Candidate Database (Bewerberdatenbank)

A candidate database (Bewerberdatenbank) is a system where you store applications and candidate information during hiring. Swiss employers must comply with revDSG (revised Data Protection Act): you can only keep data you genuinely need, delete unsuccessful applicants' files within 30 days of rejection unless they've consented to longer storage, and ensure candidates can access and correct their information. Your most common mistake is keeping files 'just in case' without legal grounds—this violates data minimisation rules.

Also available inDeutschFrançaisItaliano

When you receive CVs and applications, you need somewhere to organise them. A Bewerberdatenbank holds candidate names, contact details, qualifications, interview notes, and assessment results during your recruitment process.

You'll use this database whenever you're hiring, whether you have one opening or several. It becomes crucial when you're comparing candidates across multiple positions or running a rolling recruitment cycle.

Your Legal Obligations Under revDSG

Switzerland's revised Data Protection Act (revDSG, in force since 1 September 2023) treats candidate information as personal data. You must store only what's needed for hiring, process it fairly, and protect it from unauthorised access. Candidates have the right to see what you hold about them.

If a candidate is rejected, Swiss employment law convention expects you to delete their file within 30 days unless they've explicitly agreed to longer storage (for example, 'keep my CV for future roles'). If you wish to keep data longer, you must have documented consent and a legitimate business reason. A lawyer should confirm your retention policy aligns with revDSG.

  • Store only data directly relevant to the position: CV, cover letter, test results, interview notes
  • Delete unsuccessful candidates' files within 30 days unless they've consented in writing to longer retention
  • Grant candidates access to their stored information upon request (provide a copy within 30 days)
  • Secure your database with password protection and limit access to hiring staff only
  • Document your data retention policy and keep a record of who accessed candidate files
  • If candidates withdraw or decline an offer, mark their file closed and follow deletion timelines

When and How to Use It

You need a Bewerberdatenbank as soon as you post a job vacancy and begin receiving applications. It scales from a simple spreadsheet (acceptable for small SMEs with occasional hires) to dedicated recruiting software that automates compliance tracking.

Use it to compare shortlisted candidates fairly, store interview feedback consistently, and track offer status. If you hire repeatedly—say, seasonal staff or multiple roles per year—investing in dedicated software like zenRecruiting.ai saves time and reduces the risk of accidentally keeping data too long.

  • Centralise all applications in one system to ensure consistent, fair evaluation
  • Record interview dates, feedback, and decision reasons for each candidate
  • Use the database to spot hiring patterns (time-to-hire, source quality) without storing unnecessary detail
  • Enable quick reference if a candidate reapplies months later
  • Automate deletion reminders for rejected candidates after 30 days
  • Use filters to manage candidates by role, status (shortlisted, rejected, offered), and date applied

The Most Common Mistake

Employers often keep candidate files indefinitely 'in case we hire for a similar role later.' This violates the data minimisation principle in revDSG. Unless a candidate has explicitly agreed in writing, you must delete their file within 30 days of rejection.

A secondary mistake: storing sensitive data you don't need, such as nationality details, health information, or family status. Collect only what's necessary to assess fit for the role. If you're uncertain whether something belongs in your database, you probably don't need it.

  • Don't assume all candidates consent to long-term storage—this must be explicit and documented
  • Don't keep copies of payslips, references, or background checks longer than needed to confirm hiring
  • Don't store candidates' notes about appearance, age, or family plans in the database
  • Don't leave databases unattended on shared computers or unlocked devices
  • Don't mix candidate data with employee data (they have different retention rules)
  • Do set a calendar reminder to review and delete files 30 days after rejection

Frequently asked questions

Can I keep a rejected candidate's CV for future roles without asking permission?
No. Swiss data protection law (revDSG) requires deletion within 30 days of rejection unless the candidate has given explicit, written consent to longer storage. 'We might hire them later' is not a legal basis. If you want to keep files, add a tick-box to your application form asking permission.
What's the difference between a spreadsheet and recruiting software for candidate storage?
A spreadsheet works for occasional hires but offers no audit trail, automated deletion reminders, or access control. Recruiting software like zenRecruiting.ai logs who viewed which candidate, automates compliance reminders, and secures data with encryption. For SMEs hiring more than twice a year, software reduces legal and administrative risk.
Can I ask candidates for nationality, age, or family status in my application form?
No. Swiss employment law (ArG) and revDSG prohibit discrimination based on these factors. Collect only information needed to assess job fit. Asking about family plans, age, or nationality opens you to discrimination claims and violates data minimisation rules. Stick to qualifications, experience, and role-specific requirements.

General information for Swiss employers, not legal advice. Have a lawyer confirm anything with legal consequences.

Related