utilizar cv candidatos linkedin

Searching LinkedIn before hiring is a widespread practice and, within limits, perfectly lawful. The problem starts when “the profile is public” gets confused with “I can do what I like with it”. Using candidate CVs from LinkedIn has rules, and the Spanish Data Protection Agency has been setting them out in its guidance on data protection in employment relations, updated in December 2025.

The legal basis is not consent

Let us start by dismantling the most common error. Processing the data of a candidate who applies to a vacancy does not rest on consent, but on Article 6(1)(b) GDPR: pre-contractual measures taken at the data subject’s request. The reason is structural: given the imbalance between employer and worker, consent given in that context can rarely be considered freely given.

For data that is not strictly necessary to assess the application — an employment history report, for instance — the employer could rely on legitimate interest, but would have to carry out the balancing exercise and record it in writing.

The profile you find, not the one you are sent

Here lies the distinction that decides almost every case.

If the candidate sends you a CV or applies to your vacancy, there is a request from the data subject and the Article 6(1)(b) basis works. If it is you who locates a profile on a professional network and processes that data without the person having approached the company, that basis no longer exists.

The Spanish Agency’s position is clear: even where the profile is publicly accessible, the employer may not process that data without a valid legal basis. The search is justified only where the data relates to professional purposes, and the processing is possible only where it is shown to be necessary and relevant to the specific role. The Agency adds one further point: the company is not entitled to send a connection request or otherwise seek access to a candidate’s profile.

And you have to inform them

Where the data is not obtained from the data subject — a profile found online, a CV forwarded by a third party, an employee referral — Article 14 GDPR applies. The employer must provide information within a reasonable period and at the latest within one month, or at the time of the first communication with that person if that comes sooner.

The exceptions in Article 14(5) are narrow: the data subject already has the information, providing it proves impossible or would involve disproportionate effort in the listed cases, obtaining the data is expressly laid down by law, or professional secrecy applies. “It is awkward” is not among them.

Where there is a public vacancy notice, the Article 13 information must be included in the advertisement itself. And where a CV arrives unsolicited, the Agency recommends a procedure that leaves a trace: replying to the email address provided with the processing information.

What you may not look at

A professional profile frequently reveals far more than work experience: membership of associations, trade union affiliation, beliefs, health, sexual orientation. These are the special categories of Article 9 GDPR, and Article 9(1) of the Spanish Act is categorical: the data subject’s consent alone is not sufficient to lift the prohibition where the main purpose of the processing is to identify their ideology, trade union membership, religion, sexual orientation, beliefs or racial or ethnic origin.

Visibility does not make data processable. And using it in a hiring decision is not merely a data protection infringement: it is an employment law problem of a different order.

How long a CV may be kept

Once the process ends without a hire, the legal basis that supported the processing disappears. From there, two routes exist: delete the CV — with the blocking obligation set out in Article 32 of the Spanish Act — or add it to a talent pool, which does require consent, because there is no longer any pre-contractual measure to support anything.

The Agency does not set a fixed number of months. What it requires is that the period be defined, documented and observed. A folder of CVs from 2019 is not a talent pool: it is an infringement waiting for someone to exercise their right to erasure.

Automated screening: what arrives in 2027

More and more processes rely on tools that score or reject applications. The EU AI Act expressly lists in Annex III, point 4, systems intended for recruitment and selection: publishing advertisements, filtering applications and evaluating candidates. These are high-risk systems.

Following the reform introduced by the digital omnibus of July 2026, Annex III obligations become enforceable on 2 December 2027. The company using the tool is not its manufacturer, but it is its deployer, and that carries its own duties: use it in accordance with the provider’s instructions, ensure human oversight by people with real competence and authority, monitor its operation, keep logs for at least six months and — importantly — inform workers’ representatives and affected workers before putting it into service.

To that must be added, already today, the Article 35 GDPR impact assessment wherever automated screening presents a high risk.

What has already been penalised

The most instructive file is not the most expensive one. The Spanish Agency imposed a 2,000 euro fine for an infringement of Article 13: a company received a CV by WhatsApp, on a number published on a job portal, and never informed the candidate about the processing of their data. Two thousand euros for not sending a paragraph.

The short list

  1. A documented legal basis: pre-contractual measures, not consent.
  2. Article 13 information in the advertisement, and an informative reply to unsolicited applications.
  3. Article 14 information, within one month, where the data does not come from the candidate.
  4. No special categories in the assessment, however visible they are.
  5. A defined retention period and express consent for the talent pool.
  6. An inventory of AI tools used in recruitment, with a roadmap to December 2027.

All six fit on a one-page procedure, and that page is what gets requested when a complaint arrives. We review it and put it in writing as part of our advice on data protection.

0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply

Your email address will not be published. Required fields are marked *