Industry GDPR documentation

Written and maintained by Chris Haycock, GDPRQuick.com/CliqTo Ltd
Last reviewed Not yet reviewed


GDPR for recruitment agencies

Recruitment agencies handle personal data at volume: CVs, contact details, work history, salary expectations, right-to-work evidence, interview notes, references, background checks, client shortlists, and sometimes sensitive equality or health information. This page explains the GDPR records a recruitment agency needs, and how GDPRQuick turns those decisions into practical documentation.

Let's begin.

What personal data recruitment agencies handle

A recruitment agency does not just hold a name and phone number. It often builds a detailed picture of a candidate, their work history, preferences, pay expectations, eligibility to work, availability, interview outcomes, and suitability for a role.

Typical recruitment data includes:

  • CVs, covering letters, portfolios, and application forms
  • Candidate contact details, job preferences, salary expectations, and availability
  • Interview notes, screening notes, shortlist decisions, and client feedback
  • Right-to-work evidence and identity documents
  • References, employment history, qualification checks, and background screening
  • Client contacts, hiring manager notes, vacancies, terms, and placement records
  • Marketing preferences for job alerts, talent pools, newsletters, and similar updates

Because recruitment data is collected from candidates, clients, referees, job boards, LinkedIn, and internal consultants, the GDPR documentation needs to explain each source and each purpose clearly.

Recruiters often talk about candidate consent, but under GDPR consent has to be freely given and easy to withdraw. That can make it awkward as the main basis for ordinary recruitment work, especially once a candidate has asked you to find roles for them.

Many agencies rely on legitimate interests for core recruitment activity, such as matching candidates to suitable roles, speaking to clients about relevant candidates, and keeping placement records. Consent may still be needed for some separate activity, such as direct marketing in certain channels or processing special category data.

What your documentation should make clear

The important point is that the agency records its decision. Your GDPR documentation should explain which lawful basis applies to candidate registration, role matching, client introductions, job alerts, compliance checks, and post-placement record keeping.

Sharing CVs and profiles with clients

Sending a CV to a client is a disclosure of personal data. Candidates should know when their profile may be shared, what kind of client it may be shared with, and whether the CV will be edited or presented as a recruiter profile before it leaves the agency.

Agencies should avoid blanket sharing. A candidate being on your database does not mean every consultant can send that CV to any client for any vacancy.

  • Record when a candidate agrees to be represented for a role
  • Keep notes of which clients received a CV or profile
  • Make sure clients understand they must handle candidate data securely
  • Avoid sending excessive personal detail where a summary profile is enough

Not sure what applies to your recruitment agencies?

Take the quick risk check before you get too deep into the detail.

Take the 2-minute check

Talent pools, speculative candidates and retention

Recruitment databases can become stale quickly. A CV that was useful three years ago may now be inaccurate, irrelevant, or no longer wanted by the candidate. GDPR does not set a single retention period, but it does require you to keep personal data only for as long as you can justify.

Your retention policy should distinguish between active candidates, placed candidates, speculative contacts, rejected applicants, dormant records, clients, and finance records.

A practical retention approach

Many agencies use reminder cycles: check whether a candidate wants to remain on the database, update the record, or remove it. The exact period is a business decision, but it should be written down and followed.

Right-to-work checks, references and screening

Recruiters often collect evidence that is more sensitive than ordinary contact data. Right-to-work documents, reference notes, qualification checks, background screening, and eligibility records need careful handling because they may contain identity, nationality, immigration, employment, or criminal-record-related information.

The agency should record what checks it performs, why each check is needed, who requests it, who receives the result, and how long evidence is retained.

  • Do not keep identity documents longer than necessary without a clear reason
  • Separate compliance evidence from general candidate notes where possible
  • Restrict access to screening results to people who need them
  • Document whether the agency or the hiring client is responsible for each check

Special category data in recruitment

Recruitment can involve special category data even when the agency does not set out to collect it. Candidates may disclose health conditions, disability adjustments, union membership, religious needs, or other sensitive information during a search.

Equality monitoring, diversity reporting, occupational health information, and reasonable adjustment notes all need a separate Article 9 condition as well as an ordinary lawful basis.

Keep sensitive information deliberate

Sensitive information should not be scattered through free-text consultant notes unless there is a clear reason. If it is needed, the purpose, access controls, and retention period should be documented.

Job alerts, marketing and candidate communications

Recruitment agencies often send role alerts, newsletters, market updates, salary guides, and client development emails. Some messages are part of an active recruitment service, while others look more like marketing.

Your documentation should explain how candidates and clients are added to mailing lists, how preferences are recorded, and how opt-outs are handled.

  • Separate role-specific contact from broader promotional marketing
  • Keep evidence of marketing preferences where consent is used
  • Make opt-out routes easy to use
  • Check that job-board imports and CRM lists have a lawful source

Processors, CRMs and recruitment platforms

Most agencies depend on recruitment CRMs, job boards, email tools, payroll systems, e-signature tools, cloud storage, screening providers, and sometimes outsourced back-office providers. Each supplier may process candidate or client data on the agency's behalf.

A GDPR record should name the categories of processors used, the type of data each one handles, where data is stored, and whether appropriate processor terms are in place.

What documents does a recruitment agency need

A useful GDPR pack for a recruitment agency should reflect the way candidate data moves through the business, from first contact to placement and later retention.

  • A candidate and client privacy notice
  • A Record of Processing Activities covering candidate, client, supplier, staff, and finance data
  • A retention policy for active candidates, dormant candidates, placements, and compliance evidence
  • A lawful basis record for matching, client sharing, marketing, screening, and placement administration
  • A processor list covering CRM, job boards, screening tools, payroll, cloud storage, and email systems
  • A breach response process for lost CVs, misdirected emails, CRM access issues, and supplier incidents
  • A subject access request process for candidate data held across systems and consultant notes

The documents do not need to sound like a law firm wrote them. They need to be accurate enough that a consultant, director, or administrator can understand what the agency actually does with personal data.

Build your recruitment GDPR documents from your own answers

GDPRQuick works through this as a guided wizard. You answer questions about your agency: how candidates register, how CVs are shared, what platforms you use, what checks you perform, how long records are kept, and how marketing preferences are handled.

Your answers become the wording for your GDPR statement, action plan, processing records, and supporting forms. You can return later and update the documents when your agency changes process, supplier, or market focus.

GDPRQuick.com UI Platform Screenshot

Check your GDPR risk first.

Use the GDPRQuick risk calculator to get an indicative view of where your recruitment agencies data protection work may need attention.

Start the risk calculator

Questions about GDPR for recruitment agencies

Can a recruitment agency keep CVs on file?

Yes, if there is a lawful basis and a clear retention period. The agency should tell candidates how long records are kept, why they are kept, and how candidates can ask for deletion or updates.

Do I need consent before sending a CV to a client?

The candidate should know and agree that they are being represented for a role, but GDPR consent is not always the only lawful basis. The agency should document the lawful basis it relies on and keep a record of client submissions.

How long should recruitment agencies keep candidate records?

UK GDPR does not set one fixed period. Agencies should choose and document a defensible retention period for active candidates, placed candidates, speculative candidates, and compliance records.

Are right-to-work documents personal data?

Yes. They can include identity, nationality, and immigration-related information, so access and retention should be controlled carefully.

Can consultants write informal notes about candidates?

Consultant notes can be personal data and may be disclosed in a subject access request. Notes should be relevant, fair, factual where possible, and not excessive.

Do recruitment agencies need a Record of Processing Activities?

Many recruitment agencies should keep one because they process candidate and client data regularly and often at meaningful scale. It is also a practical way to map systems, purposes, lawful bases, and retention.

What if a CV is emailed to the wrong client?

That is a personal data breach in principle. The agency should assess the risk, record the incident, take steps to contain it, and decide whether it must be reported to the ICO.

Does the client company become a controller?

Often, yes. Once a client receives candidate data for its own hiring decision, it will usually have its own controller responsibilities. The agency still needs to handle the original sharing properly.

Is GDPRQuick a replacement for legal advice?

No. GDPRQuick helps you create and maintain practical documentation. It does not certify compliance, and your organisation remains responsible for its own policies, processes, security measures, and legal decisions.