GDPR/LOPDGDD in recruiting: a practical guide without jargon

Legal bases, transparency, transfers, and contracts, explained for HR teams.

In recruitment, we process personal data every day. The framework is simple if we get down to earth. At Mainder, we see three pillars: choosing the right legal basis, informing and respecting rights, and monitoring transfers and contracts with suppliers.

On legal grounds: if the person has applied for a specific vacancy, we may process their data for "pre-contractual measures," but only for that process and for the necessary time; it is not used to store it "just in case" in the future. Consent is valid when it is freely given, informed, and easy to withdraw; it should not be a condition for applying, and it is best used for talent pools and to retain CVs after the application process closes. Legitimate interest applies to proactive searches and networking if we conduct an internal test (LIA,Legitimate Interest Assessment), we inform you upon initial contact and provide a clear avenue for objection; be careful not to expand use without warning. The legal obligation applies to verifications required by law (for example, accreditations or compliance with equality and non-discrimination) and is limited to what is strictly necessary.

Transparency and candidate rights: The privacy notice should explain who we are and how to contact us, what we use the data for and on what basis, who we share it with, whether transfers will occur outside the EEA and with what safeguards, how long we retain the information, what rights the individual has (access, rectification, erasure, restriction, objection, and portability) and how to exercise them, as well as the contact information of the DPO, if applicable. If we use automated decision-making, we should clearly explain what the system does, why it may affect the application, and how to request human review. As an operational rule, we should respond to rights requests within one month and document the process.

International transfers and the US framework: We first check for "adequacy" (EU-recognized country). If not, we use Standard Contractual Clauses (SCCs) with a transfer impact assessment (TIA) and complementary measures if the risk warrants it. With suppliers in the US, we can rely on the EU-US Data Privacy Framework if the entity is certified; if not, we revert to SCCs and TIAs. We keep a simple record of transfers and conduct periodic reviews.
Data Processing Agreements (DPAs) with suppliers: Every supplier that processes data on our behalf must sign a contract detailing the purpose, duration, data categories, security measures, subprocessor rules, rights assistance and DPIAs, breach notification, reasonable audits, and the fate of the data upon termination of the service (return or verifiable deletion). Common red flags include: the supplier claims to be “responsible” for data reuse, reserves vague uses such as “service improvement” without limits, denies audits or notification periods, fails to identify subprocessors or countries of processing, or moves data outside the EEA without a valid basis.

Retention and minimization: Collect only what is necessary to evaluate the application and set clear deadlines. As a guide, retain CVs and process notes for the duration of the process plus a reasonable period to defend against claims; if we want to maintain a talent pool, use renewable consent and delete when the deadline expires or when consent is withdrawn. For interview videos and technical tests, consider shorter deadlines and anonymization when aggregate analysis is sufficient.

If you want to operate with peace of mind, consider this order: adequate and documented legal basis, clear notification to the candidate, proof that you're fulfilling your rights in a timely manner, transfers with guarantees, and DPAs without loopholes. At Mainder, we can help you review your recruiting workflow with a practical and compliance-by-default approach.

And you, how do you justify your legal basis for proactive searches today? What simple explanation do you give to a candidate if there's automated support in the screening process? What's your elimination criteria for talent pools and video interviews?

Frequently asked questions

What is the legal basis for processing candidate data in recruiting?

Four bases apply in recruiting. Pre-contractual measures cover someone who has applied to a specific vacancy, but only for that process and only for the time needed, not to store the CV just in case. Consent fits talent pools and keeping CVs after a process closes: it must be freely given, informed, easy to withdraw, and never a condition for applying. Legitimate interest covers proactive searches and networking, provided you run a Legitimate Interest Assessment, inform the person at first contact, and offer a clear way to object. Legal obligation covers checks required by law, such as accreditations or equality and non-discrimination duties, and is limited to what is strictly necessary.

How long can you keep a candidate's CV under GDPR?

Only for as long as you can justify. Collect only what you need to evaluate the application and set clear deadlines. As a guide, keep CVs and process notes for the duration of the process plus a reasonable period to defend against claims. If you want to maintain a talent pool beyond that, use renewable consent and delete the data when the deadline expires.

How quickly must you answer a candidate's data rights request?

Within one month, as an operational rule, and you should document how you handled it. This applies to every right the candidate can exercise: access, rectification, erasure, restriction, objection and portability. Your privacy notice has to explain how to exercise them. If automated decision-making may affect the application, explain clearly what the system does, why it may affect the outcome, and how to request human review.

Can you transfer candidate data outside the EU?

Yes, with safeguards. First check for adequacy, meaning a country recognised by the EU. If there is none, use Standard Contractual Clauses with a transfer impact assessment, plus complementary measures if the risk warrants it. With suppliers in the United States you can rely on the EU-US Data Privacy Framework when the entity is certified; if it is not, you revert to SCCs and a TIA. Keep a simple record of transfers and review it periodically.

What should you check in a DPA with a recruiting vendor?

Every supplier processing data on your behalf must sign a contract covering purpose, duration, data categories, security measures, subprocessor rules, assistance with rights and DPIAs, breach notification, reasonable audits, and the fate of the data when the service ends, whether return or verifiable deletion. Common red flags: the supplier claims to be a controller so it can reuse the data, reserves vague uses such as service improvement without limits, denies audits or notification periods, fails to identify subprocessors or countries of processing, or moves data outside the EEA without a valid basis.

Keep reading

+250 clients

Discover how to scale your recruiting processes with AI

Automate tasks, find top talent faster, and scale your recruiting processes with Mainder.