UK GDPR and candidate data: what recruitment agencies get wrong
Recruitment agencies hold an unusually large amount of personal data relative to their size — CVs, right to work documents, references, sometimes DBS results, bank details, and increasingly detailed profiles built up across years of a candidate's relationship with the agency. UK GDPR and the Data Protection Act 2018 apply to all of it, and the recruitment sector's normal way of operating — holding onto candidates indefinitely on the basis they might be useful for a future role — sits closer to the edge of what's defensible than most agencies probably assume.
Where agencies commonly get this wrong
The most common gap isn't a dramatic data breach — it's quieter than that. Candidate records held indefinitely with no clear retention policy, right to work documents kept well past any defensible retention period, and a general assumption that holding onto data is low-risk because nothing's gone wrong yet. None of that is a deliberate compliance failure; it's usually just nobody having set an explicit policy, with a default of keeping everything indefinitely taking hold as a result.
Lawful basis isn't optional, even for routine recruitment activity
Processing a candidate's personal data needs a lawful basis under UK GDPR, and for most recruitment activity that's usually legitimate interests or, for certain data, consent — but "we might place them eventually" isn't, on its own, a rigorous enough basis for holding data indefinitely without ever revisiting whether it's still justified. This is a genuinely technical area of data protection law, and it's worth getting proper advice on the specific lawful basis an agency is relying on, rather than assuming recruitment activity is automatically covered by a general sense that it must be fine.
What good retention practice looks like
- A defined retention period for candidate data that isn't placed, reviewed periodically rather than left indefinite by default.
- Clear separation between data that has an active compliance reason to be kept — right to work evidence for a placed worker — and data that's just sitting there because deleting it felt like extra work.
- A documented process for a candidate exercising a right to erasure or access request, since both are real rights under UK GDPR that an agency needs to be able to respond to within a defined timeframe.
- Clarity on what happens to a candidate's data if they're inactive for an extended period — automatic deletion, an active re-consent request, or a defined review, rather than silent indefinite retention.
Where this overlaps with compliance record-keeping
There's a real tension worth naming here: data protection principles push toward minimising how long personal data is kept, while compliance obligations — like right to work evidence retention — require keeping specific records for a defined period after engagement ends. These aren't contradictory once you separate them properly, which is exactly the kind of distinction worth building into how an agency prepares its records for scrutiny generally: the compliance-driven retention period is a legitimate, definable reason to keep specific data for a specific time, and everything outside that scope is where the general data minimisation principle should actually apply.
What to do about candidates who registered once and never came back
A large agency database inevitably accumulates candidates who registered years ago, were never placed, and have had no further contact since. Reviewing this segment specifically — rather than letting it sit untouched because it's not actively causing a visible problem — is one of the more overdue exercises most agencies could usefully run, and it's exactly the kind of data protection housekeeping that's easy to keep deprioritising until a subject access request or a regulator query forces the question.
This is worth getting proper advice on, not just a blog post's word for it
Data protection law is detailed, actively enforced, and genuinely consequential to get wrong — the ICO's own current guidance, and where appropriate a data protection professional's advice specific to your agency's exact data holdings, is the right place to confirm a retention policy and lawful basis, rather than working from a general sense of what "seems reasonable." This is squarely one of the areas where a blog post can flag the shape of the issue but shouldn't be treated as the final word on a specific agency's compliant position.
Key takeaways
- UK GDPR applies fully to candidate CVs, right to work documents, references and other data agencies hold — recruitment isn't a special exemption.
- Holding candidate data indefinitely on the basis they might be placed eventually isn't automatically a sufficient lawful basis.
- Separate data kept for an active compliance reason from data that's simply never been reviewed for deletion.
- Have a documented process for erasure and access requests — both are real rights an agency needs to respond to within a set timeframe.
- Review long-dormant candidate records specifically, rather than letting them accumulate indefinitely by default.
- Confirm lawful basis and retention policy against current ICO guidance or proper advice, not general assumption.
The AgencyOptix team
Written by people who work daily with recruitment agencies on right-to-work checks, AWR compliance and the records that hold up under an EAS inspection.