Data protection in recruitment

There are data protection obligations during the recruiting process, from the duty to provide information when applicants apply, to secure data processing and the anonymisation of rejected dossiers.
Schematic Diagram of Data Protection in Recruitment

Which laws must be complied with?

To ensure compliance with data protection regulations in the recruitment process, national and international laws must be observed. In Switzerland, this includes, in particular, the Swiss Federal Act on Data Protection (DSG). Depending on the organization and the specific circumstances, additional national, cantonal, or international regulations may also apply.

The General Data Protection Regulation (GDPR) has been in effect in the EU since May 25, 2018. The regulation governs the processing of personal data as well as the transfer of data within the European Union. Depending on the nature of your business and its international scope, the EU’s GDPR may therefore also apply.

Data protection in recruitment - but how?

Below you will find an overview of the influence of the FADP based on the recruiting process.

1. Planning

Data protection obligations begin as early as the planning stage of the recruiting process.

For example, data controllers are required to design the data processing technically and organizationally in such a way that the data protection regulations are complied with. These measures should correspond to the state of the art.

A data protection impact assessment is required if the planned data processing is likely to pose a high risk to the privacy or fundamental rights of the data subjects. Whether such a risk exists depends, in particular, on the nature, scope, circumstances, and purpose of the processing. In the case of sensitive data processing, such as extensive personality assessments, it should therefore be determined whether a data protection impact assessment is required.

2. Application

Please consider the following points when submitting your application or application receipt:

When accepting applications, the obligation to provide information must be observed. This means that applicants must be informed that their data will be processed. This includes, for example, the identity and contact information of the data controller, the purpose of processing, and, where applicable, the recipients of personal data. The easiest way to fulfill this obligation is through a privacy policy.

The obligation to provide information applies regardless of whether the application is submitted by mail, email, through a public job portal, the company’s own website, or applicant tracking software.

In addition, care must be taken to ensure that only the data that is necessary for the job to be filled is collected. This is referred to as data minimization or data economy. This principle applies in particular to the application form, which should only ask the applicant for the data that is really needed.

3. Editing

In order to comply with data protection in recruitment, the following principles play an important role during the processing of dossiers:

Data security must be guaranteed. Personal data must be protected against unauthorized processing and access by appropriate organizational and technical measures. Access and authorization concepts are important here. Access should also be restricted within the company to those persons who are responsible for the recruiting process or are involved in the decisions.

Data controllers must maintain a record of all data processing activities. However, in the ordinance implementing the Data Protection Act (DSG), the Federal Council has established an exception for companies with fewer than 250 employees, provided that they do not process large volumes of sensitive personal data or engage in high-risk profiling.

Data subjects have the right to request information about the processed data. The revDSG contains an extended list of minimum information that must be provided. This includes, for example, the retention period of the data. The right to information is generally free of charge and must generally be provided within 30 days.

Profiling has now been enshrined in law. It has a significant impact on recruitment. Profiling involves the automated processing of personal data to evaluate or predict certain personal characteristics of an individual. In recruiting, for example, this may include automated analysis and evaluation procedures. For high-risk profiling, a data protection impact assessment is generally required.

As a general rule, reference checks may only be conducted with the applicant’s prior consent. Only information relevant to the job in question may be collected.

If a decision in the application process is based solely on automated processing and has legal consequences for applicants or significantly affects them, the individuals concerned must be informed of this. They may also request to present their case and have the decision reviewed by a human being.

4. Data retention

With regard to data protection in recruitment, Article 6(4) of the Data Protection Act (DSG) applies to the retention of data, which states: “They [personal data] shall be destroyed or anonymized as soon as they are no longer necessary for the purpose of processing.”

Anonymisation or Deletion: Personal data may generally be stored only for as long as it is needed for the specified purpose of processing. If it is no longer needed for that purpose and there is neither a legal retention requirement nor any other justification, it must be deleted, destroyed, or anonymized.

According to the FDPIC, application data may generally be retained for up to three months after a rejection. This allows employers to defend themselves against potential claims arising from discriminatory non-hiring. In individual cases, an extension of a few weeks may be justified.

For longer-term retention in the talent pool, separate, voluntary consent with a clearly defined retention period should be obtained.

Do you want to recruit in compliance with data protection regulations? Dualoo can support you.

Conclusion

Data protection-compliant e-recruiting is essential in order to meet the legal requirements of the GDPR and the FADP. Companies must ensure transparency, data security and the rights of applicants. By taking data protection into account in recruitment, you can strengthen applicants’ trust and minimize legal risks.

You can also find all this information and more in the recording of the webinar “Data protection in recruiting”.

Legal Notice: The content of this article is provided for general informational purposes only and does not constitute legal advice. Despite careful research, we cannot guarantee the completeness, accuracy, or timeliness of the information provided. If you have any legal questions or concerns, we recommend seeking qualified legal advice.

Questions & Answers: Data protection in recruitment

Data protection protects applicant data, strengthens trust and ensures compliance with legal requirements such as the FADP or GDPR. This minimizes legal risks and conveys a professional impression.

Only authorized persons such as HR officers and responsible managers may view applicant data. Access must be limited to the application process and regulated in accordance with data protection regulations.

Employers may only process personal data that is necessary to assess a candidate’s suitability for the specific job. This includes, in particular, contact information, a CV, and relevant qualifications.

Application data may only be stored for as long as it is needed for the respective purpose. According to the EDÖB, it may generally be retained for up to three months after a rejection. For longer-term storage, such as in a talent pool, the applicants’ consent should be obtained.

Picture of Raphael Mösch
Raphael Mösch

CEO

Published
Reading time
Share this article

In use at 300+ innovative companies:

Logo von Siemens
Logo der Kägi Söhne AG
Logo Swissbankers
Logo von myClimate
Logo der Gemeinde Bad Ragaz
Logo thurbo

What else might interest you...

From professionals. For professionals.

See for yourself and test all Dualoo functions free of charge for 30 days.

The proof of the pudding is in the eating.

Newsletter registration

Newsletter registration

The proof of the pudding is in the eating.