By business type

Privacy Policy Generator for recruitment

Written for candidate data sourced without consent, CV databases, automated screening and the Article 14 notice nobody sends.

Generate your privacy policy Read the privacy policy guide

A recruitment privacy notice has to work for people who never gave you their data. That means naming the sources you source from, explaining the basis, and being explicit about what happens when you put a candidate forward to a client.

Recruitment is the clearest example of processing personal data you did not collect from the person. Sourcing from LinkedIn, job boards, referrals and CV databases means the candidate often has no idea you hold their data until you contact them - which is exactly the situation Article 14 was written for.

That Article 14 notice is a genuine obligation with a deadline: within a reasonable period, and at the latest when you first communicate with the person. Most agencies never send it, and it is one of the easiest failures for a candidate to complain about.

Automated screening raises the second issue. CV parsing, ranking and knock-out questions can constitute automated decision-making with significant effects, and the EU AI Act classifies recruitment and employee-management systems as high risk - which brings documentation, human oversight and transparency obligations beyond GDPR.

What a privacy policy for a recruitment business has to cover

How a recruitment business actually moves personal data

Sourced candidate profiles

Scraped or manually copied from professional networks and job boards, held before the candidate has any contact with you.

CV parsing and enrichment

Automated extraction of employment history, education and skills, sometimes enriched from third-party sources.

Screening and ranking systems

Scoring candidates against a role, which is profiling and may be automated decision-making.

Client submissions

Sending a candidate’s details to a hiring client, which is a disclosure requiring the candidate’s knowledge.

Background and reference checks

Right-to-work documents, references and, in some sectors, criminal-records checks with their own conditions.

Long-term candidate databases

Records retained for years against future roles, frequently without any review.

Third parties the draft will ask you about

Bullhorn or Vincere · LinkedIn Recruiter · Indeed or Reed · a background screening provider · DocuSign · Microsoft 365

The rules that apply

Article 14 notice

Where data was not obtained from the candidate, they must be told what you hold, where it came from and why - at the latest when you first make contact.

Automated decision-making

Ranking, scoring and knock-out screening can meet the Article 22 threshold, entitling the candidate to human intervention and an explanation.

EU AI Act high-risk classification

Systems used for recruitment and worker management are classified high risk, with documentation, oversight and transparency obligations.

Retention of unsuccessful candidates

Keeping a CV database "in case something comes up" needs a basis, a retention period and a route to object.

Right-to-work and background checks

Identity documents and criminal-records data carry stricter conditions than ordinary candidate information.

What the generated privacy policy contains

Recruitment compliance essentials

  1. Build the Article 14 notice into first contact

    Automated, attached to the first message, naming the source of the data.

  2. Get candidate agreement before submitting to a client

    And record it, because disputes here are common.

  3. Set and enforce a database retention period

    With a refresh cycle that asks candidates whether to stay on file.

  4. Add human review to any automated ranking

    And document how the decision is actually made.

  5. Handle background checks under their own conditions

    Especially criminal-records data.

  6. Assess screening tools against the AI Act

    Documentation, oversight and transparency for high-risk systems.

Where this usually goes wrong

Never sending the Article 14 notice

The most common recruitment failure, and the easiest for a candidate to complain about.

Submitting a candidate to a client without their knowledge

A disclosure the candidate is entitled to know about, and a common source of complaints.

A CV database retained indefinitely

Storage limitation applies, and a candidate from six years ago has usually moved on.

Automated ranking with no human review

Where the effect is significant, Article 22 gives the candidate a right to human intervention.

Criminal-records data treated as ordinary

It carries specific statutory conditions in the UK and most EU states.

No AI Act documentation for screening tools

Recruitment systems are classified high risk, with obligations that take time to assemble.

Frequently asked questions

Do I need consent to hold a candidate’s CV?

Usually not consent - legitimate interests is the more common basis for recruitment. But where you did not get the data from the candidate, Article 14 requires you to tell them what you hold and where it came from, at the latest when you first contact them.

Can I keep CVs on file for future roles?

With a basis, a stated retention period and a route to object. Indefinite retention with no review is the position that attracts complaints.

Is automated CV screening allowed?

Yes, with care. Where the decision is solely automated and significantly affects the candidate, Article 22 gives rights to an explanation and human intervention - and the EU AI Act classifies recruitment systems as high risk.

Can I send a candidate to a client without asking?

It is a disclosure of their personal data, and doing it without their knowledge is both a transparency failure and the fastest route to a complaint.

Is a privacy policy legally required?

If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.

Can I copy another company’s privacy policy?

It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.

How often does a privacy policy need updating?

Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.

Does PolicifyAI give legal advice?

No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.

Privacy Policy Generator for recruitment

Answer a short questionnaire and get a draft written for a recruitment business. Free to start, no card required.

Generate your privacy policy

Other documents a recruitment business needs

Each one is written for the same context, not a generic template.

The same document, by business type

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.