Privacy-safe and GDPR-conscious recruiting
Record a lawful basis before contact, minimise and encrypt candidate data, automate retention, and make erasure one click: privacy-safe recruiting in practice.
Privacy is part of the candidate experience
Candidates hand you their name, contact details, and work history on the assumption that you will treat it responsibly. Honouring that assumption is both a legal obligation under regimes like the GDPR and a competitive advantage: people are more willing to engage with a company that is visibly careful with their data. Privacy failures in recruiting are also unusually public failures, because the people affected are, by definition, people outside your walls with no reason to stay quiet. This guide walks through the practices that keep candidate data safe without slowing recruiting down.
Know your lawful basis before you make contact
Before sending a single message, record why you are allowed to process this candidate's data, whether that is their consent or a legitimate interest. Check that basis at send time, not just at capture time, so a withdrawn consent actually stops outreach. This one habit prevents most accidental misuse.
- Capture a lawful basis at first contact and store it with the candidate record.
- Re-check it before every message, so withdrawal takes effect immediately.
- Collect only the fields you genuinely need; data you never hold cannot leak.
The send-time check is the part most teams miss. A consent recorded in March does not authorise a message in September if the candidate withdrew in June, and a system that only checks at capture time will happily keep mailing them. Make the gate live where the message leaves, and withdrawal becomes self-enforcing rather than a policy that depends on someone remembering.
Collect less: minimisation in practice
Every field you store is a liability you carry and a promise you must keep. For most hiring processes, a name, a contact channel, the role, and the interview history are genuinely needed; a date of birth, a full address, or a scan of an identity document usually are not, at least not until an offer stage. Audit your intake forms and your CSV imports with one question per column: what decision does this field change? If the answer is none, stop collecting it, and delete what you already hold. Minimisation is the only privacy control that gets cheaper the better you do it.
Encrypt at rest, and limit access by role
Personal data should be encrypted at rest and travel only over secure connections. Limit who can see it to the roles that need it: a hiring manager needs their own candidates, not the whole pipeline; an interviewer needs the interview, not the salary conversation. Role-based access with a scoped "not yours, not visible" default keeps curiosity from becoming an incident, and it keeps any single compromised account from exposing everything. Encryption protects you from the disk; access scoping protects you from yourselves.
Set a retention period, and let it actually run
Candidate data does not age into harmlessness; it ages into risk without value. Decide how long a closed candidate record stays, write it into your privacy notice, and automate the deletion, because a retention policy that depends on someone remembering to purge a spreadsheet is a fiction. A workspace-wide retention window with an automatic scan that erases or anonymises expired records turns the policy into a property of the system. Keeping a candidate for a future role is a fine reason to retain, but it is a new purpose: ask, record the consent, and restart the clock.
Make erasure one click, and auditable
When a candidate asks to be forgotten, wiping their personal fields and logging the deletion should take one click, not a support ticket. The request itself should be easy to make, from the candidate's own status page, without an account or a phone call. Under the hood, erasure needs to reach everywhere the data lives: the candidate record, scheduled emails that have not sent yet, calendar events that carry a name, and any copy synced to an applicant tracking system. What should remain is an audit entry that an erasure happened, keyed by an internal identifier, never by the data you just erased. Practise the flow before you need it; the legal clock runs in days, not quarters.
Candidate rights beyond erasure
Erasure gets the attention, but candidates also have the right to see the data you hold, to correct it, and to object to how you use it. The operational answer is the same for all of them: know where candidate data lives, keep it structured, and route requests to a person who can act. A candidate whose data is scattered across inboxes, spreadsheets, and chat threads cannot be answered honestly. A candidate whose record lives in one system with a clear owner can be answered in an afternoon. Consolidation is not just tidiness; it is what makes the rights real.
Mind your vendors and where data travels
Every tool in the hiring stack, the scheduler, the ATS, the email provider, is a processor of your candidates' data. Choose vendors who state plainly where data is stored, how it is encrypted, and how deletion propagates, and put a data-processing agreement in place before the first record flows. If data crosses borders, know the mechanism that makes the transfer lawful. Your own privacy notice should name the categories of recipients, so a candidate can see the whole journey of their data, not just the first stop.
Audit without hoarding
You need to prove what happened, who saw what, when a consent was recorded, when an erasure ran, without the audit trail becoming a second copy of the personal data. The discipline is to log internal identifiers and events, never raw contact details, and to treat logs with the same access scoping as the data they describe. An audit trail built this way survives an erasure intact: the history of actions remains provable while the person inside it is gone. That combination, memory of events without memory of people, is exactly what a regulator wants to see and exactly what a candidate hopes you have.
Interview notes are personal data too
The candidate record everyone remembers to protect is the profile: name, contact details, CV. The one that causes surprises is the commentary around it. Interview notes, scorecards, and "gut feel" remarks are personal data about the candidate, subject to the same access rights and the same erasure duties, and a candidate is entitled to ask what they say. Two consequences follow. Keep evaluative notes structured and professional, written as if the candidate might read them, because legally they might. And keep them in the system of record, not in personal notebooks and chat threads where no retention policy, access control, or erasure can ever reach them.
Common pitfalls to design away
- The spreadsheet export: every CSV download of the pipeline is a copy of candidate data outside every control you built. Export rarely, minimally, and delete after use.
- The personal inbox: recruiting from individual mailboxes scatters candidate PII across accounts that offboarding does not clean. Keep candidate contact in the system.
- The over-shared CV: forwarding a CV to "the whole team for visibility" defeats role-scoped access. Share the link with the panel, not the file with the org.
- The eternal talent pool: "we will keep your CV on file" is a retention promise with no clock. If you keep it, consent it and expire it.
- The chatty log: application logs that print names or addresses turn debugging into a data leak. Log internal identifiers only.
A recruiter's quick checklist
A privacy programme fits on one card. Before contact: lawful basis recorded. At collection: only fields a decision needs. At rest: encrypted, role-scoped, in one system. In flight: consent checked at send time. On schedule: retention runs automatically. On request: access answered, corrections made, erasure in one click. Afterwards: an audit trail of events, not of people. If any line makes you wince, that line is the next project, and none of them takes a quarter.
Trust compounds across the journey
Careful data handling reinforces everything else you do; it underpins a strong candidate experience and shapes how you connect calendars when you coordinate interview scheduling. Keep collection minimal, access least-privilege, retention automatic, and erasure one click, and privacy becomes a feature candidates feel rather than a box you tick. If you would rather inherit these defaults than build them, this is how Cadence bakes them in from the first record.