
You rejected the candidate. Why do you still have their CV?
The vacancy closed three months ago: One candidate was hired, the unsuccessful applicants were informed and the recruitment file was considered complete. Yet their information may still be everywhere. A CV sits in the hiring manager’s inbox, copies of identification documents remain in a shared recruitment folder, interview notes are stored on somebody’s laptop and even the reference contacts remain inside an old shortlist. An external recruiter may still have copies of documents that were exchanged during the search. Nobody is actively using them, nor has anyone decided what should happen to them. That is where an ordinary recruitment process becomes a data protection issue.
A CV does not stop being personal data because the candidate was rejected
Kenya’s Data Protection Act defines personal data broadly as information relating to an identified or identifiable person. A candidate’s name, telephone number, employment history, education, address and identification details, therefore, fall within a legal framework that continues to apply after the recruitment decision has been made. This matters because many organizations still treat unsuccessful applications as abandoned recruitment paperwork.
They are not.
The organisation collected that information for a reason. Once the reason changes or expires, HR should be able to explain why the information is still being retained. Section 25 of the Data Protection Act requires personal data to be collected for an explicit, specified and legitimate purpose. It must be adequate and limited to what is necessary and it should not remain in identifiable form longer than necessary for the purpose for which it was collected. The practical question for HR is therefore straightforward.
Why do we still have this candidate’s information?
If nobody can answer that question clearly, the recruitment file deserves attention.
There is no single statutory retention period for every unsuccessful CV
This point is important because data protection discussions often become unnecessarily absolute.
Kenyan law does not prescribe one universal number of months or years for every employer to retain every unsuccessful candidate file.
Instead, section 39 requires personal data to be retained only for as long as reasonably necessary for the purpose for which it is processed, subject to recognised exceptions such as legal requirements, a lawful purpose, consent or specified research and historical purposes. When retention is no longer necessary, the Act provides for deletion, erasure, anonymisation or pseudonymisation.
The Data Protection (General) Regulations make the management requirement even clearer. Organisations should establish a personal data retention schedule that records why information is retained, how long it will be retained, how retained information will be periodically reviewed and what action will follow when the retention period expires.
In other words, “we normally keep CVs” is not enough. A defensible retention period needs a defensible reason.
There may be good reasons to keep some recruitment records.
The answer is not to delete every unsuccessful application immediately. An employer may have legitimate reasons for retaining particular recruitment records. Records may be relevant to a legal claim. A regulatory or statutory requirement may apply. An organisation may need evidence of how a recruitment decision was conducted. A candidate may have agreed to appropriate processing for future opportunities. The important distinction is between purposeful retention and accidental accumulation.
A properly governed organisation knows why information is being kept and when that reason will be reviewed.
An organisation with weak controls simply keeps everything. Those two practices should not be confused.
Section 40 of the Act is also relevant because the right to erasure is not absolute. Where information is required as evidence, the law can require processing to be restricted rather than the information simply being erased.
That is why the solution is a retention framework, not a blanket deletion rule.
The real weakness is often not the policy but the copies.
Most organisations can produce a privacy policy. The harder question is whether the actual recruitment process behaves like the policy.
How many people receive a candidate’s CV?
Does the hiring manager download it?
Does somebody forward it from the recruitment system into a personal mailbox?
Are interview packs printed?
Does an external recruiter retain copies after the assignment closes?
Does somebody keep an unsuccessful candidate’s CV because “they might be useful later”?
Every additional copy makes access control, correction and eventual disposal more difficult. Data protection therefore cannot sit with IT alone.
Recruitment determines what information is requested.
HR determines how that information moves through the selection process.
Hiring managers receive candidate records.
Recruitment agencies and technology providers may process information on the employer’s behalf. Candidate data protection is therefore part of recruitment design.
Candidates should know what happens to their information.
The Data Protection Act gives data subjects important rights, including the right to be informed about how their personal data will be used, the right to access personal data held by a controller or processor, the right to object to processing in appropriate circumstances and rights relating to correction and deletion.
Section 29 also requires organisations, as far as practicable before collection, to inform people that their data is being collected, explain the purpose and identify matters such as potential recipients and the controller’s contact information. For recruitment, that means the privacy notice should not be an obscure document sitting at the bottom of a careers page. It should answer useful questions:
Why are we collecting this information?
Who will have access to it?
Will it be shared with another organisation?
Will unsuccessful applicants be considered for future vacancies?
How long will recruitment records normally be retained under our policy?
What happens when that period expires?
That is what meaningful transparency looks like.
Before the next vacancy opens, audit the previous one.
There is a useful exercise every HR team can conduct before launching another recruitment campaign.
Take the last vacancy you filled.
Find the records of the unsuccessful applicants.
Establish where those records are currently stored.
Identify who can still access them.
Check whether copies exist outside the approved recruitment system.
Confirm why the organisation is retaining them and when that purpose will be reviewed.
Then compare reality with the organisation’s retention schedule.
If no retention schedule exists, that is the first control to build. The Data Protection Regulations specifically require retention schedules to address the purpose, retention period, periodic review and action to be taken once the information no longer needs to be held. This is not administrative housekeeping; it's evidence that the organisation understands the responsibility created when people entrust it with personal information.
Rejection should close the recruitment decision, not the organisation’s responsibility
A candidate may never become an employee.
They may never enter your offices again.
That does not make the information they submitted irrelevant to your obligations.
Recruitment trust includes what happens after the interview. It includes who sees candidate information, why the organisation keeps it and whether records disappear when the reason for keeping them disappears.
That discipline protects candidates and the employer.
At Eagle HR Consultants, we support organisations in strengthening recruitment governance, HR compliance, privacy-conscious HR processes and the controls surrounding candidate and employee information.
If your recruitment records have no clear owner, no documented retention period and no reliable disposal process, the next step is not another privacy statement. It is to fix the process behind it.




