GDPR settings answer one question: how long candidate data stays in the system before it is removed. An administrator configures them under Settings → GDPR, and they apply to the whole company.
GDPR settings: four independent deadlines
Four deadlines, not one
The screen looks short, but it holds four numbers that are independent of one another. Each answers a different question.
How long a consent for a specific project lasts, in months — the lifetime of a consent for one recruitment, counted from the event described below.
How long a consent for future processes lasts, in months — the lifetime of the consent that lets you come back to a candidate in later recruitments. This is the number that decides how durable your database really is.
Anonymisation deadline from the newest application, in months — an independent backstop counted from the candidate's last activity. An empty field switches this deadline off; the minimum is one month. Every re-application pushes it forward.
How long a project consent lasts after a rejection, in days — the only value counted in days, because it covers the short period after a negative decision. Leave it empty if a rejection should not shorten the consent.
You will find all four fields in "GDPR settings", after expanding the "Automated candidates personal data removal" section.
What starts the clock: that is a project decision
This is the most common misunderstanding. The company settings say how much time, but what that time is counted from is chosen separately in each recruitment, in the Project consent expiry section of the project's GDPR tab. The choices are closing the project and rejecting the candidate; you can tick both, but you cannot untick both.
The two screens depend on each other in one direction: until you enter a number of days after rejection here, the "expiry after rejection" option in projects stays greyed out. First the company gives the deadline, then the project decides whether to use it.
Hence the conclusion that surprises recruiters: archiving a project is not a tidy-up. In most configurations it is the event that starts the clock.
Which consents expire
The validity period applies to consent for a specific recruitment. Consent for future recruitments has its own, usually longer period and does not react to a single project closing.
Set this before your first recruitment
The settings apply going forward. Changing a retention period does not recalculate what has already happened, so it is worth agreeing the rules before the first candidates arrive.
What next



