Recruitment data should only be collected and retained where there is a clear lawful basis, a genuine business need and a defined retention period. Holding CVs, ID documents or application records indefinitely can create unnecessary compliance risk.
- 25 May 2018The date GDPR came into force, reshaping data protection standards across recruitment and employment.
- £17.5mThe higher maximum UK fine for the most serious infringements.
- 4%The alternative higher maximum based on worldwide annual turnover, where applicable.
What is GDPR and why does it matter?
The General Data Protection Regulation introduced stricter rules around how organisations handle personal data. In the UK, data protection obligations are now framed through UK GDPR and the Data Protection Act 2018.
For employers and recruitment agencies, this matters because recruitment activity often involves large volumes of personal information, including CVs, interview notes, right-to-work information, references, contact details and sometimes sensitive information such as health, diversity or criminal conviction data.
The central principle is simple: organisations should not collect or keep personal data just because it might be useful one day. They need a clear reason for holding it, a lawful basis for processing it, and appropriate controls around how long it is retained and who it is shared with.
Why GDPR is especially important in recruitment
Recruitment businesses and employers often receive information from a wide range of sources, including job boards, direct applications, referrals, professional networking sites and previous candidate databases. That can make data protection more complex, particularly where candidate records are kept for future vacancies.
- Candidate data must have a lawful basisEmployers and recruiters should be clear about why they are collecting candidate information and whether they are relying on consent, legitimate interests, contractual steps, legal obligations or another lawful basis.
- Retention should be limitedCVs, application notes and identification documents should not be kept indefinitely unless there is a justified reason and the individual has been clearly informed.
- Sharing must be controlledCandidate information should not be passed to clients, group companies or third parties without a proper basis and clear expectations around how that information will be used.
- Security must match the riskRecruitment records often contain identifying and sensitive details, so access controls, deletion rules and breach response processes should be strong enough to protect candidates and employees.
A practical recruitment example
If a candidate sends a CV to an employer for a Store Manager role, they would reasonably expect their information to be used for that recruitment process. They would not necessarily expect the employer to keep the CV indefinitely or share it with another company for a different role unless this has been made clear and there is a lawful basis for doing so.
If the same organisation contacts the candidate a year later using that original CV, it should be able to show why the data was retained, what privacy information was provided, and what lawful basis applies to that further contact.
Key GDPR requirements for employers and agencies
- Appoint clear data protection responsibilityLarger organisations may need a formal Data Protection Officer, while smaller agencies should still identify a senior person responsible for data protection governance, policies and breach handling.
- Audit the data currently heldReview existing candidate and employee records. Ask whether each category of data is still needed, whether individuals were properly informed, and whether the retention period can be justified.
- Be careful with sensitive or identifying informationDetails such as National Insurance numbers, dates of birth, passport information, health details or criminal conviction data should only be collected where necessary and retained for no longer than required.
- Review automated decision-makingRecruitment processes should not rely on fully automated decisions that significantly affect candidates unless the organisation has a lawful reason and appropriate safeguards. Human involvement should be meaningful, not just a rubber stamp.
- Manage breaches carefullyIf data is lost, hacked, misdirected or accidentally disclosed, the organisation should be able to show that the data was necessary, security measures were appropriate and retention periods were reasonable.
Can individuals claim compensation?
Individuals may be able to claim compensation where misuse of their personal data causes damage or distress. This does not mean every technical breach will automatically result in compensation, but employers and recruiters should still avoid collecting or retaining unnecessary personal information.
The best protection is to keep data handling proportionate, transparent and documented. If information is no longer needed, it should be securely deleted rather than stored indefinitely.
Important note for recruitment agencies
When an agency sends a CV to a client, both sides should understand how long that information may be kept and what it may be used for. Clients should not retain candidate CVs indefinitely simply because they have received them during a recruitment process.
Agencies should make sure their terms of business, privacy notices and client processes are aligned so candidate data is handled consistently and securely.
Practical GDPR checklist for employers and recruiters
- Take data protection seriously: GDPR compliance should be part of day-to-day recruitment and HR practice.
- Confirm responsibility: Appoint a Data Protection Officer where required, or assign clear internal responsibility for data protection.
- Audit existing records: Review candidate, client and employee data already held across systems, inboxes and shared folders.
- Delete what is unnecessary: Remove data that is outdated, excessive or no longer justified.
- Document your lawful basis: Make sure there is a clear reason for collecting, using and retaining each type of personal data.
- Limit retention periods: Set realistic deletion rules for CVs, ID documents, interview notes and sensitive information.
- Update recruitment terms: Make sure clients understand how candidate information should be stored, used and deleted.
- Control access: Keep recruitment records secure and limit access to those who genuinely need it.



