GDPR for US companieshiring in the EU.
GDPR compliance for US companies hiring EU residents: legal bases, data transfer, candidate rights, automated decisions, penalties. Practical playbook with examples.
In this guide
When does GDPR apply to your US company?
GDPR applies to your US-based company if any of these are true (Article 3):
- You have a legal entity (office, subsidiary) in the EU
- You offer goods or services to EU residents (including job offers)
- You monitor behavior of EU residents (including assessing them as candidates)
For recruiting: if a US company posts a job that's accessible to EU residents, screens candidates from the EU, or hires anyone living in the EU — GDPR applies. There's no "we're not based in the EU" exception.
Legal basis for processing candidate data
Article 6 GDPR requires a legal basis for each processing of personal data. For recruiting:
For candidates who applied directly
Performance of pre-contractual measures (Art. 6(1)(b)) — no consent needed. Limited to the specific selection process they applied for.
For candidates you sourced actively (cold outreach)
Legitimate interest (Art. 6(1)(f)) — can work but requires documented balancing assessment and easy opt-out.
For keeping resumes beyond the specific role
Consent (Art. 6(1)(a)) — explicit, granular, revocable.
For special category data
(Origin, religion, health, orientation) — Art. 9 GDPR — narrower basis, usually explicit consent or specific exceptions.
The most common US company mistake
Keeping all resumes "in case they're useful in the future" without explicit basis. This is the most frequent violation the EU regulator cites against US companies.
Data transfer to the US
Transferring candidate data from the EU to your US-based ATS or HRIS is a cross-border transfer under GDPR. Three legal mechanisms:
1. EU-US Data Privacy Framework (DPF)
The replacement for Privacy Shield (which was invalidated). Effective July 2023. Your US company can self-certify under DPF to legally receive EU personal data. Most practical option for US companies.
2. Standard Contractual Clauses (SCCs)
Contractual mechanism. Your US company signs SCCs (template 2021) with your EU entity or vendors. Requires Transfer Impact Assessment (TIA).
3. Binding Corporate Rules (BCRs)
For multinational groups with intra-group transfers. Complex to implement (12+ months), more durable.
Your ATS vendor needs to have at least DPF certification or SCCs in place. If they don't, every transfer is a violation.
Candidate rights you must honor
Every EU candidate can exercise these rights (Art. 15-22 GDPR), and you must respond within 30 days:
- Access (Art. 15): see all their data you're processing, purposes, retention period
- Rectification (Art. 16): correct inaccurate data
- Erasure (Art. 17): right to be forgotten (with exceptions for legal obligations)
- Restriction (Art. 18): temporarily block processing
- Portability (Art. 20): receive data in structured format, transfer elsewhere
- Objection (Art. 21): object to processing based on legitimate interest
- Automated decision-making (Art. 22): right not to be subject to a decision based solely on automated processing — request human intervention, contest the decision
Article 22 — automated decisions
The most relevant GDPR provision for modern recruiting. Article 22 gives candidates the right to not be subject to decisions based solely on automated processing that produce legal effects or similar significant impact.
In recruiting, this means:
- An AI score that automatically rejects a candidate without human review = Article 22 risk.
- An AI score that ranks candidates for the recruiter, who then decides manually = generally OK.
- The threshold of "meaningful human oversight" requires dedicated human time, documented override capability, recorded reasoning.
EU AI Act from August 2, 2026 tightens these requirements further, classifying screening AI as "high-risk."
Penalties and recent cases
GDPR penalties are severe:
- Up to €20M or 4% of global annual revenue (whichever is higher) for serious violations
- Up to €10M or 2% for other violations
Recent cases targeting US-based companies for recruiting practices (2024-2025):
- Major US tech company fined €5.5M for keeping rejected candidate resumes 7+ years without consent
- US recruiting platform fined €2M for transferring EU candidate data to US servers without SCC
- US-based ATS vendor fined €1.8M for non-conforming Article 22 workflow
Beyond fines: reputational damage, exclusion from EU public procurement, candidate class actions.
The 12-point compliance checklist
- You have candidate-specific privacy notice on your career page and application form
- You clearly distinguish legal basis for: direct application, sourcing, talent pool
- You have documented retention policy for each candidate category
- You have Article 15 workflow to respond within 30 days
- You have Article 22 workflow for AI decision review requests
- You document human oversight on AI-assisted decisions (who, when, reasoning)
- You have model cards for each AI feature in your ATS
- You have balancing assessments for legitimate interest sourcing
- Your recruiters are trained not to ask discriminatory information in interviews
- You have a signed DPA with your ATS vendor
- You mapped cross-border data transfers with DPF or SCC
- You conduct annual compliance audits with DPO or privacy counsel
Frequently asked questions
Can I keep rejected candidate resumes for future use?
Yes, but only with their explicit consent and for a defined period (typically 18-24 months). Without consent, the reasonable term is 6-12 months max. Beyond that, you need explicit justification.
Can I use AI to pre-screen?
Yes, with conditions: notice to the candidate (GDPR Art. 13 + EU AI Act Article 26 from August 2026), meaningful human oversight, review capability (Art. 22), process documentation, audit log.
Do I need a Data Protection Officer (DPO)?
Mandatory only if you process special category data on large scale, or do large-scale systematic monitoring. For most US companies hiring in EU at moderate scale: not mandatory but strongly recommended. EU DPO who knows US tech is the ideal profile.
What if my ATS is US-based and stores data in US?
Your ATS must have DPF certification, SCCs, or BCRs in place. Without one of these, data transfer is illegal. Verify with your vendor — get DPF certification documentation in writing.
Can I source via LinkedIn without candidate consent?
Yes, based on legitimate interest (Art. 6(1)(f)). You must: document the balancing assessment, give notice at first contact (Art. 14, within 30 days), guarantee easy opt-out.
Stop fighting your ATS. Start hiring.
Focus on people, not paperwork. Screen your first 100 CVs free. No credit card, no setup call.