Skip to main content

Where the consent a candidate ticks comes from

The three places consents are configured, and the one combination the system refuses.

Written by Maciej Michalewski

"Why is there no consent for future recruitments in this form?" is a question that almost always has the same answer: consents are configured in three different places, depending on which way the candidate comes in. The form has no consents of its own — it inherits them from the route.

1. The candidate applies for a specific role

This covers most cases: a job ad, a link from a job ad, a link to one recruitment. The consents then come from the template chosen in the project, that is from Project → Settings → GDPR. The article on consents in a project covers this.

The GDPR tab in project settings with the consent template list

The practical conclusion: if a job ad carries the wrong consents, do not look for them on the ad. Fix the template in the project the ad came from.

2. The candidate applies without naming a role

This is the general application link, a spontaneous application, a "leave us your CV" form on the careers page. There is no project, so there is no template to take — consents for these entries are set separately by an administrator under Settings → GDPR, in the General application links section.

The General application links section in GDPR settings with the template choice and a consent

What the system will not allow here

You cannot add a consent for a specific recruitment to a general link. Trying to save such a template shows a message saying exactly that. The reason is simple: a project consent has to point at a project, and a general link by definition points at none — there would be no way to know what the candidate is agreeing to, or when that consent should expire.

The right consent for these entries is the consent for future recruitment processes. That is the one that lets you come back to this person when a matching role appears.

3. The candidate comes through the referral programme

A separate route and a separate set of consents, also under Settings → GDPR, in the GDPR consents for the referral system section. It covers the situation where somebody other than the candidate leaves the data, so the clause has to read differently.

The referral consents section with the consent template choice

And a candidate added manually?

Then the recruiter picks the consent in the add-candidate dialog, and the field is required — you cannot put a person into the system without declaring a basis for processing their data. If there is no basis, send a GDPR consent request: the candidate gets a link to the form and ticks the consents themselves, which is a cleaner route than ticking on their behalf.

The GDPR consents section in the Create candidate window with the Send GDPR consent request switch

Cheat sheet

  • application for a role → the template in the project,

  • general link and spontaneous application → Settings → GDPR, General application links (no project consent),

  • referral → Settings → GDPR, consents for the referral system,

  • added manually → the recruiter's choice while adding, or a consent request sent to the candidate.

Did this answer your question?