FR EN

Manage your GDPR policy with your ATS

Be at ease with your candidates'' and contacts'' data

The General Data Protection Regulation (GDPR) is a European regulation that came into effect on May 25, 2018. Its main goal is to protect the personal data of individuals within the European Union (EU) and to govern how organizations process this data, whether they are located within the EU or not, as long as they handle data of EU citizens.

GDPR Policy in Recruitment

The GDPR requires all companies processing personal data of EU residents to comply with its requirements. All recruitment firms and agencies must ensure that their methods of data collection, storage, processing, and sharing comply with the GDPR, or they risk financial penalties of up to 20 million euros or 4% of their annual global turnover. Your candidates must be informed about their rights regarding their data and the purpose of its collection.

What are the GDPR Requirements for Recruiters?

Here is a list of GDPR requirements that recruiters must adhere to:


Right to InformationThe recruiter must ensure candidates' right to know about the data collected about them and its intended use.
TransparencyThe recruiter must inform individuals about how their data is used, processed, and protected.
ConsentThe recruiter must obtain explicit consent before using candidates' personal data, thus ensuring that consent is clear and freely given.
Withdrawal of ConsentThe right of individuals to withdraw their consent must be fully respected. Candidates should be able to request the deletion of their collected data at any time.
CookiesYour website should feature a banner to inform candidates and website visitors about the use of cookies during their visit to your career site. This transparency ensures they are fully informed about your use of cookies.
DeletionYou must set a data retention period to automatically delete expired profiles. Anonymized data may be retained for statistical purposes.


Candidates have the right to request the deletion of their personal data if it is no longer necessary for the purposes for which it was collected.

Security MeasuresYou must ensure appropriate technical and administrative measures are in place to protect your candidates' personal data. You should take suitable measures to protect personal data against loss, theft, unauthorized access, and disclosure.
Data Export RestrictionsAll data collected and processed by you remains within the European Union, in compliance with GDPR data export restrictions.

Data Collected in Your Recruitment Software

The data collected in your recruitment software is essential for conducting the candidate selection process. By using your ATS, you collect information necessary for this specific purpose.

This includes essential details such as candidates' names, contact information, work history, skills, and educational background. It is important to note that it is crucial to adhere to data protection regulations when collecting this information. Ensure you do not collect sensitive data such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for unique identification, health data, or data concerning sex life or sexual orientation.

In case of accidental provision of such information, ensure it is handled with utmost confidentiality and immediately deleted from your systems. As recruiters, it is your responsibility to collect only the data strictly necessary to conduct your recruitment activities in accordance with the principles of data minimization and purpose limitation outlined in the GDPR. Ensure that candidates' data is used responsibly, transparently, and securely throughout the recruitment process.

Collected Data

Candidate Data
Last Name


First Name


Postal Address

Email


Phone

Position

LinkedIn Profile


Introduction Video


Curriculum Vitae

Comments


Application Questionnaire Responses

Evaluation


Obtaining Candidate Consent

Obtaining candidate consent is a crucial step in the process of collecting and processing personal data in accordance with the GDPR. Before collecting any information, it is imperative to obtain explicit and informed consent from the candidate. This consent must be voluntary, specific, informed, and unambiguous, meaning the candidate must be fully aware of the information they provide and the purposes for which it will be used. You are committed to ensuring that each candidate fully understands the purpose of collecting their data and respecting their right to withdraw consent at any time.

Consequences of Refusal to Consent

When a candidate refuses to give their consent, the recruiter respects this choice and refrains from collecting or using the individual's personal data. However, it is important to note that refusal to consent may have implications on the recruitment process.

In this context, by respecting the choice of non-consent and anonymizing data, the recruiter ensures the privacy of individuals while maintaining the integrity of the recruitment process. Data anonymization plays a crucial role. It helps protect candidates' confidentiality while ensuring that their information is not used for recruitment purposes.

For example, if a candidate refuses to undergo testing or provide certain information, it could affect their chances of being considered for the position. The recruiter can then inform the candidate of the consequences of their refusal to consent and discuss available alternatives.

Ultimately, the recruiter ensures the rights of candidates regarding privacy and data protection are respected while striving to conduct a fair and effective recruitment process.

Need more information about our GDPR policy?

Contact the team for any questions

contact us