Recruiting

    Applicant Data and Data Protection

    By Redaktion techport.ai, HR-Beratung · Last updated on

    In almost every applicant tracking system we examine, there is data from individuals who applied five, six, or ten years ago. CVs, references, interview notes, sometimes health information. No one has deleted it because no one defined when. And no one uses it because no one knows if they are permitted to.

    This presents a risk without benefit. The General Data Protection Regulation requires personal data to be deleted as soon as the purpose ceases. The Allgemeine Gleichbehandlungsgesetz (General Equal Treatment Act) provides deadlines for rejected applicants to claim compensation. Between these two lies a deletion concept that requires only a few pages and that most companies do not possess.

    How to identify this

    • There is no single answer to the question of how long applicant data may be stored.
    • Deletions occur manually, if someone remembers.
    • A request for access under Article 15 GDPR triggers urgency because no one knows where all the data is located.
    • There is no documented consent for the talent pool.

    Why this occurs

    Applicant data originates from multiple channels: portals, email, service providers, personal inboxes of managers. The applicant tracking system is just one location among many. And the deadline is inconvenient: deleting after two months would be too soon due to potential AGG claims, but indefinite retention is prohibited. Without clear rules, the easiest option prevails, which is to do nothing.

    Our approach

    1. Map data flows. We record where applicant data originates, where it flows, and where copies are stored. Personal inboxes and service providers are common blind spots.
    2. Define a deletion concept. We define deadlines for each case: rejected without contact, rejected after interview, hired, talent pool with consent. In practice, a six-month deadline after rejection has proven effective for rejected applicants, because claims under the AGG must be asserted within two months and litigated within a further three months.
    3. Automate in the system. Deletion and anonymisation are performed in the applicant tracking system according to rules, not memory. For the talent pool, consent is obtained, documented, and renewed in the system upon expiration.
    4. Close processes. Managers only receive application documents within the system, not via email. Service providers are contractually obliged to delete data upon completion. Requests for access are handled via a standard process with a deadline.

    What you gain

    • You can tell every applicant and every supervisory authority in one sentence what happens to the data.
    • The talent pool becomes usable because the legal basis is sound.
    • Data breaches due to scattered copies become unlikely.

    From our projects

    During data flow mapping in recruiting, we almost always find applicant data in locations no one had on their list: in managers' inboxes, in Teams channels, with service providers without a deletion agreement. The deletion concept itself can be written in one to two weeks. The real work is closing off the side channels, and that only succeeds if managers receive documents exclusively within the system.

    Good to know

    The legal basis for processing in the application procedure is Article 6 Paragraph 1 Letter b GDPR, supplemented by § 26 BDSG (Federal Data Protection Act), the continued validity of which is disputed following the jurisprudence of the European Court of Justice. For storage beyond the procedure, consent is required under Article 6 Paragraph 1 Letter a, which must be voluntary, informed, and revocable. The Betriebsrat (works council) has co-determination rights regarding the introduction and modification of the applicant tracking system.

    Frequently asked questions

    Are we still allowed to accept applications via email?

    Yes. However, you must then transfer the data into the system and delete the email. An application portal is the simpler approach, as the data flow is controlled from the outset.

    What about managers' interview notes?

    They are applicant data and are subject to the same deadlines and the right of access. Notes belong in the system, not in private folders, and they should refer to the documented selection criteria.

    Let's talk about Applicant Data and Data Protection

    In a thirty-minute first call we clarify where your biggest lever is and whether we are the right partner for it.

    Further reading

    Back to the field Recruiting

    Sources