GDPR and Candidate CVs: What Recruitment Agencies Need to Get Right
A candidate CV is one of the densest pieces of personal data an agency handles. Name, contact details, employment history, education, sometimes health information or a photograph — supplied by someone who wants a job, and forwarded to third parties as a matter of routine. UK GDPR applies to all of it. This is a practical guide to the parts that actually affect a recruitment workflow, including the questions worth asking any tool that touches candidate CVs. It is general information rather than legal advice; take advice on your specific circumstances.
A CV is personal data, and sometimes more than that
Everything on a CV that identifies a living person is personal data. That much is uncontroversial. What agencies underestimate is how often CVs carry special category data, which attracts stricter conditions.
A photograph can reveal ethnicity. A gap explained as 'medical leave' is health data. Trade union roles, religious institutions in an education history, or volunteering for a political organisation all fall into special categories. None of it was requested; candidates simply include it.
The practical implication is not to refuse such CVs. It is that forwarding them onward without thought is a bigger decision than it feels, and that removing what a client does not need is both good practice and good compliance.
Lawful basis: usually legitimate interests, and it needs writing down
Most recruitment agencies rely on legitimate interests for processing candidate data, rather than consent. That is generally the more robust choice: consent must be freely given and withdrawable, and a candidate who withdraws consent mid-process leaves you unable to do the job they asked you to do.
Legitimate interests is not a free pass. It requires a balancing assessment you can produce: your interest in placing the candidate, whether the processing is necessary for it, and whether it overrides the individual's rights. Write it down once, review it when your workflow changes.
Special category data needs a separate condition on top. Many agencies handle this by not processing it at all — removing it rather than justifying it.
Data minimisation is the principle that bites in client submissions
Minimisation says you process what is adequate, relevant and limited to what is necessary. Applied to a client submission, that is a sharper question than it first appears: does this client, at this stage, need the candidate's home address, date of birth, full contact details and photograph in order to decide whether to interview them?
Almost always, no. At first submission a client needs to assess capability. Contact details exist so they can contact the candidate — through you. That is exactly why blind and partially redacted submissions are good practice, not merely a fair-hiring gesture.
This is the clearest overlap between compliance and doing the job well. Sending less is both more defensible and, as blind-hiring research consistently shows, often produces better first-stage decisions.
- Remove home address and full contact details from first-stage submissions
- Remove date of birth, and graduation years if they act as a proxy for it
- Remove photographs unless the client has a genuine, stated need
- Strip health information, and anything else that fell into a special category unasked
- Keep the identified version on file — you need it when an interview is arranged
Transparency: what candidates must be told
Candidates have to know what happens to their CV. In practice that means a privacy notice they can actually reach, saying who you are, what you do with their data, the lawful basis, who you share it with, how long you keep it, and their rights.
The share-with element is the one agencies handle loosely. 'We may share your CV with our clients' is thin if you have not told the candidate before sending it to a specific employer. Many agencies confirm each submission with the candidate anyway, for commercial reasons — it also happens to be the transparent position.
If you use AI to reformat or rewrite CVs, that is processing too, and it usually means sending the content to a third-party model provider. Candidates should be able to find that out from your notice.
Retention: the requirement most agencies quietly fail
You may not keep candidate data indefinitely because it might be useful one day. You need a defined retention period, a reason for it, and a mechanism that actually deletes.
There is no statutory number. Many UK agencies land on two years from last meaningful contact, on the basis that a candidate's CV is stale beyond that and the relationship has lapsed. What matters is that the period is deliberate and applied, rather than a policy document describing a deletion that never happens.
The uncomfortable question worth asking internally: if a candidate exercised their right to erasure today, could you find every copy? The branded submissions on a shared drive, the versions in email, the exports on a consultant's laptop. Workflows that generate a new branded file per submission make that question much harder to answer than workflows that render from a single stored record.
Your CV tool is a processor — and you are responsible for it
When you use software to format candidate CVs, you remain the controller and the vendor is your processor. Article 28 requires a written contract governing that relationship, and the obligation to check they are suitable sits with you, not them.
This is where most diligence stops at 'they say they are GDPR compliant', which is not a meaningful statement. The questions below are answerable and revealing.
- Do you offer a data processing agreement, and what does it actually commit you to?
- Where is candidate data stored, and in which jurisdiction?
- If AI is used, which model provider receives the CV content, and is it used to train their models?
- Are transfers outside the UK or EEA covered by appropriate safeguards?
- How long do you retain uploaded files and generated exports, and can I configure it?
- Can I delete a candidate's data completely, including generated outputs and any share links?
- Who inside your organisation can access candidate files, and is that access logged?
- How do you separate one agency's data from another's?
Share links deserve specific attention
Sending a candidate CV as a link rather than an attachment is better practice in most respects: the document cannot drift out of date, it is not sitting in a mailbox indefinitely, and access can be withdrawn.
It also introduces a risk that attachments do not have. A link is a credential. Anyone holding it can open the document, and links get forwarded. Anything you would not want circulated should not sit behind a link with no expiry.
Practical controls: set expiry dates as a default rather than an option, restrict downloads where the client only needs to read, and revoke links when a process closes. In ConnectIQ, share links carry expiry and download controls, and the redaction check runs against the exact document and settings being shared — if identifiers remain, the link is not created until that is acknowledged.
A workable position
None of this requires a compliance department. It requires a handful of decisions made deliberately and then applied consistently.
Write down your lawful basis. Minimise what goes to clients at first stage. Publish a privacy notice that describes what actually happens, including AI processing. Set a retention period and make deletion real. Get a DPA from every processor and ask them the questions above. Put expiry on share links.
Do that and you are ahead of most of the market — and, not coincidentally, sending better submissions.
Frequently asked questions
Do we need candidate consent to send a CV to a client?
Most agencies rely on legitimate interests rather than consent, which is generally more robust because consent can be withdrawn mid-process. You still need a documented balancing assessment, a privacy notice explaining that CVs are shared with clients, and in practice most agencies confirm specific submissions with the candidate anyway.
How long can a recruitment agency keep a candidate's CV?
There is no statutory period. You need a defined, justifiable retention period and a mechanism that actually deletes — many UK agencies use two years from last meaningful contact. The harder question is whether you could locate every copy, including branded exports and share links, if erasure were requested.
Is using AI to rewrite a CV a GDPR issue?
It is processing, and it usually means sending candidate data to a third-party model provider, so it belongs in your privacy notice and your processor diligence. Ask which provider receives the content and whether it is used for training. Formatting is not automated decision-making under Article 22, because no decision about the person is being made by the system.
Should we remove contact details before sending a CV to a client?
Usually yes at first submission. Data minimisation asks what the client needs to decide whether to interview, and that is capability rather than a home address or date of birth. It also protects the relationship, since the client contacts the candidate through you.
What should we ask a CV formatting vendor about data protection?
Whether they provide a DPA, where data is stored, which AI provider receives CV content and whether it trains on it, what safeguards cover international transfers, how long files and exports are retained, whether you can delete completely, and how one agency's data is separated from another's. 'We are GDPR compliant' on its own tells you nothing.
Try it on a real CV
Turn a candidate's own CV into a branded client submission you can check before it leaves the building. No card required, and every AI change is shown as a diff you approve before sending.
ConnectIQ — branded CV formatting for recruitment teams. 10 free conversions, no card.