Skip to content
HR & Recruitment calendar_today Updated: 28 August 2026 schedule 5 min read

Candidate Privacy Notices: What Should They Contain?

verified Last reviewed 31 August 2026 · GDPRWise legal team

A candidate privacy notice explains how you handle personal data during recruitment. Here is every section Articles 13 and 14 require, from legal bases to retention periods and transfers.

summarize Key Takeaways
  • check_circle A candidate privacy notice should reflect your real recruitment process
  • check_circle Explain purposes, legal bases, data sources, recipients, retention periods and candidate rights
  • check_circle Include relevant information about recruitment agencies, software and international transfers
  • check_circle Review the notice whenever your recruitment process changes

A candidate privacy notice explains how your organisation handles personal data during recruitment. It is the document that carries your transparency obligations under Articles 13 and 14 GDPR.

This article covers what the notice has to contain. For the equally important question of when the candidate has to receive it and how to get it in front of them, see when and how to inform candidates.

The notice should describe what actually happens in your recruitment process, not what a generic template assumes happens.

The elements at a glance

Articles 13 and 14 set out what has to be in there. In a recruitment context that comes down to:

ElementArticle 13 (candidate gives you the data)Article 14 (data from an agency or platform)
Your identity and contact detailsRequiredRequired
DPO contact details, if you have oneRequiredRequired
Purposes of the processingRequiredRequired
Legal basis for each purposeRequiredRequired
Your legitimate interests, where relied onRequiredRequired
Categories of data you processNot requiredRequired
Source of the dataNot applicableRequired
Recipients or categories of recipientsRequiredRequired
Transfers outside the EEA and safeguardsRequiredRequired
Retention period or the criteria for itRequiredRequired
Candidate rights, including objection and withdrawalRequiredRequired
Right to complain to a supervisory authorityRequiredRequired
Whether providing data is obligatory and the consequencesRequiredNot applicable
Automated decision-making, logic, significance and consequencesRequired where applicableRequired where applicable

If you receive candidates through both routes, one notice covering the wider Article 14 set is simpler than maintaining two.

Start with who you are

Candidates need to know which organisation is responsible for their personal data.

Include your organisation’s identity and contact details. If you have appointed a data protection officer, include their contact details as well.

This sounds obvious, but it becomes important when recruitment is handled through a group company, external recruiter or shared recruitment platform.

Explain what data you process

Describe the categories of applicant data you use.

Depending on your process, this could include:

  • Identification and contact information
  • CV and application information
  • Employment and education history
  • Interview notes
  • Assessments and test results
  • References
  • Information from professional profiles
  • Communications with the candidate
  • Information required before employment begins

Avoid vague wording such as “we may process any information necessary”. The starting point is deciding which applicant data you actually need.

Explain why you use it

Candidates should understand the purposes of the processing.

Typical purposes include:

  • Managing applications
  • Assessing suitability for a vacancy
  • Communicating with candidates
  • Organising interviews and assessments
  • Checking references where appropriate
  • Preparing an employment offer or contract
  • Complying with legal obligations
  • Defending or responding to recruitment-related claims
  • Keeping candidates in a talent pool, where applicable

Different purposes may rely on different legal bases.

Do not simply write “we process your data in accordance with the GDPR”.

Identify the legal bases that actually apply.

In recruitment these are usually steps taken at the candidate’s request before entering into a contract, legitimate interests, a legal obligation, or consent where you keep details for future vacancies. Where you rely on legitimate interests, Articles 13(1)(d) and 14(2)(b) require you to name the interest, not just the basis.

If you process special category data, an additional Article 9(2) condition is required and the notice should reflect it.

Where does the data come from?

Not all applicant information comes directly from candidates.

Where you obtain information from recruiters, references, professional networks or other sources, Article 14(2)(f) requires you to say so, including whether it came from a publicly accessible source.

This matters most in exactly the situations candidates do not expect: a referral from a current employee, a profile found on a professional network, a reference approached before the candidate was told.

Who receives the data?

Explain who may access or receive candidate data.

This can include:

  • HR staff
  • Hiring managers
  • Relevant interviewers
  • Group companies
  • Recruitment agencies
  • Applicant tracking systems
  • Assessment providers
  • IT and cloud providers

Access should still be limited to people who need the information.

Explain retention periods

“Your data will be kept as long as necessary” may be legally familiar, but it is not very helpful on its own.

Where possible, state concrete retention periods. Where that is not possible, explain the criteria used to determine them.

If unsuccessful candidates can join a talent pool, explain that separately.

International transfers

Recruitment software is often cloud-based.

If applicant data is transferred outside the EEA, explain this and provide the information required by the GDPR about the transfer mechanism or safeguards.

Do not assume that software used through a European website necessarily stores all data in Europe.

Explain candidate rights

Candidates have the following rights, and the notice should name them:

  • Access
  • Rectification
  • Erasure
  • Restriction
  • Objection
  • Data portability in applicable situations
  • Rights relating to certain automated decisions

Explain how candidates exercise those rights, with a working address or form rather than a general company mailbox, and state that they may lodge a complaint with the competent supervisory authority. Where you rely on consent for anything, say that it can be withdrawn at any time and that withdrawal is as easy as giving it.

What happens when the candidate becomes an employee?

A candidate privacy notice is intended for the recruitment process. Once a candidate becomes an employee, your organisation will normally process considerably more personal data and for different purposes.

We therefore recommend having a separate Staff Privacy Policy that explains how you process personal data during the employment relationship. The candidate privacy notice and Staff Privacy Policy should complement each other, rather than trying to cover both recruitment and employment in a single document.

Keep it accurate

A privacy notice is not a document you write once and forget.

If you introduce a new applicant tracking system, AI screening tool, assessment provider or talent pool, check whether your notice still describes reality.

The best candidate privacy notice is not the longest one. It is the one that accurately explains your actual recruitment process.

GDPRWise helps organisations connect their documented processing activities with the privacy information they need to provide, making it easier to keep recruitment documentation consistent.

auto_awesome Does your candidate privacy notice still match your recruitment process?

GDPRWise links your documented processing activities to the privacy information you publish, so your notice stays accurate when your recruitment changes.

Share share LinkedIn mail Email
GW
GDPRWise Editorial

This article was written by the GDPRWise team and reviewed by our privacy experts. We regularly review our content for accuracy and legal correctness.