Permissions: Site Admin

Product tier: Available to all subscription tiers

Greenhouse Recruiting allows for configuring one of two legal bases to retain candidate data in your account. You can edit your preferred legal basis at any time. We recommend consulting with your internal legal team to determine the best configuration for your organization.

Note: By default, Greenhouse Recruiting supports legitimate interest as your organization's legal basis.

Edit legal basis

To edit the legal basis for your organization's GDPR configuration, click Configure configure.png on your navigation bar, then select Privacy & Compliance on the left.

Configure___Privacy_and_Compliance.png

Click Configure inline with the General Data Protection Regulation (GDPR) panel. 

Configure_GDPR.png

Navigate to the Legal Basis panel and click Configure.

Configure_legal_basis.png

Click the button to the left of either Legitimate Interest or Explicit Consent and click Save when finished.

Save_legal_basis.png

A dialog box will ask you to confirm the change. Click Change Legal Basis

Change_legal_basis.png

Note: In compliance with GDPR, you may need to provide an email address when you manually add a candidate. This applies if:

Impact of Explicit Consent on GDPR configuration

When Explicit Consent is used as the legal basis for your organization's GDPR configuration, a question that requests consent will be automatically appended to existing and new job posts for offices with a data retention rule.

Note: This automatically appended question is non-editable. Greenhouse Recruiting will use the {{COMPANY}} token and the {{CANDIDATE_RETENTION_TIMER}} token for the office associated with job.

GDPR_notice_on_job_post.png

Additionally, an email requesting permission to collect, store, and process candidate data will be automatically sent to anyone under a data retention rule that does not enter through a consent portal.

Screen_Shot_2020-04-22_at_12.19.46_PM.png

You can also manually request consent from any pre-existing candidate and/or prospect who has yet to provide consent to have their data collected, stored, and processed. Click the links below to learn more:

Impact of Legitimate Interest on GDPR configuration 

When legitimate interest is used as the legal basis for your organization's GDPR configuration, you will lose Greenhouse Recruiting's built-in consent request functionality.

Since collecting consent is not the legal basis of your GDPR configuration, your organization can customize organizational rules and email templates to automatically email a GDPR notification to candidates and/or prospects who entered into your system without having applied to a job post.

Screen_Shot_2020-04-22_at_1.47.17_PM.png