# The Retention-Clock Reference: How Long to Keep Each Sourced Record

*You can look up any sourced record by type, lawful basis, and jurisdiction and set a defensible retention period with a named clock-start event.*

- Canonical URL: https://www.refolk.ai/guides/sourced-record-retention-clock-reference
- Pillar: Process, data, and compliance
- Format: Reference
- Published: 2026-10-05
- Last reviewed: 2026-10-05
- Reading time: 17 min

Deciding how long a sourced contact record may lawfully be kept, and when the clock starts, is a lookup job, not an essay. This reference is for the recruiting-operations and revenue-operations leads who own the retention schedule, and for the data-protection officers who have to defend it. Jump to the row for your record type, lawful basis, and the contact's jurisdiction, and leave with a period, a named clock-start event, and the authority behind it.

Most public answers collapse this into a vague "6 to 12 months" and never separate the record type from the lawful basis from the event that starts the timer. That collapse is where schedules fail an audit. A flat six months is wrong in both directions: France allows two years from last contact, the Netherlands defaults to four weeks. The number is the easy part. The clock-start event is the part that gets organisations fined.

## What the storage-limitation principle actually requires

GDPR sets no retention number, so the number is yours to derive and defend. Article 5(1)(e), the storage-limitation principle, says personal data may be kept no longer than the purpose requires. For a job application, the purpose ends when the role is filled.

That single sentence reframes the whole question. You are not looking up a statutory period for a sourced CV, because there is not one. You are naming a purpose, then setting the shortest period that serves it, then naming the event the period runs from. Everything else in this reference is the jurisdiction-specific answer to "what purpose survives after the role is filled, and for how long."

For a rejected or cold-sourced candidate, the surviving purpose is almost always the same: defending against a discrimination claim. That purpose has a natural ceiling at the claim window, which is why the period collapses to roughly 6 to 12 months and why anything beyond needs consent. The claim window is a fact about employment law in each country, not a privacy guess, which is what makes the derived period defensible.

> **Rule:** Derive the number, do not import it
>
> Keep no record longer than its purpose requires. For a rejected candidate the purpose is defending a claim, so the period is the claim window in that jurisdiction, not a round number copied from a blog post.

## Retention by jurisdiction for sourced and unsuccessful candidates

For an unsuccessful or cold-sourced candidate, the defensible period ranges from four weeks in the Netherlands to two years in France, each tied to a different authority and a different clock-start event. Read the row for the contact's country, not your own.

| Jurisdiction | Period | Clock-start | Authority |
| --- | --- | --- | --- |
| UK | ~6 mo (claim window) | process end | ICO / UK GDPR |
| Germany | 6 mo | rejection receipt | AGG / Bavarian DPA |
| France | 2 yr (+5 yr archive) | last contact | CNIL |
| Netherlands | 4 wk (1 yr w/ consent) | end of procedure | AP |
| US federal | 1 yr (2 yr public/edu) | record/decision date | EEOC |

The UK position comes from the ICO's recruitment and selection guidance, which is explicit that unless there is a clear business reason you should not keep unsuccessful-applicant records beyond the statutory period in which a claim may be brought. Practitioners default to six months, and stretch to six to twelve with documented justification.

Germany is six months as the practitioner standard, derived from the Allgemeines Gleichbehandlungsgesetz, the General Equal Treatment Act. There is a genuine disagreement here worth recording in your schedule: the AGG filing window is short, so some argue three months, but the Bavarian State Office for Data Protection Supervision deems six months after receipt of the rejection appropriate, and most agencies add a buffer to reach six.

France is the outlier on length. The CNIL recommends a maximum of two years from the last contact with the candidate for the active base, after which data may be kept in an intermediate base, consulted only on a restricted and justified basis by specifically authorised staff, for five further years. The Netherlands is the outlier the other way: if an applicant is not taken on, it is customary to delete the data no later than four weeks after the end of the application procedure, extendable to one year only with consent.

US federal is shaped by anti-discrimination recordkeeping, not privacy law. Covered employers must retain applicant records for at least one year from the date the record was made under Title VII, the ADA, GINA, and the ADEA. State and local governments, educational institutions, and certain federal contractors must preserve applicant records for two years from creation.

**360.9M - Euros in employment-sector GDPR fines**

193 employment-sector fines recorded on the GDPR Enforcement Tracker, so candidate-data mistakes are expensive, not theoretical.

## How lawful basis changes the period and the clock

Lawful basis does not change the statutory number, because there is no statutory number. It changes how long the purpose survives, which is what actually drives the clock. Two records of the same type can carry different periods if one rests on legitimate interest and the other on consent.

Legitimate interest, specifically the interest in defending against discrimination claims, justifies roughly 6 to 12 months. That is the active-sourcing basis for most RecOps teams, and it is the reason a rejected CV does not vanish the day the role is filled. You hold it long enough to answer a claim, then you purge it.

Consent is the basis for anything longer, and it is a different animal. Moving a rejected candidate into a talent pool is a new purpose, so it needs its own basis rather than a longer number. Legitimate interest does not stretch to cover it. The common mistake is to treat an opt-in box as a longer legitimate-interest clock; it is not, it is a separate basis that must be refreshed, not extended.

> **Watch out:** Consent is not a longer legitimate interest
>
> A rejected candidate on legitimate interest cannot be slid into a talent pool on the same basis. The pool is a new purpose requiring consent, and that consent must be refreshed, not quietly inherited from the application.

Document the legitimate interest assessment and keep it on file. The assessment is not paperwork for its own sake; it is the artefact that turns a derived period into a defensible one when a regulator asks why you kept a CV for eight months.

## Record type decides the clock, even inside one placement

Different record types in the same operation carry wildly different clocks, and conflating them is the costliest error in this whole reference. A single placement produces a short-clock CV and a long-clock invoice, and they must be governed separately.

| Record type | Period | Clock-start |
| --- | --- | --- |
| Sourced CV (unsuccessful) | 6 mo to 2 yr by region | process end / last contact |
| Interview notes | with the CV | same as CV |
| UK right-to-work | employment + 2 yr | employment end |
| US I-9 | 3 yr hire / 1 yr termination | hire or termination |
| Placement invoice | ~7 yr | transaction / tax year |

The seven-year figure is where category errors breed. Recruitment agencies do hold some data that legitimately runs to seven years, such as the invoice, the employment contract behind a fee, and tax records. But those are financial records about a transaction, not personal data about a candidate. The CV, salary history, and references have a much shorter window. "Finance keeps everything seven years" is true for finance's records and false for the candidate's.

Right-to-work records are their own clock entirely. In the UK you keep them for the duration of employment and for two years after employment ends, with a civil penalty of up to GBP 45,000 per illegal worker for a first breach and GBP 60,000 for repeat breaches. The US I-9 runs for three years after the date of hire or one year after termination, whichever is later. Note that the UK scheme extends to contractors and gig-economy workers from 1 October 2026 under the Border Security, Asylum and Immigration Act 2025, so the population of records you govern under this clock is about to grow.

> A deletion rule that fires in the ATS but not the inboxes is a period enforced nowhere.

## The clock-start event, defined per record type

The clock-start event is the single most under-specified field in every retention schedule, and getting it wrong means your dates are wrong even when your durations are right. Two records both set to "six months" expire on different days when one runs from rejection receipt and the other from last contact.

- **France: last contact.** The delay runs from the last contact with the candidate, which is the last email exchanged, the last login to the candidate space, or the last follow-up from you. A single calendar rule keyed to "date added" cannot capture this, because contact is a moving event.
- **Germany: receipt of rejection.** The period starts at receipt of the rejection, and the deletion rule is complete deletion of all documents and interview notes.
- **Netherlands: end of the application procedure.** The four-week default runs from when the procedure closes, not from when the CV arrived.
- **US federal (EEOC): date the record or decision was made.** The one-year minimum runs from record creation or the employment action.
- **Right-to-work: end of employment.** The two-year UK tail runs from the day employment ends, which is unknowable at the point of hire, so the rule must be event-driven.

Because the clock-start event is an event and not a fixed date, your ATS rule has to listen for the event. A rule that computes "date added plus 180 days" is already wrong in France and Germany on the day it ships.

#### From sourced record to defensible purge

1. **Classify** - Tag the record type: CV, interview notes, right-to-work, or financial
2. **Basis** - Assign legitimate interest for sourcing or consent for a pool
3. **Jurisdiction** - Resolve the contact to a single country rule
4. **Clock-start** - Name the triggering event, not a fixed date
5. **Period** - Apply the jurisdiction period plus any documented buffer
6. **Purge and log** - Delete across all stores and write a dated deletion log

*Each stage adds one field the purge decision depends on, in the order a schedule must resolve them.*

Finding the people who own these decisions is its own sourcing problem. If you need the RecOps leads, DPOs, or ATS engineers who build and defend these schedules, you can ask for them in plain English with [Refolk](/) rather than guessing at titles.

I ran this search: `Data protection officers in France and Germany working in recruitment or staffing firms` - [see the full result list](https://www.refolk.ai/s/s7cetkdb0x).

*Returns named DPOs in the two jurisdictions where the clock-start rules differ most, so you can pressure-test your schedule against the people who enforce it locally.*

## Build the retention schedule: the procedure

This is the ordered procedure that turns the tables above into a live schedule. Each step names its owner and the artefact that marks it done. Run it once per source system, then maintain it as records flow in.

#### From classified record to enforced purge

1. **Classify the record** - Tag every sourced record by type across each source system. Done when every record maps to exactly one class.
2. **Assign lawful basis per class** - Active sourcing is legitimate interest; a talent pool is consent. Done when a documented legitimate interest assessment is on file.
3. **Map the contact's jurisdiction** - Resolve each record to one country rule based on where the contact is. Done when every record carries a jurisdiction flag.
4. **Set the clock-start event per class** - France keys to last contact, Germany to rejection receipt, Netherlands to end of procedure, US to record or decision date, right-to-work to end of employment. Done when each row names a trigger.
5. **Set the period and buffer** - Apply the jurisdiction period and record any disagreement, such as Germany's three-month AGG window against the six-month buffer. Done when each class has a period with its authority cited.
6. **Configure auto-deletion in the ATS** - Build a rule that fires at expiry across the ATS, inboxes, and local drives, not the ATS alone. Done when the rule deletes or anonymizes everywhere at the same expiry.
7. **Stand up the DSAR and erasure workflow** - Create a tracked queue that logs the receipt date and runs the one-month clock. Done when requests land in a queue with dated receipts.
8. **Log every deletion** - Record each deletion with its date and keep the logs about three years. Done when dated deletion logs exist as audit evidence.

Steps 6 and 8 are the ones teams skip and the ones auditors check first. A policy document is not evidence of compliance; a dated deletion log is. The deletion logs themselves must be retained to provide evidence in case of a supervisory complaint or audit, and three years is standard practice, aligned with general limitation periods.

## Where this goes wrong: failure modes and false positives

Most retention failures are not missing policies; they are confident but wrong settings that pass a glance and fail an audit. Each failure below pairs the false positive you will see with the check that exposes it.

- **"Six months everywhere."** The false positive is a single confident number applied across all contacts. The check: France allows two years from last contact and the Netherlands defaults to four weeks, so a flat six is wrong in both directions. France allows two years, Germany and the UK recommend six to twelve months, and the Netherlands defaults to four weeks.
- **Clock started on "date added."** The false positive is a tidy, uniform database date. The check: France runs from last contact and Germany from rejection receipt, neither of which equals the date the record was created.
- **Deletion in the ATS only.** The false positive is a green "deleted" status in the applicant-tracking system. The check: inboxes and local drives still hold copies. The German standard is explicit that six months after rejection all documents, interview notes, and test results are deleted from the applicant management system, from the email inboxes of the involved managers, and from local storage locations.
- **Treating consent as a longer legitimate-interest clock.** The false positive is an opt-in box read as a time extension. The check: pool consent is a separate basis that must be refreshed, not an extension of the sourcing basis.
- **The seven-year rule applied to CVs.** The false positive is "finance keeps everything seven years." The check: seven years attaches to invoices, contracts, and tax records, not the candidate record.
- **Erasure request treated as pausable like a SAR.** The false positive is reaching for the Article 12A pause on an erasure request. The check: the pause is Article 15 subject access only. It does not pause an erasure or objection request.
- **Assuming CCPA ignores applicants.** The false positive is "HR is exempt." The check: the HR exemption has expired and CPRA now covers applicant data, with a four-year personnel-record retention from creation or the employment action.
- **No deletion evidence.** The false positive is a well-written policy document. The check: whether dated deletion logs actually exist.

> **Tip:** Audit by sampling the clock, not the policy
>
> Pull ten random records and ask each one: what event starts its clock, and can you prove deletion happened? Policies pass review; records reveal whether the clock-start and the cross-store purge are real.

## Deadlines to action access and erasure requests

Separate from how long you keep data is how fast you must act when someone asks to see or delete it. The core GDPR deadline is one month from receipt, extendable by two further months where necessary, with the data subject informed of the extension within one month of receipt.

The timing has a jurisdiction wrinkle worth flagging in your workflow. Article 12A of the UK GDPR, inserted by the Data (Use and Access) Act 2025 and in force from 5 February 2026, changes when that month starts, but it applies only to Article 15 subject access requests. It does not pause an erasure or objection request, so do not let a SAR-handling habit leak into your erasure queue.

Under CPRA the clock is different again: a business must acknowledge receipt within 10 business days and respond within 45 days. Whatever the jurisdiction, log the receipt date the moment the request lands. The deadline runs from receipt, so an undated request is an uncontrolled clock.

#### Where to spend your retention effort

Horizontal axis runs from Few copies, consolidated to Many copies, scattered. Vertical axis runs from Low exposure to High exposure.

| Quadrant | What it means |
| --- | --- |
| Monitor | Low exposure, consolidated: set the rule and audit annually |
| Consolidate first | Low exposure but scattered: merge stores before the clock matters |
| Document the basis | High exposure, consolidated: nail the legitimate interest assessment and logs |
| Fix now | High exposure and scattered: the audit-failure quadrant, prioritise cross-store purge |

*Plot each record class by regulatory exposure and how scattered its copies are, then act per quadrant.*

## Who owns this, and keeping the schedule current

This reference is only as good as the people maintaining it, and retention is shifting from a guidance question to an audit question. The CNIL made recruitment its 2026 inspection priority, and a regulator that names recruitment a priority will find retention first, because it is the most frequent non-compliance point inspectors find.

In Refolk's index, the population of people who own this work is uneven across regions, which shapes where you can pull in help. There are 391 US recruiting and talent-operations professionals against 32 in the UK, a 12.2x gap, and 377 data-protection-officer profiles in France against 234 in Germany.

| Segment | Count | Derived ratio |
| --- | --- | --- |
| US recruiting/talent ops | 391 | 12.2x UK |
| UK recruiting/talent ops | 32 | baseline |
| France DPO | 377 | 1.6x Germany |
| Germany DPO | 234 | baseline |

The practical point: in thin-coverage regions you may be the only person holding the schedule, so the documentation has to stand on its own. Pull in a named DPO in France or Germany to pressure-test the clock-start rules, since those are the two jurisdictions where the triggering event diverges most from a naive "date added" model.

Keep the schedule current by re-checking the mechanisms, not the numbers. The numbers move when claim windows, scheme scope, or enforcement priorities change, so set a review that re-reads the primary authorities rather than trusting a figure you captured once.

#### Before you call the retention schedule done

- [ ] Every record maps to exactly one class, with a jurisdiction flag and a lawful basis
- [ ] A documented legitimate interest assessment is on file for active sourcing
- [ ] Each class names a clock-start event, not a fixed "date added"
- [ ] Germany's three-month versus six-month disagreement is recorded with the period you chose
- [ ] Auto-deletion fires across the ATS, manager inboxes, and local drives at the same expiry
- [ ] Talent-pool records rest on refreshed consent, not inherited legitimate interest
- [ ] The seven-year clock is applied only to invoices and contracts, never to CVs
- [ ] Access requests run a one-month clock and erasure requests are not treated as pausable
- [ ] Dated deletion logs exist and are retained about three years as audit evidence

The sources to re-read on a schedule are the ICO recruitment and selection guidance, the CNIL recruitment retention référentiel, the Autoriteit Persoonsgegevens applicant-data page, EEOC 29 CFR 1602.14, the Home Office Employer's Guide to Right to Work Checks, and the California Privacy Protection Agency. When one of those changes, update the clock-start column first and the duration second, because the event is what your ATS rule actually listens for.

## Frequently asked questions

### How long can I keep a CV from an unsuccessful candidate under GDPR?

GDPR sets no fixed number. Article 5(1)(e) says data may be kept no longer than the purpose requires, and the purpose for a rejected candidate ends when the role is filled. The practical ceiling is the claim window: roughly 6 months in the UK and Germany, up to 2 years from last contact in France, and as little as 4 weeks in the Netherlands. Keeping it longer for a talent pool needs consent as a separate basis.

### When does the retention clock actually start?

It depends on jurisdiction, and this is where most schedules break. France runs from the last contact with the candidate, such as the last email or last login. Germany runs from receipt of the rejection. The Netherlands runs from the end of the application procedure, and the EEOC runs from the date the record or decision was made. Right-to-work records run from the end of employment, not the date added.

### Does CCPA or CPRA cover candidate data?

Yes. The HR exemption has expired, so applicant data now falls under CPRA. There is no fixed federal-style retention number, but California employers must retain personnel records for applicants and employees for 4 years from the date the records were created or the employment action was taken. Businesses must also state retention periods, or the criteria for setting them, at or before collection.

### Can I keep a rejected candidate on legitimate interest and move them into a talent pool later?

No, not on the same basis. Legitimate interest for defending discrimination claims supports roughly 6 to 12 months and no new purpose. Moving a rejected candidate into a talent pool is a new purpose and needs its own basis, usually consent. Document a legitimate interest assessment for active sourcing and refresh consent for the pool rather than treating consent as a longer version of the same clock.

### How fast must I respond to an erasure or access request?

Within one month of receipt, extendable by two further months where necessary, with the data subject informed of the extension inside the first month. Under CPRA you must acknowledge within 10 business days and respond within 45 days. The UK's Article 12A pause, in force from 5 February 2026, changes when the month starts but only for Article 15 subject access requests; it does not pause an erasure or objection request.

### Why does the 7-year rule not apply to CVs?

Because the 7-year clock belongs to the transaction, not the person. An invoice, the employment contract behind a fee, and tax records are financial records about a transaction and legitimately run to about 7 years. The CV, salary history, and references are personal data about a candidate and carry a much shorter window. Applying 7 years to a candidate record is a category error that creates liability, not protection.

---

*From the Refolk guide library. I revise these guides rather than replacing them, so the current version is always at https://www.refolk.ai/guides/sourced-record-retention-clock-reference*
