Working GDPR Compliant in Carerix: This article describes the practical steps you (recruiter, team lead, or basic user) must take to ensure you manage clients and candidates in a GDPR-compliant manner.
ℹ️ Who is this for? This article is for recruiters, sourcers, team leads, and HR staff. If you're an administrator who wants to set up GDPR tools, see GDPR Information for Administrators.
GDPR Workflow - Step by Step
You work GDPR-compliant by following this workflow:
Add Candidate: Register the source and request consent
Fill Consent Date: Record when and for how long consent applies
Monitor: Track expiring consents and take action
Anonymize or Renew: Act when consent expires
Step 1: Add Candidate & Register Source
What Must You Do?
When you add a candidate to Carerix (manually, via LinkedIn, via application form), make sure:
Source is filled: Where did you find this candidate? (LinkedIn, job board, CV database, referral, etc.)
Consent Status set: "Not Yet Asked", "Yes", or "No"
Legal Basis chosen: Consent, Legitimate Interest, etc. (administrator determines this)
Practical Example
Scenario 1: LinkedIn sourcing
You find candidate on LinkedIn and add them
Source = "LinkedIn"
Status = "Not Yet Asked" (you haven't requested consent yet)
Legal Basis = "Consent" (or whatever administrator set)
Scenario 2: Application Form
Candidate fills your website form with checkbox "I agree"
Source = "Website" or "Career Site"
Status = "Yes" (automatically — candidate already agreed)
Legal Basis = automatically filled (administrator mapping)
💡 Tip: Social Browser
You can use the Social Browser plugin to search LinkedIn without photos. This helps with GDPR (less biometric data) and prevents bias. Learn about all tools.
Step 2: Consent Date & Expiration Date
What Must You Do?
Once you have a candidate (or get consent), fill in:
Consent Date: Today (moment of consent)
Consent Retention Period: How long can you keep this candidate? (2 years, 5 years, etc.)
Expiration Date: Carerix calculates automatically (date + period)
Where Do You Fill This In?
Candidate → "Privacy Data" tab (if enabled by administrator)
You'll see a panel:
Privacy Data
📅 Consent Date: [today auto-filled]
📅 Retention Period: [dropdown: 2 years / 5 years / etc.]
📅 Expiration Date: [automatically calculated] ← Carerix does the math!
✅ Consent Status: [Yes / No / Not Yet Asked]
📋 Legal Basis: [Consent / Legitimate Interest / etc.]
Practical Example Step 2
You requested consent from LinkedIn candidate via email. Candidate replies "Yes".
Open candidate record
Go to "Privacy Data" tab
Consent Date = today (auto)
Retention Period = "2 years" (you select)
Expiration Date = "July 1, 2028" (Carerix calculates: 2026 + 2 years)
Consent Status = "Yes"
Done! This candidate is now GDPR-compliant registered
Step 3: Request Consent (via Email Template)
What Must You Do?
Do you have candidates who are still "Not Yet Asked"? You can automatically request consent via email:
How to Send a Template?
Open candidate
Click "Send Email" or "Communication"
Select template: "GDPR - Request Consent" or "GDPR - Consent Request"
Click "Send"
What Happens Then?
Candidate receives email with two links:
[Yes, keep my data] — Status automatically becomes "Yes"
[No, delete my data] — Status automatically becomes "No" and anonymization starts
You don't have to do anything more — everything happens automatically!
✅ Pro tip: Use templates instead of manual emails. Templates have automatic "Yes/No" links so status updates automatically.
Step 4: Monitor — Expiring Consents
What Must You Do?
You need to regularly check which candidates are about to expire. Carerix helps you with filters and reports:
Method 1: Use Filters
In the candidate overview:
Click "Filter" → "Consent Date"
Select: "Expiration Date < 30 days" (or "< 7 days" for urgency)
You see all candidates with expiring consent
Method 2: Reporting
If you want to monitor a group of candidates:
Go to "Reporting" → "Candidate"
Find report: "Candidate Consent History" or "GDPR Status"
Export to CSV
Share with your team or GDPR compliance officer
Method 3: Automatic Notification (via Trigger)
If administrator set up auto triggers, you'll automatically get notified when consent is about to expire. Check your email! 🔔
Practical Example Step 4
You want to know which candidates expire next month.
Go to candidate overview
Filter: "Expiration Date between Aug 15 and Sept 15, 2026"
You see: 47 candidates
Export to CSV
Send email to these candidates: "Do you want us to keep your CV?"
Step 5: Action When Expired - Renew or Anonymize
What Must You Do?
When consent expires, you have two options:
Option 1: Renew Consent
Candidate says "Yes, keep my data longer"
Open candidate
Go to "Privacy Data"
Update "Retention Period": e.g., "2 years" → "5 years"
Expiration Date is automatically recalculated
Done! Candidate is safe for another 5 years
Option 2: Anonymize (Delete Data)
Candidate gives no response or says "No"
What happens during anonymization?
Name, first name → deleted
Email, phone → deleted
Address, social media → deleted
Notes → deleted
BUT RETAINED: Match history, placement duration (for reporting)
How Do You Anonymize?
Manual (per candidate):
Open candidate
Go to "Privacy Data"
Click "Anonymize Candidate"
Confirm (⚠️ This is irreversible!)
Candidate is now anonymous
Bulk (multiple at once):
If you need to anonymize many candidates:
Filter: "Expiration Date < today AND Status = No"
Select all (checkbox)
Click "Bulk Anonymize" (if available)
Confirm
⚠️ Warning: Anonymization is permanent and irreversible! Always check before clicking. We recommend: FIRST send a reminder email before anonymizing.
Practical Example Step 5
Scenario 1: Renew
Candidate "John Smith" expires August 1, 2026
You send reminder email via template
John replies: "Yes, I want my data kept longer"
Open John → Privacy Data → Change period to "5 years"
Expiration Date = now "August 1, 2031"
✅ John stays in system for another 5 years
Scenario 2: Anonymize
Candidate "Maria Santos" expires September 15, 2026
You send reminder email
Maria doesn't respond
October 1: expiration date has passed
Open Maria → Privacy Data → Anonymize
Maria is now "Anonymous" → no PII visible
✅ GDPR-compliant
Frequently Asked Questions
Q: How long should I keep consent?
A: This is determined by your administrator together with your compliance team. Common periods:
2 years: Standard for most recruiters
5 years: For longer retention (advisory, etc.)
7 years: If candidate was hired (legal requirement)
Q: What if I forgot to fill the "source"?
A: Fill it now! Open candidate, add source. This helps later when requesting consent ("We found you on LinkedIn...").
Q: What if candidate responds to my vacancy on LinkedIn?
A: Then:
Source = "LinkedIn"
Status = "Not Yet Asked" (until candidate replies and consents)
Q: What about application form on my website?
A: Perfect! If the form has a checkbox "I agree":
Source = "Website" or "Application Form"
Status = "Yes" (automatically — they already consented)
Period = what you chose at setup
Q: Can I anonymize 100 candidates at once?
A: Yes! Use filters, select all, and choose bulk anonymization (if available). But: Always check first and send a reminder email before bulk action!
Q: Can I just delete candidates from the database?
A: No. Delete ≠ Anonymize. Anonymizing keeps data integrity (match history, placement duration) while removing PII. Deleting is irreversible and unnecessary for GDPR. Always anonymize instead of deleting.
End-User GDPR Checklist
📋 Make Sure You:
☐ Fill source when adding a candidate
☐ Register consent date and period (Privacy Data tab)
☐ Use email templates (not manual) for consent requests
☐ Monitor expiring consents monthly
☐ Renew candidates when they agree
☐ Anonymize candidates when consent expires and they don't respond
☐ NEVER just delete candidates (anonymize instead)
☐ Check audit trail (History tab) if auditors ask questions
All Available Tools
Want to know what all those GDPR tools do? Read: GDPR - Available Tools in Carerix
Related Help Articles
GDPR - Available Tools in Carerix — Overview of all 10 tools
Register Candidate Consent — Details on Privacy Data tab
Email Templates - Yes/No Consent Links — How templates work
Anonymization Tool - Activation and Setup — Technical details
Search & Filter on Consent Date — Filter examples
Overview Consent Date Updates — Reporting
GDPR Information for Administrators — Setup (for admins)
GDPR Flows in Carerix — Workflows & automation
Carerix & GDPR - Complete Guide — Total overview
Questions?
Contact our support team at helpdesk@carerix.com with questions about GDPR-compliant working in Carerix. We're happy to help!
