MioTalent Blog

GDPR and Recruitment: Processing Applicant Data Correctly

Share this post
GDPR in Recruitment: Applicant Files with a Security Seal in the Archive — 2-Month AGG Retention Period, 4-to-6-Month Deletion Practice, 5 Steps to Best Practices.

International recruiting means that resumes, transcripts, passports, and health information cross national borders—between candidates, sourcing partners, recruiters, and companies. This is precisely where the General Data Protection Regulation (GDPR) comes into full force, and this is precisely where it is most frequently violated—usually not intentionally, but out of ignorance. This article lays out the obligations in plain language: which applicant data may be processed, on what basis, for how long—and what additional requirements apply in an international context. It is not a substitute for legal advice in individual cases, but it provides a practical roadmap for asking the right questions—and it is also the standard against which every service provider that works with applicant data must be held accountable.

Why Data Privacy Is Not a Side Issue in Recruiting

Market pressures lead to sloppiness: When a position remains unfilled for an average of 165 days—and in the hospitality industry, as many as 198 days (Federal Employment Agency, 2026)—every application seems like a stroke of luck that you want to hold onto—preferably permanently, in every file, for every future opportunity. That is precisely the reflex that the GDPR prohibits.

Yet proper data protection in international recruiting is not a cost factor, but a mark of quality. Candidates entrust their most sensitive documents to the process; companies are liable for what their service providers do with them. Those who can demonstrate compliance here have a selling point that is rare in the market—and those who cannot bear a liability risk that no fee can offset. Added to this is the damage to reputation: In candidates’ home countries, word gets around about experiences with recruiters and employers, and careless handling of passports and certificates is exactly the kind of story no one wants to hear about their own company. Data protection, then, is also part of an employer’s brand—especially where trust is the scarcest commodity.

Legal Basis: What Is Permitted in Terms of Data Processing

Personal data refers to any information relating to an identified or identifiable individual—from a person’s name and resume to their passport number. Processing such data always requires a legal basis, and in the context of job applications, the law itself provides that basis: Processing is permitted to the extent that it is necessary for the decision regarding the establishment of an employment relationship. The General Data Protection Regulation (GDPR) applies, supplemented by the Federal Data Protection Act and its provisions on employee data protection.

The key term here is “necessary,” not “useful.” What is necessary is what is required for the specific hiring decision. Consent from applicants is only required in cases where processing goes beyond what is necessary—for example, if documents are to be retained for future, as-yet-undetermined positions. And consent must be voluntary, informed, and revocable at any time; otherwise, it is invalid. In practical terms, this means that companies do not need consent during the ongoing selection process—and anyone who obtains it anyway only creates the obligation to manage its revocation. Consent is the tool for the exception, not for the rule.

What data may be processed—and what may not

Anything that supports the selection process is acceptable: application materials, proof of qualifications, professional background, and documents required for the application process—such as passport and visa information and proof of language proficiency. All of these are central to the process.

On the other hand, certain categories of personal data are off-limits unless they are absolutely necessary for the position in exceptional cases: health information, religious affiliation, ethnic origin, and political beliefs. This is particularly relevant in an international context, because such information is common in résumés from some countries of origin—it must not be used as a basis for selection and should not be shared further during the process. Equally sensitive is the unsolicited scrutiny of private social media profiles: Anything not necessary for assessing suitability has no place in the hiring process. Anyone who reviews profiles nonetheless should limit themselves to professional networks where the individual has voluntarily published their information for precisely this purpose.

A simple rule of thumb applies in most cases: Every piece of information must be able to answer the question of exactly why it is needed in the selection process. If there’s no answer, the information is left out. Incidentally, this discipline not only provides legal protection but also improves the selection process itself, because it focuses attention on what really matters for the position: qualifications, experience, language skills, and suitability.

Retention Periods: How Long Applicant Data May Be Retained

The rejection marks the end of the purpose of the processing—but not the immediate end of lawful retention. The reason is the General Equal Treatment Act: Rejected applicants may assert claims of discrimination, and a two-month deadline applies for doing so, starting from the date the rejection notice is received. To be able to defend against such claims, the documents may be retained for a reasonable period beyond that; in practice, a timeframe of about four to six months after the conclusion of the process has become standard. After that, the rule is: delete everything—completely and from all secondary storage locations as well—including email inboxes and shared folders. It is precisely these secondary storage locations where deletion practices most often fall short, because while the main file is kept in order, the copies are often forgotten.

Anyone who wants to keep records longer—for example, for a talent pool—needs the person’s explicit consent, along with clear information about why and for how long. A folder of applicant records that grows tacitly is not a talent reserve, but a violation with an expiration date. A cleaner approach is the reverse: At the end of each hiring process, actively ask who would like to be added to the pool—those who agree are a genuine reserve; those who do not respond are deleted.

The International Special Case: Data Across Borders

International recruiting adds two layers that are not present in domestic recruiting. The first is the transfer of data to third countries: The Western Balkan states outside the EU are considered third countries without an adequacy decision under data protection law. Data may only be transferred there—for example, to sourcing partners—with appropriate safeguards, which in practice usually involve the European Commission’s standard contractual clauses. Anyone working with partners abroad must have established this legal basis contractually before the first application is submitted. This is not a mere formality: without this basis, every single data transfer is unlawful, no matter how carefully the process is managed afterward.

The second level is data processing on behalf of a client: If a service provider processes applicant data on behalf of the company, a data processing agreement containing the legally required information is required. In addition, there are information obligations: When their data is collected, applicants must be informed—in a clear and comprehensive manner, not hidden in the fine print—about who is processing their data, for what purpose, to whom it is disclosed, and how long it will be stored. And finally, the rights of data subjects: access, rectification, and erasure—at any time and free of charge. Anyone who cannot respond to a request for access because no one knows where the data is stored has already encountered the real problem—namely, a lack of oversight over their own data flows. A simple overview of which data is stored where and who has access to it is therefore half the battle; it turns every request into a routine procedure rather than a search operation.

Duties as a Process: Five Steps to Good Practice

The rules can be broken down into a manageable five-step process. First, clarify the legal basis for each processing purpose: selection procedures are based on the legal basis; everything beyond that requires consent. Second, fulfill the duty to inform by providing clear privacy information at the beginning of the process. Third, establish a contractual basis with all parties involved: data processing agreements with service providers, standard contractual clauses with partners in third countries. Fourth, set deadlines and deletion routines—who deletes what and when, documented and on a regular basis. Fifth, designate a responsible person: someone within the company who maintains an overview, can respond to requests for information, and actually initiates the deletion routines rather than merely documenting them.

GDPR compliance is therefore not a mountain of paperwork, but rather a process that, once properly set up, runs on its own. The effort is concentrated at the beginning—contracts, information, timeline—and then tapers off to the point where it becomes a routine that is barely noticeable in day-to-day operations. For companies, it also serves as a selection criterion for service providers: Anyone who cannot provide a clear answer to questions about standard contractual clauses and retention periods has not fully considered the international aspect of their business. Our overview of labor migration to Germany in 2026 outlines the legal framework for the entire international recruitment process; the article on the duration of international recruitment provides the timeframe.

Sources: General Data Protection Regulation; Federal Data Protection Act; General Equal Treatment Act; Federal Employment Agency (Vacancy Periods 2026).

Kostenlose Erstberatung

Personalanfrage – Express