Compliance · July 18, 2026 · 6 min read
GDPR for hiring: candidate data, consent and the right to erasure
Hiring collects sensitive personal data. What GDPR requires around lawful basis, consent and data minimisation — and how to honour deletion without destroying your audit trail.
← Part of Hiring AI is high-risk AI: building for NYC LL144 and the EU AI Act from day one
A deep dive from our guide to compliance-first hiring AI: data protection.
The obligations that bite in hiring
- A lawful basis for processing, and clear notice to candidates
- Data minimisation — collect what the decision needs, not more
- Separate, explicit consent for higher-intrusion steps like proctoring
- Candidate rights: access, correction and erasure, handled on request
Two clauses that bite hardest
Article 22 gives candidates the right not to be subject to a decision based solely on automated processing where it produces legal or similarly significant effects — which is precisely why a human-in-the-loop review is not optional for consequential hiring decisions. And where you deploy intrusive measures such as proctoring, a Data Protection Impact Assessment (DPIA) is the expected step, not a nice-to-have — it forces you to justify the intrusion and document safeguards before you collect a single frame.
Erasure without amnesia
GDPR Article 17 gives candidates a right to erasure. The trick is honouring it without deleting the record that a hiring decision was made fairly. The answer is to remove personal content while keeping anonymised integrity hashes — the deletion is real, the audit trail survives, and the two obligations stop being in tension.
Design consent as two separate switches — data processing and proctoring — from day one. Bundling them is both bad UX and a weak lawful basis.
Written by
Jakir Patel · Founder, Hanzomon
Building H-Evaluate — AI-native, quality-gated hiring assessments. Writes about assessment engineering, hiring integrity and compliance-first AI.