GDPR and AI Recruiting: What European Recruiters Must Know in 2026
AI sourcing tools have made it faster than ever to find and contact candidates across Europe. But speed creates a compliance problem. The more automated your outreach, the more GDPR exposure you carry — and in 2026, data protection authorities are paying close attention to how recruiters use AI-powered platforms.
- Why GDPR Matters More Than Ever for Recruiters
- The Six Lawful Bases and Which One Applies to Sourcing
- What AI Sourcing Tools Must Provide to Keep You Compliant
- Outreach Compliance: Email, LinkedIn, SMS, and WhatsApp
- Transparency and Candidate Notice
- Automated Decision-Making in AI Recruiting
- How Kalent Approaches Compliance
- A Practical GDPR Compliance Checklist for AI Sourcing in 2026
- FAQs
Why GDPR Matters More Than Ever for Recruiters
GDPR has been in force since 2018, but enforcement has intensified. Supervisory authorities across France, Germany, the Netherlands, and Ireland have all issued fines or formal guidance touching on HR data processing in recent years. In 2026, AI-assisted sourcing is squarely in scope.
When you source a candidate, you are processing personal data. Their name, job title, email address, phone number, and LinkedIn profile all qualify. The moment you store, search, enrich, or contact that data, GDPR applies — regardless of whether the candidate applied to you or you found them through a sourcing tool.
The question regulators ask: do you have a lawful basis for processing this data, and did the candidate know you were doing it?
The Six Lawful Bases and Which One Applies to Sourcing
GDPR requires every act of personal data processing to rest on one of six lawful bases. For recruiting, two are most relevant.
Legitimate interest is the most commonly used basis for passive candidate outreach. It allows you to process personal data without consent if your interest is genuine, proportionate, and does not override the individual's rights. Sourcing a software engineer for an open role can qualify, provided you document your reasoning and give candidates an easy way to opt out.
Consent is a higher bar. It requires a freely given, specific, informed, and unambiguous action from the candidate. Pre-ticked boxes and implied consent do not count. For most proactive sourcing scenarios, consent is impractical to obtain before first contact — which is why legitimate interest is the default.
The practical implication: before you send that first LinkedIn message or SMS, you need a written legitimate interest assessment (LIA) on file. It does not need to be long, but it does need to exist.
What AI Sourcing Tools Must Provide to Keep You Compliant
Not all sourcing platforms handle compliance the same way. When you use an AI tool to find and contact candidates, you are typically acting as the data controller, and the platform acts as a data processor. That means the platform must offer a Data Processing Agreement (DPA) — and you must sign it.
Beyond the DPA, there are four things to verify before using any AI sourcing platform in Europe.
1. Data Origin and Lawfulness
Where did the profiles come from? A reputable platform sources data from publicly available professional networks and applies its own compliance checks before making profiles searchable. Ask your vendor how profiles enter the database and whether that data collection process meets GDPR standards.
2. Data Residency and Transfers
If you are based in France or Germany and the platform stores data on US servers, you are dealing with an international data transfer. Post-Schrems II, this requires either Standard Contractual Clauses (SCCs) or another approved transfer mechanism. Check where your vendor stores data and whether their DPA covers cross-border transfers.
3. Retention Limits
GDPR requires that personal data is not kept longer than necessary. If you add a candidate to a talent pool and never contact them, how long does that profile sit in your system? You need a documented retention policy, and your platform should support deletion or anonymisation workflows.
4. Candidate Rights Fulfilment
Candidates have the right to access, correct, and erase their data. If a sourced candidate emails you asking what you hold on them, you need to respond within 30 days. Your sourcing tool should make it straightforward to locate and delete individual records on request.
Outreach Compliance: Email, LinkedIn, SMS, and WhatsApp
Multi-channel outreach raises distinct compliance questions depending on the channel.
Email to a professional address is generally permissible under legitimate interest for recruiting contact, provided you include an opt-out mechanism in every message and honour unsubscribes promptly.
LinkedIn messages sent through the platform's own interface are governed partly by LinkedIn's terms of service and partly by GDPR. Automated InMail at scale can attract scrutiny, so message volume and personalisation both matter.
SMS and WhatsApp carry higher sensitivity. These channels reach personal devices, and regulators treat them as more intrusive than email. Before texting or messaging a candidate on WhatsApp, your legitimate interest assessment needs to specifically account for the channel. Some data protection authorities have indicated that SMS to unsolicited recipients requires stronger justification than email. Document your reasoning, keep messages professional, and always include a clear opt-out path.
The practical rule: the more personal the channel, the stronger your documented justification needs to be.
Transparency and Candidate Notice
GDPR's transparency principle requires that candidates know their data is being processed, even when you contact them cold. This does not mean you need their permission before reaching out. It means your first message must include — or link to — a privacy notice explaining who you are, what data you hold, why you are processing it, and how they can exercise their rights.
A short paragraph at the bottom of your outreach message works. Something like: "Your contact details were sourced from [platform/public source]. We process this data under legitimate interest for recruiting purposes. You can request deletion at any time by replying to this message."
Keep it plain. Keep it short. Make it easy to act on.
Automated Decision-Making in AI Recruiting
Article 22 of GDPR restricts automated decision-making that produces legal or similarly significant effects on individuals. In recruiting, this means you cannot use an AI tool to automatically reject candidates without any human review.
If your AI sourcing platform ranks or scores candidates and those scores determine who never receives a message, that process likely qualifies as automated decision-making. You need a human in the loop for any decision that meaningfully affects a candidate's opportunity.
In practice: use AI to surface and prioritise candidates, but keep a human making the final call on who to contact, shortlist, or reject.
How Kalent Approaches Compliance
Kalent is built for European and US sourcing, which means GDPR compliance is a design consideration, not an afterthought. The platform draws on 200M+ profiles with approximately 80% verified contact coverage and operates under a data processor model that requires a signed DPA between Kalent and each customer.
When you run outreach through Kalent's conversational agent across LinkedIn, email, SMS, and WhatsApp, the workflow keeps you in control. You define the audience, approve the sequences, and manage opt-outs and deletions. The platform does not make autonomous hiring decisions — it surfaces candidates and automates contact, with the recruiter directing every step.
For TA teams at Series B through D companies in France and Western Europe, that distinction matters. You are accountable to your DPO and to your candidates. A platform that handles enrichment and outreach in one place makes it easier to maintain a consistent compliance posture across every channel.
A Practical GDPR Compliance Checklist for AI Sourcing in 2026
Use this as a starting point. Your legal or DPO team should review anything specific to your jurisdiction.
- Sign a Data Processing Agreement with every sourcing platform you use
- Document a legitimate interest assessment for your sourcing activity
- Confirm where candidate data is stored and whether SCCs cover any cross-border transfers
- Include a privacy notice or link in every first outreach message
- Set a data retention policy and apply it to talent pools
- Ensure you can locate and delete individual candidate records within 30 days of a request
- Keep a human in the decision loop for any AI-assisted shortlisting or rejection
- Apply additional scrutiny to SMS and WhatsApp outreach given channel sensitivity
- Train anyone on your team who accesses candidate data on these requirements
FAQs
Do I need consent to contact a candidate I found through an AI sourcing tool?
Not necessarily. Most recruiters rely on legitimate interest rather than consent for proactive outreach. You do need to document your legitimate interest assessment, include a privacy notice in your first message, and give candidates a clear way to opt out. Consent is a higher bar and is generally impractical for cold sourcing.
What is a legitimate interest assessment and do I actually need one?
A legitimate interest assessment (LIA) is a short document recording why your interest in processing candidate data outweighs the candidate's privacy rights. Regulators expect one if you are processing data under legitimate interest. It does not need to be long, but it does need to exist and be specific to your use case.
Can I use SMS and WhatsApp to contact sourced candidates under GDPR?
Yes, but with more care than email. These channels reach personal devices and are considered more intrusive. Your LIA should specifically address the channel, every message must include an opt-out mechanism, and you should honour opt-outs immediately. Some data protection authorities have signalled that the bar for SMS outreach is higher than for email.
What happens if a candidate asks me to delete their data?
You have 30 days to respond and act. You need to locate the candidate's data across every system where it is stored — including your sourcing platform, ATS, and any spreadsheets — and delete or anonymise it. This is why using a platform that supports individual record deletion matters.
Does AI-assisted candidate ranking count as automated decision-making under GDPR?
It can. If an AI tool scores or ranks candidates and those scores determine who is automatically excluded from consideration, that likely qualifies. You need a human reviewing and approving decisions that meaningfully affect candidates. Using AI to prioritise who to contact is fine; using it to reject candidates without human review is not.
What is a Data Processing Agreement and why do I need one with my sourcing platform?
A DPA is a contract defining how a data processor — your sourcing tool — handles personal data on your behalf. GDPR requires one whenever you share personal data with a third-party processor. Without it, you are exposed if the platform mishandles data. Before using any sourcing tool with European candidate data, confirm a DPA is in place.
Are US-based sourcing platforms compliant with GDPR?
They can be, but you need to check. Key questions: where is the data stored, what transfer mechanism covers EU-to-US data flows (typically Standard Contractual Clauses), and does the platform offer a GDPR-compliant DPA? A platform with explicit European database coverage and a signed DPA is a safer starting point than one built primarily for the US market.
GDPR compliance in AI recruiting is not about slowing down your sourcing. It is about building a process you can defend. Document your lawful basis, sign your DPAs, give candidates a clear opt-out, and keep humans in the loop on decisions. Do those four things consistently and you can move fast without the legal exposure.
To see how a compliant AI sourcing workflow looks in practice, book a demo at kalent.ai.


