GDPR and Candidate Data When You Outsource Recruitment Work

- Logix RPO
- Business
- Updated
GDPR and Candidate Data When You Outsource Recruitment Work
Every agency in the UK, Ireland or the EU asks the same question before outsourcing any part of its process: what happens to the candidate data? It is the right question, and the answer is more straightforward than most people expect — provided the arrangement is set up properly at the start.
You are the controller. The partner is a processor.
Under GDPR and UK GDPR, whoever decides why and how personal data is processed is the controller. That is your agency: you decide which candidates to approach, for which roles, and how long to keep the records.
A support partner acting on your instructions is a processor. That distinction drives everything else — the processor cannot use the data for its own purposes, cannot pass it on, and must act on your instructions about deletion.
The arrangement needs a written contract covering the subject matter, duration, purpose, categories of data and the obligations on both sides. Any partner who cannot produce one is not ready to handle candidate data.
Where the data should live
This is the decision that determines how painful compliance is later. There are two models:
- The partner works inside your systems. One candidate record, in your ATS, under your retention policy. A deletion request is honoured once, in one place.
- The partner keeps its own database. Two copies to reconcile, two retention clocks, and a deletion request that is only as good as the partner's follow-through.
The first is nearly always the right answer. It is how we prefer to work: our team operates in your ATS and CRM, so there is no parallel copy of your candidate data anywhere.
Transfers outside the UK and EU
If any part of the work happens outside the UK or EEA, that is a restricted transfer and needs a lawful basis — usually the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, supported by a transfer risk assessment.
This is genuinely manageable, but it has to be documented before work starts rather than after a client's audit asks about it.
Retention: the thing most agencies get wrong
GDPR does not set a number for how long you may keep a candidate record. It requires that you decide a period, justify it, and then actually delete on schedule. Most agency databases fail on the third point — the policy says two years and the records go back nine.
Outsourcing is a good moment to fix this, because it forces the question of what the partner should and should not be able to see.
A short checklist before you start
- Written processor agreement in place, with deletion obligations spelled out.
- Partner works in your ATS; no separate candidate database.
- Transfer mechanism documented if work happens outside the UK/EEA.
- Retention period defined — and a process that actually runs.
- Named contacts on both sides for data subject requests.
- Privacy notice updated to reflect that a processor is involved.
Where this applies
The same framework covers our clients in London, Dublin, Amsterdam, Berlin, Frankfurt and Paris. Canadian agencies work to PIPEDA and, in Quebec, Law 25; US agencies to a patchwork of state law.
This article is general information, not legal advice. Check your specific obligations with your DPO or a qualified solicitor before relying on any of it.
If you want to see how we handle data on a live desk, get in touch — we will walk through the processor agreement and the ATS setup before any candidate work begins.
