What GDPR-Compliant CV Screening Looks Like in Practice
See how GDPR-compliant CV screening works day to day, from lawful basis and encryption to transparency, retention, and audit-ready, explainable results.

You can screen hundreds of resumes in minutes without tripping GDPR. The path is practical: keep people in charge, document why you process data, minimize what you touch, secure it, and leave a record that explains every decision.
GDPR-compliant CV screening means using resume screening software with a lawful basis, meaningful human involvement, data minimization, appropriate security, transparency for candidates, support for their rights, and an audit trail that shows what happened and why.
What GDPR-compliant CV screening requires
Lawful basis. Most employers rely on legitimate interests (GDPR Art. 6(1)(f)) to process applicant data for recruiting. Document your Legitimate Interests Assessment: the purpose (screening and selection), necessity (you cannot run a hiring process without evaluating CVs), and the balance test (reasonable expectations, safeguards, and human oversight). Tell candidates in your privacy notice that you use automated tools to support screening and that a person will make the final call.
Human control and Article 22. If a technology makes decisions that produce legal or similarly significant effects, Article 22 limits purely automated decision-making. Keep people in the loop with clear, reviewable logic and the ability to override. With Marxel, humans set and approve the rules before any screening runs. The product can generate reviewable screening criteria from your job description and notes, then lets your team edit, weight, add, or remove criteria and approve them. Bias-aware checks flag vague or risky items before they affect scoring. During review, Marxel places candidates into four decision buckets Aligned, Potential, Hold, or Unclear to speed review, and it allows manual rebucketing so a person stays in control.
Data minimization and special-category data. Limit inputs to what is necessary for the role (GDPR Art. 5(1)(c)). Avoid processing protected characteristics or inferring them from proxies. Do not ask the model to score on non-job factors. Explainability should show job-related criteria only. Marxel’s review screens show which criteria a candidate matched, any concerns, and confidence levels so reviewers can act without rereading the CV end to end. That gives you meaningful human involvement, not a black box.
UK buyers. If you are comparing CV screening software UK buyers can use the same playbook under UK GDPR. The principles mirror the EU framework, including human involvement and explainability for high-impact decisions.
Security, data minimization, and retention
Security controls. GDPR expects security appropriate to risk (Art. 32). For AI screening that means access controls, role-based permissions, encryption in transit, and clear limits on how data is used. Marxel supports GDPR-conscious handling. It encrypts data in transit and uses access controls. It does not use uploaded CVs to train Marxel-owned models. Teams can run bulk CV screening up to 200 files in one batch and see processing progress and runtime as the data is processed. Pro plans offer priority processing for faster turnaround, which keeps personal data exposure windows short without changing your security posture.
Minimize and separate. Keep raw CVs, extracted features, and scoring outputs compartmentalized. Restrict who can view full resumes. Use named roles for recruiters and hiring managers. Do not enrich CVs with third-party data you do not need. If you use a vendor, put the processor obligations in your contract and document where data is stored and who can access it.
Retention and deletion. Set retention schedules that match your legal and business needs (Art. 5(1)(e)). Keep data only as long as necessary to run the hiring process, defend decisions, and meet regulatory requirements. Apply the same rules to raw CVs, screening outputs, notes, and audit records. In practice, this means documenting how long you store applications for filled or closed roles, how you handle talent-pool consent if you keep CVs longer, and how you remove them afterward. Marxel’s records and exports help you decide what to retain for compliance versus what to purge in your core HR systems. Align your retention plan with your applicant tracking system so the policy is consistent across tools.
Transparency, candidate rights, and audits
Privacy notice and explainability. Tell applicants you use automated tools and why, what data you process, and how long you keep it (Arts. 13–14). Share a plain-language summary of the logic you apply and explain that human reviewers can override results. Make it easy for candidates to access their data, correct errors, object to processing, or ask for human review.
Evidence you can show. Marxel supports transparency by keeping the reasoning, scores, and notes attached to each candidate. The audit trail and governance features keep approved criteria, reviewer notes, bucket changes, and decision reasoning in one place. CSV shortlist export makes it straightforward to share summaries with internal stakeholders or respond to information requests with clear, human-readable context. Candidate-pool queries let hiring teams compare applicants across CV evidence, notes, scores, recommendations, and prior evaluations, which helps demonstrate consistent treatment. Processing progress tracking shows when a batch ran and how long it took, adding timing context to your records.
Know the market context. On the candidate side of the ai job search, many applicants tune resumes to pass ATS checks. To see the playbook they use, read ApplyTop’s guide to accurate ATS resume checks. It is a useful backdrop for designing clear candidate communications about your own screening process.
A compliant workflow with Marxel
- Define the rubric. Create the screening rubric from your job description. Marxel generates draft criteria from the brief. Your team then edits and approves weighted criteria. Bias-aware checks flag vague or potentially discriminatory criteria before scoring is allowed.
- Process at scale. Upload up to 200 CVs in one run. Watch processing progress and runtime so you can plan reviews and keep stakeholders informed. Pro plans support priority processing when you face time-sensitive hiring.
- Review explainable results. Candidates are sorted into Aligned, Potential, Hold, or Unclear with per-candidate evidence showing matched criteria, concerns, and confidence. Reviewers see why a score looks the way it does and can open the underlying CV when needed.
- Exercise human judgment. Move candidates between buckets when needed. Use candidate-pool queries to compare applicants across evidence and notes for consistent decisions. Resolve bias-aware flags before finalizing a shortlist.
- Share and record. Export the shortlist with reasoning to CSV for handoff or reporting. The audit trail retains criteria, notes, bucket changes, and decision rationale for compliance needs. Align exports with your ATS so the record is consistent across systems.
Real-world examples
- Good practice. A UK tech firm documents legitimate interests for screening, approves a reusable scoring rubric before any uploads, then runs AI screening to create an automated candidate shortlist. Reviewers move two applicants from Hold to Potential based on recent project work noted in the CV. The audit trail shows the change, notes, and why. The privacy notice explains the tool and human involvement.
- Risky practice. A team copies last year’s criteria without review, includes a vague “culture fit” item, and never records who approved it. When asked, they cannot show why one candidate was rejected. Under GDPR, that opacity and lack of control creates exposure. Bias-aware checks and required criteria approval would have prevented this.
- Efficient and safe. A retail group faces a seasonal surge and uses priority processing to turn around 180 applications in a day. Encryption in transit protects files during upload, and the team exports a CSV shortlist with reasoning for store managers to review. Retention rules in the HRIS remove records after the season ends.
Key takeaways
- Keep people in charge. Approve criteria up front, use explainable outputs, and allow manual rebucketing.
- Protect data. Encrypt in transit, control access, and avoid training models on applicant data.
- Be transparent. Inform candidates about the tool and human oversight. Keep reasoning attached to each decision.
- Write the rules down. Document lawful basis, retention timelines, and who can access screening outputs.
- Be audit-ready. Preserve criteria, notes, changes, and per-candidate evidence in one record.