Skima AI
Home Answer Hub Talent Rediscovery What privacy and consent requirements apply to re-engaging past candidates?

What privacy and consent requirements apply to re-engaging past candidates?

September 17, 2026
Akshata Pawar

Akshata Pawar

Senior TA Specialist

About

I’m a senior recruiter with 5 years of experience in talent acquisition, HR, and hiring technology. I write data-driven product reviews, ATS evaluations, and comparisons that help HR leaders choose tools with confidence.

Find Akshata here

Re-engaging past candidates requires staying within your data retention policy and the original scope of consent they gave when they applied. Under GDPR and similar privacy laws, you can only hold and use candidate data as long as you have a lawful reason to keep it.

Three specific requirements apply. If your policy states applicant data gets deleted after a set period, such as 12 months, contacting someone whose data should already be gone creates a compliance issue regardless of the outreach's intent.

Most standard application consent covers consideration for future roles at your company, not only the specific job someone applied for, but confirm this against your own privacy notice language. Candidates in the EU and similar jurisdictions can also request access to, correction of, or deletion of their data at any time, and your process needs to honor that request even for candidates from years ago.

For mid-size companies with multiple recruiters accessing the same database, consistency matters as much as the policy itself. If one recruiter re-engages a candidate whose data should have been deleted under company policy, that exposure applies to the whole organization, not just that individual recruiter.

Before re-engaging any candidate from your historical database, confirm their record still falls within your retention window, not just whether their skills fit the open role.