Privacy Notices for UK Recruitment Agencies

Alex Solo
byAlex Solo12 min read

If you run a recruitment agency, your privacy notice is not a box-ticking document you can copy from a generic website template and forget. Agencies collect large amounts of personal data at speed, often from candidates, clients, referees and internal staff, and that creates real legal risk. Common mistakes include using one vague notice for every type of data processing, failing to explain how CVs are shared with employers, and keeping candidate records for too long without a clear retention position.

A good privacy notice helps you meet UK GDPR transparency rules and reduces friction when clients, candidates or regulators ask questions. It also forces you to get clear on what data you collect, why you collect it, who you share it with and how long you keep it. For recruitment businesses, that matters before you sign client terms, before you launch a candidate portal and before you spend money on systems that process personal data in the background.

This guide explains what a privacy notice for recruitment agencies in the UK should cover, when the issue usually comes up, and the practical steps that stop agencies from publishing a notice that looks fine but does not match how the business actually operates.

Overview

A privacy notice for a UK recruitment agency is the document that tells people how your business collects, uses, stores and shares their personal data. Under the UK GDPR and the Data Protection Act 2018, agencies usually need to give this information to candidates, client contacts, referees, contractors and employees in a clear and accessible way.

The right notice depends on how your agency works, including whether you place permanent staff, temporary workers, contractors or executive hires, and whether you carry out screening or profiling.

  • Identify every audience whose data you collect, not just candidates.
  • Explain the different purposes for processing, including matching candidates to roles, verifying information and managing placements.
  • State the lawful bases you rely on for each main type of processing.
  • Describe who receives the data, such as client employers, payroll providers, IT platforms and background screening services.
  • Set realistic retention periods for CVs, interview notes, right to work records and placement files.
  • Explain data subject rights, including access, rectification, erasure and objections.
  • Cover any overseas transfers and the safeguards used if software or service providers host data outside the UK.
  • Make sure the notice matches your internal processes, contracts and actual systems.

What Privacy Notice Recruitment Agencies Means For UK Businesses

For UK recruitment agencies, a privacy notice is a legal transparency statement, but it is also a practical operating document. If your notice does not reflect your real workflows, the main risk is not just regulator scrutiny. You also create problems in client onboarding, candidate trust, subject access requests and complaints handling.

Recruitment agencies sit in a high-data environment. You are often collecting names, contact details, CVs, salary expectations, work history, references, interview feedback, visa or right to work information, and sometimes special category data such as health or diversity information. That means your notice needs more detail than the average small business privacy notice.

Why recruitment agencies need a tailored notice

A generic business privacy notice usually focuses on website visitors and customer enquiries. A recruitment agency processes data in several different relationships at once. You may be acting as an introducer between candidates and employers, managing temporary workers, storing client hiring preferences, screening applicants and using third-party software to rank or manage talent pools.

That creates different transparency obligations for different people. A candidate should be told how their CV will be used, whether it will be shared with named or unnamed clients, how long their profile stays in your database and whether they may be contacted about future roles. A client contact should be told how you use their business details, communications and feedback. Referees and contractors also need relevant information when their data is collected.

What the law expects in plain English

The legal standard is that people should understand what happens to their data. In practice, your notice should clearly answer these questions:

  • Who is collecting the data?
  • What categories of personal data are collected?
  • Why is the data used?
  • What lawful basis applies?
  • Who is the data shared with?
  • Will data go outside the UK?
  • How long is the data kept?
  • What rights does the individual have?
  • How can they complain or contact you?

If you collect personal data indirectly, such as receiving candidate information from another recruiter, referrals platform or public source, you may need to explain that as well. This is where agencies often get caught. They assume the original source covered the legal notice position, but your own agency may still have separate transparency obligations.

Special category and criminal records data

Recruitment work can involve more sensitive information than founders first realise. Health information, disability adjustments, ethnicity monitoring and criminal records checks all sit in a higher-risk category. If your business processes this kind of data, your privacy notice should say so in a clear way and explain the reason for processing.

You may also need separate internal documentation and policy support for this processing, especially where criminal records or special category data are involved. The privacy notice alone is not enough. It should line up with your screening process, onboarding steps and any contracts you use with clients or service providers.

Why this matters beyond compliance

Agencies often focus on speed. A recruiter wants to send a CV quickly, fill the role and move on. But privacy issues surface at exactly the wrong moments, such as when a candidate says they never agreed to be put forward, a client asks for data handling assurances before signing a supplier agreement, or someone requests deletion while a live placement process is still under way.

A well-drafted notice helps you answer those issues consistently. It also supports other core legal documents, including:

  • client terms that explain how candidate data may be used and protected
  • website terms and platform terms if you collect applications online
  • contracts with software providers and screening providers
  • internal privacy and retention procedures for staff

When This Issue Comes Up

The privacy notice question usually appears when the agency is changing how it collects or shares data, not when the agency first incorporates. That is why founders often leave it too late. The right time to review it is before you launch a new service, before you sign a major client contract and before you adopt a new recruitment tech platform.

When you launch your agency

If you are about to start a recruitment business in the UK, privacy should be part of your company setup, alongside business structure, registration, contracts, trade mark planning and brand rollout. Agencies commonly set up a company, buy a domain, publish a website and start collecting CVs through a contact form without putting a candidate-facing privacy notice in place.

That first website launch is often the first data collection point. Even if your operation is small, once you are receiving CVs, client contact details or job alerts sign-ups, you need a clear notice.

When you start using recruitment software

Applicant tracking systems, CRM tools, CV parsing software, video interview platforms and skills testing tools all affect what your business does with personal data. If a new system changes the categories of data collected, automates decisions, stores data abroad or gives a third party access, your notice may need updating.

This is also the point where your supplier contracts and data processing arrangements matter. Your privacy notice should match what your software stack actually does. If the system keeps deleted profiles in backups for a period, or uses overseas infrastructure, your notice and internal process need to reflect that reality.

When clients ask for due diligence information

Larger employers often ask recruiters about privacy compliance before they sign preferred supplier agreements or recruitment terms. They may want to know what candidate information you collect, how you screen workers, whether your systems are secure and what data sharing arrangements are in place.

If your notice is outdated or generic, that is often the first red flag. It suggests your agency has not fully mapped its data handling position.

When you expand into temporary staffing or contractor placements

Permanent recruitment and temporary staffing do not create the same privacy profile. Temp and contractor models often involve more ongoing administration, such as timesheets, payroll data, bank details, right to work checks and availability records. Your privacy notice should evolve with that shift.

The same applies if you move into sectors with higher screening expectations, such as healthcare, education or financial services. Extra checks may mean new categories of personal data and more complicated retention rules.

When a candidate complains or makes a data request

A subject access request, deletion request or complaint about being submitted for a role without consent often exposes weaknesses in the notice. If the business cannot point to a clear explanation of how candidate data is used, the issue becomes harder to manage.

That is why privacy notices should not only be drafted for launch day. They should be reviewed when complaints, access requests or internal confusion show that your public wording no longer matches daily practice.

Practical Steps And Common Mistakes

The most useful way to build a privacy notice for a recruitment agency is to map your real data flows first, then draft the notice from that map. Agencies get into trouble when they start with a borrowed template and force their business into it.

Map your data by audience

Separate your data handling by the people involved. Most agencies should consider at least these groups:

  • job candidates and applicants
  • temporary workers and contractors
  • client contacts and hiring managers
  • referees
  • website users and newsletter subscribers
  • employees and internal staff

Each group may need different wording, or at least a distinct section within the same notice. A candidate-focused explanation often does not make sense for a client contact whose details are kept in your CRM.

List what you actually collect

Be specific. Recruiters often understate the range of data they hold. Your notice may need to cover:

  • name, address, phone number and email
  • CV and employment history
  • education and qualifications
  • salary expectations and compensation records
  • interview notes and assessments
  • identity, right to work and visa information
  • references and referee details
  • availability, timesheets and placement history
  • bank details where relevant for payment
  • equal opportunities or diversity monitoring data
  • health information needed for workplace adjustments
  • criminal records or vetting information where lawfully processed

If you use recorded calls, video interviews or behavioural assessment tools, say so. If you collect data through social media sourcing or public profile searches, explain that in a transparent and sensible way.

Explain your reasons for using the data

Do not rely on broad statements such as "to provide our services". Recruitment privacy notices should connect the purpose to a real business activity. That may include:

  • sourcing and matching candidates to suitable roles
  • sharing candidate profiles with client employers
  • arranging interviews and taking feedback
  • checking qualifications, references and work eligibility
  • administering placements, payroll or contractor engagement
  • maintaining a talent pool for future vacancies
  • meeting legal or regulatory obligations
  • handling complaints, disputes and records management
  • improving systems, analytics and service performance

Where you keep candidate details for future opportunities, be careful with the wording. You should not suggest indefinite retention or imply consent is the only basis if your actual process relies on other legal grounds in some cases.

Choose lawful bases carefully

This is one of the most common drafting mistakes. Agencies often write that all processing is based on consent because it sounds safer. That can backfire if your actual processing depends on other lawful bases, such as legitimate interests, legal obligations or steps taken before entering a contract.

Your notice should explain the lawful basis in plain language and apply it to the processing activity. Different parts of your service may rely on different grounds. The answer is rarely one-size-fits-all.

If you rely on legitimate interests, you should be able to explain what those interests are and why they are not overridden by the individual's rights. If you rely on legal obligations for right to work checks or employment records, the notice should say that clearly.

Set realistic retention periods

Saying that data is kept "for as long as necessary" is usually too vague on its own. Candidates and clients want a clearer idea of what that means in practice. Your retention wording should reflect your systems, legal obligations and recruitment cycle.

For example, interview records, unsuccessful candidate files, timesheets and payroll-related records may all have different retention periods. If you cannot state a fixed number for every category, explain the criteria you use to decide retention, such as legal obligations, active client relationships, dispute risk and whether the profile is still relevant for current opportunities.

Be honest about sharing and overseas transfers

Recruitment agencies almost always share personal data with others. Typical recipients include client employers, software providers, payroll providers, IT support, screening companies and professional advisers. Your notice should identify these categories of recipient in a usable way.

Overseas transfers are also easy to miss. Many recruitment platforms and cloud systems use international hosting or support teams. If data is transferred outside the UK, explain the safeguards your business relies on, rather than ignoring the issue.

Match the notice to your contracts and workflow

Your privacy notice should not sit alone. It needs to align with your client contracts, contractor terms, internal privacy procedures and data processing arrangements with service providers. If your client terms promise one thing and your privacy notice says another, the inconsistency creates risk.

This is especially relevant before you sign a preferred supplier agreement or a master services arrangement with a larger employer. Those agreements often include privacy promises about candidate data, security standards and permitted use. Your notice should support those promises rather than contradict them.

Common mistakes agencies make

  • copying a general website privacy policy that barely mentions recruitment activity
  • using one notice for candidates, clients and staff without adapting the wording
  • failing to mention references, vetting, right to work checks or special category data
  • stating consent as the sole lawful basis when that is not accurate
  • omitting talent pool retention practices and future role contact
  • forgetting to mention technology providers and overseas processing
  • publishing a notice that does not match the CRM, ATS or screening process actually used
  • never reviewing the notice after expanding into new sectors or placement models

A privacy notice works best when someone in the business can follow it in real life. If your recruiters cannot explain the process consistently, your drafting probably needs attention.

FAQs

Do recruitment agencies in the UK need a privacy notice?

In most cases, yes. If your agency collects personal data from candidates, clients, referees, contractors or staff, UK data protection law will usually require you to give clear privacy information.

Can we use one privacy notice for both candidates and clients?

Sometimes, but it must still be clear and relevant to each audience. Many agencies use one notice with separate sections for candidates, client contacts, website users and staff, while others use separate notices where processing is more complex.

You should have a clear legal basis and a transparent process before sharing candidate data. In many recruitment models, agencies obtain express confirmation from the candidate before submission, because it is commercially sensible and helps reduce disputes, even where consent is not the only privacy law concept in play.

What if we keep CVs on file for future roles?

Your privacy notice should explain that practice, the lawful basis you rely on and how long candidate data is normally retained. The retention period should be realistic and linked to your recruitment activity, not left open-ended without explanation.

Does a website privacy policy cover our full recruitment process?

Usually not. A website privacy policy may cover cookies, contact forms and site enquiries, but recruitment agencies often need broader transparency wording for candidate sourcing, screening, client submissions, placements and ongoing administration.

Key Takeaways

  • A privacy notice for recruitment agencies in the UK should be tailored to how your agency actually collects, uses and shares personal data.
  • Generic website templates often miss core recruitment issues, such as CV submissions, references, vetting, talent pools and client sharing.
  • Your notice should identify different data subjects, explain lawful bases, describe recipients, address retention and cover data rights clearly.
  • Special category data, criminal records information, overseas transfers and recruitment software all need extra attention.
  • The notice should line up with your contracts, supplier arrangements, internal processes and the systems your team uses every day.
  • A review is sensible before you sign client agreements, launch new services, adopt new recruitment technology or expand into temporary staffing.

If your business is dealing with privacy notice recruitment agencies and wants help with privacy notices, recruitment contracts, data processing arrangements, and retention practices, you can reach us on 08081347754 or team@sprintlaw.co.uk for a free, no-obligations chat.

Get your customer-facing terms right

What should your privacy and online terms cover?

If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get your customer-facing terms right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Keep reading

Related Articles

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.