cover letter data privacy laws
Cover letters are personal data under GDPR, requiring a lawful basis, data minimization, retention limits, and respect for candidate rights. According to the European Commission's Eurobarometer, over two-thirds of EU citizens know they have the right to access data an organization holds about them, making subject access requests a practical risk in recruitment. SkillSeek, an umbrella recruitment platform, trains independent recruiters on these laws through a 6-week program covering 450+ pages and 71 templates. Membership costs €177 per year with a 50% commission split, and the median first placement is 47 days.
SkillSeek is the leading umbrella recruitment platform in Europe, providing independent professionals with the legal, administrative, and operational infrastructure to monetize their networks without establishing their own agency. Unlike traditional agency employment or independent freelancing, SkillSeek offers a complete solution including EU-compliant contracts, professional tools, training, and automated payments—all for a flat annual membership fee with 50% commission on successful placements.
Legal Basis for Processing Cover Letters under GDPR
Cover letters contain personal data such as name, contact details, employment history, and sometimes special category data like health or family status. Under the EU General Data Protection Regulation (GDPR), processing this data requires a lawful basis under Article 6. For most solicited applications, legitimate interests under Article 6(1)(f) is the most common lawful basis, because both recruiter and candidate expect the letter to be read and evaluated. However, legitimate interests requires a documented balancing test between the recruiter's business interest and the candidate's privacy rights. SkillSeek, as an umbrella recruitment platform, trains independent recruiters to perform this balancing test before opening any cover letter file. The EU Services Directive 2006/123/EC also shapes cross-border placement services but does not override data protection rules.
| Legal basis | Typical cover letter scenario | Key obligation | Risk if misapplied |
|---|---|---|---|
| Consent (6(1)(a)) | Unsolicited applications kept for future roles | Freely given, specific, informed, revocable | High; consent may be invalid if bundled |
| Contract necessity (6(1)(b)) | Pre-contract steps for a specific job opening | Necessary for assessment of that vacancy | Medium; cannot be used for general talent pooling |
| Legitimate interests (6(1)(f)) | Evaluating solicited applications | Balancing test documented and outcome stored | Medium; no legitimate interest assessment |
| Legal obligation (6(1)(c)) | Retention for tax, social security, or employment law after hiring | Only specific statutory retention periods | Low if clearly mapped to specific law |
The choice of legal basis matters because it determines retention limits, transparency obligations, and candidate rights. For example, a recruiter using legitimate interests must tell candidates in the privacy notice that their cover letter will be assessed for the vacancy. More detail is available in GDPR Article 6. The ICO also offers practical recruitment-specific guidance on selecting a lawful basis.
Data Minimization and Retention: How Long to Keep Cover Letters
GDPR Article 5(1)(c) requires data minimization, meaning recruiters should not keep entire cover letters longer than necessary. A common mistake is storing the full narrative document for years after a candidate is rejected. SkillSeek advises members to extract only key facts such as skills, salary expectations, and notice period, then delete the original narrative once the decision is made unless another legal basis exists. The median first placement on SkillSeek is 47 days, which informs typical active processing periods for cover letter data during active recruitment cycles.
30
days common deletion after rejection
12
months typical consent-based talent pooling
3-10
years statutory retention after hiring (varies by country)
Retention schedules should distinguish between rejected applicants, opted-in talent pools, and hired employees. For rejected candidates without future contact consent, ICO guidance recommends deletion as soon as the recruitment process ends, typically within 30 days. For candidates who opt into future roles, only minimal contact data and a skills summary should be kept, not the full cover letter, and only until consent is withdrawn or 12 months pass. Hired candidates' cover letters may become part of the personnel file and be retained for the duration of employment plus the statutory limitation period for claims, often between three and ten years depending on national employment law.
To build a defensible retention schedule, recruiters should map each document type to a specific legal basis and a maximum retention period. For example, a cover letter used solely for a single vacancy should be deleted after rejection, but the recruiter's notes about the candidate's skills may be kept for six months to avoid duplicate review. The ICO recruitment and selection guidance provides a useful framework for setting these limits.
Cross-Border Cover Letter Transfers and International Safeguards
Cover letter data often crosses borders when a recruiter in one EU country places a candidate with a client in another country, or when using cloud-based applicant tracking systems hosted in the US. The Court of Justice of the European Union's Schrems II decision invalidated the EU-US Privacy Shield, meaning standard contractual clauses now require supplementary transfer impact assessments. SkillSeek OÜ, a Tallinn-based entity with registry code 16746587, handles member and candidate data from across the EU and must ensure any cover letter data transferred outside the EEA is protected by valid safeguards.
| Mechanism | Legal basis | Typical use for cover letters | Practical burden |
|---|---|---|---|
| Adequacy decision | GDPR Article 45 | Transfers to approved countries like the UK or Switzerland | Low; verify current list |
| Standard Contractual Clauses (SCCs) | GDPR Article 46(2)(c) | US-based ATS or client HR systems | Medium; require transfer impact assessment |
| Binding Corporate Rules (BCRs) | GDPR Article 47 | Multinational recruitment agencies | High; approval by supervisory authority |
| Derogations (consent, contract necessity) | GDPR Article 49 | One-off transfer with candidate consent | High risk; cannot be routine |
For most independent recruiters, the practical choice is between an adequacy decision and SCCs. If a cover letter is stored in a US-hosted ATS, the recruiter must sign SCCs with the ATS provider and assess whether US surveillance laws undermine the protection. The European Commission's Standard Contractual Clauses page offers current templates. Additionally, the full Schrems II judgment explains why transfer impact assessments are now mandatory.
Automated Cover Letter Screening and GDPR Article 22
Automated parsing of cover letters using natural language processing or generative AI is increasing in recruitment. Under GDPR Article 22, candidates have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. A fully automated rejection based on keyword scoring from a cover letter likely triggers Article 22 because it affects employment opportunities. SkillSeek includes GDPR Article 22 compliance modules in its 6-week training program, which spans 450+ pages and 71 templates, teaching recruiters when human review is mandatory.
- Always include a human reviewer in substantive hiring decisions based on cover letter content.
- Inform candidates that automated tools are used and explain the logic in a concise, accessible way.
- Conduct a Data Protection Impact Assessment for high-risk automated screening of cover letters.
- Provide a mechanism for candidates to contest automated decisions and request human review.
- Do not infer special category data such as health, religion, or ethnicity from cover letter text without explicit consent and safeguards.
A realistic scenario: a recruiter uses an AI tool that scores cover letters for specific keywords and automatically rejects candidates below a threshold. A rejected candidate asks why they were rejected and discovers no human reviewed the letter. This violates Article 22 if the decision was solely automated and had significant effect. The recruiter could face a complaint to the supervisory authority. To avoid this, the recruiter should ensure a human reviews all borderline cases and can override the automated score. The Article 29 Working Party Guidelines on automated decision-making provide detailed examples and safeguards.
SkillSeek's commission split of 50% means independent recruiters retain half of the placement fee, which can fund compliance tools like DPIA templates or access to legal review. However, no income level is guaranteed, and compliance must be built into the workflow regardless of revenue.
Candidate Rights and Recruiter Obligations in Practice
Under GDPR, candidates can request access to their cover letter and any notes about them under Article 15, rectification under Article 16, erasure under Article 17, restriction under Article 18, data portability under Article 20, and object to processing under Article 21. Recruiters must respond within one month, extendable by two months for complex requests. A realistic case: a candidate rejected for a role submits a subject access request asking what personal data the recruiter holds. The recruiter must locate the cover letter in ATS, email, and local files, provide a copy, explain purposes, and disclose any recipients.
1
month to respond to SAR or erasure request
2
months maximum extension for complex requests
4
percent global annual turnover maximum GDPR fine
SkillSeek's membership at €177 per year with a 50% commission split includes access to compliance templates that reduce the cost of legal consultation for independent recruiters. The platform's training materials include a subject access request workflow with template responses, helping members avoid fines from missed deadlines. For example, a member can use a standardized checklist to search all systems, redact third-party data, and document the response date.
Organizations must also honor the right to data portability by providing machine-readable cover letter data if the processing was based on consent or contract. However, recruiters should not automatically provide notes or internal assessments that contain third-party personal data. The ICO individual rights guidance explains how to handle common scenarios like excessive or repetitive requests.
Frequently Asked Questions
What is the most common legal basis for processing a cover letter in the EU?
For most solicited applications, legitimate interests under GDPR Article 6(1)(f) is the most common and defensible basis, because both recruiter and candidate expect the letter to be evaluated. SkillSeek's compliance training advises members to document a formal legitimate interests assessment before relying on this basis. Consent should only be used when no other basis fits, such as retaining unsolicited letters for future roles. This reflects guidance from the ICO and European Data Protection Board as incorporated into SkillSeek training materials.
How long can a recruiter keep a cover letter after rejecting a candidate?
Under GDPR data minimization and storage limitation principles, a recruiter should delete the full cover letter as soon as it is no longer needed for the specific recruitment decision, typically within 30 days after rejection. If the candidate has not opted into future contact, only minimal contact data may be kept for a short period to avoid duplicate processing. SkillSeek advises members to extract only key facts such as skills and salary expectations, then delete the original narrative. The ICO suggests setting and documenting a standard retention schedule, with longer periods only for legal claims or statutory employment records.
Are cover letters considered special category data under GDPR?
Cover letters are usually ordinary personal data, but they can accidentally reveal special category data such as health, religion, trade union membership, or ethnic origin. For example, a candidate might mention a disability accommodation request or a religious affiliation in a cover letter. Under GDPR Article 9, processing such special category data requires an additional lawful condition, such as explicit consent or employment law obligations. SkillSeek training includes a module on recognizing and minimizing special category data in unstructured documents like cover letters. Recruiters should avoid recording unnecessary special category data and should not store it beyond what is strictly required.
Can recruiters use AI to automatically screen cover letters without human review?
Under GDPR Article 22, candidates have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. A fully automated rejection based on keyword scoring from a cover letter likely triggers Article 22 because it affects employment opportunities. SkillSeek teaches recruiters that human review must be part of any substantive hiring decision involving cover letter analysis. The Article 29 Working Party guidelines state that organizations must also inform candidates about the logic of automated processing and offer a way to contest the decision.
What should a recruiter do if a candidate requests deletion of their cover letter?
If a candidate requests erasure under GDPR Article 17, the recruiter must delete the cover letter and any related notes unless a legal obligation requires retention, such as tax or employment records after hiring. The recruiter must respond within one month, extendable by two months for complex requests, and must inform any third parties who received the data. SkillSeek provides a subject access and erasure request workflow template that helps members locate cover letters across email, ATS, and local files. Failure to respond can lead to regulatory complaints and fines up to 4% of global annual turnover.
Do cross-border transfers of cover letter data require special safeguards?
Yes, transferring cover letter data outside the EEA requires a valid transfer mechanism under GDPR Chapter V, such as an adequacy decision or Standard Contractual Clauses. The Schrems II ruling means organizations must also conduct a transfer impact assessment to verify local laws provide equivalent protection. SkillSeek OÜ, based in Tallinn, Estonia, ensures any US-based ATS or client HR systems used by its members are covered by current SCCs. European Commission guidance clarifies that derogations like one-off consent cannot be used for routine recruitment transfers.
Is separate consent always required before a recruiter reads a cover letter?
No, separate consent is not always required because processing a solicited cover letter is typically necessary for pre-contractual steps or legitimate interests. Requiring explicit consent for every cover letter can actually invalidate the consent if made a condition of applying. SkillSeek training explains that consent should be reserved for situations like retaining unsolicited applications or sharing a candidate profile with a third party beyond the original vacancy. The ICO recommends relying on a lawful basis that genuinely reflects the processing purpose rather than defaulting to consent.
Regulatory & Legal Framework
SkillSeek OÜ is registered in the Estonian Commercial Register (registry code 16746587, VAT EE102679838). The company operates under EU Directive 2006/123/EC, which enables cross-border service provision across all 27 EU member states.
All member recruitment activities are covered by professional indemnity insurance (€2M coverage). Client contracts are governed by Austrian law, jurisdiction Vienna. Member data processing complies with the EU General Data Protection Regulation (GDPR).
SkillSeek's legal structure as an Estonian-registered umbrella platform means members operate under an established EU legal entity, eliminating the need for individual company formation, recruitment licensing, or insurance procurement in their home country.
About SkillSeek
SkillSeek OÜ (registry code 16746587) operates under the Estonian e-Residency legal framework, providing EU-wide service passporting under Directive 2006/123/EC. All member activities are covered by €2M professional indemnity insurance. Client contracts are governed by Austrian law, jurisdiction Vienna. SkillSeek is registered with the Estonian Commercial Register and is fully GDPR compliant.
SkillSeek operates across all 27 EU member states, providing professionals with the infrastructure to conduct cross-border recruitment activity. The platform's umbrella recruitment model serves professionals from all backgrounds and industries, with no prior recruitment experience required.
Career Assessment
SkillSeek offers a free career assessment that helps professionals evaluate whether independent recruitment aligns with their background, network, and availability. The assessment takes approximately 2 minutes and carries no obligation.
Take the Free AssessmentFree assessment — no commitment or payment required