Skip to content
Recruiting

Taking Applications Online: Fields, Deadlines, Deletion

Which fields an application form may contain, which ones the pay transparency directive removes, how long documents have to stay and what a documented deletion looks like.

14 min read DatenschutzTeamFormulare

The application form is the one place on a company website where complete strangers voluntarily hand over a CV, an address, a date of birth and certificates. That page decides two things at once: whether enough suitable people reach the send button, and whether the business then stores those documents — and gets rid of them again — as data protection law requires. In practice both go wrong: the form asks for too much, and nothing is deleted, because no one can say when deletion becomes permitted and when it becomes due. This article follows the life of the data: fields with a legal basis, retention, and a deletion you can evidence.

Data lifecycle of an application Four checkpoints from intake to documented deletion 1 Intake 100 % submit digitally 2 Access 97.3 % home pages over HTTPS 3 Retention 2 + 3 months after rejection 4 Deletion 1 month access-request deadline Day 0 procedure running rejection plus 2 months plus 3 months to file Every checkpoint needs an owner, a legal basis and a date Sources: Bitkom 2025, HTTP Archive Web Almanac 2025, AGG and ArbGG, GDPR Article 12

Why the form helps decide the hire

The demand is documented. In the first quarter of 2026 there were 1.15 million (IAB) vacancies across Germany, surveyed among 9,342 responding employers. For every 100 positions advertised in the same quarter there were on average 264 (IAB) registered unemployed people. Candidates exist; they turn into applications only if the path to the send button holds up. That path has long been digital: before 82 percent (IAB) of the new hires made in 2025, companies had searched through at least one digital channel, and online portals, the company's own website and social media were together decisive for a successful hire in 52 percent (IAB) of cases. A careers page with vacancies and a named contact has its own success rate.

What a stuttering application process costs can be stated in days. The average completed vacancy duration between the intended start date and the withdrawal of the position stood at 157 days (Federal Employment Agency) in the rolling twelve-month total from September 2025 to August 2026; the agency notes in the same monthly report that an operational change raised the figure. 47 percent (Federal Employment Agency) of the positions withdrawn had been vacant for more than three months, and 142,000 (Federal Employment Agency) new vacancies were registered in August alone. A form that cannot be operated on a phone loses weeks in the calendar.

Submission is digital everywhere in any case. 100 percent (Bitkom) of the companies surveyed allow application documents to be submitted digitally, and 88 percent (Bitkom) add them to a pool for later selection; the basis is a representative survey of 852 companies with three or more employees. The process stays digital afterwards: 63 percent (Bitkom) interview at least partly by video and 47 percent (Bitkom) use online tests or digital assessment centres. The pool figure carries the side effect this article turns to later: keeping documents means processing beyond the original purpose, which needs its own basis and deadline.

Two questions, one form

An application form has to pass two tests at once. First: can someone with a phone, in five minutes, without creating an account, reach the send button? Second: can the business say for every field why it is collected, who sees it and when it disappears? Forms that pass only the first produce applications and, later, trouble.

Which fields have a legal basis

The starting point is the Federal Data Protection Act. Applicants for an employment relationship, and people whose employment relationship has ended, are treated as employees (Federal Ministry of Justice) — section 26(8) BDSG. Every question therefore hangs on the same threshold: processing must be necessary for the decision on entering into the employment relationship, and necessary is meant narrowly. Everything needed for the shortlist belongs in the form; everything needed only after the offer — bank details, social security number, details about children — is collected on joining. What belongs in the privacy policy is covered in the article on imprint, privacy policy and the other legal pages.

  • Name and one way to reply — one required field for email or phone
  • The position as a select field, so matching does not depend on free text
  • An upload field for common formats and several files, with a visible size limit
  • Earliest possible start date — short, optional, no forced date picker
  • An optional free-text field of about three lines
  • Consent to longer storage as a separate box that is not pre-ticked
  • A visible note on the retention period and on whom to contact

A field that is legally clean can still be technically unusable — and then the applicant drops out just the same. In the 2025 crawl, 24.93 percent (HTTP Archive Web Almanac 2025) of input fields in the mobile measurement had no accessible name at all, and only 34.57 percent (HTTP Archive Web Almanac 2025) took their name from an associated label element; the rest rely on placeholder text that disappears once someone types. For required fields the native attribute prevails: 66 percent (HTTP Archive Web Almanac 2025) on mobile. Phrasing understandable labels is covered in the article on accessible, plain website copy.

A field that works for keyboard and screen reader
<label for="app-mail">Email address</label>
<input
  id="app-mail"
  name="email"
  type="email"
  autocomplete="email"
  required
  aria-describedby="app-mail-help">
<p id="app-mail-help">We reply within five working days.</p>

Scroll table sideways

Field in the formDoes it belong there?Reason
Name, email or phoneYes, requiredWithout a reply channel there is no answer
Date of birthOnly after the offerDispensable for the shortlist, an opening for age discrimination
PhotographOptional, not requiredA compulsory photo creates risk without gain
Current salarynot included The directive requires the ban; German transposition is still outstanding
Marital status, childrenOnly after joiningIrrelevant to the selection
Severe disabilityOptional, clearly markedPublic employers need it for the interview duty
Bank detailsnot included Needed only with the contract
Consent to the talent poolYes, a separate boxA separate purpose, a separate revocable decision

The two-step for cutting fields

Take the existing form and write two things next to every field: the reason it is there and the point at which it will be deleted. Any field where one of the two stays blank comes out. Everything needed only after the offer moves into an onboarding form. In many cases a considerable share of the fields falls away.

Fields that have to leave the form

The single biggest change comes from Brussels. Directive (EU) 2023/970 on the principle of equal pay had to be transposed into national law by 7 June 2026 (EUR-Lex). Article 5(2) provides for a ban on the question about previous earnings: employers shall not ask applicants about their pay history in their current or previous employment relationships (EUR-Lex). The deadline has passed and no German transposing act is in force yet. A directive has no direct effect between private parties, so private employers are not bound by it directly at present; for public employers direct effect comes into consideration once the deadline has expired. In practice that changes little: anyone rebuilding the form now drops the field rather than touching it a second time. A field for salary expectations may stay. In return the directive imposes an obligation: under Article 5(1) information on the initial pay level must be provided in such a way as to ensure an informed and transparent negotiation on pay (EUR-Lex). Employers with 250 or more workers (EUR-Lex) also owe a first pay report by 7 June 2027.

The severe disability field is different: it has a basis, but it may not be forced. Private and public employers with an annual monthly average of at least 20 workplaces (Federal Ministry of Justice) must employ people with severe disabilities on at least 5 percent (Federal Ministry of Justice) of their workplaces. For public employers there is more: if people with severe disabilities have applied or been proposed by the Federal Employment Agency, they are invited to an interview (Federal Ministry of Justice). The form must receive the information without making it compulsory. The related logic appears in the article on what public sector buyers look up.

  • Asking for current or previous salary: remove it, even though the German transposition of the directive is still outstanding
  • Date of birth and photograph as required fields: make them optional or remove them
  • Questions about pregnancy, religion, party membership or convictions without a job link: remove them outright
  • Health information: only where the work demands it, and then with its own explanatory text
  • Pre-ticked consent boxes: invalid and easy to prove
  • A registration requirement before sending: the most effective barrier against incoming applications

The route of the data: transport, inbox, access

Encrypted transmission is the normal case, not an extra. In the 2025 crawl, 98.8 percent (HTTP Archive Web Almanac 2025) of all recorded mobile requests went over HTTPS and 97.3 percent (HTTP Archive Web Almanac 2025) of home pages were served encrypted; TLS 1.3 carries around 76 percent (HTTP Archive Web Almanac 2025) of all sites. For planning, the Federal Office for Information Security sets the direction: TLS 1.2 is recommended only until the end of 2031 (BSI), because no quantum-safe key agreement methods are being standardised for it; the exclusive use of classical key agreement methods is likewise recommended only until the end of 2031 (BSI). More on a small attack surface is in the article on website security for small businesses.

After transmission comes the part encryption does not cover. Applications land in a shared mailbox that more people can open than anyone assumes, get forwarded, sit as attachments in private mailboxes and reappear months later on a network drive. Every copy is a separate processing operation with its own deletion duty. The way out: one storage location, a named group with access, no forwarded attachments and a documented split of roles and permissions in website maintenance. Where storage runs through a provider, a data processing agreement belongs with it.

Stage 1: receipt

The form transmits encrypted, confirms receipt and writes a timestamp. That timestamp anchors every deadline.

Stage 2: access

A named group sees the documents and one location holds them. Departments get a view, not a copy.

Stage 3: retention

With the rejection the record receives a deletion date. Until then it stays untouched, but not forgotten.

Stage 4: deletion

Deletion happens everywhere: storage, mailbox, backups on their cycle. A short entry records what was removed and when.

Deadlines: how long documents have to stay

The rule of thumb of six months is not a legal norm but a rounded sum of two real deadlines. The first is in the General Equal Treatment Act: a claim under section 15 AGG must be asserted in writing within a period of two months (Federal Ministry of Justice) unless a collective agreement provides otherwise; for rejected applicants the period starts when the rejection is received. Destroying the file the moment the rejection goes out leaves the business without a defence. The order of magnitude sits in the same section: compensation for a failure to hire may not exceed three months' salary (Federal Ministry of Justice) where the person would not have been hired under a non-discriminatory selection either.

A second clock then starts. An action for compensation under section 15 AGG must be brought within three months (Federal Ministry of Justice) of the claim being asserted in writing; that is section 61b(1) ArbGG. Two plus three months from receipt of the rejection is therefore the defensible lower bound — not a rigid rule, but the interval in which a defence against legal claims may be necessary. How tight employment deadlines otherwise are is shown by the Protection Against Dismissal Act: after a dismissal there are three weeks (Federal Ministry of Justice) to bring an action.

Scroll table sideways

EventDeadlineWhat it means for the file
Application arrivesNo statutory deadlineSet a timestamp and match it to the position
Access requestOne month from receiptThe records must be fully reportable within days
Rejection goes outStart of retentionNote the deletion date on the record
Two months after the rejectionEnd of the AGG period for asserting a claimEarliest sensible deletion
Three months after assertionEnd of the ArbGG limitation for court actionOnly then does the reason for retention fall away
Consent to the talent poolSelf-imposed, usually six to twelve monthsRevocation must trigger deletion
A data breach becomes known72 hours to notifyWithout knowing the records, the scope cannot be described

How a supervisory authority handles this in its own affairs is set out in its privacy notice for applications — the most practical benchmark available. Where the procedure ends with receipt of a rejection, the personal data are deleted two months (State Data Protection Commissioner of Baden-Württemberg) after receipt of the rejection, unless longer storage is necessary for the defence of legal claims. That wording shows both a standard case and the reservation for a dispute. Keeping everything indefinitely brings no advantage.

The mistake that most often gets expensive

The widespread problem is not retention that is too short, but retention with no end date. Documents from old procedures sit in mailboxes, on network drives and in backups without anyone being able to place them. When an access request arrives, the business has to describe records it does not know itself.

Talent pool: with consent only, and with an end date

The pool is the most common reason for longer storage — 88 percent (Bitkom) of companies keep documents for later selection. Legally that is a new purpose, and it can no longer rest on necessity for the specific position, because that decision has been made. It rests on consent that is freely given, declared separately, revocable at any time and limited to a stated period. Which is why the question belongs in the rejection message rather than the send step. How to set up such forms is shown in the article on service forms for existing customers.

  • Consent is obtained after the rejection, not inside the application form
  • The text names a concrete period, twelve months for example, not an open-ended until further notice
  • The revocation link sits in the message and requires no login
  • Once the period ends, a recurring calendar entry deletes — not good intentions
  • Anyone approached from the pool is told in the first sentence where the data came from
  • The pool sits with live applications so one access request covers both

Consent without an end date is not consent but an archive with a friendly heading.

Access requests, breaches and the fine range

Rejected applicants ask more often than expected, and a hard deadline then runs. The controller shall provide information on action taken to the data subject without undue delay and in any event within one month (EUR-Lex) of receipt of the request; that is Article 12(3) GDPR. Supervisory figures show the trend: the Bavarian authority received 9,746 (Bavarian Data Protection Authority) complaints and enforcement requests in 2025, 61 percent more than the year before, and 62 percent (Bavarian Data Protection Authority) of concluded formal complaints were dealt with within three months. How such a request is worked through is in the article on answering GDPR access requests.

The second case is the more unpleasant one. In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours (EUR-Lex) after having become aware of it, notify the competent supervisory authority. The same report counts 3,603 (Bavarian Data Protection Authority) breach notifications in 2025. The framework has two tiers: infringements of the processing principles, which include storage limitation, sit in the upper tier of 20 million euros (EUR-Lex) or up to 4 percent of worldwide annual turnover, missing technical measures in the lower tier of 10 million euros (EUR-Lex) or up to 2 percent. How the 72 hours play out is covered in the article on a website data breach.

A deletion log that survives a follow-up question
2026-09-13  Role: mechanical fitter  Case: BW-2026-0184
            Rejection received:      2026-07-11
            AGG period (2 months)    expired 2026-09-11
            ArbGG action pending:    no
            Deleted: storage, mailbox, attachments
            Backup drops out of cycle on 2026-10-11
            Carried out by: HR office

Apprenticeships: the drop-off happens before the click

The connection is clearest with apprenticeships. The share of unfilled apprenticeship places most recently stood at 30 percent (IAB), five points below the two previous years but still high; the highest non-fill rate, at 49 percent (IAB), was in construction. The basis is the IAB Establishment Panel with around 15,000 establishments. As a reason, companies mostly name not the selection but the absence of applications: 57 percent (IAB) said not enough people had applied. And 27 percent (IAB) cite applicants withdrawing, against 23 percent ten years earlier.

  • Allow applications without a cover letter: contact details, school record and a free-text field
  • Accept files from a phone, photographs of certificates included, with a visible size limit
  • Send a confirmation of receipt with a name and a direct line, not a no-reply address
  • Name a response deadline, state it in the confirmation of receipt and keep it
  • On the vacancy page, say what happens in the first week and who the contact is
  • The trade-off with a network profile is in the article on an own website versus a social media profile

Done in four weeks

The rebuild is a question of four decisions: which fields stay, who has access, when deletion happens and who does it. In XICflow the application route is built as part of the page rather than as an embedded third-party form: fields, labels, required markers and the retention note sit in one place, delivery is static and encrypted, and submissions land in a defined mailbox. The path from description to finished page is under how it works; the scope is in the features overview.

  1. Week 1: annotate every field with a reason and a deletion point; delete fields lacking either
  2. Week 1: list every location where applications sit today
  3. Week 2: build the form, connect the labels, mark required fields, test the upload
  4. Week 2: write the retention note with the same period as the privacy policy
  5. Week 3: define the access group, set up the shared mailbox, switch off forwarding
  6. Week 3: extend the rejection template with the pool note, period and revocation link
  7. Week 4: create the deletion date as a recurring calendar entry and clear old records
  8. Week 4: submit a test application from a phone and walk the reply chain

The final test is the same as for any other form: someone who does not know the business fills it in on a phone while another person times it. Anything that prompts a question is a finding. Such a run for enquiries is described in the article on the contact form; how quickly to answer is in the article on response times for enquiries. Examples are in the demos.

Sources and studies

IAB Job Vacancy Survey 1/2026 and IAB Establishment Panel, Institute for Employment Research. Monthly report of the Federal Employment Agency, August 2026. Bitkom press release on digital applications, 852 companies surveyed. 15th Activity Report 2025 of the Bavarian Data Protection Authority. Web Almanac 2025, Accessibility and Security chapters, HTTP Archive. Technical Guideline TR-02102-2 of the Federal Office for Information Security, version 2026-01. Statutes via gesetze-im-internet.de: AGG, ArbGG, KSchG, SGB IX, BDSG. Regulation (EU) 2016/679 and Directive (EU) 2023/970 via EUR-Lex. Privacy notice of the State Data Protection Commissioner of Baden-Württemberg. Editorial guidance; it does not replace legal advice in an individual case.