A candidate's CV can contain more sensitive information than it first appears. Health information, religious beliefs, political activity or trade union involvement can all appear in ordinary applications. Once this information is processed, GDPR special category data rules become relevant. For recruiters using AI, this matters even more. An AI system can process the entire resume, including information a recruiter may not have intended to use in screening.

Understanding GDPR special category data can therefore help recruitment teams handle candidate information more carefully.

What Counts as GDPR Special Category Data?

GDPR special category data covers certain types of sensitive information that receive stronger protection under GDPR, including health information, religious beliefs, political opinions and trade union membership. Some special category data examples are obvious. Others can be less direct.

A resume mentioning medical leave could reveal health information. Volunteering for a religious organization could reveal religious beliefs. Political campaigning or trade union roles could reveal political opinions or union membership.

This is why GDPR special category data isn't limited to information that is explicitly labelled as sensitive.

For recruiters, the important point is that sensitive personal data GDPR rules can apply even when the information appears naturally within a candidate's resume.

Where Can GDPR Special Category Data Appear in a Resume?

There are several ways GDPR special category data can appear during recruitment:

  • A career break explained by medical treatment
  • Volunteer work with a religious or political organisation
  • Trade union representative experience
  • Information about a disability or reasonable adjustment
  • A photograph or other information that may reveal protected characteristics

These are useful special category data examples, but they don't mean recruiters should automatically remove this information. The issue is how the information is collected, stored and used.

This is also where individuals rights under GDPR become important. Candidates have rights over how their personal information is processed, including specific rights around their special category data.

A recruitment team should therefore know what information enters its systems and what happens to it afterwards.

Why GDPR Special Category Data Matters in AI Recruitment

The issue becomes more important when using ai hiring software.

An AI system doesn't necessarily distinguish between information that is useful for assessing a candidate and information that should receive additional protection. If it processes the entire resume, GDPR special category data could become part of the information being analysed.

This raises questions around automated decision making GDPR requirements and human oversight. AI can support candidate screening, but recruiters still need to understand what information is influencing the process.

The same applies to an applicant tracking system GDPR workflow. If candidate information moves through several systems, recruiters need to understand where that special category data is stored and who can access it.

Being GDPR compliant isn't simply about having a privacy policy. It means understanding how candidate information is actually handled throughout the recruitment process.

What Should Recruiters Check?

When dealing with GDPR special category data, a few practical questions are worth asking:

  • What candidate information is the system processing?
  • Could the resume contain special category data?
  • Who has access to that information?
  • Where is the data stored?
  • Is the information being used by AI to influence candidate decisions?
  • Can the recruiter explain how the information is being used?

These questions support data protection by design, where privacy is considered as part of how recruitment technology is built rather than added later.

They also help recruiters understand their responsibilities around individuals rights under GDPR, particularly when candidates ask how their information is being processed.

A tool being marketed as GDPR compliant shouldn't remove the need to ask these questions.

How EdgeTal Handles Candidate Data

GDPR special category data is one reason the architecture behind recruitment software matters.

EdgeTal runs its AI directly on the recruiter's device using a private LLM. Candidate resumes don't need to be sent to a cloud server simply for AI processing.

That can reduce some external processing and transfer considerations and supports data protection by design by keeping AI processing close to where the candidate data is being used.

Importantly, EdgeTal doesn't claim that on-device processing automatically makes recruitment gdpr compliant. Recruiters still have responsibilities around lawful processing, retention, access and individuals' rights under GDPR.

The difference is architectural: GDPR special category data contained within a candidate's resume stays on the recruiter's device while EdgeTal processes it locally.

That doesn't eliminate every risk associated with sensitive personal data GDPR requirements, but it removes the need to send candidate information to a cloud server for the AI processing itself.

Final Thoughts

GDPR special category data can appear in ordinary resumes without recruiters immediately recognising it. When AI is added to the recruitment process, understanding what happens to that information becomes even more important. Recruiters don't need to treat every resume as a compliance problem. They do need to understand what information their recruitment technology processes, where it goes and how AI uses it.

Because a resume isn't just a CV. It can contain sensitive information that deserves to be handled with care.


FAQs

What is GDPR special category data?

GDPR special category data includes sensitive information such as health data, religious beliefs, political opinions, trade union membership, and sexual orientation.

Can special category data appear in a CV?

Yes. A CV can contain special category data through information such as medical leave, disability information, religious volunteering, or trade union experience.

How should recruiters handle special category data?

Recruiters should understand what candidate information is collected, where it is stored, who can access it, and how it is used in recruitment and AI screening.

How does EdgeTal process sensitive candidate data?

EdgeTal processes candidate CV data directly on the recruiter's device using a private LLM, so the CV does not need to be sent to a cloud server for AI processing.