If you are buying GDPR recruiting software, the first question is not “Is the vendor compliant?” It is “What does our recruiting team control, and what must the vendor prove?” In most employer-ATS setups, the employer is the controller, the vendor is the data processor, and candidate data rights have to work end to end, not just on a slide.
That matters because AI recruiting touches more than resumes. It can touch search indexes, notes, rankings, messages, exports, attachments, and derived profiles. So before procurement, you need a practical test for access, rectification, erasure, restriction, objection, and portability. CVViZ provides a GDPR toolkit with public controls for consent handling, request tracking, export, delete, erase, and stop-processing actions. Even so, the buyer still has to verify the workflow, the contract, and the technical edges that public pages do not fully cover.
Who is the controller, and why does that matter?
The controller is the party deciding why candidate data is collected and how it is used. In a normal employer and ATS setup, that is the employer, not the software vendor. The employer sets the recruitment purpose, retention, lawful basis, candidate notice, and final hiring decision.
By contrast, the data processor handles candidate data on documented instructions. That sounds simple until you map the real workflow. Hosted resumes, email imports, job-board sourcing, calendars, video interviews, analytics, support access, subprocessors, and model training may not all sit in the same legal bucket. Some operations can be processor activity, while others can make the vendor a controller for its own purpose.
So the first procurement job is allocation, not branding. A general “GDPR compliant” label is not enough. The Article 28 contract should spell out subject matter, duration, nature, purpose, data types, data subjects, instructions, confidentiality, security, subprocessors, rights support, breaches, DPIAs, deletion or return, and audit information.
What should a candidate-data map include?
A good review starts with a data map. This is where you list every source, field, purpose, recipient, AI output, and location. If you skip this step, you will miss the hidden paths where data lives.
For example, a resume PDF is only one piece of the record. You also need to check notes, tags, scores, messages, activity history, source metadata, recordings, and test results. Then you need to know where those items flow: recruiters, hiring managers, clients, integrations, subprocessors, production storage, support systems, logs, backups, and AI services.
| Area | Questions to ask | Evidence to request |
|---|---|---|
| Sources | Applications, referrals, email, job boards, social sites, public web? | Source inventory and collection controls |
| Data | Resumes, contact details, notes, messages, scores, recordings, tests? | Data dictionary and sample export |
| Purpose | Vacancy, talent pool, analytics, communications, or another use? | Processing register and purpose map |
| AI | Parse, rank, profile, reject, recommend, or train? | Decision-flow diagram and model documentation |
| Recipients | Recruiters, managers, clients, integrations, subprocessors? | Role matrix and subprocessor register |
| Lifecycle | Indexing, sharing, archiving, deletion, backup expiry? | Retention schedule and deletion process |
| Geography | Production, support, logs, backups, AI services? | Location map and transfer mechanism |
That map is the backbone of GDPR recruiting software due diligence. Without it, you cannot test rights properly.
How should access work in practice?
Access should do more than dump a resume. It should confirm whether data is processed, provide the personal data, and give context on purposes, categories, recipients, retention, source, and automated-decision information where relevant. A plain PDF export often misses tags, notes, ranking outputs, communications, and source metadata.
The workflow should also be traceable. Test identity verification, search across the ATS, talent pool, applications, integrations, and indexes. Then check third-party data handling, readable export, secure delivery, and an audit record. The normal deadline is without undue delay and within one month, with a possible two-month extension for complexity or number of requests. If an extension is used, the candidate must be told within the first month, with reasons. Handling is generally free.
CVViZ provides an Access request flow in the Data Privacy tab and export options, plus an Update Resume link. That is useful, but the real test is whether the export includes every field, score, note, file, message, activity event, integration copy, and derived AI output.
How should rectification work?
Rectification is not just editing a profile. It has to update the authoritative record and, where applicable, indexes, connected systems, candidate-facing views, and AI inputs. If you fix a wrong skill or date but search results still show the stale version, the workflow is broken.
A practical test is easy. Submit an incorrect name, date, skill, and contact field. Then check whether the change propagates into search, ranking, reports, and any connected systems. Also ask whether candidates can self-correct selected fields, whether approval is required, how recruiter notes and tags are corrected, and whether a correction changes an AI recommendation.
CVViZ provides an Update Resume function and a Rectification request type. What still needs verification is propagation. Buyers should confirm whether a change reaches indexes and downstream outputs, not just the visible profile.
What should erasure and deletion prove?
Erasure is not automatic. It depends on the purpose, consent status, objections, legal claims, and statutory exceptions. Once the controller decides to erase, the vendor needs to carry that decision through production data and connected processing locations.
So test the full path. Log the request. Delete the profile, files, and duplicates. Inspect search indexes, email history, exports, integrations, analytics, backups, logs, subprocessors, AI scores, and derived profiles. Also define backup expiry, notify recipients where required, and keep only the evidence needed to show the request was handled.
CVViZ provides Delete and Erase request types, a received-to-in-progress-to-completed status flow, a Delete Candidate action, and permanent removal of candidate data. Its GDPR notice says the record and associated files are erased immediately. The public materials do not explain backups, indexes, subprocessors, exports, model training data, derived scores, or legal holds, so those items still need procurement review.
How does restriction, or stop processing, behave?
Restriction is different from deletion. It allows storage without active use in certain situations, such as a disputed accuracy issue, unlawful processing where erasure is opposed, a legal-claim need, or an unresolved objection. In plain terms, the record stays, but the system should stop using it in ways that go beyond the restricted state.
That means you should test every active path. Can the candidate still be used in outreach, campaigns, sourcing, ranking, rediscovery, submission, API access, exports, and integrations? Or does the restriction actually block those actions while preserving only the minimum data needed?
CVViZ calls this Stop Processing and says it halts further activity without deleting data. Its public notice also describes inactive or suspended status so the candidate is no longer sent to companies for open opportunities. That is directionally helpful, but the buyer still has to verify every automated route and whether lifting the restriction is logged.
What does portability require, and how is it different from access?
Portability is narrower than access. It applies to personal data provided by the candidate, processed automatically, where the basis is consent or contract. The data should be in a structured, commonly used, machine-readable format, and direct transmission to another controller should happen where technically feasible.
That means portability is not a request for every note, inference, or internal judgment. It is a move-your-own-data workflow. A good test includes field labels, encoding, attachments, application answers, consent history, relevant metadata, secure delivery, authentication, direct transfer, and request tracking. Then try importing the file into another system.
CVViZ provides export options and documents Export Data, but it does not publicly describe a separate portability-specific control. So the buyer should verify the actual machine-readable scope and the transfer path, not just the presence of an export button.
How should transparency, lawful basis, and consent be handled?
The candidate notice should clearly identify the controller, DPO where applicable, purposes, lawful basis, data categories, recipients, retention, source, rights, transfers, and automated decision-making. If data was collected indirectly, the notice given at that point also matters.
Consent is not a default recruitment basis. It must be freely given, specific, informed, unambiguous, separable from unrelated terms, provable, and easy to withdraw. In employment settings, the power imbalance makes freely given consent difficult in many cases. So the buyer should verify that the basis is documented for each purpose, and that withdrawal works across campaigns, integrations, retention, and future use.
CVViZ provides an application-page opt-in with a privacy document and consent states such as Pending, Withdrawn, Offered, and Not Offered. It also says customers must inform candidates and obtain necessary consent for information collected through the service. The remaining checks are versioning, timestamps, purpose granularity, manual-import notices, and withdrawal propagation.
What should buyers verify about AI screening and profiling?
AI screening is allowed, but it needs control. You have to distinguish assistive ranking from a solely automated decision. Profiling is automated analysis used to evaluate personal aspects, and Article 22 protections apply to solely automated decisions with legal or similarly significant effects.
That is why “it’s only a recommendation” is not enough on its own. You need to know whether the system automatically rejects applicants, uses shortlist thresholds, relies on sensitive or proxy data, or produces a score that determines progression. You also need meaningful human intervention, which means an authorised, competent reviewer who can independently assess and change the result.
CVViZ provides NLP and machine-learning contextual screening and ranking. Public materials do not establish a model card, accuracy benchmark, bias audit, feature list, AI-training policy, or score-deletion treatment. So buyers should test varied career paths, employment gaps, education routes, names, and languages, and record false exclusions, overrides, explanations, and model versioning.
What security evidence should the vendor provide?
Security review should be concrete. Ask for encryption in transit and at rest, key management, role-based access, least privilege, administrator MFA, tenant separation, logging, monitoring, vulnerability management, secure development, backup protection, recovery testing, deletion controls, and support-access restrictions.
Also ask whether resumes, recordings, and test results get the same controls as account data. That is a common blind spot. If the answer is vague, keep digging.
CVViZ’s privacy policy, effective January 23, 2024, states industry-standard security measures and SSL encryption, while also saying transmission security cannot be guaranteed. It does not publicly provide detailed architecture, certifications, penetration-test results, MFA configuration, breach SLA, recovery objectives, or an incident playbook. So the procurement file should ask for all of that.
What should the DPIA and transfer review cover?
A DPIA is required when processing is likely to create high risk to people’s rights and freedoms. AI recruiting can trigger that because it often involves systematic evaluation, profiling, large-scale processing, employment-context vulnerability, and decisions affecting access to work.
The employer should assess necessity, proportionality, exclusion and discrimination risks, transparency, security, rights handling, human oversight, and residual risk before launch. Then review the DPIA after any material workflow or model change. If high residual risk remains, the supervisory authority may need to be consulted before processing.
Transfers need their own review. CVViZ says data may be stored and processed in the United States, the European Economic Area, and possibly other countries through third parties, and may be transferred to group companies and subcontractors. That means buyers should request exact entities, locations, purposes, access routes, and transfer tools. Where data leaves the EEA, a Chapter V mechanism is required on top of ordinary GDPR compliance.
How does CVViZ map against these checks?
| Requirement | Publicly documented position | Verify before purchase |
|---|---|---|
| Processor | CVViZ says it is a data processor and customers are responsible for GDPR compliance | Signed Article 28 DPA and instructions |
| Consent | Data Privacy tab; add, update, withdraw consent; four consent states; application opt-in | Proof, versioning, purpose separation, withdrawal propagation |
| Access | Request tracking, Update Resume link, export options | Complete record scope and secure delivery |
| Rectification | Candidate update function and Rectification request type | Propagation to indexes, integrations, and AI outputs |
| Erasure | Delete and Erase types, Delete Candidate, claimed immediate removal | Backups, logs, indexes, subprocessors, exports, derived data |
| Restriction | Stop Processing and inactive or suspended status | Blocking of campaigns, APIs, ranking, exports, integrations |
| Portability | Export Data is described | Machine-readable scope, direct transfer, dedicated workflow |
| Tracking | Received, in progress, completed | Alerts, ownership, escalation, audit detail |
| Retention | 14-day post-termination account deletion; no public candidate schedule | Configurable schedule, automation, backup expiry |
| Security | Industry-standard measures and SSL stated | Architecture, encryption at rest, MFA, tests, incident SLA |
| Transfers | U.S., EEA, and possibly other countries; group companies and subcontractors | Exact locations, SCCs or adequacy, TIA, subprocessor list |
| AI governance | Contextual NLP and ML screening and ranking described | Model card, bias testing, human review, explanations, training, score deletion |
What is the acceptance test before procurement?
Here is the gate I would use before signing any GDPR recruiting software deal.
- Obtain the DPA, security annex, subprocessor list, retention schedule, transfer documents, and current product documentation.
- Map every source, field, purpose, recipient, AI output, integration, and location.
- Test least privilege for recruiter, hiring manager, administrator, support, and vendor roles.
- Submit access, rectification, erasure, restriction, objection, and portability requests; assign an owner and start the clock.
- Confirm the access export is complete, readable, and securely delivered, then test portability by importing it elsewhere.
- Correct test data and verify search, ranking, reports, integrations, and candidate views.
- Delete a test candidate and inspect production, attachments, duplicates, indexes, campaigns, APIs, exports, logs, backups, and AI-derived data.
- Restrict another candidate and attempt every contact, ranking, rediscovery, and submission path.
- Run AI tests using varied histories and languages; record exclusions, overrides, explanations, and model version.
- Run a breach tabletop exercise and confirm processor contacts, timing, evidence, and escalation.
- Record DPIA risks, mitigations, residual risk, review dates, and model-change triggers.
- Fail the gate if a critical answer is only verbal or the end-to-end workflow cannot be demonstrated.
FAQ
Is GDPR banning AI resume screening?
No. GDPR does not ban AI resume screening. It requires a lawful, transparent, and accountable process, with the right controls around rights, profiling, security, and transfers.
Is access the same as portability?
No. Access is broader. Portability is narrower and applies only to specific candidate-provided data processed automatically under consent or contract.
Does a “GDPR compliant” label prove the vendor is ready?
No. It only tells you the vendor is making a claim. You still need the contract, the workflows, the transfer tools, the deletion behavior, and the security evidence.
What should we do if a vendor cannot demonstrate a workflow?
Treat that as a risk. If the workflow cannot be shown end to end, it is not ready for procurement in a serious hiring environment.
Is this legal advice?
No. This is practical procurement guidance for controller-side review, not legal advice.
The short version is simple: a good data processor should not just say it supports candidate data rights. It should prove the workflow works when a real candidate asks for access, correction, deletion, restriction, or portability. That is the standard worth buying.



