Share Article

March 13, 2018

How the GDPR affects recruitment

How the GDPR affects recruitment is a vast subject. As recruitment is highly data driven, this can be one of the most difficult areas to control when it comes to complying with GDPR.

Most companies recruit. Even if you are using a recruitment agency, you will need to be stringent with the personal data you are storing. Personal data is anything relating to a person’s life, including their address, CV and pretty much any personal data you might collect during the recruitment process.


In this second instalment of our GDPR compliance series, we’re going to be looking at how the GDPR affects recruitment and the areas you need to be aware of when it comes to the changes in legislation. We’ll also give you seven necessary tasks that you need to carry out to ensure that you’re ready for the GDPR before the deadline.


How the GDPR affects recruitment processes

Your recruitment process may involve online applications, CV’s forwarded by agencies and CV’s sent directly. With GDPR coming into play, you will need to gain an understanding of the personal data you are storing throughout your recruitment process and whether this fits in with the new legislation.

Before storing any information, you will require consent from the individual and they will have the right to be informed about what you intend to use their information for. Please note that an individual can withdraw consent at any time to the processing of their personal data.


Changes to Individual Rights

Individuals have the right to subject access; this means that they can ask, at any time, to get a copy of any information you hold on them, so now is the time to archive any personal data you no longer need and ultimately delete. Archiving alone will not meet the erasure requirements.

There will be examples where you are required to keep data for a minimum period e.g. the Conduct Regulations require recruiters to keep certain records for at least a year. In this instance, you must ensure data is destroyed after the set period and you must explain the same to the individual.

We discussed the changes to individual rights in our first article – What is the GDPR, so click here to take a look.

Any automated processes in recruitment must be transparent. If candidates have a decision made about them based on automated processes, they may be able to appeal the decision.


Recruitment Agencies

Employers who are working with recruitment agencies must also be aware of their compliance with GDPR. It is worth taking a look at your PSL and making sure you know what the agencies processes are and how they are ensuring compliance with the GDPR legislation.


What you need to do now to ensure GDPR compliance

Now is the time to start reviewing your current recruitment process to get ready for the GDPR, so some investigation is required to gauge just how many changes you need to put in place to be fully compliant and stay on the right side of the law.


Carrying out the following tasks will give you a great start towards total GDPR compliance and provide you with a clearer picture of what changes your business needs to make in regards to personal data:


  1. Carry out an information audit to assess how you manage candidate, client and other personal data.
  2. Review your data processes and develop a procedure to record data processing activities.
  3. Review your data security procedures to ensure you are taking sufficient steps to keep personal data secure.
  4. Assess how you handle subject access requests to ensure you will be able to process these for free and within one month.
  5. Discuss the implications of the GDPR with companies in your supply chain.
  6. Train your employees to handle personal data correctly.
  7. Consider appointing a data protection officer


We hope you’ve found our how the GDPR affects recruitment article useful. If you missed the first part of our GDPR series, what is the GDPR?, click here to read the article.


In our final GDPR article, we’ll be sharing an easy to follow checklist for complying with the legislation throughout your recruitment process. Check back soon and don’t forget to subscribe to our mailing list to get the latest update.


Disclaimer: The information contained within this article are given in goodwill and Appointments Personnel Limited uses all reasonable efforts to ensure that it is accurate. Appointments Personnel Limited shall not be liable under any circumstances for any loss, expense, damage, delay, costs or compensation (whether direct, indirect or consequential) which may be suffered or incurred by you.

By Kerry Bonfiglio-Bains April 22, 2026
A practical guide covering interview preparation, structured questioning, and the mistakes most SMEs don't realise they're making during interviews.
By Kerry Bonfiglio-Bains April 22, 2026
A 2026 UK guide to legal and unlawful interview questions for SMEs, covering the Equality Act 2010, what you can and can't ask, and what it costs to get it wrong.
By Kerry Bonfiglio-Bains March 20, 2026
A practical guide to salary reviews in 2026. Understand pay structures, National Living Wage impacts, benchmarking, and how to avoid inconsistency.
By Kerry Bonfiglio-Bains February 25, 2026
Statutory Sick Pay, maternity pay and payroll thresholds increase from April 2026. See the new SSP rates, family leave payments, Lower Earnings Limit and what UK employers must update now.
By Kerry Bonfiglio-Bains February 24, 2026
UK National Minimum Wage and National Living Wage rise in April 2026. Check the new hourly rates, payroll cost impact, common compliance risks and what employers must do now to stay compliant.
By Kerry Bonfiglio-Bains February 23, 2026
Small Business UK Employment Law Checklist 2026. Review contracts, SSP, flexible working, harassment duties, ACAS compliance and minimum wage updates to reduce legal risk.
By Kerry Bonfiglio-Bains February 21, 2026
How to prevent workplace sexual harassment under UK law. Understand the strengthened preventative duty, “all reasonable steps” requirement, third-party risk and employer compliance in 2026.
By Kerry Bonfiglio-Bains February 20, 2026
Flexible working rules explained for UK employers. Learn day-one request rights, the two-request rule, consultation requirements, statutory refusal grounds and 2026 compliance risks.
Close-up of a judge’s gavel and scales of justice on a desk with two workers reviewing documents
By Kerry Bonfiglio-Bains February 19, 2026
Avoid common UK employment law mistakes that lead to costly disputes. A practical guide for SMEs covering contracts, holiday pay, SSP changes, flexible working, probation, redundancy rules and 2026 updates.
By Kerry Bonfiglio-Bains February 9, 2026
Small and medium employers are used to juggling checklists. Payroll, recruitment, line-manager training, etc. But 2026 is different: the rules aren’t just changing, and the way decisions are judged is shifting. That makes everyday choices (flexible-working replies, sickness pay, probation calls) more likely to land a business in trouble, even when managers act in good faith. Below are the practical changes UK SMEs should prioritise now, what they mean in everyday terms, and a short checklist you can action this week. Quick summary From 6 April 2026 , some family and sick-pay rights become day-one entitlements. That affects paternity, unpaid parental leave and statutory sick pay. Statutory Sick Pay (SSP) waiting days are being removed and entitlement rules change — payroll must be ready. Collective redundancy penalties increase: protective awards can double, so consult properly or risk larger fines. These changes are rolling in across 2026; employers should focus on process, documentation and manager training , not just policy wording. What’s changing (and why it matters) 1. Day-one family rights — paternity & unpaid parental leave From April 2026, employees can give notice for statutory paternity leave and unpaid parental leave from their first day of employment. That removes the old 26-week / 12-month service tests and brings more people into scope immediately, which is good for families, but means employers must be ready to process, record and respond to requests from day one. Practical impact: update your parental-leave procedure, train whoever handles returns and leave, and make sure your contractual templates and employee handbook reflect the new eligibility rules. 2. Statutory Sick Pay: waiting days gone, wider entitlement The current three waiting-day rule for SSP is being removed from 6 April 2026, and entitlement rules are being widened (for example, the lower earnings threshold is being removed). SSP rates are also updated for 2026–27. Payroll teams need to be able to pay SSP from day one and to calculate linked periods correctly. Practical impact: talk to payroll/your software provider now. Test scenarios: short absences, linked periods, low-paid staff. Confirm how your payroll will apply the new SSP rules from 6 April. 3. Redundancy and collective consultation: higher protective awards The maximum protective award for failing to consult properly in a collective redundancy situation will increase (reports indicate a doubling to 180 days’ pay). That makes getting consultation, records and redundancy planning right far more important. Practical impact: audit your redundancy playbook, update consultation steps, and ensure you have a clear paper trail showing how decisions were reached and who was consulted. 4. The broader shift: process matters more than ever Across the Employment Rights Act and related reforms, a repeated theme is that tribunals and regulators are looking for defensible processes: consistent handling, documented reasoning and fair communication. That means the smallest missing note in a file, an informal chat that wasn’t recorded, or inconsistent treatment of similar cases can be costly. Practical impact: build manager scripts, standard templates for decisions, and a simple central filing system for HR notes. Train managers to log reasoning, not just outcomes. What SMEs should do this week (practical checklist) Immediate (this week) Talk to payroll: confirm SSP changes will be applied from 6 April 2026 and test a Day-1 absence scenario. Update your parental-leave and paternity-leave procedure to reflect day-one entitlement. Put a ‘how to’ note in the employee handbook and your manager guidance. Identify who handles redundancy consultation and map the steps — confirm who will lead and document each stage. Short term (2–4 weeks) Run a 30-minute manager briefing: how to record decision reasoning, where to save notes, how to respond to flexible-working and SSP queries. (Make it practical, use examples.) Review and update contract templates and staff handbook sections that reference qualifying periods, waiting days or eligibility tests. If you have uncertainties Keep a short list of questions and seek a 15-minute HR/ employment-law clinic rather than overhauling everything at once. Many small fixes (clear wording, a consistent file note template, payroll checks) remove most risk. FAQs Q: Do I have to update every contract before 6 April? A: Not always. Prioritise payroll and policies for SSP and parental rights, and ensure your core contract wording doesn’t contradict the new rules. Plan a phased update for full contract refresh. Q: What happens if I get it wrong? A: For individual disputes, you might face claims (and back-pay for SSP). For collective redundancy failures, protective awards can be materially higher from April 2026, so weak process can be costly. Q: Should I panic and rewrite every policy now? A: No. Start with the high-risk items: payroll SSP, parental-leave eligibility, and redundancy consultation steps. Fix the data and the decision flow; wording and full rewrites can follow on a schedule. Want a hand? If you’d rather not puzzle through the detail alone, we’re running a short, practical webinar that covers these exact points and gives you an immediate checklist to act on. Learn more about it here.
More Posts