September 21, 20268 min
Application privacy notice: template + generator checklist
This article is not legal advice and does not replace a review by your DPO or counsel. It summarises what Art. 13 requires for applicant data, which legal bases are typical in recruiting, and how an ATS can surface the notice on the career site. The template below is a starting point with placeholders — not a finished document to publish unreviewed.
- GDPR
- Privacy
- Applications
- Compliance
- ATS
Why applications need their own privacy notice
The general website privacy policy usually covers visits, newsletters, and contact forms. Application files are a different purpose: CVs, certificates, salary expectations, sometimes special-category data if someone sends it unsolicited. Art. 13 requires information at the time of collection — on the career site or in the form, not only on request.
- The processing purpose is running the hiring process, not website analytics
- Recipients are hiring managers, possibly the works council, vendors (the ATS as processor)
- Retention follows the AGG claim window and your deletion concept — not “as long as needed” with no number
- Missing or incomplete notices are a frequent finding when someone complains to a supervisory authority
Art. 13 disclosures required in recruiting
Treat the table as a generator checklist: every field must appear in your applicant privacy notice. If your ATS hosts career pages, maintain these blocks as their own copy — not a footer link to marketing privacy.
| Disclosure | What must be specific | Typical gap |
|---|---|---|
| Controller | Company, address, representation, contact | Brand name only, no serviceable address |
| DPO | Contact if you must appoint one | Missing even though appointed |
| Purposes | Hiring process; talent pool separately | “HR purposes” with no split |
| Legal bases | Art. 6(1)(b), (f), (a) as applicable — per purpose | “Legitimate interest” for everything |
| Recipients | Internal roles + ATS/host as processor | Cloud vendor unnamed |
| Third country | Whether/which transfer, SCCs or adequacy | US tool with no mention |
| Retention | Concrete periods per category | “After the process ends” with no months |
| Rights | Access, erasure, complaint authority | Rights list without the authority |
| Art. 22 | Whether an automated decision happens | AI ranking with no clarification |
Legal bases that are typical in hiring
One purpose, one basis. Do not fold a talent pool into the same basis as the live process.
- GDPR Art. 6(1)(b): processing to take steps at the person’s request before entering a contract — the live application process
- Art. 6(1)(f): legitimate interest in keeping rejected files for the AGG claim window (in practice often 3–6 months after rejection) to defend the company
- Art. 6(1)(a): consent for a talent pool or longer storage after the process ends — freely given, informed, withdrawable
- Art. 9: special categories (health, severe disability) only if a clear permission exists; minimise and protect data sent unsolicited
- Art. 22: if AI ranks applications, state that no solely automated decision with legal effect is taken and a human decides
Template: structure of an application privacy notice
Replace the placeholders. Have legal or the DPO check legal bases and periods against your deletion concept and the DPA with the ATS before the text goes live.
- 1. Controller: [company name], [address], [legal representation], [recruiting or privacy email].
- 2. Privacy contact: [DPO / privacy team], [email].
- 3. Purposes: We process your application data to decide on hiring and to run the process. A talent pool happens only if you consent separately.
- 4. Data types: contact details, CV, cover letter, certificates, information you send us; career-site usage data where technically necessary.
- 5. Legal bases: Art. 6(1)(b) (process); Art. 6(1)(f) (retention for legal defence after rejection, balancing: our interest in defending AGG claims); Art. 6(1)(a) (talent pool).
- 6. Recipients: recruiters and hiring managers for the posted role, works council where legally required. [ATS vendor] as processor, DPA in place, hosting: [EU/Germany].
- 7. Third-country transfer: [does not occur / occurs under [mechanism, e.g. adequacy decision or SCCs]].
- 8. Retention: if hired, transfer into the personnel file under a separate notice; if rejected, deletion after [3–6 months] unless you consented to a talent pool. If you withdraw consent, we delete unless another basis applies.
- 9. Your rights: access, rectification, erasure, restriction, portability, objection to Art. 6(1)(f) processing, withdrawal of consent for the future, complaint to the competent supervisory authority [name/country].
- 10. No obligation to provide data, but without the required data we cannot assess the application. No solely automated decision under Art. 22: [short description if AI support is used, plus human final decision].
Where the notice must live — and what a “generator” should do
“Generator” here means the same building blocks, structured and versioned — not an unsupervised auto-legal document. The text must be true for your stack.
- Before form submit: a checkbox or a clear link “Privacy notice for applications” — not only in the marketing-site footer
- On every career page / job ad that accepts applications
- Link it again in the acknowledgement email so unsolicited applications by mail still get the notice
- Version it: date and controller; when you change ATS or hosting, change the notice and the DPA together
- An ATS with EU hosting and a documented DPA shrinks the third-country section — it does not replace informing applicants
Bottom line
An application privacy notice is the Art. 13 information for the recruiting purpose: specific, separate from the website policy, with real periods and real recipients. Use the checklist and template as a draft, have legal check it against the DPA and deletion concept, and surface the text where the data is collected — on the career site.
See GDPR-compliant hiring softwareFrequently asked questions
Does the general website privacy policy cover applications?
Usually not. Art. 13 requires information on the specific purposes, legal bases, recipients, and retention of applicant data. A cookie and marketing policy does not do that. A dedicated section or a dedicated notice for the hiring process is the usual and safer path.
Do you need consent for the application process itself?
For the live process the typical basis is Art. 6(1)(b) (pre-contractual steps), not consent. You mainly need consent for a talent pool or other purposes after the process ends. A pre-ticked box is not valid consent.
Where should the privacy notice sit in the application form?
Where applicants can see it before or when they submit: on the form itself, not only after they click send. A required link plus a short acknowledgement is common; hiding it in the website footer is not enough.
What if we use AI to rank applications?
Then you must inform about that processing and respect Art. 22: no solely automated decision with significant effect without human involvement. State clearly that scores support and recruiters decide. Details also belong in the DPA and internal AI documentation.
