Welcome, Administrator! This article provides a complete step-by-step guide for implementing GDPR compliance in Carerix. As an administrator, you are responsible for activating the right tools, configuration, and monitoring. Follow this guide to prepare your organization for GDPR.
Getting Started — Setup Checklist
Execute the following steps before your organization goes live with GDPR-enabled processes:
☐ Determine your organization-wide GDPR strategy (which basis, which retention periods)
☐ Activate GDPR tools in Carerix (Privacy Settings)
☐ Configure legal bases and retention periods (adjust table)
☐ Set up anonymization (determine which fields to retain)
☐ Prepare email templates (consent and reminder emails)
☐ Configure triggers for automated actions
☐ Assign user roles with appropriate rights
☐ Test workflows on a test environment
☐ Document your processes in a processing register
☐ Train your team on GDPR processes
Step 1: Determine Your GDPR Strategy
Questions for Your Strategy
Before configuring Carerix, you must determine internally:
Which basis is primary? Do you rely on consent, or on legitimate interest / legal obligation?
What are your retention periods? How long do you keep candidates based on consent? (typically 2 years). How long after employment? (typically 7 years for tax)
What personal data do you process? Only name/email, or also photo, social media profiles, references?
Who takes action upon expiration? Automatically anonymize, or manual per team?
How do you document consent? Via application form (direct) or via email (indirect)?
💡 Tip: Document these choices in a "GDPR Policy" document that you share internally with your team. This helps ensure consistent work and gives you clarity during inspections.
Step 2: Activate GDPR Tools in Carerix
Turn On Privacy Settings
GDPR features in Carerix are off by default. You must explicitly enable them:
Log in as Mainuser (Administrator)
Go to Settings → Application → Privacy Settings
Turn "Use Privacy Restrictions" ON
Save and restart the application (may take a few minutes)
Verify that new fields appear in candidate record:
Legal Basis
Basis Expiration Date
Consent Status
ℹ️ Important: After enabling Privacy Settings, all users can see GDPR fields, but only users with specific roles (see Step 6) can edit them.
Step 3: Configure Legal Bases and Retention Periods
Adjust the "Legal Basis" Table
In Carerix, "Legal Basis" is a table with fixed values. You don't need to change them, but can add extra options:
Standard options:
Legal Obligation
Contract Performance
Legitimate Interest
Consent
No Consent
Add custom options? You can add extras like:
"Employee Referral" (for employee referrals)
"Marketing" (for jobseeker database)
"Archive" (old candidates, no active processing)
Configure the "Retention Period" Table
This is critical. You set here how long candidates are kept:
Go to Settings → Tables → Retention Period
Create records for your typical scenarios:
Consent (2 years): "2 year consent"
Employment Contract (3 years): "Employment contract 3y"
Legal (7 years): "Tax retention 7y"
For each record, enter:
Name (for your team)
Months (retention period in months: 24 for 2 years, 36 for 3 years, 84 for 7 years)
Description (brief note)
Save. Carerix automatically calculates the expiration date based on today + period
💡 Best Practice: Use English names for retention period records so they remain clear across multiple languages. Example: "Consent 2Y" instead of "Toestemming (2 jaren)"
Step 4: Set Up Anonymization
Which Fields Are Retained During Anonymization?
This is important: anonymization removes personal data, but you can determine what remains for reporting:
Typically deleted:
First name, last name
Email address, phone number
Address
All consent fields
All notes and communication
Typically retained (for reporting):
Candidate ID (internal reference)
Creation date
Legal Basis (for audit)
Anonymization date
Match history (which positions matched)
Placement data (employer, duration, period)
Configure Anonymization Settings
Go to Settings → Application → Anonymization
Per field group: choose "Delete" or "Retain"
Typical choices:
Personal Data (name, email): Delete
Address: Delete
Consent: Delete
Match Data: Retain
Placement: Retain
Test on test environment before going live
⚠️ Warning: Once you save anonymization settings, administrators can anonymize candidates. This is irreversible. Ensure your team understands the process well.
Step 5: Prepare Email Templates
Which Email Templates Are Needed?
For GDPR workflows, you need at least these email templates:
"Request Initial Consent (GDPR)" — For candidates found indirectly (LinkedIn)
"Request Consent Renewal (GDPR)" — Reminder that consent is about to expire
"Consent Renewal" — Candidate reactive after absence, ask again
"Consent Withdrawal Confirmation" — Confirmation that candidate said "No"
Set Up Templates
Go to Library → Email Templates
Search for GDPR templates (filter by "GDPR")
Activate the templates you need (click "Activate")
Customize content to your operations (e.g., sign with your company name)
Test by sending yourself a test email
Important: These templates contain automatic Yes/No links. When candidate clicks "Yes", consent is automatically recorded in Carerix.
Step 6: Set Up Triggers for Automation
Common GDPR Triggers
Triggers execute automated actions based on conditions. Some GDPR examples:
Trigger 1: Reminder Email on Expiration
IF: "Basis expiration date < 30 days"
THEN: "Send email 'Request Consent Renewal'"
Trigger 2: Change Status on Hire
IF: "Placement approved"
THEN: "Change Legal Basis to 'Contract Performance'; Change Retention Period to '3 years'"
Trigger 3: Prepare Anonymization
IF: "Basis expiration date < today" AND "No contact for 3 months"
THEN: "Add to 'Anonymization Candidates' group" (so you anonymize them in bulk weekly)
Configure Triggers
Go to Settings → Application → Automation → Triggers
Click "New"
Define condition (IF) and action (THEN)
Set trigger to "Active"
Test first on small group (add filter to match only test candidates)
Then expand to all candidates
ℹ️ Important: Triggers check on a daily or hourly basis, depending on settings. Always test first on test environment!
Step 7: User Roles with GDPR Rights
Which Roles Should Have GDPR Rights?
Not everyone needs to see or edit GDPR data. Determine per role:
Recruiter: Can read consent status, but cannot anonymize
Team Lead: Can give consent, can add candidates to anonymization queue
Administrator: Can do everything: edit GDPR fields, anonymize, adjust triggers
HR Manager: Can anonymize and view reporting
Configure Roles
Go to Settings → Users → Roles
Per role: set rights for "GDPR" (depending on Carerix version)
Typical permissions:
"Read GDPR Fields": Who can see status?
"Edit GDPR Fields": Who can change status?
"Anonymize": Who can anonymize candidates?
Assign roles to users
Step 8: Set Up Monitoring and Reporting
Report "Candidate Consent History"
This report shows all candidates with their consent status. Run this weekly:
Go to Reporting → Candidate
Search for "Consent History" or "GDPR Status" report
Filter on: "Basis expiration date < 30 days" or "No consent"
Export to CSV, send to your GDPR team
Filters in Candidate List
Create these filters in your candidate list view:
"Basis expiration date < 30 days": Candidates needing action soon
"Legal Basis = No Consent": Candidates who haven't given consent yet
"Anonymization Status = In Queue": Candidates awaiting anonymization
Step 9: Audit Trail and Compliance Logging
What Should I Log?
For legal compliance, you must document these actions:
Date consent given (automatic)
Change of legal basis (who, when, why)
Anonymization (who, when, reason)
Deletion requests (date received, follow-up date)
How to Log
Option 1: Carerix Logging (Automatic)
Carerix automatically saves all GDPR field changes to the audit log
Go to Candidate → History to see all changes
Option 2: External Register
Keep an Excel/Google Sheet with all GDPR actions
Columns: Date | Candidate | Action | By Whom | Reason | Status
This helps during inspections by supervisory authorities
Step 10: Train Your Team
Training Checklist
☐ Recruiter training: "How to request and record consent"
☐ Team Lead training: "How to monitor GDPR status and recognize expiring candidates"
☐ Administrator training: "How to anonymize, adjust triggers, run reporting"
☐ HR training: "What are our GDPR policies and retention periods"
☐ Documentation: Internal wiki with screenshots and step-by-step guides
Related Help Articles
GDPR Flows in Carerix — Practical workflows
GDPR - Available Tools in Carerix — Overview of all features
GDPR Tools Activate — Turn on Privacy Settings
Anonymization Tool - Activation and Setup — How to configure anonymization
GDPR - Automate Your Processes with Triggers — Trigger examples
Email Templates - Yes/No Consent Links — Email setup
User Roles — Roles and permissions
Carerix & GDPR - Complete Guide — Total overview
Ready? Final Checklist
☑ Privacy Settings enabled
☑ Legal bases and retention periods configured
☑ Anonymization set up (fields determined)
☑ Email templates activated and customized
☑ Triggers configured and tested
☑ User roles configured
☑ Reporting set up and tested
☑ Audit logging configured
☑ Team trained
☑ Test run with small group executed
☑ Live!
Need Help?
This setup can be complex. Contact our support team at helpdesk@carerix.com with questions about configuration, triggers, or anonymization. We're happy to help you establish a GDPR-compliant Carerix setup.
