The application form is the one place on a company website where complete strangers voluntarily hand over a CV, an address, a date of birth and certificates. That page decides two things at once: whether enough suitable people reach the send button, and whether the business then stores those documents — and gets rid of them again — as data protection law requires. In practice both go wrong: the form asks for too much, and nothing is deleted, because no one can say when deletion becomes permitted and when it becomes due. This article follows the life of the data: fields with a legal basis, retention, and a deletion you can evidence.
Why the form helps decide the hire
The demand is documented. In the first quarter of 2026 there were 1.15 million (IAB) vacancies across Germany, surveyed among 9,342 responding employers. For every 100 positions advertised in the same quarter there were on average 264 (IAB) registered unemployed people. Candidates exist; they turn into applications only if the path to the send button holds up. That path has long been digital: before 82 percent (IAB) of the new hires made in 2025, companies had searched through at least one digital channel, and online portals, the company's own website and social media were together decisive for a successful hire in 52 percent (IAB) of cases. A careers page with vacancies and a named contact has its own success rate.
What a stuttering application process costs can be stated in days. The average completed vacancy duration between the intended start date and the withdrawal of the position stood at 157 days (Federal Employment Agency) in the rolling twelve-month total from September 2025 to August 2026; the agency notes in the same monthly report that an operational change raised the figure. 47 percent (Federal Employment Agency) of the positions withdrawn had been vacant for more than three months, and 142,000 (Federal Employment Agency) new vacancies were registered in August alone. A form that cannot be operated on a phone loses weeks in the calendar.
Submission is digital everywhere in any case. 100 percent (Bitkom) of the companies surveyed allow application documents to be submitted digitally, and 88 percent (Bitkom) add them to a pool for later selection; the basis is a representative survey of 852 companies with three or more employees. The process stays digital afterwards: 63 percent (Bitkom) interview at least partly by video and 47 percent (Bitkom) use online tests or digital assessment centres. The pool figure carries the side effect this article turns to later: keeping documents means processing beyond the original purpose, which needs its own basis and deadline.
Two questions, one form
Which fields have a legal basis
The starting point is the Federal Data Protection Act. Applicants for an employment relationship, and people whose employment relationship has ended, are treated as employees (Federal Ministry of Justice) — section 26(8) BDSG. Every question therefore hangs on the same threshold: processing must be necessary for the decision on entering into the employment relationship, and necessary is meant narrowly. Everything needed for the shortlist belongs in the form; everything needed only after the offer — bank details, social security number, details about children — is collected on joining. What belongs in the privacy policy is covered in the article on imprint, privacy policy and the other legal pages.
- Name and one way to reply — one required field for email or phone
- The position as a select field, so matching does not depend on free text
- An upload field for common formats and several files, with a visible size limit
- Earliest possible start date — short, optional, no forced date picker
- An optional free-text field of about three lines
- Consent to longer storage as a separate box that is not pre-ticked
- A visible note on the retention period and on whom to contact
A field that is legally clean can still be technically unusable — and then the applicant drops out just the same. In the 2025 crawl, 24.93 percent (HTTP Archive Web Almanac 2025) of input fields in the mobile measurement had no accessible name at all, and only 34.57 percent (HTTP Archive Web Almanac 2025) took their name from an associated label element; the rest rely on placeholder text that disappears once someone types. For required fields the native attribute prevails: 66 percent (HTTP Archive Web Almanac 2025) on mobile. Phrasing understandable labels is covered in the article on accessible, plain website copy.
<label for="app-mail">Email address</label>
<input
id="app-mail"
name="email"
type="email"
autocomplete="email"
required
aria-describedby="app-mail-help">
<p id="app-mail-help">We reply within five working days.</p>Scroll table sideways
| Field in the form | Does it belong there? | Reason |
|---|---|---|
| Name, email or phone | Yes, required | Without a reply channel there is no answer |
| Date of birth | Only after the offer | Dispensable for the shortlist, an opening for age discrimination |
| Photograph | Optional, not required | A compulsory photo creates risk without gain |
| Current salary | not included | The directive requires the ban; German transposition is still outstanding |
| Marital status, children | Only after joining | Irrelevant to the selection |
| Severe disability | Optional, clearly marked | Public employers need it for the interview duty |
| Bank details | not included | Needed only with the contract |
| Consent to the talent pool | Yes, a separate box | A separate purpose, a separate revocable decision |
The two-step for cutting fields
Fields that have to leave the form
The single biggest change comes from Brussels. Directive (EU) 2023/970 on the principle of equal pay had to be transposed into national law by 7 June 2026 (EUR-Lex). Article 5(2) provides for a ban on the question about previous earnings: employers shall not ask applicants about their pay history in their current or previous employment relationships (EUR-Lex). The deadline has passed and no German transposing act is in force yet. A directive has no direct effect between private parties, so private employers are not bound by it directly at present; for public employers direct effect comes into consideration once the deadline has expired. In practice that changes little: anyone rebuilding the form now drops the field rather than touching it a second time. A field for salary expectations may stay. In return the directive imposes an obligation: under Article 5(1) information on the initial pay level must be provided in such a way as to ensure an informed and transparent negotiation on pay (EUR-Lex). Employers with 250 or more workers (EUR-Lex) also owe a first pay report by 7 June 2027.
The severe disability field is different: it has a basis, but it may not be forced. Private and public employers with an annual monthly average of at least 20 workplaces (Federal Ministry of Justice) must employ people with severe disabilities on at least 5 percent (Federal Ministry of Justice) of their workplaces. For public employers there is more: if people with severe disabilities have applied or been proposed by the Federal Employment Agency, they are invited to an interview (Federal Ministry of Justice). The form must receive the information without making it compulsory. The related logic appears in the article on what public sector buyers look up.
- Asking for current or previous salary: remove it, even though the German transposition of the directive is still outstanding
- Date of birth and photograph as required fields: make them optional or remove them
- Questions about pregnancy, religion, party membership or convictions without a job link: remove them outright
- Health information: only where the work demands it, and then with its own explanatory text
- Pre-ticked consent boxes: invalid and easy to prove
- A registration requirement before sending: the most effective barrier against incoming applications
The route of the data: transport, inbox, access
Encrypted transmission is the normal case, not an extra. In the 2025 crawl, 98.8 percent (HTTP Archive Web Almanac 2025) of all recorded mobile requests went over HTTPS and 97.3 percent (HTTP Archive Web Almanac 2025) of home pages were served encrypted; TLS 1.3 carries around 76 percent (HTTP Archive Web Almanac 2025) of all sites. For planning, the Federal Office for Information Security sets the direction: TLS 1.2 is recommended only until the end of 2031 (BSI), because no quantum-safe key agreement methods are being standardised for it; the exclusive use of classical key agreement methods is likewise recommended only until the end of 2031 (BSI). More on a small attack surface is in the article on website security for small businesses.
After transmission comes the part encryption does not cover. Applications land in a shared mailbox that more people can open than anyone assumes, get forwarded, sit as attachments in private mailboxes and reappear months later on a network drive. Every copy is a separate processing operation with its own deletion duty. The way out: one storage location, a named group with access, no forwarded attachments and a documented split of roles and permissions in website maintenance. Where storage runs through a provider, a data processing agreement belongs with it.
Stage 1: receipt
The form transmits encrypted, confirms receipt and writes a timestamp. That timestamp anchors every deadline.
Stage 2: access
A named group sees the documents and one location holds them. Departments get a view, not a copy.
Stage 3: retention
With the rejection the record receives a deletion date. Until then it stays untouched, but not forgotten.
Stage 4: deletion
Deletion happens everywhere: storage, mailbox, backups on their cycle. A short entry records what was removed and when.
Deadlines: how long documents have to stay
The rule of thumb of six months is not a legal norm but a rounded sum of two real deadlines. The first is in the General Equal Treatment Act: a claim under section 15 AGG must be asserted in writing within a period of two months (Federal Ministry of Justice) unless a collective agreement provides otherwise; for rejected applicants the period starts when the rejection is received. Destroying the file the moment the rejection goes out leaves the business without a defence. The order of magnitude sits in the same section: compensation for a failure to hire may not exceed three months' salary (Federal Ministry of Justice) where the person would not have been hired under a non-discriminatory selection either.
A second clock then starts. An action for compensation under section 15 AGG must be brought within three months (Federal Ministry of Justice) of the claim being asserted in writing; that is section 61b(1) ArbGG. Two plus three months from receipt of the rejection is therefore the defensible lower bound — not a rigid rule, but the interval in which a defence against legal claims may be necessary. How tight employment deadlines otherwise are is shown by the Protection Against Dismissal Act: after a dismissal there are three weeks (Federal Ministry of Justice) to bring an action.
Scroll table sideways
| Event | Deadline | What it means for the file |
|---|---|---|
| Application arrives | No statutory deadline | Set a timestamp and match it to the position |
| Access request | One month from receipt | The records must be fully reportable within days |
| Rejection goes out | Start of retention | Note the deletion date on the record |
| Two months after the rejection | End of the AGG period for asserting a claim | Earliest sensible deletion |
| Three months after assertion | End of the ArbGG limitation for court action | Only then does the reason for retention fall away |
| Consent to the talent pool | Self-imposed, usually six to twelve months | Revocation must trigger deletion |
| A data breach becomes known | 72 hours to notify | Without knowing the records, the scope cannot be described |
How a supervisory authority handles this in its own affairs is set out in its privacy notice for applications — the most practical benchmark available. Where the procedure ends with receipt of a rejection, the personal data are deleted two months (State Data Protection Commissioner of Baden-Württemberg) after receipt of the rejection, unless longer storage is necessary for the defence of legal claims. That wording shows both a standard case and the reservation for a dispute. Keeping everything indefinitely brings no advantage.
The mistake that most often gets expensive
Talent pool: with consent only, and with an end date
The pool is the most common reason for longer storage — 88 percent (Bitkom) of companies keep documents for later selection. Legally that is a new purpose, and it can no longer rest on necessity for the specific position, because that decision has been made. It rests on consent that is freely given, declared separately, revocable at any time and limited to a stated period. Which is why the question belongs in the rejection message rather than the send step. How to set up such forms is shown in the article on service forms for existing customers.
- Consent is obtained after the rejection, not inside the application form
- The text names a concrete period, twelve months for example, not an open-ended until further notice
- The revocation link sits in the message and requires no login
- Once the period ends, a recurring calendar entry deletes — not good intentions
- Anyone approached from the pool is told in the first sentence where the data came from
- The pool sits with live applications so one access request covers both
Consent without an end date is not consent but an archive with a friendly heading.
Access requests, breaches and the fine range
Rejected applicants ask more often than expected, and a hard deadline then runs. The controller shall provide information on action taken to the data subject without undue delay and in any event within one month (EUR-Lex) of receipt of the request; that is Article 12(3) GDPR. Supervisory figures show the trend: the Bavarian authority received 9,746 (Bavarian Data Protection Authority) complaints and enforcement requests in 2025, 61 percent more than the year before, and 62 percent (Bavarian Data Protection Authority) of concluded formal complaints were dealt with within three months. How such a request is worked through is in the article on answering GDPR access requests.
The second case is the more unpleasant one. In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours (EUR-Lex) after having become aware of it, notify the competent supervisory authority. The same report counts 3,603 (Bavarian Data Protection Authority) breach notifications in 2025. The framework has two tiers: infringements of the processing principles, which include storage limitation, sit in the upper tier of 20 million euros (EUR-Lex) or up to 4 percent of worldwide annual turnover, missing technical measures in the lower tier of 10 million euros (EUR-Lex) or up to 2 percent. How the 72 hours play out is covered in the article on a website data breach.
2026-09-13 Role: mechanical fitter Case: BW-2026-0184
Rejection received: 2026-07-11
AGG period (2 months) expired 2026-09-11
ArbGG action pending: no
Deleted: storage, mailbox, attachments
Backup drops out of cycle on 2026-10-11
Carried out by: HR officeApprenticeships: the drop-off happens before the click
The connection is clearest with apprenticeships. The share of unfilled apprenticeship places most recently stood at 30 percent (IAB), five points below the two previous years but still high; the highest non-fill rate, at 49 percent (IAB), was in construction. The basis is the IAB Establishment Panel with around 15,000 establishments. As a reason, companies mostly name not the selection but the absence of applications: 57 percent (IAB) said not enough people had applied. And 27 percent (IAB) cite applicants withdrawing, against 23 percent ten years earlier.
- Allow applications without a cover letter: contact details, school record and a free-text field
- Accept files from a phone, photographs of certificates included, with a visible size limit
- Send a confirmation of receipt with a name and a direct line, not a no-reply address
- Name a response deadline, state it in the confirmation of receipt and keep it
- On the vacancy page, say what happens in the first week and who the contact is
- The trade-off with a network profile is in the article on an own website versus a social media profile
Done in four weeks
The rebuild is a question of four decisions: which fields stay, who has access, when deletion happens and who does it. In XICflow the application route is built as part of the page rather than as an embedded third-party form: fields, labels, required markers and the retention note sit in one place, delivery is static and encrypted, and submissions land in a defined mailbox. The path from description to finished page is under how it works; the scope is in the features overview.
- Week 1: annotate every field with a reason and a deletion point; delete fields lacking either
- Week 1: list every location where applications sit today
- Week 2: build the form, connect the labels, mark required fields, test the upload
- Week 2: write the retention note with the same period as the privacy policy
- Week 3: define the access group, set up the shared mailbox, switch off forwarding
- Week 3: extend the rejection template with the pool note, period and revocation link
- Week 4: create the deletion date as a recurring calendar entry and clear old records
- Week 4: submit a test application from a phone and walk the reply chain
The final test is the same as for any other form: someone who does not know the business fills it in on a phone while another person times it. Anything that prompts a question is a finding. Such a run for enquiries is described in the article on the contact form; how quickly to answer is in the article on response times for enquiries. Examples are in the demos.
Sources and studies