UK and EU
Holding candidate data lawfully under UK and EU GDPR
Most candidates in a recruitment database never applied for anything, which is exactly why lawful basis, transparency and retention are harder here than in other software.
Under UK and EU GDPR you are the controller of the candidate data you hold and Surhires is your processor. The product supports lawful basis on every record, dated consent events, retention measured from last contact, subject access export, erasure and transfer mechanisms. No software makes a controller compliant, and none is claimed to.
By Surhires Editorial · Published · Reviewed
What this page is, and the role it assumes you hold
This is a plain-English explanation of how the product supports obligations under the UK GDPR and the EU GDPR. It is not a compliance declaration, not a legal opinion, and not the policy. The binding documents are the privacy policy published on this site, the executed customer agreement and the data processing addendum. Where this page differs from those, those govern.
It also assumes a role. You are the controller for the candidate data in your tenant, because you decided to source, accept, import or keep every record in it. Soor LLC processes that data on your instructions. If your firm is acting as a processor for a client, the chain runs one step further and your own client contract decides what you may do, which is a question for your counsel rather than for this page.
Nothing here is legal advice. Recruitment sits awkwardly across data protection law, and the answers turn on facts a website cannot see: which entity contracts with the client, where the candidate is, whether you are an employment agency or an employment business, and what your client flows down to you.
Lawful basis is a decision you record, not a setting we choose
Every candidate record carries the basis you rely on, chosen from a fixed list rather than typed: consent, legitimate interests, performance of a contract, or a legal obligation. The list is short and fixed on purpose. A free-text field lets sixty recruiters describe the same basis forty different ways, and the resulting database cannot be counted, reviewed or defended.
Where the basis is consent, the record carries the channel it arrived through, the wording shown at the time, the timestamp, and the user or form that captured it. Basis changes across a record's life: a candidate sourced under legitimate interests who later replies and opts in moves to consent, and both events stay on the record rather than the first being overwritten. Withdrawal is its own dated event.
What the product will not do is pick the basis for you. Choosing between consent and legitimate interests for a sourced candidate is a controller decision with consequences, and a vendor default would be a bad answer dressed as a convenience.
- Fixed basis list rather than a free-text note
- Consent records carry channel, wording, timestamp and capturing user
- Basis changes appended as dated events, never overwritten in place
- Withdrawal recorded as its own event with its own timestamp
- The choice of basis stays with you, without a vendor default
Legitimate interests in recruitment, and what an assessment has to survive
Sourcing works on legitimate interests far more often than on consent, because the candidate has not been asked yet. That basis is available, and it is not a free pass. It requires an assessment that identifies the interest, tests whether the processing is necessary to it, and balances it against the rights and reasonable expectations of the person whose data you took from a public profile.
The parts that fail in practice are usually the same. Volume without relevance, where a whole board is scraped rather than a role sourced. Retention long after any plausible interest has expired. Silence, where the person is never told you hold their data. And a lack of any record showing the assessment happened at all.
The product carries the assessment reference on the record, keeps the source and the date of collection, runs the retention clock from real contact and surfaces expiry for a decision. What it cannot do is perform the balancing test. That is a controller judgement, and it needs writing down before the sourcing starts rather than after a complaint arrives.
Transparency is the obligation recruitment fails most often
A candidate whose data you obtained from somewhere other than the candidate has to be told: who you are, what you hold, where you got it, why you are processing it, on what basis, for how long, and what rights they have. There is a deadline for telling them, and the first contact you make is usually the moment it has to happen.
In practice most sourced candidates are never told, because the notice lives on a website nobody visits and the outreach message says nothing about it. The product supports doing this properly: privacy notice text can be attached to outreach templates so the first message carries it, the notice version shown is recorded against the record, and the candidate portal gives a route to see what is held without emailing anybody.
None of that decides your wording. The notice is yours, it names your firm as controller, and it has to describe your actual practice rather than a generic paragraph. A notice that does not match what you do is worse than a short one that does.
Retention runs from the last real contact, and expiry is a decision
Retention measured from record creation is the wrong clock. A candidate placed eighteen months ago and spoken to last week is a live relationship; a record parsed three years ago that has never replied is not, whatever the creation date says. Windows in the product run from the last meaningful contact: a reply, an answered call, an application, a submittal, an interview or a portal update the candidate made themselves.
Meaningful is defined narrowly. A bulk campaign the candidate ignored does not reset the clock, and neither do opens or delivery receipts. If they did, retention would become a function of how often you email people rather than of whether a relationship exists.
At expiry the record surfaces in a review queue carrying its basis, its last contact and three options: extend with a recorded justification, contact the candidate to refresh, or erase. Automatic deletion on a timer sounds tidy and destroys records somebody had a live reason to keep, while leaving no evidence that any decision was taken.
- Windows configurable per record type and per market
- Clock reset only by contact the candidate took part in
- Bulk campaign sends, opens and receipts do not reset anything
- Expiry raises a review queue rather than deleting silently
- Extend, refresh or erase, each written with an actor and a date
Each right, and how it is actually served in the product
Access is a self-service export from the record: the structured profile, parsed resume text, custom fields, notes, message history, call and interview records, stage and disposition history and consent events, as CSV for a person and JSON for a system. It runs without a support ticket in the path, because a statutory deadline should not depend on a vendor's queue.
Rectification is editing the record with an audit trail, and candidates can correct their own details through the portal, which is usually more accurate than a recruiter's two-year-old guess. Erasure removes the profile, custom fields, notes, messages, the original uploaded file, the extracted text and the search representation together, and keeps a fulfilment record which is the fact of the request rather than the data it concerned.
Restriction flags a record so it is excluded from search, matching and outreach without being deleted. Objection to processing, including objection to direct marketing, sets suppression that survives re-import, which matters because the most common failure is a suppressed person reappearing through a fresh spreadsheet. Portability uses the same structured export as access.
Automated decisions, and why a human stays in the loop
Match scores are decision support, not decisions. A score is shown with the requirement that drove each point, a person reviews it, and the product does not auto-reject candidates on a score threshold. Keeping a person in the loop is a design position and it also happens to keep the processing outside the narrowest reading of automated decision-making with legal or similarly significant effect.
Explainability is the practical control. A score nobody can inspect cannot be defended, and a scoring system that cannot be explained launders a judgement into something that looks like a measurement. Field-level explanations let a recruiter disagree with the model, which is the entire point of having one.
Where a jurisdiction adds its own rules on automated tools, such as New York City's bias audit regime, the product records which candidates were scored and exports the data an independent audit needs. Commissioning that audit and issuing notice remain yours.
Transfers out of the UK and the EU, described without spin
Primary processing is in the United States on AWS us-east-1, which makes this an international transfer for UK and EU customers. The mechanisms are the European Commission standard contractual clauses and the UK international data transfer addendum as applicable, incorporated through the data processing addendum, with a transfer impact assessment and the supplementary technical measures described in the security overview.
Those are the mechanisms available to a US processor today. What they are not is a guarantee about how a regulator or a court will view a given transfer in the future, and any vendor offering that certainty is selling something it does not have. The assessment is a document to read with counsel, not to file unread.
Subprocessors add their own transfer questions, particularly model providers and messaging providers. The register states where each category processes, which is the field to read if you carry a residency requirement, and objections during the notice period are the mechanism for acting on what you find there.
What you get
Basis on every record
A fixed lawful-basis list per candidate, with source, channel, wording and capture timestamp.
Dated consent events
Grants, refreshes and withdrawals appended in sequence rather than overwriting the last one.
Assessment reference
A legitimate interests assessment identifier held against records sourced under that basis.
Notice in first contact
Privacy notice text attachable to outreach templates, with the version shown recorded.
Last-contact retention clock
Windows measured from a contact the candidate took part in, not from record creation.
Review queue at expiry
Extend with justification, refresh consent or erase, each recorded with actor and date.
Self-service subject access
Full record exported as CSV and JSON from the record, without a support ticket in the path.
Portal rectification
Candidates correct their own details, which beats a recruiter's two-year-old guess.
Deep erasure
Profile, notes, messages, original file, extracted text and search index removed together.
Restriction flag
Excludes a record from search, matching and outreach without destroying it.
Suppression that survives import
An objection to marketing holds even when the same person arrives in a fresh spreadsheet.
Explainable scoring
Match scores show the requirement behind each point, with a person making the decision.
No auto-rejection
The product does not reject candidates on a score threshold without human review.
Transfer mechanisms
Standard contractual clauses and the UK addendum as applicable, with a transfer impact assessment.
Questions recruiters ask
Does using Surhires make us GDPR compliant?
No product can do that. You are the controller of the candidate data you hold, and the outcome depends on your lawful basis, your notices, your retention decisions, your training and daily recruiter behaviour. The product supports the record-keeping the role requires: basis per record, dated consent events, retention windows, subject access export and erasure. The obligations stay with you.
Can we rely on legitimate interests for sourced candidates?
It is commonly the right basis, and it requires an assessment that identifies the interest, tests necessity and balances against the person's rights and reasonable expectations. The product holds the assessment reference, the source, the collection date and the retention clock. It cannot perform the balancing test, which needs writing down before sourcing rather than after a complaint.
When do we have to tell a sourced candidate we hold their data?
Where data came from somewhere other than the candidate, they must be informed within the period the regulation sets, and in practice your first contact is the moment to do it. The product can attach notice text to outreach templates and records which version was shown. The wording, and the accuracy of it, remain yours.
How does erasure work if the candidate was placed?
A completed placement creates financial records that statute usually requires you to keep. The workflow separates personal data that can go from the financial record that must stay, erases the first, retains the second under a named reason and produces a summary of what was kept and why. The alternative, a deletion that silently leaves everything, is worse.
Is match scoring an automated decision under the GDPR?
It is designed not to be. Scores are decision support shown with the requirement behind each point, a person reviews them, and there is no auto-rejection on a threshold. Whether a particular configuration crosses a line depends on how your firm uses it, which is a question for your counsel with your actual workflow in front of them.
What covers the transfer of candidate data to the United States?
The data processing addendum incorporates the European Commission standard contractual clauses and the UK international data transfer addendum as applicable, with a transfer impact assessment and supplementary technical measures. Those are the mechanisms available to a US processor. They are not a guarantee about future regulatory views, and no vendor can honestly offer one.
Keep reading
- What the processor agreement commits us to, clause by clause
- Two sets of people, two different roles, one privacy position
- The subprocessor register, and why recruitment needs one
- The compliance matrix, walked posture by posture
- Know why you hold every candidate record, and for how long
- One system for a mixed perm and contract desk
- The engineering answer to how your candidate data is protected
See it against your own reqs
Bring one live role and three resumes. In twenty minutes you will see the match scores, the shortlist and the placement invoice that comes out the other end.