Search
laptop

GDPR: What Employers and Recruitment Agencies Need to Know

GDPR changed how organisations collect, store, use and share personal data, with major implications for employers, HR teams and recruitment agencies handling candidate and employee information.

Key insight: Recruitment data should only be collected and retained where there is a clear lawful basis, a genuine business need and a defined retention period. Holding CVs, ID documents or application records indefinitely can create unnecessary compliance risk.
25 May 2018

The date GDPR came into force, reshaping data protection standards across recruitment and employment.

£17.5m

The higher maximum UK fine for the most serious infringements.

4%

The alternative higher maximum based on worldwide annual turnover, where applicable.

What is GDPR and why does it matter?

The General Data Protection Regulation introduced stricter rules around how organisations handle personal data. In the UK, data protection obligations are now framed through UK GDPR and the Data Protection Act 2018.

For employers and recruitment agencies, this matters because recruitment activity often involves large volumes of personal information, including CVs, interview notes, right-to-work information, references, contact details and sometimes sensitive information such as health, diversity or criminal conviction data.

The central principle is simple: organisations should not collect or keep personal data just because it might be useful one day. They need a clear reason for holding it, a lawful basis for processing it, and appropriate controls around how long it is retained and who it is shared with.

Why GDPR is especially important in recruitment

Recruitment businesses and employers often receive information from a wide range of sources, including job boards, direct applications, referrals, professional networking sites and previous candidate databases. That can make data protection more complex, particularly where candidate records are kept for future vacancies.

Candidate data must have a lawful basis

Employers and recruiters should be clear about why they are collecting candidate information and whether they are relying on consent, legitimate interests, contractual steps, legal obligations or another lawful basis.

Retention should be limited

CVs, application notes and identification documents should not be kept indefinitely unless there is a justified reason and the individual has been clearly informed.

Sharing must be controlled

Candidate information should not be passed to clients, group companies or third parties without a proper basis and clear expectations around how that information will be used.

Security must match the risk

Recruitment records often contain identifying and sensitive details, so access controls, deletion rules and breach response processes should be strong enough to protect candidates and employees.

A practical recruitment example

If a candidate sends a CV to an employer for a Store Manager role, they would reasonably expect their information to be used for that recruitment process. They would not necessarily expect the employer to keep the CV indefinitely or share it with another company for a different role unless this has been made clear and there is a lawful basis for doing so.

If the same organisation contacts the candidate a year later using that original CV, it should be able to show why the data was retained, what privacy information was provided, and what lawful basis applies to that further contact.

Key GDPR requirements for employers and agencies

Appoint clear data protection responsibility

Larger organisations may need a formal Data Protection Officer, while smaller agencies should still identify a senior person responsible for data protection governance, policies and breach handling.

Audit the data currently held

Review existing candidate and employee records. Ask whether each category of data is still needed, whether individuals were properly informed, and whether the retention period can be justified.

Be careful with sensitive or identifying information

Details such as National Insurance numbers, dates of birth, passport information, health details or criminal conviction data should only be collected where necessary and retained for no longer than required.

Review automated decision-making

Recruitment processes should not rely on fully automated decisions that significantly affect candidates unless the organisation has a lawful reason and appropriate safeguards. Human involvement should be meaningful, not just a rubber stamp.

Manage breaches carefully

If data is lost, hacked, misdirected or accidentally disclosed, the organisation should be able to show that the data was necessary, security measures were appropriate and retention periods were reasonable.

Can individuals claim compensation?

Individuals may be able to claim compensation where misuse of their personal data causes damage or distress. This does not mean every technical breach will automatically result in compensation, but employers and recruiters should still avoid collecting or retaining unnecessary personal information.

The best protection is to keep data handling proportionate, transparent and documented. If information is no longer needed, it should be securely deleted rather than stored indefinitely.

Important note for recruitment agencies

When an agency sends a CV to a client, both sides should understand how long that information may be kept and what it may be used for. Clients should not retain candidate CVs indefinitely simply because they have received them during a recruitment process.

Agencies should make sure their terms of business, privacy notices and client processes are aligned so candidate data is handled consistently and securely.

Practical GDPR checklist for employers and recruiters

  • Take data protection seriously: GDPR compliance should be part of day-to-day recruitment and HR practice.
  • Confirm responsibility: Appoint a Data Protection Officer where required, or assign clear internal responsibility for data protection.
  • Audit existing records: Review candidate, client and employee data already held across systems, inboxes and shared folders.
  • Delete what is unnecessary: Remove data that is outdated, excessive or no longer justified.
  • Document your lawful basis: Make sure there is a clear reason for collecting, using and retaining each type of personal data.
  • Limit retention periods: Set realistic deletion rules for CVs, ID documents, interview notes and sensitive information.
  • Update recruitment terms: Make sure clients understand how candidate information should be stored, used and deleted.
  • Control access: Keep recruitment records secure and limit access to those who genuinely need it.

Looking Ahead to Your Next Opportunity?

Understanding data protection is part of building a more professional, transparent recruitment experience. If you are ready to explore your next move in retail, start with the latest opportunities on The Retail Appointment.

Browse Retail Jobs

GDPR: What Employers and Recruitment Agencies Need to Know

The General Data Protection Regulation (GDPR) came into force on 25 May 2018 and introduced strict rules on how organisations collect, store, use, and share personal data. The consequences for non‑compliance are severe, including fines of up to €20 million or 4% of global turnover. Employers and recruitment agencies must review the data they hold, ensure they have lawful grounds to keep it, and adopt robust data‑protection practices.

What Is GDPR and Why Was It Introduced?

GDPR is an EU‑wide regulation designed to standardise data‑protection rules across Europe and bring the EU in line with countries such as Canada and Australia. It applies directly in the UK and is expected to remain in force even after Brexit.

The regulation was introduced in response to a series of high‑profile data breaches — including the TalkTalk/Carphone Warehouse incident, where customer data was retained for decades without clear consent. GDPR aims to prevent unnecessary data retention and reduce the impact of breaches by ensuring organisations only keep data they genuinely need.

Why GDPR Matters

Although case law is still developing, organisations cannot afford to ignore GDPR. The penalties for non‑compliance are significant:

  • Up to €20 million
  • Or 4% of global annual turnover
    (Whichever is higher)

For employers, HR teams and recruitment agencies, GDPR has major implications for how candidate and employee data is handled.

GDPR and the Recruitment Industry

Recruitment agencies and employers routinely hold large volumes of personal data — CVs, interview notes, ID documents, and more. Under GDPR:

  • Data can only be retained with consent or another lawful basis
  • Consent must be specific, informed, and time‑limited
  • Data must not be kept longer than necessary
  • Data must not be shared without permission, even within the same corporate group

Example
If a candidate sends their CV to ABC plc for a Store Manager role, they have consented to ABC holding their data for the duration of the recruitment process. They have not consented to ABC keeping it indefinitely or passing it to another company.

If ABC contacts the candidate a year later using the same CV, this may breach GDPR unless the candidate explicitly agreed to long‑term retention.

Key GDPR Requirements for Employers and Agencies

1. Appoint a Data Protection Officer (DPO)

Large organisations often already have one, but HR teams may need their own dedicated officer. Smaller agencies may appoint a senior director or IT specialist.

2. Review All Data Currently Held

Ask two questions:

  • Do we need this data? If not, delete it.
  • Would the individual reasonably believe they consented to us holding it? If not, obtain consent or delete it.

3. Be Cautious With Sensitive or Identifying Information

Data such as:

  • National Insurance numbers
  • Dates of birth
  • Passport details

…should only be kept when absolutely necessary and should be deleted automatically after a reasonable period.

4. Avoid Automated Decision‑Making

GDPR restricts automated decisions that significantly affect individuals.

This means:

  • No automatic rejection based on “killer questions”
  • No pre‑ticked marketing boxes
  • No fully automated selection processes

Some automated decisions are allowed (e.g., fraud prevention), but recruitment decisions must involve human intervention.

5. Manage Data Breaches Carefully

If data is leaked, hacked, or accidentally disclosed, the organisation must show:

  • The data held was reasonable and necessary
  • Appropriate security measures were in place
  • Retention periods were justified

Recruitment agencies must be especially careful. If a CV is sent to a client, the client should only retain it while the application is under consideration, but no longer.

Agencies should update their terms and conditions to reflect this.

Can Individuals Claim Compensation?

Individuals can only claim damages if they can show actual loss, such as identity theft or financial harm. This makes claims less common, but employers and agencies should still avoid retaining unnecessary identifying information.

Practical Advice for Employers and Agencies

  • Take GDPR seriously, the fines are substantial.
  • Appoint a Data Protection Officer as soon as possible.
  • Audit all data you currently hold.
  • Delete anything unnecessary or anything you cannot justify.
  • Obtain consent where needed and keep records of it.
  • Limit retention periods for sensitive data.
  • Update recruitment terms to prevent clients from retaining CVs indefinitely.