Back to blog

August 11, 20267 min

GDPR Candidate Data Retention: Deletion Deadlines Every German Employer Needs to Know

This article explains the legal basis for candidate data deletion deadlines, gives a practical overview of the exact timelines for each scenario, and shows how to build a deletion policy that actually works day to day — not just on paper.

  • GDPR
  • Data Retention
  • Compliance
  • ATS

Why applicant data deletion deadlines are a legal requirement, not best practice

GDPR requires that personal data be kept only as long as necessary for the purpose it was collected for (Art. 5(1)(e) — storage limitation). For candidate data, that purpose ends when the hiring process concludes — either with an offer or a rejection. Keeping applicant data beyond that without a specific justification breaches the storage-limitation principle and creates real regulatory exposure.

  • The processing purpose ends at offer or rejection — not only once someone actively deletes the record
  • German supervisory authorities consistently flag over-retention as one of the most common recruiting-related violations
  • Candidates can request information about stored data and its deletion at any time (GDPR Art. 15, 17)

The legal basis: GDPR Article 17 and Germany's AGG claim period

The commonly cited 3–6 month retention window after a rejection is not arbitrary — it derives from the Allgemeines Gleichbehandlungsgesetz (AGG), Germany's General Equal Treatment Act. Rejected candidates can file a discrimination compensation claim up to two months after receiving the rejection. Employers need to retain the application file for that window as evidence to defend against such a claim.

  • AGG claim window: 2 months from receipt of the rejection (§15(4) AGG)
  • Recommended safety buffer: an additional 1–4 months to account for delivery and internal processing delays
  • Result: a total retention period of 3–6 months is standard practice and accepted by German data protection authorities
  • Retaining data longer without a separate legal basis is not covered by the AGG rationale

Retention periods at a glance

Not every application follows the same rule. The right retention period depends on the outcome of the process and the type of application.

ScenarioRecommended retention periodLegal basis
Rejected after applying3–6 months after receipt of the rejectionAGG claim period (2 months) + safety buffer
Candidate hiredMoves into the personnel file; deleted after the employment relationship ends per statutory retention rulesPurpose change; employment and tax-law retention periods
Talent pool (with consent)Max. 12–24 months, then renew consent or deleteGDPR Art. 6(1)(a) — consent
Unsolicited applicationUp to 6 months without a response, then delete — unless consent was givenGDPR Art. 5(1)(e)
Withdrawn applicationDelete promptly, unless another retention ground appliesGDPR Art. 17(1)(a)

How to automate deletion deadlines in practice

A deletion policy that exists only on paper gets ignored in day-to-day operations. Deletion deadlines need to live in the system that stores the data — not in a spreadsheet nobody checks.

  • Configure retention periods per application status in your ATS (rejected, hired, talent pool, unsolicited)
  • Set up automated reminders or automatic deletion once the deadline passes — a status flag alone is not enough
  • Log every deletion in an audit trail so you can demonstrate compliance if challenged
  • Attach an expiry date to talent-pool consent and prompt automatically for renewal
  • Assign clear ownership: who periodically verifies that the deletion routine is actually running?

Common mistakes companies make when deleting candidate data

These mistakes come up repeatedly in data protection audits — and are fully avoidable with a properly configured ATS.

  • Rejected applications kept for years instead of months, 'just to be safe'
  • Talent pool entries without documented, specific consent or without an expiry date
  • Deletion happens only when someone remembers, with no system-driven reminder or automation
  • Application files remain in email inboxes or local folders even after being deleted from the ATS
  • No documentation of why a particular retention period was chosen — the reasoning is missing during an audit

Checklist: building a deletion policy for your company

Use this checklist to build your own deletion policy or review an existing one.

  • Retention periods defined in writing for each application category (rejected, hired, talent pool, unsolicited)
  • Legal basis documented for each period (AGG claim window, consent, statutory retention)
  • Automated deletion or a binding reminder is active in your ATS
  • Talent-pool consent includes an expiry date and a renewal process
  • Deletions are logged in an audit trail
  • All copies of the data are accounted for — not just in the ATS, but also in emails and exports
  • The deletion policy is reflected in the privacy notice on the application form
  • Regular checks confirm the deletion routine is actually being enforced

Conclusion

Deletion deadlines are not an administrative footnote — they are one of the most concrete GDPR obligations in recruiting, and one of the fastest to implement. Knowing the timelines, documenting them, and automating enforcement in your ATS meaningfully reduces liability while building candidate trust. An ATS that supports retention deadlines out of the box turns compliance into the default, not the exception.

Request a Virkla demo

Frequently asked questions

When does the deletion deadline start after a rejection?

The clock starts when the candidate receives the rejection, not when it was sent. From that point, the two-month AGG claim window applies, which is the basis for the recommended 3–6 month total retention period.

Do I need to notify candidates before deleting their data?

A separate notification before deletion is not a strict legal requirement if the retention period was already communicated transparently in the privacy notice on the application form. Even so, it's good practice to state the timeline clearly so candidates know what to expect.

Can I keep application files for a talent pool?

Yes, but only with explicit, freely given, documented consent that specifically covers the talent pool — a general application consent is not sufficient. The consent should carry an expiry date (12–24 months is recommended) and remain revocable at any time.

What happens if a data protection complaint is filed over excessive retention?

The relevant supervisory authority can request evidence of the retention period and its legal basis. If there is no defensible justification, or the recommended timeline was significantly exceeded, fines under GDPR Art. 83 and an order for immediate deletion are both possible outcomes.

Does the 3–6 month rule also apply to internship and working-student applications?

In principle, the same logic applies, since an AGG claim window exists for these roles too. In practice, some companies shorten the period slightly for short-term positions — but this should still be documented and applied consistently to avoid unequal treatment.

Cookies and analytics consent

We use Google Analytics to understand usage and improve the product. You can accept or reject analytics tracking.