Back to blog

September 21, 20268 min

Application privacy notice: template + generator checklist

This article is not legal advice and does not replace a review by your DPO or counsel. It summarises what Art. 13 requires for applicant data, which legal bases are typical in recruiting, and how an ATS can surface the notice on the career site. The template below is a starting point with placeholders — not a finished document to publish unreviewed.

  • GDPR
  • Privacy
  • Applications
  • Compliance
  • ATS

Why applications need their own privacy notice

The general website privacy policy usually covers visits, newsletters, and contact forms. Application files are a different purpose: CVs, certificates, salary expectations, sometimes special-category data if someone sends it unsolicited. Art. 13 requires information at the time of collection — on the career site or in the form, not only on request.

  • The processing purpose is running the hiring process, not website analytics
  • Recipients are hiring managers, possibly the works council, vendors (the ATS as processor)
  • Retention follows the AGG claim window and your deletion concept — not “as long as needed” with no number
  • Missing or incomplete notices are a frequent finding when someone complains to a supervisory authority

Art. 13 disclosures required in recruiting

Treat the table as a generator checklist: every field must appear in your applicant privacy notice. If your ATS hosts career pages, maintain these blocks as their own copy — not a footer link to marketing privacy.

DisclosureWhat must be specificTypical gap
ControllerCompany, address, representation, contactBrand name only, no serviceable address
DPOContact if you must appoint oneMissing even though appointed
PurposesHiring process; talent pool separately“HR purposes” with no split
Legal basesArt. 6(1)(b), (f), (a) as applicable — per purpose“Legitimate interest” for everything
RecipientsInternal roles + ATS/host as processorCloud vendor unnamed
Third countryWhether/which transfer, SCCs or adequacyUS tool with no mention
RetentionConcrete periods per category“After the process ends” with no months
RightsAccess, erasure, complaint authorityRights list without the authority
Art. 22Whether an automated decision happensAI ranking with no clarification

Legal bases that are typical in hiring

One purpose, one basis. Do not fold a talent pool into the same basis as the live process.

  • GDPR Art. 6(1)(b): processing to take steps at the person’s request before entering a contract — the live application process
  • Art. 6(1)(f): legitimate interest in keeping rejected files for the AGG claim window (in practice often 3–6 months after rejection) to defend the company
  • Art. 6(1)(a): consent for a talent pool or longer storage after the process ends — freely given, informed, withdrawable
  • Art. 9: special categories (health, severe disability) only if a clear permission exists; minimise and protect data sent unsolicited
  • Art. 22: if AI ranks applications, state that no solely automated decision with legal effect is taken and a human decides

Template: structure of an application privacy notice

Replace the placeholders. Have legal or the DPO check legal bases and periods against your deletion concept and the DPA with the ATS before the text goes live.

  • 1. Controller: [company name], [address], [legal representation], [recruiting or privacy email].
  • 2. Privacy contact: [DPO / privacy team], [email].
  • 3. Purposes: We process your application data to decide on hiring and to run the process. A talent pool happens only if you consent separately.
  • 4. Data types: contact details, CV, cover letter, certificates, information you send us; career-site usage data where technically necessary.
  • 5. Legal bases: Art. 6(1)(b) (process); Art. 6(1)(f) (retention for legal defence after rejection, balancing: our interest in defending AGG claims); Art. 6(1)(a) (talent pool).
  • 6. Recipients: recruiters and hiring managers for the posted role, works council where legally required. [ATS vendor] as processor, DPA in place, hosting: [EU/Germany].
  • 7. Third-country transfer: [does not occur / occurs under [mechanism, e.g. adequacy decision or SCCs]].
  • 8. Retention: if hired, transfer into the personnel file under a separate notice; if rejected, deletion after [3–6 months] unless you consented to a talent pool. If you withdraw consent, we delete unless another basis applies.
  • 9. Your rights: access, rectification, erasure, restriction, portability, objection to Art. 6(1)(f) processing, withdrawal of consent for the future, complaint to the competent supervisory authority [name/country].
  • 10. No obligation to provide data, but without the required data we cannot assess the application. No solely automated decision under Art. 22: [short description if AI support is used, plus human final decision].

Where the notice must live — and what a “generator” should do

“Generator” here means the same building blocks, structured and versioned — not an unsupervised auto-legal document. The text must be true for your stack.

  • Before form submit: a checkbox or a clear link “Privacy notice for applications” — not only in the marketing-site footer
  • On every career page / job ad that accepts applications
  • Link it again in the acknowledgement email so unsolicited applications by mail still get the notice
  • Version it: date and controller; when you change ATS or hosting, change the notice and the DPA together
  • An ATS with EU hosting and a documented DPA shrinks the third-country section — it does not replace informing applicants

Bottom line

An application privacy notice is the Art. 13 information for the recruiting purpose: specific, separate from the website policy, with real periods and real recipients. Use the checklist and template as a draft, have legal check it against the DPA and deletion concept, and surface the text where the data is collected — on the career site.

See GDPR-compliant hiring software

Frequently asked questions

Does the general website privacy policy cover applications?

Usually not. Art. 13 requires information on the specific purposes, legal bases, recipients, and retention of applicant data. A cookie and marketing policy does not do that. A dedicated section or a dedicated notice for the hiring process is the usual and safer path.

Do you need consent for the application process itself?

For the live process the typical basis is Art. 6(1)(b) (pre-contractual steps), not consent. You mainly need consent for a talent pool or other purposes after the process ends. A pre-ticked box is not valid consent.

Where should the privacy notice sit in the application form?

Where applicants can see it before or when they submit: on the form itself, not only after they click send. A required link plus a short acknowledgement is common; hiding it in the website footer is not enough.

What if we use AI to rank applications?

Then you must inform about that processing and respect Art. 22: no solely automated decision with significant effect without human involvement. State clearly that scores support and recruiters decide. Details also belong in the DPA and internal AI documentation.

Cookies and analytics consent

We use Google Analytics to understand usage and improve the product. You can accept or reject analytics tracking.