Compliance & Blind Hiring

GDPR CV Compliance for EU Recruiters in 2026

Understand 2026 GDPR updates affecting EU candidate CVs. Learn lawful bases, data minimisation, and retention rules to ensure compliance. Get the guide.

By Xabi Errotabehere, founder, Distill · Updated 18 July 2026

Recruiters handling CVs from EU candidates face tighter rules in 2026. These affect how you collect, store, and share candidate data. Getting this wrong risks fines and delays in your hiring process.

TL;DR

GDPR updates in 2026 sharpen the focus on lawful bases for processing, data minimisation, and retention limits. Recruiters should review their consent procedures, securely manage candidate information, and keep clear records of processing activities. Redacting sensitive data like photos and graduation years is increasingly important. Penalties for non-compliance can reach millions in fines, so operationalising compliance through standardised workflows and tools is key.

What changed in 2026

The main GDPR text remains unchanged, but enforcement and guidance tightened in 2026, especially around recruitment.

  • Lawful bases clarified: Consent is less favoured due to its revocability. Agencies are encouraged to rely on legitimate interest or contract performance where possible.
  • Data minimisation emphasised: Only collect what's strictly necessary. This includes reconsidering data like photos or precise age.
  • Retention periods limited: Candidate data shouldn't be kept indefinitely. Typical maximum retention is six to twelve months after the recruitment process ends, unless there's a lawful reason to keep it longer.
  • Data subject rights reinforced: Candidates have stronger rights to access, rectify, and erase their data. Agencies must respond promptly.
  • Processor accountability increased: Agencies must hold processors (like ATS providers) to high standards and have clear contracts in place.

The UK's version of GDPR (UK GDPR) largely mirrors the EU's but with some divergences in enforcement tone. For agencies recruiting across borders, EU GDPR compliance remains essential.

The GDPR (EU) obligations recruiters care about

Recruiters process candidate data daily. Here are the key GDPR obligations that matter most:

  • Lawful basis for processing: Most agencies rely on legitimate interest (Article 6(1)(f)) or contract necessity (Article 6(1)(b)). Consent (Article 6(1)(a)) is less common because candidates can withdraw it anytime, complicating recruitment.
  • Transparency: Under Articles 12-14, candidates must be informed clearly about what data you collect, why, how long you keep it, and their rights.
  • Data minimisation (Article 5(1)(c)): Only hold data relevant to the role and recruitment process. Avoid collecting unnecessary sensitive data.
  • Storage limitation (Article 5(1)(e)): Keep data only as long as necessary. Set a retention schedule matched your privacy notice.
  • Data subject rights (Articles 15-22): Be prepared to handle access, rectification, deletion, and portability requests quickly—usually within one month.
  • Security (Article 32): Implement technical and organisational measures to protect candidate data from loss, unauthorised access, or leaks.
  • Processor agreements (Article 28): Ensure contracts with ATS providers and other processors specify GDPR responsibilities.

What recruiters must redact / disclose / retain

Handling CVs means balancing transparency with data protection.

  • Redact: Remove or anonymise data not strictly needed for recruitment decisions. Common items include:
    • Photos (can reveal protected characteristics)
    • Graduation years or dates of birth (avoid age discrimination)
    • Personal identifiers beyond contact details (e.g., ID numbers)
    • References or salary history unless explicitly requested
  • Disclose: Candidates should receive a clear privacy notice covering:
    • What data you collect and why
    • How you use the data (e.g., to assess suitability, verify qualifications)
    • Retention period or criteria used to decide it
    • Their rights, including how to complain to a data protection authority
  • Retain: Keep only what supports the recruitment decision or legal obligations. Typical retention:
    • Active recruitment: until the position is filled
    • Post-process: six to twelve months to defend against discrimination claims or for future vacancies
    • Longer only if candidates consent or there's a contractual reason

Where you act as a processor (e.g., forwarding CVs to clients), your obligations include ensuring the client uses the data lawfully and limiting data in line with the client's instructions.

Penalties and enforcement landscape

GDPR fines remain a serious risk. Enforcement has become stricter since 2026:

  • Supervisory authorities across the EU are imposing fines on recruitment agencies for failures to obtain valid lawful bases or for poor data security.
  • Penalties can reach up to €20 million or 4% of global turnover (whichever is higher).
  • Aside from fines, agencies face reputational damage and legal claims from candidates.
  • Enforcement trends show particular focus on:
    • Retention beyond reasonable periods
    • Unlawful sharing or sale of candidate data
    • Insufficient transparency and failure to respond to data subject requests
  • Agencies operating in multiple jurisdictions must monitor local supervisory authorities for guidance and coordinate compliance efforts.

How agencies operationalise this

Compliance isn't just theory — it needs clear steps embedded in your recruitment workflow:

  • Update privacy notices: Make candidate-facing notices thorough but concise. Link them in application portals and emails.
  • Review data collection forms: Remove unnecessary fields like photos or birthdates unless strictly required.
  • Set retention schedules: Automate deletion or anonymisation of CVs older than your retention period.
  • Train recruiters: Ensure all staff understand lawful bases, data minimisation, and how to handle candidate rights requests.
  • Use compliant tools: ATS and CV parsing software should support data redaction and secure storage. Distill, for example, strips photos, emails, phone numbers, and graduation years automatically before submission.
  • Document processing activities: Maintain records of your lawful bases, retention policies, and processor contracts for audit readiness.
  • Respond promptly: Assign responsibility for handling access or deletion requests within one month.
  • Audit regularly: Conduct periodic checks to identify gaps in data handling and fix them.

FAQ

Can I rely on consent to process CV data?

Consent is valid but fragile. Candidates can withdraw it anytime, which complicates recruitment workflows. Legitimate interest or contract necessity are usually better lawful bases.

How long can I keep unsuccessful candidates’ CVs?

Typically, six to twelve months after recruitment ends is reasonable. Longer retention requires clear justification or candidate consent.

Do I have to remove photos from CVs?

Photos reveal protected characteristics and aren't necessary for most recruitment decisions. Removing them reduces discrimination risk and matches data minimisation.

What happens if a candidate requests deletion after submitting a CV?

You generally need to delete their data unless you have a lawful reason to keep it (e.g., ongoing contract negotiations or legal defence). Respond within one month.

Are there differences between the UK GDPR and EU GDPR I should worry about?

Differences exist but are minor for recruitment. If you recruit in both jurisdictions, comply with the stricter rules and monitor regulatory updates.


If you send 20+ CVs a week to clients using ATS systems, Distill helps you stay compliant by automatically stripping photos, contact details, and graduation years from CVs before submission. Try Distill free to remove compliance risks without adding extra work.