Skip to content
Guide

GDPR and AI in recruitment: where does your candidate data go?

AI in recruitment touches personal data. CVs, contact details, interview notes, sometimes an intake you ask it to summarise. So before you switch anything on, you want one thing settled: where does that data go and who can reach it? This page lays out what AI in a recruitment process actually touches, where that data stays, and what to ask a builder before you say yes. Plain, no legal jargon.

By Martin Veltman

What candidate data does AI touch?

An AI system in recruitment works with the data already sitting in your ATS. Name and contact details, the CV content, work history, the notes a recruiter left behind. On an intake, sometimes a transcript or a summary of the call. Nothing beyond that. The system has no need to know someone's religion, health or background, and those fields have no place in a judgement about a CV. In the CV checker we built for Forta, the prompts block that kind of data outright: it never goes in and it is never stored. That is a choice you make up front, not something you patch afterwards.

The short version: AI sees no more than a recruiter working the same candidate would. Just faster.

Where does your data sit, and does it stay in the EU?

Short answer: in the EU, and ideally in your own environment. Your candidates stay where they already were. The systems we build run inside your existing ATS, whether that is Bullhorn, Carerix, Easyflex or OTYS. The AI model runs through AWS Bedrock in Paris, region eu-west-3, not on a server in the US. Hosting sits on Vercel or a dedicated Hetzner machine, both inside the EU. So does the database.

This is exactly where a lot of off-the-shelf AI tools differ: they ship your input to a server outside Europe, often in the United States. It does not have to work that way. Ask about it before you switch anything on, because it is hard to walk back later.

Does the AI train on your candidates?

This is the question that trips people up. The answer you want is no. Under the business terms of AWS Bedrock and Anthropic, what you put into the model is not used to train that model. A candidate you screen today does not surface tomorrow in the answer another agency gets.

Honest about the edge: whether this holds depends on the terms your vendor signs. With a consumer tool off the shelf you cannot be sure. With a builder who puts it in writing you can. Get it into the data processing agreement, so you never have to take anyone's word for it.

The data processing agreement and the GDPR, in plain terms

Let's separate the roles. You are the controller: it is your candidate data and, under the GDPR, your responsibility. The builder is the processor and acts only on your instruction. The data processing agreement (DPA) puts that on paper: which data, which sub-processors and where they sit, that nothing is used for training, what happens in a breach, and how long data stays. The sub-processors are no secret. For our builds that means AWS Bedrock for the model, Vercel or Hetzner for hosting, and an EU database. All inside the EU, each with its own purpose.

Be wary if anyone promises you are "fully GDPR compliant". No one can, because that hat stays on you as the controller, not your vendor. What a builder can arrange is the list above: processing in the EU, no training, a short retention window, and a DPA your lawyer can actually read.

Two things make the difference and rarely reach the brochure. Retention: at Forta, a cron wiped the raw CVs and questionnaires after 30 days. What you do not keep cannot leak. And security: keys are stored encrypted, not in the source code, and real candidate data never sits in a git repo. What sits there is invented test data, not your candidates.

AI and privacy in recruitment: five questions for any vendor

Put these five questions in an email before you sign. A good vendor answers within a day and without dancing around it. If someone talks a question away, you have learned enough.

1. Where does the AI model run, and does the data stay in the EU?

You want a concrete answer with a region, not "in the cloud". A good one: AWS Bedrock, eu-west-3, Paris.

2. Do you train on my data?

The answer has to be no, and it has to be in the data processing agreement, not just an email.

3. Who are the sub-processors and where do they sit?

Ask for the list with a country per party. If anyone is outside the EU, you want to know why.

4. Do I get a data processing agreement?

Yes is the only good answer. Being able to read it up front is better.

5. How long do you keep the data and how do you delete it?

You are after a period and a method, say a cron that wipes raw data after 30 days. Not "as long as needed".

These questions work with us, and just as well with anyone else. They cost you five minutes and save you a lot of hassle later.

What this means for your agency

Whether you do search and selection or staffing, the base is the same: EU processing, no training, a DPA, and no keeping data longer than needed. Where the time is won differs per agency, which you can read in AI for staffing agencies and AI for recruitment agencies. And to see how this fits automating recruitment with AI as a whole, start there.

Want this on paper for your own agency? Book a call. We will walk through the DPA and the five questions with you, no pitch.

Not sure about your candidate data?

Book a call. We run your setup past the five questions and put the arrangements on paper.