GDPR and sourcing passive candidates
When you find a candidate who never applied, you're processing personal data about someone who doesn't know it yet. That's lawful when it's done properly, and most of it is good recruiting practice written down. These are the six things to get right, with the Danish regulator's view where it has one. This is practical guidance, not legal advice.
1. Who is responsible
Whoever decides why and how the data is processed is the controller. When an agency or company finds candidates for its own roles, that's the agency or company. A tool that processes candidates on your behalf is a processor, and you need a data processing agreement with it (Article 28).
When an agency presents a candidate to a client, the client becomes a controller for its own processing of that candidate. Tell the candidate before you send their profile on.
2. The legal basis: legitimate interest
Private companies almost always base sourcing on legitimate interest, Article 6(1)(f) of the GDPR. The European Data Protection Board's draft guidelines on legitimate interest set out three conditions, all of which must be met:
- A legitimate interest. Finding the right person for a role, and offering someone a job, is a legitimate interest.
- Necessity. You process only what you need: titles, employers, tenure, location, and a way to reach the person.
- A balance. The person's interests mustn't outweigh yours. What counts: whether the data is professional and was published to be found, whether the approach is relevant, and whether saying no is easy.
A public profile isn't enough on its own. Datatilsynet, the Danish data protection authority, says an employer may use publicly available information that an applicant has published about themselves, on social media for example, but that the principles in Article 5 and the duty to inform still apply. The EU's data protection authorities have warned employers before not to assume they may process data for their own purposes just because a social media profile is public.
Write the assessment down. It takes half a page, and it's the first thing you'll be asked for if anyone asks. Consent isn't a practical basis for the first contact: you can't ask before you've contacted the person, and Datatilsynet notes that consent in an employment setting is rarely freely given.
3. Only what you need
Process only data that's relevant to the role (Article 5(1)(c)). Stay away from special categories such as health, religion, ethnic origin, political opinions, union membership and sexual orientation (Article 9), and from the person's private social media. Data in a database can be out of date, so check it before you judge on it.
4. The duty to inform: Article 14
Datatilsynet uses recruitment firms as its own example: they often collect data about the people they're trying to recruit from someone other than those people, and must therefore give them the Article 14 information. That means who you are, why you're processing their data and on what basis, which legitimate interest you're pursuing, what kinds of data you hold, where it came from, who receives it, how long you keep it, what rights they have, and that they can complain to the data protection authority.
Article 14(3) sets the timing:
- within a reasonable period, and at the latest within one month;
- at the latest at the first contact, if you use the data to contact the person;
- at the latest when the data is first disclosed, if you pass it to someone else, such as a client.
Datatilsynet says a reasonable period normally means within 10 days. If you already know when you find someone that you'll be writing to them shortly, you may wait and give the information in that message, but never later than one month. The right to object must be brought to the person's attention explicitly, clearly and separately from other information, at the latest at the first contact (Article 21(4)).
In practice, a short line with a link to your privacy notice in the first message covers most of it. Make sure the notice actually covers sourcing: your sources, your legal basis, how long you keep data, and how to opt out.
Candidates you find but never contact are still covered by the time limit. The exemption for "disproportionate effort" in Article 14(5)(b) is, according to the EU transparency guidelines, to be read narrowly and not relied on routinely. If you do rely on it, you must make the information publicly available and be able to show your balancing. The safest course is to delete the people you don't contact, quickly.
5. Retention
Data may not be kept longer than the purpose requires (Article 5(1)(e)). Set fixed limits:
- Found but not contacted: delete when the search is over.
- Contacted and turned down: keep what you need to show why they didn't go further, for as short a time as possible. Datatilsynet accepts up to 3 years for applicants who didn't get the job, because they can complain to the Board of Equal Treatment, but only where it's actually necessary.
- For future roles: to keep a candidate for another role, you need their consent, and you must say for how long and that they can withdraw it.
Don't delete everything at once either. In a Danish case from January 2026, an employer couldn't document why an applicant for a job advertised as "yngre salgsassistent" (younger sales assistant) had been turned down, because the applications had been deleted "due to GDPR rules". The applicant was awarded DKK 25,000.
6. Candidates' rights and the do-not-contact list
Candidates have the right of access (Article 15), rectification (16), erasure (17), restriction (18) and to object (21). You must respond without undue delay and within one month at most. You can extend by two further months where necessary, but you must say so within the first month (Article 12(3)).
If a candidate objects to processing based on legitimate interest, you must stop unless you can demonstrate compelling legitimate grounds that override theirs. In sourcing you rarely will, so stop.
A no has to be remembered, or a colleague will write again. Keep a do-not-contact list with the minimum needed to recognise the person, and check it before anyone on the team sends anything. We found no statement from Datatilsynet on such lists in recruitment, and in 2022 it criticised a list of withdrawn consents in a marketing case. For marketing, the UK regulator, the ICO, advises keeping just enough to respect an objection, and France's CNIL advises keeping it for at least 3 years, ideally as hashes. Write down why the list is needed, and keep no more than that.
Checklist
- Is it written down who the controller is, and do you have processing agreements with your tools?
- Is your legitimate interest assessment written down?
- Do you process professional data only?
- Does the candidate get the Article 14 information in your first message at the latest, with the right to object set out separately?
- Are there fixed deletion deadlines?
- Can you answer a request within a month?
- Is the do-not-contact list checked before every send?
How Navigent handles it
In Navigent, you're the controller and Navigent is the processor. The duty to inform is yours, and Navigent adds no privacy line to your messages. If you want a link in them, you write it into your own template. Candidates who aren't on a shortlist for an active role are deleted 90 days after they were last fetched, and closing a role deletes its shortlist 90 days later. The do-not-contact list covers the whole organisation, people and companies alike. A reply in which the candidate opts out puts them on it, and the list is enforced both in search and at send. Navigent offers candidates one thing directly: the "Remove me from Navigent" page. A confirmed removal deletes the person across all customers, and they're never fetched, assessed or contacted again. Everything else about a candidate's rights, access included, rests with you as the controller.
Read more about how Navigent handles data on Security.
Sources
- Regulation (EU) 2016/679 (GDPR), Articles 5, 6, 9, 12, 14, 15–18, 21 and 28: https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (checked 30 September 2026)
- European Data Protection Board, Guidelines 1/2024 on legitimate interest, draft of 8 October 2024: https://www.edpb.europa.eu/our-work-tools/documents/public-consultations/2024/guidelines-12024-processing-personal-data-based_en (checked 30 September 2026)
- Article 29 Working Party, Guidelines on transparency (WP260 rev.01), paragraphs 27–28 and 57–64: https://ec.europa.eu/newsroom/article29/redirection/document/51025 (checked 30 September 2026)
- Article 29 Working Party, Opinion 2/2017 on data processing at work, section 5.1: https://cdn.datatilsynet.dk/datatilsynet/media/7623/wp249_da.pdf (checked 30 September 2026)
- Datatilsynet, "Databeskyttelse i ansættelsesforhold", March 2023, sections 1.2, 2.2 and 2.3, and its page on keeping applicants' data (in Danish): https://www.datatilsynet.dk/regler-og-vejledning/databeskyttelse-i-forbindelse-med-ansaettelsesforhold (checked 30 September 2026)
- Datatilsynet, guidance on data subjects' rights, section 3.3.2 (in Danish): https://www.datatilsynet.dk/Media/C/0/Registreredes%20rettigheder.pdf (checked 30 September 2026)
- Datatilsynet, guidance on codes of conduct, June 2023, example 2 (in Danish): https://www.datatilsynet.dk/Media/638233755631220855/Vejledning%20om%20adf%C3%A6rdskodekser.pdf (checked 30 September 2026)
- Datatilsynet, decision on SmartResponse A/S, 30 September 2022 (in Danish): https://www.datatilsynet.dk/afgoerelser/afgoerelser/2022/sep/smartresponses-behandling-af-personoplysninger-i-forbindelse-med-udbud-af-internetkonkurrencer (checked 30 September 2026)
- Board of Equal Treatment (Ligebehandlingsnævnet), decision no. 9416 of 14 January 2026 (in Danish): https://www.retsinformation.dk/eli/accn/W20260941625 (checked 30 September 2026)
- CNIL, "Comment utiliser une liste repoussoir", 10 June 2026 (in French): https://www.cnil.fr/fr/comment-utiliser-une-liste-repoussoir-pour-respecter-lopposition-la-prospection (checked 30 September 2026)
- ICO, "Right to object": https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-object/ (checked 30 September 2026)