Is candidate rediscovery software compliant with GDPR and other data retention laws?
Reputable candidate rediscovery software can operate in compliance with GDPR and similar data retention laws. However, compliance depends on both the vendor's practices and how your organization configures retention and consent within the tool. The software itself does not automatically make your hiring process compliant; it needs to support the specific obligations your organization already has.
When confirming a vendor's GDPR posture, look for three key things. First, a signed Data Processing Agreement (DPA) defines how the vendor can use candidate data and confirms that it cannot repurpose that data outside your agreement. Second, support for data subject rights, including access, correction, and deletion requests, must work when a candidate submits a request. This support should not just exist in policy documentation, as candidates can exercise these rights years after they applied. Third, data residency matters. GDPR restricts certain cross-border transfers, so confirm where candidate data is physically stored and processed.
Rediscovery tools like Skima AI operate under a signed DPA and maintain GDPR compliance. It directly supports access, correction, and deletion requests. Candidate data is processed exclusively through Skima AI's internal models, not through public AI services. This approach keeps sensitive information within a closed environment and prevents it from being shared with a third-party API outside the agreement's scope.
Retention is your organization's responsibility, not the vendor's. A compliant tool can help by automatically flagging or excluding candidates who are past your stated retention window. However, your organization is the one that sets and enforces that window. Confirm this division of responsibility with any vendor before assuming that the software alone meets your compliance obligations.