Talent & Workforce

GDPR Candidate Consent

GDPR Candidate Consent refers to using a candidate's freely given, informed agreement as the legal basis for collecting and processing their personal data under Europe's data-protection framework, one of several lawful bases recruiters can rely on and generally not the default choice for core recruiting activity. The framework's specific requirements must be confirmed with a qualified data-protection adviser.

Is consent always the legal basis recruiters need for candidate data?

No, and this is the part most explanations of GDPR in recruiting get wrong. Consent is only one of several lawful bases the framework recognizes, and for the core steps of a hiring process, such as reviewing an application or scheduling an interview, many employers rely on a different basis, often closer to the steps necessary to enter into a contract with the candidate, rather than consent. That distinction matters, because consent has to be freely given and must be capable of being withdrawn at any time without penalty. If a candidate could withdraw agreement to be considered for a role at any point and the company had to stop processing the application on request, that is a fragile foundation for something as central as a hiring pipeline. Which basis actually applies to a given activity is a legal determination that has to be confirmed with a qualified data-protection adviser rather than assumed from a general description like this one.

What does giving candidates clear information at the point of collection actually involve?

In practical terms it means telling a candidate, in plain language near the moment a [job application](/job-descriptions) is submitted, what data is collected, why, roughly how long it will be kept, and who else might see it, whether an [applicant tracking system](/ats) vendor, an assessment provider, or a background-check partner. This is usually a short, readable privacy notice linked from the application form rather than buried in a lengthy general privacy policy the candidate never opens. Keeping a record of what was presented to candidates and when matters too, since showing what was communicated is part of demonstrating the process was handled properly. None of this requires legal jargon. The opposite is usually true, since notices written entirely in compliance language tend to fail the plain-language expectation the framework generally encourages. What the notice must cover still depends on the specific rules that apply and should be reviewed with counsel.

How should a company handle a candidate's request to access or delete their data?

A candidate generally has the right to ask what data a company holds about them and to request that it be deleted, and a company needs a real process for handling that request within whatever timeframe the applicable rule sets, not an ad hoc scramble each time it happens. In an [ATS setup](/ats-implementation) with data spread across resumes, notes, assessment scores, and email threads, actually fulfilling a deletion request can be more involved than it sounds, which is one reason companies increasingly build the capability to search and delete a candidate's full record as a standard system feature rather than a manual export. How quickly a request must be honored, what counts as a valid request, and what limited exceptions might apply are all specifics that vary and have to be confirmed against the current rule rather than assumed from general practice.

How long can a candidate's data be kept for future roles, and what about third parties?

Keeping a candidate's profile on file for a role that might open later is common practice, but it usually needs its own specific basis and a defined retention period rather than sitting indefinitely on the theory that it might be useful someday. An indefinite hold is one of the more common practical problems data-protection advisers flag when they review a recruiting process. Third parties add another layer. A [recruitment agency](/recruitment-agency-software), an assessment vendor, or a video-interview platform that also touches candidate data needs its own lawful basis and its own agreement with the hiring company about how that data is handled, and the company doing the hiring generally cannot assume its own basis automatically covers every vendor in the chain. Exactly how long is appropriate, and what a specific agency or vendor relationship requires, is a jurisdiction- and contract-specific question that should go to counsel or a data-protection adviser, not a rule of thumb.

See how Pitch N Hire handles gdpr candidate consent on your roles

Choosing your recruiting stack

Next step

FAQ

GDPR Candidate Consent — FAQs

If consent isn't the usual legal basis, why do candidates still see consent checkboxes? +
Some companies use consent for specific, genuinely optional processing, such as adding someone to a talent pool for future roles or a marketing newsletter, where the withdrawal problem is less disruptive, while relying on a different basis for the core application process itself. Seeing a checkbox does not tell you which basis is actually being used for which piece of processing; that has to be checked in the company's own privacy notice.
Can a candidate withdraw consent at any time? +
Where consent genuinely is the legal basis being relied on, yes. Withdrawal has to be as easy as giving it, and the company must stop that specific processing once consent is withdrawn. This is exactly why consent is often a poor fit for the parts of a hiring process that cannot simply stop midway, which is why many employers rely on a different basis for those steps.
Does GDPR apply to a company outside Europe hiring European candidates? +
It can, depending on the specifics of where the candidates are and what the company is doing, and this is a genuinely complex cross-border question that trips up companies who assume the employer's own location is what matters. Any company hiring across borders should get a clear answer on this from a data-protection adviser rather than guess.
What happens to a candidate's data if they're rejected? +
Practice varies, but a defined retention period for rejected candidates, after which the data is deleted or anonymized, is generally the expectation rather than keeping every application indefinitely. How long that period should be, and whether it differs by role or region, is a policy decision that should be set with counsel, not left to default system behavior.
Built for recruiters & hiring teams

See GDPR Candidate Consent in action

Pitch N Hire unifies sourcing, screening and hiring decisions on one AI-native platform. Book a quick demo on your real roles.

Prefer to talk? Book a demo · View pricing

Free 1-user plan · No credit card · Talk to a real hiring expert

One Hiring Infrastructure.
Zero Tool Chaos.

Demos are consultative. We respect privacy and enterprise
governance. No lock-ins.

Start free Book demo