Most employers eventually write a candidate privacy notice. Far fewer get it to the candidate at the right moment, which is the part the GDPR is specific about.
This article covers when you have to inform candidates and how to deliver that information. For the contents of the document itself, see what a candidate privacy notice should contain.
Data you collect from the candidate
When the candidate gives you their data directly, by filling in your application form, emailing their CV or applying through your careers page, Article 13 applies.
The rule is simple: the information must be provided at the time the data is obtained. Not in the rejection email, not when the candidate asks.
In practice this means the candidate privacy notice is linked from the application form itself and is visible before the candidate presses send.
Data you receive from somewhere else
When a recruitment agency, a job board, a professional platform or a referrer sends you a candidate’s data, Article 14 applies instead. It sets three deadlines, and the earliest one that occurs is your deadline:
| Trigger | Deadline |
|---|---|
| Receipt of the data | Within a reasonable period, at the latest one month |
| First communication with the candidate | At the latest at that first communication |
| First disclosure to another recipient | At the latest when you first disclose |
The one-month period is the outer limit. It is not a grace period, and in recruitment it is almost never the deadline that actually applies, because you contact the candidate or forward their file long before a month has passed.
What this looks like in practice
An agency sends you three CVs on Monday. On Wednesday you email one of those candidates to invite them for an interview.
That Wednesday email is your first communication. The privacy information has to reach the candidate with that email or before it, not within a month of Monday. In practical terms: include the link in the interview invitation, or send the notice as a separate message first.
Now suppose that on Tuesday, before contacting anyone, you forward all three CVs to a hiring manager in a sister company that acts as a separate controller. That is a disclosure to another recipient, and it pulls your deadline forward to Tuesday for all three candidates, including the two you never contact.
The workable rule for a recruitment team: inform the candidate as soon as their file lands in your system, and you will never need to work out which trigger came first.
The exceptions are narrower than they look
Article 14(5) removes the obligation where the candidate already has the information, where providing it proves impossible or would involve disproportionate effort, or where obtaining or disclosing the data is laid down by law.
Do not lean on disproportionate effort. You have the candidate’s contact details, you intend to use them, and sending a link costs nothing. Where the agency has genuinely already given the candidate your identity and your purposes, document that rather than assuming it.
What if a recruitment agency sends you the CV?
The agency’s privacy notice does not discharge your obligation.
The agency explains what it does with candidate data. You are responsible for explaining what your organisation does with it once you act as controller.
Settle two things in your arrangement with the agency:
- Who is controller for which processing, and whether any part of it makes you joint controllers
- Whether the agency will hand candidates your notice on your behalf, and how you evidence that it happened
If the agency processes data on your instructions rather than its own, your data processing agreement should reflect that.
How to deliver the information
The obligation is to provide the information, not to bury it somewhere it could theoretically be found.
What works:
- A link on the application form and the vacancy page, visible before submission
- A link in the automatic acknowledgement your applicant tracking system sends
- A link in the interview invitation, which doubles as the Article 14 trigger for agency candidates
- A layered notice: a short summary with the essentials, linking through to the full document
What does not work: a general website privacy statement written for customers, a notice reachable only through the site footer and three further clicks, or a PDF sent after the process is over.
Whichever route candidates take into your organisation, the information they receive should be the same. Check your application page, your email templates, your recruitment platform and your agency arrangements together.
Make it readable
A candidate privacy notice is not improved by sounding like a statute.
Candidates should be able to work out what you use, why, who receives it, how long you keep it and what rights they have, without a second reading. Plain language and a logical structure do more for compliance here than length.
Say something specific about AI
If automated systems are used anywhere in your selection, transparency stops being a formality.
Articles 13(2)(f) and 14(2)(g) require meaningful information about the logic involved, and about the significance and envisaged consequences, where automated decision-making within Article 22 takes place. Even where the system stops short of that, tell candidates what it does. A screening tool that a candidate discovers only after rejection is a complaint waiting to happen.
Candidates who become employees
The information you give during recruitment explains the application process. Once someone is hired you process considerably more data, for different purposes.
Keep them separate. A Staff Privacy Policy covers the employment relationship, and the candidate notice stays focused on recruitment. New joiners should receive the staff policy at the start of employment, not be left with the recruitment notice.
Check your staff privacy policy in two minutes
Upload your current staff privacy policy and see which GDPR elements are missing before your next hire starts.
Run the free checker arrow_forwardGDPRWise helps organisations generate and maintain privacy documentation based on the personal data processing activities they have documented, including HR and recruitment.
GDPRWise turns your documented recruitment processing into the privacy information you need to publish, so candidates and employees each get the right document.