The boilr Agent is live Read now

GDPR governs every candidate record.

Lawful basis, minimisation, erasure, on every desk.

GDPR is the EU law that decides whether a CV, a contact record or an enriched company profile can be collected, held and used at all.

recruiter-lexikon / gdpr
G
GDPR
General Data Protection Regulation
Defined
Definition

The EU regulation governing how personal data, including candidate CVs, contact details and enriched company records, must be collected, processed, stored and deleted, with a lawful basis, data minimisation and the right to erasure at its core.

At a glance
Term General Data Protection Regulation
Used for Lawful handling of candidate and contact data
In boilr Scoped enrichment, logged, reviewed before it sends
b
boilr turns this term into a task
Defined here · operationalised by your AI employee

GDPR, explained for the desk.

What it is, why it matters, and how your AI employee runs it.

What it is

GDPR, the General Data Protection Regulation, is the EU law that governs how personal data can be collected, used, stored and deleted. For a recruitment agency that reaches further than the obvious case of a candidate's CV. It covers candidate names, contact details, salary history and interview notes, and it covers the company and contact records built for business development too: a named person's work email, direct-dial number or job title is personal data whether they are a candidate or a hiring manager you are prospecting.

The regulation sets out lawful bases that make processing personal data permissible in the first place, and two matter most on a recruitment desk. Legitimate interest is the basis most agencies rely on to source and match candidates, and to enrich company and contact records for BD, provided the interest is real, necessary and weighed against the individual's rights. Consent is needed for anything beyond that core purpose, such as adding someone to a marketing newsletter. GDPR applies to any agency processing the data of people in the EU or EEA regardless of where the agency itself is based, UK GDPR mirrors it after Brexit, and in Germany employment-related processing, including applicants, sits under Section 26 BDSG alongside it.

A CV database is not an asset until you can say why you are allowed to hold it, and for how long.

Why it matters

A CV database is not a neutral asset, it is a store of personal data that has to be justified, minimised and eventually deleted. GDPR sets no single fixed retention period, but it does require an agency to have a documented reason for how long it keeps a record. In practice that tends to land around six months after a rejection in markets that weigh it against discrimination-claim windows, stretching to two or three years from the last meaningful contact for candidates genuinely kept warm in a talent pool, never indefinitely by default.

Candidates and contacts also hold a right to erasure. A request to be forgotten has to be honoured within a set timeframe, and it has to reach every place the record lives, not just the CRM or ATS of record. That is where AI tools raise the stakes rather than lower them: an enrichment or scraping tool that pulls names, titles and contact details without a defined purpose, or beyond what a task actually needs, creates exposure that did not exist when the same lookup was done by hand, one contact at a time. The fix is not avoiding automation, it is making sure the lawful basis, the minimisation and the audit trail hold up regardless of who, or what, gathered the data.

How boilr handles it

boilr only enriches companies and contacts that match your ICP or sit inside a live signal, not the internet at large, so data minimisation is built into targeting rather than bolted on afterwards. What gets enriched is logged in the Company Brain rather than scattered across a dozen spreadsheets and browser tabs, so there is one place to see what is held on an account and why it was gathered.

Nothing boilr drafts reaches a candidate or a client contact without a consultant reviewing it first, which gives your desk a human checkpoint before a stale, out-of-scope or mistaken record ever turns into outreach. That said, boilr is a tool, not your data protection officer: your agency remains the data controller, responsible for its own lawful basis, retention policy and how it answers a subject access or erasure request. What boilr's guardrails, review step and Company Brain give you is the visibility to answer those questions quickly, not a substitute for having answered them at all.

Questions, answered.

Everything a working consultant asks about gdpr, and how boilr puts it to work.

Is legitimate interest a valid lawful basis for sourcing candidates and enriching contact data?

Yes, for most recruitment desks it is the basis relied on, both for candidate sourcing and for building out company and contact records for business development. It is not automatic, though: you have to be able to show the interest is real, that the processing is necessary to achieve it, and that you weighed it against the individual's rights before relying on it. Consent, not legitimate interest, is the right basis for anything beyond that core purpose, such as a marketing newsletter.

How long can a recruitment agency keep a candidate's CV under GDPR?

GDPR itself sets no fixed number, only a requirement that retention be justified and documented. In Germany, six months after a role closes is common practice, reflecting the window in which a rejected candidate could raise a discrimination claim. For candidates genuinely kept warm in a talent pool, two to three years from the last meaningful contact is a more typical ceiling, after which the record should be deleted or refreshed with a new basis to hold it.

What has to happen when a candidate asks to be forgotten?

The request has to be honoured within a set timeframe, one month under the regulation, unless a genuine exception applies, such as an active contract or a live legal claim. The harder part is usually operational, not legal: the record has to be located and removed everywhere it lives, the ATS, the CRM, any enrichment tool and any export, not just the system someone happens to check first.

Does GDPR apply to company and contact data used for business development, not just candidates?

Yes. A hiring manager's or founder's name attached to a work email, a direct-dial number or a job title is personal data, whether they are a candidate or a prospect you are targeting for BD. Legitimate interest, with a documented balancing test, is the basis most agencies rely on for that kind of enrichment, and the same minimisation and retention discipline applies: enrich what a specific account or signal needs, not every contact you can find.

How does boilr help my agency stay within GDPR in practice?

boilr scopes enrichment to accounts that match your ICP or sit inside a live signal rather than pulling data broadly, logs what it holds in the Company Brain so you can see it in one place, and holds every task for your review before anything is sent. Your agency remains the data controller responsible for its own lawful basis and retention policy, boilr's job is to make that easier to stand behind, not to make the decision for you.

Helen Wright
Boilr gave us the BD structure and follow-up support to sign our first client and secure a job brief in under a month.
Helen Wright
Managing Director, 923 Jobs

Enrich within scope. Review before it sends.

boilr scopes every enrichment to your ICP and holds every task for your review before it reaches a candidate or a client. One AI sales employee per consultant, built to work inside your agency's compliance boundaries, not around them.