Home ratgeber Welche Einwilligungen braucht man im Bew...

Welche Einwilligungen braucht man im Bewerbermanagement?

Jetzt teilen!

In the applicant management process, you need to obtain various consents from candidates depending on the intended use of their data. For the conduct of the application process itself, no separate consent is required, as this is covered by the initiation of a contract. However, explicit consent is required if you wish to store applicant data for longer periods, include it in talent pools, or use it for other purposes. The GDPR clearly regulates these requirements and protects the rights of applicants.

What legal bases apply to applicant data?

The processing of applicant data is based on Art. 6(1)(b) GDPR for the initiation of a contract and on Art. 88 GDPR in conjunction with § 26 BDSG for employment-related data. These legal bases allow you to process all information relevant to the decision on hiring.

Applicant data constitutes personal data and requires special protection. You may only use this data for the purpose for which it was collected. In practical terms, this means: everything directly related to filling the position is permitted.

Striking the right balance between your operational requirements and the data protection rights of applicants is essential. You must only collect data that you genuinely need to assess the application. Questions about marital status, pregnancy, or political views are not permitted, as they are not relevant to the candidate’s suitability.

The General Equal Treatment Act (AGG) supplements these requirements. It protects applicants from discrimination and obliges you to retain all documents for a specified period, so that you can demonstrate, in the event of an AGG claim, that your selection decision was based on objective criteria.

When do you need consent from applicants?

Explicit consent is always required when you wish to use applicant data beyond the original application process. This applies to storage for future positions, inclusion in talent pools, disclosure to third parties, or use for purposes other than filling the current vacancy.

For the conduct of the application process itself, no consent is required. The legal basis of contract initiation covers all steps directly related to filling the position. This includes reviewing documents, conducting interviews, checking references, and making the hiring decision.

Once the application process is complete, the situation changes. If you wish to retain rejected applicants in your system in order to contact them later for other positions, you must obtain their consent beforehand. This consent must be given voluntarily and must not be made a condition of participation in the application process.

Sharing applicant data with external service providers such as recruitment consultants or assessment centres also requires consent if they are not acting as data processors. Important: applicants may withdraw their consent at any time without suffering any disadvantage as a result.

How do you draft a legally compliant consent declaration?

A GDPR-compliant consent declaration must be written in plain language and provide transparent information about all processing purposes. Avoid legal jargon and explain clearly what you will do with the data and why. Applicants must be able to understand at a glance what they are consenting to.

Your consent declaration should include the following elements: the precise purpose of data processing, the retention period, a clear reference to the right of withdrawal, and information that refusing consent will have no negative consequences. For example, you might state: „We would like to retain your application documents for 12 months so that we can contact you regarding suitable positions.“

A common mistake is the use of pre-ticked checkboxes. Consent must be given by means of a clear, active action. Applicants must consciously tick an empty box or provide a signature. Bundling multiple purposes into a single consent declaration is also problematic. Separate different purposes so that applicants can consent to each one individually.

Document all consents obtained with care. You must be able to demonstrate who consented, when, and to what. Store the exact wording of the consent declaration, the date, and the manner in which consent was given. This documentation protects you in the event of queries or complaints.

What do you need to consider when storing applicant data?

The retention period for application documents is governed by the AGG and amounts to at least the end of the application process plus the limitation period for claims of two months. This retention obligation applies to all applicants so that you can justify your selection decision in the event of a potential discrimination claim.

Without the applicant’s consent, you must delete the documents once this period has expired. The maximum retention period without consent is therefore approximately three to four months after the conclusion of the process. After this point, retaining the data constitutes a breach of the GDPR.

For applicants who are hired, the application documents become part of the personnel file. Different retention periods apply here, arising from employment law and tax law requirements. These documents may be retained for considerably longer, as they serve to document the employment relationship.

Secure deletion after the expiry of retention periods is essential. Delete data not only from your active system but also from backups and email inboxes. Paper documents must be disposed of in a data-protection-compliant manner. Technical and organisational measures such as access controls, encryption, and regular deletion schedules protect data during the retention period. A modern applicant management system helps you implement these processes in an automated and legally compliant way.

How do you inform applicants about their data protection rights?

You are obliged to provide applicants with a privacy notice before or at the latest at the point of data collection. This information must contain all relevant details about the processing of their personal data and must be easily accessible.

Your privacy notice for applicants must include the following information: the controller responsible for data processing along with contact details, the purpose of processing, the legal basis, potential recipients of the data, the retention period, and all data subject rights. You should also explain whether providing the data is mandatory and what the consequences of refusal would be.

Data subject rights include the right to access, rectification, erasure, restriction of processing, data portability, and objection. Applicants may request information at any time about which data you have stored about them. You must also inform them of their right to lodge a complaint with a data protection authority.

Integrate the privacy information directly into your application forms or link to it prominently on your careers page. Applicants must be able to review the information before submitting their application. A separate checkbox to confirm acknowledgement is advisable, though not strictly required by law.

The practical implementation of these requirements is made considerably easier by digital solutions. Modern systems automatically provide the correct information, document consents, and enforce deletion deadlines. This allows you to fulfil your obligations in the applicant management process efficiently and in full compliance with the law.