Data processing agreements for recruiting software: what to check
On this page
A data processing agreement (DPA) is the contract that limits what a recruiting software vendor may do with your candidates' data. Under GDPR Article 28 it must say the vendor processes data only on your documented instructions, keeps it confidential and secure, uses sub-processors only with your authorization, helps you answer candidate rights requests, deletes or returns data at the end, and lets you check compliance. The CCPA requires similar written terms for service providers handling California applicants.
This page lists the required terms, then the recruiting-specific points generic DPAs miss: interview recordings, AI model training, speech-to-text and language model sub-processors, and deletion that matches your retention schedule. For the other half of vendor review, independent evidence that controls work, see SOC 2 for recruiting software.
Not legal advice. This summarizes GDPR Article 28, ICO guidance and the California regulations on service provider contracts as published on the linked pages as of September 2026. Contract terms, transfer mechanisms and national rules vary. Have your privacy counsel or data protection officer review any DPA before signing.
Who needs one, and in which direction
The DPA runs from you, the controller that decides why candidate data is processed, to the vendor, the processor that handles it on your behalf. For an employer using an applicant tracking system, that is straightforward. For agencies it depends on the activity: the ICO's draft recruitment guidance treats an agency sourcing strictly on one employer's instructions as likely a processor, while an agency running its own candidate database is a controller and needs DPAs with its own vendors. The candidate privacy notice guide sets out those roles.
| Tool | Typical role | Needs a DPA from the vendor? |
|---|---|---|
| Applicant tracking system or CRM | Processor | Yes |
| Video interview or scheduling platform | Processor | Yes |
| Interview transcription or AI note-taker | Processor, with its own sub-processors | Yes |
| Assessment or AI screening vendor | Processor, sometimes a controller for its own model improvement | Yes, and check what it does as a controller |
| Background screening company | Often a controller in its own right | A data sharing or controller-to-controller agreement, plus FCRA terms in the US |
| Job board | Usually an independent controller | Its terms and privacy notice, not an Article 28 DPA |
What GDPR Article 28 requires
Article 28(3), in the UK GDPR and the EU GDPR, requires a contract that sets out the subject matter and duration, the nature and purpose of processing, the type of personal data and categories of data subjects, and the controller's obligations and rights. It then requires the processor to:
| Art. 28(3) | Term | What to look for in a recruiting DPA |
|---|---|---|
| (a) | Process only on documented instructions, including on transfers | The instructions cover your use of the product and nothing else, such as model training or benchmarking for other customers |
| (b) | Confidentiality of people authorized to process | Vendor staff who can see transcripts or recordings are bound, and access is limited to support cases |
| (c) | Security measures under Article 32 | A security annex naming encryption, access control and logging, not only "industry standard" |
| (d) | Conditions for sub-processors | A list, a notice period for changes and a right to object |
| (e) | Assist with data subject rights | Export and deletion for one candidate, fast enough for your one-month or 45-day clock |
| (f) | Assist with security, breach notification, DPIAs and prior consultation (Articles 32 to 36) | A breach notice timeline in hours or days, and help with your DPIA for AI features |
| (g) | Delete or return data at the end of services | A date by which deletion happens, including backups, and a certificate on request |
| (h) | Information to demonstrate compliance, and audits | Audit rights, usually satisfied by current third-party reports with a right to follow-up questions |
Article 28 also says the processor must immediately inform you if an instruction infringes the law, and under Article 28(4) a processor that uses a sub-processor must pass down the same obligations and remains fully liable to you for the sub-processor's performance. The ICO's guidance on what needs to be in the contract walks through the same list.
What California adds for applicant data
If the CCPA applies to you, a vendor is only a "service provider" if the contract contains the terms in Cal. Code Regs. tit. 11, § 7051(a). Among them: a prohibition on selling or sharing the personal information; the specific business purposes, which cannot be described generically; no use, retention or disclosure outside those purposes; no combining with personal information from other sources except as the regulations allow; the same level of privacy protection the CCPA requires; your right to take reasonable steps to ensure compliance and to stop unauthorized use; and notice if the vendor can no longer meet its obligations. Without these terms, disclosing candidate data to the vendor may be treated differently under the CCPA. The CCPA applicant data guide covers the rest of the California picture.
Recruiting-specific points generic DPAs miss
Interview content is sensitive by default
Candidates volunteer health conditions, pregnancies, religious practices, immigration status and criminal history in interviews without being asked. A transcript of a screening call can contain special category data even if your job ad never asks for any. The DPA's description of data types should say so, and the security annex should reflect it.
AI model training
Ask whether the vendor, or any of its AI sub-processors, uses customer data or outputs to train or improve models, for your account or for everyone. A vendor acting only on your documented instructions should not be using candidate interviews to improve a product sold to your competitors unless your contract says it may. Get the answer written into the DPA, not only into a help center article that can change.
Sub-processors in the audio path
Interview and note-taking tools typically send audio to a speech-to-text provider and text to a large language model provider. Each is a sub-processor. Ask for the retention each applies: some delete immediately, some keep data for a period for abuse monitoring, and some offer zero retention only on specific plans. The answer decides where your candidates' words exist after the call.
Where the data actually sits
Some tools store transcripts in the vendor's cloud; others, including Interview Signal, keep transcripts and submittals on the recruiter's computer and send audio in short chunks to a speech-to-text provider that does not retain it. Local storage reduces what the vendor holds, but the DPA still matters for the audio in transit, the speech-to-text sub-processor and any account data. Neither model removes your own obligations for data on your team's laptops.
Deletion that matches your retention schedule
A DPA that deletes data "within 90 days of termination" says nothing about the candidate you rejected two years ago. Check that the product can apply your retention periods automatically or in bulk, and that deletion reaches backups and sub-processors within a stated time. How long to keep interview notes helps set the periods.
Recordings and consent records
If the tool records, ask where the consent or notice record is kept and whether it survives deletion of the recording, since you may need to show a candidate was told. The spoken line is in the interview recording consent script.
International transfers
If candidate data leaves the UK or EEA, the DPA needs a transfer mechanism. The common ones:
- EU: the European Commission's standard contractual clauses adopted in June 2021 (Implementing Decision (EU) 2021/914), or an adequacy decision for the destination, such as the EU-US Data Privacy Framework for certified US companies.
- UK: the ICO's International Data Transfer Agreement or the UK Addendum to the EU clauses, in force since March 21, 2022, or UK adequacy regulations. Old EU clauses stopped being valid for UK transfers after March 21, 2024.
Transfer mechanisms have been challenged in court before. Check the current position, and whether a US vendor is still certified, at the time you sign rather than relying on the vendor's sales deck.
Questions to send before you sign
RECRUITING SOFTWARE DPA — VENDOR QUESTIONS — [vendor] — [date]
Scope
1. What candidate data does the product collect: CVs, messages, audio,
video, transcripts, notes, scores, AI summaries?
2. Where is each stored (vendor cloud / our devices / sub-processor),
in which countries, and for how long by default?
Instructions and AI
3. Is any of our data, or output from it, used to train or improve
models, for us or for other customers? Where is that in the DPA?
4. Can we switch off each AI feature that scores, ranks or summarizes?
Sub-processors
5. Full list, with purpose, location and retention for each, including
speech-to-text and language model providers.
6. Notice period for new sub-processors and our right to object.
Rights and deletion
7. How do we export or delete one candidate's data, including from
backups and sub-processors, and how long does it take?
8. Can we set retention periods per data type and apply them in bulk?
Security and breaches
9. Breach notification timeline to us, in hours.
10. Current SOC 2 Type II or ISO 27001 report, with scope and period.
Transfers
11. Transfer mechanism for UK/EEA data: SCCs, UK Addendum/IDTA,
adequacy or Data Privacy Framework certification.
California
12. Does the DPA include the service provider terms in 11 CCR 7051(a)?
End of contract
13. Return format, deletion deadline and deletion certificate.
The processing details annex
Most DPAs leave the processing details to an annex that customers never fill in. For recruiting, write it specifically, because it is what defines the vendor's permitted instructions:
ANNEX 1 — DETAILS OF PROCESSING
Subject matter: Provision of [product] for recruiting and interviewing
Duration: Term of the agreement plus [X] days for deletion
Nature: Collection, storage, transcription, [summarization,
scoring], retrieval, export, deletion
Purpose: Assessing candidates for roles at [controller /
controller's clients]; no other purpose
Data subjects: Candidates, referees, [controller's] interviewers
Personal data: Contact details, CVs and work history, interview
audio [not retained / retained X days], transcripts,
interviewer notes, scores and written feedback
Special categories: Not requested, but may be disclosed by candidates in
interviews (e.g. health, religion); handled under the
security measures in Annex 2
Retention: As configured by controller; default [ ]
Sub-processors: Annex 3, with purpose, location and retention
Transfers: [none / countries and mechanism]
A checklist before signing
- DPA signed or incorporated into the main terms, with the Article 28(3) terms present.
- Processing details annex filled in specifically for recruiting, including volunteered special category data.
- AI training on your data addressed in writing.
- Sub-processor list reviewed, with retention for speech-to-text and language model providers.
- Breach notification timeline stated.
- Per-candidate export and deletion tested before rollout, not after the first request.
- Retention settings match your schedule and your candidate privacy notice.
- Transfer mechanism in place and current for UK and EEA candidates.
- CCPA service provider terms included if you have California applicants and the CCPA applies.
- Security evidence reviewed alongside the contract; see SOC 2 for recruiting software.
- The vendor added to your records of processing and your candidate privacy notice's recipients list.
Questions people ask
Do we need a DPA if the vendor already has a privacy policy?
Yes. A privacy policy describes the vendor's practices; it does not bind the vendor to your instructions. GDPR Article 28(3) requires a contract or other legal act with specific terms, and the CCPA regulations require specific written terms for service providers. The DPA is usually an addendum to the main terms.
Can a recruiting software vendor use our candidate data to train its AI models?
Only if your contract allows it and the law permits it. Under the GDPR a processor may act only on documented instructions from the controller, so training on your candidates' data for the vendor's own purposes needs clear treatment in the contract. Ask directly and get the answer written into the DPA.
What is a sub-processor and why does it matter for interview tools?
A sub-processor is another company the vendor uses to process your data, such as a cloud host, a speech-to-text provider or a large language model provider. Article 28 requires your authorization for them and equivalent obligations passed down, so ask for the list and how you will be told about changes.
Is a SOC 2 report a substitute for a DPA?
No. A SOC 2 report is evidence about a vendor's controls from an independent auditor. The DPA is the contract that sets what the vendor may do with your data. You usually want both, and the DPA's security annex can point to the controls the report covers.