GDPR-compliant ATS: What to look for when evaluating applicant tracking systems
Learn what to look for in a GDPR-compliant ATS, from candidate data controls and retention to security, vendor governance, and responsible AI.
Learn what to look for in a GDPR-compliant ATS, from candidate data controls and retention to security, vendor governance, and responsible AI.

Recruitment teams handle a huge amount of personal candidate data.
Your applicant tracking system will likely contain resumés, contact details, interview notes, assessment results, salary information, right-to-work documentation, and other information collected throughout the hiring process.
It goes without saying, then, that data protection a hugely important part of any ATS evaluation. Alongside recruiting functionality, usability, integrations, and reporting, buyers need to understand how a platform supports the way candidate data is collected, accessed, retained, transferred, and deleted.
A GDPR-compliant ATS should give your organization practical controls that support its data protection responsibilities. No applicant tracking system can make an organization GDPR compliant on its own, your organization remains responsible for deciding why it processes candidate data, which data is necessary, how long to keep it, and who should have access.
This guide covers what recruiting, procurement, security, and compliance teams should evaluate when choosing an ATS. It’s intended as a practical buying guide, not legal advice.
GDPR is the European Union’s data protection framework. It applies to organizations within its scope, including some organizations outside the EU that process the personal data of people in the EU. The UK has its own UK GDPR framework, while the US and other countries have separate privacy and data protection laws that can also affect how candidate information is handled.
For recruiting teams, GDPR affects how candidate data is collected, used, accessed, retained, and deleted. It also gives candidates rights over their personal data and requires organizations to take appropriate steps to protect it.
An ATS should provide controls that help you manage these responsibilities consistently, from retention and deletion to permissions and candidate data requests. Your organization still decides why candidate data is processed, how long it’s kept, and who can access it.
For more on the regulation itself, see the European Commission’s GDPR guidance. You can also explore the practical controls that can support GDPR compliance in recruitment.
Evaluating ATS GDPR compliance means looking beyond a vendor’s statement that its platform is GDPR compliant. You need to understand how the product works in practice and whether the vendor can provide the documentation and evidence your organization needs.
Candidates should receive clear information about how their personal data will be processed. Look for an ATS that lets your team configure privacy information within your careers site and application process, then update it as your requirements change.
Where your organization relies on consent for a particular processing activity, the system should support the appropriate consent process and maintain the necessary records. That doesn’t mean every recruiting activity should be based on consent. The appropriate legal basis depends on the processing involved and your circumstances.
What matters when evaluating the ATS is flexibility. You might need different approaches for applications, talent pools, job alerts, or nonessential cookies. Look for application forms you can configure around the information and consent requirements of different hiring processes.
Candidate data shouldn’t remain in an ATS indefinitely simply because nobody has deleted it.
Your organization should establish appropriate retention periods based on why candidate data is being processed and any other applicable requirements. The ATS should make those policies practical to implement without relying on recurring manual cleanup.
Check whether retention periods can be configured and applied automatically, whether policies can vary between regions, and what happens when a retention period expires.
This becomes especially important for international hiring, where your organization may need to apply different data-handling requirements across the regions where it recruits.
Candidate data requests can quickly become difficult to manage if your ATS doesn’t provide suitable tools for handling them.
During an evaluation, ask the vendor to demonstrate how an authorized user would find the information held about a candidate, correct it, export it, or delete it. Find out which actions your team can complete directly and which require help from the vendor.
Candidate self-service can make this easier too. Giving candidates appropriate ways to manage their own information can reduce administration while supporting a more transparent candidate experience.
Product functionality is only part of the picture. The vendor’s Data Processing Addendum should also explain how it will assist with relevant data subject requests.
Not everyone involved in recruitment needs access to every piece of candidate information.
A hiring manager may need to see candidates for their own roles without needing access to every requisition in the organization. Some information may need tighter restrictions because of its sensitivity or because it shouldn’t form part of the hiring decision.
Look closely at the ATS permission model. Can access be restricted by role, requisition, team, location, or type of information? How are administrative permissions managed when somebody changes role or leaves the organization? Can you see who performed important actions and when?
These are areas to test in the product itself rather than relying on a feature list. Reviewing the vendor’s documented security, access, and privacy controls can help you verify what sits behind the functionality you see in a demo.
Knowing where candidate data goes is an important part of assessing GDPR-compliant recruitment software.
Start by asking where the vendor stores customer data and whether you have a choice over data location. Then look beyond the ATS provider itself.
ATS vendors typically use other service providers to deliver parts of their service. These sub-processors may provide infrastructure or other functionality that involves processing customer data.
Ask for a current sub-processor list and check what each provider does, where relevant processing takes place, and how you’ll be notified about changes.
Data residency is only one part of the assessment. GDPR doesn’t require all personal data to remain inside the EU or EEA. International transfers can take place when the applicable GDPR requirements and safeguards are met, so you also need to understand how the vendor manages transfers when data is processed elsewhere.
The Data Processing Addendum, or DPA, should be part of your ATS evaluation rather than paperwork left until the end of procurement.
Review how it defines the responsibilities of the controller and processor, along with the vendor’s commitments around processing instructions, confidentiality, security, sub-processors, international transfers, data subject requests, breaches, and what happens to customer data when the relationship ends.
Your legal or privacy team may have additional requirements based on where your organization operates. Having the DPA available to review early in the buying process makes it easier to identify questions before you reach the contract stage.
Protecting personal data is a core part of GDPR, so security needs to be part of the same evaluation.
Ask vendors for evidence that supports their security claims. Depending on your requirements, that might include independent security certifications and assurance reports, encryption practices, authentication controls such as SSO and MFA, penetration testing, incident management processes, access controls, audit logs, and business continuity arrangements.
You’re looking for evidence your security and procurement teams can review, not simply a collection of security claims. A well-documented Security & Privacy center can make it easier to find certifications, security practices, and privacy controls without waiting for them to surface later in procurement.
Organizations rarely have a single hiring process.
You may recruit in multiple countries, operate several brands or legal entities, or have hiring workflows with different data requirements. A single global retention policy or permission structure may not fit every situation.
During your ATS evaluation, establish which privacy settings can vary and at what level they can be configured. For international organizations in particular, the ability to manage regional requirements within the same recruitment platform can make policies much easier to administer consistently.
A vendor demo is a good opportunity to move from policy statements to specific workflows. Ask vendors to show you how their controls work wherever possible.
Use questions such as these during demos, procurement, and security reviews:
The strongest answers will usually combine documentation with a product demonstration. Seeing how a retention rule, permission, export, or deletion workflow works gives your team more useful evidence than a simple confirmation that the feature exists.
AI introduces additional questions when it processes candidate data.
Start with data handling. Your team needs to understand what candidate information is sent to an AI system, why it’s required, where processing occurs, how long information is retained, and whether another provider becomes a sub-processor.
Transparency and human oversight should form part of the evaluation too. Organizations need to understand where AI is used in the recruitment process, what candidates need to know about that use, and where a person reviews an output before it affects a hiring decision.
If an AI feature scores, summarizes, filters, or recommends candidates, ask what information the system provides about that output and what records are available for later review.
For example, Pinpoint has an approach to AI page, covering how our AI features handle candidate data, model training, third-party providers, and human oversight.
It’s worth considering the potential requirements beyond GDPR too. Under the EU AI Act, certain AI systems used in employment, including systems intended to analyze and filter job applications or evaluate candidates, can fall within the high-risk framework.
Requirements and implementation timelines continue to develop, so recruiting teams should refer to current European Commission AI Act guidance and seek appropriate legal advice for their circumstances.
Privacy and security claims are more useful when you can verify them.
If a vendor says it supports GDPR requirements, review its DPA and privacy documentation. If it offers regional data residency, confirm its hosting locations and check how sub-processors affect that arrangement. If it provides automated retention, ask to see the configuration in the product. If it says access is tightly controlled, review the permission model.
For security claims, look for relevant independent certifications, assurance reports, security documentation, and information about testing and incident management. Review the vendor’s sub-processor information too, including how changes are communicated.
Treat the claim as the starting point, then look for the evidence behind it. For teams evaluating Pinpoint, our Security & Privacy center brings that evidence together, with the DPA, sub-processor information, and GDPR resources available for review.
For organizations operating in regulated environments, GDPR may be one part of a wider set of hiring requirements.
Many of the controls you’re evaluating here can support those broader requirements too. Permissions and audit trails can help organizations control and document access, while structured workflows can make required hiring steps easier to apply consistently.
It’s important to consider these needs together during an ATS evaluation, especially if your organization also has requirements around approvals, background checks, structured assessments, or other compliance-oriented hiring processes.
If those requirements extend beyond candidate data protection, look at how the ATS supports structured, auditable hiring in regulated environments.
A GDPR-compliant ATS should make it easier to put your organization’s data protection policies into practice.
As you evaluate vendors, focus on the controls you can configure, the processes your team can manage directly, and the evidence available to support privacy and security claims.
If you’d like to see how Pinpoint supports secure, compliant recruiting in practice, book a demo with our team.