Betterfolio
Betterfolio

Betterfolio

Betterfolio team

GDPR and candidate data: compliance starts in your PDF exports too

Collection isn't everything: client sharing counts. Badly named attachments, duplicates, or contact details leaking across versions create traceability holes.

Documents and pen on a desk, Unsplash photo

What GDPR really says about the CVs you share

Sending a CV to a client is not just handing over a document. Under the GDPR, it is a transfer of personal data to a third party. That transfer needs a solid legal basis.

For ESNs, two bases come up most often in practice:

  • Legitimate interest (Article 6(1)(f)): you consider the send necessary for your commercial activity. But beware: you must be able to show the transfer was proportionate. An internal audit or a check by your supervisory authority will ask you to justify each send.
  • Explicit consent (Article 6(1)(a)): the candidate has agreed. Except that consent must be specific. A generic form saying “I accept that my data may be used for commercial purposes” is not enough. If the candidate challenges a send to a particular client, that kind of consent collapses.

The nuance many people miss

The GDPR does not distinguish between “emailing a CV” and “sharing a link to an online dossier.” Both are processing. The difference is the level of control you keep after you send.

A PDF attached to an email, once sent, is out of your control. The client can forward it, store it, and share it internally without limit. A link to an online profile can be switched off, updated, or restricted at any time.

What supervisory authorities expect in practice

Regulators are not looking for perfection. They look for evidence of a serious approach. Here is what an inspector will check first:

Control pointWhat you must be able to show
Documented legal basisUp-to-date record of processing activities mentioning client sends
Information to the candidateProof the candidate knows who their profile is sent to
ProportionalityOnly the data needed for the assignment is shared
Retention periodA purge policy that is applied and traceable

Retention: the blind spot for ESNs

The rule looks simple on paper: do not keep data longer than necessary for the purpose. In practice, it is the most neglected area.

What regulators recommend

For CVs in sourcing databases, many European authorities (including France’s CNIL) cite a maximum of two years after the last contact with the candidate. After that:

  • Either you delete the dossier
  • Or you contact the candidate again to renew consent
  • Or you anonymise the data (statistics only)

What happens on the ground

In most ESNs, profiles from 2019 or 2020 sit in the same databases as active candidates. Nobody has set up automatic purging. The reasons are always the same:

  • “We might need them one day”
  • “Sales does not want to lose their pool”
  • “We do not have time to sort it”

The issue is not only legal. A profile that is four years old is a profile with outdated skills, a role that has changed, and a daily rate that no longer matches reality. Sending it to a client costs you credibility before it costs you compliance.

Putting realistic purging in place

You do not need a six-month project. A simple process works:

  • Tag each profile automatically with the date of last contact (email, call, update)
  • Send a renewal email at month 22 with a link to confirm continued processing
  • Archive or delete at month 24 with no response
  • Log each action so you can prove the approach if inspected

You get two wins: a clean database for sales, and demonstrable compliance for legal.


The right to erasure: when a candidate says stop

Article 17 of the GDPR gives every candidate the right to ask for their data to be deleted. That applies even after their profile has been sent to one or more clients.

The typical scenario

A senior developer has worked with you as a freelancer for two years. They change direction, join a vendor on a permanent contract, and email you: “I want all my data removed from your systems.”

At that point you must:

  • Identify every version of their profile in your systems (CRM, ATS, shared folders, mail)
  • List every client their profile was sent to
  • Notify each client of the erasure request
  • Actually delete the data from your own systems
  • Document the whole procedure
  • Reply to the candidate within one month at most

Why it is a nightmare without traceability

If your dossiers live as PDFs scattered across mailboxes, OneDrive folders, Slack channels, and Teams threads, traceability is impossible in practice.

Concrete questions you will have to answer:

  • Was the profile sent as V1 to client A, then as V3 to client B after an update?
  • Did sales forward the PDF to a subcontractor without documenting it?
  • Did the client store the dossier in their own ATS?

Without a centralised log of sends, answering these questions is archaeological work.

Exceptions to the right to erasure

Erasure is not absolute. You can refuse if:

  • The data is needed to perform an ongoing contract
  • You have a legal obligation to keep it (invoices, signed contracts)
  • The data is needed to establish, exercise, or defend legal claims

But these exceptions are narrow. “We might need it for a hypothetical dispute” does not hold. You need a real dispute or one that is reasonably foreseeable.


Silent leaks: the real day-to-day risk

GDPR incidents at ESNs almost never come from hacking or a technical flaw. They come from everyday practices nobody questions.

The most common leaks

  • A personal email address left in a field of the PDF sent to the client. The candidate gave their Gmail for the first contact: they end up exposed to the client’s internal recruiters.
  • A phone number in the metadata of a Word file turned into PDF. The source document’s “Author” or “Comments” field sometimes holds information nobody thought to strip.
  • A private LinkedIn profile whose URL is copied into the dossier. The candidate’s profile is restricted, but the URL can still expose information they did not intend for that client.
  • An ID photo included by default in the template. There is no legal obligation to send it to the client, and it is a documented discrimination risk.
  • Personal-life information: family situation, nationality, full date of birth. No relevance for a technical assignment, but often there out of habit.

The real cost of a leak

A formal notice from a supervisory authority, even without a fine, means:

  • Lost time: answering information requests, building the file, involving the DPO and management
  • Reputational risk: public enforcement notices are indexed by search engines
  • Loss of trust: the candidate involved will not work with you again, and they will talk
  • A domino effect: one inspection on one point often triggers others

The pre-send checklist

Before every dossier send to a client, five checks take less than two minutes:

  • No personal email address visible
  • No personal phone number
  • No full date of birth (year only if needed)
  • No photo unless explicitly requested and the candidate has consented
  • File metadata cleaned

The record of processing: what you must document

Article 30 of the GDPR requires any organisation with more than 250 employees, and in practice any ESN that regularly processes candidate data, to keep a record of processing activities.

What the record must cover for staffing

ElementConcrete example
Purpose of processingPresenting consultant profiles to clients for IT assignments
Categories of dataIdentity, career history, technical skills, contact details
Categories of recipientsEnd clients, co-processing partners
Retention period24 months after last contact, unless a contract is ongoing
Security measuresEncrypted exports, role-based access, strong authentication
Transfers outside the EUWhere applicable (international clients, cloud hosting)

Frequent mistakes

  • A theoretical record: a Word document written once and never updated. Supervisory authorities check the last modified date.
  • An incomplete record: sourcing is documented, but not sending dossiers to clients, yet that is separate processing with its own recipients.
  • No mention of the processor: if you use a SaaS tool to generate dossiers or store profiles, that tool is a processor under the GDPR. It must appear in the record.

Candidate consent: collecting and managing it properly

Consent is the safest legal basis for sending profiles, but also the hardest to maintain.

Criteria for valid consent

The GDPR sets four cumulative conditions:

  • Freely given: the candidate must not suffer negative consequences if they refuse. “If you do not consent, we cannot propose assignments to you” is pressure that invalidates consent.
  • Specific: consent covers a precise processing operation. “I agree that my profile may be presented to client X for assignment Y” is specific. “I agree to the use of my data” is not.
  • Informed: the candidate must know what they are accepting. Which data, to whom, for what, and for how long.
  • Unambiguous: a clear positive action. No pre-ticked boxes, no silence as acceptance.

Operational consent management

In practice, two approaches work:

Per-assignment approach: you ask for consent for each send. Heavier, but legally robust. Suited to senior profiles or sensitive assignments.

Scope-based approach: the candidate consents to being presented to a category of clients (e.g. “ESNs and end clients in banking in the Paris region”) for a defined period. More flexible, but the scope must stay precise.

In both cases you must:

  • Keep proof of consent (date, channel, exact wording)
  • Allow withdrawal at any time, as easily as consent was given
  • Not make the commercial relationship conditional on consent

Sub-processing and SaaS tools: your contractual obligations

Every tool you use to store or process candidate data is a processor under Article 28 of the GDPR. CRM, ATS, dossier generation tools, cloud storage, all are in scope.

What the data processing agreement must cover

  • Subject matter and duration of processing
  • Nature and purpose of processing
  • Categories of personal data
  • Processor obligations on security
  • Conditions for engaging another processor
  • Assistance when a candidate exercises their rights
  • Return or deletion of data at the end of the contract

The “it is in the cloud” trap

Many ESNs use Google Drive, SharePoint, or Dropbox to store and share candidate dossiers. Those services are processors. When the server is in the United States, that is a transfer outside the EU that needs extra safeguards (standard contractual clauses, or an adequacy decision for the country).

Since the Schrems II judgment and the EU–US Data Privacy Framework, the situation with US providers has stabilised, but it still belongs in your record.

Betterfolio and processor compliance

For ESNs that use dossier generation tools like Betterfolio, the design aims to limit exposure from the outset: only fields relevant to the assignment appear in the export, metadata is cleaned automatically, and send history is logged to support erasure requests.


Action plan: from “we will see” to compliant in 30 days

GDPR compliance is not an 18-month programme. For an ESN with 20 to 200 consultants, the foundations can be laid in a month.

Week 1: stocktake

  • List everywhere candidate data is stored (CRM, ATS, mail, Drive, internal tools)
  • Identify who has access to what
  • Count profiles with no contact for more than 24 months

Week 2: cleanup

  • Purge obsolete profiles (or start a consent renewal campaign)
  • Clean dossier templates: remove unnecessary fields (photo, date of birth, full address)
  • Check metadata on existing PDF exports

Week 3: processes

  • Draft or update the record of processing activities
  • Define the procedure for erasure requests (who does what, by when)
  • Implement the pre-send dossier checklist

Week 4: documentation and training

  • Train sales and recruiters on the basics (no CV forwards by mail with no process, no unnecessary data)
  • Document procedures in one accessible place
  • Plan a quarterly review

What must not wait

Three actions are priorities even if everything else slips:

  • Stop sending personal contact details in client dossiers
  • Put send tracking in place (who received which profile, when)
  • Answer erasure requests within the legal one-month deadline

Sanctions: what ESNs actually risk

Theoretical GDPR fines (up to 4% of global turnover) make headlines. In practice, for an ESN, the path is more gradual, but still painful.

The scale of supervisory action

LevelMeasureExample
1Formal reminderMinor non-compliance, first offence
2Formal noticeDeadline to comply (often 1 to 3 months)
3Order with periodic penaltyX euros per day of delay
4Administrative fineProportional to seriousness and turnover
5Publication of the decisionThe company name appears on the regulator’s website

What triggers an inspection

  • A candidate complaint via the supervisory authority’s form. This is the most common trigger.
  • A report from a former employee (sales, recruiter) who knows internal practices.
  • A sector inspection: authorities publish priority themes each year. Recruitment and HR appear regularly.
  • A reported security incident (data breach, unauthorised access).

The real cost beyond the fine

For a mid-sized ESN, a supervisory procedure ties up:

  • The DPO or legal lead for several weeks
  • Management for official responses
  • Technical teams for audits and fixes
  • A specialist lawyer if the case escalates

All while commercial activity continues. That opportunity cost is rarely planned for, but it is almost always felt.


Key takeaways

GDPR compliance in IT staffing is neither a purely legal topic nor an oversized IT project. It is operational hygiene at three levels:

  • Data: collect and share only what the assignment needs
  • Processes: log sends, manage consent, purge databases
  • Tools: use solutions that build compliance in by design instead of patching it afterwards

The GDPR does not demand perfection. It demands proof of a serious approach. For an ESN, that starts with cleaning exports and knowing exactly who received what.