How long should job application data be retained under the GDPR?

8 mins’ reading time

Tadaah team meeting

A recruitment process can quickly result in a pile of personal data: CVs, cover letters, notes, test results and sometimes even copies of qualifications. HR teams often wish to retain this information to support the process or to get in touch again at a later date. The GDPR sets clear limits on this, and in practice these limits are often stricter than many organisations realise.

What does the GDPR mean by “job application data”?

Recruitment data refers to all personal data that you collect and use to assess a person’s suitability for a role. This goes far beyond just a CV. Internal documents are also included in this category as soon as they can be traced back to an individual.

Examples that almost always fall within the scope of job application details

  • CV, cover letter, portfolio and (LinkedIn) profile information that you save.
  • Email correspondence, WhatsApp messages, meeting minutes and interview notes.
  • Scorecards, assessment rubrics and justification for the selection.
  • Test results (assessments, aptitude tests, personality questionnaires).
  • Reference information, including who you spoke to and what was said.

Take care when handling sensitive personal data

Data relating to health, criminal history, ethnic origin or trade union membership is subject to particularly strict rules. In recruitment, such information is sometimes obtained unintentionally, for example via a covering letter or during an interview (“I have been off work for a long time due to illness”). Only retain this type of information if it is genuinely necessary and there is a valid legal basis for doing so, and document how you handle it.

How long should job application data be retained under the GDPR?

The core principle of the GDPR is data retention limitation: you must not retain personal data for longer than is necessary for the purpose for which it was collected. For job applications, this usually means retaining the data until the end of the recruitment process, and thereafter only for a short period in case of any queries or complaints. In the Netherlands, the Dutch Data Protection Authority applies a maximum retention period of four weeks following the end of the recruitment process as a practical guideline, unless you have consent to retain the data for longer.

Would you like to find out more about data-driven recruitment?
Discover how AI, target audience data and labour market insights can help you attract the right candidates. Download our white paper for practical insights, or feel free to get in touch for advice tailored to your organisation.

Practical rule of thumb: 4 weeks, unless otherwise agreed

A retention period of four weeks following the completion of the procedure is often used to explain your decision and to deal with any queries from candidates. This might include a request for clarification, an objection, or reconstructing the steps taken should a dispute arise regarding the selection. After that, the purpose usually ceases to apply, so you must either delete or anonymise the data.

If you wish to retain data for longer for a “talent pool” or future vacancies, you will generally need the candidate’s consent to do so. Without that consent, “it might come in handy later” is not a valid purpose under the GDPR.

Consent: what works and what doesn’t?

Consent must be freely given, specific, informed and unambiguous. This means that you must not conceal the fact that you are retaining data for longer in a general privacy notice, nor should you suggest that refusal will have consequences for the ongoing job application.

  • Well: a separate question at the end of the procedure, with a clear time limit (for example, 6 or 12 months) and a simple option to choose “no”.
  • Not: a pre-ticked box or a general statement such as “we will retain your data for future opportunities” without specifying a specific period.

Sources on which to base your retention period

It is advisable for HR to ensure that its policies are in line with official guidance, so that it can act consistently internally and justify externally why it has chosen a particular timeframe. See the regulator’s guidance on Job application data and retention periods as set out by the Dutch Data Protection Authority. For the legal basis for data retention limits under the GDPR, you may also refer to the Official GDPR texts (EU Regulation 2016/679).

What factors determine what is “necessary”?

“Necessary” depends on your objective, your risks and your process. An organisation filling a role with safety requirements may need different documentation to one dealing with high volumes and short turnaround times. It is, however, important not to retain more documentation than you actually use as a matter of course.

Objectives that generally fit within a short retention period

  • Completing the selection process and communicating decisions.
  • Being able to explain the choice of candidate to the hiring manager.
  • Dealing with enquiries, complaints or objections shortly after the event.

Objectives requiring further justification

  • “Talent pool” or future vacancies (usually: consent required).
  • Internal analyses of recruitment and selection (often possible using anonymised data).
  • Evidence for potential legal proceedings (in which case, choose carefully what you keep, and document why).

What exactly do you need to remove, and what can you keep?

In many organisations, it is mainly “shadow data” that remains: copies in email inboxes, exports from ATS systems and separate folders held by hiring managers. In practice, therefore, when a retention period expires, you need to do more than simply delete a single record from your system.

Checklist: where application details often get held up

  • ATS or recruitment software (candidate profile, notes, tags, attachments).
  • Recruiters’ and hiring managers’ email addresses.
  • Shared drives and Teams/SharePoint folders.
  • Calendar notes, meeting agendas and internal chat.
  • Assessment platforms and test portals.

Anonymisation can sometimes be a solution

If you do want to learn from your recruitment process, anonymisation or pseudonymisation can help. Anonymised data is no longer subject to the GDPR, but the candidate must be completely unidentifiable. A document referring to “candidate A” and containing a unique combination of educational background, age and place of residence may still be traceable in a small specialist field.

How do you incorporate this into your recruitment process?

Retention periods only work if they form part of your workflow. A single rule in a privacy policy is not going to change behaviour, especially not when several stakeholders are involved in compiling the file.

1) Set retention periods in your ATS and make them automatic

Use automatic reminders or auto-delete wherever possible. If your ATS does not support this, schedule a monthly clean-up with a designated person in charge. Ensure that “delete” actually means that attachments, notes and exports are removed.

2) Create a single, consistent folder structure

A large part of the risk lies in loose documents and scorecards that end up outside the system. If you work with scorecards, set them up so that they fit directly into your process and do not end up floating around in Excel files. In the FosFor knowledge base, for example, you can see how to structure an assessment using a selection scorecard for hiring managers, and how you can make the conversation itself more predictable with a Structured interview in 8 steps.

3) Communicate clearly with candidates

Transparency is not only a requirement under the GDPR; it also prevents complications later on. In your privacy notice for job applications, you should at least specify:

  • What data you process (and from which sources).
  • Why you process them (purposes).
  • How long you keep them (for example, 4 weeks, or longer with consent).
  • Who has access (HR, hiring manager, assessment provider).
  • How someone can withdraw their consent and what rights they have.

Common mistakes that lead to unnecessary risk

Most GDPR issues in recruitment are not caused by malicious intent, but by a desire for convenience and routine. These are pitfalls that frequently crop up in audits and internal checks.

“Keeping everything ”just in case’

If you cannot explain a specific purpose, retention is usually not permitted. Instead, document exactly what evidence you need to justify your decisions, and stick to that. This is also in line with the idea of not selecting on the basis of “gut feeling”, but on the basis of verifiable evidence; see also These 4 recruitment mistakes that are costing you your best candidates.

Asking for permission at the wrong time

Obtaining consent during an ongoing recruitment process can be controversial, as the candidate may feel under pressure to agree. It is better to wait until someone has been rejected or has withdrawn their application themselves, and ensure that the decision is genuinely non-binding.

No distinction between “rejected” and “employed”

When someone is taken on, some of the data is transferred to their personnel file. That does not mean you are automatically allowed to keep everything from the application file. Make a conscious decision: what do you need for the employment contract and onboarding, and what becomes redundant afterwards?

A practical retention period at a glance

The table below will help you set out your policy in HR terminology and make discussions with managers more practical. Use this as a starting point and adapt it to your processes, systems and risks.

Situation Objective Standard retention period Condition
Candidate rejected, procedure completed Explanation/handling of enquiries or objections Up to 4 weeks Deletion/anonymisation upon completion
Candidate in the talent pool Contact us regarding future vacancies E.g. 6–12 months Giving and withdrawing consent should be easy
Candidate accepted Employment relations and payroll administration In accordance with HR and employment law deadlines Limit yourself to what is necessary; do not include everything from the selection
Analysis of the recruitment process Process improvement and quality measurement As short as possible Preferably anonymised or heavily pseudonymised data

Practical next steps for HR and hiring managers

If you want retention periods to be effective, link them to your selection tools and your candidate journey. Think of standardised scorecards, clear-cut interview notes and a single centralised location for candidate files, so that you can genuinely streamline the process without any blind spots. If you’d like to discuss a selection process that’s easier to justify and make GDPR-compliant, a data-driven review of your candidate journey and file structure would fit in well with the way FosFor designs recruitment processes.

We would like to get in touch

Get in touch

Good people don’t look for job vacancies. Download the white paper and find out how you can reach them anyway.