The GDPR does not ban CV screening, and it does not ban screening software. What it does is constrain four specific things: the basis you rely on to process applicant data, how much of it you collect, how long you keep it, and how much of the decision a machine is allowed to make on its own. Get those four right and a high-volume screening process is entirely lawful. Get them wrong and the exposure is real, because a rejected candidate has the right to ask what happened to their data and why, and the answer has to exist.
There is also a deadline attached now. From 2 August 2026, software used to filter job applications sits inside the EU AI Act’s high-risk category, which brings its own obligations on top of the GDPR. That date arrives whether or not a hiring team has looked at it.
Is CV screening allowed under the GDPR at all?
Yes. A CV is personal data, and reading it is processing, so the regulation applies from the moment an application lands in your inbox. Applying is not the problem. Processing without a lawful basis is.
Article 6 lists the six bases available, and two of them are realistic for recruitment. The first is Article 6(1)(b), processing necessary for steps taken at the request of the candidate before entering a contract. Someone applied for a job; assessing the application is exactly the step they requested. The second is Article 6(1)(f), legitimate interests, which covers the surrounding activity that the candidate did not specifically request: keeping a record of why a decision was made, checking for duplicate applications, retaining a strong candidate for a future role.
The basis most teams reach for first, consent, is usually the wrong one. Consent under the GDPR has to be freely given, and the power imbalance between an applicant and a prospective employer makes that difficult to argue for the core screening activity. It also has to be as easy to withdraw as to give, which means a candidate could withdraw consent mid-process and leave you without a basis to finish assessing them. Consent has a genuine role at the edges, and retention beyond the normal period is the clearest example, but it is a poor foundation for the screening itself.
Put plainly, the three bases divide up like this:
| Lawful basis | Use it for | The catch |
|---|---|---|
| Article 6(1)(b), pre-contract steps | Assessing the application the candidate submitted | Covers the assessment itself, little around it |
| Article 6(1)(f), legitimate interests | Record-keeping, duplicate checks, retaining a strong candidate | Needs a balancing test you can show |
| Consent | Keeping data beyond the normal period | Must be freely given and easy to withdraw; weak for core screening |
What does Article 22 actually require?
This is the article that decides whether your screening setup is a routine data-processing question or a much bigger one.
Article 22 gives a person the right not to be subject to a decision based solely on automated processing which produces legal effects concerning them or similarly significantly affects them. Being screened out of a job qualifies as a significant effect. The pivotal word is “solely”.
A system that ranks candidates and hands the ranking to a recruiter who reads the shortlist, reviews the near-misses, and decides who to interview is not making a solely automated decision. A system that auto-rejects everyone below a threshold, sends the rejection email, and never surfaces those people to a human is. The difference is not the sophistication of the software. It is whether a human being with the authority and the information to disagree actually looks.
Three practical consequences follow:
- Keep a human in the loop, and make the loop real. A reviewer who rubber-stamps a list without ever seeing the people it excluded is not meaningful human involvement. They need the rejected pile in front of them, with reasons.
- Never configure a silent auto-reject. This is the single most common way a compliant tool becomes a non-compliant process. It is also why soft filters that flag near-misses rather than deleting them matter for more than kindness; the same design that stops you losing good candidates is what keeps the decision non-automated.
- Be able to explain any individual outcome. If a candidate asks why they were not shortlisted, “the system scored them low” is not an answer. Which criteria did they meet, which did they miss, and by how much?
That last point is why explainable ranking and lawful screening turn out to be the same engineering problem. A score with no reasons attached cannot be defended to a candidate, to a hiring manager, or to a regulator. It is also the reason readable filter logic beats a clever query string: a rule a candidate could have explained to them is a rule you can stand behind.
How much candidate data should you actually collect?
Less than you are collecting now, almost certainly.
Article 5 sets out the principles, and data minimisation is the one recruitment teams break most often. Personal data must be adequate, relevant and limited to what is necessary for the purpose. Date of birth, a photograph, marital status, nationality and a full home address are all routinely collected in application forms, and almost none of them are necessary to assess whether someone can do the job.
There is a happy overlap here with fairness. The fields that fail the necessity test are largely the same fields that carry bias signals, which is the mechanism behind blind screening in the first pass. Removing a photograph from the first review is simultaneously a data-minimisation improvement and a bias-reduction one. Two obligations, one change.
Special category data deserves separate attention. Health information, trade union membership, religion and ethnic origin fall under Article 9 and require a specific condition beyond an ordinary lawful basis. Candidates volunteer this material constantly, in a CV that mentions a disability, a cover letter that explains a career gap, or a photograph. You cannot stop them sending it. You can decide not to build it into a filter, not to index it, and not to surface it during the first pass.
How long can you keep a CV after the role is filled?
The GDPR gives no number. It gives a principle, storage limitation, which says personal data is kept in a form permitting identification no longer than necessary for the purpose. That leaves the specific period to national guidance and to your own documented reasoning.
The Dutch supervisory authority publishes the most commonly cited figure in Europe. Its guidance on applicant personal data is that where a candidate does not get the position, their data is customarily deleted no later than four weeks after the procedure ends, and that keeping it for up to one year is reasonable where the candidate has consented, typically so they can be considered for a future opening.
Two things are worth noticing about that. First, four weeks is a norm rather than a statutory ceiling, and a documented, justified deviation is defensible; what is not defensible is an unexamined default of forever. Second, the one-year extension is precisely the place where consent is the right lawful basis, because it is genuinely optional and the candidate loses nothing by refusing.
In practice the workable pattern is a two-tier retention policy. Everything from a closed procedure is deleted at four weeks by default. A separate, consented talent pool holds the candidates who agreed to it, for one year, with an easy exit. Set the deletion as an automatic job rather than a calendar reminder, because a retention policy nobody executes is worse than none: it documents the rule you then broke.
What changes on 2 August 2026?
The EU AI Act adds a second regime on top of the GDPR, and recruitment is named in it explicitly.
Annex III, point 4(a) classifies as high-risk any AI system “intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates”. Filtering applications is not an edge case here. It is the worked example the legislators chose.
On timing, Article 113 sets general application from 2 August 2026, with the later 2 August 2027 date applying to Article 6(1), the separate route covering AI that is a safety component of a regulated product. Recruitment systems are classified under Article 6(2) via Annex III, so the 2026 date is the one that matters for hiring.
Most of the obligations land on the provider of the system rather than the employer using it: risk management, data governance, technical documentation, logging, accuracy and human oversight by design. But deployers are not passive. An employer using a high-risk system is expected to use it according to its instructions, to assign human oversight to people with the competence and authority to exercise it, to keep the logs it generates, and to inform workers and their representatives before putting it into use.
The practical move for a hiring team is a procurement question rather than an engineering one. Before your next screening tool goes live, ask the vendor which side of the high-risk line they believe they sit on, what documentation they will provide, and what they expect of you as deployer. A vendor who has not thought about it by mid-2026 has told you something useful.
What you have to tell candidates, and when
Article 13 requires that when you collect data directly from a person, you tell them at the time of collection: who the controller is, the purposes and lawful basis, the recipients, the retention period, their rights, and, where automated decision-making under Article 22 is in play, meaningful information about the logic involved and the consequences.
That last clause is the one that catches recruitment teams. “Meaningful information about the logic involved” does not require publishing an algorithm. It requires being able to say, in plain language, what the system evaluates and how that feeds the decision. If your privacy notice cannot describe your screening criteria in a sentence a candidate would understand, the criteria are probably too opaque to defend.
Two rights then need an operational answer rather than a policy paragraph. Under Article 15 a candidate can ask for a copy of their data and the information above, and under Article 17 they can ask for erasure. Both arrive by email, usually to a recruiter, and the clock is one month. Decide now who owns that inbox and how they find every copy of one applicant’s file, because the answer is rarely “one system”. Rejected candidates are the group most likely to ask, which is one reason how you word and time a rejection is a data-protection question as well as a courtesy one.
A checklist you can run this week
| Area | The question to answer | What good looks like |
|---|---|---|
| Lawful basis | What are we relying on, and is it written down? | Article 6(1)(b) for assessment, 6(1)(f) for records, consent only for extended retention |
| Minimisation | Which fields do we collect that we never use? | Date of birth, photo and full address removed from the application form |
| Article 22 | Can any candidate be rejected without a human seeing them? | No auto-reject; near-misses surfaced with reasons |
| Retention | When is a closed procedure actually deleted? | Automatic deletion at four weeks, consented pool at one year |
| Transparency | Could a candidate understand our criteria from the notice? | Screening logic described in plain language |
| Rights | Who handles an access or erasure request? | A named owner and a one-month process |
| AI Act | Is our screening tool in Annex III scope, and does the vendor agree? | A written answer from the vendor before August 2026 |
None of these require a lawyer to start. They require someone to write down what is currently happening, which is usually the step that reveals the problem.
Where to start if you screen CVs today
Start with retention and auto-reject, in that order. They are the two failures that are simultaneously the most common, the easiest to fix, and the most damaging if a complaint arrives. An unbounded archive of old applications is a growing liability that serves no purpose, and a silent auto-reject converts an ordinary screening process into an automated decision you did not intend to make.
Two questions deserve their own treatment: exactly how long you can keep candidate CVs under each country’s rules, and whether AI CV screening is legal in the EU once the AI Act applies. Everything after that is documentation: writing down the basis you already rely on, describing the criteria you already apply, and naming the person who already answers candidate emails. Compliance in recruitment is rarely about buying something. It is about being able to describe, accurately, what you already do, which is a good argument for running screening as a deliberate workflow rather than an improvised one.
Zen Job CV is built around that constraint rather than against it: plain-language criteria a candidate could have explained to them, a reason attached to every ranking, near-misses surfaced for review instead of dropped, and an audit trail that answers “why was this person set aside?” without a forensic exercise. It assists a hiring decision; it does not make one, and it should not.
Quick answers
Is CV screening legal under the GDPR? Yes. A CV is personal data and screening is processing, so you need a lawful basis, but the regulation does not prohibit it. Most recruitment relies on Article 6(1)(b), processing necessary for steps taken at the candidate’s request before a contract, with legitimate interests covering record-keeping around it.
Can software reject a candidate automatically? Not safely. Article 22 gives people the right not to be subject to decisions based solely on automated processing that significantly affect them, and rejection from a role qualifies. Keep a human who sees the rejected pile with reasons attached and has the authority to disagree.
How long can we keep candidate CVs? The GDPR sets no fixed period, only that you keep data no longer than necessary. The Dutch supervisory authority’s widely used guidance is deletion no later than four weeks after the procedure ends, extending to one year where the candidate has consented to being kept on file.
Does the EU AI Act apply to CV screening? Yes. Annex III point 4(a) names systems used to analyse and filter job applications as high-risk, and those obligations apply from 2 August 2026. Most duties fall on the provider, but employers must follow the instructions for use, assign competent human oversight, and keep logs.
When is Zen Job CV the wrong choice? When you need a full applicant tracking system rather than a screening step, when your hiring volume is low enough that a careful manual read is genuinely feasible, or when your organisation requires a specific certification we do not yet hold. It is a first-pass tool, and it assumes a human makes the final call.