How long can you keep candidate data under GDPR?

GDPR sets no fixed retention period for candidate data. Practical norms: often 6-12 months in the UK, up to two years in France — define, document, automate.

Published July 24, 2026

The short answer

The GDPR does not name a number. Article 5(1)(e) — storage limitation — says personal data may be kept "no longer than is necessary" for the purpose it was collected for. For recruiting, that purpose is filling a role, so once the process for that role has ended, the clock is running. What "necessary" means in months is for you to define, document, and be able to defend — and the national supervisory authorities have published norms that most teams anchor to.

What the authorities say

None of this is legal advice — retention interacts with local employment law, and your counsel should sign off the final number. The pattern, though, is consistent: pick a period, write down why, and actually enforce it.

The two clocks: process data vs talent pool

A common mistake is treating "keep the CV in case another role opens" as a free extension. It is not: a talent pool is a different purpose from filling the original role, so it needs its own lawful basis — most teams ask the candidate's consent at rejection time — and its own retention period. If the candidate says nothing, the process clock applies; if they opt in, a new, longer clock starts, and they can withdraw at any time. Either way, the answer to "how long do we keep this?" should never be "until someone remembers to clean up".

Why enforcement is the hard part

Writing "12 months" into a privacy notice takes a minute. The failure mode is operational: candidate data lives in the ATS, in calendar events, in email threads, and in spreadsheets, and nobody's calendar has a recurring "purge candidates" task that survives a busy quarter. This is where tooling earns its keep. Cadence lets you set the retention period per workspace and then flags and processes candidates who pass it automatically — and its one-click erasure reaches the scheduling artifacts and synced ATS fields, not just the top-level record. The broader practice is covered in our guide to privacy-safe recruiting, and the product side on the interview scheduling built for GDPR page.

A retention policy you can actually run

  1. Pick the number: 6–12 months after process end is a defensible default in most of the EU and UK; two years is the ceiling if you follow the CNIL.
  2. Write the justification: name the claim windows and business reasons behind the number, and put it in your privacy notice.
  3. Separate the talent pool: rejected-but-promising candidates get an explicit opt-in with its own clock.
  4. Automate the purge: configure the period in your tooling so expiry is processed without a human remembering.
  5. Log the erasures: keep a PII-free record that deletion happened — proof of compliance that survives the deletion itself.