A candidate privacy notice explains how your organisation handles personal data during recruitment. It is the document that carries your transparency obligations under Articles 13 and 14 GDPR.
This article covers what the notice has to contain. For the equally important question of when the candidate has to receive it and how to get it in front of them, see when and how to inform candidates.
The notice should describe what actually happens in your recruitment process, not what a generic template assumes happens.
The elements at a glance
Articles 13 and 14 set out what has to be in there. In a recruitment context that comes down to:
| Element | Article 13 (candidate gives you the data) | Article 14 (data from an agency or platform) |
|---|---|---|
| Your identity and contact details | Required | Required |
| DPO contact details, if you have one | Required | Required |
| Purposes of the processing | Required | Required |
| Legal basis for each purpose | Required | Required |
| Your legitimate interests, where relied on | Required | Required |
| Categories of data you process | Not required | Required |
| Source of the data | Not applicable | Required |
| Recipients or categories of recipients | Required | Required |
| Transfers outside the EEA and safeguards | Required | Required |
| Retention period or the criteria for it | Required | Required |
| Candidate rights, including objection and withdrawal | Required | Required |
| Right to complain to a supervisory authority | Required | Required |
| Whether providing data is obligatory and the consequences | Required | Not applicable |
| Automated decision-making, logic, significance and consequences | Required where applicable | Required where applicable |
If you receive candidates through both routes, one notice covering the wider Article 14 set is simpler than maintaining two.
Start with who you are
Candidates need to know which organisation is responsible for their personal data.
Include your organisation’s identity and contact details. If you have appointed a data protection officer, include their contact details as well.
This sounds obvious, but it becomes important when recruitment is handled through a group company, external recruiter or shared recruitment platform.
Explain what data you process
Describe the categories of applicant data you use.
Depending on your process, this could include:
- Identification and contact information
- CV and application information
- Employment and education history
- Interview notes
- Assessments and test results
- References
- Information from professional profiles
- Communications with the candidate
- Information required before employment begins
Avoid vague wording such as “we may process any information necessary”. The starting point is deciding which applicant data you actually need.
Explain why you use it
Candidates should understand the purposes of the processing.
Typical purposes include:
- Managing applications
- Assessing suitability for a vacancy
- Communicating with candidates
- Organising interviews and assessments
- Checking references where appropriate
- Preparing an employment offer or contract
- Complying with legal obligations
- Defending or responding to recruitment-related claims
- Keeping candidates in a talent pool, where applicable
Different purposes may rely on different legal bases.
State the legal bases
Do not simply write “we process your data in accordance with the GDPR”.
Identify the legal bases that actually apply.
In recruitment these are usually steps taken at the candidate’s request before entering into a contract, legitimate interests, a legal obligation, or consent where you keep details for future vacancies. Where you rely on legitimate interests, Articles 13(1)(d) and 14(2)(b) require you to name the interest, not just the basis.
If you process special category data, an additional Article 9(2) condition is required and the notice should reflect it.
Where does the data come from?
Not all applicant information comes directly from candidates.
Where you obtain information from recruiters, references, professional networks or other sources, Article 14(2)(f) requires you to say so, including whether it came from a publicly accessible source.
This matters most in exactly the situations candidates do not expect: a referral from a current employee, a profile found on a professional network, a reference approached before the candidate was told.
Who receives the data?
Explain who may access or receive candidate data.
This can include:
- HR staff
- Hiring managers
- Relevant interviewers
- Group companies
- Recruitment agencies
- Applicant tracking systems
- Assessment providers
- IT and cloud providers
Access should still be limited to people who need the information.
Explain retention periods
“Your data will be kept as long as necessary” may be legally familiar, but it is not very helpful on its own.
Where possible, state concrete retention periods. Where that is not possible, explain the criteria used to determine them.
If unsuccessful candidates can join a talent pool, explain that separately.
International transfers
Recruitment software is often cloud-based.
If applicant data is transferred outside the EEA, explain this and provide the information required by the GDPR about the transfer mechanism or safeguards.
Do not assume that software used through a European website necessarily stores all data in Europe.
Explain candidate rights
Candidates have the following rights, and the notice should name them:
- Access
- Rectification
- Erasure
- Restriction
- Objection
- Data portability in applicable situations
- Rights relating to certain automated decisions
Explain how candidates exercise those rights, with a working address or form rather than a general company mailbox, and state that they may lodge a complaint with the competent supervisory authority. Where you rely on consent for anything, say that it can be withdrawn at any time and that withdrawal is as easy as giving it.
What happens when the candidate becomes an employee?
A candidate privacy notice is intended for the recruitment process. Once a candidate becomes an employee, your organisation will normally process considerably more personal data and for different purposes.
We therefore recommend having a separate Staff Privacy Policy that explains how you process personal data during the employment relationship. The candidate privacy notice and Staff Privacy Policy should complement each other, rather than trying to cover both recruitment and employment in a single document.
Keep it accurate
A privacy notice is not a document you write once and forget.
If you introduce a new applicant tracking system, AI screening tool, assessment provider or talent pool, check whether your notice still describes reality.
The best candidate privacy notice is not the longest one. It is the one that accurately explains your actual recruitment process.
GDPRWise helps organisations connect their documented processing activities with the privacy information they need to provide, making it easier to keep recruitment documentation consistent.
GDPRWise links your documented processing activities to the privacy information you publish, so your notice stays accurate when your recruitment changes.