What GDPR actually requires from recruitment software and hiring processes — written for HR teams, not lawyers.
If you hire candidates located in the EU or UK, GDPR applies to your recruitment process — regardless of where your company is headquartered. This is a practical overview, not legal advice; consult counsel for your specific obligations.
CVs, application forms, interview notes, assessment results, and even informal recruiter notes about a candidate are all personal data under GDPR. That means they're subject to the same lawful-basis, retention, and access-request rules as any other personal data your company holds.
Most recruitment processing relies on "legitimate interest" (you need the data to evaluate the candidate for a role) rather than consent, though some activities — like keeping a CV on file for future roles after a rejection — typically do require explicit consent.
GDPR doesn't set a fixed retention period for candidate data, but it requires you to define one and stick to it. A common practice is 6–12 months for rejected candidates unless the candidate has separately consented to a talent pool.
Candidates can request access to the data you hold on them, ask for corrections, or request deletion. Your recruitment software needs to make it realistically possible to fulfill these requests — not just store data, but locate and export or delete it on demand.
Browse HR compliance tools or check a specific country's requirements on our country pages.