Back to all articles
18 min read

GDPR and AI in recruitment: how to handle candidate data and retention periods

GDPR and AI in recruitment: find out which candidate data you may process, which legal basis applies, and how long you can retain application data.

GDPR and AI in recruitment: a recruiter checking candidate data privacy and retention rules on a laptop
Key points

Keep a clear line between active applicants and sourced candidates, each with its own retention period and purpose for holding the data. Use AI purely to search and summarise, while the actual selection decision always stays with a human.

4 weeksThe standard retention period for application data without the candidate's explicit consent.
1 yearThe maximum period for keeping candidate data once consent has been given.
Human judgementAI helps organise information, but a human makes the final call.
No free passPublic LinkedIn data is still personal data requiring careful balancing.

Under GDPR, AI in recruitment only works if you can use candidate data with a clear purpose, keep it to what's genuinely necessary, and delete it on time. Applicants, passively sourced candidates and people in a talent pool are usually subject to different rules. That's why it pays to map out, step by step, which legal basis applies, what the minimum data requirement is, and when you need to delete it or stop processing it. This article makes that practical, so you can put it to work straight away.

  • Choose a clear purpose for each step. This determines exactly which candidate data you may and may not process.
  • Keep applicants, LinkedIn sourcing and talent pools clearly separate. Don't default to the same legal basis or retention period for all three.
  • In the Netherlands, application data is typically kept for four weeks without consent, or up to a year with consent, under Dutch Data Protection Authority (Autoriteit Persoonsgegevens) guidance; check your own regulator for the equivalent benchmark.
  • Treat an AI tool as a processor in most cases, when it only acts on your instructions. Note: you remain responsible yourself for the purpose, the legal basis and the data you feed into it.
  • Use AI to support searching, organising and summarising, but always leave the final judgement to a human.

How GDPR and AI in recruitment come together in sourcing and selection

AI is playing an increasingly large role in recruitment. You'll see it in searching, approaching, summarising and, sometimes, in making an initial selection. Because this involves names, CVs, work history, contact details and personal notes, privacy quickly comes into play. Whenever GDPR and AI in recruitment meet, it always comes down to the same basic questions: what's the purpose, what data is genuinely necessary, and how long are you allowed to keep it?

For recruitment under GDPR, this means you look at the process first and only then at the tool. Technology doesn't change the privacy rules. The core question is always why you're using certain data, whether it's actually needed for your legal basis for sourcing, and whether you can explain that the candidate could reasonably expect this. That approach makes GDPR-compliant recruitment and selection a lot more workable in practice.

2 / 9

Why GDPR and AI in recruitment work differently for applicants, sourcing and talent pools

Active applicant

An active applicant has responded to a vacancy themselves or is already in an ongoing process. In that situation, you may process the data needed to assess the application: name, contact details, CV, motivation, work history and targeted notes on suitability. Even so, you don't need to store everything. Under GDPR, every note involving candidate data needs a clear purpose and must be relevant to the role.

A simple example makes this clear: if someone applies for a sales role, experience, region and availability are usually relevant. A personal remark about someone's family situation or health almost never belongs there. That's why it's wise to keep interview notes factual and avoid unfounded opinions.

Passively sourced professional

A passively sourced professional hasn't applied themselves. You've approached them proactively, for example via LinkedIn. GDPR around LinkedIn sourcing often causes confusion, because public information can feel like data you're free to use however you like. That's a misconception. Public information on LinkedIn is still personal data. A visible profile is not a blank cheque for any use you can think of.

In this situation, you're usually relying on legitimate interest for sourcing. That calls for a genuine balancing test. Is there an actual vacancy or assignment? Is the data you've collected genuinely necessary to approach someone appropriately? And do the candidate's privacy rights not outweigh your commercial interest? Also record why the approach makes sense, what minimum information you're using, and how the candidate can easily object.

Candidate in a talent pool

A talent pool is fundamentally different from an active application or an initial approach. Here, you're storing data for future contact. That calls for a clear purpose, a defined end point and, in almost all cases, explicit consent. That's the core of a GDPR-compliant talent pool. You don't keep candidate data simply because it might be useful someday. You may only store it if the candidate knows exactly what for, for how long, and for what type of vacancies.

Another example helps here. Say someone was rejected for a specific role but would like to stay in the picture for similar positions in the same region. In that case, you can ask for consent to add them to a talent pool, with a hard end date. If the person withdraws that consent later on, you need to delete the data immediately.

3 / 9

A practical approach to GDPR and AI in recruitment, step by step

You can build the approach below straight into your own process. The principle is simple: attach a clear purpose, a possible legal basis, the minimum required data and a strict deletion point to every step. That turns GDPR and AI in recruitment into something genuinely concrete instead of vague and abstract.

Sourcing

  • Purpose: finding a suitable candidate for a specific vacancy or assignment.
  • Possible legal basis: often legitimate interest, provided there's a genuine recruitment purpose.
  • Minimum data: name, job title, relevant experience, location and the specific expertise needed for the role.
  • Retention period: short, and always tied directly to the open vacancy or assignment.
  • When to delete or stop: as soon as the vacancy closes, the match no longer makes sense, or the data simply isn't needed any more.

Approaching

  • Purpose: making first contact about a specific opportunity in the job market.
  • Possible legal basis: usually legitimate interest.
  • Minimum data: name, contact channel, reason for the approach, source and date of contact.
  • Retention period: only for as long as needed for this specific approach and any brief follow-up.
  • When to delete or stop: immediately on objection, opt-out, or as soon as no suitable next step is expected.

Following up

  • Purpose: building constructively on an earlier contact or initial response.
  • Possible legal basis: legitimate interest or preparation for an actual application, depending on the situation.
  • Minimum data: the response, the date, relevant context, and only brief notes with a clear purpose.
  • Retention period: work with a fixed internal clean-up point specifically for inactive leads.
  • When to delete or stop: if someone doesn't want to continue, after your fixed period with no response, or if the context no longer applies.

Application process

  • Purpose: properly assessing whether a candidate is genuinely suitable for the role.
  • Possible legal basis: processing required at the candidate's request as part of the application process, sometimes supplemented with a legitimate interest relevant to the wider selection process.
  • Minimum data: name, contact details, CV, motivation and closely targeted notes on suitability.
  • Retention period: in the Netherlands, application data is typically kept for four weeks without consent, or up to a year with explicit consent, per the practical guidance of the Dutch Data Protection Authority (Autoriteit Persoonsgegevens); check your own national regulator for the equivalent benchmark.
  • When to delete or stop: immediately after the agreed period ends, or sooner if the data is simply no longer needed.

Talent pool

  • Purpose: contacting promising candidates later about suitable future roles.
  • Possible legal basis: almost always explicit consent.
  • Minimum data: name, contact details, relevant work experience, clear preferences for future contact, and the exact date consent was given.
  • Retention period: until the pre-agreed end date, or sooner if the candidate withdraws consent in the meantime.
  • When to delete or stop: immediately on withdrawal of consent, once the formal period expires, or if the underlying purpose no longer applies.

If you want to set this up practically and safely, take a look at our detailed guide on GDPR-conscious AI sourcing. It shows how minimal, relevant data and a scorecard, which the recruiter then assesses themselves, can support a transparent and careful way of working. This never replaces your own judgement per vacancy, but it does make every step in the process a lot easier to explain.

Tip: Elvatix gets more out of every InMail credit. Higher response rates, lower cost per contact.

See how
4 / 9

The three-step test for legitimate interest

The term 'legitimate interest' sounds fairly legal, but you can apply it in a very practical way. Step one is whether there's a genuine interest, such as an open vacancy or a specific assignment. Step two is about necessity: do you genuinely need this specific data to achieve that purpose? Step three is the final balancing act: do the candidate's rights and privacy expectations outweigh your commercial interest? Working with only limited, highly relevant data makes that balancing act far stronger and easier to justify.

A recruiter who approaches someone on LinkedIn for a specific, current vacancy has a much stronger case than a sourcer building broad lists without a concrete purpose. That's why it's essential to record the precise reason for approaching each candidate. That immediately makes the legal basis for sourcing clear.

What you record and what you don't

Data minimisation simply means you only note down what's genuinely necessary. Suitable data includes things like job title, work experience, (relevant) location, specific expertise, and a brief note on why someone is a good fit for the role. Special or irrelevant details about health, ethnicity, religion, political views or other private matters picked up from someone's online presence have no place here. Personal notes without a clear purpose also don't belong in an AI tool for candidate data or in manual recruitment notes.

There's a useful rule of thumb here: if you don't need a particular piece of information to approach or assess a candidate properly, simply don't store it. That keeps your systems clean and avoids awkward discussions about why something was kept.

Public LinkedIn data is, and remains, personal data

Public data on LinkedIn absolutely does not fall outside the scope of privacy law. This kind of data remains an integral part of GDPR and AI in recruitment. You must always be able to explain why you're using this source, exactly what information you're recording, and how the person concerned can easily object. Be transparent from the first point of contact about exactly where the data came from. That's the professional, careful approach, and it's simply the right thing to do for the candidate.

5 / 9

GDPR and AI in recruitment with AI tools and vendors

When an AI tool acts as a processor

An AI tool generally acts as a processor when the software only processes personal data on your instructions and doesn't determine the purpose itself. Think of technology that organises candidates, summarises profiles, or supports the matching process within your own systems. The recruiter or employer remains, in almost all cases, the data controller. Ultimate responsibility for the data therefore sits entirely with you, regardless of whether an external vendor supplies the underlying technology.

What to ask a vendor

Before you buy or activate a new tool, it's wise to ask the vendor some critical questions. First, check whether a solid data processing agreement for recruitment AI is available. Also ask: how is information security arranged? Which sub-processors are used, and where is the data physically stored? Find out how the deletion process works and whether the vendor cooperates with candidates' privacy requests. Finally, always ask exactly which data input is genuinely necessary for the application to function well, to avoid unnecessary data storage.

If you want to better understand how smart tooling fits into day-to-day practice, take a look at our page on LinkedIn integration. There, we show how the relationship between the external source, your internal workflow and the underlying data flows forms part of a sound, practical assessment. For more context and market insights, you can also read our AI in recruitment case studies.

Responsibility stays with the recruiter or employer

The party that ultimately decides why data is used always carries responsibility for the purpose, the legal basis and the actual content of the processing. A vendor supplies the technology, but they can never take over your strategic and legal decisions. That's why it's essential to keep critically assessing, on your own, what data you feed into your systems, how long you hold onto it, and whether the whole process still fits your internal privacy policy.

The practical product context

In day-to-day practice, we consistently focus on processing minimal data, keeping tight process boundaries, and positioning AI correctly within the workflow. Looking at the context of our own sourcing module, for example, it mainly revolves around relevant profile information and a clear scorecard that the recruiter then weighs and assesses themselves. An important part of this product design is that candidate data isn't structurally stored beyond the active session. While that on its own is no formal legal seal of approval, it's genuinely a practical plus that helps a great deal when assessing your data flows and implementing the software more safely.

6 / 9

Candidate rights and automated decision-making in an application

What rights candidates have

Every candidate has the legal right to access, correct and, in certain cases, fully delete their personal data. They can also formally object to specific processing that relies solely on legitimate interest. That's exactly why a crystal-clear recruitment privacy notice matters so much. In it, you explain transparently which data you collect, for what purpose, from which sources, who you share the data with, and how the candidate can exercise their rights without hassle.

When human intervention is needed

Extra care is needed around automated decision-making in an application. This involves automatic decisions that have a genuinely felt (and often legal) effect on a candidate, purely because a system dictates the final outcome. A fully automated, hard rejection with no independent human review is the best-known example. In situations with this kind of impact, a candidate generally has every right to demand human intervention after all.

Why a human tick-box isn't enough

One thing to watch: a token tick-box or a quick glance by a recruiter doesn't legally count as a genuine, independent assessment. If the AI's initial output effectively remains the deciding factor and the recruiter barely applies their own judgement, you're still at risk of unwanted automated decision-making. So use artificial intelligence, first and foremost, purely as a helpful aid for targeted searching, structuring and summarising. Always leave it to the professional to make their own case, with reasons, for why a candidate moves to the next round or is turned down.

7 / 9

Checklist for GDPR and AI in recruitment in your privacy notice and retention schedule

Checklist for your privacy notice

  • Explain the purpose of processing per situation, such as sourcing, applications or talent pool management.
  • Name the appropriate legal basis for each situation.
  • Describe which data categories you use and why exactly that data is needed.
  • State the source of the data, for example an application form or LinkedIn.
  • Explain which recipients or systems the data is shared with.
  • Name the retention period per process, including the practical benchmark for applications.
  • Describe the role of AI in plain language, for example in searching, summarising or supporting selection.
  • Explain exactly how candidates can request access, correction, deletion or object.

Checklist for your internal retention schedule

  • Set a fixed deletion point per process step: for sourcing, approaching, follow-up, applications and the talent pool.
  • Assign a responsible person for each step within your own team.
  • Record when and how you effectively clean up inactive leads.
  • Check whether loose notes kept outside your ATS or CRM also get deleted properly in time.
  • Include concretely how you handle given consent, its withdrawal and any objections.

The difference between GDPR and the EU AI Act

GDPR focuses primarily on personal data, the right legal basis, the rights of data subjects, and careful processing overall. The upcoming EU AI Act, by contrast, sets additional requirements for the use of specific AI systems, depending on their risk level and intended use. There's one thing that's crucial for you as a recruiter to realise: GDPR is already fully in force. So don't sit back and wait for future rules when you're already working with candidate data today.

Do you have specific product questions, or would you like factual information about our own data processing? You can submit a question about data processing at Elvatix through this page and get in touch quickly. That way, you can better judge whether and how a particular tool fits smoothly into your own way of working.

8 / 9

Practical points for agencies working with LinkedIn and AI

Recruitment agencies are often characterised by high working speed and small, flexible teams. That's exactly why a clear, consistent process with firm agreements is the key to success. Decide internally, in no uncertain terms, who decides on new tooling, who's responsible for incoming rights requests, and who proactively keeps an eye on the agreed retention periods. For agency environments in particular, where this dynamic plays out especially strongly, our page on GDPR for recruitment agencies fits well with the complexities of daily practice.

Also stay sharply aware of the line between a client's wishes and your own legal responsibility. If a demanding client asks for broad, unfocused search lists or long-term data storage, that doesn't automatically mean it falls within the bounds of your role and authority. You remain primarily responsible yourself for your own data processing. That's exactly why it's always wise to consistently record the choices you make around sourcing, the actual approach, follow-up and talent pool management, including when (and especially because) a client is putting real pressure on the speed of the process.

9 / 9

Frequently asked questions

Can I proactively approach someone on LinkedIn without their prior consent? Yes, that's permitted in some cases, provided you can demonstrate a genuine legitimate interest and the approach is directly tied to a current, specific vacancy or assignment. In that case, always apply data minimisation, be clear about the source of the data from the first point of contact, and stop processing immediately if the person objects.

How long can I keep CVs and the related application data? In the Netherlands, application data is typically kept for around four weeks without active consent, and up to a year at most with the candidate's consent. Outside an ongoing or completed application process, other retention periods may be appropriate, provided the underlying purpose, the legal basis and the exact deletion point are always crystal clear. Check the equivalent guidance from your own national data protection authority.

Can I add a candidate I've just rejected straight into a talent pool? You can, but in practice almost only if you've obtained clear, unambiguous consent for this beforehand. Always explain to the candidate exactly why you want to keep this data, for what specific period, and for which type of future vacancies they might be approached.

Is the public information on a LinkedIn profile simply free to use? Absolutely not. Public data is, and remains, simply a collection of personal data. For this information too, you need to be able to explain watertight why you're using the data and why this specific processing fits neatly within the legal boundaries of GDPR.

What should I demand, at minimum, from a new AI vendor before buying? Always require a watertight data processing agreement to be signed, and ask probing questions about their information security. Ask about the sub-processors they use, the exact physical location of the data, how final data deletion is handled, and their support for privacy or rights requests. Also ask closely which data is genuinely strictly necessary for reliable, proper use of the tool.

Can AI fully autonomously decide who is rejected and who isn't? You need to be extremely careful with that. The moment a system, in practice, makes decisions entirely on its own about someone's rejection or progression, there's a good chance you're dealing with automated decision-making in an application. To avoid legal complications, it's important to always ensure a genuine, thorough human assessment, backed by well-reasoned and transparent motivation.

A workable, responsible approach always starts with drawing a sharp distinction between active applicants, passively sourced talent and candidates within an established talent pool. Then attach a clear purpose to each individual step, the right, appropriate legal basis, only the minimum data required, and a crystal-clear retention period. Apply this consistently, and GDPR and AI in recruitment become genuinely practical and directly workable for every recruiter, team lead and agency. Important disclaimer: this information is general in nature and explicitly does not constitute formal legal advice. If your organisation involves highly exceptional processes, particularly sensitive personal data or major automation projects, seeking specialist additional legal advice is always a very sound choice.

Try it now

Write a personal message right here

Enter a name or LinkedIn URL and get a personalised message within 30 seconds. No account needed.

1Candidate
2Your profile

Automate your recruitment process, stay GDPR-proof

Elvatix helps you manage retention periods and consent per candidate group. Our AI features support your process while you keep full control and compliance.