The Legal Importance of Consent in Hiring
Hiring processes are dynamic processes where employers collect extensive personal data about candidates. Every data point, from the information in a candidate's resume to interview records, test results, and reference evaluations, is under the guarantee of the General Data Protection Regulation (GDPR).
The most frequent misconception human resources units fall into regarding GDPR applications is interpreting the candidate's submission of their resume as "giving implicit approval for all their data to be processed and their references to be called." However, under data protection law, implicit (tacit) consent is not valid. In order for the candidate to be subjected to the reference check process and for their former workplaces to be contacted, there must be a clear and unambiguous declaration of will that meets the conditions sought by the law.
In this comprehensive guide, we will examine how to prepare a valid consent form in line with the precedent-setting principle decisions of the data protection supervisory authority, discuss the legal intricacies, and share ready-to-use text templates that you can directly use in your company.
3 Essential Elements of a Valid Consent
Consent under Art. 4(11) and Art. 7 is defined as:
*"Freely given, specific, informed, and unambiguous indication of the data subject's wishes."*
According to this legal definition, for a consent form to be considered valid in audits and courts, it must cumulatively carry the following three elements:
The Legal Difference Between a Privacy Notice and a Consent Form
The biggest procedural error made by the human resources and legal departments of many companies is merging the Privacy Notice and the Consent Form into a single text or trying to have both accepted together with a single checkbox.
In accordance with the established principle decisions of the data protection supervisory authority, these two legal actions must be definitively separated from each other:
- Privacy Notice (GDPR Art. 13): It is the statutory obligation of the data controller. It is not subject to the other party's approval, consent, or acceptance; it is a unilateral and binding notification. A declaration like "I approve the privacy notice" cannot be requested from the candidate; the statement "I have read, understood, and been informed about my rights regarding the privacy notice" is sufficient.
- Consent Form (GDPR Art. 6 and Art. 9): It is an exceptional declaration of will that comes into play when other legitimate legal bases for processing data (explicitly stipulated in laws, being directly related to the establishment or performance of a contract, the legal obligation of the data controller) do not exist. It must absolutely be presented as a separate text and must be obtained with a separate checkbox and an active affirmative action by the candidate (by clicking on an initially unchecked empty box).
The Principle of Not Conditioning Consent on the Application
One of the most critical rules persistently emphasized in the precedent-setting decisions of the data protection supervisory authority is the "prohibition of conditionality on the provision of a service."
On a job application portal or form, the candidate cannot be subjected to a requirement like:
*"If you do not approve the consent form, your job application cannot be completed and will not be taken into consideration."*
Because the candidate's name, surname, contact information, education, and professional experience in a basic job application are necessary and legitimate for the establishment of an employment contract within the framework of national employment law. These basic data can be processed on the legal basis of establishing the contract even without consent. However, calling the candidate's previous workplaces (reference check) or retaining the data in a talent pool for 2 years is an additional activity and relies on consent. Even if the candidate does not consent to the reference check, they cannot be deprived of the right to be evaluated with their current information.
The Role of Consultancy and Headhunter Firms in Hiring
Hiring processes are often conducted through outsourced consultancy or headhunter companies. In this scenario, the candidate's personal data changes hands among multiple data controllers:
- Recruitment Consultancy: Is the data controller in the capacity of the institution that first collects the candidate's data and performs the preliminary reference check.
- Employer Company: The client company that will make the final hiring decision and is an independent data controller.
A Data Processing Agreement (DPA) must necessarily have been signed between these two institutions, and the consent form presented to the candidate must clearly state with which client companies the data and the reference report can be shared. Leaking the reference report to third-party companies without the candidate's knowledge is a severe violation of legislation.
Special Categories of Personal Data and the Reference Process
During reference checks, former managers must be strictly prevented from delving into sensitive topics such as the candidate's health, trade union membership, political, or philosophical opinions. In accordance with GDPR Art. 9, the processing of special categories of personal data is subject to much stricter conditions and a separate consent structure.
In reference forms and question sets, no questions about:
- "Whether the candidate frequently takes sick leave or has a chronic illness"
- "The candidate's family situation, marital status, or pregnancy plans"
- "Religious belief, ethnic origin, or political opinion"
can be included. Even if the person providing the reference makes comments on these topics of their own accord, these statements must not be included in minutes or reports and must be destroyed immediately.
Sample Reference Consent Form Template for the Candidate
The following text is a legally sound template that you can directly integrate into your documents or application portals while obtaining reference check permission from candidates in your hiring processes:
CANDIDATE CONSENT FORM REGARDING THE REFERENCE CHECK PROCESS
I have read and understood the "Privacy Notice Regarding the Processing of
Candidate Employee Personal Data" presented to me by [Company Trade Name]
("Company") and I have been informed in detail about my rights under the
General Data Protection Regulation.
In this regard;
For the purpose of verifying my suitability for the open position I applied
for, my past professional experiences, duty and responsibility areas, work
discipline, team compatibility, and work outputs;
1. I consent to the contact of the reference persons (my former managers,
department officials, and colleagues) specified by me in the job
application form or resume via phone, email, or digital reference
verification systems,
2. I consent to these persons being asked questions regarding my previous
employment relationship, performance, competencies, and departure
process, and to the professional evaluation data declared by these
persons being collected and processed by Company officials for the
purpose of establishing the hiring decision,
3. I consent to the prepared reference verification and consistency report
being kept encrypted on the secure servers within the Company for the
maximum retention period prescribed in the legislation and the Personal
Data Retention and Destruction Policy,
Without being under any pressure or coercion, I GIVE MY CONSENT with my
free will.
[ ] I Accept (Please check)
Candidate Name Surname : ....................................................
ID Number : ....................................................
Date : ...... / ...... / 202...
Signature / Time-Stamped Digital Approval: ..................................Privacy Notice and Consent Form for the Reference Provider
Another party that should not be forgotten in the reference process is the person providing the reference. The name, title, corporate title, work phone, email, and opinions about the candidate of the manager acting as a reference are also personal data. The following text should be included at the opening of the digital link sent to the reference person:
REFERENCE PROVIDER PRIVACY NOTICE AND DATA PROCESSING CONSENT FORM
Dear Authorized Person,
[Candidate Name Surname] has listed you as a reference in order to obtain
information about their past work experience and competencies within the
framework of their job application to our company.
In this context, your identity, contact, title, institution data, and
objective evaluation data about the candidate that you will share in the
form you will fill out; in accordance with the GDPR, will be processed
solely for the purpose of evaluating the hiring process of the candidate in
question, will not be shared with third parties, and will be safely
destroyed at the end of the legal retention periods in accordance with our
company's Retention and Destruction Policy.
I confirm the accuracy of the information I shared and I approve the
processing of this data limited to the legitimate purpose stated above.
[ ] I Approve and ContinueThe Right to Withdraw Consent (Revocation) and Its Procedure
Since consent is a right dependent on the data subject's will, it can be revoked at any time. According to GDPR legislation, data processing must be stopped immediately from the moment the data subject reports that they have withdrawn their consent.
The consent withdrawal procedures that companies must provide are:
- Easy Access: The candidate must be offered the right to withdraw consent with a method as easy as giving consent (e.g., a web form opening with one click or a specific email address).
- Stopping the Process: When consent is withdrawn, references that have not yet been called must be canceled, and the intermediate data collected must be destroyed immediately.
- Principle of Non-Retroactivity: The withdrawal of consent does not invalidate the data processing activities carried out lawfully up to that point; however, it immediately terminates prospective processing.
Step-by-Step Consent Checklist for HR Teams
Human resources units wishing to zero out legal risks should review the following checklist before every reference check:
Conclusion: Digital Infrastructure That Zeroes Legal Risks
It is impossible to successfully pass data protection audits in reference processes conducted over paper forms, WhatsApp messages, or phone calls. It cannot be proven when consent was obtained, whether the text was fully shown to the candidate, and whether the reference provider was provided with a privacy notice.
AuditCV.io presents the time-stamped digital consent approval to the candidate step by step during the reference collection process, meets the reference persons with fully compliant privacy notices, and grants both the candidate and the reference provider the possibility to withdraw consent (revoke) with a single click. In this way, companies zero out the risk of administrative fines while offering a prestigious and corporate hiring experience.