What privacy and consent requirements apply to re-engaging past candidates?
Re-engaging past candidates requires staying within your data retention policy and the original scope of consent they gave when they applied. Under GDPR and similar privacy laws, you can only hold and use candidate data as long as you have a lawful reason to keep it.
Three specific requirements apply. If your policy states applicant data gets deleted after a set period, such as 12 months, contacting someone whose data should already be gone creates a compliance issue regardless of the outreach's intent.
Most standard application consent covers consideration for future roles at your company, not only the specific job someone applied for, but confirm this against your own privacy notice language. Candidates in the EU and similar jurisdictions can also request access to, correction of, or deletion of their data at any time, and your process needs to honor that request even for candidates from years ago.
For mid-size companies with multiple recruiters accessing the same database, consistency matters as much as the policy itself. If one recruiter re-engages a candidate whose data should have been deleted under company policy, that exposure applies to the whole organization, not just that individual recruiter.
Before re-engaging any candidate from your historical database, confirm their record still falls within your retention window, not just whether their skills fit the open role.