Skip to main content

GDPR Information for Administrators

Step-by-step setup guide for implementing GDPR/AVG processes in Carerix

Welcome, Administrator! This article provides a complete step-by-step guide for implementing GDPR compliance in Carerix. As an administrator, you are responsible for activating the right tools, configuration, and monitoring. Follow this guide to prepare your organization for GDPR.

Getting Started — Setup Checklist

Execute the following steps before your organization goes live with GDPR-enabled processes:

☐ Determine your organization-wide GDPR strategy (which basis, which retention periods)

☐ Activate GDPR tools in Carerix (Privacy Settings)

☐ Configure legal bases and retention periods (adjust table)

☐ Set up anonymization (determine which fields to retain)

☐ Prepare email templates (consent and reminder emails)

☐ Configure triggers for automated actions

☐ Assign user roles with appropriate rights

☐ Test workflows on a test environment

☐ Document your processes in a processing register

☐ Train your team on GDPR processes

Step 1: Determine Your GDPR Strategy

Questions for Your Strategy

Before configuring Carerix, you must determine internally:

  • Which basis is primary? Do you rely on consent, or on legitimate interest / legal obligation?

  • What are your retention periods? How long do you keep candidates based on consent? (typically 2 years). How long after employment? (typically 7 years for tax)

  • What personal data do you process? Only name/email, or also photo, social media profiles, references?

  • Who takes action upon expiration? Automatically anonymize, or manual per team?

  • How do you document consent? Via application form (direct) or via email (indirect)?

💡 Tip: Document these choices in a "GDPR Policy" document that you share internally with your team. This helps ensure consistent work and gives you clarity during inspections.

Step 2: Activate GDPR Tools in Carerix

Turn On Privacy Settings

GDPR features in Carerix are off by default. You must explicitly enable them:

  1. Log in as Mainuser (Administrator)

  2. Go to Settings → Application → Privacy Settings

  3. Turn "Use Privacy Restrictions" ON

  4. Save and restart the application (may take a few minutes)

  5. Verify that new fields appear in candidate record:

    • Legal Basis

    • Basis Expiration Date

    • Consent Status

ℹ️ Important: After enabling Privacy Settings, all users can see GDPR fields, but only users with specific roles (see Step 6) can edit them.

Step 3: Configure Legal Bases and Retention Periods

Adjust the "Legal Basis" Table

In Carerix, "Legal Basis" is a table with fixed values. You don't need to change them, but can add extra options:

Standard options:

  • Legal Obligation

  • Contract Performance

  • Legitimate Interest

  • Consent

  • No Consent

Add custom options? You can add extras like:

  • "Employee Referral" (for employee referrals)

  • "Marketing" (for jobseeker database)

  • "Archive" (old candidates, no active processing)

Configure the "Retention Period" Table

This is critical. You set here how long candidates are kept:

  1. Go to Settings → Tables → Retention Period

  2. Create records for your typical scenarios:

    • Consent (2 years): "2 year consent"

    • Employment Contract (3 years): "Employment contract 3y"

    • Legal (7 years): "Tax retention 7y"

  3. For each record, enter:

    • Name (for your team)

    • Months (retention period in months: 24 for 2 years, 36 for 3 years, 84 for 7 years)

    • Description (brief note)

  4. Save. Carerix automatically calculates the expiration date based on today + period

💡 Best Practice: Use English names for retention period records so they remain clear across multiple languages. Example: "Consent 2Y" instead of "Toestemming (2 jaren)"

Step 4: Set Up Anonymization

Which Fields Are Retained During Anonymization?

This is important: anonymization removes personal data, but you can determine what remains for reporting:

Typically deleted:

  • First name, last name

  • Email address, phone number

  • Address

  • All consent fields

  • All notes and communication

Typically retained (for reporting):

  • Candidate ID (internal reference)

  • Creation date

  • Legal Basis (for audit)

  • Anonymization date

  • Match history (which positions matched)

  • Placement data (employer, duration, period)

Configure Anonymization Settings

  1. Go to Settings → Application → Anonymization

  2. Per field group: choose "Delete" or "Retain"

  3. Typical choices:

    • Personal Data (name, email): Delete

    • Address: Delete

    • Consent: Delete

    • Match Data: Retain

    • Placement: Retain

  4. Test on test environment before going live

⚠️ Warning: Once you save anonymization settings, administrators can anonymize candidates. This is irreversible. Ensure your team understands the process well.

Step 5: Prepare Email Templates

Which Email Templates Are Needed?

For GDPR workflows, you need at least these email templates:

  • "Request Initial Consent (GDPR)" — For candidates found indirectly (LinkedIn)

  • "Request Consent Renewal (GDPR)" — Reminder that consent is about to expire

  • "Consent Renewal" — Candidate reactive after absence, ask again

  • "Consent Withdrawal Confirmation" — Confirmation that candidate said "No"

Set Up Templates

  1. Go to Library → Email Templates

  2. Search for GDPR templates (filter by "GDPR")

  3. Activate the templates you need (click "Activate")

  4. Customize content to your operations (e.g., sign with your company name)

  5. Test by sending yourself a test email

Important: These templates contain automatic Yes/No links. When candidate clicks "Yes", consent is automatically recorded in Carerix.

Step 6: Set Up Triggers for Automation

Common GDPR Triggers

Triggers execute automated actions based on conditions. Some GDPR examples:

Trigger 1: Reminder Email on Expiration

  • IF: "Basis expiration date < 30 days"

  • THEN: "Send email 'Request Consent Renewal'"

Trigger 2: Change Status on Hire

  • IF: "Placement approved"

  • THEN: "Change Legal Basis to 'Contract Performance'; Change Retention Period to '3 years'"

Trigger 3: Prepare Anonymization

  • IF: "Basis expiration date < today" AND "No contact for 3 months"

  • THEN: "Add to 'Anonymization Candidates' group" (so you anonymize them in bulk weekly)

Configure Triggers

  1. Go to Settings → Application → Automation → Triggers

  2. Click "New"

  3. Define condition (IF) and action (THEN)

  4. Set trigger to "Active"

  5. Test first on small group (add filter to match only test candidates)

  6. Then expand to all candidates

ℹ️ Important: Triggers check on a daily or hourly basis, depending on settings. Always test first on test environment!

Step 7: User Roles with GDPR Rights

Which Roles Should Have GDPR Rights?

Not everyone needs to see or edit GDPR data. Determine per role:

  • Recruiter: Can read consent status, but cannot anonymize

  • Team Lead: Can give consent, can add candidates to anonymization queue

  • Administrator: Can do everything: edit GDPR fields, anonymize, adjust triggers

  • HR Manager: Can anonymize and view reporting

Configure Roles

  1. Go to Settings → Users → Roles

  2. Per role: set rights for "GDPR" (depending on Carerix version)

  3. Typical permissions:

    • "Read GDPR Fields": Who can see status?

    • "Edit GDPR Fields": Who can change status?

    • "Anonymize": Who can anonymize candidates?

  4. Assign roles to users

Step 8: Set Up Monitoring and Reporting

This report shows all candidates with their consent status. Run this weekly:

  1. Go to Reporting → Candidate

  2. Search for "Consent History" or "GDPR Status" report

  3. Filter on: "Basis expiration date < 30 days" or "No consent"

  4. Export to CSV, send to your GDPR team

Filters in Candidate List

Create these filters in your candidate list view:

  • "Basis expiration date < 30 days": Candidates needing action soon

  • "Legal Basis = No Consent": Candidates who haven't given consent yet

  • "Anonymization Status = In Queue": Candidates awaiting anonymization

Step 9: Audit Trail and Compliance Logging

What Should I Log?

For legal compliance, you must document these actions:

  • Date consent given (automatic)

  • Change of legal basis (who, when, why)

  • Anonymization (who, when, reason)

  • Deletion requests (date received, follow-up date)

How to Log

Option 1: Carerix Logging (Automatic)

  • Carerix automatically saves all GDPR field changes to the audit log

  • Go to Candidate → History to see all changes

Option 2: External Register

  • Keep an Excel/Google Sheet with all GDPR actions

  • Columns: Date | Candidate | Action | By Whom | Reason | Status

  • This helps during inspections by supervisory authorities

Step 10: Train Your Team

Training Checklist

☐ Recruiter training: "How to request and record consent"

☐ Team Lead training: "How to monitor GDPR status and recognize expiring candidates"

☐ Administrator training: "How to anonymize, adjust triggers, run reporting"

☐ HR training: "What are our GDPR policies and retention periods"

☐ Documentation: Internal wiki with screenshots and step-by-step guides

Related Help Articles

Ready? Final Checklist

☑ Privacy Settings enabled

☑ Legal bases and retention periods configured

☑ Anonymization set up (fields determined)

☑ Email templates activated and customized

☑ Triggers configured and tested

☑ User roles configured

☑ Reporting set up and tested

☑ Audit logging configured

☑ Team trained

☑ Test run with small group executed

☑ Live!

Need Help?

This setup can be complex. Contact our support team at helpdesk@carerix.com with questions about configuration, triggers, or anonymization. We're happy to help you establish a GDPR-compliant Carerix setup.

Did this answer your question?