Skip to main content

Working GDPR Compliant in Carerix

Practical guide for recruiters and end-users - How to work GDPR-compliant in Carerix

Working GDPR Compliant in Carerix: This article describes the practical steps you (recruiter, team lead, or basic user) must take to ensure you manage clients and candidates in a GDPR-compliant manner.

ℹ️ Who is this for? This article is for recruiters, sourcers, team leads, and HR staff. If you're an administrator who wants to set up GDPR tools, see GDPR Information for Administrators.

GDPR Workflow - Step by Step

You work GDPR-compliant by following this workflow:

  1. Add Candidate: Register the source and request consent

  2. Fill Consent Date: Record when and for how long consent applies

  3. Monitor: Track expiring consents and take action

  4. Anonymize or Renew: Act when consent expires

Step 1: Add Candidate & Register Source

What Must You Do?

When you add a candidate to Carerix (manually, via LinkedIn, via application form), make sure:

  • Source is filled: Where did you find this candidate? (LinkedIn, job board, CV database, referral, etc.)

  • Consent Status set: "Not Yet Asked", "Yes", or "No"

  • Legal Basis chosen: Consent, Legitimate Interest, etc. (administrator determines this)

Practical Example

Scenario 1: LinkedIn sourcing

  • You find candidate on LinkedIn and add them

  • Source = "LinkedIn"

  • Status = "Not Yet Asked" (you haven't requested consent yet)

  • Legal Basis = "Consent" (or whatever administrator set)

Scenario 2: Application Form

  • Candidate fills your website form with checkbox "I agree"

  • Source = "Website" or "Career Site"

  • Status = "Yes" (automatically — candidate already agreed)

  • Legal Basis = automatically filled (administrator mapping)

💡 Tip: Social Browser

You can use the Social Browser plugin to search LinkedIn without photos. This helps with GDPR (less biometric data) and prevents bias. Learn about all tools.

Step 2: Consent Date & Expiration Date

What Must You Do?

Once you have a candidate (or get consent), fill in:

  • Consent Date: Today (moment of consent)

  • Consent Retention Period: How long can you keep this candidate? (2 years, 5 years, etc.)

  • Expiration Date: Carerix calculates automatically (date + period)

Where Do You Fill This In?

Candidate → "Privacy Data" tab (if enabled by administrator)

You'll see a panel:

Privacy Data

  • 📅 Consent Date: [today auto-filled]

  • 📅 Retention Period: [dropdown: 2 years / 5 years / etc.]

  • 📅 Expiration Date: [automatically calculated] ← Carerix does the math!

  • Consent Status: [Yes / No / Not Yet Asked]

  • 📋 Legal Basis: [Consent / Legitimate Interest / etc.]

Practical Example Step 2

You requested consent from LinkedIn candidate via email. Candidate replies "Yes".

  1. Open candidate record

  2. Go to "Privacy Data" tab

  3. Consent Date = today (auto)

  4. Retention Period = "2 years" (you select)

  5. Expiration Date = "July 1, 2028" (Carerix calculates: 2026 + 2 years)

  6. Consent Status = "Yes"

  7. Done! This candidate is now GDPR-compliant registered

Step 3: Request Consent (via Email Template)

What Must You Do?

Do you have candidates who are still "Not Yet Asked"? You can automatically request consent via email:

How to Send a Template?

  1. Open candidate

  2. Click "Send Email" or "Communication"

  3. Select template: "GDPR - Request Consent" or "GDPR - Consent Request"

  4. Click "Send"

What Happens Then?

Candidate receives email with two links:

  • [Yes, keep my data] — Status automatically becomes "Yes"

  • [No, delete my data] — Status automatically becomes "No" and anonymization starts

You don't have to do anything more — everything happens automatically!

✅ Pro tip: Use templates instead of manual emails. Templates have automatic "Yes/No" links so status updates automatically.

Step 4: Monitor — Expiring Consents

What Must You Do?

You need to regularly check which candidates are about to expire. Carerix helps you with filters and reports:

Method 1: Use Filters

In the candidate overview:

  1. Click "Filter" → "Consent Date"

  2. Select: "Expiration Date < 30 days" (or "< 7 days" for urgency)

  3. You see all candidates with expiring consent

Method 2: Reporting

If you want to monitor a group of candidates:

  1. Go to "Reporting" → "Candidate"

  2. Find report: "Candidate Consent History" or "GDPR Status"

  3. Export to CSV

  4. Share with your team or GDPR compliance officer

Method 3: Automatic Notification (via Trigger)

If administrator set up auto triggers, you'll automatically get notified when consent is about to expire. Check your email! 🔔

Practical Example Step 4

You want to know which candidates expire next month.

  1. Go to candidate overview

  2. Filter: "Expiration Date between Aug 15 and Sept 15, 2026"

  3. You see: 47 candidates

  4. Export to CSV

  5. Send email to these candidates: "Do you want us to keep your CV?"

Step 5: Action When Expired - Renew or Anonymize

What Must You Do?

When consent expires, you have two options:

Option 1: Renew Consent

Candidate says "Yes, keep my data longer"

  1. Open candidate

  2. Go to "Privacy Data"

  3. Update "Retention Period": e.g., "2 years" → "5 years"

  4. Expiration Date is automatically recalculated

  5. Done! Candidate is safe for another 5 years

Option 2: Anonymize (Delete Data)

Candidate gives no response or says "No"

What happens during anonymization?

  • Name, first name → deleted

  • Email, phone → deleted

  • Address, social media → deleted

  • Notes → deleted

  • BUT RETAINED: Match history, placement duration (for reporting)

How Do You Anonymize?

Manual (per candidate):

  1. Open candidate

  2. Go to "Privacy Data"

  3. Click "Anonymize Candidate"

  4. Confirm (⚠️ This is irreversible!)

  5. Candidate is now anonymous

Bulk (multiple at once):

If you need to anonymize many candidates:

  1. Filter: "Expiration Date < today AND Status = No"

  2. Select all (checkbox)

  3. Click "Bulk Anonymize" (if available)

  4. Confirm

⚠️ Warning: Anonymization is permanent and irreversible! Always check before clicking. We recommend: FIRST send a reminder email before anonymizing.

Practical Example Step 5

Scenario 1: Renew

  1. Candidate "John Smith" expires August 1, 2026

  2. You send reminder email via template

  3. John replies: "Yes, I want my data kept longer"

  4. Open John → Privacy Data → Change period to "5 years"

  5. Expiration Date = now "August 1, 2031"

  6. ✅ John stays in system for another 5 years

Scenario 2: Anonymize

  1. Candidate "Maria Santos" expires September 15, 2026

  2. You send reminder email

  3. Maria doesn't respond

  4. October 1: expiration date has passed

  5. Open Maria → Privacy Data → Anonymize

  6. Maria is now "Anonymous" → no PII visible

  7. ✅ GDPR-compliant

Frequently Asked Questions

Q: How long should I keep consent?

A: This is determined by your administrator together with your compliance team. Common periods:

  • 2 years: Standard for most recruiters

  • 5 years: For longer retention (advisory, etc.)

  • 7 years: If candidate was hired (legal requirement)

Q: What if I forgot to fill the "source"?

A: Fill it now! Open candidate, add source. This helps later when requesting consent ("We found you on LinkedIn...").

Q: What if candidate responds to my vacancy on LinkedIn?

A: Then:

  • Source = "LinkedIn"

  • Status = "Not Yet Asked" (until candidate replies and consents)

Q: What about application form on my website?

A: Perfect! If the form has a checkbox "I agree":

  • Source = "Website" or "Application Form"

  • Status = "Yes" (automatically — they already consented)

  • Period = what you chose at setup

Q: Can I anonymize 100 candidates at once?

A: Yes! Use filters, select all, and choose bulk anonymization (if available). But: Always check first and send a reminder email before bulk action!

Q: Can I just delete candidates from the database?

A: No. Delete ≠ Anonymize. Anonymizing keeps data integrity (match history, placement duration) while removing PII. Deleting is irreversible and unnecessary for GDPR. Always anonymize instead of deleting.

End-User GDPR Checklist

📋 Make Sure You:

☐ Fill source when adding a candidate

☐ Register consent date and period (Privacy Data tab)

☐ Use email templates (not manual) for consent requests

☐ Monitor expiring consents monthly

☐ Renew candidates when they agree

☐ Anonymize candidates when consent expires and they don't respond

☐ NEVER just delete candidates (anonymize instead)

☐ Check audit trail (History tab) if auditors ask questions

All Available Tools

Want to know what all those GDPR tools do? Read: GDPR - Available Tools in Carerix

Related Help Articles

Questions?

Contact our support team at helpdesk@carerix.com with questions about GDPR-compliant working in Carerix. We're happy to help!

Did this answer your question?