GDPR-compliant ATS: What to look for when evaluating applicant tracking systems

Learn what to look for in a GDPR-compliant ATS, from candidate data controls and retention to security, vendor governance, and responsible AI.

Alice Dodd
Content Manager
Article
5 mins
Last updated
September 22, 2026
This is the default text value

Recruitment teams handle a huge amount of personal candidate data.

Your applicant tracking system will likely contain resumés, contact details, interview notes, assessment results, salary information, right-to-work documentation, and other information collected throughout the hiring process.

It goes without saying, then, that data protection a hugely important part of any ATS evaluation. Alongside recruiting functionality, usability, integrations, and reporting, buyers need to understand how a platform supports the way candidate data is collected, accessed, retained, transferred, and deleted.

A GDPR-compliant ATS should give your organization practical controls that support its data protection responsibilities. No applicant tracking system can make an organization GDPR compliant on its own, your organization remains responsible for deciding why it processes candidate data, which data is necessary, how long to keep it, and who should have access.

This guide covers what recruiting, procurement, security, and compliance teams should evaluate when choosing an ATS. It’s intended as a practical buying guide, not legal advice.

What does GDPR compliance mean for an ATS?

GDPR is the European Union’s data protection framework. It applies to organizations within its scope, including some organizations outside the EU that process the personal data of people in the EU. The UK has its own UK GDPR framework, while the US and other countries have separate privacy and data protection laws that can also affect how candidate information is handled.

For recruiting teams, GDPR affects how candidate data is collected, used, accessed, retained, and deleted. It also gives candidates rights over their personal data and requires organizations to take appropriate steps to protect it.

An ATS should provide controls that help you manage these responsibilities consistently, from retention and deletion to permissions and candidate data requests. Your organization still decides why candidate data is processed, how long it’s kept, and who can access it.

For more on the regulation itself, see the European Commission’s GDPR guidance. You can also explore the practical controls that can support GDPR compliance in recruitment.

What to look for in a GDPR-compliant ATS

Evaluating ATS GDPR compliance means looking beyond a vendor’s statement that its platform is GDPR compliant. You need to understand how the product works in practice and whether the vendor can provide the documentation and evidence your organization needs.

Candidate privacy notices and consent controls

Candidates should receive clear information about how their personal data will be processed. Look for an ATS that lets your team configure privacy information within your careers site and application process, then update it as your requirements change.

Where your organization relies on consent for a particular processing activity, the system should support the appropriate consent process and maintain the necessary records. That doesn’t mean every recruiting activity should be based on consent. The appropriate legal basis depends on the processing involved and your circumstances.

What matters when evaluating the ATS is flexibility. You might need different approaches for applications, talent pools, job alerts, or nonessential cookies. Look for application forms you can configure around the information and consent requirements of different hiring processes.

Configurable data retention and deletion

Candidate data shouldn’t remain in an ATS indefinitely simply because nobody has deleted it.

Your organization should establish appropriate retention periods based on why candidate data is being processed and any other applicable requirements. The ATS should make those policies practical to implement without relying on recurring manual cleanup.

Check whether retention periods can be configured and applied automatically, whether policies can vary between regions, and what happens when a retention period expires.

This becomes especially important for international hiring, where your organization may need to apply different data-handling requirements across the regions where it recruits.

Support for candidate data rights

Candidate data requests can quickly become difficult to manage if your ATS doesn’t provide suitable tools for handling them.

During an evaluation, ask the vendor to demonstrate how an authorized user would find the information held about a candidate, correct it, export it, or delete it. Find out which actions your team can complete directly and which require help from the vendor.

Candidate self-service can make this easier too. Giving candidates appropriate ways to manage their own information can reduce administration while supporting a more transparent candidate experience.

Product functionality is only part of the picture. The vendor’s Data Processing Addendum should also explain how it will assist with relevant data subject requests.

Role-based access and controls for sensitive information

Not everyone involved in recruitment needs access to every piece of candidate information.

A hiring manager may need to see candidates for their own roles without needing access to every requisition in the organization. Some information may need tighter restrictions because of its sensitivity or because it shouldn’t form part of the hiring decision.

Look closely at the ATS permission model. Can access be restricted by role, requisition, team, location, or type of information? How are administrative permissions managed when somebody changes role or leaves the organization? Can you see who performed important actions and when?

These are areas to test in the product itself rather than relying on a feature list. Reviewing the vendor’s documented security, access, and privacy controls can help you verify what sits behind the functionality you see in a demo.

Data residency, international transfers, and sub-processors

Knowing where candidate data goes is an important part of assessing GDPR-compliant recruitment software.

Start by asking where the vendor stores customer data and whether you have a choice over data location. Then look beyond the ATS provider itself.

ATS vendors typically use other service providers to deliver parts of their service. These sub-processors may provide infrastructure or other functionality that involves processing customer data.

Ask for a current sub-processor list and check what each provider does, where relevant processing takes place, and how you’ll be notified about changes.

Data residency is only one part of the assessment. GDPR doesn’t require all personal data to remain inside the EU or EEA. International transfers can take place when the applicable GDPR requirements and safeguards are met, so you also need to understand how the vendor manages transfers when data is processed elsewhere.

A clear Data Processing Addendum

The Data Processing Addendum, or DPA, should be part of your ATS evaluation rather than paperwork left until the end of procurement.

Review how it defines the responsibilities of the controller and processor, along with the vendor’s commitments around processing instructions, confidentiality, security, sub-processors, international transfers, data subject requests, breaches, and what happens to customer data when the relationship ends.

Your legal or privacy team may have additional requirements based on where your organization operates. Having the DPA available to review early in the buying process makes it easier to identify questions before you reach the contract stage.

Security controls and evidence

Protecting personal data is a core part of GDPR, so security needs to be part of the same evaluation.

Ask vendors for evidence that supports their security claims. Depending on your requirements, that might include independent security certifications and assurance reports, encryption practices, authentication controls such as SSO and MFA, penetration testing, incident management processes, access controls, audit logs, and business continuity arrangements.

You’re looking for evidence your security and procurement teams can review, not simply a collection of security claims. A well-documented Security & Privacy center can make it easier to find certifications, security practices, and privacy controls without waiting for them to surface later in procurement.

Privacy controls that work across your hiring operation

Organizations rarely have a single hiring process.

You may recruit in multiple countries, operate several brands or legal entities, or have hiring workflows with different data requirements. A single global retention policy or permission structure may not fit every situation.

During your ATS evaluation, establish which privacy settings can vary and at what level they can be configured. For international organizations in particular, the ability to manage regional requirements within the same recruitment platform can make policies much easier to administer consistently.

Questions to ask an ATS vendor about GDPR and candidate data

A vendor demo is a good opportunity to move from policy statements to specific workflows. Ask vendors to show you how their controls work wherever possible.

Use questions such as these during demos, procurement, and security reviews:

Candidate data and retention

  • Where is candidate data stored?
  • Can customers choose a hosting or data residency region?
  • Can retention periods be configured automatically?
  • Can retention requirements vary between regions or hiring workflows?
  • What happens to candidate data when a retention period expires?
  • How do we configure our privacy information and any required consent processes?

Candidate rights, permissions, and auditability

  • How would an authorized user respond to a candidate access request?
  • What candidate information can we export ourselves?
  • How are corrections and deletion requests handled?
  • What information can candidates manage themselves?
  • How granular are user permissions?
  • How is sensitive candidate information protected from unnecessary access?
  • Which actions are recorded in audit logs, and how can those records be accessed?

Sub-processors, transfers, and contracts

  • Which sub-processors process our candidate data?
  • Where does that processing take place?
  • How will you notify us when your sub-processors change?
  • How do you manage transfers of personal data outside the EEA or other relevant regions?
  • Can we review your DPA before procurement reaches the contract stage?
  • What happens to our candidate data when our contract ends?

Security

  • Which security certifications or independent assurance reports do you maintain?
  • How is candidate data protected in transit and at rest?
  • Which authentication and access controls are available?
  • How do you test the security of the platform?
  • What is your process for identifying, managing, and communicating relevant security incidents?

AI

  • Which AI features process candidate data?
  • Which data does each feature use?
  • Which third-party AI providers process that information, and where?
  • Is customer or candidate data used to train or improve shared models?
  • Can individual AI features be enabled or disabled?
  • Where is human review required before an AI-assisted output affects a candidate?
  • What information is available to explain or audit an AI-assisted output?

The strongest answers will usually combine documentation with a product demonstration. Seeing how a retention rule, permission, export, or deletion workflow works gives your team more useful evidence than a simple confirmation that the feature exists.

GDPR and AI in recruitment

AI introduces additional questions when it processes candidate data.

Start with data handling. Your team needs to understand what candidate information is sent to an AI system, why it’s required, where processing occurs, how long information is retained, and whether another provider becomes a sub-processor.

Transparency and human oversight should form part of the evaluation too. Organizations need to understand where AI is used in the recruitment process, what candidates need to know about that use, and where a person reviews an output before it affects a hiring decision.

If an AI feature scores, summarizes, filters, or recommends candidates, ask what information the system provides about that output and what records are available for later review. 

For example, Pinpoint has an approach to AI page, covering how our AI features handle candidate data, model training, third-party providers, and human oversight.

It’s worth considering the potential requirements beyond GDPR too. Under the EU AI Act, certain AI systems used in employment, including systems intended to analyze and filter job applications or evaluate candidates, can fall within the high-risk framework. 

Requirements and implementation timelines continue to develop, so recruiting teams should refer to current European Commission AI Act guidance and seek appropriate legal advice for their circumstances.

How to verify an ATS vendor’s GDPR and security claims

Privacy and security claims are more useful when you can verify them.

If a vendor says it supports GDPR requirements, review its DPA and privacy documentation. If it offers regional data residency, confirm its hosting locations and check how sub-processors affect that arrangement. If it provides automated retention, ask to see the configuration in the product. If it says access is tightly controlled, review the permission model.

For security claims, look for relevant independent certifications, assurance reports, security documentation, and information about testing and incident management. Review the vendor’s sub-processor information too, including how changes are communicated.

Treat the claim as the starting point, then look for the evidence behind it. For teams evaluating Pinpoint, our Security & Privacy center brings that evidence together, with the DPA, sub-processor information, and GDPR resources available for review.

GDPR compliance within broader regulated hiring

For organizations operating in regulated environments, GDPR may be one part of a wider set of hiring requirements.

Many of the controls you’re evaluating here can support those broader requirements too. Permissions and audit trails can help organizations control and document access, while structured workflows can make required hiring steps easier to apply consistently.

It’s important to consider these needs together during an ATS evaluation, especially if your organization also has requirements around approvals, background checks, structured assessments, or other compliance-oriented hiring processes.

If those requirements extend beyond candidate data protection, look at how the ATS supports structured, auditable hiring in regulated environments.

Choosing an ATS that supports your GDPR responsibilities

A GDPR-compliant ATS should make it easier to put your organization’s data protection policies into practice. 

As you evaluate vendors, focus on the controls you can configure, the processes your team can manage directly, and the evidence available to support privacy and security claims.

If you’d like to see how Pinpoint supports secure, compliant recruiting in practice, book a demo with our team.

Author
Alice Dodd
Content Manager

With over seven years in B2B SaaS, Alice creates data-driven content that makes complex topics simple and engaging. She believes every good story (no matter how dry or technical) should feel human, useful, and built on insight.

Manage every hiring stream in one place
Support multiple roles, teams, and workflows in one platform, with the clarity and consistency your team needs.
G2
4.8
Capterra
4.8
SSR
4.8