GDPR Policy Generator for recruitment
Written for candidate data sourced without consent, CV databases, automated screening and the Article 14 notice nobody sends.
Recruitment GDPR work is dominated by two things a regulator will ask for first: how candidates who did not contact you are informed, and how automated screening decisions are made and reviewed.
Recruitment is the clearest example of processing personal data you did not collect from the person. Sourcing from LinkedIn, job boards, referrals and CV databases means the candidate often has no idea you hold their data until you contact them - which is exactly the situation Article 14 was written for.
That Article 14 notice is a genuine obligation with a deadline: within a reasonable period, and at the latest when you first communicate with the person. Most agencies never send it, and it is one of the easiest failures for a candidate to complain about.
Automated screening raises the second issue. CV parsing, ranking and knock-out questions can constitute automated decision-making with significant effects, and the EU AI Act classifies recruitment and employee-management systems as high risk - which brings documentation, human oversight and transparency obligations beyond GDPR.
What a GDPR policy for a recruitment business has to cover
A ROPA covering sourcing, screening, submission and database retention
Legitimate interests assessments for sourcing and for long-term database retention
The Article 14 notice process, with evidence it is actually sent
A DPIA for automated screening, plus AI Act high-risk documentation where applicable
Controller and joint-controller analysis between agency and hiring client
How a recruitment business actually moves personal data
Sourced candidate profiles
Scraped or manually copied from professional networks and job boards, held before the candidate has any contact with you.
CV parsing and enrichment
Automated extraction of employment history, education and skills, sometimes enriched from third-party sources.
Screening and ranking systems
Scoring candidates against a role, which is profiling and may be automated decision-making.
Client submissions
Sending a candidate’s details to a hiring client, which is a disclosure requiring the candidate’s knowledge.
Background and reference checks
Right-to-work documents, references and, in some sectors, criminal-records checks with their own conditions.
Long-term candidate databases
Records retained for years against future roles, frequently without any review.
Third parties the draft will ask you about
Bullhorn or Vincere · LinkedIn Recruiter · Indeed or Reed · a background screening provider · DocuSign · Microsoft 365
The rules that apply
Article 14 notice
Where data was not obtained from the candidate, they must be told what you hold, where it came from and why - at the latest when you first make contact.
Automated decision-making
Ranking, scoring and knock-out screening can meet the Article 22 threshold, entitling the candidate to human intervention and an explanation.
EU AI Act high-risk classification
Systems used for recruitment and worker management are classified high risk, with documentation, oversight and transparency obligations.
Retention of unsuccessful candidates
Keeping a CV database "in case something comes up" needs a basis, a retention period and a route to object.
Right-to-work and background checks
Identity documents and criminal-records data carry stricter conditions than ordinary candidate information.
What the generated GDPR policy contains
Article 13 and 14 transparency notice
The full disclosure set, split by whether the data came from the person or from somewhere else.
Lawful basis register
Every processing activity mapped to one of the six bases, with the legitimate interests assessment written down where you rely on that basis.
Records of processing (Article 30)
The internal register a supervisory authority can ask for at any time, covering purposes, categories, recipients, transfers and retention.
Data subject rights procedure
How a request arrives, how identity is verified, who handles it, and the one-month clock with its two-month extension.
International transfer mechanism
Adequacy, SCCs with a transfer impact assessment, or the UK IDTA/addendum - named per destination, not asserted in general.
Breach detection and 72-hour notification
The internal escalation path, the assessment test, and the template for notifying the regulator and, where required, the individuals.
Processor and sub-processor controls
Article 28 terms, the sub-processor list, and the change-notification commitment your customers will ask for.
Recruitment compliance essentials
Build the Article 14 notice into first contact
Automated, attached to the first message, naming the source of the data.
Get candidate agreement before submitting to a client
And record it, because disputes here are common.
Set and enforce a database retention period
With a refresh cycle that asks candidates whether to stay on file.
Add human review to any automated ranking
And document how the decision is actually made.
Handle background checks under their own conditions
Especially criminal-records data.
Assess screening tools against the AI Act
Documentation, oversight and transparency for high-risk systems.
Where this usually goes wrong
Never sending the Article 14 notice
The most common recruitment failure, and the easiest for a candidate to complain about.
Submitting a candidate to a client without their knowledge
A disclosure the candidate is entitled to know about, and a common source of complaints.
A CV database retained indefinitely
Storage limitation applies, and a candidate from six years ago has usually moved on.
Automated ranking with no human review
Where the effect is significant, Article 22 gives the candidate a right to human intervention.
Criminal-records data treated as ordinary
It carries specific statutory conditions in the UK and most EU states.
No AI Act documentation for screening tools
Recruitment systems are classified high risk, with obligations that take time to assemble.
Frequently asked questions
Do I need consent to hold a candidate’s CV?
Usually not consent - legitimate interests is the more common basis for recruitment. But where you did not get the data from the candidate, Article 14 requires you to tell them what you hold and where it came from, at the latest when you first contact them.
Can I keep CVs on file for future roles?
With a basis, a stated retention period and a route to object. Indefinite retention with no review is the position that attracts complaints.
Is automated CV screening allowed?
Yes, with care. Where the decision is solely automated and significantly affects the candidate, Article 22 gives rights to an explanation and human intervention - and the EU AI Act classifies recruitment systems as high risk.
Can I send a candidate to a client without asking?
It is a disclosure of their personal data, and doing it without their knowledge is both a transparency failure and the fastest route to a complaint.
Does GDPR apply to a business outside the EU?
Yes, where you offer goods or services to people in the EU or monitor their behaviour. Article 3(2) is about where the person is, not where you are - and Article 27 may also require you to appoint an EU representative.
What is the difference between EU GDPR and UK GDPR?
The text is nearly identical, but they are separate laws with separate regulators, separate fine ceilings in different currencies, and separate transfer regimes. A business serving both needs both named, not "GDPR" as shorthand.
Do I need a Data Protection Officer?
Only where your core activities involve large-scale regular monitoring or large-scale special-category data, or you are a public authority. Many businesses do not need one - but if you do not have one, say who is accountable instead.
Is a GDPR policy the same as a privacy policy?
No. The privacy policy is the outward-facing notice. The GDPR policy set is the internal machinery - lawful basis register, ROPA, rights procedure, breach plan - that lets you answer a regulator when they ask how the notice is honoured.
GDPR Policy Generator for recruitment
Answer a short questionnaire and get a draft written for a recruitment business. Free to start, no card required.
Generate your GDPR policyOther documents a recruitment business needs
Each one is written for the same context, not a generic template.
The same document, by business type
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.