Do not run one retention timer for every candidate record. Keep data needed for a live hiring process only until that process and any justified evidence period are complete; keep a person in a talent pool only for the separate future-opportunity purpose they have freely agreed to. The GDPR does not prescribe one universal retention period. In Germany, six months after a rejection is a common operational benchmark for the application file, while pool retention needs its own stated end date or criteria. This guide reflects sources checked on 20 August 2026 and is not legal advice.
A talent pool is a maintained set of people an organisation may consider for future roles and contact for that stated purpose. It is not a backup folder for every past applicant. The distinction matters because a recruiter deciding a current vacancy needs a different set of data, access and retention justification from a team preserving a voluntary relationship for a future opening. A useful talent-pool reactivation approach starts with that separation.
A hiring record is not automatically a talent-pool profile
During an open application, the organisation needs information to assess the person against a specific role and to run a fair process. In Germany, Section 26(1) of the Federal Data Protection Act addresses processing that is necessary to decide whether to establish an employment relationship. The scope should remain proportionate: a CV, interview notes and the documented decision may be relevant; collecting additional future-use data merely because it could be useful later is a different question.
Once the applicant withdraws, accepts an offer, or receives a rejection, the immediate recruitment purpose changes or ends. A talent pool has a different job: it supports a possible future match. Treating that new purpose as an automatic continuation obscures both candidate choice and retention. Teams dealing with high application volume can improve the quality of the initial decision through the application volume and CV-screening hub, but better process data does not turn into permanent pool data by default.
Consent for a pool must be a real choice
For a voluntary talent pool after the procedure, use a separate, explicit consent request. It should say what the pool is for, which categories of data will be retained, how long the retention lasts or how it is determined, how the person may be contacted, and how they can leave. The choice should be optional, separate from the application decision, easy to understand and not preselected. A candidate who declines must be able to continue the current recruitment process without a disadvantage.
Article 7 GDPR requires the controller to be able to demonstrate consent and gives the data subject the right to withdraw it at any time, as easily as it was given. In Germany, Section 26(2) BDSG also places particular weight on voluntariness and requires information about purpose and the right to withdraw in the employment context. Record more than a yes/no field: retain the consent timestamp, wording version, stated purpose, chosen retention period and withdrawal channel.
Why a six-month rule is not a GDPR retention rule
The GDPR requires storage limitation rather than a standard number of months. Under Articles 5(1)(e), 5(2) and 17 GDPR, identifiable personal data should be kept no longer than necessary for their purpose, and deletion must be assessed when the purpose no longer applies or consent is withdrawn, subject to applicable exceptions. The employer must also be able to demonstrate compliance. Those principles explain why an application file and a talent pool need separate rules.
In Germany, the commonly used six-month application-file benchmark is a risk-management practice, not a statutory GDPR deadline. Its background includes two defined periods: under Section 15(4) of the General Equal Treatment Act, a claim generally has to be asserted in writing within two months of receiving a rejection; under Section 61b(1) of the Labour Courts Act, an action for compensation must be brought within three months after the written assertion. A six-month window can leave an administrative margin for selection evidence. Collective agreements, other claims and the facts of a case can change the analysis, so obtain advice on the actual policy.
Use three checkpoints rather than one expiry field
A robust operating model keeps three separate checkpoints. First, the application checkpoint closes the active recruitment process. Second, the evidence checkpoint governs the limited period for records that may be needed to explain or defend the selection decision. Third, the pool checkpoint starts only after the separate opt-in and ends on the stated date or on withdrawal. One profile can therefore have different actions at different times; an ATS field called “retention date” is too blunt if it merges all three.
There is no defensible universal pool duration. Set it from the genuine future-recruitment purpose, the value promised to candidates and the organisation's ability to keep records current. State that period in the consent notice and ask for a fresh, deliberate choice before it expires if you want the relationship to continue. A structured CV-screening workflow may make an application record more useful, but it does not extend the retention period that was promised for the pool.
Deletion is a process, not a button
A deletion concept connects each category of data with its purpose, retention trigger, owner and technical outcome. It should cover the visible candidate profile as well as attached documents, interview notes, scores, exports, access rights and backup or restoration cycles. When pool consent expires or is withdrawn, the record should first become unavailable for pool search and outreach; the organisation then applies the deletion or genuine anonymisation action defined for that category.
Evidence of deletion does not mean retaining the full candidate file indefinitely just to prove it was removed. A better audit trail records the applicable rule, the time of the action, the responsible system and the result. That creates evidence that the workflow operated while avoiding the contradiction of storing the CV as a deletion receipt. The accountability principle in Article 5(2) GDPR becomes workable when those records are designed as part of the process.
Notice and old-data migration need their own review
Before someone joins a pool, the privacy information should identify the controller, pool purpose, legal basis, relevant recipients or transfers, retention period or criteria, and the ways to exercise access, correction, deletion, complaint and withdrawal rights. Where data was collected from the individual for an application and will be used for the new pool purpose, the additional purpose information must be given before that further processing. Where data came from somewhere else, assess the information duties in Articles 13 and 14 GDPR according to its source.
Do not import an old applicant database into an active talent pool merely because the records are already in an old system. Check whether there is evidence of pool-specific consent, whether its wording covered the intended future use, and whether its stated duration has not passed. If the answer is unclear, seek a new opt-in before activation rather than treating a technical migration as consent. A renewed choice also lets people update their role preferences, contact route and visibility on their own terms.
Make retention executable in the product workflow
A suitable system should make the end of an application a branching decision, not a silent copy to a pool. It should distinguish an application evidence period from a consent-backed pool expiry, alert before a renewal is needed, prevent expired records from appearing in active search, and trigger the appropriate deletion workflow. Automation is valuable because it executes a rule consistently; it must not be presented as a machine that determines the legal basis on its own.
A candidate portal with self-managed profiles makes the voluntary relationship more credible: people can correct their data, alter visibility and leave the pool without asking a recruiter to find an inbox. Sprad Atlas supports a candidate portal and talent-pool management, but each employer remains responsible for setting its retention periods, permissions and deletion policy. When evaluating software, test those controls alongside the criteria in a comparison of AI recruiting tools, rather than asking only whether profiles can be stored.
A stated limitation: technology cannot resolve the exception
Expiry automation and candidate self-service reduce forgotten records, but neither proves that a particular record may be retained or must be kept longer. A tool cannot determine the effect of a pending claim, special-category data, a collective agreement or a local rule in every jurisdiction. For EU and US operations, apply the laws that actually govern the data and process, and involve privacy, legal and where relevant employee-representation stakeholders before rollout.
Frequently asked questions about talent-pool retention
Can we keep every rejected applicant for six months?
Six months is commonly used in Germany for a limited application-evidence period after rejection, based on the AGG and labour-court timings described above. It is not a blanket GDPR permission and does not itself justify an active future-opportunity pool.
Does a consent checkbox need a retention date?
It should communicate a concrete retention period or transparent criteria that let the candidate understand when pool use ends. The organisation also needs to retain enough evidence of the wording and the candidate's choice.
What should happen when a candidate withdraws pool consent?
Stop future pool processing based on that consent, remove the profile from active search and outreach, and run the deletion assessment in the retention policy. The exact handling of any separate legal-retention exception should be reviewed for the case.
May we migrate applicants from a legacy ATS?
A system migration does not create a new permission. Verify pool-specific consent and its scope and duration before importing a record into active pool use; otherwise ask for a new opt-in or leave the profile out.
Can automatic deletion demonstrate compliance?
It is strong operational evidence when paired with a documented policy and an audit trail. You still need to show what was covered, when the rule applied, who owned it, and how exports and backup restoration are handled.
