How long can you keep candidate data under GDPR?
GDPR sets no fixed retention period for candidate data. Practical norms: often 6-12 months in the UK, up to two years in France — define, document, automate.
The short answer
The GDPR does not name a number. Article 5(1)(e) — storage limitation — says personal data may be kept "no longer than is necessary" for the purpose it was collected for. For recruiting, that purpose is filling a role, so once the process for that role has ended, the clock is running. What "necessary" means in months is for you to define, document, and be able to defend — and the national supervisory authorities have published norms that most teams anchor to.
What the authorities say
- France (CNIL): the clearest guidance in Europe. The CNIL recommends keeping an unsuccessful candidate's file for at most two years after the last contact with the candidate, unless the candidate asks for earlier deletion — or agrees to longer.
- United Kingdom (ICO): the ICO prescribes no fixed period; you must set and justify your own. In practice UK employers commonly retain unsuccessful-applicant data for 6 to 12 months, informed by the three-month window (extendable by tribunals) for discrimination claims under the Equality Act 2010.
- Germany: retention practice is anchored to the AGG (General Equal Treatment Act), under which rejected candidates have two months to assert a discrimination claim. Adding time for service and proceedings, German guidance commonly lands on about four to six months after rejection.
- Elsewhere in the EU: most authorities follow the same logic — no fixed number, a documented justification, and a period measured in months, not years. When in doubt, the CNIL's two-year ceiling is a conservative upper bound for an EU-wide policy.
None of this is legal advice — retention interacts with local employment law, and your counsel should sign off the final number. The pattern, though, is consistent: pick a period, write down why, and actually enforce it.
The two clocks: process data vs talent pool
A common mistake is treating "keep the CV in case another role opens" as a free extension. It is not: a talent pool is a different purpose from filling the original role, so it needs its own lawful basis — most teams ask the candidate's consent at rejection time — and its own retention period. If the candidate says nothing, the process clock applies; if they opt in, a new, longer clock starts, and they can withdraw at any time. Either way, the answer to "how long do we keep this?" should never be "until someone remembers to clean up".
Why enforcement is the hard part
Writing "12 months" into a privacy notice takes a minute. The failure mode is operational: candidate data lives in the ATS, in calendar events, in email threads, and in spreadsheets, and nobody's calendar has a recurring "purge candidates" task that survives a busy quarter. This is where tooling earns its keep. Cadence lets you set the retention period per workspace and then flags and processes candidates who pass it automatically — and its one-click erasure reaches the scheduling artifacts and synced ATS fields, not just the top-level record. The broader practice is covered in our guide to privacy-safe recruiting, and the product side on the interview scheduling built for GDPR page.
A retention policy you can actually run
- Pick the number: 6–12 months after process end is a defensible default in most of the EU and UK; two years is the ceiling if you follow the CNIL.
- Write the justification: name the claim windows and business reasons behind the number, and put it in your privacy notice.
- Separate the talent pool: rejected-but-promising candidates get an explicit opt-in with its own clock.
- Automate the purge: configure the period in your tooling so expiry is processed without a human remembering.
- Log the erasures: keep a PII-free record that deletion happened — proof of compliance that survives the deletion itself.