GDPR Checklist for Applicant Tracking Software

Twelve criteria worth checking before signing any ATS contract. Ask for written documentation on every point — a verbal assurance won't hold up under a supervisory-authority review.

Last updated: 21 September 2026

Get the checklist as a PDF by email

The full checklist is also right below on this page — no email required to read it.

The 12-point checklist

Use this as the minimum bar before serious evaluation begins.

  • 1. DPA: Is a Data Processing Agreement available? Who initiates it?
  • 2. Data residency: Where does candidate data live? EU-only? Germany specifically? And backups?
  • 3. Sub-processors: Who else touches the data? Are their own DPAs in place?
  • 4. Legal basis: Can the legal basis be documented per processing activity and role?
  • 5. Retention: Can automatic deletion deadlines be set per role or status?
  • 6. Consent: If consent is the basis — how is it captured, stored, withdrawn?
  • 7. Data subject requests: How does the platform handle access, correction, deletion?
  • 8. Automated decisions: Does any AI feature make hiring decisions? How is Article 22 addressed?
  • 9. Data minimization: Can early screening be restricted (e.g. blind-CV mode)?
  • 10. Access controls: Roles that limit exposure to sensitive categories
  • 11. Audit log: Tamper-evident record of who viewed and changed data?
  • 12. Breach notification: What's the vendor's Article 33 process (72 hours)?

DPA details that get overlooked

A DPA exists — but is the content actually sufficient? These points are frequently skipped during review.

  • Sub-processors: the DPA must list or link them, including their own DPA paperwork
  • Post-termination retention: how long does the vendor keep data, and what exactly gets deleted?
  • Audit rights: can your organization or a third party review GDPR practice?
  • Third-country transfers: if data leaves the EEA — SCCs, adequacy, BCRs?
  • Incident notification: the 72-hour Article 33 duty must be written into the DPA

Red flags during vendor selection

These phrases in a sales call should trigger follow-up questions.

  • "GDPR compliant" with no public sub-processor list: ask for it explicitly
  • "Data in the EU" with no region named: Ireland and Germany carry different risk profiles for some buyers
  • "We handle GDPR for you": no vendor removes your obligations as the controller
  • "ISO 27001 certified": information security isn't GDPR — the overlap is only partial
  • No German DPA or legal support: in a dispute, a German court applies German law

How Virkla implements this checklist

So you can see what the answers should look like in practice:

  • Signed DPA for every customer from day one — not gated behind enterprise plans
  • Configurable deletion deadlines per role and status, with automatic enforcement
  • Blind-CV mode per role for data minimization in early screening
  • AI Score Matching produces an explainable shortlist, not an autonomous decision — Article 22 by design
  • Role-based access limits who can see candidate data
  • Audit log for Works Councils and DPOs
Back to home

Cookies and analytics consent

We use Google Analytics to understand usage and improve the product. You can accept or reject analytics tracking.