Privacy Policy Generator for recruitment
Written for candidate data sourced without consent, CV databases, automated screening and the Article 14 notice nobody sends.
A recruitment privacy notice has to work for people who never gave you their data. That means naming the sources you source from, explaining the basis, and being explicit about what happens when you put a candidate forward to a client.
Recruitment is the clearest example of processing personal data you did not collect from the person. Sourcing from LinkedIn, job boards, referrals and CV databases means the candidate often has no idea you hold their data until you contact them - which is exactly the situation Article 14 was written for.
That Article 14 notice is a genuine obligation with a deadline: within a reasonable period, and at the latest when you first communicate with the person. Most agencies never send it, and it is one of the easiest failures for a candidate to complain about.
Automated screening raises the second issue. CV parsing, ranking and knock-out questions can constitute automated decision-making with significant effects, and the EU AI Act classifies recruitment and employee-management systems as high risk - which brings documentation, human oversight and transparency obligations beyond GDPR.
What a privacy policy for a recruitment business has to cover
Sources of candidate data, named - job boards, professional networks, referrals, your own database
The Article 14 information for data not collected from the candidate, and when it is sent
Client submissions as disclosures, and how candidate agreement is obtained
Automated screening and ranking, with the human review route
Retention of unsuccessful and unplaced candidates, with the refresh cycle
How a recruitment business actually moves personal data
Sourced candidate profiles
Scraped or manually copied from professional networks and job boards, held before the candidate has any contact with you.
CV parsing and enrichment
Automated extraction of employment history, education and skills, sometimes enriched from third-party sources.
Screening and ranking systems
Scoring candidates against a role, which is profiling and may be automated decision-making.
Client submissions
Sending a candidate’s details to a hiring client, which is a disclosure requiring the candidate’s knowledge.
Background and reference checks
Right-to-work documents, references and, in some sectors, criminal-records checks with their own conditions.
Long-term candidate databases
Records retained for years against future roles, frequently without any review.
Third parties the draft will ask you about
Bullhorn or Vincere · LinkedIn Recruiter · Indeed or Reed · a background screening provider · DocuSign · Microsoft 365
The rules that apply
Article 14 notice
Where data was not obtained from the candidate, they must be told what you hold, where it came from and why - at the latest when you first make contact.
Automated decision-making
Ranking, scoring and knock-out screening can meet the Article 22 threshold, entitling the candidate to human intervention and an explanation.
EU AI Act high-risk classification
Systems used for recruitment and worker management are classified high risk, with documentation, oversight and transparency obligations.
Retention of unsuccessful candidates
Keeping a CV database "in case something comes up" needs a basis, a retention period and a route to object.
Right-to-work and background checks
Identity documents and criminal-records data carry stricter conditions than ordinary candidate information.
What the generated privacy policy contains
Identity and contact details of the controller
Your legal entity, trading name, registered address and a working contact route - plus a representative or DPO where one is required.
Categories of personal data and their sources
What you collect directly, what you observe automatically, and what you receive from third parties such as payment providers or ad platforms.
Purposes and lawful basis, purpose by purpose
A table that pairs each processing purpose with its lawful basis rather than listing all six bases and hoping one fits.
Recipients and sub-processors
The categories of recipient, and for the ones that matter to users - payment, hosting, analytics, support - the named provider.
International transfers and their safeguards
Where data leaves its home jurisdiction, and the mechanism relied on: adequacy, standard contractual clauses, the UK addendum or IDTA.
Retention periods per data category
Concrete periods or the criteria used to set them, which is what regulators ask for first when a complaint lands.
Rights and how to exercise them
Access, rectification, erasure, portability, objection and restriction, with the actual route to make a request and the deadline you work to.
Complaints and supervisory authority
The regulator a user can escalate to, named, with a link - not a generic "your local authority".
Recruitment compliance essentials
Build the Article 14 notice into first contact
Automated, attached to the first message, naming the source of the data.
Get candidate agreement before submitting to a client
And record it, because disputes here are common.
Set and enforce a database retention period
With a refresh cycle that asks candidates whether to stay on file.
Add human review to any automated ranking
And document how the decision is actually made.
Handle background checks under their own conditions
Especially criminal-records data.
Assess screening tools against the AI Act
Documentation, oversight and transparency for high-risk systems.
Where this usually goes wrong
Never sending the Article 14 notice
The most common recruitment failure, and the easiest for a candidate to complain about.
Submitting a candidate to a client without their knowledge
A disclosure the candidate is entitled to know about, and a common source of complaints.
A CV database retained indefinitely
Storage limitation applies, and a candidate from six years ago has usually moved on.
Automated ranking with no human review
Where the effect is significant, Article 22 gives the candidate a right to human intervention.
Criminal-records data treated as ordinary
It carries specific statutory conditions in the UK and most EU states.
No AI Act documentation for screening tools
Recruitment systems are classified high risk, with obligations that take time to assemble.
Frequently asked questions
Do I need consent to hold a candidate’s CV?
Usually not consent - legitimate interests is the more common basis for recruitment. But where you did not get the data from the candidate, Article 14 requires you to tell them what you hold and where it came from, at the latest when you first contact them.
Can I keep CVs on file for future roles?
With a basis, a stated retention period and a route to object. Indefinite retention with no review is the position that attracts complaints.
Is automated CV screening allowed?
Yes, with care. Where the decision is solely automated and significantly affects the candidate, Article 22 gives rights to an explanation and human intervention - and the EU AI Act classifies recruitment systems as high risk.
Can I send a candidate to a client without asking?
It is a disclosure of their personal data, and doing it without their knowledge is both a transparency failure and the fastest route to a complaint.
Is a privacy policy legally required?
If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.
Can I copy another company’s privacy policy?
It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.
How often does a privacy policy need updating?
Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.
Does PolicifyAI give legal advice?
No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.
Privacy Policy Generator for recruitment
Answer a short questionnaire and get a draft written for a recruitment business. Free to start, no card required.
Generate your privacy policyOther documents a recruitment business needs
Each one is written for the same context, not a generic template.
The same document, by business type
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.