Data Protection in Recruiting (revDSG)
Data protection in recruiting means you must collect, store and process job applicant information—names, CVs, phone numbers, test results—only for the hiring purpose, keep it secure, and delete it within defined periods. The revised Federal Data Protection Act (revDSG, effective 1 September 2023) sets these rules. Breaches can trigger complaints to cantonal data protection officers and fines up to CHF 100,000.
When you advertise a position or receive applications, you become responsible for personal data. This includes CV text, email addresses, references, test scores, and interview notes. The revDSG defines how you must handle it.
Swiss employers often assume applying for a job means candidates accept unlimited data use. That is incorrect. You need a lawful basis—usually the employment contract or legitimate interest—and must be transparent about what you do with their information.
When data protection obligations arise in recruiting
Your obligations start when you receive the first application. This includes email submissions, LinkedIn messages, referrals, and internal candidates. You hold their personal data and must comply with revDSG from that moment.
The obligation continues through interviews, reference checks, background verification, and the final hiring decision. If you reject a candidate, you still hold their data and must manage it according to law until you delete it.
- Job postings: be clear about data collection and use
- Application storage: keep files secure and separate from other systems
- Interview notes: document only job-relevant information
- Reference checks: inform the candidate before contacting references
- Rejected applicants: set a deletion deadline (typically 30 days to 1 year)
- Successful hire: transfer data into the employment file with fresh consent if needed
Your main obligations under revDSG
You must be transparent: tell candidates when you collect data, what you do with it, and how long you keep it. A privacy notice in the job posting or application form is standard practice. You must also have a lawful basis—usually the employment contract or your legitimate interest in hiring.
Security is mandatory. This does not mean enterprise software; a password-protected folder, encrypted email, or recruiting tool with basic access controls is often sufficient for a small firm. You must also appoint a data protection contact if you process data systematically.
- Provide a privacy notice before or at the point of application
- Limit data to what you actually need for the hiring decision
- Do not share candidate information with third parties without consent
- Keep application files locked and accessible only to hiring staff
- Delete rejected applicant data after a reasonable period (check your canton's practice)
- Document your retention and deletion practices in writing
The most common mistake
Most Swiss employers collect CVs without a clear retention policy and never delete them. Candidates' personal data sits in email folders or shared drives indefinitely. This violates the storage limitation principle in revDSG: you must not keep data longer than necessary.
A second frequent error is sharing candidate details with team members, contractors, or talent pools without informing the applicant. Even internal sharing requires a basis and transparency. Set a rule: only hiring-team members see applications, and only for this role.
- Set a deletion deadline before the hiring process starts (e.g., 90 days post-rejection)
- Keep CVs out of shared email accounts or generic folders
- Do not forward candidate details to consultants or external recruiters without consent
- Do not reuse application data from old hiring cycles without new consent
- Inform candidates if you keep their data for future opportunities
- If a candidate requests deletion, comply within 30 days (right of erasure)
Frequently asked questions
- Can I store a rejected candidate's CV 'just in case' for future roles?
- Only if you told them in advance that you do so. Your privacy notice at application must clearly state this. Even then, you should ask for re-consent after 12 months. If you do not have explicit consent, delete the file within 90 days of rejection.
- Do I need a data protection officer (DPO) for my SME?
- No, not automatically. You need one only if your processing is systematic, large-scale, or involves sensitive data (such as criminal records). Most SMEs do not. But you should designate someone internally (the office manager or hiring lead) as responsible for data protection in recruiting.
- What happens if I breach revDSG?
- A candidate can lodge a complaint with their cantonal data protection authority (the office varies by canton). Serious breaches can result in fines up to CHF 100,000. More often, the authority issues a warning or order to delete data. Consult a lawyer if you receive a complaint.
General information for Swiss employers, not legal advice. Have a lawyer confirm anything with legal consequences.