GDPR retention period for job application data relating to scorecards

6 mins’ read time

Tadaah team meeting

A practical problem: scorecards end up gathering dust in inboxes

After a busy recruitment drive, there are often ‘mini-files’ scattered everywhere: interview notes in a note-taking app, scorecards as PDFs in a folder, and summaries in emails. It is precisely these scattered documents that make it difficult to GDPR retention period for job application data easy to follow.

The GDPR does not require perfect record-keeping, but it does require oversight: knowing what you are storing, why you are storing it, where it is kept, and when it needs to be deleted. In this article, you’ll learn how to apply this to scorecards, interview records and practical arrangements within your team.

What constitutes recruitment data under the GDPR?

Job application data refers to all personal data that you process in order to assess a candidate for a role. This covers more than just a CV or cover letter.

Examples that are often overlooked

  • Scorecards showing marks for each competence and explanatory notes
  • Interview notes (including brief keywords)
  • Reports on telephone screenings
  • Case study answers or test results (even if you’ve “just had a quick look” at them)
  • Email correspondence with the candidate
  • Reference check notes

Anything from which a person can be identified, either directly or indirectly, is generally considered to be personal data. Even “candidate A” could be considered as such if you can link it to a specific profile.

GDPR retention period for job application data: what is standard practice?

The key rule is: do not keep data for longer than is necessary for the purpose. In the case of job applications, that purpose is usually to complete the recruitment process and to be able to justify decisions.

Would you like to find out more about data-driven recruitment?
Discover how AI, target audience data and labour market insights can help you attract the right candidates. Download our white paper for practical insights, or feel free to get in touch for advice tailored to your organisation.

Guidance for unsuccessful candidates

In the Netherlands, a retention period of up to 4 weeks once the process has ended, unless you request permission to keep your details in a talent pool for longer.

The Dutch Data Protection Authority provides guidance on the handling of job application data and retention periods, including the principle of consent for extended retention; see Explanation from the Dutch Data Protection Authority regarding job application data.

If you have authorisation for a talent pool

With consent, you can retain data for longer, for example up to 1 year. Please be specific: what data do you store, for what types of functions, and how can someone opt out?.

For successful candidates

Some of the application details may become relevant to the personnel file (for example, agreements regarding the start date or salary). In that case, the purpose shifts: from the application process to the employment relationship. Make sure you make that transition deliberately: not everything needs to be carried over automatically.

How long do you keep scorecards and interview notes?

Scorecards and interview notes are often the most sensitive, as they contain subjective impressions. Nevertheless, you sometimes need them to explain a decision, carry out an internal evaluation and ensure consistency in the selection process.

Practical starting point

  • Rejected candidate without consent: Do not keep scorecards or notes for any longer than the rest of the application file (guideline: 4 weeks after the end of the process).
  • Rejected candidate with consent (talent pool): Only keep what you really need to get back in touch later and match candidates effectively. Old, detailed interview reports are rarely useful anymore.
  • Successful candidate: Only transfer relevant sections to the personnel file. The full scorecard, containing all comments, is often not necessary for the employment relationship.

Beware of ‘function creep’

A scorecard is designed for selection purposes. If you later use it for performance appraisal (“but this was mentioned in your interview”), the purpose changes. This may conflict with purpose limitation and data minimisation.

From policy to implementation: how to make it workable

Compliance stands or falls on habits. Not on a PDF in a folder that nobody reads.

1) Consolidate storage locations into a single site

The quickest way to prevent data from being kept for too long is to centralise it. If scorecards are scattered across five different tools, deleting them becomes a matter of guesswork.

  • Use a single ATS/HR folder as the “single source of truth”
  • Prohibit the storage of data in personal inboxes as a long-term solution
  • Establish a standard naming convention for files and scorecards

2) Use a simple storage matrix

This table helps to ensure consistency across different document types. Adjust the deadlines to suit your own process, but do make sure to set them out clearly.

Document Objective Retention period (guideline) Action after the deadline
CV + covering letter Selection Until the end of the proceedings + 4 weeks Delete or anonymise
Scorecard Objective assessment Until the end of the proceedings + 4 weeks Delete; retain only what is strictly necessary, and only with permission
Interview notes Reasons for the choice Until the end of the proceedings + 4 weeks Delete
Talent pool authorisation Contact us later Up to 12 months (example) Re-confirm or delete

3) Make deletion part of your “close file” process step”

Make a note of the following: once the vacancy has been filled (or withdrawn), you must close the file administratively. This involves:

  • whether control or consent has been documented (or not)
  • deleting loose notes outside the ATS
  • setting an automatic deletion date where possible

Consent: when is it appropriate, and when is it best to avoid it?

Consent can be useful for a talent pool, but it must be freely given and just as easy to withdraw. “You’re applying for a job, so you’re giving your consent” doesn’t work.

What you’ll need in practical terms

  • A separate, clear question: would you like us to keep your details on file for future vacancies?
  • A specific timeframe: for example, 6 or 12 months
  • A clear explanation of what data you store (and what you do not)

The basic rules on storage limitation and data minimisation are also set out in the GDPR itself; see the official text of the GDPR (EU 2016/679).

How this ties in with structured interviews and scorecards

A structured process not only helps you make better decisions, but also protects privacy. If everyone uses the same scorecard and you have set criteria, you can keep your notes shorter, more factual and more consistent.

  • If you use fixed rubrics and a single format, you’ll avoid including unnecessary details in the free-text section.
  • If your team assesses the situation independently and records only the evidence, the case file will be more defensible and less “opinion-driven”.

If you want to standardise the selection further, this ties in well with How to conduct a structured interview in 8 steps and on Create a selection scorecard for hiring managers.

A quick checklist for compliance in practice

  • Do you have a clear closing date for the application process for each vacancy?
  • Are all the scorecards and notes stored in one central location?
  • Has the retention period for job application data under the GDPR been set out internally (and are hiring managers aware of it)?
  • Is consent for extended retention documented in a verifiable manner?
  • Is deletion a standard step in the “close file” process?

Would you like to organise your selection process in such a way that scorecards and interview files become both more objective and easier to manage (including in terms of retention periods)? FosFor can help you set up a practical framework for structured interviews, scorecards and the surrounding process, so that compliance is not a one-off task but an integral part of your working method.

Find out how we work via our approach or get in touch via the contact page to discuss your approach.

We would like to get in touch

Get in touch

Good people don’t look for job vacancies. Download the white paper and find out how you can reach them anyway.