
Full Focus in Every Interview with AI Summaries
Stop struggling with manual notes and start building real connections by using AI-driven summaries that capture every detail.
Remo Vloet7 min.

How does Simply protect your candidate data? With enterprise-grade security, ISO-27001 certification, and full GDPR compliance. Here's how it works.
Recruiters work with sensitive data every day. CVs, conversation transcripts, salary expectations, personal preferences, sometimes even medical information. One data breach and you’re in the news. One GDPR violation and you risk fines up to 4% of your annual turnover.
Yet many recruitment teams treat privacy as a checkbox. They have a privacy statement on the website, ask for consent, and think that’s enough. It’s not.
In this article, you’ll learn what the GDPR actually requires when you use AI and automation in your recruitment process. No legal jargon, but practical guidelines you can apply immediately.
The General Data Protection Regulation (GDPR) sets requirements for how you collect, process, and store personal data. For recruitment, there are a few core principles:
You may only collect personal data for a specific, defined purpose. In recruitment: assessing a candidate’s suitability for a specific role. You may not use that data for other purposes, such as marketing or profiling.
Collect only what you need. A resume and cover letter: fine. The social media profile of the candidate’s partner: no. This principle is often violated out of curiosity, not malice.
You may not store candidate data indefinitely. After the procedure ends, you must delete the data, unless the candidate gives consent for inclusion in a talent pool. The standard retention period is four weeks after rejection, extendable to one year with consent.
Candidates have the right to know what data you have about them, and to request deletion. You must respond within one month.
When you deploy AI in recruitment, additional obligations apply. The GDPR is clear about this:
Automated decision-making: Article 22 of the GDPR gives individuals the right not to be subject to decisions based solely on automated processing. In practice: you may not let AI be the sole decision-maker on whether a candidate advances to the next round.
Transparency: You must inform candidates that you use AI in the selection process. What does the AI do? On what basis does it make assessments? How are those assessments used?
Data Protection Impact Assessment (DPIA): When you deploy AI for assessing candidates, you’re obligated to conduct a DPIA. This is a risk analysis that describes what data you process, why, and what protective measures you take.
Transparency at Simply is not an abstract concept. Every AI-generated observation refers back to the exact moment in the conversation. Candidates (and regulators) can always verify how an assessment was formed.
In addition to the GDPR, you’ll be dealing with the EU AI Act in 2025. This law classifies AI systems for recruitment and selection as ‘high risk.’ That means:
If you’re already using AI tools, start mapping your compliance now. Don’t wait until enforcement begins.
Here’s a checklist you can use immediately:
With AI summaries, conversations are automatically summarized. The summary contains only relevant information, no personal details that aren’t relevant to the assessment.
Every tool that processes candidate data (your ATS, your recording tool, your AI assistant) is a processor. You must have a processing agreement. No exception.
‘We keep it in case the candidate applies again later.’ That’s not a valid legal basis. Without explicit consent, you must delete the data after the retention period.
Many teams use AI tools without mentioning this to candidates. That’s a violation of the transparency obligation. Include it in your privacy statement and mention it in the interview invitation.
If you use AI for assessing candidates, you must conduct a DPIA. Many organizations skip this because it’s ‘too complicated.’ But it’s mandatory, and the consequences of not doing it are bigger than the effort of doing it.
GDPR compliance isn’t just about policy. It’s also about technical security. Candidate data must be protected against unauthorized access, data breaches, and loss.
Enterprise-grade security at Simply includes:
These aren’t nice-to-haves. These are the minimum requirements for any tool that processes candidate data.
If your organization has a DPO, involve them in your recruitment technology choices. Not after the fact, but upfront. The DPO can help you with:
Don’t have a DPO? Then this is a good time to consider whether you need one. For large-scale processing of special categories of personal data (which is what recruitment involves), a DPO is often mandatory.
Recruiting candidates outside the EU? Then you’ll face additional rules around data transfers to third countries.
Tools that process your candidate data must be transparent about where data is stored. Fewer systems also means fewer copies: when the recording, the parsed CV and the record itself live in one place, candidate data isn’t duplicated across a chain of tools.
Privacy isn’t just compliance. It’s also trust. Candidates who trust that you handle their data carefully are more honest in conversations, more engaged in the process, and more positive about your brand.
How do you build that trust?
Many agencies want to use AI but hesitate over privacy implications. The most important step is informing the candidate. Explain upfront that the conversation will be recorded, what the recording will be used for, and how long it will be stored. This can be done with a standard statement at the beginning of each conversation.
On top of that, it’s important to have a data processing agreement with your AI provider. This document specifies where data is stored, who has access, and what happens when the contract ends. Simply offers this as standard. The platform and your candidate data sit in the Netherlands, on infrastructure we run, stored encrypted and automatically deleted after the agreed retention period; AI processing runs in European regions or on your own key, with the models themselves coming from OpenAI and Anthropic. ISO-27001 certification guarantees that these processes are not just documented but are actually verified by an independent auditor.
About the author

Remo Vloet is a co-founder of Simply, the AI Operating System for recruitment agencies: inbox, meetings, sourcing, CV parsing, search and matching, documents and automation in one system. With a background in building complex software, he contributes to the technical vision behind Simply.
LinkedInArticles by Remo VloetYes, provided you have explicit prior consent from the candidate. Document how the recording will be used, who has access, and when it will be deleted. The candidate must have the option to refuse without negative consequences.
The standard is four weeks after the procedure ends. With explicit consent from the candidate, you can extend this to a maximum of one year (for a talent pool). After that period, you must delete the data.
Yes. The GDPR requires transparency about automated processing. Include it in your privacy statement and in your communication with the candidate. Explain what the AI does and how the output is used.
The candidate has the right not to be subject to fully automated decision-making. Offer an alternative. In practice, this means: always ensure human oversight of AI assessments.

Stop struggling with manual notes and start building real connections by using AI-driven summaries that capture every detail.
Remo Vloet7 min.

Summarizing interviews is useful, but real efficiency comes from data. Simply converts conversations into structured ATS fields automatically.
Remo Vloet7 min.

Don't just trust AI; verify it. Simply connects every summary sentence to the original audio, giving recruiters 100% control and transparency.
Remo Vloet7 min.

Find out how Simply can completely evolve your workflow.No slides, just product.