Candidate data retention policies are under sharper scrutiny than ever. Compliance officers must balance legal requirements across the UK, Australia, and Europe while managing operational realities.
TL;DR — what compliance officers need to know in 2026
Candidate data retention policies must clearly define how long you keep personal data, why, and how you securely delete it. Across the UK, Australia, and Europe, the rules vary but share key principles:
- Keep data no longer than necessary for the recruitment purpose.
- Obtain explicit consent if retaining data beyond the original purpose.
- Document your retention periods and deletion processes.
- Respond promptly to candidate requests for data access or erasure.
- Regularly audit data holdings to reduce compliance risk.
Failing to meet these can lead to enforcement actions under the UK GDPR, EU GDPR, or Australian Privacy Act, including fines and reputational damage. A policy template and decision matrix help operationalise this. This article includes worked examples and recent enforcement trends.
Background and current legal posture
Data protection laws focus on minimising risk by limiting storage of personal data. The UK and EU GDPR frameworks require data controllers to keep personal data "no longer than necessary" for the purpose collected (Article 5(1)(e) GDPR). The Australian Privacy Act 1988 has similar principles under the Australian Privacy Principles (APP 11).
UK GDPR
- Candidate data is personal data, so retention must have a lawful basis.
- Agencies often rely on consent or legitimate interest.
- Legitimate interest requires balancing agency needs with individual rights.
- Retention periods should be justified and documented.
- After the recruitment process, data may be kept for up to 6 months to consider future roles or deal with disputes, but longer retention requires consent.
EU GDPR
- Rules mirror the UK GDPR but with some local variations.
- EU regulators emphasise minimising retention to reduce breach risks.
- Some member states have issued sector-specific guidance with retention caps (e.g., Germany suggests 6 months post-recruitment).
Australian Privacy Act
- Agencies must take reasonable steps to destroy or de-identify personal information no longer needed.
- No fixed retention periods but must be "reasonable" based on purpose.
- Consent is critical if holding data for direct marketing or future roles beyond initial recruitment.
Practical recruiter / agency obligations
Recruitment agencies should translate legal principles into clear, practical steps:
- Define retention periods by data type and purpose. For example, CVs from unsuccessful candidates might be retained for 6 months by default, extended to 2 years with consent.
- Document your policy clearly and train staff. Everyone working with candidate data must understand when and how to delete.
- Obtain and record candidate consent if you plan longer retention. Use opt-in checkboxes that clearly state retention durations.
- Automate deletion where possible. Manual deletion is error-prone and risks over-retention.
- Respond promptly to candidate rights requests. Candidates can ask for access, correction, or deletion under GDPR and Australian law.
- Keep audit trails. Records of consent, deletion, and data access requests protect against enforcement.
- Secure data during retention. Encryption, access controls, and secure backups remain essential.
Templates and worked examples
Below is a simplified candidate data retention decision matrix:
| Data type | Default retention | Extended retention (with consent) | Notes |
|---|---|---|---|
| CVs (unsuccessful) | 6 months | Up to 2 years | For future roles or marketing |
| Interview notes | 6 months | Not recommended | Keep only as long as necessary |
| Offer letters & contracts | 6 years after end date | Not applicable | Statutory record-keeping |
| References | 6 months | Not recommended | Sensitive, delete promptly |
Sample retention clause for candidate CVs
“We retain CVs of unsuccessful candidates for six months following the recruitment process. If you consent, we may keep your CV for up to two years to consider you for future roles or to send relevant job alerts. You can withdraw your consent at any time by contacting us.”
Worked example: Consent collection
A recruitment agency includes a checkbox on its online application form:
“I agree to allow [Agency Name] to retain my personal data for up to two years for future recruitment opportunities in line with the candidate data retention policy.”
The agency logs the timestamp and IP address of the consent to demonstrate compliance.
Edge cases and recent enforcement
Candidates withdrawing consent
If a candidate withdraws consent, agencies must delete data unless another legal basis applies. This can be operationally challenging if data is embedded in multiple systems. Clear workflows are essential.
Data retention beyond recruitment
Some agencies retain candidate data indefinitely "just in case". Regulators have flagged this as a compliance risk, especially if no valid legal basis exists. The ICO fined a UK agency in 2023 for retaining candidate data for over five years without consent or legitimate interest documentation.
Recruitment via third parties
When candidate data is sourced from job boards or LinkedIn, agencies must clarify retention policies to candidates and ensure third-party compliance. Transparency is key.
Special categories of data
If CVs include sensitive data (e.g., disability, ethnicity), retention periods should be strictly limited and justified to reduce discrimination and privacy risks.
FAQ
How long can we keep candidate data without consent?
Typically up to six months to conclude the recruitment process and manage disputes. Beyond that, explicit consent or another lawful basis is advisable.
Can we keep CVs for future job alerts?
Yes, but only with clear, documented consent. Candidates must be able to withdraw consent easily.
What if a candidate asks to delete their data?
You must delete it promptly unless you have a lawful reason to keep it (e.g., to defend a legal claim).
Should we keep data from successful candidates?
Offer letters and contracts should be retained for statutory periods (usually six years in the UK) for tax and employment law purposes.
How often should we review our data retention policy?
At least annually, or when regulations change.
Candidate data retention is a compliance minefield but manageable with clear policies and proper processes. Automating retention and deletion reduces risk and frees your team to focus on recruitment.
Audit-ready blind hiring with Distill helps agencies strip personal data like name, email, phone, photo, and graduation year from CVs before submission, reducing compliance liability and speeding up your workflow. Try Distill free to see how it fits your agency.