Active sourcing can be compatible with the GDPR when an organisation uses only necessary professional data for a defined role, documents a legitimate-interest assessment and tells the person what is happening. It is not a general permission to build hidden candidate lists or contact people through any channel. In Germany, email and telephone outreach also require a separate check under the UWG. This is practical guidance based on sources accessed on 20 August 2026, not legal advice.
What active sourcing means under the GDPR
Active sourcing is the purposeful identification of people who may fit a role, followed by an approach before they apply. The processing starts when a recruiter records or enriches a profile, not when a message leaves the outbox. The AI active sourcing and people search hub explains the operational side; the legal side begins with the source and intended use of each data point.
A sound process separates three decisions. First, is collecting and using the data lawful? Second, has the person received the required information? Third, does the selected channel comply with the applicable direct-marketing and communications rules? A GDPR legal basis does not itself permit a cold email or call.
Legitimate interest is often the starting point, not the final answer
For a limited search and initial assessment, organisations commonly consider legitimate interests under Article 6(1)(f) GDPR on EUR-Lex. Filling a genuine vacancy or performing a defined recruitment mandate can be a legitimate interest. The provision only works where the individual’s interests, rights and freedoms do not override that interest.
That calls for a recorded three-part assessment. Define the interest precisely, such as hiring for a particular engineering role. Confirm necessity: could the role be filled without collecting this specific data, or with less of it? Then balance the likely expectation and impact on the person against the business need. A person who has publicly presented their skills and work contact details in a professional setting is in a different position from someone whose information is private or socially contextual. The Hessian data-protection authority reached the same distinction in its published discussion of active sourcing.
Professional public sources are different from merely accessible data
Usually lower-risk sources are public professional profiles, a person’s work-focused website, or a publicly accessible CV where the information is relevant to the position. A candidate database may also be usable where the source is traceable and its terms permit the intended recruitment use. Limit the record to what supports the role: professional experience, relevant skills and an appropriate contact route.
Higher-risk sources include private social-network activity, closed communities, information visible only after a connection is accepted, and opaque data-broker lists that cannot explain provenance. Data being searchable does not make it fair to repurpose. The Hessian authority specifically notes that restricted professional-network data are not generally accessible; transparency about the recruiter role at the connection-request stage matters.
Do not turn sensitive information into sourcing criteria or recruiter notes. Data that reveal health, religion, political views, trade-union membership, ethnicity, sexual orientation or similar matters fall within the special categories addressed by Article 9 GDPR. A profile may disclose more than a recruiter needs; the safer practice is not to collect, infer, rank or retain those details.
Article 14 requires meaningful notice when data came from elsewhere
When personal data were not collected from the person, Article 14 GDPR requires the controller to provide information including its identity and, where relevant, its data-protection officer; the purpose and legal basis; the data categories; recipients and relevant third-country transfers; the retention period or criteria; rights and complaint route; and the source, including whether it was publicly accessible. Where the basis is legitimate interests, explain what that interest is. If profiling or an automated decision is involved, the required notice also expands.
The timing matters. If the data will be used to communicate with the candidate, notice is due at the latest with the first communication. If no communication happens, the outside limit is one month after obtaining the data, taking the circumstances into account. A concise notice in the first message can link to fuller privacy information, but the organisation must still be able to identify the actual source behind the profile when asked.
A one-time approach and a candidate pool have different risk profiles
A one-time approach for a defined role has a narrow purpose: identify a suitable person, make contact, process the response and close the activity. That supports minimal fields, a short operational retention period and no automatic reuse. Silence is not permission to keep a person available for future campaigns.
A talent pool has an ongoing purpose and a longer impact. Before moving a profile into one, document the purpose, access rights, review dates, deletion criteria and legal basis separately. A voluntary, documented opt-in for future opportunities is often clearer after someone has expressed interest; an organisation relying on legitimate interests instead needs a more demanding, well-documented balancing exercise. Resources on talent-pool reactivation and a candidate portal for self-managed profiles can help design the experience, but neither replaces the legal assessment.
Retention should follow the purpose, then end
The GDPR does not prescribe a universal active-sourcing retention period. Its storage-limitation principle requires identifiable data to be kept no longer than necessary for the purpose. Set a short, justified period for the role before launching the search, and apply it rather than treating it as a suggestion. If the role closes, the person declines or there is no longer a defined purpose, erase or anonymise the candidate record and the enrichment attached to it unless another documented basis applies.
A minimal suppression record may be needed to prevent a later import from overriding an objection. Keep it tightly scoped: an identifier, the date, the objection’s scope and suitable access controls – not a full candidate profile. Articles 5 and 17 GDPR connect retention to necessity and require erasure where data are no longer needed or an objection prevails.
An objection must stop the workflow, not disappear into a mailbox
People must be told about their right to object when processing rests on Article 6(1)(f). When an objection arrives, log the date, channel, scope and action taken, then suppress further sourcing and outreach across the relevant systems. Under Article 21, processing based on legitimate interests must stop unless the controller can demonstrate compelling overriding grounds. For direct marketing, the rule is stricter: processing for that purpose must cease. Operationally, an explicit “do not contact me again” should be treated as a firm stop for recruitment outreach.
Email and telephone have a separate German UWG test
For German outreach, the wording of section 7 UWG addresses unreasonable nuisance independently of data protection. Telephone advertising to consumers requires prior express consent; for other market participants, at least presumed consent is required. Electronic mail generally requires prior express consent, while the statutory existing-customer exception will rarely fit a first approach to an unknown candidate. Whether a tailored recruitment message is advertising in a particular setting may need legal analysis, so do not treat legitimate interests under the GDPR as a substitute for a channel review. For EU and US campaigns, also assess the relevant local e-privacy, direct-marketing and employment rules.
A practical active-sourcing GDPR check before launch
The most useful checklist is built into the recruiting flow rather than saved as a policy nobody opens:
- Define the role: confirm a real, sufficiently specific vacancy or recruitment mandate.
- Validate the source: establish that it is professional, public, traceable and usable under the platform’s terms.
- Minimise data: keep role-relevant information only; exclude private observations and special-category data.
- Record the balancing test: capture purpose, necessity, reasonable expectation, risks and safeguards.
- Prepare Article 14 notice: include source, retention logic, objection route and accessible privacy information before the first message.
- Approve the channel separately: check email, telephone and platform messaging under UWG and the other laws that apply to the campaign.
Automation does not automate legal permission
Technology can structure research, approvals, notices and suppression lists, but it cannot create a legal basis or turn an unsuitable channel into a lawful one. Teams using People Search for active sourcing should make source capture, human approval, Article 14 notice, deletion runs and objection suppression part of the configured workflow. The AI sourcing tools category is useful for comparing approaches; compliance still depends on how the organisation actually uses the tool.
An explicit limitation
This framework cannot decide every individual message, platform clause or international transfer. The outcome may change with a staffing-agency mandate, works-council arrangements, group-company access, transfers outside the EEA or the precise legal classification of a message. Before scaling outreach or creating a long-lived candidate pool, involve the data-protection officer or qualified local counsel in the specific design.
FAQ
Can I use a public LinkedIn profile for active sourcing?
A public, work-focused profile can support a legitimate-interest assessment for a relevant approach. It does not remove the duties of transparency, data minimisation and source documentation. Do not use private-context information or data that are only visible to accepted connections as if they were public.
When must the Article 14 notice be given?
If you use the data to contact the person, provide the information at the latest with that first communication. Where no communication occurs, Article 14 sets an outside limit of one month after collection. The notice should name the source and make the objection route easy to use.
May we retain people who do not reply in a pool?
No response is not an opt-in. Ongoing storage needs a defined purpose, a documented lawful basis, a proportionate retention period and transparent notice. A voluntary opt-in for future opportunities often creates a clearer and more respectful relationship.
Is an unsubscribe link enough to honour an objection?
Only if the resulting instruction reaches every system used for sourcing and outreach. Record the objection, prevent future imports from reactivating the person and retain only the minimal suppression data needed to honour it. A reply requesting no further contact should trigger the same operational result.
