Summary: What data is processed in HR, what is the legal basis, how long can candidate CVs be retained? A simple GDPR compliance checklist for HR teams.

GDPR and Human Resources: How to Protect Candidate and Employee Data

4 min read 1
Also available in: DE ES FR PT TR

Human resources is the department that processes the most personal data in a company: CVs, identification details, health reports, bank account information, performance notes. Most of this data falls under the GDPR-equivalent data protection laws and some are considered "sensitive" data, requiring stricter protection. This article is prepared for HR teams who want to grasp the essentials without reading legal texts.

Note: This content is for general informational purposes and does not constitute legal advice. Consult your legal advisor for company-specific situations.

What data is processed in HR?

  • Identification and contact: Name, national ID number, address, phone, email.
  • Personnel: Contract, salary, social security information, leave records.
  • Education and professional experience: Diploma, certificates, references, CV content.
  • Sensitive data: Health report, disability status, criminal record, union membership, biometric data (including fingerprint entry systems).

Sensitive data is a critical distinction: processing these generally requires explicit consent and cannot be stored except under legal exceptions. For instance, requesting a health report or criminal record from a candidate during recruitment is not defensible unless required by the position.

Legal basis: obtaining consent for everything is incorrect

A common misconception is obtaining consent from employees for all data processing activities. However, data necessary for the establishment and execution of employment contracts and legally required notifications fall under other legal bases. Moreover, asserting that consent is given "freely" in an employer-employee relationship is challenging; thus, consent-based processes are more vulnerable during audits.

Conversely, uses not mandatory for the employment relationship require explicit consent. Typical examples: sharing a candidate's CV with other companies, publishing an employee's photo on the website, using data collected for recruitment for other purposes later.

How long can candidate CVs be retained?

The law does not specify a single duration; the criterion is when the purpose for processing the data ceases. When the applied position is filled, the purpose ends. If you wish to keep the CV in a pool for future consideration, this is a separate purpose and requires informing the candidate and obtaining consent. A commonly accepted practice is:

  • During the application process: until the position is closed.
  • Pool retention: with the candidate's explicit consent and for a specific period (commonly 1-2 years), with automatic deletion at the end of the period.
  • When consent is withdrawn: immediate deletion and notification to the candidate.

When does the disclosure obligation arise?

Before data collection begins. This means candidates must be informed of who is processing what data, for what purpose, and on what legal grounds, as well as their rights, before they start filling out the application form. The disclosure text and consent form are separate documents; combining them in a single checkbox invalidates consent.

Compliance checklist for HR teams

  • Are separate disclosure texts prepared for candidates and employees?
  • Are processes requiring explicit consent approved individually (not in a single checkbox)?
  • Is a data inventory (what data, where, how long) created?
  • Are retention periods defined and deletion executed at the end of the period?
  • Is access to HR folders restricted based on roles? Is there a shared folder accessible to everyone?
  • Is a data processing agreement signed with software providers?
  • In case of a data breach, who will report to whom within how many hours — is it documented?
  • Are sensitive data stored separately and in more restricted locations?
  • Is there a defined process for handling the data of departing employees?
  • Is there a process for responding to employee requests (access, deletion)?

Three most common mistakes

  • CVs stored indefinitely in a shared email inbox: Deletion cannot be executed, access cannot be restricted, and tracking who viewed them is impossible.
  • Collective consent with a single checkbox: When disclosure, consent, and electronic communication permission are combined in one checkbox, none are considered valid.
  • Ignoring consent withdrawal: If the data of a candidate who withdraws consent remains searchable in the system, compliance is only on paper.

Addressing these three points on the system side is more secure than writing procedures. In ProCvLab's CV pool, companies can only see candidates who have given explicit consent for sharing; when consent is withdrawn, the record is automatically removed from the pool. The CV bank created from your applications is exclusive to your company and not shared externally.

Next step: We publish our disclosure texts on our GDPR disclosure page; you can review them for structure when preparing your own texts.

Share:

Create Your Professional CV Now

Apply the tips from our blog posts and create a professional CV in minutes with ProCvLab.

Create CV Now

Related Posts