GDPR in Recruitment
No items found.

GDPR in employee recruitment: consents, data retention, and a secure process

Ensuring compliance with personal data protection regulations is a key responsibility for every Talent Acquisition team and HR department. Errors in application collection procedures, lack of control over CV retention, or improperly drafted consent forms can lead not only to severe penalties imposed by the Personal Data Protection Office (UODO) but also to a loss of candidate trust and damage to the employer's reputation.

GDPR in recruitment requires processing data based on appropriate legal grounds: the Labor Code for basic data, and the candidate's voluntary consent for additional data and future recruitment processes. A secure process relies on fulfilling the information obligation (Article 13 of the GDPR), strictly adhering to established data retention periods, and using HR systems that automate the deletion and anonymization of applications once the process is complete.

Legal grounds for data processing in recruitment

To legally process a job candidate's personal data, an employer must have a clear legal basis as defined in Article 6 of the General Data Protection Regulation (GDPR). In the Polish legal system, the key is linking the GDPR with the provisions of the national Labor Code.

The Labor Code and the scope of candidate data

In accordance with Article 22 § 1 of the Labor Code, an employer has the right to request that a job applicant provide a strictly defined scope of personal data:

  • First name(s) and surname
  • Date of birth
  • Contact details (provided by the candidate, e.g., phone number, email address)
  • Education
  • Professional qualifications
  • employment history

Processing the above data for the purpose of conducting current recruitment does not require separate consent from the candidate. The legal basis in this case is taking steps at the request of the data subject prior to entering into a contract (Article 6(1)(b) of the GDPR) and compliance with a legal obligation to which the controller is subject (Article 6(1)(c) of the GDPR).

When is candidate consent absolutely required?

Candidate consent (Article 6(1)(a) of the GDPR) becomes necessary in two primary situations:

  1. Excessive (additional) data: If a candidate includes data in their CV that goes beyond the scope defined by the Labor Code (e.g., a photo, interests, or image in the form of a video recording), its processing is based on voluntary consent. Sending such data by the candidate on their own initiative is considered a clear affirmative action.
  2. Future recruitment (Talent Pool): If a company wishes to retain a CV after the current recruitment process has ended for the purpose of future vacancies, it must obtain separate, voluntary, and unambiguous consent from the candidate.

Tip: An employer cannot make participation in the current recruitment process conditional upon providing consent for data processing for future recruitment purposes.

Information obligation (Article 13 GDPR) in HR practice

Every data collection process must involve providing the candidate with full information about who will process their data, for what purpose, and under what terms. The information obligation must be fulfilled at the time of data collection — most commonly by including an information clause in the job advertisement or application form.

Clause Element
Required Content Pursuant to Art. 13 GDPR
Data Controller Identity
Full company name, registered office address, contact details (e.g., email to HR/DPO).
Purpose and Legal Basis
Conducting the recruitment process (Labor Code / Art. 6(1)(b) and (c) GDPR) and optionally future recruitments (consent / Art. 6(1)(a) GDPR).
Data Recipients
Information about data processors acting on behalf of the controller (e.g., ATS system vendors, IT infrastructure providers).
Retention Period
Duration of the recruitment process or a specified timeframe in case of consent for future recruitments (e.g., 12 months).
Candidate Rights
Right to access, rectify, erase data, restrict processing, and withdraw consent at any time.
Right to Lodge a Complaint
Information on the right to lodge a complaint with the supervisory authority (President of the Personal Data Protection Office - PUODO).

Consent for data processing — common myths

Many misunderstandings have grown around GDPR consent in recruitment, often leading to unnecessary delays in selection processes.

Myth 1: The absence of a GDPR clause on a CV disqualifies a candidate

If a candidate sends a CV in response to a specific job posting, the act of sending the document itself is an action aimed at participating in the process. If the CV contains only data required by the Labor Code, the lack of a manually written "GDPR clause" does not prevent the application from being considered, provided the employer has fulfilled the information obligation in the job posting.

Myth 2: Consent for future recruitment can be granted "forever"

In accordance with the storage limitation principle, data cannot be processed indefinitely. Consent for processing data in talent pools must specify a precise or determinable timeframe (e.g., "for a period of 24 months"). After this time, the data must be deleted, or the company must obtain renewed consent from the candidate.

Data retention and secure database purging (Talent Pool)

One of the most common irregularities detected during data protection audits in HR departments is the retention of outdated CV files on network drives, in recruiters' email inboxes, or in folders not designed for this purpose.

Retention periods for application documents

  1. Successful recruitment: The CV of the hired candidate is moved to their personnel file (Part A) and is stored in accordance with regulations concerning employee documentation.
  2. Unsuccessful candidates (no consent for future processes): Documents must be deleted immediately after the recruitment process concludes and the contract is signed with the selected individual. Short-term storage of data is permitted solely for the purpose of defense against potential claims (e.g., allegations of discrimination in recruitment), which requires justification based on the legitimate interest of the controller (Article 6(1)(f) GDPR).
  3. Candidates in the talent pool (consent for future processes): Data is stored for the period specified in the consent. It is worth maintaining systematic data retention, for example by using dedicated modules when choosing a modern ATS, which automatically anonymize files after the consent period expires.

Proper data hygiene when building your own talent pool helps maintain a high level of security while reducing the time needed to search for suitable profiles.

GDPR and specific recruitment methods

Modern HR is increasingly moving away from relying solely on traditional CV submissions from job boards. Sourcing on social media, automation, and referral recruitment require additional precautions.

Direct Search and sourcing on LinkedIn

Acquiring candidates through Direct Search involves processing the data of individuals who have not applied directly to the company. Browsing public profiles is permitted, but saving a candidate's data in the company's recruitment system requires fulfilling the information obligation under Article 14 of the GDPR (at the latest upon first contact with the candidate).

Employee Referral

A common mistake is for recruiters to accept CVs of acquaintances that are brought or sent directly by current employees. This practice violates GDPR rules, as the referred person has not consented to the transfer of their data to a specific controller.

A secure employee referral model:

  • The employee provides their acquaintance with a unique link to the job posting or recruitment platform.
  • The candidate visits the website themselves, reviews the information clause, and submits their application independently, including the required consents.
  • Using a dedicated solution, such as ShareHire, ensures that the entire path of consent and data collection is 100% automated and GDPR-compliant.

You can read more about the legal aspects of referral programs in our guide on GDPR in referral programs.

Checklist: How to audit your recruitment process for GDPR compliance

To ensure that your organization's recruitment processes are fully secure and compliant with regulations, verify them using the following checklist:

  • [ ] Verify job posting content: Check that every job posting includes a clear information clause in accordance with Article 13 of the GDPR.
  • [ ] Separate consent forms: Ensure that consent for the current recruitment process is separate from consent for future recruitment processes.
  • [ ] Review application channels: Eliminate the practice of accepting paper CVs at the reception desk or having them sent to the private email addresses of hiring managers.
  • [ ] Implement automatic retention: Set up automatic rules in your ATS or recruitment tool to delete applications once the consent expiration date has passed.
  • [ ] Secure data access: Limit permissions to view candidate profiles to only those individuals directly involved in a specific recruitment process.
  • [ ] Train your HR team and managers: Ensure that those conducting interviews know which questions are prohibited (e.g., regarding marital status, family plans, or health status).
  • [ ] Sign data processing agreements (DPA): Ensure you have signed data processing agreements with all your HR Tech software providers.

Frequently Asked Questions (FAQ)

Does a candidate need to include a GDPR clause in their CV for a company to consider their application?

No. Under Article 6(1)(b) of the GDPR, the processing of data specified in the Labor Code for current recruitment purposes is initiated by the candidate. The absence of a clause in a CV does not disqualify an application, provided the company has fulfilled its information obligation in the job posting. Consent is only required for future recruitment purposes or for redundant data.

How long can CVs be legally stored after recruitment ends?

Once the process is complete and a candidate has been selected, the CVs of other applicants should be deleted unless they have provided voluntary consent to participate in future recruitment. If consent for future processes is obtained, the standard and safe retention period is 12 to 24 months.

Can a candidate's data be collected from their LinkedIn profile without their knowledge?

Simply viewing a public profile is permitted, but downloading data and entering it into a company's applicant tracking system (ATS) constitutes personal data processing. This requires fulfilling the information obligation toward the candidate (Article 14 of the GDPR) no later than at the time of the first contact.

How can employee referrals be handled safely under GDPR?

A secure model involves the employee sending a referral link to a friend so they can apply and provide the necessary consents themselves, or using a dedicated referral portal that automates the collection of consents and the fulfillment of the information obligation.

Key takeaways

  • The legal basis depends on the purpose: Current recruitment is based on the Labor Code and steps taken to enter into an agreement, whereas building a database for the future requires the candidate's voluntary consent.
  • The information obligation is essential: Every job posting and application form must clearly inform the candidate who is processing their data and for what purpose.
  • Retention under strict control: Storing CVs without current consent is a direct path to GDPR non-compliance. The process of deleting outdated data should be automated.
  • Security of modern channels: Using methods such as employee referrals requires the implementation of tools that eliminate the risk of sharing third-party CVs without their knowledge.

What's next?

Do you want to organize your company's referral program and ensure that the entire recommendation process is 100% GDPR compliant? Consult on a secure referral model with ShareHire experts and learn how automation helps protect data while increasing recruitment efficiency.

Please note: This article is for informational and educational purposes only and does not constitute binding legal advice. If you have any doubts regarding the implementation of data protection procedures in your specific organization, we recommend consulting with a Data Protection Officer (DPO) or legal counsel.