GDPR and Recruitment: Handling Candidate Data Correctly
My first week at a London agency back in 2020, I watched in horror as a senior recruiter emailed 200+ candidates in an open CC field rather than BCC. Small mistake, massive implications. Six years on, and I'm still seeing recruiters make fundamental GDPR errors that could cost their companies thousands in fines.
So what's changed in 2026? Well, the UK GDPR is still very much alive despite predictions it would be watered down post-Brexit. If anything, the enforcement has gotten stricter, with the ICO issuing record fines last quarter. The regulations themselves haven't fundamentally changed, but the way we need to apply them certainly has.
Look, I'm not a lawyer, but I've navigated these waters long enough to know where the dangerous currents are. Here's what you absolutely need to know about handling candidate data correctly in today's recruitment landscape.
Consent Is Everything (But It's Not Forever)
Candidates own their data, not you. This was true when GDPR first arrived, and it remains the cornerstone principle in 2026. The difference now? Candidates are significantly more aware of their rights and increasingly willing to report breaches.
Consent must be:
- Active (pre-ticked boxes don't count)
- Specific ("Can we keep your CV for future roles?" not "Can we do whatever we want with your data?")
- Time-limited (you can't keep data indefinitely)
This last point catches out so many recruiters. I still see agencies with databases full of CVs from 2022. Those aren't assets, they're liabilities.
There's no fixed statutory period under UK GDPR, but the ICO and employment law practitioners recommend no more than 6 months for early-stage rejections (covering the Employment Tribunal window) and up to 12 months for shortlisted candidates, according to Treegarden's 2026 GDPR recruitment compliance guidance. Beyond that, you need fresh consent or a documented legal justification to retain. CVs from 2022 sitting in your database without either aren't assets. Delete them.
The Right to Be Forgotten Has Teeth
A candidate asks you to delete their data? Under UK GDPR Article 17, you've got one calendar month to respond and action the request across every system you use, including backups, email archives, and third-party platforms. The ICO is explicit: the clock starts the day after the request lands, and weekends count. "We forgot about that system" won't hold up.
This gets complicated with modern recruitment tech stacks. If you're using The OHub for your job posting alongside separate CRM and email systems, you need documented processes for purging data across all platforms.
I've worked with firms who thought they were compliant until they discovered old candidate data lurking in email attachments or cloud storage. The ICO won't accept "we forgot about that system" as an excuse.
Beyond Tick Boxes: Diversity Recruitment Strategies That Actually Transform UK Workplaces
Master the Virtual Hot Seat: 7 Video Interview Techniques Recruiters Don't Tell You
How to Master 'Tell Me About Yourself' Interview Question: UK Expert Insights
Legitimate Interest Is Not a Get-Out-of-Jail-Free Card
There's a persistent myth that "legitimate interest" lets recruiters contact anyone they find on LinkedIn. It doesn't.
The Data (Use and Access) Act 2025 introduced a "recognised legitimate interests" basis, but as Herbert Smith Freehills Kramer notes, it covers pre-approved public interest purposes like crime prevention and safeguarding. Recruitment outreach doesn't qualify. For sourcing candidates via LinkedIn or similar platforms, the standard legitimate interests test still applies: you must demonstrate necessity and weigh it against the candidate's privacy rights. Spotting someone's profile online doesn't give you the right to contact them. If you can't point to a clear, documented basis for reaching out, don't.
The ICO's latest guidance (May 2026) makes this crystal clear: finding someone on a professional network doesn't create automatic legitimate interest to contact them about roles.
What DOES constitute legitimate interest?
- Recent application (last 6 months)
- Clear professional connection (you placed them before)
- Specific skills match for a unique role (but even this is getting scrutinised more)
When in doubt, don't reach out. Or better yet, find proper channels for introduction.
The International Transfer Headache
This is where things have gotten messier since 2025. With the UK's data adequacy agreement with the EU renewed but modified, we're in a strange position where data transfers require additional safeguards depending on:
- Where your systems are hosted
- Where the candidate is based
- Where the hiring company is headquartered
Working with US tech firms? You need enhanced safeguards beyond standard contractual clauses.
Recruiting EU candidates for UK roles? Different requirements apply than for UK candidates.
Managing multi-country searches? God help you.
The smartest agencies I work with have moved to recruitment platforms with built-in compliance features rather than trying to navigate this alone. The tech can handle the geographic complexity better than most humans can.
Documentation: Your Only Real Defence
When the ICO comes knocking (and they're doing more random audits now than ever), your documentation is your only shield.
You need:
- Written policies for data handling
- Evidence of staff training
- Data processing records
- Retention schedules with enforcement mechanisms
- Consent records for every candidate
But here's the thing no one tells you: it's not enough to have these documents gathering digital dust on your SharePoint. You need to show they're living, breathing practices.
I audited a mid-sized financial recruiter last month who had beautiful policies, created by expensive lawyers. But when I asked the consultants basic GDPR questions, they couldn't answer. That's a ticking time bomb.
The Cost of Getting It Wrong
The enforcement picture shifted when the Data (Use and Access) Act 2025 commenced on 5 February 2026, the most substantial reform to UK data protection law since Brexit. The maximum penalty stays at £17.5 million or 4% of annual global turnover, whichever is greater. What changed: fines under the Privacy and Electronic Communications Regulations (PECR) now sit at that same ceiling, up from a previous cap of £500,000, according to Hill Dickinson. The ICO has already shown it'll use these powers. In 2025, it issued six monetary penalty notices totalling over £20 million, including a record £14 million fine against Capita for security failures affecting 6.6 million people, as reported by Blackfords LLP. For a small recruitment business, even a fraction of that wipes out a year's profit margin.
Smaller infractions that might have cost a few thousand pounds in 2024 are now routinely drawing £10-15K penalties. That's enough to destroy the profit margins of a small recruitment business.
And it's not just fines. The reputational damage can be catastrophic. When candidates don't trust you with their data, they don't trust you with their careers.
Practical Steps for 2026 Compliance
-
Audit your database now. If you haven't contacted candidates in 12+ months, either refresh consent or delete.
-
Create automated deletion processes. Manual compliance doesn't scale.
-
Train your team monthly, not yearly. GDPR knowledge degrades faster than you think.
-
Document your legitimate interest assessments before sourcing campaigns, not after.
-
Invest in compliant recruitment technology that builds safeguards into workflows.
The ICO's updated recruitment guidance from March this year provides detailed examples of what good practice looks like. It's dry reading but essential reference material.
The Compliance Advantage
I've started seeing forward-thinking agencies turning GDPR compliance into a competitive advantage. They're not just following rules; they're advertising their data protection credentials as a selling point.
Candidates increasingly choose which recruiters to work with based on data handling reputation. Especially in sensitive sectors like healthcare, financial services, and of course technology.
Prospect with care. Store with purpose. Delete with confidence. That's my recruitment data mantra for 2026.
The recruitment industry's relationship with personal data has fundamentally changed. Some still see GDPR as a burden. The smart ones see it as an opportunity to stand out. Which camp are you in?