the candidate asks rather than when the message reaches the right desk. Someone has to locate every copy: the primary record, exported spreadsheets, notes kept elsewhere, scheduling tools and anything fed by an integration. Verify identity proportionately, act, and log what was done and when. Watch for records you cannot simply erase, because some data may need to be retained to defend a legal claim or to satisfy another obligation, and the interaction between deletion rights and retention duties is precisely the question that belongs with counsel. Building this capability into [talent acquisition](/talent-acquisition) operations early costs far less than improvising against a deadline.

See how Pitch N Hire handles candidate data consent (gdpr) on your roles

Choosing your recruiting stack

Next step

FAQ

Candidate Data Consent (GDPR) — FAQs

Does applying for a job count as giving consent? +
Submitting an application is usually understood as the candidate asking you to consider them, which is not the same thing as consent to every later use such as long-term pool storage or outreach about unrelated roles. Many employers rely on a different lawful basis for the application itself and seek explicit permission for the extras. Which reading applies where you operate is a question for counsel.
How long can a candidate stay in a talent pool? +
For as long as your documented retention rule allows and no longer, with the period justified by purpose rather than convenience. Because permitted durations differ by jurisdiction and record type, the number belongs in a policy your legal counsel has approved. Practically, refreshing permission before a new campaign both respects the person and keeps the pool useful, since stale profiles rarely convert anyway.
What is the difference between a controller and a processor here? +
The employer deciding why and how candidate data is processed generally acts as controller, while a vendor processing it on the employer's instructions acts as processor. The distinction drives who answers a candidate's request, who signs which contract terms and where responsibility sits after an incident. Agency and outsourced recruiting arrangements complicate it, so have the roles confirmed in writing rather than assumed.
Do you need consent to source someone from a public profile? +
Publicly visible does not automatically mean freely usable, and the answer varies by jurisdiction. Many frameworks still require a lawful basis, a privacy notice at first contact and a way to object. Some regions apply additional restrictions to unsolicited outreach. Sourcing teams should work to a documented approach reviewed by counsel rather than assuming that visibility equals permission.
Built for recruiters & hiring teams

See Candidate Data Consent (GDPR) in action

Pitch N Hire unifies sourcing, screening and hiring decisions on one AI-native platform. Book a quick demo on your real roles.

Prefer to talk? Book a demo · View pricing

Free 1-user plan · No credit card · Talk to a real hiring expert

One Hiring Infrastructure.
Zero Tool Chaos.

Demos are consultative. We respect privacy and enterprise
governance. No lock-ins.

Start free Book demo