How Kalent Handles GDPR Compliance for European Recruiting Outreach
Why GDPR Compliance Is a Sourcing Problem, Not Just an HR Problem The Lawful Basis Question for Passive Candidate Outreach How Kalent Handles Data Origin and Lawfulness Data Residency and Cross-Border Transfers Retention Limits and Talent Pool Management Candidate Rights: Access, Correction, and Erasure Outreach Compliance Across LinkedIn, Email, SMS, and WhatsApp Email LinkedIn SMS WhatsApp Transparency and Candidate Notice Automated Decision-Making in AI Sourcing A Practical GDPR Compliance Checklist for AI Sourcing in 2026 How Kalent Supports Your Compliance Workflow FAQs
Why GDPR Compliance Is a Sourcing Problem, Not Just an HR Problem
GDPR has been in force since 2018, but enforcement targeting AI-assisted sourcing has sharpened considerably. Supervisory authorities in France, Germany, the Netherlands, and Ireland have all issued fines or formal guidance on HR data processing. In 2026, automated candidate sourcing sits squarely in scope.
The moment you search for a passive candidate, you are processing personal data. Their name, job title, email address, phone number, and LinkedIn profile all qualify under GDPR. Storage, enrichment, search, and outreach are each separate processing activities — and each requires a lawful basis.
The question regulators ask is simple: do you have a lawful basis for processing this data, and did the candidate know you were doing it?
The Lawful Basis Question for Passive Candidate Outreach
Every act of personal data processing under GDPR must rest on one of six lawful bases. For proactive sourcing, two are relevant.
Legitimate interest is the most practical basis for passive candidate outreach. It allows processing without prior consent if your interest is genuine, proportionate, and does not override the candidate's rights. Sourcing a software engineer for an open role can qualify — provided you document your reasoning and give candidates a clear way to opt out.
Consent sets a higher bar. It requires a freely given, specific, informed, and unambiguous action from the candidate. Pre-ticked boxes and implied consent do not count. For most proactive sourcing scenarios, consent is impractical to obtain before first contact, which is why legitimate interest is the standard approach.
The practical implication: before you send that first message, you need a written legitimate interest assessment (LIA) on file. It does not need to be long, but it does need to exist. Kalent's workflow is built around legitimate interest as the default basis for sourcing outreach, and the platform supports the documentation you need to back that up.
How Kalent Handles Data Origin and Lawfulness
A core compliance question for any AI sourcing platform is: where did these profiles come from?
Kalent's database of 200M+ profiles across Europe and the US is built from publicly available professional data sources. Before profiles become searchable, they go through compliance checks designed to verify that the underlying data collection meets GDPR standards. This matters because you, as the recruiter, are the data controller — and if the data your processor supplies was collected unlawfully, that exposure flows back to you.
When evaluating any sourcing vendor, the right question is not just "how many profiles do you have?" but "how did those profiles enter your database, and can you document that?" Kalent provides a Data Processing Agreement (DPA) that covers this relationship. Signing a DPA with your sourcing platform is not optional under GDPR — it is a legal requirement when a processor handles personal data on your behalf.
Data Residency and Cross-Border Transfers
If you are based in Germany or France and your sourcing platform stores data on servers outside the European Economic Area, you are executing an international data transfer. Post-Schrems II, this requires Standard Contractual Clauses (SCCs) or another approved transfer mechanism.
Kalent's DPA addresses cross-border transfer requirements, including the use of SCCs where applicable. Before using any AI sourcing platform for European candidates, confirm where candidate data is stored and whether the vendor's DPA explicitly covers international transfers. A platform that cannot answer this question clearly is a compliance risk.
Retention Limits and Talent Pool Management
GDPR requires that personal data is not kept longer than necessary for the purpose it was collected. In a sourcing context, that means you need a documented retention policy for your talent pools.
If you add a candidate to a pipeline and never contact them, how long does that profile sit in your system? If a role closes without a hire, what happens to the candidates you sourced for it? These are not hypothetical questions — supervisory authorities have cited indefinite retention as a violation in HR data cases.
Kalent supports deletion and anonymisation workflows so you can manage retention in line with your documented policy. The platform makes it practical to locate and remove individual records, which matters when a candidate exercises their rights.
Candidate Rights: Access, Correction, and Erasure
Sourced candidates have the same GDPR rights as applicants who came through your careers page. If a passive candidate you contacted asks what data you hold on them, you have 30 days to respond. If they ask you to delete it, you need to action that request.
This is where many sourcing workflows break down. When candidate data is spread across a sourcing platform, a CRM, an ATS, and an email thread, fulfilling a subject access request becomes a manual investigation. Kalent centralises the sourcing and outreach workflow, which reduces the number of systems you need to search when a rights request arrives.
The four rights most likely to arise in a sourcing context:
- Right of access — the candidate wants to know what you hold
- Right to erasure ("right to be forgotten") — the candidate wants their data deleted
- Right to object — the candidate objects to processing based on legitimate interest
- Right to rectification — the candidate wants inaccurate data corrected
When a candidate opts out through Kalent's conversational agent, that opt-out is recorded. This creates an auditable trail that supports your response to any subsequent rights request.
Outreach Compliance Across LinkedIn, Email, SMS, and WhatsApp
Kalent automates outreach across four channels. Each carries distinct compliance requirements.
Outreach to a professional email address is generally permissible under legitimate interest for recruiting contact, provided every message includes a clear opt-out mechanism and you honour unsubscribes promptly. Kalent's outreach sequences include opt-out language by default and suppress future messages to candidates who opt out.
Messages sent through LinkedIn are governed partly by LinkedIn's own terms of service and partly by GDPR. Automated outreach at scale can attract regulatory attention, so personalisation and message volume both matter. Kalent's conversational agent generates personalised messages rather than sending identical bulk sequences, which reduces both compliance risk and the likelihood of being flagged by LinkedIn's own systems.
SMS
SMS reaches a personal device and carries higher sensitivity than professional email. Regulators in several EU member states have issued guidance treating unsolicited SMS as requiring stronger justification under legitimate interest. Kalent's multi-channel sequencing lets you configure which channels are used and in what order, so you can reserve SMS for candidates who have already engaged with an earlier touchpoint.
WhatsApp sits at the highest sensitivity end of the spectrum. Sending unsolicited recruiting messages to candidates who have not indicated willingness to receive them is difficult to justify under legitimate interest alone in most EU jurisdictions. Kalent supports WhatsApp outreach, but channel selection is your responsibility as the data controller. Use it selectively and document your reasoning.
Transparency and Candidate Notice
GDPR's transparency principle requires that candidates know their data is being processed. When you contact a sourced candidate for the first time, that message should include:
- Who you are and which organisation you represent
- Why you are contacting them
- The lawful basis for processing their data (legitimate interest)
- How they can opt out or request erasure
- A link to your privacy notice
Kalent's outreach templates are built to include these elements. You can customise the language, but the structure ensures the required information reaches the candidate in the first message. This is not just good practice — it is what Article 14 of GDPR requires when data has not been collected directly from the individual.
Automated Decision-Making in AI Sourcing
Article 22 of GDPR restricts solely automated decisions that produce legal or similarly significant effects on individuals. In a sourcing context, this is most relevant when AI ranking or scoring is used to make a final hiring decision without human review.
Kalent's matching surfaces candidates for human review — a recruiter evaluates the profiles and decides who to contact. The AI handles search and ranking; the recruiter makes the call. This keeps the process within GDPR's acceptable use of automated processing and avoids triggering Article 22 obligations.
If you use any AI tool to make final hiring decisions without human involvement, that is a separate compliance question to address with your data protection officer.
A Practical GDPR Compliance Checklist for AI Sourcing in 2026
Before running a sourcing campaign through any AI platform in Europe, work through this list:
- Signed DPA in place with your sourcing platform
- Legitimate interest assessment documented for this sourcing activity
- Data origin confirmed as GDPR-compliant by the vendor
- Cross-border transfer mechanism confirmed (SCCs or equivalent)
- Retention policy documented and deletion workflows in place
- First outreach message includes Article 14 transparency notice
- Opt-out mechanism active on every outreach channel
- Candidate rights request process defined and tested
- Human review step confirmed before any hiring decision
This is not an exhaustive legal checklist — your data protection officer or legal counsel should review your specific setup. But these are the questions that come up most often when sourcing teams face a GDPR audit.
How Kalent Supports Your Compliance Workflow
Kalent is built for recruiters who need to move quickly without creating compliance exposure. The platform provides a DPA, sources from publicly available data with compliance checks applied, centralises outreach across channels with opt-out tracking, and keeps a human recruiter in the decision loop throughout.
The goal is to compress the full sourcing-to-interview cycle into a single workflow — and that workflow is designed to support GDPR compliance rather than work around it. You can explore how the platform handles sourcing and outreach at kalent.ai.
GDPR compliance in recruiting is ultimately your responsibility as the data controller. Kalent gives you the infrastructure to meet that responsibility without slowing your hiring down.
FAQs
Does Kalent sign a Data Processing Agreement with customers?
Yes. Because Kalent processes personal data on behalf of recruiters, a DPA is required under GDPR. Kalent provides a DPA covering the processor relationship, data origin, and cross-border transfer mechanisms including Standard Contractual Clauses where applicable.
What lawful basis does Kalent's outreach support?
Kalent's workflow is built around legitimate interest as the default lawful basis for passive candidate outreach. The platform supports the documentation and opt-out mechanisms you need to rely on that basis. Consent-based workflows are also possible but are less common for proactive sourcing.
Is it GDPR-compliant to send recruiting messages via WhatsApp?
WhatsApp outreach is the most sensitive channel in a recruiting context. It is difficult to justify under legitimate interest alone in many EU jurisdictions without prior engagement from the candidate. Kalent supports WhatsApp outreach, but channel selection is the recruiter's decision as data controller. Use it selectively and document your reasoning.
What happens when a candidate opts out of Kalent outreach?
When a candidate opts out through Kalent's conversational agent, the opt-out is recorded and future outreach to that candidate is suppressed. This creates an auditable trail that supports your response to any subsequent rights request or regulatory inquiry.
Does using AI for candidate matching trigger Article 22 of GDPR?
Article 22 applies to solely automated decisions with legal or similarly significant effects. Kalent's AI surfaces and ranks candidates for human review — the recruiter decides who to contact and who to progress. This keeps the process outside Article 22's restrictions, provided a human remains in the decision loop before any hiring action is taken.
How should I handle a subject access request from a sourced candidate?
You have 30 days to respond. You need to tell the candidate what data you hold, why you hold it, and how long you intend to keep it. Centralising your sourcing workflow in Kalent reduces the number of systems you need to search when a request arrives. Your data protection officer should define the formal response process for your organisation.
Where is candidate data stored in Kalent, and does this affect GDPR compliance?
Data residency and cross-border transfers are covered in Kalent's DPA. Where data is stored or processed outside the EEA, Standard Contractual Clauses or another approved transfer mechanism applies. Review the DPA with your legal counsel to confirm the transfer arrangements meet your organisation's requirements.


