The email arrives at 09:14 on a Tuesday. A former candidate — someone who interviewed for a CFO role eighteen months ago, did not get it, and has since found a position elsewhere — writes three sentences. They would like their data deleted. All of it. Please confirm when it is done.
You have one calendar month to respond. You also have their CV in your ATS, their salary expectation in a spreadsheet a consultant built in 2023, a note in a shared inbox thread, and a PDF attachment forwarded to three hiring managers who no longer work at the client company. None of that was documented in your data register. The clock is already running.
The GDPR right to erasure — Article 17, widely known as the "right to be forgotten" — is one of the rights that European data protection authorities treat most seriously. The European Data Protection Board launched a coordinated enforcement sweep in early 2025 with 32 national DPAs focusing specifically on erasure compliance. For recruitment agencies, which handle dense personal data on hundreds or thousands of candidates at any one time, this is a category of risk that spreadsheet-based processes cannot absorb.
What Article 17 Actually Requires — and What It Does Not
Article 17 of the GDPR (and its UK equivalent, the UK GDPR) gives individuals the right to request deletion of their personal data when one of six conditions applies. For recruitment candidates, the two most common triggers are: the data is no longer necessary for the purpose it was collected (the role was filled, the candidate has withdrawn), or the candidate withdraws consent where consent was the legal basis for processing. The ICO's right to erasure guidance is the authoritative reference for UK-based agencies and is worth bookmarking as DPA policy continues to develop following the Data (Use and Access) Act 2025.
The right is not, however, absolute. Agencies can refuse or restrict erasure in a limited set of circumstances: the data is needed to comply with a legal obligation (certain employment or tax records may have statutory retention requirements), it is needed for the establishment, exercise, or defence of legal claims (a candidate has threatened litigation), or the processing serves a legitimate public interest purpose. These exceptions are narrow. "We might want to contact them again one day" is not one of them.
"A request does not need to reference Article 17 or use the phrase 'right to erasure' to be valid. Any communication that clearly asks for data to be deleted must be treated as a formal erasure request." — ICO, Right to Erasure Guidance
The practical implication: if a candidate emails "please remove me from your database", that is a valid Article 17 request regardless of the words used. The 30-day clock starts from the moment you receive it — not from when a consultant remembers to action it.
Why the Email Inbox Is the Hardest Part of Candidate Data Deletion
Most ATS platforms now include a deletion or anonymisation function that wipes candidate profiles from the main database. That step, while necessary, typically covers less than half the places where candidate data actually lives. The harder problem is the data that escaped the ATS before anyone thought about GDPR.
When a candidate applies, their CV lands in an inbox. It gets forwarded to a hiring manager. A consultant pastes salary expectations into a shared Google Sheet. Call notes go into a personal notebook or a WhatsApp message. Interview feedback is emailed between two people who have since left the firm. Each of those points is a separate location where personal data exists — and each must be erased, not just the ATS record. According to GDPR deletion guidance for recruitment CRMs, the most common source of incomplete erasure is email — not the ATS itself.
"Improper data deletion accounts for an estimated 35% of GDPR violations in the HR sector, with average fines for SMEs around €50,000." — ENISA HR Sector Data Report, 2025
A useful mental model: before you can delete candidate data, you need to know where all of it is. That means maintaining a data map — a register of every system that touches candidate information — and updating it whenever you add a new tool. Without that map, a deletion workflow is a best-guess exercise, not a compliance one.
A Step-by-Step Erasure Request Workflow for Recruitment Agencies
A defensible erasure process has six stages, each of which needs to be documented — because "we deleted it" is only half the answer a DPA will accept. The other half is evidence that you deleted it everywhere, within the deadline, and notified any third parties who received the data.
- Log the request immediately. Create a dated entry the moment you receive the request — email, voicemail, LinkedIn message, or any other channel. The 30-day clock runs from receipt, not from when you start processing.
- Identify the candidate's data footprint. Cross-reference your data map against the candidate's name and any known identifiers (email address, phone number, application reference). List every location: ATS profile, email threads, forwarded CVs, assessment notes, spreadsheets, LinkedIn messages, WhatsApp exchanges, physical documents.
- Apply the exception test. Check whether any of the narrow Article 17(3) exceptions apply. Document your reasoning either way. If an exception applies, write to the candidate explaining which one and why, within the same 30-day window.
- Execute deletion across all identified locations. Delete or anonymise the ATS record. Delete emails (including sent items and forwarded copies where you have access). Remove spreadsheet rows. Delete physical documents. Where you shared data with third parties — client companies, assessment providers, background-check firms — contact them in writing requesting deletion and retain their confirmation.
- Document every deletion step. For each location, record what was deleted, when, and by whom. This is your audit trail. If your tools generate deletion certificates or logs, save them. If they do not, a simple timestamped spreadsheet entry per deletion action is sufficient — provided it is consistent and complete.
- Confirm to the candidate in writing. Send a confirmation email within the 30-day window stating that the deletion has been completed, listing the categories of data erased, and noting if any data was retained under an exception. Keep a copy of that confirmation.
What Recruitment Agencies Must Erase vs. What They Can Retain
Not every record connected to a candidate is automatically erasable. Some data overlaps with obligations that sit outside GDPR — financial records, contractual documents, tax filings. The table below maps the most common data types in a recruitment agency against the erasure obligation. Use it as a starting point, not a substitute for legal advice on your specific situation.
| Data Type | Typical Location | Erasure Required? | Possible Exception |
|---|---|---|---|
| CV and cover letter | ATS, email inbox, shared drive | Yes | None typical |
| Application notes and call records | ATS, CRM, personal notes | Yes | None typical |
| Salary expectations and benchmarks | Spreadsheets, ATS | Yes | None typical |
| Interview feedback (about the candidate) | Email, ATS, shared docs | Yes | Legal claim defence if active |
| Assessment results | Third-party tool or email | Yes — including at third parties | None typical |
| Reference contact details provided by candidate | ATS, email | Yes | None typical |
| Placement invoice referencing candidate name | Finance system | Possible anonymisation | Legal/tax obligation (6–7 yr) |
| Contract between agency and client (names a placed candidate) | Finance/legal system | Possible anonymisation | Legal obligation |
| Discrimination or complaint record | HR/legal files | Possible restriction, not erasure | Legal claim defence |
Where an exception allows retention of certain data, best practice is to anonymise the record rather than keep a named file — so that the placement revenue figure, for example, is retained for accounting purposes without linking back to a named individual. That approach satisfies both the erasure request and the statutory retention obligation.
Building an Audit Trail That Actually Protects You
When the EDPB's 2025 enforcement sweep examined organisations' erasure compliance, the most common finding was not that organisations had refused to delete data — it was that they could not demonstrate deletion had occurred. "We told the ATS to delete it" and "we think we removed it from everywhere" are not audit-ready responses. A usable audit trail needs four elements recorded for each erasure request.
- Request log: date received, channel, candidate name/identifier, nature of request, name of the team member who received it.
- Exception assessment: a written note, however brief, confirming you considered and applied (or ruled out) each Article 17(3) exception.
- Deletion record: a line-by-line or system-by-system record of what was deleted, when, and by whom. Where a system generates a deletion log or confirmation, attach it.
- Third-party notifications: copies of any communications sent to client companies, assessment providers, or other processors asking them to delete the candidate's data, plus any confirmation received back.
"The controller must have mechanisms for confirming that deletion occurred. 'We told them to delete it' is not sufficient." — Jackson Lewis, EU Data Enforcement Sweep Analysis, 2025
The bar is not high — a timestamped Google Sheet row per deletion action, saved in a dedicated compliance folder, will satisfy most DPA queries. What matters is that the record exists, is consistent, and covers every system. Agencies that process more than a handful of erasure requests per quarter should invest in a lightweight request-management workflow, whether that is a column in their ATS or a dedicated DSAR (Data Subject Access Request) tool.
How Erasure Compliance Fits Into Your Broader GDPR Framework
The right to erasure does not exist in isolation. It is one of eight individual rights under the GDPR, and the infrastructure you build to handle erasure requests — a data map, a request log, documented retention periods — also supports your obligations under Articles 15 (right of access), 16 (right to rectification), and 21 (right to object). Agencies that treat these rights as separate checklists end up rebuilding the same processes multiple times.
The more useful framing is a single candidate data lifecycle: you have a lawful basis and a purpose for collecting data; you retain it for a defined period; you delete it when that period expires or when the candidate requests it earlier. If you have that lifecycle documented and enforced, most individual-rights requests become straightforward — because you already know where the data is, what it is for, and when it should go. The full GDPR guide for recruitment agencies covers the legal bases and consent architecture that sit upstream of erasure. And if your database contains large numbers of stale profiles that have never had explicit retention periods applied, the recruitment compliance Europe guide walks through how to audit and remediate that backlog.
It is also worth understanding how erasure obligations interact with your sourcing strategy. The GDPR does not prohibit proactive sourcing — it requires that you have a lawful basis and that you inform candidates of your processing. Agencies that source from LinkedIn and other channels need a consent or legitimate interest assessment in place before they add a profile to their ATS — because if that assessment does not exist, the candidate has grounds to object under Article 21 before any erasure request is even triggered. For a detailed look at how agentic sourcing tools handle this, the guide to agentic AI sourcing for recruitment agencies addresses how compliant data-capture should work when sourcing is automated.
Why EU Data Residency Makes Erasure Provable — and Why US-Hosted Tools Create a Second Problem
When a candidate submits an erasure request, you need to confirm deletion across every system that holds their data. If your ATS or sourcing tool is hosted by a US-headquartered vendor, even on EU servers, you face an additional compliance question: you are instructing a data processor to delete data — but you have no independent means to verify it was deleted, and US legal frameworks may require the vendor to retain copies for different purposes. The EDPB's enforcement sweep findings specifically called out processor verification as a weak point: the controller bears responsibility for ensuring processors have actually completed the deletion, not just acknowledged the instruction.
EU-incorporated platforms are subject to EU data protection law directly — including the same erasure obligations as the agencies using them. When both the controller and the processor are under EU jurisdiction, the deletion verification chain is cleaner: the processor's deletion obligation under Article 28 runs in the same legal environment as yours, and any DPA investigation would apply consistent standards to both sides. This is one concrete reason why jurisdiction matters in technology procurement — not just for data residency marketing language, but for the enforceability of the contractual obligations that underpin your erasure workflow.
What a Sovereignty-First Platform Changes About Deletion Workflows
The platforms that make GDPR deletion easiest share a structural characteristic: they know where every piece of candidate data lives, because they built around a single structured data layer rather than allowing data to sprawl across email threads and shared drives. That is not a feature to market — it is a design choice that determines whether erasure is a ten-minute task or a three-day investigation.
Yena is building its agentic Talent Sourcer, unified inbox (WhatsApp, LinkedIn, and email in one thread), candidate sequencer, and email and phone finders on an EU-native, GDPR-by-design architecture. Early access opens later in 2026. The practical implication for erasure: when outreach, enrichment, and candidate engagement all run through one platform — rather than across five separate tools that each hold their own copy of the profile — a deletion request becomes an action, not an audit. You know what exists, you know where it is, and you can confirm its removal with a timestamped log rather than a best-effort memory exercise.
That design choice also addresses the third-party processor verification problem: if your sequencing, email finding, and inbox management are all within the same EU-jurisdiction platform, the confirmation chain for a deletion request is internal — not a series of emails to vendors in different time zones asking whether they have actioned your instruction.
For agencies building out their sourcing capability in parallel with compliance infrastructure, the intersection of those two requirements — better data, handled legally — is where GDPR-aligned candidate database management and AI candidate sourcing should meet.
Frequently Asked Questions
How long do we have to respond to a GDPR right to erasure request?
Under both the EU GDPR and UK GDPR, the response deadline is one calendar month from the date you receive the request. Where the request is complex or you have received a high volume simultaneously, you can extend by a further two months — but you must notify the individual within the first month, before the original deadline expires, explaining why the extension is needed. For most single-candidate erasure requests in recruitment, the standard one-month deadline applies.
Can we keep a candidate's data after they request deletion if we think we might have a vacancy for them?
No. "Future opportunity" is not a recognised exception under Article 17. Once the purpose for which you collected the data has lapsed — the role was filled, the mandate closed, or consent was withdrawn — you cannot retain data on the basis of potential future interest. If a candidate withdraws their data and a relevant vacancy arises later, they would need to apply afresh and provide a new consent or legitimate interest basis for you to process their information again.
Do we have to notify the client company if a candidate requests erasure?
Yes, if you shared the candidate's personal data with the client as part of the recruitment process. Article 17(2) requires the controller to take "reasonable steps" to inform other controllers who have received the data about the erasure request. In practice this means contacting the client company in writing, explaining the erasure request, and asking them to delete any copies of the candidate's CV, assessment results, interview notes, or other personal data they hold. Document that communication and retain the client's response.
What is the difference between erasure and anonymisation for GDPR purposes?
Erasure means the data is deleted entirely — no trace of the personal information remains in that record. Anonymisation means the personal identifiers are removed such that the individual can no longer be identified from the remaining data. Truly anonymised data falls outside the scope of the GDPR, so an anonymised placement record (revenue figure, role type, date — no name, no contact details) can be retained for legitimate business purposes. The anonymisation must be irreversible; pseudonymisation, where re-identification is still technically possible, does not satisfy an erasure request.
Does the UK GDPR right to erasure still apply post-Brexit?
Yes. The UK retained the GDPR as domestic law through the EU Withdrawal Act 2018, creating the UK GDPR as a parallel framework to the EU version. The right to erasure provisions in the UK GDPR are substantively identical to Article 17 of the EU GDPR. UK-based agencies operating with EU candidates, or processing data of EU residents, may need to comply with both frameworks simultaneously — worth confirming with a data protection adviser if your candidate pool spans both jurisdictions regularly.
If you are building out a GDPR-compliant candidate database and want to explore how a recruitment platform designed around EU data sovereignty handles sourcing, enrichment, and candidate engagement — Yena is taking early-access registrations ahead of the 2026 platform launch. See what the Talent Sourcer does and request early access if it looks like the right fit for your agency.