You can keep a candidate’s CV for as long as you have a genuine, documented reason and no longer, which under the GDPR means the recruitment process plus the window in which a rejected applicant could bring a legal claim, and then deletion, unless the candidate has consented to stay on file. There is no single EU-wide number, because the GDPR sets a principle rather than a period, so the practical answer varies by country: the Netherlands treats four weeks as the norm, the UK and Germany land closer to six months, and everywhere the extension to keep someone for future roles rests on their consent. The one answer that is always wrong is “indefinitely.”

The reason this trips teams up is that the law names a principle, storage limitation, not a deadline, so people either invent a comfortable-sounding period with no basis or, more often, keep everything forever. Both are the wrong instinct. The right one is to tie the retention period to a specific purpose and write it down.

The principle, not a number

The GDPR’s storage-limitation principle in Article 5 says personal data must be kept in a form that identifies people no longer than is necessary for the purpose it was collected for. For a rejected candidate, the purpose, assessing them for this role, ends when the role is filled. What can justify holding the CV a little longer is a second, legitimate purpose: defending against a discrimination or unfair-recruitment claim, which is why national guidance clusters around the length of the relevant claim window.

So the calculation is always the same shape: how long is the process, plus how long could a claim arising from it be brought, equals your defensible retention period, and anything beyond that needs the candidate’s consent. The numbers differ by country only because the claim windows do.

Retention periods by country

Because the claim windows vary, so do the norms. These are the widely-followed positions, not a substitute for checking your own jurisdiction.

CountryCommon retention normWhat it is anchored to
Netherlands4 weeks after the process, 1 year with consentThe Dutch DPA’s published guidance
United KingdomAround 6 to 12 monthsThe Equality Act claim window plus a buffer
GermanyAbout 6 months after rejectionThe AGG written-claim and court-filing windows
EU generalProcess plus claim window, then deleteThe GDPR storage-limitation principle

The Dutch supervisory authority is the most specific: its guidance on applicant personal data treats deletion no later than four weeks after the procedure ends as customary, extending to one year where the candidate consents. In the UK, the ICO’s recruitment and selection guidance says not to keep unsuccessful applicants’ data beyond the statutory period in which a recruitment claim could be brought unless there is a clear business reason, which in practice points employment lawyers toward roughly six to twelve months given the Equality Act’s six-month claim window. Germany’s common six-month figure is anchored to the AGG’s claim-and-filing windows. The through-line is identical everywhere: keep it for the process and the claim window, then delete.

When you can keep a CV longer

There is one clean way to hold a candidate beyond the default period, and it is consent. If someone agrees to stay on file so you can consider them for future roles, that is a separate, lawful purpose with its own basis, and the Dutch one-year figure is the common yardstick for how long is reasonable.

Consent here has to be real: freely given, specific, and as easy to withdraw as to grant. That means an actual choice at the point of rejection, not a pre-ticked box or a line buried in a privacy policy, and a working way to opt out later. Done properly, a consented talent pool is genuinely useful, it is the warm list your next role starts from, and it is also the honest version of “we’ll keep your CV on file,” a phrase that is a data-protection promise, not a pleasantry. The wider set of obligations this sits inside is covered in the rules on GDPR CV screening.

The two-tier retention policy

The workable pattern for most teams is two tiers, because it separates the data you must eventually delete from the data a candidate has asked you to keep.

TierWhat it holdsHow longBasis
DefaultEveryone from a closed roleProcess plus claim window, then deleteLegitimate interest, then erase
Talent poolOnly candidates who opted inAbout a year, then re-consent or deleteConsent

The discipline that makes this real is automation, not intention. A retention rule you mean to apply by hand is one you will eventually forget, and a forgotten rule is worse than none because it documents the standard you then breached. Set deletion as a scheduled job, so a closed role’s default-tier data is erased on time and the talent pool is reviewed before its year is up, and the policy runs itself.

What “delete” actually has to mean

Deletion is where retention policies quietly fail, because a CV is rarely in one place. The applicant’s data may sit in your ATS or spreadsheet, the original email with the attachment, a shared drive, an interviewer’s notes, and a screening tool. A retention rule that clears one of those and leaves the rest is not deletion, it is the appearance of it, and it is exactly what a candidate exercising their right to erasure will expose.

Two practical moves keep this honest. Reduce the number of places a CV lives, because fewer copies is both easier to delete and a smaller liability to begin with, and keep a simple record of where candidate data is held so that “delete this person everywhere” is a task you can actually complete. The leaner your data footprint, the shorter this list, which is one more reason to hold only job-relevant fields from the start.

Where a tool helps

A screening tool helps with retention in a specific, honest way: it concentrates the CVs into one place with a status and a date, which is exactly what makes a retention rule enforceable. Zen Job CV stores candidate data in the EU, keeps every candidate visible with their status, holds an audit trail, and applies your retention rule, so a closed role’s applications can be deleted on schedule and a consented pool tracked to its expiry. That is the difference between a policy on paper and one that runs.

The honest boundary is that a tool only governs the data inside it. If copies of a CV also live in an inbox, a shared drive, and an interviewer’s laptop, the tool cannot reach those, which is why the real fix is fewer copies plus a clear record of where data lives, not a single product. A tool makes its own tier enforceable; it does not absolve the rest of your process.

A worked example

A Netherlands-based company closes a marketing role with 160 applicants and hires one. Under the Dutch norm, the other 159 should be deleted no later than four weeks after the process ends, unless they consented to stay on file. In the rejection message, 30 of them tick a genuine, withdrawable box agreeing to be kept for future roles. So the retention splits cleanly: 129 candidates are deleted at four weeks, and 30 sit in a talent-pool tier for up to a year, after which they are re-consented or removed.

The failure mode this avoids is the common one. Without the split, all 160 CVs would have drifted in an inbox and a shared drive indefinitely, because nobody set a stop date, and eighteen months later one of the 159 sends an erasure request and the company cannot even find every copy. With the two tiers and a scheduled deletion job, the four-week erasure runs on its own, the talent pool has a visible expiry, and an erasure request is a task that can actually be completed. The same company operating in Germany would set the default nearer six months to cover the AGG claim window instead of four weeks, but the structure, a dated default tier plus a consented pool, would be identical.

The lesson is that the country changes the number, not the method. Decide the default from your own jurisdiction’s claim window, offer a real consented extension, automate both deletions, and the policy holds regardless of where you hire.

How long to keep candidate CVs, and what to do

Set your default retention to the length of the recruitment process plus the window in which a rejected candidate could bring a claim, which is four weeks in the Netherlands and closer to six months in the UK and Germany, then delete, and check your own jurisdiction rather than borrowing another country’s number. Keep anyone longer only on genuine, withdrawable consent, on a roughly one-year talent-pool tier. Automate the deletion so it actually happens, reduce the number of places a CV lives so deletion is achievable, and keep a record of where candidate data sits so an erasure request is a task you can complete. The only universally wrong answer is keeping CVs forever because nobody decided when to stop.

Quick answers

How long can you keep a candidate’s CV under GDPR? As long as you have a genuine, documented purpose and no longer: in practice the recruitment process plus the window in which a rejected applicant could bring a claim, then deletion. There is no single EU number, so the norm varies, four weeks in the Netherlands, closer to six months in the UK and Germany, with the extension to keep someone for future roles resting on their consent.

Is there a legal maximum retention period for CVs? Not a fixed EU-wide one. The GDPR sets a principle, storage limitation, rather than a deadline, so the period is tied to purpose and to national claim windows. The Netherlands treats four weeks as customary and up to a year with consent; the UK and Germany land around six months, anchored to their discrimination-claim windows. Always check your own jurisdiction rather than assuming a universal number.

Can I keep a rejected candidate’s CV for future roles? Yes, but only with their consent and a time limit. Keeping someone on file for future openings is a separate purpose from assessing them for the current role, so it needs a real, freely given, withdrawable consent, not a pre-ticked box. The Dutch one-year figure is the common yardstick for how long that is reasonable, and it should be offered as a genuine choice at the point of rejection.

What is the risk of keeping candidate data too long? You breach the storage-limitation principle, and you carry a growing liability of personal data that serves no purpose, which is exactly what a data-protection complaint or an erasure request will surface. An unbounded archive of old applications is a risk with no upside: it cannot lawfully be used, it must be handed over or deleted on request, and holding it only increases the exposure if the data is ever breached.

How do I actually delete a candidate’s CV? Everywhere it lives, not just in one system. A CV often sits in an ATS or spreadsheet, the original email, a shared drive, interviewer notes, and a screening tool, so deletion means clearing all of them. The practical approach is to reduce the number of copies from the start and keep a record of where candidate data is held, so that deleting one person everywhere is a task you can complete rather than a guess.