You found a candidate’s email on LinkedIn. It was public. You saved it. Now you’re sending outreach. That’s not enough. Under GDPR, that email is personal data — and storing it without a valid basis is a compliance risk, not a formality.

Even if the data is publicly available, you can’t assume you’re free to use it. Just because you can see an email doesn’t mean you can process it. The law treats all email addresses as personal data, and storing them without one of six lawful bases could lead to fines of up to €20 million or 4% of global annual revenue. That’s not theoretical — it’s how the EU enforces accountability.

You’re not just managing contacts. You’re handling sensitive information with real legal consequences. This guide explains exactly how GDPR rules apply to recruiters sourcing emails — whether from public profiles, job boards, or referrals. It tells you what you need to do to stay compliant, and what you can’t skip.

Key takeaways

  • Email addresses are personal data under GDPR, even if found on public platforms like LinkedIn.
  • Storing candidate emails without a lawful basis — such as consent or legitimate interest — exposes your company to fines up to €20 million or 4% of global revenue.
  • A public profile does not grant permission to store or use an email; you must meet one of the six GDPR processing bases, including explicit consent or documented legitimate interest.

What does GDPR say about storing sourced candidate emails?

Under GDPR, you must have a lawful basis—like explicit consent, legitimate interest, or a contract—to store and process candidate email data. If you’re sourcing emails from public sources, consent is unlikely, so legitimate interest is commonly relied on, but only if you’ve documented it and balanced it against the candidate’s privacy rights.

Lawful bases for processing candidate email data

You can’t just collect candidate emails and store them without a clear reason. GDPR’s Article 6 requires a lawful basis. For sourced candidate emails, the most applicable bases are consent, legitimate interest, or a contract. Consent is valid only if the candidate explicitly agreed, something that’s rare when you’re sourcing from LinkedIn or job boards.

Legitimate interest is often used in recruitment—especially when you’re building a talent pool. But it’s not automatic. You must show that your interest in storing the email is reasonable and that it doesn’t outweigh the individual’s rights. For example, repeatedly emailing someone who never applied and never asked to be contacted may not qualify.

Contractual basis applies when a candidate has applied for a role. At that point, email processing is tied to performance of the job application, which meets Article 6(1)(b). But only for roles they’ve applied to—not for passive outreach.

Documenting and balancing legitimate interest

If you're relying on legitimate interest, you must document your assessment. This includes identifying the purpose (e.g., “building a talent database for future roles”), measuring its necessity, and considering the candidate’s expectations. The ICO’s guidance on legitimate interest offers practical steps and warns that interest must be proportionate and not used as a blanket excuse.

A key part of the balance is giving candidates a clear way to opt out. Even if you claim legitimate interest, they still have the right to object. If they do, you must stop processing their data unless you can prove a compelling reason that overrides their objection.

Using email verification tools like bulk verification can help ensure you’re not storing invalid or fake addresses, reducing risk. It also supports compliance—by not sending to non-existent emails, you limit data exposure and avoid unnecessary processing. This is one way to demonstrate you’re not over-collecting data.

Remember: GDPR isn’t just about consent. It’s about accountability. The rules apply equally to sourced emails, even if they’re public. If you’re not sure about your basis, test it. If you can’t justify it, don’t store it.

How to handle candidate emails collected through public sources

You can use publicly sourced candidate emails for outreach only if you have a lawful basis—such as legitimate interest—and ensure the data is necessary, proportionate, and not stored indefinitely. Collecting emails from LinkedIn or company websites doesn’t grant blanket permission to store or repurpose them without justification. Long-term retention without consent usually violates GDPR’s data minimization principle.

Public doesn’t mean free

Just because an email appears on a public profile doesn’t mean you can harvest it freely. GDPR treats all personal data—whether scraped from a company website or a social network—as protected. Even if the data is publicly visible, lawful processing requires a valid basis. Legitimate interest is possible, but it’s not automatic. You must evaluate whether the use is fair, necessary, and balanced against the individual’s privacy rights.

Let’s be clear: scraping email lists from public sources and storing them for years doesn’t pass scrutiny. The data minimization principle says you should only keep data as long as needed. Storing every candidate email you find—even if you never send to them—increases risk and violates proportionality. If you’re planning long-term use, you need explicit consent or another legal basis.

Use with care, store with discipline

When reaching out to a candidate using a public email, ask yourself: “Was this data collected in a way that respects their privacy?” If the email was listed on a corporate site and not specifically marked for public outreach, even outbound messaging may cross lines without proper justification. The European Data Protection Board (EDPB) warns against automated scraping for commercial purposes without adequate safeguards.

For safe, scalable outreach, verify emails before contacting—and validate them after. Tools like bulk email verification help you weed out invalid addresses, reduce bounces, and maintain sender reputation. This also supports compliance: sending to known-bad or non-existent emails harms deliverability and can expose your organization to scrutiny.

When you’re sourcing emails, always use them only for the intended purpose. If you plan to keep the data internally, you’ll likely need consent. Otherwise, limit retention to a defined period. This isn’t just about compliance—it’s about respecting the privacy of people you’re trying to reach.

Learn more about maintaining compliance while scaling recruitment outreach: integrate with your CRM and run inbox placement tests to verify outreach reliability without crossing legal lines.

The 3-step process to legally store sourced candidate emails under GDPR

You can store candidate emails under GDPR only if you have a valid legal basis—like explicit consent or documented legitimate interest—retain them only for the purpose of recruitment (e.g., up to six months after outreach), and delete or anonymize them when no longer needed or when the candidate withdraws consent. Let’s walk through it.

  1. Confirm you have a valid lawful basisYou must verify that your data processing aligns with one of GDPR’s six lawful bases. For sourcing, explicit consent from the candidate or a documented legitimate interest (like identifying potential hires) are your primary options. If you’re collecting emails from public sources, you're not automatically allowed to store them. You must still prove the processing is necessary and balanced against the individual’s rights.For example, if you’re sourcing emails from LinkedIn, you can’t assume implied consent. Even if you use your own legitimate interest (e.g., filling open roles), you must document it and maintain an opt-out mechanism.
  2. Limit retention to a specific purpose and timeDon’t keep candidate emails indefinitely. Store them only for a defined purpose—like outreach, follow-up, or evaluation—and apply time limits. A common practice is to retain data for up to six months after the last outreach, unless the candidate applies or signs up for ongoing updates.If you extend this period, you need an updated basis that matches the new purpose. Even a 12-month retention span must be justified and auditable.
  3. Delete or anonymize when no longer neededWhen the recruitment cycle ends, the candidate doesn’t apply, or they withdraw consent, delete their data immediately or anonymize it so it can no longer identify them. Even if they never responded, you're not allowed to keep the data just “in case.”Retaining data beyond the stated purpose breaches GDPR’s principle of storage limitation, which can result in enforcement actions. The EU’s Article 5 explicitly requires minimizing data retention.

Why accuracy matters in your recruitment database

You’re not just complying with GDPR—you’re building trust. Bad data leads to miscommunication, poor outreach, and even accidental violations. Validating emails before adding them to your CRM ensures you’re not storing non-existent or outdated addresses, which could otherwise be seen as negligent processing.

That’s where bulk verification helps: it checks your candidate list against real-time deliverability rules, catch-all patterns, and disposable domains—reducing the risk of sending to invalid or non-recoverable addresses.

Keep the process transparent and auditable

You don’t just store data—you maintain records of your processing activities. This means documenting the basis for each email collection, who consented, how long it’s kept, and when it was deleted. This documentation must be available upon request—for example, during a data subject access request or a regulatory audit.

For ongoing recruitment, consider using tools like our email verification API to validate new sources in real time. It ensures every addition to your database meets basic deliverability and compliance standards before it’s even stored.

What happens if a candidate asks to be removed from your database?

You must comply with a data subject access request (DSAR) within one month of receipt. This means deleting or anonymizing the candidate’s email and any associated personal data across all systems you control. Failure to act can result in fines up to 4% of global revenue under GDPR, and reputational damage.

Here’s exactly what you must do

  • Confirm receipt of the DSAR within one calendar month from the date it was received, as required by Article 12 of GDPR.
  • Locate and delete the candidate’s email and any personal data linked to it—job history, notes, application status, or contact logs—across your HR tools, hiring platforms, and internal databases.
  • Verify data is removed from all integrated systems, including CRMs like HubSpot or Salesforce, via your integrations dashboard or by checking logs. Don't assume deletion in one tool means deletion everywhere.
  • Retain records of the deletion process for at least six months. This includes timestamps, access logs, and confirmation of removal from all platforms.
  • Use tools like a bulk email verification service to audit your list for outdated or unverified entries, ensuring you don’t accidentally store data you no longer have a legal basis to keep. Bulk verification helps maintain compliance by flagging inactive or invalid addresses.
  • Ensure that even if a candidate’s data was anonymized (e.g., replaced with a random ID), it remains irreversible. Anonymized data is no longer personal data under GDPR, but the process must be documented.

When deletion isn’t the full answer

Sometimes, deletion isn’t enough—especially if the data was collected under a different legal basis. Let’s say you collected an email because the candidate applied to a job that’s now closed. You can delete it.

But if you have a legitimate interest in retaining records for legal or HR purposes—say, to defend against a claim—then you may keep it, but only if you’ve documented that interest and ensured it doesn’t harm the candidate. Real-time API integration can help clean your database on the fly, reducing the risk of retaining outdated records.

For those using automated sourcing, always double-check that your email finder tools like email finder don’t re-introduce outdated data when new candidates are added. Rechecking consent is critical.

GDPR doesn't just require deletion—it demands accountability and traceability. The European Data Protection Board provides guidance on maintaining audit trails through edpb.europa.eu. If you can’t prove deletion happened, the fine applies.

Why invalid or outdated emails break GDPR compliance

Storing unverified or non-existent emails violates GDPR because you’re keeping data that isn’t accurate, relevant, or necessary—breaking the principle of data minimization. If an email doesn’t exist or no longer belongs to the candidate, you can’t legally justify retaining it, and you risk non-compliance during audits or data subject requests.

Data minimization and accuracy under GDPR

GDPR requires that personal data be accurate and kept up to date. You’re not allowed to store information you know is incorrect, like an email that returns a hard bounce or fails verification. If an email is invalid, it’s not just a technical issue—it’s a compliance failure. The European Data Protection Board (EDPB) emphasizes that inaccurate data undermines the lawful basis for processing, and maintaining it exposes you to fines.

Let’s say you keep a list of 1,000 “sourced” candidate emails, including 300 that no longer exist. That’s 30% of your data being inaccurate. You’re holding onto records you can’t verify, which violates Article 5(1)(d) of GDPR—ensuring data is kept accurate and, where necessary, updated. If a candidate requests deletion, you can’t claim that email was never yours. You’re responsible.

Even worse, storing invalid emails increases the chance of accidental exposure. If someone gains access to your database—say, through a phishing attack or misconfigured cloud storage—you’re now sharing data that doesn’t belong to anyone. This isn't just a breach of trust; it's a breach of regulation. The ICO has made clear that inaccurate data collection can lead to enforcement action, especially when it’s not essential.

What happens when an email doesn’t exist

If an email is non-existent, you can’t claim it’s necessary for recruitment. You might have “sourced” it from LinkedIn, but that doesn't mean it’s valid or deliverable. Under GDPR, you must ask: is this data accurate? Is it needed? If not, it should be deleted. You don’t get a pass just because you collected it.

Automated verification helps here. You can check large lists for validity, detect catch-alls, and weed out disposable or role-based emails—common pitfalls in recruiter data. Tools like bulk email verification can flag invalid addresses before they enter your system, reducing the risk of non-compliance.

Remember: GDPR isn’t just about consent. It’s about responsibility. Keeping inaccurate data isn’t just inefficient—it’s a legal liability. Make sure your data is valid before you store it, and delete what you can’t verify. That’s how you align with the core principles of data protection.

For more, see the GDPR Info website and the standard for email formats (RFC 5322), which underpins how we verify addresses.

The role of email verification in GDPR-compliant list hygiene

Validating candidate emails reduces your database to only active, deliverable addresses—supporting GDPR’s data minimization principle by eliminating fake, outdated, or placeholder data that you shouldn’t be storing in the first place. This isn’t just about avoiding bounces; it’s about responsible data stewardship.

Reducing unnecessary data storage

Under GDPR, you can only process personal data that is necessary and accurate. Every fake, invalid, or inactive email you store increases your risk of non-compliance. Email verification helps you identify and remove those entries before they become liabilities.

For example, a catch-all email domain might accept any address without validation, so a placeholder like "[email protected]" could slip into your database. You’re not verifying intent, just storing data. Over time, that leads to bloated, inaccurate lists—exactly what GDPR aims to prevent.

Supporting data accuracy and legitimacy

You’re not just cleaning outdated entries—you’re reinforcing the legitimacy of your data. If you verify an email address in real time, you confirm it belongs to a real person, actively using that inbox. That supports the "lawfulness" of your data processing under Article 6 of GDPR.

Many recruiters assume that sourcing data via public profiles or networking events means consent is implied. It’s not. Email verification doesn’t create consent, but it helps ensure you're not misclassifying inactive or fictional data as valid records—something regulators can challenge during audits.

When you use a tool like EmailListChecker.io’s bulk verification or real-time API, you’re not adding more data—you’re refining what’s already there. It’s the difference between bulk storage and precision stewardship.

Even if the data was collected under a valid legal basis, if it’s inaccurate or outdated, it violates GDPR’s accuracy principle. Regular verification keeps your lists lean, compliant, and deliverable.

As the European Data Protection Board notes, keeping data that isn’t needed “can result in a significant breach of the data minimization principle.” Verification tools help you stay on the right side of that standard.

Think of it this way: every email you keep must pass a test—valid, active, and necessary. Email verification is the tool that runs that test.

How Emaillistchecker.io helps you meet GDPR requirements

You can meet GDPR’s data minimization and accuracy requirements by ensuring only valid, active candidate emails are stored. Emaillistchecker.io verifies entire lists at scale, removes invalid or outdated entries, and confirms email validity with 98.9% accuracy—reducing the risk of holding unnecessary personal data. This strengthens your justification for data retention and aligns with Article 5’s principle of storage limitation.

Bulk verification reduces your data footprint

Let’s be honest: recruiting lists often include typos, old addresses, or fake emails. Storing these violates GDPR’s data minimization principle. With our bulk verification tool, you can clean entire candidate pools in minutes—confirming only active, deliverable addresses. No more guesswork. No more bloated, outdated records. This is not just cleaner data—it’s compliant data.

Our verification process checks domains, MX records, and SMTP responses to confirm deliverability. It flags invalid, syntactically incorrect, or role-based emails (like info@ or recruiting@) that aren’t suitable for personal communications. You can then remove these from your database, reducing your scope of personal data processing.

Supporting retention policies with real validation

GDPR doesn’t require you to keep data forever, but you must justify why you’re keeping it. A common challenge: you can’t remember which emails were last contacted. Emaillistchecker.io helps by identifying non-deliverable or outdated entries—those that have bounced or are no longer active. This makes enforcing retention rules far easier.

For example, if a candidate hasn’t responded in 18 months, you can cross-reference your system with a verification run. If the email is no longer valid, you can confidently delete it without fear of violating GDPR’s accuracy requirement. Regular verification—done through our bulk verification tool—turns compliance from a theoretical stance into a repeatable, auditable practice.

Privacy isn't optional—it's mandatory. Tools like Emaillistchecker.io help you act on that reality. The sooner you stop storing unverified data, the stronger your compliance posture becomes.

The difference between valid, catch-all, and risky emails — what your data retention policy should include

You must retain only valid emails—confirmed deliverable addresses that are actively used—under a lawful basis like consent or legitimate interest. Catch-all domains, which accept any address, usually indicate low-quality or disposable domains and should not be stored. Risky emails—often role accounts, spam traps, or temporary domains—should be deleted within 30 days, even if they pass initial verification, to avoid GDPR violations and sender reputation damage.

Valid: Only store what’s truly deliverable

A valid email has passed real-time SMTP checks and confirms an active inbox. These are the only addresses that should be kept long-term, provided you have a valid lawful basis under GDPR—like explicit consent or a legitimate interest that’s proportionate. Even then, you should only keep them for as long as needed. For example, if a candidate applies to a job and you store their email, keep it only while that application is active or until they withdraw consent. Use tools like bulk verification to filter out invalid addresses before storage.

Catch-all: Avoid storing these entirely

Catch-all domains accept all incoming mail, regardless of whether the specific inbox exists. This means an address might be technically deliverable, but the recipient may never see the message. These often come from low-quality domains, free email providers, or temporary account setups. Even if they don’t bounce, they waste resources and risk appearing on spam trap lists. GDPR requires you to minimize data retention—storing catch-all addresses violates the principle of data minimization. The ICT Security guide explains how catch-all domains can lead to unintended data exposure.

Risky: Delete fast, don't wait

Risky emails include role accounts like info@ or admin@, spam traps, and disposable domains. These can be flagged by spam filters or cause blacklisting if used in outreach. Even if they pass basic syntax checks, they often originate from low-intent or compromised sources. Under GDPR, storing such data for long periods is not justified unless you’re actively engaging with the individual. A safe rule: if an email is flagged as risky, erase it within 30 days. This aligns with GDPR’s accountability principle—you must be able to demonstrate that you didn’t store unnecessary or high-risk data.

Use an inbox placement test before sending at scale to confirm deliverability and avoid false confidence. Inbox placement testing helps you verify if your messages reach real inboxes safely. The goal isn’t just to avoid bounces—it’s to ensure you’re not violating privacy by sending to inactive or risky addresses.

How GDPR impacts your cold outreach and CRM integration strategy

You can’t store or use a candidate’s email without a clear, lawful purpose — like consent or legitimate interest — and even then, you must document it. If your outreach is truly cold, you’re not allowed to store the email in your CRM or marketing tools unless you’ve obtained proper consent or have a documented legal basis. Integrations with platforms like Mailchimp, HubSpot, or SendGrid must include mechanisms for opt-out, and every stored address must align with GDPR’s data minimization and retention principles.

Why cold outreach data isn't GDPR-compliant by default

Under GDPR, a cold email isn’t automatically a valid data processing activity. If you’re reaching out to someone who hasn’t engaged with your brand, you’re not building consent. Storing their email in your CRM without explicit permission — or even without a documented basis for processing — is a violation.

Even if your email lands in a recipient’s inbox, that doesn’t mean you can keep their data. The right to be forgotten and the requirement for lawful basis apply equally to every email collected through outreach. You must prove you have a valid reason to keep it.

CRM and email tool integrations must include compliance layers

Platforms like HubSpot, Mailchimp, or SendGrid are not GDPR-compliant on their own. They require you to implement consent logs, opt-out links, and clear data governance policies.

If a candidate unsubscribes through a link in a campaign email, that action must be recorded and honored in real time. Failing to do so — even if you didn’t send the original email — can trigger enforcement actions.

Let’s be clear: no matter how clean your email list, if it includes contacts without consent or documentation, your integration is non-compliant. The burden is on you to verify the legitimacy of every address before syncing.

That’s where verification tools come in. Use a service like bulk email verification to scrub invalid and risky addresses before you import them into your CRM or email provider. This isn’t just about deliverability — it’s about compliance. You’re not supposed to be sending emails to addresses you can’t verify as valid or legally permitted.

For real-time integration, use the API to verify emails at the point of entry. This stops invalid data from entering your system in the first place.

And if you’re finding leads manually, the email finder helps you source only verified, potentially valid addresses — not just any name and domain.

Remember: GDPR isn’t a one-time checkbox. It’s a continuous process of accountability. Each stored email must have a purpose, and that purpose must be documented. You can’t rely on tools alone — but you can rely on them to reduce your risk.

For more, see the official GDPR text and guidance from the European Data Protection Board (EDPB).

Your final checklist for legally storing sourced candidate emails

Storing candidate emails under GDPR requires more than just a database. It demands purpose, consent, and ongoing validation. Each email you collect must serve a specific, documented recruitment need — not general marketing or data hoarding.

Key compliance steps

  • Collect emails only for active recruitment, with clear purpose documented in your records.
  • Apply GDPR-compliant justification — either explicit consent or legitimate interest — and maintain proof.
  • Verify every address before storing using a trusted verification tool like Emaillistchecker.io.
  • Remove or anonymize data after six months, or immediately upon candidate request.
  • Audit your list quarterly to identify and remove invalid, catch-all, or risky addresses.
  • Ensure all integrations (HubSpot, Klaviyo, SendGrid) enforce your compliance policies.

Even small oversights in verification or retention can lead to significant penalties. A robust email validation process is not optional — it’s a foundational part of lawful data handling.

Sources

Keep reading

Ready to put this into practice? Emaillistchecker.io verifies emails with 98.9% accuracy — start with 100 free verifications.

Frequently asked questions

Can I store a candidate’s email from LinkedIn under GDPR?

Only if you have a valid lawful basis—such as explicit consent or documented legitimate interest—and you do not store it longer than necessary.

How long can I keep a candidate’s email under GDPR?

Up to 6 months after outreach, or until the candidate withdraws consent. After that, you must delete or anonymize the data.

Consent is not required if you use legitimate interest, but you must document it and allow opt-out at any time.

What are the risks of storing invalid or disposable emails?

Invalid or disposable emails increase the risk of data breaches, violate data minimization rules, and can lead to GDPR fines.

Can email verification tools help me comply with GDPR?

Yes — they help ensure only valid, active emails are stored, reducing the risk of keeping inaccurate or unnecessary data.

What should I do if a candidate asks to be removed from my database?

Respond within one month, delete or anonymize their email and related data, and confirm the removal across all systems.

Are role emails like hr@ or careers@ allowed under GDPR?

Role accounts can be used for outreach, but should not be stored long-term. They are often high-risk and may indicate non-personal data.

How does data minimization apply to candidate emails?

You must only store emails necessary for a specific purpose and delete them when no longer needed, reducing exposure and compliance risk.

Can I use automated tools to verify candidate emails under GDPR?

Yes — using tools like Emaillistchecker.io to verify emails supports compliance by ensuring only valid, active addresses are stored.

What happens if I verify and then store an email from a fake domain?

Storing invalid or disposable domains violates data minimization and accuracy principles, increasing compliance risk.

How do integrations with HubSpot or SendGrid affect GDPR compliance?

Ensure the tool logs consent, supports opt-out functionality, and syncs only data that meets your lawful basis and retention rules.

Is a 'catch-all' email address considered valid under GDPR?

No — catch-all domains accept all emails, so the address may not be assigned. Storing such emails does not meet the accuracy or necessity standard.