Back to Blog
GDPR candidate data retentiongdpr data retentiongdpr data retention periodGDPR recruitmentcandidate database

GDPR Candidate Data Retention: How Long Can You Keep CVs?

GDPR sets no fixed retention period for candidate data — but keeping CVs indefinitely is illegal. Learn the lawful periods, the 7-year myth, consent refresh rules, and how to reactivate your database compliantly.

Janis Kolomenskis

11 min read
Share

Your candidate database has a problem you probably already sense but haven't fully counted. Somewhere between 40 and 70 percent of the profiles in it — depending on how long your agency has been running — can no longer be lawfully contacted. Not because the candidates moved on. Because you never set a retention clock, and GDPR was counting down without you.

That's not a scare tactic. It's the consistent finding from every database audit done across European recruitment agencies in the past three years. The data exists. The purpose that justified collecting it expired long ago. And the plan to clean it up keeps getting pushed behind whatever's urgent this week.

This guide covers the actual rules — not a lawyer's summary of them — so you can run a compliant database, retain what you can defend, and turn the candidates you've already paid to source into active, reachable pipeline.

Why GDPR Sets No Fixed Retention Period (and What It Actually Requires)

GDPR's storage limitation principle does not name a number of months. The regulation requires that personal data be kept only as long as necessary for the purpose for which it was collected — and that you can demonstrate this is proportionate. Your retention period isn't handed to you; you have to justify it, document it, and enforce it.

This design is deliberate. A CV collected to fill a specific CFO role in Munich has a fundamentally different retention window than a speculative application to a talent pool. The ICO's recruitment and selection guidance is explicit: "Unless there is a clear business reason, you should not keep recruitment records for unsuccessful applicants beyond the statutory period in which a claim arising from the recruitment process may be brought." In the UK, that's six months under the Equality Act. In Germany, it's three months under the AGG — though most agencies add a buffer.

What this means in practice: the moment a vacancy closes, a retention clock starts. If you have no documented reason to keep a candidate's data beyond that point, you need either a new lawful basis or a deletion workflow. Most agencies have neither.

The 7-Year Myth: Where It Comes From and Why It Doesn't Apply to CVs

The "GDPR 7-year rule" is one of the most persistent compliance misconceptions in HR. The 7-year figure refers to financial and accounting records — invoices, fee notes, payroll — required under tax legislation in most EU member states. It has no bearing on candidate CVs, interview notes, or personal data collected during recruitment.

The confusion is understandable. Recruitment agencies do hold some data that legitimately runs to 7 years: the invoice you raised for a successful placement, the employment contract that underpinned a fee, tax-related financial records. But those are financial records about a transaction — not personal data about a candidate. The CV that sat behind that transaction, the candidate's salary history, their references — those have a much shorter window.

"The 7-year retention period applies to financial records under tax law. Applying it to candidate CVs is a category error — and it leaves you holding personal data for five to six years longer than any European regulator would accept."

A clean distinction to build into your retention schedule:

Data TypeRetention PeriodLawful BasisNotes
CV / application (unsuccessful)6 monthsLegitimate interestDiscrimination-claim window
Talent pool (with consent)12–24 months, then re-consentConsentRenew before expiry or delete
Placed candidate recordPlacement + 12 monthsLegitimate interest / contractCovers guarantee period disputes
Interview notes6 months from interviewLegitimate interestDelete with CV unless separate basis
Right-to-work documentationEmployment end + 2 yearsLegal obligationStatutory requirement
Invoices / fee records7 yearsLegal obligation (tax law)Financial records only — not CVs

Lawful Basis for Candidate Data: Legitimate Interest vs Consent

Most recruitment activity sits under one of two GDPR lawful bases: legitimate interest (Article 6(1)(f)) or consent (Article 6(1)(a)). Choosing the right one for each type of candidate data is not a technicality — it determines what you can do with the data and for how long.

When legitimate interest is your lawful basis

Legitimate interest lets you process candidate data without explicit consent — provided you pass a three-part test: there's a genuine interest, processing is necessary for it, and that interest isn't overridden by the candidate's rights. For recruiters, it works best when a candidate has a reasonable expectation of being approached. The European Commission's guidance on legitimate interest emphasises that you must show the candidate's privacy interests are not "seriously impacted" — which means documenting your assessment, not assuming it.

Legitimate interest typically covers:

  • Candidates who applied directly for a specific open role
  • Candidates sourced from professional networks (LinkedIn, Xing) where their profile is clearly career-oriented and public
  • Candidates referred by clients or contacts where the referrer had a reasonable basis for sharing their details
  • Previously placed candidates within the guarantee period

What legitimate interest does not cover: keeping a candidate in your database indefinitely after the original purpose has ended. Once the role is filled and the claim window has passed, the legitimate interest has expired with it. You need either a new basis or a deletion.

When consent is required

Consent is the right tool when you want to keep candidates in a talent pool beyond the original role — which is exactly the situation most agencies are trying to manage. The ICO's storage limitation guidance is clear that long-term talent pool retention requires an active opt-in: specific, informed, freely given, and easily revocable.

Consent also applies to sensitive personal data (disability information, right-to-work status), any marketing communication to candidates beyond the immediate placement process, and any re-purposing of data from one search to another.

"Consent in recruitment isn't a checkbox you ask candidates to tick during onboarding. It's a documented permission for a specific purpose, with a clear expiry — and it has to be as easy to withdraw as it was to give."

The Consent Refresh: Why Your Talent Pool Has an Expiry Date

Consent-based talent pool records don't last forever. Once the retention period you documented has expired — typically 12 or 24 months after the candidate last interacted with you — your lawful basis for holding that data disappears unless you renew it. A consent refresh is the mechanism for doing that: a short, transparent communication asking candidates to confirm they still want to be in your pool.

A consent refresh that works is not a marketing email. Candidates can tell the difference. It needs to include: what data you hold, why you want to keep it, how long you'll hold it for, and a clear way to say no. Something like:

"We've had your details since [date] and want to make sure you still want us to. If you're open to hearing about suitable opportunities, confirm below. If not, we'll remove you within 48 hours — no hard feelings."

A well-executed consent refresh typically sees 30–50% of engaged candidates opt back in. The remaining 50–70% either decline or don't respond — and non-response within your stated window should be treated as non-consent and trigger deletion. That's not a loss. Candidates who didn't respond are unlikely to convert anyway, and cleaning them out gives you a database where everyone who's still present actually wants to hear from you. That's the foundation of a pipeline that places.

According to the ICO's November 2024 audit of AI recruitment tools, one of the most common compliance failures was retaining candidate data indefinitely "without candidate knowledge" — meaning no retention limit had been set and no refresh process existed. Regulators flagged this as a clear violation, not a grey area.

What GDPR Enforcement Actually Looks Like for Recruiters

GDPR fines hit €1.2 billion across Europe in 2024, with enforcement agencies processing more than 400 breach notifications per day by early 2025 according to DLA Piper's annual GDPR fines survey. Most of those fines targeted large technology companies — but the enforcement trend is moving downstream. Smaller organisations, including recruitment agencies, are increasingly in scope.

Enforcement against recruitment agencies rarely arrives through proactive regulatory audits. It comes from candidate complaints. The most common scenarios:

  • A candidate uploaded their CV to a job board three years ago. They receive an unsolicited call from your agency about an unrelated role. They have no idea how you got their details. They complain to the ICO or their national DPA.
  • A candidate requests deletion. You delete their ATS record but miss the CV in an email thread, a Google Drive folder, and last month's backup. The candidate finds out their data is still findable. They escalate.
  • Your agency is acquired. Due diligence reveals a database of 8,000 candidates with no retention schedule and no documented lawful basis for most records. The acquiring party now owns your liability.

LinkedIn's €310 million GDPR fine from the Irish DPC in October 2024 centred on behavioural advertising — but the underlying issue was processing data beyond the purposes users reasonably expected. The same logic applies to recruitment databases: if a candidate gave you data for a specific vacancy in 2022, processing it for a different purpose in 2026 needs a fresh lawful basis.

From Compliance Problem to Active Pipeline: The Reactivation Move

Here's the opportunity most agencies miss when they think about GDPR retention: the compliance audit is also a sourcing opportunity. Before you delete a segment of your database, you send a consent refresh. Some percentage of those candidates — often 30–40% in practice — will confirm they're still open to opportunities. Those are warm contacts, not cold outbound. They already know your agency, they've interacted with you before, and they've just signalled they're reachable.

The find, rank, reactivate model treats your existing database as the first sourcing channel — before you go to LinkedIn or any external platform. The logic is simple: re-sourcing someone you already profiled costs three to five hours of recruiter time plus platform credits. Reactivating someone from your talent pool costs one well-crafted email.

That reactivation only works if the data is compliant and clean. Candidates in your pool who have current, documented consent can be re-engaged immediately when a role fits. Candidates without valid consent can't be contacted until you've completed a refresh — and if they don't respond, they come out of the database. This is the correct sequence:

  1. Segment your database by last contact date. Any record with no contact in the past 12 months and no documented consent basis goes on your reactivation list first, deletion list second.
  2. Run a consent refresh campaign. Not a pitch — a compliance notification with a clear opt-in. Document every response.
  3. Set a hard window for non-responders. Four weeks is standard. Non-response = deletion. Delete and log it.
  4. Reconfigure your ATS to enforce retention limits going forward. Every new candidate record should have a retention clock attached from the moment it's created.
  5. Work the reactivated pool as active pipeline. These candidates have just confirmed they're open to contact. Use that window.

Agencies that have run this process consistently report that 2 in 5 placements in the months following a reactivation campaign come from the reactivated pool — candidates who had been sitting dormant in a non-compliant database, now surfaced cleanly. See also: the dark matter problem in candidate databases — candidates who exist in your records but never get surfaced because the data isn't clean enough to query reliably. Keeping those records complete with automated candidate data enrichment is what makes reactivation queries work at all.

What Your ATS Should Handle Automatically

The reason GDPR compliance fails in most agencies isn't intent — it's that manual processes break down under volume. A recruiter managing 150 active candidates across 12 open roles isn't going to manually track consent expiry dates. An ATS that doesn't enforce retention limits won't remind anyone. The data just accumulates.

A platform built for compliant recruiting should handle these without manual intervention:

Retention period enforcement. Every candidate record should have a configurable retention window. When a record approaches expiry, the system flags it for review or triggers a consent refresh workflow automatically — not a calendar reminder to a recruiter who may be on leave.

Consent state tracking. The system should record when consent was captured, what it covered, the expiry date, and any subsequent changes (refresh confirmed, withdrawal logged). This is your audit trail if a regulator asks.

Erasure request workflow. When a candidate requests deletion, the system should surface every location where their data exists — record, pipeline entries, notes, attachments — and log the deletion with a timestamp. The one-month compliance window requires a traceable response, not a manual search across four systems.

DSAR (Data Subject Access Request) reporting. Candidates can request a copy of all data you hold on them. Compiling a DSAR manually from an ATS, an email client, and a shared drive can take half a day. A properly designed platform generates this in minutes.

EU data residency. If your platform stores candidate data on US infrastructure without a formal EU adequacy or Standard Contractual Clauses arrangement, you're making an international data transfer every time you upload a CV. EU data residency isn't a premium feature — it's the baseline for any agency operating under EU GDPR. Yena stores all candidate data on EU infrastructure, and the platform's retention controls, consent tracking, and erasure workflows are built into the core product rather than sold as compliance add-ons. Agent/MCP-based workflows for candidate search and reactivation are rolling out in preview through June 2026.

For a broader comparison of how ATS platforms handle compliance, the candidate sourcing automation guide covers what to look for in platforms that touch candidate data at volume.

Country-Specific Notes: UK, Germany, France

GDPR sets the floor. National law can raise it — and in several key European recruiting markets, it does.

UK (ICO). UK GDPR is substantively identical to EU GDPR but enforced independently by the Information Commissioner's Office. The ICO's November 2024 audit of AI recruitment tools found systematic data retention failures and has indicated it will continue monitoring the sector. The UK's six-month Equality Act limitation period is the most cited basis for 6-month CV retention on unsuccessful applications. Agencies operating across the UK-EU boundary should verify that their adequacy arrangements remain current — the UK's adequacy decision from the EU Commission is periodically reviewed.

Germany (BfDI / BDSG). Germany adds Section 26 of the BDSG (Bundesdatenschutzgesetz) to EU GDPR, specifically governing data processing in employment contexts. German supervisory authorities — both the BfDI at federal level and the Länder authorities — are active in the HR and recruitment space. One important nuance: in the German employment relationship, consent is often considered weakened by power imbalance, making legitimate interest or legal obligation the stronger basis for most processing. Works Councils in German client companies may also have co-determination rights over which recruitment tools are used.

France (CNIL). The CNIL's formal recommendation (Délibération 2020-092) sets a 2-year outer limit from last contact for candidate data, with re-consent required before that period expires. The CNIL has actively investigated LinkedIn scraping by French recruitment firms and issued formal warnings. Any agency sourcing from LinkedIn at scale for French-based candidates should have a documented legitimate interest assessment and a clear privacy notice process.

Frequently Asked Questions

How long can a recruiter keep a CV under GDPR?

There is no single fixed period. The GDPR storage limitation principle requires you to justify your retention period against the purpose. For unsuccessful applicants, 6 months aligns with discrimination-claim windows. For talent pools with explicit consent, 12–24 months is the widely accepted range. Beyond 24 months without re-contact or renewed consent, retention is very hard to defend with any European regulator.

Does the 7-year GDPR data retention rule apply to candidate CVs?

No. The 7-year figure applies to financial and accounting records under tax legislation — not candidate CVs. Conflating the two is one of the most common GDPR mistakes in recruitment. Candidate personal data has a much shorter justified retention window, typically 6 to 24 months depending on your lawful basis. Financial records related to a placement (invoices, fees) can legitimately run to 7 years, but those are financial documents, not personal data about the candidate.

Can you keep passive candidates in your database under GDPR?

Yes, but only with a documented lawful basis. Legitimate interest can cover initial contact with candidates who have a reasonable expectation of being approached — for example, sourced from a public LinkedIn profile. For long-term talent pool retention, consent is the safer basis: explicit, revocable, and renewed before it expires. Without a documented basis, holding passive candidate data is a compliance exposure regardless of how the candidate was sourced.

What happens if a candidate asks you to delete their data?

You must comply within one calendar month under Article 17 of GDPR. Deletion must cover all systems: your ATS, email threads, shared drives, and any third-party tools that received the data. Document the request and your response, including what was deleted from where. The one exception is data you are legally obliged to retain — right-to-work records during an active employment, for example — which you can hold but must inform the candidate you're doing so.

What is a consent refresh and when do you need one?

A consent refresh is a communication you send to candidates before their retention period expires, asking them to confirm they still want to be in your talent pool. It is required whenever you hold data under consent as the lawful basis and that consent is approaching its documented expiry. Candidates who do not respond within your stated window — typically four weeks — should be deleted and the deletion logged. Non-response cannot be treated as implicit consent.


GDPR candidate data retention is genuinely manageable — but only if it's built into your workflow rather than treated as a periodic cleanup exercise. The agencies that handle it best aren't the ones that spent the most on legal advice. They're the ones whose ATS enforces retention limits automatically, whose consent refresh cadence runs quarterly without being pushed, and whose database reflects only candidates who've confirmed they want to be there.

That database — smaller, cleaner, and fully consented — places faster than the 6,000-record graveyard most agencies are sitting on. If you want to see how Yena handles retention automation, consent tracking, and database reactivation in practice, explore the sourcing product or start a trial to see the compliance workflows directly.

Janis Kolomenskis

June 19, 2026

Share
Yena

Turn a role brief into a qualified shortlist.

Describe who you need. Yena finds and ranks candidates, explains why they fit, surfaces available contact details for review, and keeps outreach in the same recruiting workspace.