Not the general guide. The specific ones: how long you can keep a CV and from when, whether you are relying on consent or legitimate interest and which is right, what your ATS covers and what it quietly does not, whether you need to register with the ICO, what a candidate DSAR obliges you to hand over, and what to send when a client's procurement team asks for your data protection documents.
A client's procurement team asks the same things of every agency on the PSL: your record of processing, your ATS named as a sub-processor along with the job boards and the CV parser, how long you keep a CV and from when, whether candidate data leaves the UK and under what mechanism, and how you handle a candidate DSAR. Those are the data protection rows; most of the sheet is security (access control, encryption, backups, incident response, staff training, whether you hold Cyber Essentials), and every row has to be answered from something you actually do rather than from what the ATS vendor publishes about itself. Paste or upload the one they sent and see every row classified, free, no account, before you start writing.
Almost every GDPR guide assumes the person whose data you hold is your customer. In recruitment they are not. Your customer is the hiring company; the data subject is the candidate, who often did not choose to be on your system, and whose interests you are weighing against your own commercial ones every time you keep a record.
That single fact produces most of the difficulty. Your lawful basis is usually legitimate interest, which is the only basis a person can object to outright. Retention is bounded by purpose rather than by storage, and the purpose ends when the search does. Interview notes are disclosable. Diversity data is special category. Your ATS holds the bulk of it and enforces almost none of it. And every client onboarding asks you to prove all of the above in writing.
None of that is unmanageable. It just is not what the generic checklist covers.
| What you hold | How long, and from when | What sets the period |
|---|---|---|
| CV of a candidate you placed | Life of the placement plus the limitation period on the contract, commonly six years from the end of the engagement. | Contract and limitation, not storage cost |
| CV of a candidate you did not place | Typically 6 to 12 months from last meaningful contact, then delete or re-consent. Pick a period, write it down, and apply it. | Purpose: the purpose ends when the search does |
| Speculative CV, never worked with | Shortest of all. If you have not spoken in a year, the legitimate interest has expired with the relationship. | Purpose, and the objection risk |
| Interview notes and scorecards | Same clock as the CV they attach to. They are personal data, they are disclosable in a DSAR, and they are the ones that embarrass people. | Same purpose as the application |
| Right to work documents | Two years after employment ends for the employer; as an agency, only as long as your client contract requires you to hold them. | Home Office guidance, then contract |
| Diversity monitoring data | Aggregate and delete the individual records as soon as the report is produced. This is special category data and the shortest period you can defend. | Article 9: a higher bar |
| Placement and payroll records | Six years plus current year for tax, held for a different purpose than recruitment and often by a different system. | HMRC, not GDPR |
| Candidate marketing list | Until they object, and they can object at any time. Objection has to actually remove them, not flag them. | PECR and Article 21 |
| The period your ATS actually enforces | Whatever it is set to, which is often forever. This is the row that makes the others theoretical. | Only you can answer this: check the setting |
There is no statutory retention period for a CV. These are the periods agencies defend in practice, each tied to the thing that actually sets it. Write yours down, put them in the privacy notice, and set them in the ATS. Doing the first two without the third is the most common gap.
Everything above is work you can do yourself, and this page is the guide to doing it. If you would rather not: Rowpa reads your website, drafts the record across candidate, client and supplier flows, holds the recruitment stack in a vendor library with source links and review signals, writes the privacy notice with the balancing test in it, publishes the DSR and complaints routes, and turns the lot into the pack a client's procurement team asks for. Free to build and read the whole record. £39 once per supplier pack, or Starter £34/mo for three a month. Business £79/mo adds unlimited packs, the scanner, DPIA and breach planner, which is where most agencies with a PSL land. All prices ex VAT.
Build your whole record free, no card. Pay only when you send something.
Start free