Home ratgeber Wie informiert man Bewerber über Datens...

Wie informiert man Bewerber über Datenschutz im Prozess?

Jetzt teilen!

Bewerber haben ein Recht darauf zu erfahren, was mit ihren persönlichen Daten passiert. Die DSGVO verpflichtet Arbeitgeber, transparent über die Verarbeitung von Bewerbungsdaten zu informieren. Sie müssen angeben, wer die Daten verarbeitet, zu welchem Zweck, auf welcher Rechtsgrundlage und wie lange sie gespeichert werden. Diese Transparenz schafft Vertrauen im Bewerbermanagement Prozess und zeigt professionelles Handeln. Ohne korrekte Information riskieren Sie Bußgelder und Reputationsschäden.

Why Do Applicants Need to Be Informed About Data Protection?

The GDPR requires employers to actively inform applicants about the processing of their personal data. This obligation to provide information takes effect the moment you collect application data — that is, from the very first contact or when an online form is completed.

Applicants entrust you with sensitive information: their CV, references, contact details, and often their salary expectations. They have the right to know what happens to this data. Will it be shared? How long will it be stored? Who has access to it?

The legal basis is found in Article 13 GDPR, which sets out exactly what information you must provide to applicants. The legal basis for the processing itself is typically Article 6(1)(b) GDPR — the performance of pre-contractual measures at the request of the data subject.

Transparent communication about data protection signals professionalism and strengthens your employer brand. Candidates feel respected and secure throughout the application process. This is especially important at a time when skilled professionals can choose their employers.

What Data Protection Information Must You Provide to Applicants?

The GDPR clearly defines what mandatory details must be included in your data protection notices. This information ensures that applicants understand what happens to their data and what rights they have.

Controller: State your company’s full name, address, and contact details. If applicable, also include the contact details of your data protection officer.

Purpose of data processing: Explain specifically why you are using the application data — for example, to assess suitability for the advertised position or for similar vacancies.

Legal basis: Identify the legal basis for the processing. For applications, this is typically Article 6(1)(b) GDPR in conjunction with Section 26 of the German Federal Data Protection Act (BDSG).

Retention period: State how long you will retain the data. Six months after the conclusion of the application process is standard practice, allowing time to address any follow-up queries or legal claims.

Recipients of the data: Inform applicants about who has access to their data — for example, specialist departments, management, or external service providers such as recruitment consultants.

Data subject rights: Draw attention to applicants‘ rights: access, rectification, erasure, restriction of processing, objection, and data portability. Also mention the right to lodge a complaint with the competent data protection authority.

When and Where Should You Place Data Protection Notices in the Application Process?

The right time to provide data protection information is before — or at the latest at the point of — data collection. You must position the notices so that applicants cannot miss them and can access them before submitting their documents.

In job postings: Link to your full data protection notice directly within the job advertisement. A brief note such as „Find information on data protection here“ is sufficient, provided the link is clearly visible.

On the careers page: Include a dedicated section for data protection information, or link prominently to your general privacy policy with a specific section for applicants.

In online application forms: Place the data protection notice directly within the form — ideally as a link immediately before the submit button. Some companies also use a checkbox for applicants to confirm they have read the notice. This is not a legal requirement, but it does draw attention to the information.

For email applications: Include a reference to your data protection information in your acknowledgement of receipt. If you list an email address in the job posting, a link to the data protection notice should already appear there.

What matters most is the combination of visibility and accessibility. The information must be easy to find without complicating the application process.

How Should You Write Clear Data Protection Notices for Applicants?

Data protection notices must be legally sound, but no one benefits from impenetrable legal jargon. Your goal is to genuinely inform applicants — not to confuse them with technical terminology.

Use plain language: Write in short sentences and avoid complex nested clauses. Instead of „Processing is carried out on the basis of Art. 6(1)(b) GDPR,“ write: „We process your data in order to review your application (legal basis: Art. 6(1)(b) GDPR).“

Structure information clearly: Divide the content into logical sections with meaningful subheadings. Use bullet points rather than long paragraphs when explaining multiple items.

Explain technical terms: If you must use legal terminology, add a brief explanation. „Data subject rights“ sounds abstract — „Your rights: what you can do“ is far more accessible.

Be specific: Instead of „Your data will be stored for an appropriate period,“ write: „We will delete your application documents six months after the conclusion of the process.“

Provide contact options: Clearly state who applicants can contact with questions. An email address and phone number build trust.

A modern applicant management system helps you integrate data protection notices into the application process in a legally compliant and user-friendly way.

What Happens If You Fail to Inform Applicants Correctly About Data Protection?

Violations of the GDPR’s information obligations can be costly. Data protection authorities have the power to impose fines of up to €20 million or four percent of global annual turnover — whichever is higher.

In practice, penalties for smaller companies tend to be more moderate, but even five-figure sums can cause real financial pain. The amount depends on the severity of the violation, the number of individuals affected, and the degree of fault.

Complaints to data protection authorities: Applicants can report directly to the competent supervisory authority if they believe their rights have been violated. The authority will then review your processes and may order corrective action. Such proceedings consume time and resources.

Reputational damage: In the age of review platforms and social media, negative experiences spread quickly. Applicants who feel they have been treated unfairly will share that publicly — damaging your employer brand and making it harder to attract top talent.

Legal risks: Applicants may also pursue civil law claims, such as compensation for demonstrable harm caused by data protection breaches.

The good news is that correct data protection communication is not rocket science. With clear processes and straightforward notices, you can meet the requirements with ease. This not only protects you from penalties, but also demonstrates respect for the people who choose to apply to your organisation.

Professional applicant management today means more than simply administering documents. It also encompasses the responsible handling of sensitive data and transparent communication with every candidate who expresses interest in your company.