# Applicant data GDPR compliant: Retention periods, talent pool, AGG storage

> How long can applicant data be stored? Deletion concept between AGG (General Equal Treatment Act) deadlines and GDPR (General Data Protection Regulation), consent for talent pools, rights of access and the role of the applicant tracking system.

URL: https://techport.ai/en/hr-beratung/recruiting/bewerberdaten-dsgvo

---

1.  [HR Consulting](/en/hr-beratung)/
2.  [Recruiting](/en/hr-beratung/recruiting)/
3.  Applicant Data and Data Protection

[Recruiting](/en/hr-beratung/recruiting)

# Applicant Data and Data Protection

By Redaktion techport.ai, HR-Beratung · Last updated on 21 August 2026

In almost every applicant tracking system we examine, there is data from individuals who applied five, six, or ten years ago. CVs, references, interview notes, sometimes health information. No one has deleted it because no one defined when. And no one uses it because no one knows if they are permitted to.

This presents a risk without benefit. The General Data Protection Regulation requires personal data to be deleted as soon as the purpose ceases. The Allgemeine Gleichbehandlungsgesetz (General Equal Treatment Act) provides deadlines for rejected applicants to claim compensation. Between these two lies a deletion concept that requires only a few pages and that most companies do not possess.

## How to identify this

*   There is no single answer to the question of how long applicant data may be stored.
*   Deletions occur manually, if someone remembers.
*   A request for access under Article 15 GDPR triggers urgency because no one knows where all the data is located.
*   There is no documented consent for the talent pool.

## Why this occurs

Applicant data originates from multiple channels: portals, email, service providers, personal inboxes of managers. The applicant tracking system is just one location among many. And the deadline is inconvenient: deleting after two months would be too soon due to potential AGG claims, but indefinite retention is prohibited. Without clear rules, the easiest option prevails, which is to do nothing.

## Our approach

1.  **Map data flows.** We record where applicant data originates, where it flows, and where copies are stored. Personal inboxes and service providers are common blind spots.
2.  **Define a deletion concept.** We define deadlines for each case: rejected without contact, rejected after interview, hired, talent pool with consent. In practice, a six-month deadline after rejection has proven effective for rejected applicants, because claims under the AGG must be asserted within two months and litigated within a further three months.
3.  **Automate in the system.** Deletion and anonymisation are performed in the applicant tracking system according to rules, not memory. For the talent pool, consent is obtained, documented, and renewed in the system upon expiration.
4.  **Close processes.** Managers only receive application documents within the system, not via email. Service providers are contractually obliged to delete data upon completion. Requests for access are handled via a standard process with a deadline.

## What you gain

*   You can tell every applicant and every supervisory authority in one sentence what happens to the data.
*   The talent pool becomes usable because the legal basis is sound.
*   Data breaches due to scattered copies become unlikely.

## From our projects

During data flow mapping in recruiting, we almost always find applicant data in locations no one had on their list: in managers' inboxes, in Teams channels, with service providers without a deletion agreement. The deletion concept itself can be written in one to two weeks. The real work is closing off the side channels, and that only succeeds if managers receive documents exclusively within the system.

## Good to know

The legal basis for processing in the application procedure is Article 6 Paragraph 1 Letter b GDPR, supplemented by [§ 26 BDSG](https://www.gesetze-im-internet.de/bdsg_2018/__26.html) (Federal Data Protection Act), the continued validity of which is disputed following the jurisprudence of the European Court of Justice. For storage beyond the procedure, consent is required under Article 6 Paragraph 1 Letter a, which must be voluntary, informed, and revocable. The Betriebsrat (works council) has co-determination rights regarding the introduction and modification of the applicant tracking system.

## Frequently asked questions

Are we still allowed to accept applications via email?

Yes. However, you must then transfer the data into the system and delete the email. An application portal is the simpler approach, as the data flow is controlled from the outset.

What about managers' interview notes?

They are applicant data and are subject to the same deadlines and the right of access. Notes belong in the system, not in private folders, and they should refer to the documented selection criteria.

## Let's talk about Applicant Data and Data Protection

In a thirty-minute first call we clarify where your biggest lever is and whether we are the right partner for it.

[Book a first call](/en/kontakt)[Our consulting](/en/so-funktionierts)

## Further reading

[RecruitingSourcing Channels and Talent PoolsWhich recruiting channels truly deliver, how a talent pool is built and maintained in compliance with DSGVO (General Data Protection Regulation), why employee referrals often go unused, and how recruitment agencies are managed.](/en/hr-beratung/recruiting/sourcing-und-talentpools)[HR Data and SystemsMaster Data Quality and Single Source of TruthThe same person in five systems with five truths: How an HR data model is created, which system is leading, how clean-up and interfaces function, and how quality is maintained long-term.](/en/hr-beratung/hr-daten-und-systeme/stammdaten)[Co-determination and ComplianceHR Software and Works CouncilsEvery HR system is subject to co-determination, even without an intention to monitor. How to successfully introduce it with the Works Council: early information, framework works agreement, data protection concept, AI clauses.](/en/hr-beratung/mitbestimmung-und-compliance/betriebsrat)[KnowledgeHR Regulatory RadarWhat applies, what is coming, what to do now.](/en/hr-beratung/regulatorik-radar)[KnowledgeHR GlossaryKey HR terms, briefly explained.](/en/hr-beratung/glossar)

Back to the field [Recruiting](/en/hr-beratung/recruiting)

## Sources

*   [Regulation (EU) 2016/679 (GDPR), EUR-Lex](https://eur-lex.europa.eu/eli/reg/2016/679/oj)
*   [§ 26 BDSG (Federal Data Protection Act), data processing for employment purposes](https://www.gesetze-im-internet.de/bdsg_2018/__26.html)
*   [§ 15 AGG (General Equal Treatment Act), compensation and damages](https://www.gesetze-im-internet.de/agg/__15.html)
*   European Court of Justice, judgment of 30 March 2023, C-34/21 (Employee Data Protection)

Rt

Written by

[Redaktion techport.ai](/ueber-uns), HR-Beratung

Mehr als 15 Jahre Erfahrung in HR-Prozessen und HR-Systemen, Einführung von HR-Software in mittelständischen Unternehmen, Verhandlung von Betriebsvereinbarungen zu IT-Systemen.

This page reflects the position as at the date shown and does not constitute legal advice. For specific questions we work together with your legal advisers.

[More about us](/en/ueber-uns)

More from techport.ai

[

Software

Custom process software for mid-sized companies.

](/en/loesungen)[

IT consulting

Strategy, architecture, operations and security.

](/en/it-beratung)[

IT maturity check

Ten minutes to a clear position.

](/en/it-beratung/reifegrad-check)[

HR maturity check

24 statements, a result per field.

](/en/hr-beratung/reifegrad-check)[

Funding

BAFA grant plus more than 50 programmes for delivery.

](/en/foerderung)[

Process in practice

How workflows become reliable software.

](/en/sop-praxis)[

Data and AI

Analysis, forecasts and assistance systems.

](/en/daten-ki)[

About us

The people behind techport.ai.

](/en/ueber-uns)
