{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Candidate Confidentiality and Data Handling Policy
1. Purpose
The purpose of this policy is to establish clear and legally compliant requirements for the collection, use, recording, storage, disclosure, transfer, retention and secure disposal of personal data relating to candidates, work-seekers and temporary workers processed by {{org_field_name}} in connection with recruitment, engagement, placement and employment-business activities.
{{org_field_name}} will process personal data in accordance with applicable data protection legislation, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Data (Use and Access) Act 2025, together with other legislation governing the processing and retention of information by employment agencies and employment businesses, including the Employment Agencies Act 1973 and the Conduct of Employment Agencies and Employment Businesses Regulations 2003, as amended.
Where criminal-record information is processed in connection with recruitment or safeguarding, {{org_field_name}} will also comply with the applicable requirements of the Data Protection Act 2018, the Police Act 1997, the Rehabilitation of Offenders Act 1974 and associated exceptions legislation, and the statutory framework governing Disclosure and Barring Service checks.
Maintaining the confidentiality, integrity and security of candidate information is essential to protecting individuals’ rights and ensuring that {{org_field_name}} complies with its legal obligations as an employment business and data controller.
2. Scope
This policy applies to:
- All registered nurses, healthcare assistants (HCAs), support workers, and other candidates applying for positions through {{org_field_name}}
- All employees, directors, and temporary staff involved in the recruitment, onboarding, compliance, and placement of candidates
- All personal and sensitive information collected, processed, stored, shared, or disposed of by {{org_field_name}} regarding candidates
The policy applies throughout the entire candidate relationship, from initial enquiry and application through to placement, employment, and retention of records.
3. Related Policies
- Data Protection and Confidentiality Policy
- Recruitment Policy
- Safeguarding Adults and Children Policy
- Whistleblowing Policy
- Complaints Policy
- Disciplinary Policy
4. Policy Statement
{{org_field_name}} is committed to protecting the privacy, confidentiality and data-protection rights of candidates, work-seekers and temporary workers. Personal data will be processed lawfully, fairly and transparently and in accordance with the principles of the UK GDPR.
{{org_field_name}} will ensure that personal data is:
- processed lawfully, fairly and transparently;
- collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes;
- adequate, relevant and limited to what is necessary for the purposes for which it is processed;
- accurate and, where necessary, kept up to date, with reasonable steps taken to correct or delete inaccurate personal data;
- kept in an identifiable form for no longer than is necessary for the purposes for which it is processed, subject to any statutory record-retention requirement;
- processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage; and
- processed in a manner for which {{org_field_name}} is able to demonstrate compliance with applicable data-protection legislation.
Access to candidate information will be restricted to authorised persons who require access for legitimate and lawful business purposes.
The Director will ensure that appropriate technical and organisational measures are maintained to protect candidate information and that the organisation can demonstrate compliance with its data-protection obligations.
5. Definitions
Personal Data: Any information relating to an identified or identifiable living individual. This may include, for example, a person’s name, address, telephone number, email address, identification information, employment history or other information from which the individual can be identified directly or indirectly.
Special Category Data: Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership; genetic data; biometric data processed for the purpose of uniquely identifying an individual; data concerning health; or data concerning a person’s sex life or sexual orientation.
Criminal Offence Data: Personal data relating to criminal convictions and offences or related security measures. This includes relevant information contained in or derived from Disclosure and Barring Service checks and may include allegations, proceedings or information concerning the absence of convictions where this falls within the statutory definition.
Data Subject: The identified or identifiable living individual to whom personal data relates. For the purposes of this policy, this will principally include candidates, work-seekers and temporary workers.
Data Controller: A person or organisation that determines the purposes and means of processing personal data. {{org_field_name}} will be a controller where it makes these decisions in relation to candidate information.
Data Processor: A person or organisation that processes personal data on behalf of a controller.
Processing: Any operation or set of operations performed on personal data, including collecting, recording, organising, storing, altering, retrieving, consulting, using, disclosing, sharing, restricting, deleting or destroying personal data.
Data Breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
6. Responsibilities
Director
The Director is responsible for:
- ensuring compliance with the UK GDPR, Data Protection Act 2018 and Data (Use and Access) Act 2025;
- ensuring that appropriate technical and organisational measures are maintained to protect candidate information;
- ensuring that the organisation identifies and documents an appropriate Article 6 lawful basis for each processing activity;
- ensuring that an appropriate Article 9 condition is identified where special category data is processed;
- ensuring that an appropriate condition under the Data Protection Act 2018 is identified where criminal-offence data is processed;
- ensuring that an Appropriate Policy Document is maintained where one is required under Schedule 1 of the Data Protection Act 2018;
- ensuring that all staff handling candidate information receive appropriate data-protection and confidentiality training;
- ensuring that data-protection complaints are received, acknowledged and handled within the statutory requirements;
- managing personal data breaches and determining whether notification to the Information Commissioner’s Office or affected individuals is required;
- overseeing audits of candidate-data processing activities; and
- reviewing and updating this policy following relevant changes in legislation or processing activities.
All Staff
All employees and workers of {{org_field_name}} involved in recruitment, placement or the processing of candidate information are responsible for:
- complying with this policy and applicable data-protection procedures;
- treating candidate information as confidential;
- accessing personal data only where access is required for their authorised duties;
- collecting, accessing, using, disclosing, transferring and storing candidate information only for authorised and lawful purposes;
- ensuring that personal data is not disclosed to an unauthorised person;
- following the organisation’s security requirements when processing personal data;
- immediately reporting any suspected or confirmed personal data breach to the Director; and
- immediately referring any request by a candidate to exercise a data-protection right, or any complaint concerning the use of personal data, to the Director.
7. Types of Candidate Data Collected
Where necessary and lawful for recruitment, engagement, placement, payroll, safeguarding or compliance purposes, {{org_field_name}} may process candidate information including:
- name, date of birth, address and contact information;
- identity documentation;
- evidence relating to the right to work in the United Kingdom;
- employment history and references;
- professional registration information, including Nursing and Midwifery Council registration information where applicable;
- qualifications and training records;
- Disclosure and Barring Service check information and other criminal-offence data where {{org_field_name}} is legally entitled to process that information;
- occupational health and other health information where necessary and lawful;
- equality and diversity monitoring information where collected;
- bank and payment information;
- records concerning assignments and placements;
- correspondence and communications with the candidate; and
- information required to meet the record-keeping obligations applying to employment agencies and employment businesses.
{{org_field_name}} will only collect and process personal data that is adequate, relevant and limited to what is necessary for an identified lawful purpose. The organisation will identify the applicable lawful basis before processing personal data and will apply the additional statutory conditions required for special category data and criminal-offence data.
8. Lawful Basis for Processing
{{org_field_name}} will identify and document an appropriate lawful basis under Article 6 of the UK GDPR before processing personal data.
Depending upon the purpose and circumstances of the processing, the lawful basis may include:
- contract – where processing is necessary for the performance of a contract with the candidate or to take steps at the candidate’s request before entering into a contract;
- legal obligation – where processing is necessary for compliance with a legal obligation to which {{org_field_name}} is subject;
- legitimate interests – where processing is necessary for the legitimate interests of {{org_field_name}} or a third party and those interests are not overridden by the candidate’s interests, rights or freedoms; or
- consent – where consent is an appropriate lawful basis and has been freely given, specific, informed and unambiguous and may be withdrawn.
{{org_field_name}} will not rely on consent where the circumstances mean that the candidate does not have a genuine and free choice or where another lawful basis is more appropriate.
Special Category Data
Where {{org_field_name}} processes special category personal data, it will identify both:
- a lawful basis under Article 6 of the UK GDPR; and
- a valid condition under Article 9(2) of the UK GDPR.
Depending on the processing undertaken, the relevant Article 9 condition may include processing necessary for the purposes of carrying out obligations and exercising specific rights in the field of employment and social protection law, or another applicable statutory condition.
Where the relevant condition requires an additional condition under Schedule 1 of the Data Protection Act 2018, {{org_field_name}} will ensure that the relevant Schedule 1 condition is satisfied.
Where required by the Data Protection Act 2018, {{org_field_name}} will maintain an Appropriate Policy Document setting out its procedures for securing compliance with the data-protection principles and its policies regarding retention and erasure.
Criminal-Offence and DBS Data
Information relating to criminal convictions and offences, including relevant DBS information, is criminal-offence data and is not classified as special category data.
{{org_field_name}} will process criminal-offence data only where:
- an Article 6 lawful basis applies; and
- the processing is authorised by Article 10 of the UK GDPR and an applicable condition in Schedule 1 of the Data Protection Act 2018 or other applicable statutory authority.
Where the applicable Schedule 1 condition requires an Appropriate Policy Document, one will be maintained for the relevant processing.
DBS and other criminal-record information will only be obtained, used and disclosed for positions and purposes for which {{org_field_name}} is lawfully entitled to process that information.
9. Confidentiality
All candidate data is strictly confidential. Staff must:
- Not share candidate data outside of {{org_field_name}} unless there is a lawful and justified reason
- Only share data with authorised persons, including client organisations, for placement purposes
- Ensure information is shared securely (e.g., encrypted emails, secure portals)
- Avoid discussing candidate data in public areas or with unauthorised persons
Any breach of confidentiality will be treated seriously and may result in disciplinary action.
10. Data Sharing
{{org_field_name}} will disclose candidate personal data only where the disclosure is lawful, necessary and proportionate for an identified purpose.
Depending on the circumstances, information may be disclosed to:
- client organisations where necessary to assess suitability for or facilitate an assignment;
- the Disclosure and Barring Service and organisations lawfully involved in obtaining or assessing DBS checks;
- training providers where necessary for authorised training;
- occupational health providers where necessary and lawful;
- payroll, pension, IT or other service providers acting under appropriate contractual arrangements;
- HM Revenue and Customs or another public authority where disclosure is required or authorised by law; and
- other persons or organisations where there is a valid lawful basis for the disclosure.
Before disclosing personal data, {{org_field_name}} will ensure that an appropriate Article 6 lawful basis applies. Where special category data is disclosed, an applicable Article 9 condition and any additional requirement under the Data Protection Act 2018 must also be satisfied. Where criminal-offence data is disclosed, the requirements of Article 10 of the UK GDPR and the Data Protection Act 2018 must be satisfied.
DBS certificate information will only be disclosed to persons who are lawfully entitled to receive it. Where the Police Act 1997 or the DBS Code of Practice applies, {{org_field_name}} will comply with the applicable restrictions governing disclosure and handling of that information.
Candidates will be provided with information about categories of recipients or disclosures as required by data-protection legislation. Consent will only be obtained where consent is the appropriate lawful basis for the relevant processing.
11. Data Storage and Security
{{org_field_name}} will implement appropriate technical and organisational measures to protect candidate personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
Candidate information will be stored using security measures appropriate to the nature, sensitivity and risk associated with the information. These measures will include, where applicable:
- restricting access to authorised personnel who require the information for their duties;
- protecting electronic systems and accounts against unauthorised access;
- securely storing paper records and other physical records;
- applying appropriate controls to the transmission and sharing of personal data;
- maintaining appropriate measures for the confidentiality, integrity and availability of systems processing candidate data; and
- securely disposing of records when the applicable retention period expires.
Special category data and criminal-offence data, including DBS information, will be subject to access controls appropriate to the sensitivity of the information.
Where {{org_field_name}} uses a processor to process candidate personal data on its behalf, the processor will be appointed subject to the requirements of Article 28 of the UK GDPR, including a legally compliant written contract governing the processing.
12. Data Retention and Disposal
{{org_field_name}} will retain candidate personal data only for as long as it is necessary for the purpose for which it was collected or subsequently lawfully processed, or for as long as retention is required by applicable legislation.
Retention periods will be determined by reference to:
- the purpose for which the information is held;
- statutory or regulatory retention requirements;
- the nature and sensitivity of the information;
- any continuing contractual, employment, taxation or legal obligations; and
- the need to establish, exercise or defend legal claims where applicable.
Employment Agency and Employment Business Records
Records required under regulation 29 of the Conduct of Employment Agencies and Employment Businesses Regulations 2003 will be retained for at least the minimum period required by those Regulations.
Where regulation 29 requires records concerning an application from a work-seeker or hirer to be retained, the relevant records will be kept for at least one year from their creation and, where applicable, for at least one year after the date on which {{org_field_name}} last provides services to the relevant applicant, subject to the precise requirements and exceptions in the Regulations.
Such records may be retained electronically provided that they are capable of being reproduced in legible form and remain accessible as required by law.
DBS Certificate Information
DBS certificate information will not be retained for longer than is necessary for the purpose for which it was obtained.
Where {{org_field_name}} is subject to the DBS Code of Practice in relation to a certificate, the certificate or copy of the certificate will normally be retained for no longer than six months after the relevant recruitment or suitability decision, unless exceptional circumstances justify longer retention and such retention is lawful.
When the relevant retention period expires, any retained copy or representation of DBS certificate information will be securely destroyed. {{org_field_name}} may retain those limited details that it is lawfully permitted to retain, such as the date of issue, the name of the individual, the type of certificate, the position for which it was requested and the certificate reference or other permitted administrative information.
Other Candidate Records
Other candidate records will be retained in accordance with {{org_field_name}}’s applicable retention schedule. No category of candidate personal data will automatically be retained for six years merely because it forms part of a candidate file. Where a six-year retention period is used for a particular category of information, {{org_field_name}} must be able to identify and document the reason for that retention period.
At the end of the applicable retention period, personal data will be securely deleted, destroyed or anonymised unless further retention is required or permitted by law.
13. Candidate Data Protection Rights
Subject to the conditions, limitations and exemptions provided by data-protection legislation, candidates have rights in relation to their personal data, including:
- the right to be informed about the processing of their personal data;
- the right to obtain confirmation as to whether their personal data is being processed and to obtain access to that data;
- the right to request rectification of inaccurate personal data and completion of incomplete personal data;
- the right to request erasure of personal data in circumstances where the statutory right to erasure applies;
- the right to request restriction of processing in circumstances specified by law;
- the right to data portability where the statutory conditions for that right are met;
- the right to object to processing in circumstances specified by law; and
- rights and safeguards relating to decisions based solely on automated processing that produce legal effects concerning the individual or similarly significantly affect them.
Candidates may submit a request to exercise a data-protection right to {{org_field_name}} using the contact arrangements notified to them.
{{org_field_name}} will respond to requests within the period required by applicable data-protection legislation. Where legislation permits the response period to be extended, the candidate will be informed of the extension and the reasons for it within the applicable statutory period.
Where {{org_field_name}} has reasonable doubts concerning the identity of a person making a request, it may request additional information necessary to confirm that person’s identity.
Where a request is manifestly unfounded or excessive, {{org_field_name}} may take the action permitted by data-protection legislation and will provide the individual with the information required by law.
Where {{org_field_name}} makes a decision based solely on automated processing that produces legal effects concerning a candidate or similarly significantly affects them, it will ensure that the processing has a lawful basis and that the safeguards required by the UK GDPR are provided. This includes enabling the individual, where required by law, to make representations about the decision, obtain human intervention and contest the decision.
14. Data Protection Complaints
{{org_field_name}} will provide candidates and other data subjects with an appropriate means of making a complaint about the way in which their personal data has been processed.
A data-protection complaint may be made using the contact arrangements provided by {{org_field_name}}, including an appropriate electronic means of submitting a complaint.
When {{org_field_name}} receives a data-protection complaint, it will:
- acknowledge receipt of the complaint within 30 days of receiving it;
- take appropriate steps to investigate and respond to the complaint without undue delay;
- make appropriate enquiries into the subject matter of the complaint;
- keep the complainant appropriately informed about the progress of the complaint; and
- inform the complainant of the outcome of the complaint without undue delay.
The Director will ensure that data-protection complaints are recorded and handled in accordance with applicable data-protection legislation.
Where applicable, the complainant will also be informed of their right to raise their concerns with the Information Commissioner’s Office and of any other rights of redress available under data-protection legislation.
Making a complaint to {{org_field_name}} does not remove or restrict any statutory right the individual may have to make a complaint to the Information Commissioner’s Office.
15. Training
All staff will receive:
- Data protection and confidentiality training during induction
- Annual refresher training
- Additional training if required following incidents or updates to legislation
The Director will ensure training remains current and relevant.
16. Personal Data Breach Management
A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
All members of staff must immediately report any suspected or confirmed personal data breach to the Director in accordance with {{org_field_name}}’s breach-reporting procedures.
The Director will ensure that each suspected or confirmed breach is promptly investigated and assessed, including consideration of:
- the nature and circumstances of the breach;
- the categories and approximate number of affected individuals and personal-data records where these can be established;
- the likely consequences for affected individuals; and
- the measures taken or proposed to contain the breach and mitigate its possible adverse effects.
Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, {{org_field_name}} will notify the Information Commissioner’s Office without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach.
Where notification to the Information Commissioner’s Office is made later than 72 hours after {{org_field_name}} became aware of a reportable breach, the notification will be accompanied by reasons for the delay as required by law.
Where a personal data breach is likely to result in a high risk to the rights and freedoms of an affected individual, {{org_field_name}} will communicate the breach to that individual without undue delay unless an applicable statutory exception removes that requirement.
{{org_field_name}} will document personal data breaches, including the facts relating to the breach, its effects and the remedial action taken, to the extent required by data-protection legislation. This record will be maintained whether or not the breach is reportable to the Information Commissioner’s Office.
17. Governance and Quality Assurance
The Director will:
- Conduct annual audits of data handling and confidentiality compliance
- Investigate and address data handling incidents or complaints
- Maintain records of staff training and awareness
- Monitor compliance with this policy and all applicable data protection laws
18. Director’s Oversight
The Director is responsible for:
- Ensuring that this policy is implemented effectively
- Overseeing all matters relating to data protection and confidentiality
- Ensuring that data processing practices remain aligned with legal, regulatory, and best practice requirements
- Promoting a culture of confidentiality and data protection among all staff
19. Policy Review
This policy will be reviewed by the Director at least annually and sooner where necessary following a material change in applicable legislation, regulatory requirements or {{org_field_name}}’s processing activities, or following a significant personal data breach or other event indicating that the policy requires amendment.
The review will take account of applicable data-protection legislation, including the UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025, together with legislation and statutory requirements applying to {{org_field_name}} in its capacity as an employment agency or employment business.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.