What it is
GDPR, the General Data Protection Regulation, is the EU law that governs how personal data can be collected, used, stored and deleted. For a recruitment agency that reaches further than the obvious case of a candidate's CV. It covers candidate names, contact details, salary history and interview notes, and it covers the company and contact records built for business development too: a named person's work email, direct-dial number or job title is personal data whether they are a candidate or a hiring manager you are prospecting.
The regulation sets out lawful bases that make processing personal data permissible in the first place, and two matter most on a recruitment desk. Legitimate interest is the basis most agencies rely on to source and match candidates, and to enrich company and contact records for BD, provided the interest is real, necessary and weighed against the individual's rights. Consent is needed for anything beyond that core purpose, such as adding someone to a marketing newsletter. GDPR applies to any agency processing the data of people in the EU or EEA regardless of where the agency itself is based, UK GDPR mirrors it after Brexit, and in Germany employment-related processing, including applicants, sits under Section 26 BDSG alongside it.
A CV database is not an asset until you can say why you are allowed to hold it, and for how long.
Why it matters
A CV database is not a neutral asset, it is a store of personal data that has to be justified, minimised and eventually deleted. GDPR sets no single fixed retention period, but it does require an agency to have a documented reason for how long it keeps a record. In practice that tends to land around six months after a rejection in markets that weigh it against discrimination-claim windows, stretching to two or three years from the last meaningful contact for candidates genuinely kept warm in a talent pool, never indefinitely by default.
Candidates and contacts also hold a right to erasure. A request to be forgotten has to be honoured within a set timeframe, and it has to reach every place the record lives, not just the CRM or ATS of record. That is where AI tools raise the stakes rather than lower them: an enrichment or scraping tool that pulls names, titles and contact details without a defined purpose, or beyond what a task actually needs, creates exposure that did not exist when the same lookup was done by hand, one contact at a time. The fix is not avoiding automation, it is making sure the lawful basis, the minimisation and the audit trail hold up regardless of who, or what, gathered the data.
How boilr handles it
boilr only enriches companies and contacts that match your ICP or sit inside a live signal, not the internet at large, so data minimisation is built into targeting rather than bolted on afterwards. What gets enriched is logged in the Company Brain rather than scattered across a dozen spreadsheets and browser tabs, so there is one place to see what is held on an account and why it was gathered.
Nothing boilr drafts reaches a candidate or a client contact without a consultant reviewing it first, which gives your desk a human checkpoint before a stale, out-of-scope or mistaken record ever turns into outreach. That said, boilr is a tool, not your data protection officer: your agency remains the data controller, responsible for its own lawful basis, retention policy and how it answers a subject access or erasure request. What boilr's guardrails, review step and Company Brain give you is the visibility to answer those questions quickly, not a substitute for having answered them at all.