GDPR candidate privacy notice template for UK and EU recruiting
On this page
A GDPR candidate privacy notice tells job applicants and sourced candidates who holds their data, why, on what lawful basis, who receives it, how long it is kept and what rights they have. Articles 13 and 14 of the GDPR, and the same articles in the UK GDPR, list what it must contain. Give it when you collect the data from the candidate, or within one month (or at first contact, if sooner) when you found them through a job board, a referral or a database.
Below is a full template that covers every required item, a table mapping each section to the article, and notes for the situations recruiters actually hit: sourced candidates, agency and client roles, interview transcription and talent pools. If your question is only about recording or transcribing interviews, the UK GDPR recording guide goes deeper on that one purpose; for California applicants see the CCPA applicant notice.
Not legal advice. This summarizes Articles 13 and 14 of the EU GDPR and the UK GDPR, and ICO guidance, as published on the linked pages as of September 2026. The ICO's recruitment guidance was still in draft. National law in EU countries adds employment-specific rules. Have your data protection officer or adviser review the notice before you publish it.
What the notice must contain
Article 13 applies when you collect data from the candidate (an application, an interview). Article 14 applies when you get it from somewhere else (a job board, LinkedIn, a referral, another agency). The lists overlap almost completely. Sources: the UK GDPR Article 13 and Article 14 on legislation.gov.uk, and the EU text in Regulation (EU) 2016/679.
| Required item | Art. 13 (from candidate) | Art. 14 (from elsewhere) | Template section |
|---|---|---|---|
| Identity and contact details of the controller, and its representative | 13(1)(a) | 14(1)(a) | 1 |
| Data protection officer contact, where you have one | 13(1)(b) | 14(1)(b) | 1 |
| Purposes and lawful basis | 13(1)(c) | 14(1)(c) | 3, 4 |
| Legitimate interests relied on | 13(1)(d) | 14(2)(b) | 4 |
| Categories of personal data | Not required | 14(1)(d) | 2 |
| Recipients or categories of recipients | 13(1)(e) | 14(1)(e) | 6 |
| International transfers and safeguards | 13(1)(f) | 14(1)(f) | 7 |
| Retention period, or the criteria for it | 13(2)(a) | 14(2)(a) | 8 |
| Rights: access, rectification, erasure, restriction, objection, portability | 13(2)(b) | 14(2)(c) | 9 |
| Right to withdraw consent, where consent is the basis | 13(2)(c) | 14(2)(d) | 9 |
| Right to complain to the regulator (and, in the UK, to the controller) | 13(2)(d) | 14(2)(e); UK 14(2)(da) | 10 |
| Whether providing data is a requirement, and what happens if not | 13(2)(e) | Not required | 2 |
| Source of the data, including public sources | Not required | 14(2)(f) | 2 |
| Automated decision-making, including profiling | 13(2)(f) | 14(2)(g) | 5 |
Two form rules sit next to the list. Article 12(1) requires the information to be concise, transparent, intelligible and easily accessible, in clear and plain language. And where you rely on legitimate interests, Article 21(4) says the right to object must be brought to the person's attention explicitly and presented clearly and separately from other information, which is why the template gives it its own heading.
The candidate privacy notice template
Replace the brackets. Delete sections that do not apply rather than leaving placeholders, and keep the language plain: a candidate reading this on a phone should understand it.
CANDIDATE PRIVACY NOTICE
[Organisation legal name] · Last updated [date]
1. Who we are
[Organisation], [registered address], is the controller of the personal
data described here. Contact us at [privacy email]. [Our data protection
officer is [name/role], [email].] [EU representative: [name, address].]
[UK representative: [name, address].]
2. What we collect and where it comes from
From you: your CV, contact details, work history, qualifications, answers
to application questions, what you tell us in interviews, and your salary
expectations and availability.
From others: [job boards such as [name], professional networking sites,
referrals from [employees/partners], [agency name], your referees, and
[background check provider] where we make an offer].
We will tell you the source in our first message if we contacted you
before you applied.
Some information is needed to consider your application, such as contact
details and your right to work. If you do not provide it, we may not be
able to progress your application.
3. What we use it for
- Assessing your suitability for [the role you applied for / roles you
may be suited to]
- Arranging and conducting interviews, and keeping a record of them
- Communicating with you about your application
- [Presenting you to our client for a specific role, only with your
agreement for that role]
- Checking your right to work and, after an offer, [references /
background checks]
- Meeting our legal obligations and defending legal claims
4. Our lawful bases
- Steps you have asked us to take before entering into a contract
(Article 6(1)(b)): processing your application.
- Legal obligation (Article 6(1)(c)): right-to-work checks, equality
and record-keeping duties.
- Legitimate interests (Article 6(1)(f)): contacting people whose
profiles suggest they may be interested in a role; keeping an accurate
record of interviews; [keeping your details for future roles for
[period]]. You can ask for our assessment of these interests.
- [Consent (Article 6(1)(a)): [only for something genuinely optional,
e.g. joining our talent community]. You can withdraw it at any time.]
Special category data (such as health information for adjustments, or
diversity monitoring you choose to give) is used only [for adjustments /
anonymised equality monitoring] under [Article 9 condition and, in the
UK, DPA 2018 Schedule 1 condition].
5. Interviews, tools and automated decisions
[We transcribe [screening calls / interviews] with your knowledge. We
tell you before we start and you can decline without any effect on your
application.] [Transcripts are kept for [period]; we do not keep audio.]
Decisions about your application are made by people. [We do not make
decisions based solely on automated processing.] / [Describe any
automated step, the logic involved, its significance, and how to ask for
a person to review it.]
6. Who we share it with
- Hiring managers and interviewers at [organisation / our client]
- Service providers acting on our instructions: [applicant tracking
system], [video interview platform], [transcription provider],
[background check provider]
- [Our client, for a named role, after you agree to be put forward]
- Professional advisers, regulators and courts where required
We do not sell your personal data.
7. International transfers
[Your data is processed in [countries]. Where it leaves the [UK/EEA], we
rely on [adequacy regulations / standard contractual clauses / the UK
international data transfer agreement or addendum]. Ask us for a copy
of the safeguards.]
8. How long we keep it
- Unsuccessful applications: [period] after the role is filled, then
deleted, [because this covers the period in which a claim about the
recruitment could be brought].
- Talent pool: [period], [renewed only if you tell us you want to stay].
- Interview transcripts and notes: [period].
- Successful candidates: moved to your employee record under our
[employee privacy notice].
9. Your rights
You can ask to access, correct or erase your data, to restrict how we
use it, and to receive data you gave us in a portable format where that
right applies. Where we rely on consent, you can withdraw it at any time.
YOUR RIGHT TO OBJECT
Where we rely on legitimate interests, you can object at any time. We
will stop unless we have compelling legitimate grounds that override
your interests, or need the data for legal claims.
To make a request: [email / form]. We respond within one month, and
tell you if we need up to two more months for a complex request.
10. Complaints
Please contact us first at [email]; we will acknowledge your complaint
[within 30 days]. You can also complain to [the Information
Commissioner's Office, ico.org.uk] / [the data protection authority in
your EU country, or [lead authority]].
Sourced candidates: Article 14 in practice
Most agency candidates and many in-house ones never applied. Under Article 14(3), you must give them the information within a reasonable period and at the latest within one month of obtaining the data, and if you use the data to contact them, at the latest at that first communication. The ICO's draft guidance on finding candidates repeats the one-month limit and adds two points recruiters should build into sourcing:
- Searching recruitment-focused platforms can be reasonable because candidates are likely to expect it, but the ICO says you should not search for candidates on their personal social media profiles, even public ones.
- Once you contact candidates directly, the direct marketing rules also apply to that outreach.
A first outreach message that meets the timing rule without reading like a legal letter:
Hi [name], I found your profile on [platform] and think you could be a
strong fit for a [role] with [client type / our team] in [location].
Would you be open to a 15-minute call this week?
If you'd rather not hear from me, reply "no thanks" and I will remove
your details. How we handle candidate data, including where I found
yours: [short link to candidate privacy notice]
Article 14(5) has an exception where providing the information would be impossible or involve disproportionate effort. It is narrow, and a recruiter who is about to send someone a message will struggle to rely on it for that person.
Agencies and clients: whose notice is it?
Controller status decides who owes the notice. The ICO's draft guidance on responsibility during recruitment says an employer is typically a controller, that a recruiter contracted to source candidates for a particular role on the employer's behalf is likely to be a processor, and that the two are likely joint controllers where both determine the purposes and means. It also says the status can change between activities.
| Activity | Commonly analyzed as | Notice point |
|---|---|---|
| Agency builds and keeps its own candidate database for many clients | Agency is controller | Agency's own notice, from first collection or contact |
| Agency runs a search strictly on one employer's instructions | Agency likely processor (ICO draft) | Employer's notice; processor contract under Article 28 |
| Agency submits a candidate to a client, which then interviews | Client is controller for its own hiring decision | Client's notice once it receives the data; tell the candidate who the client is before you submit |
| Employer and agency jointly decide how candidates are assessed | Possibly joint controllers | Arrangement setting out responsibilities, with its essence made available to candidates |
Write the answer into your terms of business with each client. Getting the candidate's agreement before every submission is also a data protection point, not only a fee protection one.
Interview transcription and AI: what to add
If you transcribe, record or use AI anywhere in the process, the notice needs more than a line saying so. Section 5 of the template covers the minimum; the reasoning is on the neighboring pages.
- Transcription and recording. Say what is captured, what is kept (transcript, audio, video), for how long, and that candidates can decline. The lawful basis analysis is in recording interviews under UK GDPR, and the spoken line is in the interview recording consent script.
- Where data goes. Name the transcription provider as a recipient category, and mention transfers if its servers are outside the UK or EEA. Some tools keep transcripts on the recruiter's computer; Interview Signal does, and sends audio in short chunks to a speech-to-text provider that does not retain it. Even so, that provider is a recipient and belongs in the notice.
- Automated decisions. Articles 13(2)(f) and 14(2)(g) require meaningful information about the logic involved, and the significance and consequences, where there is automated decision-making covered by Article 22. In the UK, Articles 22A to 22D apply since February 5, 2026. If a person makes every decision, say so plainly.
Retention wording you can defend
Neither GDPR sets a number. The notice must give the period or the criteria, and you must actually delete on schedule. Write periods as "[X] months after [event]" so they can be applied, and base them on a reason: the time limit for a claim about the recruitment in your jurisdiction, your legal record-keeping duties, and how long a talent pool entry is genuinely useful. How long to keep interview notes has the reasoning for each record type. Avoid "as long as necessary" on its own; it states no criteria.
Where to put it, and a check before publishing
- Link it from the careers page, every application form and every job posting that accepts applications.
- Link it in the first outreach message to a sourced candidate.
- Link it again in interview invitations when transcription or recording starts at that stage.
- Every section of the article table above is covered, or deliberately marked as not applicable.
- The lawful basis matches what you actually do; consent is not used for core application processing.
- The right to object has its own heading.
- Every tool that touches candidate data is in the recipients list, and each has a processor contract. See the DPA guide for recruiting software.
- Retention periods match the deletion settings in your ATS and other tools.
- The regulator named is right for where your candidates are.
- A date and version appear at the top, and someone owns reviewing it at least once a year.
Questions people ask
When do I have to give a sourced candidate the privacy notice?
Where you did not collect the data from the candidate, Article 14(3) requires it within a reasonable period and at the latest within one month, or at the first communication if you use the data to contact them, whichever is earlier. For most sourcing that means the first outreach message should link to the notice.
Can one privacy notice cover both UK and EU candidates?
Yes, if it names the right regulator for each, reflects any differences such as the UK's right to complain to the controller first, and covers transfers in both directions. Many organizations use one notice with a short jurisdiction section.
Does a recruitment agency need its own candidate privacy notice?
Usually yes. An agency that keeps its own candidate database decides why and how that data is used, which is controller activity. The ICO's draft guidance says an agency sourcing strictly for one employer's role is likely to be a processor for that work, so the roles should be set out in the agency's terms with each client.
Should the notice ask candidates to consent?
Generally no. Regulators in the UK and EU say consent is rarely appropriate in recruitment because of the imbalance of power. State the lawful basis you actually rely on, usually steps before a contract, legal obligation or legitimate interests, and keep consent for genuinely optional things such as staying in a talent pool, where your approach calls for it.