For UK recruitment agencies

GDPR for a recruitment agency: the questions that actually come up.

Not the general guide. The specific ones: how long you can keep a CV and from when, whether you are relying on consent or legitimate interest and which is right, what your ATS covers and what it quietly does not, whether you need to register with the ICO, what a candidate DSAR obliges you to hand over, and what to send when a client's procurement team asks for your data protection documents.

A client has sent you a security questionnaire

A client's procurement team asks the same things of every agency on the PSL: your record of processing, your ATS named as a sub-processor along with the job boards and the CV parser, how long you keep a CV and from when, whether candidate data leaves the UK and under what mechanism, and how you handle a candidate DSAR. Those are the data protection rows; most of the sheet is security (access control, encryption, backups, incident response, staff training, whether you hold Cyber Essentials), and every row has to be answered from something you actually do rather than from what the ATS vendor publishes about itself. Paste or upload the one they sent and see every row classified, free, no account, before you start writing.

Why recruitment is harder than most GDPR advice assumes

Almost every GDPR guide assumes the person whose data you hold is your customer. In recruitment they are not. Your customer is the hiring company; the data subject is the candidate, who often did not choose to be on your system, and whose interests you are weighing against your own commercial ones every time you keep a record.

That single fact produces most of the difficulty. Your lawful basis is usually legitimate interest, which is the only basis a person can object to outright. Retention is bounded by purpose rather than by storage, and the purpose ends when the search does. Interview notes are disclosable. Diversity data is special category. Your ATS holds the bulk of it and enforces almost none of it. And every client onboarding asks you to prove all of the above in writing.

None of that is unmanageable. It just is not what the generic checklist covers.

The answers, in the order they come up

01
How long can we keep a CV?
There is no statutory period, which is why everyone asks. The period is set by the purpose you are holding it for, and it ends when that purpose does. Most agencies land on 6 to 12 months from last meaningful contact for a candidate they did not place, and the contractual limitation period for one they did. The table below sets out the common ones. What matters is that you pick, write it down, and enforce it, because an unenforced policy is worse than an honest short one.
02
Consent or legitimate interest?
For holding and processing a CV to find someone work, legitimate interest, almost always. Consent is a poor fit: it must be freely given and withdrawable at any moment, and a candidate does not meaningfully consent to a database they were added to from a job board. But legitimate interest is not a free pass. It requires a balancing test you have actually done and can produce, and it gives the candidate an absolute right to object. Marketing to candidates is a separate question and often does need consent under PECR.
03
Do we need to register with the ICO?
Yes. Almost every UK recruitment agency processes personal data electronically for commercial purposes and must pay the data protection fee. It is banded by size and turnover, most agencies are in the lowest or middle tier, and the register is public, which means a client can check whether you are on it in about ten seconds. It is the cheapest credibility item on this page.
04
A candidate has asked for everything you hold. What do you hand over?
Everything that is their personal data, which is more than the CV: interview notes, scorecards, internal comments about them, emails that discuss them, the ATS audit trail. One month to respond. You may redact other people's personal data and genuinely confidential commercial information, but not to spare your own blushes. This is the request that teaches agencies what their consultants have been typing into the notes field.
05
Diversity monitoring data
Special category data under Article 9, so it needs its own condition, not just a lawful basis, and it should be separated from the candidate record, aggregated for the report, and deleted at the individual level as soon as the report exists. If it is sitting in a spreadsheet next to names, that is the highest-risk thing in the agency.
06
EU candidates and EU clients
If you place EU-based candidates or serve EU-based clients you are handling transfers in both directions, and both sides will ask. What matters is naming the mechanism per flow, standard contractual clauses with the UK addendum in most cases, and having it agree with what your sub-processor list says. The two disagreeing is what a reviewer catches.
07
References and background checks
A reference is personal data about the candidate and, usually, about the referee too. Background and credit checks bring in a processor you need an agreement with and a lawful basis that stands up. Both belong in the record as their own processing activities rather than being folded into the general recruitment entry.
08
When a client's procurement team asks you to prove it
PSL onboarding and framework tenders ask for the same set: your record, sub-processors including the ATS, transfers, retention, security measures, breach and complaints procedures, a named contact. Answering it from scratch takes a week. Answering it from a record you keep takes an hour, and it is the same record everything above lives in.

Candidate data, and how long you can keep it

What you holdHow long, and from whenWhat sets the period
CV of a candidate you placedLife of the placement plus the limitation period on the contract, commonly six years from the end of the engagement.Contract and limitation, not storage cost
CV of a candidate you did not placeTypically 6 to 12 months from last meaningful contact, then delete or re-consent. Pick a period, write it down, and apply it.Purpose: the purpose ends when the search does
Speculative CV, never worked withShortest of all. If you have not spoken in a year, the legitimate interest has expired with the relationship.Purpose, and the objection risk
Interview notes and scorecardsSame clock as the CV they attach to. They are personal data, they are disclosable in a DSAR, and they are the ones that embarrass people.Same purpose as the application
Right to work documentsTwo years after employment ends for the employer; as an agency, only as long as your client contract requires you to hold them.Home Office guidance, then contract
Diversity monitoring dataAggregate and delete the individual records as soon as the report is produced. This is special category data and the shortest period you can defend.Article 9: a higher bar
Placement and payroll recordsSix years plus current year for tax, held for a different purpose than recruitment and often by a different system.HMRC, not GDPR
Candidate marketing listUntil they object, and they can object at any time. Objection has to actually remove them, not flag them.PECR and Article 21
The period your ATS actually enforcesWhatever it is set to, which is often forever. This is the row that makes the others theoretical.Only you can answer this: check the setting

There is no statutory retention period for a CV. These are the periods agencies defend in practice, each tied to the thing that actually sets it. Write yours down, put them in the privacy notice, and set them in the ATS. Doing the first two without the third is the most common gap.

What your ATS covers, and what it does not

Bullhorn, Vincere, JobAdder, Jobylon, Greenhouse, Workable and the rest are processors acting on your instructions. They are not your compliance department, and the split is consistent across all of them.

What the ATS generally does: stores the candidate record and its audit trail; provides retention or purge settings, usually off or set to never by default; handles consent capture if you configured it; gives you an export for a DSAR; publishes its own security documentation and sub-processor list for you to reference.

What it does not do: your record of processing activities, which has to cover the whole agency and not just the ATS; your agreements with every other tool that touches candidate data, the job boards, the CV parser, the video interview tool, LinkedIn Recruiter, the email platform; your legitimate interest balancing test; your privacy notice; your DSAR workflow, as opposed to the export button; your complaints procedure; and the pack a client asks for.

The question worth asking today: open your ATS retention setting and look at it. In most agencies it has never been changed, which means the retention policy in the privacy notice and the behaviour of the system disagree. A candidate DSAR or a client audit is how that gets discovered.

"GDPR compliant ATS" is a category error, incidentally. An ATS can be a processor you can lawfully use. Compliance is a property of what your agency does, not of a piece of software you bought.

Where agencies actually get caught

  • The retention policy nobody enforces. A written period and an ATS that keeps everything forever. The policy makes it worse, not better, because it documents that you knew.
  • Consultant notes. Free-text fields containing opinions that read badly when handed to the candidate under a DSAR. Train for it once and it stops being a problem.
  • The job board and CV parser nobody documented. Every tool that touches a CV is a processor and needs an agreement. The stack is longer than agencies expect: usually a dozen or more.
  • Diversity data next to names. Special category data in the same sheet as the candidate list, kept long after the report was produced.
  • An objection treated as an unsubscribe. Legitimate interest gives an absolute right to object to processing, which is broader than opting out of marketing, and it has to actually stop the processing.

What to do this week, in order

  1. Check the ICO register, and pay the fee if you are not on it. Ten minutes.
  2. Open the ATS retention setting and see what it actually says. Ten minutes, and it usually produces a surprise.
  3. Write down your retention periods, per record type, from the table below. An hour.
  4. List every tool that touches candidate data and find the agreement for each. Half a day, and it is the input to everything else.
  5. Write the legitimate interest balancing test down. It is a page, and it is the thing you will be asked to produce.
  6. Put a DSAR and complaints route somewhere a candidate can find it. The complaints procedure has been mandatory for every UK organisation since 19 June 2026.
Do those and the next client onboarding form is an hour of work instead of a week.

Pricing

Everything above is work you can do yourself, and this page is the guide to doing it. If you would rather not: Rowpa reads your website, drafts the record across candidate, client and supplier flows, holds the recruitment stack in a vendor library with source links and review signals, writes the privacy notice with the balancing test in it, publishes the DSR and complaints routes, and turns the lot into the pack a client's procurement team asks for. Free to build and read the whole record. £39 once per supplier pack, or Starter £34/mo for three a month. Business £79/mo adds unlimited packs, the scanner, DPIA and breach planner, which is where most agencies with a PSL land. All prices ex VAT.

Start free See all plans

Common questions

How long can we keep candidate CVs?
There is no statutory period. It is set by the purpose: for a candidate you did not place, commonly 6 to 12 months from last meaningful contact; for one you did, the limitation period on the contract, usually six years from the end of the engagement. Pick a period you can defend, write it in the privacy notice, and set it in the ATS. The third step is the one that gets skipped.
Is a 'GDPR compliant applicant tracking system' a thing?
Not really. An ATS can be a processor you can lawfully use, with a proper agreement, sensible security and retention settings that work. Compliance is a property of what your agency does with it. A vendor claiming their product makes you compliant is selling you the settings page.
Do recruitment agencies need to register with the ICO?
Yes, in almost every case. You process personal data electronically for commercial purposes, so the data protection fee applies. The register is public and clients do check it.
Consent or legitimate interest for candidate data?
Legitimate interest for holding and processing a CV to find someone work, with a balancing test you have actually written down. Consent is a poor fit for a database candidates were added to rather than joined. Marketing to candidates is a separate question and often does need consent under PECR.
Are interview notes covered by a subject access request?
Yes. Notes, scorecards and internal comments about the candidate are their personal data and are disclosable. You may redact other people's personal data and genuinely confidential commercial information. You may not redact something because it is unflattering.
Do we need a DPIA for AI CV screening?
If you use AI or automated tools to screen, rank or score candidates, that is a standard DPIA trigger, and the assessment should be done before the feature goes on rather than after. Rowpa's Business plan includes a DPIA tool.
A candidate wants to be forgotten. Do we have to?
Where you rely on legitimate interest they have an absolute right to object, and unless you can show compelling grounds that override theirs, the processing stops. In practice that means deletion across the ATS, the job boards, the mailing list and anywhere a CV was copied. Deleting in one place and not the others is the common failure.
Can we hide candidate data when responding to a client compliance questionnaire?
You should not be sending candidate data at all. A client questionnaire asks how you handle personal data, not for examples of it. If a client asks for actual candidate records to audit, that needs a separate conversation and usually a different lawful basis.
Do you handle SCCs for EU candidates and EU clients?
The record captures each transfer with its mechanism, standard contractual clauses with the UK addendum in most cases, and the pack prints them so they agree with your sub-processor list. Rowpa records the position; the clauses themselves are contracts you sign.

Further reading

The next PSL form should take an hour.

Build your whole record free, no card. Pay only when you send something.

Start free