Skip to main content

GDPR consents in a project and project consent expiry

The consent template for one recruitment, plus the extra setting that decides when the anonymisation clock starts.

Written by Maciej Michalewski

Every project has its own GDPR tab. You will find it under Project → Settings → GDPR, and it answers two questions: which consents the candidate ticks in this recruitment, and when the countdown to their anonymisation starts.

The GDPR tab in project settings

The GDPR tab in project settings

The consent template

At the top of the screen there is a single list: Consent templates. You pick a ready-made set of consents prepared for the whole company rather than writing clauses inside the project. Until you pick one you will see Project does not have GDPR consents — and that is a state in which the form must not go out into the world.

The templates themselves are edited by an administrator under Settings → GDPR templates; the Consents settings button in the project leads there, but only an administrator can see it. The types of consent and how they work are covered in a separate article.

Changing the template in a running project

The change applies going forward. Candidates who have already ticked their consents keep them in the wording that was in force when they applied — as it must be, because a consent is a declaration made at a particular time under particular text. People applying from now on will see the new template.

Project consent expiry

This is the setting that is easy to miss, because it appears conditionally. The Project consent expiry section is shown only when the chosen template contains a consent for this recruitment. If the project collects only the consent for future processes, there is nothing to time-limit and the section is not there.

When it is there, you decide what starts the countdown to the consent expiring in this particular project. Two independent options:

  • Expiry after project close — the clock starts when the recruitment is archived. Ticked by default.

  • Expiry after candidate rejection — the clock starts individually, the moment that one person is rejected.

You can tick both, and then whichever happens first counts. You cannot untick both — the system blocks saving with "Select at least one option". A project consent has to end somehow.

The second option is sometimes greyed out

If Expiry after candidate rejection is inactive, a value above it is missing: nobody has set how many days after a rejection the consent should still hold. A hint then appears under the field pointing to GDPR settings, where an administrator fills in How long the project consent lasts after a candidate is rejected, in days.

So the order is: the company sets the number of days once for everyone, then each project decides whether to use that mechanism. Until the number exists the option does nothing — rightly so, because "expires after rejection" with no deadline given means nothing.

It works the other way round too: if an administrator clears that number in the company settings, projects that had the rejection countdown ticked stop applying it. The setting is greyed out and is not sent on.

Where the candidate sees it

The actual expiry date appears on the candidate profile in the Consents tab, in the tooltip of the GDPR column on the list, and in the consent filter. What happens after that date is covered in the anonymisation article.

The Consents tab on the candidate profile with the consent valid until date

Three settings that are easy to confuse

  • Consent template (project) — which clauses the candidate ticks.

  • Project consent expiry (project) — which event starts the clock.

  • Retention periods (whole company) — how much time there is.

Did this answer your question?