recruitment strategy

8 min reading

GDPR and AI Sourcing in 2026: What Every European Recruiter Needs to Know Before Sending a Message

GDPR rules for candidate sourcing: what you must do before every outreach, and how AI sourcing keeps you compliant without slowing your pipeline.

A European recruiter reviewing candidate data on a laptop with a GDPR compliance checklist on screen

Why GDPR applies directly to your sourcing

The General Data Protection Regulation applies to any processing of personal data concerning residents of the European Union, wherever your company is based. The moment you collect, store or use the name, email, phone number or LinkedIn profile of a potential candidate, you are processing personal data within the meaning of the regulation.

Passive sourcing, contacting people who have not applied to you, is the most exposed activity of all. You have no explicit prior consent. You are operating on another legal basis, and this is where many recruiters slip up without realising it.

The six legal bases: which one applies to recruitment?

GDPR recognises six legal bases for processing personal data. For sourcing passive candidates, two of them matter in practice.

Legitimate interest (Article 6.1.f) is the basis most commonly relied on. It lets you contact a candidate without prior consent, provided your interest (filling a role) is proportionate and does not override the person's fundamental rights. In concrete terms: the role must be real, the candidate's profile must match that role, and you must inform them of their right to object from the very first contact.

Consent (Article 6.1.a) is stronger legally, but hard to obtain in proactive sourcing. It is mostly relevant for candidate databases you build over time, for example through a sign-up form on your job listings.

What you cannot do: process a candidate's data without an identified legal basis, keep profiles in your ATS indefinitely, or pass data to third parties without consent.


What you need to do before sending the first message

Check that the profile is relevant

Legitimate interest is not a blank cheque. Case law and the guidance issued by data protection authorities (the CNIL in France, the ICO in the United Kingdom) put the emphasis on proportionality. The profile you contact has to genuinely match the role you are filling. Mass-contacting profiles that are only loosely connected to your sector does not hold up.

An AI sourcing tool that generates contextual summaries for each profile helps here: you can document why each candidate was selected, which gives you a useful record if you are ever audited.

Inform the candidate from the first contact

This is the obligation people forget most often. From the very first message, you have to communicate:

  • The identity of the data controller (your company)
  • The purpose of the processing (recruitment for a specific role)
  • The legal basis relied on (legitimate interest, in most cases)
  • The candidate's rights of access, rectification and objection
  • How long their data will be kept

You do not need a long legal text. A short paragraph at the bottom of your outreach message is enough, as long as it is there every single time.

Honour the right to object immediately

If a candidate replies "stop contacting me", you are legally obliged to end all contact and delete or anonymise their data within a reasonable time. In a multichannel workflow (LinkedIn, email, SMS, WhatsApp), that means an objection on one channel has to carry across to all the others. An automated sequence that keeps sending SMS after a candidate has asked to be removed is a clear-cut breach.


Retention periods: the rule nobody really follows

GDPR requires that personal data not be kept longer than necessary for the purpose it was collected for. For recruitment, European authorities generally recommend a maximum of two years for unsuccessful candidates, counted from the last contact or the end of the process.

In practice, plenty of ATS instances pile up years of profiles with no purge policy. That is a real risk: a regulator such as the CNIL can ask to audit your candidate database, and a database that has not been cleaned since 2021 is hard to defend.

A few concrete good practices:

  • Set an explicit retention policy in your ATS (automatic deletion after 24 months with no activity, for example)
  • Record the date of the last contact with each candidate
  • Put a consent renewal process in place for profiles you want to keep beyond the standard period
  • Train your teams not to export contact lists into unsecured Excel files

AI sourcing and GDPR: the questions specific to automation

Using AI tools for sourcing raises extra questions that European recruiters need to get ahead of in 2026.

Enriched profiles: where does the data come from?

When a sourcing platform hands you the mobile number and email of a candidate you have never met, you need to ask where that data came from. Serious platforms rely on public sources (LinkedIn profiles, professional websites, publications) and on aggregated databases built in line with local regulations.

As a recruiter, you are not off the hook simply because a third-party tool collected the data. You become the data controller the moment you use it to contact someone. Make sure your provider can give you clear information about its sources and its compliance practices.

Multichannel automation and the minimisation principle

GDPR imposes a data minimisation principle: only collect and use what is strictly necessary for your purpose. In automated sourcing, that means you should not store a candidate's mobile number if you have no intention of using it, nor keep enrichment data beyond the recruitment cycle it relates to.

Automated outreach sequences are particularly exposed. A sequence that sends an email, then an SMS three days later, then a WhatsApp message a week after that is processing personal data across several channels over an extended period. Every step has to be justifiable against the legal basis you are relying on.

Automated decision-making (Article 22)

If your AI tool automatically filters or ranks candidates with no human involvement, and that classification significantly affects their access to a job, you may fall within the scope of Article 22. That article governs fully automated decisions and gives individuals the right to obtain human intervention.

In practice, most AI sourcing tools produce suggestions that the recruiter validates, which keeps a human decision in the loop. But if you fully automate the rejection of profiles with no human review, you need a solid legal basis and you must inform the candidates concerned.


How to structure a compliant sourcing workflow

Here is a practical sequence for staying compliant without weighing your process down.

Step 1: Define the legal basis before you start
For every sourcing campaign, document the legal basis you are relying on. In the vast majority of cases it will be legitimate interest. Note the role concerned, the campaign start date, and the criteria used to select profiles.

Step 2: Check that profiles are relevant
Only contact profiles whose experience and skills genuinely match the role. AI sourcing tools that generate profile summaries help you document that relevance.

Step 3: Include a GDPR notice in every first message
Write a short template (three to five lines) that you drop into every initial outreach message, on every channel. It should mention your company's identity, the purpose of the contact, the legal basis, and the right to object.

Step 4: Handle opt-outs across all channels at once
If your outreach tool does not sync opt-outs across channels automatically, you have to do it manually and straight away. A candidate who asks to be removed from your list on LinkedIn should never receive another SMS.

Step 5: Purge your databases regularly
Set a cleaning frequency (quarterly or twice a year) and stick to it. Delete or anonymise profiles you no longer have an active purpose for.


Can AI tools help you stay compliant?

Good news: modern AI sourcing platforms include features that make compliance easier rather than harder.

A platform like Kalent shows what a unified workflow brings. By centralising profile search, data enrichment and multichannel outreach in a single tool, it reduces the risk of personal data being scattered across several uncoordinated systems. When every interaction with a candidate runs through one workflow, handling an opt-out or documenting a legal basis is far simpler than with a chain of five different tools.

The AI summaries generated for each profile also give you a documented record of how relevant the candidate is to the role, which strengthens your case if anyone questions your legitimate interest basis.

That said, no tool excuses you from understanding your obligations. GDPR compliance remains your responsibility as the data controller.


What regulators are looking at in 2026

European data protection authorities have sharpened their approach to digital recruitment in recent years. In 2026, several areas are getting particular attention.

Retention periods that are not respected remain the most common thing checked during audits. Companies that cannot demonstrate an active retention policy are penalised every time.

Missing information notices in outreach messages have already cost several organisations fines. Sourcing campaigns that failed to mention candidates' rights have been targeted by several national authorities.

Data transfers outside the EU are another watch point. If your sourcing tool stores data on US servers with no adequate transfer mechanism (standard contractual clauses, and so on), you are potentially in breach. Check your provider's terms.

The use of sensitive data deserves particular attention. Data revealing ethnic origin, political opinions, health or trade union membership falls into GDPR's special categories and requires a reinforced legal basis. Some AI tools can infer this kind of information from public profiles, which creates a real risk.


FAQ

Is sourcing passive candidates legal under GDPR?
Yes, provided you rely on a valid legal basis. Legitimate interest is the basis most used for proactive sourcing. It requires the role to be real, the profile to be relevant, and the candidate to be informed of their rights from the first contact.

Do I have to get a candidate's consent before contacting them?
Not necessarily. Consent is one legal basis out of six. For passive sourcing, legitimate interest is generally enough, as long as you meet the information obligations and allow people to object.

How long can I keep an unsuccessful candidate's data?
European authorities generally recommend a maximum of two years from the last contact or the end of the process. Beyond that, you either renew consent or delete the data.

What happens if a candidate asks to be removed from my database?
You are obliged to end all contact and delete or anonymise their data within a reasonable time, generally 30 days. That deletion has to cover every channel and every system where their data is stored.

Are AI sourcing tools GDPR compliant by default?
No. Tools can make compliance easier, but the responsibility stays with the recruiter as the data controller. You need to check your provider's practices around data collection and storage, and make sure your own use complies with the regulation.

Does Article 22 on automated decision-making apply to AI sourcing?
Potentially, if your tool filters or rejects candidates in a fully automated way with no human involvement. In most AI sourcing workflows, the recruiter validates the suggestions, which keeps a human decision in the loop and reduces your exposure to that article.

Do I need to appoint a DPO to do AI sourcing?
Appointing a DPO is mandatory in certain cases (large-scale processing of sensitive data, public authorities, and so on). For an SME doing occasional sourcing, it is not necessarily required, but it is worth having someone in-house who knows the basics of GDPR as it applies to recruitment.


GDPR is not an obstacle to effective sourcing. It is a framework that, once understood, fits naturally into a professional workflow. Recruiters who document their legal basis, inform candidates from the first message, and manage their data rigorously are not slowing their pipeline down, they are simply making it more solid. If you want to build AI sourcing that covers Europe while staying on the right side of the rules, see how Kalent approaches it at kalent.ai.

Ready to recruit
more efficiently?

Kalent simplifies sourcing by enhancing precision with AI-powered talent and recruiter matching.