{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Candidate Confidentiality and Data Handling Policy

1. Purpose

The purpose of this policy is to establish clear and legally compliant requirements for the collection, use, recording, storage, disclosure, transfer, retention and secure disposal of personal data relating to candidates, work-seekers and temporary workers processed by {{org_field_name}} in connection with recruitment, engagement, placement and employment-business activities.

{{org_field_name}} will process personal data in accordance with applicable data protection legislation, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Data (Use and Access) Act 2025, together with other legislation governing the processing and retention of information by employment agencies and employment businesses, including the Employment Agencies Act 1973 and the Conduct of Employment Agencies and Employment Businesses Regulations 2003, as amended.

Where criminal-record information is processed in connection with recruitment or safeguarding, {{org_field_name}} will also comply with the applicable requirements of the Data Protection Act 2018, the Police Act 1997, the Rehabilitation of Offenders Act 1974 and associated exceptions legislation, and the statutory framework governing Disclosure and Barring Service checks.

Maintaining the confidentiality, integrity and security of candidate information is essential to protecting individuals’ rights and ensuring that {{org_field_name}} complies with its legal obligations as an employment business and data controller.

2. Scope

This policy applies to:

The policy applies throughout the entire candidate relationship, from initial enquiry and application through to placement, employment, and retention of records.

3. Related Policies

4. Policy Statement

{{org_field_name}} is committed to protecting the privacy, confidentiality and data-protection rights of candidates, work-seekers and temporary workers. Personal data will be processed lawfully, fairly and transparently and in accordance with the principles of the UK GDPR.

{{org_field_name}} will ensure that personal data is:

Access to candidate information will be restricted to authorised persons who require access for legitimate and lawful business purposes.

The Director will ensure that appropriate technical and organisational measures are maintained to protect candidate information and that the organisation can demonstrate compliance with its data-protection obligations.

5. Definitions

Personal Data: Any information relating to an identified or identifiable living individual. This may include, for example, a person’s name, address, telephone number, email address, identification information, employment history or other information from which the individual can be identified directly or indirectly.

Special Category Data: Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership; genetic data; biometric data processed for the purpose of uniquely identifying an individual; data concerning health; or data concerning a person’s sex life or sexual orientation.

Criminal Offence Data: Personal data relating to criminal convictions and offences or related security measures. This includes relevant information contained in or derived from Disclosure and Barring Service checks and may include allegations, proceedings or information concerning the absence of convictions where this falls within the statutory definition.

Data Subject: The identified or identifiable living individual to whom personal data relates. For the purposes of this policy, this will principally include candidates, work-seekers and temporary workers.

Data Controller: A person or organisation that determines the purposes and means of processing personal data. {{org_field_name}} will be a controller where it makes these decisions in relation to candidate information.

Data Processor: A person or organisation that processes personal data on behalf of a controller.

Processing: Any operation or set of operations performed on personal data, including collecting, recording, organising, storing, altering, retrieving, consulting, using, disclosing, sharing, restricting, deleting or destroying personal data.

Data Breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

6. Responsibilities

Director

The Director is responsible for:

All Staff

All employees and workers of {{org_field_name}} involved in recruitment, placement or the processing of candidate information are responsible for:

7. Types of Candidate Data Collected

Where necessary and lawful for recruitment, engagement, placement, payroll, safeguarding or compliance purposes, {{org_field_name}} may process candidate information including:

{{org_field_name}} will only collect and process personal data that is adequate, relevant and limited to what is necessary for an identified lawful purpose. The organisation will identify the applicable lawful basis before processing personal data and will apply the additional statutory conditions required for special category data and criminal-offence data.

8. Lawful Basis for Processing

{{org_field_name}} will identify and document an appropriate lawful basis under Article 6 of the UK GDPR before processing personal data.

Depending upon the purpose and circumstances of the processing, the lawful basis may include:

{{org_field_name}} will not rely on consent where the circumstances mean that the candidate does not have a genuine and free choice or where another lawful basis is more appropriate.

Special Category Data

Where {{org_field_name}} processes special category personal data, it will identify both:

Depending on the processing undertaken, the relevant Article 9 condition may include processing necessary for the purposes of carrying out obligations and exercising specific rights in the field of employment and social protection law, or another applicable statutory condition.

Where the relevant condition requires an additional condition under Schedule 1 of the Data Protection Act 2018, {{org_field_name}} will ensure that the relevant Schedule 1 condition is satisfied.

Where required by the Data Protection Act 2018, {{org_field_name}} will maintain an Appropriate Policy Document setting out its procedures for securing compliance with the data-protection principles and its policies regarding retention and erasure.

Criminal-Offence and DBS Data

Information relating to criminal convictions and offences, including relevant DBS information, is criminal-offence data and is not classified as special category data.

{{org_field_name}} will process criminal-offence data only where:

Where the applicable Schedule 1 condition requires an Appropriate Policy Document, one will be maintained for the relevant processing.

DBS and other criminal-record information will only be obtained, used and disclosed for positions and purposes for which {{org_field_name}} is lawfully entitled to process that information.

9. Confidentiality

All candidate data is strictly confidential. Staff must:

Any breach of confidentiality will be treated seriously and may result in disciplinary action.

10. Data Sharing

{{org_field_name}} will disclose candidate personal data only where the disclosure is lawful, necessary and proportionate for an identified purpose.

Depending on the circumstances, information may be disclosed to:

Before disclosing personal data, {{org_field_name}} will ensure that an appropriate Article 6 lawful basis applies. Where special category data is disclosed, an applicable Article 9 condition and any additional requirement under the Data Protection Act 2018 must also be satisfied. Where criminal-offence data is disclosed, the requirements of Article 10 of the UK GDPR and the Data Protection Act 2018 must be satisfied.

DBS certificate information will only be disclosed to persons who are lawfully entitled to receive it. Where the Police Act 1997 or the DBS Code of Practice applies, {{org_field_name}} will comply with the applicable restrictions governing disclosure and handling of that information.

Candidates will be provided with information about categories of recipients or disclosures as required by data-protection legislation. Consent will only be obtained where consent is the appropriate lawful basis for the relevant processing.

11. Data Storage and Security

{{org_field_name}} will implement appropriate technical and organisational measures to protect candidate personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

Candidate information will be stored using security measures appropriate to the nature, sensitivity and risk associated with the information. These measures will include, where applicable:

Special category data and criminal-offence data, including DBS information, will be subject to access controls appropriate to the sensitivity of the information.

Where {{org_field_name}} uses a processor to process candidate personal data on its behalf, the processor will be appointed subject to the requirements of Article 28 of the UK GDPR, including a legally compliant written contract governing the processing.

12. Data Retention and Disposal

{{org_field_name}} will retain candidate personal data only for as long as it is necessary for the purpose for which it was collected or subsequently lawfully processed, or for as long as retention is required by applicable legislation.

Retention periods will be determined by reference to:

Employment Agency and Employment Business Records

Records required under regulation 29 of the Conduct of Employment Agencies and Employment Businesses Regulations 2003 will be retained for at least the minimum period required by those Regulations.

Where regulation 29 requires records concerning an application from a work-seeker or hirer to be retained, the relevant records will be kept for at least one year from their creation and, where applicable, for at least one year after the date on which {{org_field_name}} last provides services to the relevant applicant, subject to the precise requirements and exceptions in the Regulations.

Such records may be retained electronically provided that they are capable of being reproduced in legible form and remain accessible as required by law.

DBS Certificate Information

DBS certificate information will not be retained for longer than is necessary for the purpose for which it was obtained.

Where {{org_field_name}} is subject to the DBS Code of Practice in relation to a certificate, the certificate or copy of the certificate will normally be retained for no longer than six months after the relevant recruitment or suitability decision, unless exceptional circumstances justify longer retention and such retention is lawful.

When the relevant retention period expires, any retained copy or representation of DBS certificate information will be securely destroyed. {{org_field_name}} may retain those limited details that it is lawfully permitted to retain, such as the date of issue, the name of the individual, the type of certificate, the position for which it was requested and the certificate reference or other permitted administrative information.

Other Candidate Records

Other candidate records will be retained in accordance with {{org_field_name}}’s applicable retention schedule. No category of candidate personal data will automatically be retained for six years merely because it forms part of a candidate file. Where a six-year retention period is used for a particular category of information, {{org_field_name}} must be able to identify and document the reason for that retention period.

At the end of the applicable retention period, personal data will be securely deleted, destroyed or anonymised unless further retention is required or permitted by law.

13. Candidate Data Protection Rights

Subject to the conditions, limitations and exemptions provided by data-protection legislation, candidates have rights in relation to their personal data, including:

Candidates may submit a request to exercise a data-protection right to {{org_field_name}} using the contact arrangements notified to them.

{{org_field_name}} will respond to requests within the period required by applicable data-protection legislation. Where legislation permits the response period to be extended, the candidate will be informed of the extension and the reasons for it within the applicable statutory period.

Where {{org_field_name}} has reasonable doubts concerning the identity of a person making a request, it may request additional information necessary to confirm that person’s identity.

Where a request is manifestly unfounded or excessive, {{org_field_name}} may take the action permitted by data-protection legislation and will provide the individual with the information required by law.

Where {{org_field_name}} makes a decision based solely on automated processing that produces legal effects concerning a candidate or similarly significantly affects them, it will ensure that the processing has a lawful basis and that the safeguards required by the UK GDPR are provided. This includes enabling the individual, where required by law, to make representations about the decision, obtain human intervention and contest the decision.

14. Data Protection Complaints

{{org_field_name}} will provide candidates and other data subjects with an appropriate means of making a complaint about the way in which their personal data has been processed.

A data-protection complaint may be made using the contact arrangements provided by {{org_field_name}}, including an appropriate electronic means of submitting a complaint.

When {{org_field_name}} receives a data-protection complaint, it will:

The Director will ensure that data-protection complaints are recorded and handled in accordance with applicable data-protection legislation.

Where applicable, the complainant will also be informed of their right to raise their concerns with the Information Commissioner’s Office and of any other rights of redress available under data-protection legislation.

Making a complaint to {{org_field_name}} does not remove or restrict any statutory right the individual may have to make a complaint to the Information Commissioner’s Office.

15. Training

All staff will receive:

The Director will ensure training remains current and relevant.

16. Personal Data Breach Management

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

All members of staff must immediately report any suspected or confirmed personal data breach to the Director in accordance with {{org_field_name}}’s breach-reporting procedures.

The Director will ensure that each suspected or confirmed breach is promptly investigated and assessed, including consideration of:

Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, {{org_field_name}} will notify the Information Commissioner’s Office without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach.

Where notification to the Information Commissioner’s Office is made later than 72 hours after {{org_field_name}} became aware of a reportable breach, the notification will be accompanied by reasons for the delay as required by law.

Where a personal data breach is likely to result in a high risk to the rights and freedoms of an affected individual, {{org_field_name}} will communicate the breach to that individual without undue delay unless an applicable statutory exception removes that requirement.

{{org_field_name}} will document personal data breaches, including the facts relating to the breach, its effects and the remedial action taken, to the extent required by data-protection legislation. This record will be maintained whether or not the breach is reportable to the Information Commissioner’s Office.

17. Governance and Quality Assurance

The Director will:

18. Director’s Oversight

The Director is responsible for:

19. Policy Review

This policy will be reviewed by the Director at least annually and sooner where necessary following a material change in applicable legislation, regulatory requirements or {{org_field_name}}’s processing activities, or following a significant personal data breach or other event indicating that the policy requires amendment.

The review will take account of applicable data-protection legislation, including the UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025, together with legislation and statutory requirements applying to {{org_field_name}} in its capacity as an employment agency or employment business.


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *