Home › Blog › Compliance

GDPR for Recruiters: What You May Keep, For How Long, and What Candidates Can Ask

Compliance8 min read
Organised bright desk with a laptop showing a tidy candidate list and a lock icon

Every CV in your inbox, every WhatsApp application, every interview note in a drawer is personal data under GDPR - and the informal hiring workflow of a typical small employer breaks the rules at half a dozen points nobody ever decided on. The good news: recruitment GDPR is mostly about deciding three things once - basis, clock, and process - and letting a system enforce them.

Key takeaways
  • Applications are personal data from the second they arrive - CVs in an inbox are a GDPR surface.
  • Recruitment runs on legitimate interest; keeping people for future roles runs on consent.
  • Set a retention clock and let it actually delete - unlimited keeping is the most common violation.
  • Access and deletion requests are rights, not favours; the WhatsApp-and-spreadsheet workflow fails them.

For an active vacancy, you generally do not need consent: processing applications is covered by pre-contractual steps and legitimate interest - candidates apply precisely so you will process their data. The basis has edges, though: it covers assessing this application for this role, not everything you might fancy doing later.

How long may I keep applications?

As long as the purpose lasts, plus a defensible buffer - then deletion has to actually happen. Common practice keeps rejected-candidate data for a period around six months to a year (jurisdictions and advice vary, partly tracking discrimination-claim windows), and pool candidates for the consented period, often a year or two with renewal. The number you pick matters less than three properties: it is written down, it is told to candidates, and something enforces it.

That last one is where inboxes fail. An email account never deletes anything; a 2019 folder of CVs is a standing violation and a breach payload waiting for one phishing click.

What can a candidate demand?

  1. Access: a copy of what you hold - including interview notes about them. Write notes you could hand over.
  2. Erasure: deletion where no legal ground justifies keeping - for a rejected candidate past your window, that is usually everything.
  3. Rectification and information: corrections, and knowing what you do with their data - which your privacy notice should already answer.
  4. Timescale: generally a month. 'It is in Marko's old phone' is not an exemption.

Where do small employers actually get burned?

Rarely by regulators hunting cafes - usually by a disgruntled candidate who knows their rights, an ex-employee dispute that widens, or a breach that exposes years of hoarded CVs. The pattern in every case: data kept with no purpose, spread across personal devices, with no deletion story. Centralising applications in one system with roles, retention automation and an export path converts all three risks into a settings page.

The takeaway

Pick your bases, set the clock, centralise the data, and make erasure a button rather than an archaeology project. GDPR-compliant hiring is not extra work - it is the same work, done in one place, with an expiry date.

Qwiza ships this by default: candidate data lives in one system, retention periods auto-delete expired records and their files, erasure requests are one click, and nothing sensitive is collected in the first place.

CVs from 2021 still in the inbox?

Qwiza keeps candidate data in one place with automatic retention, one-click erasure and no sensitive fields collected - 48-hour pilot target.

See how Qwiza works

Frequently asked questions

Do I need consent to process job applications?

For an active vacancy, generally no - pre-contractual necessity and legitimate interest cover assessing the application. You do need consent, clearly given and withdrawable, to keep candidates for future roles in a talent pool, and a privacy notice telling applicants what happens either way.

How long can I keep a rejected candidate's CV?

Practice commonly lands around six months to a year, informed by local discrimination-claim windows, unless the candidate consented to a longer pool retention. The critical part is enforcement: a written period that nothing deletes is a policy, not compliance.

A candidate asked me to delete their data - must I?

If no active process or legal ground requires keeping it, yes, and generally within a month - including copies in inboxes and interview notes. If part of it must be kept, say for an ongoing dispute, delete the rest and explain what remains and why.

Keep reading