GDPR in Recruitment: DON’T do this

Every business in the EU has to comply with the GDPR, that also applies to recruiters and noncompliance can cost a business as much as 4% of annual revenue.

GDPR in Recruitment: DON’T do this

The General Data Protection Regulation (GDPR) is a regulation of EU law on data protection and privacy in the European Union.

The GDPR was designed to integrate data privacy laws across EU member countries and has the goal to help protect privacy rights to individuals by directing how businesses and organisations can process the information of individuals.

As a result, many recruiters wonder what data they can still use and under what circumstances.

The good news is that a lot of personal data can still be used for recruitment purposes.

But how you use the data is key in being and staying compliant and preventing fines that can go up to 4% of the entire company revenue.

Since you rely on personal data as a recruiter this blog informs you about what not to do and what to do to be and stay GDPR compliant.

Who must comply with GDPR?

Anyone who processes the personal data of people in the EU must comply, even if the company itself sits outside the EU. Under Article 3, the law follows the data subject: a US based sourcing tool that holds data on European candidates is squarely in scope. That matters when you pick vendors, because "we are a US company" is not a reason a tool is exempt.

What is personal data?

In simple terms, personal data is any information related to an individual.

The official definition of personal data is “any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.”

Before you touch a single candidate record, the GDPR requires you to have a lawful basis for processing it. In recruitment, two of the six bases in Article 6 do almost all the work: legitimate interest and consent. Choosing the right one is the decision most compliance mistakes trace back to.

For sourcing passive candidates who never applied to you, legitimate interest is usually the right basis, not consent. You cannot realistically ask someone’s permission before you look them up, and consent has to be freely given and easy to withdraw, which does not match how sourcing actually works. Legitimate interest lets you process professional data for a genuine recruitment purpose, but it is not a free pass: you have to run and document a balancing test (a legitimate interests assessment) that weighs your interest against the candidate’s rights, and the candidate keeps the right to object at any time.

Consent is the right basis for the extra things: adding someone to a long term talent pool, keeping their data for future roles, or any use beyond the vacancy at hand. When you do rely on consent it has to be a clear opt in, and withdrawing it has to be as easy as giving it.

If you sourced them, tell them (within a month)

This is the rule sourcers trip over most. When you collect someone’s data from anywhere other than the candidate themselves, from LinkedIn, GitHub, a CV database or a third party, Article 14 says you have to tell them: who you are, what data you hold, why you are processing it, and how they can object or have it deleted.

The deadline is one month at the latest after you first obtained the data, or at your first contact with the candidate if that comes sooner. In practice this is easy to satisfy: your first outreach message plus a link to a candidate privacy notice does the job. What is not compliant is quietly building a database of people you sourced and never telling any of them.

What happens if you don’t comply?

Then your company risks fines up to 4% of annual global revenue or €20 million, whichever is greater. These are not theoretical. In October 2024 the Irish regulator fined LinkedIn €310 million for processing member data for behavioural advertising without a valid legal basis, a platform most recruiters use every day - Irish DPC. The lesson for recruiters is precise: the fine turned on the legal basis, the exact question covered above, not on some exotic edge case.

What NOT to do

❌ Do NOT use candidate data for purposes other than recruitment. For example, don’t use candidate information for marketing or commercial uses unless they have given consent for these other purposes.

✔️ Always be aware about why you are processing data and limit the use of data to that particular purpose. If you need to use the data for other purposes, ask for consent from the candidate.

❌ Do NOT use more data than you need for your purpose. Avoid collecting data on candidates at scale if you don’t need it in the process.

✔️ Minimize your data collection to the data needed for decision making and contacting the candidate.

❌ Do NOT use old and inaccurate candidate data. You are required to use accurate data about the candidate.

✔️ Review the data that you are collecting and that you already have in your database based on quality, relevancy and how up to date the data is.

❌ Do NOT keep candidate data forever. The GDPR requires storage limitation: data must not be kept longer than you need it for the purpose you collected it for.

✔️ Set a retention period and delete or re-consent when it ends. France's regulator, the CNIL, treats two years from the last contact with an unsuccessful candidate as a sensible outer limit for a sourcing database, after which you should refresh consent or delete.

❌ Do NOT have hidden and unclear policies regarding how you process data. The GDPR requires you to be transparent about what data you use and how you use it and process it.

✔️ Explain and document your practices regarding data processing. Answer any questions that candidates might have about their data.

❌ Do NOT do business with third party data and solution providers that are not GDPR compliant. It is your responsibility to do business with GDPR compliant partners and suppliers. You are accountable for any noncompliance of third party solutions that affect your practices.

✔️ Always check new solutions based on GDPR compliance and ask for argumentation and proof of compliance. Also re-evaluate your current suppliers on GDPR compliance.

Can you make use of third party data and solutions?

Many data providers and sourcing tools in the market are not GDPR compliant. Many solutions make use of private data sets that are not publicly available. The databases used for these primarily US based sourcing software companies make use of breached and leaked databases, two well known breaches are the People Data Labs leak and the Facebook leak.

Some tools are GDPR compliant and make use of publicly available information that can be linked to a legitimate professional purpose.

Be careful with the phrase "publicly available", though. Public does not mean free to use. In 2024 the Dutch regulator warned that scraping personal data is almost always unlawful under GDPR, even when the data is openly visible, unless a narrow legitimate interest applies - Pinsent Masons. The test is whether the information is genuinely public professional data tied to a legitimate professional purpose, not merely whether you could technically grab it.

HeroHunt.ai is an example of a GDPR compliant tool that finds the best tech candidates through platforms like LinkedIn, GitHub and Stack Overflow and only uses publicly available data for professional use.

GDPR is no longer the only rulebook

Since GDPR passed, a second regime has landed on top of it: the EU AI Act. It classifies AI systems used to recruit, screen or select candidates as high risk, which brings obligations around transparency, human oversight, bias testing and record keeping. If you use software that ranks or filters applicants, this now touches you as well.

The timing shifted in 2026. Under the Digital Omnibus simplification package, given final approval by the Council on 29 June 2026, the high risk obligations for standalone systems like hiring tools now apply from 2 December 2027 rather than August 2026. Treat that as breathing room, not a reprieve: the GDPR rules in this article already apply today, and the AI Act layer is coming on a fixed date.

This guide reflects the rules as they stand in 2026. Data protection enforcement moves quickly, so verify current guidance with your DPO or a qualified adviser before acting on it.