GDPR for recruitment agencies UK compliance is not limited to adding a privacy notice to a website. Recruitment businesses process large volumes of personal information every day, including CVs, interview notes, work histories, references and right-to-work information.
Whether details arrive through an application, LinkedIn, a job board or a referral, the agency needs a clear purpose, an appropriate lawful basis and a transparent process.
The UK GDPR and Data Protection Act 2018 apply alongside other relevant recruitment and employment obligations. For a broader explanation of the core rules, read our UK GDPR overview.
Why Recruitment Is a High-Volume Data Processing Activity
Recruitment agencies often operate searchable databases containing information about active applicants, previous candidates, contractors, temporary workers, referees and people identified through talent searches. The ICO recognises that recruitment supply chains can involve several organisations and increasingly large amounts of candidate information. CV may contain:
- A candidate’s name and contact details
- Employment and education history
- Professional qualifications
- Salary or availability information
- Referee details
- Location and travel preferences
- Information that reveals health, ethnicity, religion or another protected characteristic
Agencies are likely to be controllers in many circumstances because they decide why and how candidate data is used for their own recruitment services, talent pools or legal obligations. An agency may instead act as a processor when it handles information only under a client’s documented instructions, or as a joint controller where both organisations jointly decide the purposes and essential means of processing. The label depends on the real working arrangement, not simply what the commercial contract calls the parties. ume creates practical risks, from misdirected CVs and excessive notes to inactive records held indefinitely. Recruitment agency data protection therefore needs clear rules for collection, sharing, accuracy, retention and deletion.
Sourcing Candidate Data — What's Allowed?
Agencies can source candidates through applications, recruitment platforms, job boards, professional networking sites and referrals. Public availability does not remove UK GDPR responsibilities.
The ICO says recruiters may manually search appropriate public, recruitment-focused social media platforms where candidates are reasonably likely to expect professional information to be used for recruitment. Searching a person’s general social media profiles is more intrusive and may reveal irrelevant or special category information that the candidate would not expect to influence recruitment. rcing candidates:
- Use a recruitment-related source. A professional profile or job-board CV is generally more relevant than a personal social account.
- Collect only what is necessary. Avoid copying entire profiles when a name, role history and contact route are sufficient.
- Record where the information came from. This supports transparency and helps answer candidate questions.
- Provide privacy information promptly. Where data comes from another source, candidates should normally receive the required privacy information within a reasonable period and no later than one month.
- Check communication rules. Direct messages promoting vacancies may also engage the UK’s electronic marketing rules.
The right to be informed means candidates should know the agency’s identity, why their data is being used, how long it may be retained, who it may be shared with and what rights they have. s require similar care. Explain where the details came from and avoid building a detailed profile before the person shows interest.
Lawful Basis for Holding CVs and Candidate Profiles
Candidate consent is not the only lawful basis for processing CV data under GDPR—and it is often not the most appropriate one.
The ICO states that legitimate interests is likely to be relevant in many recruitment activities, including reviewing CVs, shortlisting candidates and verifying information. Before relying on it, an agency should assess:
- The legitimate recruitment purpose it is pursuing
- Whether using the information is necessary for that purpose
- Whether the candidate’s interests, rights or reasonable expectations override the agency’s interest
This is commonly documented through a legitimate interests assessment. Simply writing “legitimate interests” in a privacy notice is not enough; the agency must be able to show that its processing is targeted, proportionate and fair. may be suitable for a genuinely optional and clearly defined activity, but it must be specific, informed, freely given and easy to withdraw. The ICO cautions that consent is unlikely to be suitable for considering candidates across multiple or future roles because it may not be sufficiently specific and there may be a power imbalance. ses can apply in narrower circumstances. Contract may cover an agreed candidate service, while legal obligation may apply to checks or records required by law.
Where a CV contains special category data, such as health or ethnicity information, the agency needs both an Article 6 lawful basis and an additional Article 9 condition. Criminal offence information is subject to separate safeguards under the Data Protection Act 2018. ng Candidate Data With Clients
Sending a CV to a client is a disclosure of personal data. It should be treated as a controlled step, not an automatic part of adding someone to an agency database.
Before sharing an identifiable profile, the agency should make sure that:
- The candidate knows their information may be shared with prospective employers
- The client or vacancy has been explained at the appropriate stage
- The disclosure is covered by the agency’s lawful basis
- Only information relevant to the role is included
- Sensitive or unnecessary details have been removed
- The transfer method is secure
- The client understands its own data protection responsibilities
The ICO says a recruiter must explain how it uses and discloses candidate information. If the employer’s identity has not yet been provided to the candidate, the recruiter should send only anonymised information.
Once an application is being pursued, the candidate should be told the employer’s identity as soon as reasonably practicable and no later than when the employer first receives their personal information. cy-client relationship must be mapped correctly. An agency acting only on a client’s instructions may be a processor and require an Article 28-compliant contract. Where each party determines its own purpose, they may be separate controllers; if they decide the purposes and essential means together, they may be joint controllers. e agreement should therefore address:
- Each party’s data protection role
- Permitted uses of candidate information
- Security requirements
- Retention and deletion
- Responsibility for candidate rights requests
- Personal data breach reporting
- Restrictions on further sharing
Speculative CVs and Unsolicited Applications
An unsolicited CV is still personal data. An agency cannot ignore its responsibilities because it did not request the information.
The ICO recommends explaining whether speculative applications are accepted, covering them in the privacy notice and including them in the retention and disposal policy. If the agency has no intention of using the CV, it should delete it securely as soon as possible.
If it plans to consider the person for suitable roles, it needs a lawful basis, a defined purpose and a justified retention period. cal process is to:
- Acknowledge receipt
- Provide or link to the candidate privacy notice
- Explain whether the CV will be considered now or added to a talent pool
- Record the source and date received
- Set a review or deletion date
- Remove information that is unnecessary for recruitment
Do not treat the arrival of a speculative CV as blanket consent for every possible vacancy, marketing message or client introduction. Use it only in ways the person would reasonably expect and explain any materially different use before it begins.
How Long Can You Keep Candidate Data?
There is no universal UK GDPR retention period for CVs or unsuccessful applications. The storage limitation principle requires agencies to keep identifiable data only for as long as it is needed for a stated purpose and to be able to justify that period.
A retention schedule may distinguish between:
- Candidates being considered for an active vacancy
- Unsuccessful applicants retained for possible queries or claims
- Candidates who have asked to hear about relevant future roles
- Temporary workers and placed candidates
- Vetting or right-to-work records
- Speculative CVs
- Suppression records needed to respect objections
The ICO advises organisations to set and document clear retention periods, review records and erase or anonymise information that is no longer required. Recruitment agencies may also have record-keeping duties under sector-specific legislation, so the correct period should reflect both data protection principles and applicable legal obligations. every unsuccessful applicant indefinitely “just in case” is unlikely to be defensible. If data is kept for future vacancies, the agency should genuinely intend to use it, inform candidates of that purpose and explain the retention period or the criteria used to determine it. hygiene should be active. Automated review dates, duplicate detection and inactivity flags can identify records for updating or deletion, while candidate check-ins can confirm continued interest.
Do not describe every check-in as a “consent refresh”. Where the agency relies on legitimate interests, the purpose is to confirm relevance, accuracy and reasonable expectations—not to manufacture consent for processing that uses another lawful basis.
To strengthen these everyday practices, managers can use GDPR Essentials for UK Businesses as a practical foundation for consultants who source, store and share candidate information.
Candidate Rights and Subject Access Requests
Candidates have data protection rights whether they are successful, unsuccessful, passively sourced or held in a future-opportunities database.
They may ask an agency to:
- Confirm whether it holds their personal data
- Provide a copy through a subject access request
- Correct inaccurate or incomplete information
- Restrict certain processing
- Stop processing based on legitimate interests
- Erase information in qualifying circumstances
- Explain significant automated decision-making
A subject access request does not need to mention “UK GDPR” or use a particular form. It may be made verbally, by email or through another communication channel. Organisations usually have one month to respond, subject to the rules on identification, clarification, extensions and limited exceptions. t to erasure is not absolute. Limited information may sometimes be retained for a legal obligation or legal claims, but deletion will often be required when the data is no longer needed or a legitimate-interests objection succeeds. should train consultants to recognise rights requests immediately and escalate them rather than debating the request with the candidate. Search procedures must cover the CRM, email accounts, shared drives, interview notes and exported spreadsheets—not only the main candidate profile.
Structured Data Protection & GDPR Compliance training can help managers build consistent processes for access, erasure, objections and secure disclosure.
Training Recruitment Consultants on GDPR
Recruiters make rapid decisions while handling personal data throughout the day. A policy stored on an intranet is unlikely to prevent mistakes unless consultants understand how the rules apply during sourcing calls, CV submissions, client updates and database searches.
Effective GDPR training for recruitment teams should cover:
- Choosing and documenting a lawful basis
- Giving privacy information to sourced candidates
- Distinguishing consent from legitimate interests
- Handling special category and criminal offence data
- Sharing CVs only with appropriate clients
- Writing fair, relevant and professional database notes
- Recognising access, deletion and objection requests
- Applying retention and deletion rules
- Using approved systems and secure transfer methods
- Reporting misdirected emails and other personal data breaches promptly
Training should be role-specific. A consultant needs scenario-based guidance on candidate searches and client submissions, while managers need deeper knowledge of controller relationships, retention schedules, contracts, complaints and oversight.
Short refreshers, case studies, quality checks and system prompts help turn legal principles into repeatable habits without making consultants hesitant.
FAQs
Do recruitment agencies need candidate consent to hold CVs?
Not always. Legitimate interests is often more appropriate for ordinary recruitment activity, provided the agency completes the necessary assessment, acts transparently and respects candidate rights. Consent should be used only where it is genuinely optional, specific and freely given.
How long can a recruitment agency keep candidate data?
There is no single statutory retention period for every CV. The agency must define and justify periods based on its recruitment purpose, legal obligations and potential claims, then delete or anonymise information when it is no longer needed.
Can agencies share CVs with clients without permission?
Specific consent is not automatically required, but the sharing must have a lawful basis, be fair and transparent, and match the candidate’s reasonable expectations. The candidate should know the client’s identity before an identifiable CV is shared; otherwise, anonymised information should be used.
What should I do with speculative or unsolicited CVs?
Acknowledge the CV, provide privacy information and decide whether there is a genuine recruitment purpose for retaining it. If there is no intention to use it, delete it securely; if it enters a talent pool, apply a lawful basis, review date and clear retention rule.
Can a candidate ask a recruitment agency to delete their data?
Yes. Candidates can request erasure verbally or in writing, although the right is not absolute and the agency may retain limited data where a continuing legal justification applies.
Recruit compliantly and give consultants the confidence to handle candidate information correctly. Equip your team with practical GDPR knowledge by exploring our GDPR Essentials for UK Businesses course.