§ GDPR BRIEFING

GDPR Obligations for Recruitment and HR

5 obligations from GDPR mapped to recruitment and HR. Articles, deadlines, and penalties — extracted verbatim from the Regulation.

Summary

GDPR sets 5 obligations that apply to recruitment and HR. This page lists them with article references, obligated-entity language, and penalties — extracted verbatim from the Regulation, not paraphrased.

Use the obligation table and breakdown to scope a compliance programme. The cross-regulatory conflicts section surfaces places where this regulation pulls against neighbouring EU frameworks for the same sector.

Who this applies to
Companies operating in recruitment and HR that fall within GDPR's scope.
Compliance deadline
25 May 2018 — earliest dated obligation on this page. __COUNTDOWN_DAYS__ days remaining.
§ Detail

In depth

Obligations in scope

Article 9 — controller

Ensure that processing for employment and social security purposes is authorized by Union or Member State law or a collective agreement and provides for appropriate safeguards for the fundamental rights and interests of the data subject. Action required: authorize.

Article 88 — Member States

Member States may provide for more specific rules by law or collective agreements to ensure the protection of rights and freedoms regarding the processing of employees' personal data in the employment context. Action required: provide.

Article 88 — Member States

The specific rules adopted by Member States shall include suitable and specific measures to safeguard the data subject's human dignity, legitimate interests, and fundamental rights, with particular regard to transparency, data transfers within groups, and monitoring systems. Action required: include.

Article 88 — Member States

Each Member State shall notify the Commission of the provisions of its law adopted pursuant to paragraph 1 by 25 May 2018. Action required: notify. Deadline: 25 May 2018.

Article 88 — Member States

Each Member State shall notify the Commission without delay of any subsequent amendment affecting the provisions of its law adopted pursuant to paragraph 1. Action required: notify. Deadline: without delay.

Practical steps

What the obligations on this page actually require you to do, ordered by article. Use this as a starting checklist; verify each item against the underlying article text before treating it as legal advice.

Obligation reference table

ArticleObligated entityDeadlinePenalty
Art 9controller
Art 88Member States
Art 88Member States
Art 88Member States25 May 2018
Art 88Member Stateswithout delay

Penalty exposure

None of the 5 obligations on this page carry an explicit penalty figure in the GDPR text itself — the fine ceiling is set elsewhere in the regulation and applies by reference. Refer to GDPR's general penalties article (or the diagnostic below) to estimate exposure before signing off on a compliance programme.

Cross-regulatory conflicts

GDPR interacts with other EU regulations in ways that can pull compliance teams in opposite directions. The most concrete conflicts in the Fontvera corpus involving this regulation:

Related Fontvera pages

Check your full compliance exposure with the 5-minute Fontvera diagnostic →

§ What Fontvera found

Documents in our corpus

imy SE Fetched 2026-05
§ Cross-references

Related Fontvera intelligence

Need a cross-border briefing on this?
Search Fontvera ↵ Run the AI Act diagnostic
AI Act enforcement
63 days
until 2026-08-02, when most AI Act provisions begin to apply.