Join sells an applicant tracking system (ATS), and General Data Protection Regulation (GDPR) controls are part of the pitch, so read this as field notes from an interested party rather than neutral counsel. It is also not legal advice; for anything with money or a regulator attached, ask a lawyer who knows your member state. What it can be is a map of where the regulation lands on a hiring team in practice, drawn from the seat where our customers’ candidate data lives. The two-minute version is in the GDPR in recruiting glossary entry. This is the longer walk.
Lawful basis settles most of it
When someone applies to your job ad, you do not need a consent checkbox to process the application. Article 6(1)(b) of the GDPR covers processing that is necessary “in order to take steps at the request of the data subject prior to entering into a contract”, and an application is precisely that: a candidate asking you to consider them for one. Screening the CV, circulating it to the hiring team, writing interview notes, recording the decision. All of it sits on that basis, for that role, for as long as the process runs.
The basis runs out where the application ends. Keeping a rejected candidate’s CV for future openings, contacting a sourced profile who never applied, adding anyone to a pool: each of those is a new purpose, and none of them is a step toward the contract the candidate requested. For keeping a rejected CV and for pooling, the basis that holds in every member state is consent under Article 6(1)(a): informed, specific, freely given. Some regulators accept less — France’s CNIL allows a two-year pool on information and a right to object — but consent is the only answer that travels. Sourcing is the odd case out: you cannot ask someone you have never written to, which is why first contact usually rests on legitimate interest, and the consent question arrives with the reply. A pre-ticked box fails the consent test either way, and Article 7(3) adds a duty with teeth: withdrawing consent must be as easy as giving it was.
“Necessary” is doing quiet work in both clauses. Article 5(1)(c) requires personal data to be “adequate, relevant and limited to what is necessary” for the purpose — data minimisation. Applied to screening, the test is whether a field ties to the role’s requirements. A driving-licence question on a delivery role passes. A date-of-birth field sitting on the default application form does not, and a photo upload rarely survives the question “what hiring decision does this inform?”
Retention after rejection has no EU number
The question hiring teams ask most has no EU-wide answer. The GDPR sets no statutory retention period for candidate data anywhere in its text; the storage-limitation principle says only that data may be kept no longer than its purpose requires. What fills the gap is practice, and the practice anchors on discrimination claims: national law gives a rejected candidate a window to allege that the decision discriminated, the length of that window differs by member state, and keeping the hiring record until it closes is a defensible purpose. Keeping the CV “in case something opens up” is a different purpose, and it needs its own footing — in most of the EU, the candidate’s consent.
National regulators publish reference points. France’s data protection authority, the CNIL, advises that an unsuccessful candidate’s file can be kept for two years after the last contact, longer only with the candidate’s formal agreement. That is French guidance; it travels well as a sanity check and it overrides nothing in your own jurisdiction. The durable move is unglamorous: pick a window on advice, write it into the privacy notice, and let the system enforce it. A stated number that runs down automatically beats a generous policy nobody executes.
Talent pools change the purpose
Moving a rejected candidate into a talent pool is the moment their data changes purpose, so it is the moment to ask. France is the documented exception: the CNIL accepts a two-year pool on information and a right to object, no consent required. Everywhere else, and for any pool that crosses borders, the ask is the only answer that holds. The ask works when it is separate from the application, plainly worded, and scoped: may we keep your profile for future roles, for this long, withdrawable here. Folded into a privacy policy it fails “informed”; pre-ticked it fails “freely given”; and if withdrawal takes a certified letter, it fails Article 7(3). Pools also age badly by default: the person who said yes two years ago has usually forgotten, which is why the withdrawal path has to keep working long after the recruiter who built the pool has moved on.
What we built for the one-month clock
Candidate rights carry the only hard deadline in this post. Under Article 15 a candidate can demand confirmation that you hold their data and a copy of it; under Article 17 they can require erasure when the data is no longer necessary or consent is withdrawn. Article 12(3) gives you one month from receipt to act, extendable by two further months for complex or numerous requests, provided you tell the candidate about the extension, with reasons, within the first month. Requests from rejected candidates tend to arrive when the relationship is already sour. The clock does not care.
This is the part of the product you could screenshot. Consent status sits at the top of every candidate profile in Join. A data export — machine-readable JSON plus a PDF — is one click, which is the Article 15 copy obligation reduced to a button. Redaction replaces personal fields with placeholders while keeping the hiring record intact, for cases where the team’s decision trail has to outlive the person’s data. Erasure under Article 17 propagates across backups instead of stopping at the visible profile. We built it that way because the one-month clock rewards teams whose response to a request is an action inside the tool rather than a project for the quarter.
Controller and processor: who answers for what
Using an ATS moves the storage, never the responsibility. You, the employer, remain the controller: you decide why candidate data is processed and what happens to it. The ATS is your processor, acting on your instructions. Article 28(3) requires that relationship to be a contract with specific terms, including that the processor acts “only on documented instructions from the controller” and, at the end of the service, deletes or returns all personal data at the controller’s choice. In practice that contract is the data processing agreement; ours is public, and whichever vendor you use, the delete-or-return clause is the one to read before signing, because it decides what an offboarding looks like years later.
The split also decides who answers the candidate. An access request lands on the controller even when the data lives in our systems; the processor’s job is to make answering it possible inside the deadline.
What we’d do differently
If we were setting up hiring at a 25-person company today, the list before the first job ad went out would be short. Strip the application form to fields that inform a decision. Write the retention window down and automate the deletion, so the policy holds when everyone is busy. Make the talent-pool ask a separate, dated, withdrawable yes — retrofitting consent onto a pool that grew informally lands somewhere between painful and impossible.
Then one rehearsal: file an access request against your own process and watch what happens. Export a test candidate, read what comes out, note how long it took. The one-month deadline is the piece of all this a regulator can measure to the day, and it is also the cheapest to be ready for.


