Browse topics
GDPR & Data

Send GDPR consent requests to candidates

Send GDPR consent requests to candidates

If your agency relies on consent to hold candidate data, Crumblelead can email candidates a link to agree or decline, and keep a record of their answer. This helps you stay compliant without chasing paperwork.

Before you start

  • Your workspace's lawful basis must be set to Consent. An admin sets this under Settings → Lawful Basis, where you also write the Candidate Notice Email and the Consent Page Content the candidate will see.
  • You need a connected email account, because consent requests send from your own address. See Sync your Gmail or Outlook email and calendar.
  • The candidate must have an email address on file.

Send a consent request

  1. Go to Settings, then Data Retention.
  2. Find the Candidates requiring review list. Candidates who are eligible show a Request consent button.
  3. Click Request consent for a candidate. To ask several people at once, select them and use the bulk Request consent action.
  4. Confirm in the dialog. The candidate is emailed a link to agree or decline, sent from your connected email account.

What the candidate sees, and how answers are recorded

  • The candidate receives your notice email with a secure link. The link opens a page with your agency's branding and content, and an Agree or Decline choice. They do not need a login.
  • If they agree, their consent is recorded against their profile.
  • If they decline, that is recorded too, and the team member you nominated is notified.
  • The link is valid for 30 days. You can see the full history from the candidate's Privacy tab using View history.

Roles and limits

  • Consent requests are sent from the admin-only Data Retention page.
  • You cannot send a second request to someone who already has one pending.
  • In demo workspaces, sending is simulated and no real email goes out.

FAQs

Who does the email come from?
Your own connected email address, not a generic system address, so it looks like it came from you.

What if the candidate ignores the link?
The link lasts 30 days. You can review who has and has not responded from the Data Retention page and each candidate's Privacy tab.

Do I need consent for everyone?
Only if your workspace uses consent as its lawful basis. Your admin sets this under Lawful Basis.

Related articles