
That single hire can trigger GDPR obligations, even though the company has zero offices in Europe.
Many US talent acquisition teams still treat GDPR as "someone else's problem." That assumption is expensive. Fines can reach 4% of global revenue, and in a specialized, reputation-driven field like MedTech, a data mishandling story travels fast through a small talent pool.
This article breaks down what GDPR actually requires, how it reshapes sourcing, screening, and retention practices, and the concrete steps TA leaders can take to build a compliant, diversity-forward hiring strategy.
Key Takeaways
- GDPR applies the moment you process an EU candidate's personal data, no matter where you're based
- Core obligations include lawful processing, data minimization, retention limits, and honoring candidate access/erasure rights
- AI-driven screening and cross-border data transfers carry additional compliance requirements
- Non-compliance risks fines up to 4% of global turnover, plus lasting reputational damage in MedTech
What Is GDPR and Why Should US Talent Acquisition Teams Care?
The General Data Protection Regulation is the EU's 2018 data protection law governing how personal data belonging to EU residents gets collected, processed, and stored. Its reach extends well past European borders.
Here's the part that catches US recruiters off guard: GDPR follows the data subject, not the company's location. A US firm with no EU entity, no EU staff, and no plans to open a European office can still fall under GDPR's scope simply by processing an EU resident's application.
Does GDPR Apply to Your US-Based Hiring Process?
According to the European Data Protection Board's guidelines on territorial scope, Article 3(2) applies when a non-EU company targets individuals in the Union by offering goods or services, or by monitoring their behavior.
The guidance clarifies that simply employing someone based in the EU isn't automatically enough to trigger the law; the processing has to be tied to that person's activities in a targeted way.
For MedTech recruiters, the practical triggers usually look like this:
- Actively sourcing EU citizens or residents for regulatory, clinical, or R&D roles
- Running a careers page that EU applicants can access and submit resumes through
- Using recruitment agencies or global ATS platforms that pull EU candidate data
- Acquiring or partnering with a European MedTech company

A common scenario: a US device manufacturer sources an EU-based clinical affairs specialist to help navigate EU MDR requirements. The moment that candidate's CV lands in your system, GDPR obligations attach.
Indirect exposure counts too. If your background-check vendor or ATS provider processes EU candidate data on your behalf, that pulls your company into scope even if your internal team never touches the raw data.
Core GDPR Principles & Their Impact on Recruitment Activities
GDPR operates as a set of interlocking principles that touch nearly every stage of recruitment, from the job posting to the offer letter.
Lawful, transparent processing means every data point you collect needs a stated purpose. Your job postings, application forms, and privacy notices should tell candidates exactly what you're collecting and why, stated in plain language rather than buried in legal jargon.
Data minimization and purpose limitation require you to collect only what's essential to the hiring decision. This is where many US application forms overreach. Fields like:
- Marital status
- Date of birth
- Photographs
- Nationality or citizenship details beyond work authorization
...rarely serve a legitimate hiring purpose and create unnecessary risk. Sensitive categories such as health status, ethnicity, or religious affiliation are especially restricted and almost never justifiable to collect during recruitment.
Storage Limits and Candidate Rights
GDPR doesn't hand you a fixed retention number, but it demands justification for however long you keep data. France's data protection authority, the CNIL, has published a recruitment retention guide recommending a maximum of two years from last contact for candidates held in a general talent pool, with shorter windows for unsuccessful applicants tied to an active req.
Candidates also hold five specific rights under GDPR:
- Access: Request a copy of their data
- Correction: Fix inaccurate information
- Erasure: Request deletion
- Restriction: Limit how their data gets used
- Portability: Receive their data in a transferable format

Ignoring these requests creates more than a compliance gap; it can sour a relationship with a candidate who might reapply or share their experience with peers later.
AI Screening, Cross-Border Transfers & Vendor Data
Article 22 of GDPR restricts automated decision-making. If a candidate gets filtered out solely by an algorithm, with no human involved, they have the right to request human review and to contest the outcome. This matters directly for MedTech firms using AI tools to match niche talent against hard-to-fill regulatory or engineering roles: full automation without a human checkpoint isn't compliant.
Cross-border data transfers add another layer. The US isn't automatically considered "adequate" under GDPR, so moving an EU candidate's data into a US-based ATS or HRIS requires a legal safeguard. Since 2023, companies can rely on the EU-US Data Privacy Framework if certified, or fall back on Standard Contractual Clauses for transfers outside that framework.
Third-party vendors round out the risk picture:
- ATS and assessment platforms need signed Data Processing Agreements (DPAs)
- Background-check providers require explicit, separate consent from candidates
- "Separate" matters here: bundling consent for background checks into a general application waiver doesn't meet the transparency bar
Building a GDPR-Compliant Talent Acquisition Strategy: Practical Steps
Compliance sounds abstract until you break it into a checklist. Here's where to start.
- Audit every data touchpoint. Map application forms, ATS records, spreadsheets, interview notes, and offline files. Most companies find data hiding in places nobody expected, like a recruiter's personal notes folder.
- Rewrite privacy notices and consent flows. Use plain language, opt-in checkboxes, and separate consent for distinct purposes: one checkbox for the current role, a different one for future talent pool consideration.
- Strip non-essential fields from application forms. If a data point doesn't influence the hiring decision, remove it. Marital status and date of birth are the usual culprits.
- Set retention and deletion policies in writing. Define timeframes by candidate category and automate deletion once the clock runs out, since manual deletion tends to get skipped when hiring gets busy.
- Train recruiters and vet vendors. Build GDPR literacy into TA onboarding and require DPAs from every recruitment technology and background-check partner before signing a contract.

For lean MedTech HR teams juggling multiple open reqs, this list can feel like a second job.
Partnering with a recruiter that already builds these safeguards into its process, rather than retrofitting them, can shorten the runway to compliance. FloodGate Medical, for example, specializes exclusively in MedTech placements and structures its intake and screening around industry-specific hiring needs. That structure reduces the compliance burden on internal teams already juggling sourcing and interviews.
The Cost of Non-Compliance: Penalties and Business Risks
The headline number is well known: fines up to €20 million or 4% of global annual turnover, whichever is higher.
Employee and candidate data has already triggered major enforcement action. The CNIL fined Amazon France Logistique €32 million in January 2024 for excessive employee surveillance, including monitoring practices that violated core GDPR principles around lawfulness and data minimization, as reported by CNBC.
France's Conseil d'Etat later reduced that fine to €15 million on appeal, but the case remains a clear signal: workforce data draws regulatory scrutiny, and penalties can run into eight figures.
Beyond fines, two risks matter just as much for TA leaders:
- Reputational damage. In specialized fields like MedTech, the candidate pool is small and tight-knit. A publicized data mishandling incident can quietly deter top talent from applying, even if no fine ever gets issued.
- Operational disruption. A regulatory investigation can pause use of recruitment technology, divert HR resources toward legal response, and stall hiring for roles that were already time-sensitive.
- Slower time-to-hire. Overcorrecting after a compliance scare often adds approval layers to routine candidate outreach, extending time-to-fill for roles that were already hard to staff.
Why GDPR Compliance Matters Even More for MedTech Recruiting
MedTech hiring rarely stays within domestic borders. Companies routinely source EU-based regulatory affairs experts, clinical specialists, and R&D engineers, which means GDPR exposure runs higher here than in purely US-focused hiring.
There's also a direct link between GDPR discipline and ethical DEI practice. Diversity analytics work best on anonymized, aggregated data: tracking pipeline trends by role or stage, not tying outcomes to raw sensitive attributes like ethnicity or health status collected on individual candidates. Done this way, DEI measurement and GDPR's data minimization principle point in the same direction rather than pulling against each other.
FloodGate Medical's approach reflects this alignment. The firm's recruiting model centers on equity, diversity, and inclusion while staying focused exclusively on the MedTech sector, giving its search teams a dual advantage:
- Understanding of industry-specific regulatory nuances, from clinical trial roles to cath lab specialists
- Familiarity with the data sensitivities that come with cross-border sourcing
- Ability to apply DEI-focused analytics without exposing individual candidates' sensitive data
For MedTech companies building a diverse, high-caliber pipeline, that combination of DEI focus and industry specialization reduces data risk in ways a generalist staffing firm typically can't match.
Frequently Asked Questions
What are the GDPR requirements for talent acquisition?
GDPR requires lawful, transparent data processing, strict data minimization, defined retention periods, strong security measures, and honoring candidate rights like access, correction, and erasure throughout hiring.
Is GDPR compliance mandatory in the USA?
GDPR isn't a US law, but it applies to any US company processing personal data from EU-based candidates. For globally-minded recruiters, compliance is effectively mandatory.
Does GDPR apply to US companies without any EU offices?
Yes. GDPR follows the data subject, not the company's location, so recruiting even one EU-based candidate can trigger compliance obligations regardless of where the company is headquartered.
How long can a company retain candidate data under GDPR?
GDPR doesn't set a fixed period, but retention must be justified. Many companies use a 6-to-12-month benchmark for unsuccessful candidates unless renewed consent is obtained.
Can AI be used to screen candidates under GDPR?
AI screening is permitted, but candidates have the right to request human review of any significant automated decision. Full human oversight in final hiring calls is required.
What should recruiters do if a candidate requests data deletion?
Recruiters must comply within GDPR's required timeframe, typically one month, unless a legal basis exists to retain the data, such as an ongoing dispute or litigation hold.


