GDPR Compliance in CV Processing: A Complete Guide for Recruiters

    Formatix.AI TeamFebruary 14, 202610 min read

    The General Data Protection Regulation (GDPR) has fundamentally changed how recruitment agencies handle candidate data. CVs are rich with personal information — names, addresses, employment history, education, and sometimes sensitive data like health conditions or nationality. Mishandling this data exposes agencies to fines of up to 4 percent of global turnover or 20 million euros, whichever is higher. Beyond the financial risk, data breaches destroy trust and reputation. This guide provides a practical, actionable framework for ensuring your CV processing practices comply with GDPR requirements.

    Understanding the Legal Basis for Processing CVs

    Under GDPR, you need a valid legal basis to process personal data. For recruitment agencies, the two most relevant bases are legitimate interest and consent. Understanding which applies — and when — is critical to compliance.

    Legitimate Interest

    When a candidate applies for a specific role through your agency, you generally have a legitimate interest in processing their CV for that role. The candidate has initiated contact, expects their data to be used for recruitment purposes, and the processing is necessary to fulfil the recruitment service. However, legitimate interest is not a blanket justification. You must conduct a Legitimate Interest Assessment (LIA) documenting the purpose, necessity, and balance against the candidate's rights. Importantly, legitimate interest typically does not cover retaining the CV for unrelated future roles unless you clearly communicate this at the point of collection.

    Consent

    Consent is required when you want to add a candidate to your general talent pool, share their CV with clients they have not specifically applied to, or retain their data beyond the original recruitment purpose. GDPR consent must be freely given, specific, informed, and unambiguous. This means no pre-ticked checkboxes, no bundled consents, and no "by submitting your CV you agree to everything" language. The candidate must actively opt in to each specific use of their data, and they must be able to withdraw consent as easily as they gave it.

    Data Minimisation: Only Collect What You Need

    GDPR's data minimisation principle requires that you only process personal data that is adequate, relevant, and limited to what is necessary for the purpose. In the context of CV processing, this means carefully considering what information you actually need at each stage of the recruitment process.

    At the initial screening stage, you need the candidate's professional qualifications, experience, and skills. You do not need their home address, date of birth, marital status, or photograph. Many CVs — particularly those from continental Europe — include this information by default. Your standardisation process should strip unnecessary personal data before sharing the CV with clients.

    This is where AI-powered CV formatting tools provide a compliance advantage. Platforms like Formatix.AI can automatically anonymise CVs during the formatting process, removing photographs, dates of birth, home addresses, and other personal identifiers that are not relevant to the hiring decision. This serves a dual purpose: it supports GDPR data minimisation requirements and reduces unconscious bias in the screening process.

    Storage Limitation: How Long Can You Keep CVs?

    GDPR does not specify exact retention periods for CVs — this is a decision you must make and justify based on your business needs. However, the principle of storage limitation requires that personal data should not be kept for longer than is necessary for the purpose for which it was collected.

    For CVs submitted for a specific role, a reasonable retention period is the duration of the recruitment process plus a short additional period — typically 6 months — to handle any disputes or complaints. After this period, the CV should be securely deleted unless the candidate has consented to being included in your talent pool for future opportunities.

    For talent pool CVs held on the basis of consent, the ICO (Information Commissioner's Office) guidance suggests reviewing retained data at regular intervals. Many agencies operate a 12-month consent cycle: they contact candidates annually to confirm whether they wish to remain in the talent pool. Candidates who do not respond within a reasonable window (typically 30 days) should have their data securely deleted.

    Document your retention policy, communicate it clearly to candidates, and implement automated deletion reminders. Keeping CVs indefinitely "just in case" is a GDPR violation, not a business strategy.

    Candidate Rights: What You Must Be Ready to Handle

    GDPR grants candidates several rights regarding their personal data. Your agency must have processes in place to handle each of these within the required timeframes — typically one month from receipt of the request.

    Right of Access (Subject Access Request)

    Candidates can request a copy of all personal data you hold about them. This includes their CV, any notes or assessments attached to their profile, email correspondence, interview feedback, and records of which clients received their data. You must be able to locate and compile this information across all your systems — ATS, email, shared drives, and any third-party tools that process candidate data.

    Right to Rectification

    Candidates can request corrections to inaccurate data. If a candidate notifies you that their job title, dates of employment, or qualifications are recorded incorrectly, you must update your records promptly. This is particularly relevant after CV formatting — always verify that your formatting process has not introduced errors in the candidate's data.

    Right to Erasure (Right to Be Forgotten)

    Candidates can request that you delete all their personal data. When this request is received, you must delete the candidate's data from all systems, including backups, within one month. You must also notify any third parties (such as clients) who received the candidate's data. There are limited exceptions — for example, you may retain data required for legal claims — but these are narrow and must be specifically justified.

    Right to Object

    If you are processing a candidate's data on the basis of legitimate interest, they have the right to object. If they do, you must stop processing their data unless you can demonstrate compelling legitimate grounds that override the candidate's rights. In practice, if a candidate objects to their CV being shared with further clients, you should comply immediately.

    Practical Tips for GDPR-Compliant CV Processing

    Compliance is not just about understanding the law — it is about implementing practical measures that become part of your daily operations. Here are actionable steps every recruitment agency should take:

    Create a privacy notice specifically for candidates. This should explain what data you collect, why, how long you keep it, who you share it with, and how candidates can exercise their rights. Provide this notice at the point of CV collection — on your website, in job advertisements, and in initial candidate communications.

    Maintain a Record of Processing Activities (ROPA). GDPR Article 30 requires you to document all processing activities. For CV processing, record the categories of data processed, the legal basis, recipients of the data, retention periods, and security measures in place.

    Choose tools that support compliance by design. When selecting CV processing, formatting, and storage tools, evaluate their GDPR credentials. Do they store data in EU/UK data centres? Do they offer automatic data deletion? Can they generate audit trails for data access? Formatix.AI, for example, processes CVs in real-time without persistent storage of candidate data — the CV is formatted and the output is delivered without the platform retaining a copy, which significantly reduces your data protection risk surface.

    Train your team. GDPR compliance is only as strong as the weakest link in your organisation. Every recruiter and administrator should understand the basics: what constitutes personal data, why they should not email CVs to personal accounts, how to handle data subject requests, and what to do if they suspect a data breach. Regular training — at least annually, with refresher sessions for new joiners — is essential.

    Implement access controls. Not everyone in your agency needs access to every candidate's full CV. Apply the principle of least privilege: recruiters see CVs for their assigned roles, administrators have broader but audited access, and temporary staff or contractors have strictly limited access. Audit access logs regularly to detect and investigate unusual patterns.

    Data Breach Response

    Despite best efforts, data breaches can occur. GDPR requires that you report breaches to the relevant supervisory authority (the ICO in the UK) within 72 hours of becoming aware of the breach, if the breach is likely to result in a risk to individuals' rights. If the breach is high-risk, you must also notify affected candidates directly.

    Have a data breach response plan documented and rehearsed. The plan should specify who to notify, how to assess severity, how to contain the breach, and how to communicate with affected parties. Do not wait until a breach occurs to figure out your response — by then, the 72-hour clock is already ticking.

    International Data Transfers

    If your agency operates internationally or uses tools hosted outside the EU/UK, you must ensure that international data transfers comply with GDPR requirements. Following the Schrems II ruling, transferring data to countries without an adequacy decision — including the United States, unless the recipient is covered by the EU-US Data Privacy Framework — requires additional safeguards such as Standard Contractual Clauses (SCCs) and Transfer Impact Assessments.

    When selecting CV processing tools, prioritise those that process and store data within the EU/UK. If the tool uses cloud infrastructure, verify the specific data centre locations — "cloud-based" does not automatically mean EU-hosted. Ask your vendors for Data Processing Agreements (DPAs) and verify that their sub-processors also comply with GDPR requirements.

    For more information on how our platform handles data protection, visit our help centre or contact our compliance team directly.

    Ready to transform your CV formatting process?

    Join 200+ recruitment agencies already saving hours every week with AI-powered CV formatting. Start your free trial today — no credit card required.