8 min reading

GDPR Consent in Recruiting: What You Must Collect Before Reaching Out to a Candidate

Reaching out to a passive candidate feels straightforward. You find a profile, write a message, hit send. But under GDPR, that sequence involves at least three distinct compliance decisions before your message lands in anyone's inbox. In 2026, data protection authorities across Europe are scrutinising AI-assisted sourcing more closely than ever. If you're using a platform that searches millions of profiles and automates outreach across LinkedIn, email, SMS, and WhatsApp, you need to know exactly what you're required to collect, document, and disclose before that first contact.

GDPR Consent in Recruiting: What You Must Collect Before Reaching Out to a Candidate

GDPR doesn't require consent for every act of data processing. That's a common misconception. What it requires is a lawful basis — and consent is only one of six options.

The distinction matters because consent under GDPR is a high bar. It must be freely given, specific, informed, and unambiguous. A candidate hasn't consented simply because their profile is publicly visible on LinkedIn. Pre-ticked boxes, implied agreement, and assumed permission all fail the standard.

For most proactive sourcing scenarios, consent isn't the right basis at all. Attempting to use it creates a practical problem: you need to obtain it before you process data, which is logistically impossible when you haven't yet contacted the person. And if a candidate later withdraws consent, you must stop processing immediately and delete their data.

In practice, most recruiters rely on a different lawful basis entirely — and that choice carries its own documentation requirements.


The Lawful Basis That Actually Applies to Sourcing

For passive candidate outreach, legitimate interest is the most commonly used lawful basis under GDPR Article 6(1)(f). It allows you to process personal data without prior consent, provided your interest is genuine, proportionate, and doesn't override the individual's rights and freedoms.

Sourcing a qualified candidate for an open role can qualify. But the regulation doesn't grant this automatically. You're required to conduct and document a Legitimate Interest Assessment (LIA) before you process the data.

An LIA doesn't need to be lengthy, but it must cover three things:

  • Purpose test: What is your legitimate interest? Filling a specific role, building a talent pipeline for a defined function, and so on.
  • Necessity test: Is processing this person's data actually necessary to achieve that purpose, or could you get there another way?
  • Balancing test: Do your interests outweigh the candidate's privacy rights? Consider the sensitivity of the data, whether they'd reasonably expect to be contacted, and whether you're giving them a clear way to opt out.

If you can't pass all three, legitimate interest doesn't apply and you need a different basis or a different approach.

Keep your LIAs on file. If a supervisory authority investigates your sourcing practices, this documentation is your first line of defence.


What You Must Have in Place Before First Contact

Before you send a single message to a sourced candidate, the following need to be in order.

A Completed Legitimate Interest Assessment

This should be role-specific or at least function-specific — not a single blanket document covering all your hiring activity. A generic LIA for "all recruiting" is unlikely to satisfy a regulator.

A Data Processing Agreement With Your Sourcing Platform

When you use an AI sourcing tool, you are the data controller and the platform is your data processor. GDPR Article 28 requires a written Data Processing Agreement (DPA) between you. Without one, you're non-compliant regardless of how carefully you handle the data on your end.

Your DPA should specify what data the processor handles on your behalf, how it's protected, where it's stored, and what happens to it when you end the relationship. If your vendor can't produce a DPA, that's a significant red flag.

Confirmation of Lawful Data Origin

You need to know how the profiles in your sourcing database were collected. Reputable platforms source data from publicly available professional networks and apply their own compliance checks before making profiles searchable. Ask your vendor directly: where does this data come from, and how do you ensure that collection meets GDPR standards?

If the platform can't answer that clearly, using it exposes you to risk. Claiming ignorance of your processor's data collection methods is not a defence.

A Documented Retention Policy

GDPR requires that personal data isn't kept longer than necessary. If you add a candidate to a talent pool and never progress them, how long does that profile sit in your system? You need a written retention schedule, and your sourcing platform should support deletion or anonymisation workflows so you can act on it.

A Transfer Mechanism If Data Crosses Borders

If you're based in France, Germany, or another EU member state and your sourcing platform stores data on servers outside the EEA, you're dealing with an international data transfer. Post-Schrems II, this requires either Standard Contractual Clauses (SCCs) or another approved mechanism. Check your vendor's DPA to confirm it's covered.


What You Must Disclose in Your First Message

Even when legitimate interest applies, GDPR Articles 13 and 14 require you to give candidates specific information about how you're processing their data. For sourced candidates who didn't provide their data directly, Article 14 applies.

You don't need to send a separate privacy notice before your first message. But that first contact must include — or link to — the following:

  • Your identity and contact details, or those of your organisation
  • The purpose and legal basis for processing their data
  • Your legitimate interests, if that's the basis you're relying on
  • How long you'll retain their data
  • Their rights: access, rectification, erasure, objection, and the right to complain to a supervisory authority
  • A clear and easy way to opt out

This doesn't mean your outreach message needs to be a wall of legal text. A short paragraph followed by a link to your privacy notice is sufficient, as long as the notice itself is complete and accessible.

Failing to include this information in first contact is one of the most common GDPR violations in recruiting — and one regulators can identify easily.


How Channel Choice Changes Your Obligations

The lawful basis and disclosure requirements apply regardless of channel. But each one carries additional considerations.

Email

Outreach to a professional email address is generally permissible under legitimate interest, provided the role is relevant to the candidate's professional background. Every message must include an opt-out mechanism, and you must honour unsubscribes promptly. Continuing to contact someone after they've opted out is a direct GDPR violation.

LinkedIn

Messages sent through LinkedIn's interface are governed partly by LinkedIn's terms of service and partly by GDPR. Automated outreach at scale can attract scrutiny from both. Personalisation and relevance matter — for compliance as much as for response rates.

SMS and WhatsApp

These channels reach personal devices and carry higher sensitivity under GDPR. Regulators in several EU member states have taken the position that SMS and WhatsApp outreach for recruiting requires stronger justification under the balancing test of your LIA. You need to demonstrate that the intrusion is proportionate to the purpose, and your opt-out mechanism must work on these channels too.

If you're running outreach across all four channels simultaneously, your LIA and privacy notice need to account for each one.


Candidate Rights You Must Be Ready to Honour

Once you've contacted a candidate, they can exercise their GDPR rights at any time. You need a process for handling each of these within the required timeframes.

Right of access: A candidate can ask what data you hold on them. You have 30 days to respond with a complete picture of what you process and why.

Right to erasure: A candidate can ask you to delete their data. Unless you have a compelling legitimate interest to retain it — an active application process, for example — you must comply.

Right to object: A candidate can object to processing based on legitimate interest. When they do, you must stop unless you can demonstrate compelling grounds that override their interests.

Right to rectification: If a candidate tells you that data you hold is inaccurate, you must correct it.

Your sourcing platform should make it straightforward to locate, export, and delete individual records on request. If it doesn't, that's a gap in your compliance infrastructure.


How Kalent Approaches This

Kalent is built with these requirements in mind. Searching across a database of 200M+ profiles and automating outreach across LinkedIn, email, SMS, and WhatsApp creates a significant compliance surface. The platform operates under a Data Processing Agreement, sources profiles from publicly available data, and supports the deletion and management workflows you need to honour candidate rights.

That said, the platform handles data processing on your behalf. The LIA, the retention policy, the opt-out mechanism in your messages, and the first-contact disclosure are your responsibility as the data controller. No tool removes that obligation.


A Pre-Outreach Compliance Checklist

Before you reach out to any sourced candidate, confirm the following:

  • Legitimate Interest Assessment completed and on file for this role or function
  • Data Processing Agreement signed with your sourcing platform
  • Platform can explain the lawful origin of its profile data
  • International transfer mechanism in place if data is stored outside the EEA
  • Retention policy documented and supported by your tooling
  • First outreach message includes identity, processing purpose, legal basis, retention period, candidate rights, and opt-out link
  • Opt-out mechanism functional across all channels you're using
  • Process in place to respond to access, erasure, and objection requests within 30 days

FAQs

Do I need consent to contact a passive candidate under GDPR?
In most cases, no. Legitimate interest under GDPR Article 6(1)(f) is the standard lawful basis for proactive candidate outreach. Consent is a separate and higher standard — it requires a prior, freely given action from the candidate, which is impractical for sourcing. You do need a documented Legitimate Interest Assessment before you process or contact anyone.

What must I include in my first outreach message to a sourced candidate?
Your first message must inform the candidate of your identity, the purpose and legal basis for processing their data, how long you'll retain it, their rights (including the right to object and request erasure), and how to opt out. A link to a complete privacy notice can cover most of this, but the opt-out mechanism must be functional and immediate.

Does GDPR apply if I found the candidate's profile on a public website?
Yes. Publicly available data is still personal data under GDPR. The fact that someone published their profile on LinkedIn or a professional directory doesn't give you an unrestricted right to collect, store, enrich, or contact them. You still need a lawful basis and must provide the required disclosures.

What is a Legitimate Interest Assessment and do I really need one?
An LIA is a documented evaluation of whether your purpose for processing data is genuine, necessary, and proportionate relative to the candidate's privacy rights. There's no legally required template, but you must be able to demonstrate that you conducted the assessment. Without one, your reliance on legitimate interest is difficult to defend if challenged.

What happens if a candidate asks me to delete their data?
You must comply unless you have a compelling legitimate reason to retain it — an active legal claim or contractual obligation, for example. Deletion requests must be acted on promptly, and you should have a process in your sourcing platform that lets you locate and remove individual records quickly.

Are SMS and WhatsApp outreach treated differently from email under GDPR?
They're not subject to a different legal basis, but regulators in several EU jurisdictions apply stricter scrutiny to outreach on personal messaging channels. Your LIA needs to address the proportionality of using these channels, and your opt-out mechanism must work on each one you use.

If I use an AI sourcing platform, who is responsible for GDPR compliance?
You are, as the data controller. The platform acts as your data processor and must operate under a Data Processing Agreement. But the lawful basis, the candidate disclosures, the retention policy, and the handling of rights requests are your responsibility. The platform provides the infrastructure; the compliance decisions are yours.


GDPR compliance in recruiting isn't a one-time checkbox. It's a set of ongoing obligations that attach to every sourcing workflow you run. Get the LIA written, sign the DPA, include the required disclosures in your first message, and build a process for handling rights requests. Those four steps cover the vast majority of your exposure.

If you're building or refining an AI-assisted sourcing workflow, Kalent is designed to support the full sourcing-to-interview cycle while giving you the data management controls you need to stay on the right side of these requirements.

Similar articles

No items found.

Ready to recruit
more efficiently?

Kalent simplifies sourcing by enhancing precision with AI-powered talent and recruiter matching.