Back to blog

June 2, 20259 min

GDPR-Compliant ATS: What Companies Need to Know

This article explains what GDPR concretely requires of an ATS, which mistakes show up most often, and what to look for when choosing a data-protection-ready applicant tracking system.

  • GDPR
  • Data Protection
  • ATS
  • Compliance

Why data protection in recruiting is especially delicate

An ATS holds name, address, salary expectations, career history, sometimes health information or photos — submitted in a relationship of trust, with far-reaching consequences for the person. These data are often kept far too long, even though only short retention periods are allowed.

  • Sensitive personal data in a relationship of trust
  • Far-reaching consequences: offer or rejection
  • Over-retention is the most common GDPR breach in recruiting

The seven most important GDPR requirements for an ATS

You and your ATS vendor must meet these seven requirements together. Each has practical consequences for how the system is configured.

  • 1. Lawful basis (Art. 6): the application process itself; talent pool only with consent
  • 2. Transparency (Art. 13): full information at or before collection, in the application form
  • 3. Data minimisation (Art. 5): only necessary fields — no questions on pregnancy, religion, nationality
  • 4. Deletion deadlines (Art. 17): 3–6 months after rejection; talent pool max. 12–24 months with renewable consent
  • 5. Data processing agreement (Art. 28): AVV with the ATS vendor; check EU server location
  • 6. No solely automated decisions (Art. 22): AI may rank, humans decide
  • 7. Data-subject rights (Art. 15–22): access, rectification, erasure fulfilable from the system

Deletion deadlines at a glance

Retention periods for applicant data differ by situation. A GDPR-compliant ATS monitors them automatically.

SituationRecommended period
Rejected after applying3–6 months (AGG claim window)
Candidate hiredDuration of employment + statutory retention
Talent pool (with consent)Max. 12–24 months, then renew consent
Unsolicited applicationUp to 6 months, then delete

The most common GDPR mistakes in recruiting

These five mistakes keep appearing — and a correctly configured ATS can avoid them entirely.

  • No AVV signed with the ATS vendor
  • Rejected applications kept for years instead of months
  • Talent pool without explicit, documented consent
  • AI use not mentioned in the privacy notice
  • Privacy notice not updated after a tool change

GDPR checklist for your ATS

Use this checklist when selecting or reviewing your applicant tracking system.

  • AVV with the vendor in place and current
  • Server location in the EU (ideally Germany)
  • Privacy notice automatically embedded in the application form
  • Consent management for the talent pool built in
  • Automated deletion-deadline monitoring active
  • Data-subject rights fulfilable from the system
  • AI features documented transparently
  • No solely automated decisions without human review
  • Only necessary fields on the application form
  • Audit log of data access

Conclusion

A GDPR-compliant ATS is not optional — it is a legal necessity for every company that hires in Germany. With the right system, GDPR compliance runs in the background without slowing recruiting. Choose a vendor that treats data protection as part of the product, not a checkbox.

Request a Virkla demo

Frequently asked questions

How long may applicant data be stored after a rejection?

Usually 3–6 months after rejection. The period tracks the two-month AGG claim window plus a buffer. After that the data must be deleted fully unless another legal basis applies.

Do I need an AVV even if my ATS vendor is “GDPR-compliant”?

Yes. Even if the vendor is GDPR-oriented, you as controller must conclude a data processing agreement (AVV) under Art. 28. Check whether it is already in the contract or must be requested separately.

May I keep applicants in a talent pool?

Yes, but only with explicit, freely given, documented consent that specifically covers the talent pool. It must be revocable. Without consent, storage beyond the end of the process is not allowed.

What if my ATS vendor hosts servers outside the EU?

Transfers to third countries (e.g. the US) need extra safeguards such as Standard Contractual Clauses (SCCs). Also check whether the US CLOUD Act could reach the data — privacy-sensitive organisations usually prefer a vendor with servers in Germany.

Is fully automated AI screening allowed under GDPR?

Not if it is a legally significant decision. Art. 22 GDPR prohibits decisions based solely on automated processing with significant effects on a person, without human involvement. AI screening is allowed if a human takes the final decision.

Cookies and analytics consent

We use Google Analytics to understand usage and improve the product. You can accept or reject analytics tracking.