Back to blog

May 1, 20269 min

GDPR-Compliant ATS Selection: The Checklist Every German HR Team Needs

The consequences of a non-compliant ATS range from DPO pushback during procurement to supervisory authority investigations after a data subject complaint. Most issues are avoidable — if you know what to ask. This guide distils what experienced German HR compliance leads check before evaluating any recruiting software.

  • GDPR
  • ATS
  • Compliance
  • Germany
  • HR Software

Why German employers carry more GDPR risk in recruiting

Candidate data is among the most sensitive data any organisation processes. EU GDPR imposes strict rules on lawful basis, retention periods, and automated decision-making — all of which are directly triggered by standard ATS workflows. German employers additionally operate under the Bundesdatenschutzgesetz (BDSG) and, for any AI-assisted hiring step, increasingly under the EU AI Act.

  • Candidate CVs, cover letters, and evaluation notes all constitute personal data under GDPR Art. 4
  • Automated scoring and ranking may trigger GDPR Art. 22 (solely automated decisions)
  • Works councils (Betriebsrat) have codetermination rights over technical systems used in hiring
  • BDSG §26 governs processing of employee and applicant data specifically — stricter than the general GDPR framework
  • Data retention beyond what is necessary for the application process requires a separate lawful basis

The 12-point ATS GDPR checklist

Use this as your minimum viable checklist before entering serious ATS evaluation. Each item should have written documentation from the vendor.

  • 1. AVV (Auftragsverarbeitungsvertrag): Is a signed data processing agreement available? Who initiates it?
  • 2. Data residency: Where is candidate data stored? EU-only? Germany specifically? What about backups?
  • 3. Sub-processor list: Which sub-processors handle candidate data? Are their own DPAs available?
  • 4. Lawful basis configuration: Can you configure and document the lawful basis for each processing activity per role?
  • 5. Retention periods: Can you set automated deletion timelines per role or candidate status?
  • 6. Consent management: If consent is the lawful basis, how is it collected, recorded, and revoked?
  • 7. Data subject requests: How does the platform handle DSAR (access, correction, deletion) requests?
  • 8. Automated decision-making: Does any AI feature make or significantly influence hiring decisions? How is Art. 22 compliance documented?
  • 9. Data minimisation: Can early screening be configured to limit data displayed to interviewers (e.g., blind CV mode)?
  • 10. Access controls: Role-based permissions to limit who sees candidate data — especially sensitive categories
  • 11. Audit log: Is there a tamper-evident audit trail of who accessed and changed candidate data?
  • 12. Breach notification: What is the vendor's GDPR Art. 33 breach notification procedure and timeline?

The AVV: what to look for beyond the signature

Most ATS vendors provide a template AVV. Not all of them hold up under German legal review. Here is what experienced DPOs check beyond the first page.

  • Sub-processor clause: the AVV must list or link to all sub-processors with their own DPA documentation
  • Deletion timeline: after contract termination, how long does the vendor retain data and what exactly is deleted?
  • Audit rights: can your organisation or a third party audit the vendor's GDPR practices?
  • International transfers: if data leaves the EEA, what safeguards apply — SCCs, adequacy decisions, binding corporate rules?
  • Incident notification: 72-hour notification under GDPR Art. 33 must be explicitly committed to in the AVV
  • Instruction scope: is the vendor required to process only according to your instructions, or does the AVV contain carve-outs?

AI features and GDPR Article 22

AI-assisted recruiting tools — particularly those that score, rank, or filter candidates automatically — must be evaluated against GDPR Art. 22. This article restricts decisions 'based solely on automated processing' that significantly affect individuals. A hiring rejection counts.

  • Art. 22 compliance requires either explicit candidate consent, contractual necessity, or Member State law as the legal basis
  • Even if AI only 'supports' a decision, if the human rubber-stamps rather than genuinely reviews, it may be treated as automated
  • The vendor must be able to provide an explainability document: what features does the AI use, how are scores calculated?
  • Candidates must be informed of AI use in a privacy notice or job posting disclosure
  • Your Works Council may require a Betriebsvereinbarung (workplace agreement) covering algorithmic systems

Retention configuration: the most commonly missed requirement

German DPOs consistently flag retention as the highest-risk ATS gap. Most vendors offer retention settings — but whether those settings are correct for BDSG §26 context requires active configuration, not default installation.

  • Default retention periods in US-built ATS tools are often set to years, not the 6 months that German practice recommends for rejected candidates
  • Retention timelines must be documented in your Record of Processing Activities (RoPA) with the lawful basis for each period
  • Active applicants have different retention requirements than rejected candidates
  • Talent pools and passive candidate databases require explicit consent and separate retention rules
  • Automated deletion reminders or enforcement (not just a flag) are required for credible compliance

Questions to ask your Works Council before ATS rollout

In German companies with more than 5 employees, the Betriebsrat has codetermination rights under BetrVG §87(1) No. 6 over technical systems that monitor employee behaviour — which can include recruiter activity monitoring and AI-assisted tools. Involving the Works Council early avoids procurement blockers later.

  • Which technical capabilities of the ATS are subject to §87(1) No. 6 codetermination?
  • Does the AI scoring system assess employees as well as external candidates (e.g., for internal mobility)?
  • What data about recruiter activity does the system log and who can access it?
  • A Betriebsvereinbarung covering the ATS scope, purpose, and limits is strongly advisable

Red flags in ATS vendor GDPR claims

Some marketing language around GDPR compliance is accurate; some is not. Here are the claims that warrant follow-up questions.

  • 'GDPR-compliant' without a publicly available sub-processor list: ask for it explicitly
  • 'Data stored in the EU' without specifying region: Ireland and Germany have different risk profiles for some enterprise buyers
  • 'We handle GDPR for you': no vendor can take on the data controller obligations that sit with your organisation
  • 'ISO 27001 certified': information security certification is not the same as GDPR compliance — the overlap is partial
  • No German-language AVV or legal support: in disputes, a German court will apply German law to the contract

How Virkla is built for this environment

Virkla was designed specifically for European hiring teams operating under GDPR. The platform builds compliance infrastructure into the default workflow rather than offering it as a configuration option that requires expertise to activate correctly.

  • Signed AVV available for all customers from day one — not gated behind enterprise plans
  • Configurable retention periods per role and candidate status with automated enforcement
  • Blind CV mode available per role to support data minimisation at early screening stages
  • AI Score Matching produces an explainable shortlist, not an autonomous decision — GDPR Art. 22 compliant by design
  • Role-based access controls limit candidate data visibility to the team members who need it
  • Audit log records every action on a candidate record for Works Council and DPO review
See Virkla GDPR features

Frequently asked questions

Is a signed AVV mandatory for any ATS used in Germany?

Yes. Under GDPR Art. 28, any controller using a processor to handle personal data must have a signed data processing agreement. An ATS that processes candidate data on your behalf is a processor. The AVV must be in place before data processing begins.

What is the recommended retention period for rejected candidate data in Germany?

German practice under BDSG §26 generally supports a retention period of up to 6 months after rejection, to cover potential AGG (General Equal Treatment Act) claims. Some DPOs advise reducing this to 3 months for most roles. Document your retention decision and the lawful basis for it in your RoPA.

Do AI scoring tools always trigger GDPR Article 22?

Not automatically. Art. 22 applies to decisions 'based solely on automated processing that produces legal effects or similarly significantly affects' a person. If a human recruiter genuinely reviews AI scores and applies independent judgment before a rejection or advance, the process is not solely automated. The key word is 'genuinely' — rubber-stamping an AI output does not qualify.

Can Virkla provide documentation for our Works Council review?

Yes. Virkla provides documentation covering AI feature scope, data flows, access controls, and audit log capabilities — the information typically required for a Betriebsvereinbarung or §87(1) No. 6 review. Contact us via the support or sales channel for documentation packages.

Cookies and analytics consent

We use Google Analytics to understand usage and improve the product. You can accept or reject analytics tracking.