Compliance & Blind Hiring

UK GDPR Right to Erasure for Recruitment Agencies

Understand UK GDPR right to erasure rules for recruitment agencies. Learn when to delete candidate data and how to stay compliant. Get the guide.

By Xabi Errotabehere, founder, Distill · Updated 18 July 2026

When a candidate asks you to delete their CV and personal data, it's not always straightforward what you need to do — or when. The UK GDPR gives candidates a right to erasure. But this comes with limits and conditions that recruitment agencies must understand to avoid compliance risks.

What the right to erasure actually covers

The right to erasure — often called the right to be forgotten — allows candidates to request deletion of their personal data held by your agency. Under UK GDPR (Article 17), this generally includes:

  • CVs and application forms
  • Contact details (email, phone number, address)
  • Any notes or assessments linked to the candidate

The right only applies in specific circumstances. Typically, candidates can ask for deletion if:

  • Their data is no longer necessary for the purpose collected (for example, a role they applied for has closed)
  • They withdraw consent and you have no other lawful basis to keep their data
  • They object to processing and there's no overriding legitimate interest
  • The data was processed unlawfully
  • You are legally required to erase the data

This right doesn't grant automatic deletion in every case. For example, data needed to defend a legal claim, comply with statutory obligations, or establish a contract is usually exempt.

When you can (and can't) refuse a request

You may refuse or delay erasure when:

  • You need to keep data to comply with legal or regulatory obligations (e.g., tax, anti-money laundering checks)
  • The data is necessary for defending or exercising legal claims, such as discrimination complaints
  • The processing is based on legitimate interests that override the candidate's request — for example, fraud prevention
  • There's an ongoing recruitment process where the candidate consented to data use

Refusals should be communicated clearly and promptly, explaining which exemption applies. Blanket refusals without justification risk enforcement action by the ICO.

The 30-day clock — and what happens if you miss it

You generally have one calendar month from receiving an erasure request to comply or provide a refusal explanation. This period starts the day after the request arrives.

You may extend this by a further two months if the request is complex or numerous. But you must inform the candidate within the first month and explain the delay.

Failing to respond within 30 days (or the extended deadline) can lead to ICO complaints and investigations. The ICO has fined agencies for ignoring or delaying erasure requests, particularly where personal data was retained without lawful basis.

Keep records of requests and responses to demonstrate compliance and timelines if challenged.

Step-by-step: handling an erasure request

  1. Confirm identity. Verify the requester is the candidate or authorised representative to avoid accidental deletion.
  2. Acknowledge receipt. Confirm the request within a few days, stating the 30-day timescale.
  3. Assess the request. Check whether the right to erasure applies based on the data held and lawful basis.
  4. Locate all data. Search your ATS, emails, shared drives, backups, and any third-party processors.
  5. Delete or anonymise data. Remove personal information irreversibly, or anonymise if retention is necessary for statistical or legal reasons.
  6. Communicate outcome. Inform the candidate whether their data has been deleted or if you're refusing (with reasons).
  7. Record the process. Log the request, actions taken, and correspondence for accountability.

If you rely on third-party systems, ensure they can delete data promptly or that you have processes to retrieve and erase data manually.

How to prevent data lingering in ATS, email and shared drives

Data often remains hidden in places agencies overlook:

  • ATS systems: Candidate data may be backed up or synced to multiple modules or partner systems. Check if your ATS supports erasure requests and how quickly it processes deletions.
  • Email archives: Candidate CVs or notes sent or received by email can stay indefinitely. Use auto-deletion policies or search-and-destroy routines for candidate-related emails.
  • Shared drives and folders: CVs saved in team folders or cloud storage may not be linked to your ATS. Regular audits and clear file-naming conventions help locate and remove these files promptly.
  • Backups: Data stored in backups is harder to erase immediately. Document your approach here and inform candidates if erasure from backups is delayed.
  • Third-party processors: If you share CVs with clients or other vendors, confirm their erasure procedures to avoid compliance gaps.

Regular training for your team on data handling and erasure procedures reduces the chance of accidental retention.

FAQ

Q: Can candidates request erasure of data shared with clients? A: No. Once a CV is shared, the client becomes a separate data controller responsible for their own GDPR compliance. Your obligation is to delete your copy but inform the candidate they need to request erasure from the client separately.

Q: What if a candidate asks for erasure but I have an active job for them? A: If you have ongoing recruitment activities and a lawful basis other than consent (such as contract negotiation), you may refuse or delay erasure until the process completes.

Q: Does deleting a CV mean I have to delete all related notes and assessments? A: Generally yes, if they contain personal data. If you need to keep anonymised notes for legitimate reasons, ensure they can't be linked back to the candidate.

Q: How long should we keep CVs if no erasure request is made? A: The ICO recommends no longer than six months to a year after the last contact, unless there is a legal or business reason to keep them longer. See ICO guidance on CV data retention for recruitment.

Q: What if a candidate asks to delete their data but wants to reapply later? A: You can delete their current data and request a new CV when they reapply. Keep clear records that the previous data was erased as requested.

If you're responsible for compliance and want to reduce the risk of data lingering unnoticed, Distill strips the name, email, phone, photo, and graduation year from CVs before you submit them. This helps you manage erasure requests more confidently and keeps your agency within UK GDPR requirements. Start free Distill trial.