Compliance

GDPR and candidate CVs: a practical guide for recruitment agencies

A general guide to GDPR recruitment agency CV handling: lawful basis, notices, minimisation, retention, processors and client sharing. Not legal advice.

Under the GDPR (in the UK, the UK GDPR), a candidate's CV is personal data, and your agency is usually its controller. In practice, GDPR recruitment agency CV handling comes down to six things. Have a lawful basis for each thing you do with the CV. Tell candidates how you use their data. Share only what each client needs, and only with the candidate's agreement. Keep CVs no longer than you need them. Use processors under written contracts. And be ready to answer access and deletion requests. This article is general information, not legal advice. Rules differ by country and by your circumstances, so check specifics with your data protection officer or a qualified adviser.

Who is who: controller, processor, client

Most confusion about GDPR in recruitment comes from roles. In a typical agency setup:

PartyUsual roleWhat that means
Your agencyControllerYou decide why and how candidate data is used, and you carry the main obligations
Your clientUsually a separate controllerOnce they receive a CV, they're responsible for their own use of it
ATS, CV formatting tool, email providerProcessorThey act on your instructions under a written contract
AI model provider used by a toolSubprocessorEngaged by your processor; it should be on the vendor's subprocessor list
Job boards and networksUsually separate controllersTheir terms govern what you can do with data from them

Roles depend on the facts, and some arrangements, such as joint recruitment campaigns, can create joint controllership. If in doubt, ask your adviser.

Lawful basis

Every use of a CV needs a lawful basis. The common approaches in agency recruitment are:

  • Legitimate interests, often relied on for holding a candidate database and contacting candidates about relevant roles. It needs a documented balancing assessment, and candidates can object.
  • Steps at the candidate's request before a contract, which can apply when a candidate applies for a specific role.
  • Consent, sometimes used for specific activities. It has to be freely given, specific, informed and as easy to withdraw as to give, which makes it fragile as the only basis for core recruitment work.

CVs sometimes contain special category data, such as health, ethnicity, religion or trade union membership, as well as criminal offence information. These need an additional legal condition. The practical rule is simple: don't ask for them, don't keep them unless you have a clear need, and never pass them to clients in a submission.

Transparency: telling candidates

Candidates must be told who you are, what you do with their data, your lawful basis, who you share it with, how long you keep it and what their rights are.

  • If the candidate sends you their CV, give the privacy notice when you collect it.
  • If you sourced the CV elsewhere, such as a job board or a public profile, the GDPR generally requires the notice within a reasonable period and at the latest within one month, or at your first communication with them if that's sooner.

Separately from the privacy notice, get the candidate's agreement before you send their CV to a specific client for a specific role. It's basic good practice, it prevents duplicate submissions, and in many countries regulators and agency rules expect it.

Minimisation: share only what's needed

The data minimisation principle says personal data should be adequate, relevant and limited to what's necessary. For client submissions:

  • Remove personal email, phone, home address and personal links unless the client genuinely needs them at this stage. Our guide to removing contact details from a CV covers the hidden places they live.
  • Leave out photos, date of birth, marital status and nationality unless there's a specific, lawful reason.
  • Keep sensitive interview notes out of the submission document.
  • Consider a blind or anonymised CV for early-stage or speculative sharing. A pseudonymised CV is still personal data.

Write internal notes as if the candidate will read them, because under a subject access request they may.

Retention: how long to keep CVs

The GDPR doesn't set a number of months. It says you must not keep personal data longer than necessary for its purpose, and you must be able to justify your periods. In practice, write a retention schedule by purpose. The decisions look like this (these are illustrative examples, not recommended periods):

DataPurposeDecision to make
CV uploaded to a formatting toolPreparing a submissionDelete soon after the submission is done
Candidate record in your ATSFuture relevant rolesSet a review point after a period without meaningful contact
Submission historyEvidence of introductions and feesKeep for as long as your terms of business and limitation periods need
Placed contractor recordsContract, payroll, taxFollow the statutory periods for those records

Formatting creates copies: the original, the Word version, the PDF, email attachments, shared links and the downloads folder on a laptop. Each copy needs its own rule. The cheapest copy to manage is the one you didn't keep.

Turn your next CV into a client-ready submission

Upload a candidate CV, check every fact against the source, remove contact details and export your agency’s branded DOCX and PDF. Your first 10 CVs are free.

Start free See how it works

Processors and AI tools: questions to ask

Before candidate CVs go into any tool, ask the vendor:

  • Do you offer a data processing agreement with the terms the GDPR requires of processors?
  • Who are your subprocessors, including any AI model provider, and where do they process data?
  • What transfer safeguards apply if data leaves the UK or EEA?
  • Is candidate data used to train models?
  • How long are uploaded files kept, and how does deletion work, including in backups?
  • Who in your company can access customer data, and how is access logged?
  • How quickly will you notify us of a personal data breach?

AI assistants connected to your systems need the same thinking. If you connect recruitment software to Claude or ChatGPT, anything returned to the assistant goes to that provider under your account's terms. Our guide to connecting recruitment software via MCP explains how to keep that deliberate.

Candidate rights

Be ready to handle these requests, usually within one month:

  • Access: a copy of their data, including your notes and submission history.
  • Rectification: correcting inaccurate data, such as a wrong date on a formatted CV.
  • Erasure: deletion where no other basis or obligation requires you to keep it.
  • Objection: stopping processing based on legitimate interests unless you have compelling grounds, and always stopping direct marketing.
  • Restriction and portability, in the situations the GDPR sets out.

The GDPR also restricts decisions based solely on automated processing that have legal or similarly significant effects. If any tool automatically rejects or ranks candidates, understand exactly what it does.

When it goes wrong: breaches

Sending a CV to the wrong client, or a CV with contact details that should have been removed, can be a personal data breach. Assess the risk. Where a breach is likely to result in a risk to individuals, the GDPR requires you to notify your supervisory authority (in the UK, the ICO) within 72 hours of becoming aware of it. You must tell the individual if the risk is high. Record every breach internally, including the ones you don't report.

GDPR recruitment agency CV checklist

  • A documented lawful basis for each activity, including a legitimate interests assessment if you rely on it.
  • A privacy notice given at collection, or within the deadline for sourced CVs.
  • Candidate agreement recorded for each client submission.
  • Contact details and unnecessary personal data removed from submissions, including metadata.
  • A retention schedule by purpose that covers every copy.
  • Data processing agreements and subprocessor lists for every tool.
  • A process for access, erasure and objection requests.
  • A breach procedure and log.

How CVPitch supports this

Using any tool doesn't make you compliant, but tools can make good practice easier. In CVPitch:

  • Recruiters confirm they're authorised to process a CV before uploading it.
  • Only members of your agency workspace can see your candidates. Candidate documents are never sent to analytics.
  • Contact removal covers the generated DOCX, PDF and hidden metadata, with presets for named clients and anonymous profiles. Lines stating date of birth, nationality, marital status or religion can be removed too, and employers can be masked.
  • Owners set a retention period of up to 90 days. Deleting a submission revokes access immediately and queues the stored files for removal.
  • Notifications and webhooks carry statuses and links, not candidate content.
  • Connected AI assistants can't read candidate content unless a workspace owner enables it.
  • Candidate data goes to a short list of recipients: the AI provider for extraction, OCR and optional AI writing; the email provider when you use email intake; and only the ATSs you connect yourself.
  • Owners can require single sign-on and export the workspace audit log.
  • CVPitch doesn't rank, score or reject candidates.

Details are on our security page and in the privacy notice.

Frequently asked questions

Can a recruitment agency keep CVs on file?

Generally yes, if you have a lawful basis, have told the candidate, keep the CV only as long as your documented purpose needs, and respect objections and erasure requests. Indefinite "just in case" storage is hard to justify.

Your lawful basis may not be consent. Separately, you should get the candidate's agreement before sending their CV to a specific client for a specific role. It's expected good practice and, in many places, a regulatory expectation.

How long should a recruitment agency keep a CV?

The GDPR sets no fixed period. Set periods by purpose, justify them, and review records after a period of no meaningful contact. Copies made for a single submission should go soon after.

Is a CV formatting tool a data processor?

Usually, yes. It processes candidate data on your instructions, so you need a data processing agreement with it and should know its subprocessors, including any AI provider.

Bottom line

Know your role, pick and document a lawful basis, tell candidates, share less, delete on schedule and choose processors you can question. Again, this is general information, not legal advice. Get specific advice for your agency and jurisdiction.

Turn your next CV into a client-ready submission

Upload a candidate CV, check every fact against the source, remove contact details and export your agency’s branded DOCX and PDF. Your first 10 CVs are free.

Start free See how it works

Send your next candidate CV in your agency’s format

CVPitch reformats candidate CVs into your branded template, checks every fact against the source and removes contact details on your terms. Start with 10 free CVs.

Start free See pricing