GDPR Checklist for Applicant Tracking Software
Twelve criteria worth checking before signing any ATS contract. Ask for written documentation on every point — a verbal assurance won't hold up under a supervisory-authority review.
Last updated: 21 September 2026
The 12-point checklist
Use this as the minimum bar before serious evaluation begins.
- 1. DPA: Is a Data Processing Agreement available? Who initiates it?
- 2. Data residency: Where does candidate data live? EU-only? Germany specifically? And backups?
- 3. Sub-processors: Who else touches the data? Are their own DPAs in place?
- 4. Legal basis: Can the legal basis be documented per processing activity and role?
- 5. Retention: Can automatic deletion deadlines be set per role or status?
- 6. Consent: If consent is the basis — how is it captured, stored, withdrawn?
- 7. Data subject requests: How does the platform handle access, correction, deletion?
- 8. Automated decisions: Does any AI feature make hiring decisions? How is Article 22 addressed?
- 9. Data minimization: Can early screening be restricted (e.g. blind-CV mode)?
- 10. Access controls: Roles that limit exposure to sensitive categories
- 11. Audit log: Tamper-evident record of who viewed and changed data?
- 12. Breach notification: What's the vendor's Article 33 process (72 hours)?
DPA details that get overlooked
A DPA exists — but is the content actually sufficient? These points are frequently skipped during review.
- Sub-processors: the DPA must list or link them, including their own DPA paperwork
- Post-termination retention: how long does the vendor keep data, and what exactly gets deleted?
- Audit rights: can your organization or a third party review GDPR practice?
- Third-country transfers: if data leaves the EEA — SCCs, adequacy, BCRs?
- Incident notification: the 72-hour Article 33 duty must be written into the DPA
Red flags during vendor selection
These phrases in a sales call should trigger follow-up questions.
- "GDPR compliant" with no public sub-processor list: ask for it explicitly
- "Data in the EU" with no region named: Ireland and Germany carry different risk profiles for some buyers
- "We handle GDPR for you": no vendor removes your obligations as the controller
- "ISO 27001 certified": information security isn't GDPR — the overlap is only partial
- No German DPA or legal support: in a dispute, a German court applies German law
How Virkla implements this checklist
So you can see what the answers should look like in practice:
- Signed DPA for every customer from day one — not gated behind enterprise plans
- Configurable deletion deadlines per role and status, with automatic enforcement
- Blind-CV mode per role for data minimization in early screening
- AI Score Matching produces an explainable shortlist, not an autonomous decision — Article 22 by design
- Role-based access limits who can see candidate data
- Audit log for Works Councils and DPOs
