Under UK GDPR, recruiters must have a lawful basis to hold a candidate's CV, tell candidates how long it will be kept, and delete it on request. A CV is personal data, so data protection law applies the moment it lands in your inbox. In practice this comes down to five duties you can act on: pick a lawful basis to hold the CV, keep it no longer than you can justify, answer candidate rights requests, share only what a client needs, and stop and delete when a candidate withdraws consent.
This guide explains those five obligations in plain English and turns them into a simple workflow you can follow from receipt to deletion. It is written for UK recruitment agencies and draws on Information Commissioner's Office (ICO) guidance.
This is general guidance, not legal advice. Data protection depends on your specific facts, and the rules can change. The ICO is updating its employment guidance to reflect the Data (Use and Access) Act 2025, but the core duties in this post still apply. Check the current ICO guidance and take professional legal advice before you rely on anything here, and confirm your own obligations. If you operate outside the UK, check your local data protection law instead.
Key takeaways
- A candidate's CV is personal data under UK GDPR, so data protection law applies the moment you receive it.
- You need a lawful basis to hold a CV. Legitimate interests is often sturdier than consent, which a candidate can withdraw at any time.
- UK GDPR sets no fixed retention limit, but the ICO says you should not keep unsuccessful applicants beyond the statutory claim window without a clear business reason.
- Respond to access and erasure requests within one month, extendable by two more for complex or numerous requests. Share only what a client needs.
- If you relied on consent and the candidate withdraws it, the right to erasure applies, so delete the CV unless an exemption lets you keep it.
- This is general guidance, not legal advice. Check the current ICO guidance and take professional advice for your agency.
Why it matters
CVs are among the most detailed personal data an agency handles. A single CV can hold a name, contact details, employment history, education, and sometimes more. The ICO's recruitment and selection guidance is designed to help recruiters understand their data protection obligations under UK GDPR and the Data Protection Act 2018 when handling candidate information, covering activities such as identifying, selecting, verifying, and vetting candidates. So handling CVs well is part of the job, not an optional extra.
Getting it right protects candidates and supports your agency. Candidates trust you with their information, and clients expect you to handle it responsibly. Clear processes around lawful basis, privacy notices, retention, and security help you work with the seven data protection principles and show you are accountable. They also make subject access and erasure requests easier to deal with when they arrive.
The five obligations recruiters actually face
Most of UK GDPR lands on a recruiter as five concrete duties. Get these right and you have covered the ground that matters most when you handle a candidate CV.
1. A lawful basis to hold the CV
You must identify a lawful basis before you process a CV. The ICO advises that organisations often have a choice between legitimate interests and consent. Legitimate interests is the most flexible but requires a three-part balancing test. It is also often the sturdier choice for a recruiter, because consent can be withdrawn at any time. Whichever you pick, record it.
2. A retention period you can justify
Under storage limitation, UK GDPR does not set a specific time limit, so you must justify your own. The ICO says you should not keep recruitment records for unsuccessful applicants beyond the statutory period in which a claim could be brought, unless there is a clear business reason. The base window for an Equality Act 2010 discrimination claim is three months less one day. Because early conciliation and late claims can push that back, many agencies keep unsuccessful CVs for around six months as a safe margin, then delete or anonymise.
3. Candidate rights requests
Candidates have a right of access to a copy of their data and a right to erasure. You must respond without undue delay and within one month. You can extend by up to two further months if the request is complex or you receive several from one person, but you must tell the candidate within the first month and explain why. Erasure does not apply where you are legally required to keep the data.
4. Sharing with clients
Sending a CV to a client is a further processing act. You need a lawful basis (often legitimate interests, not necessarily consent), and your privacy notice must tell candidates who you share data with. Apply data minimisation: send the client only the information they need to decide, not your full file. Anonymising or trimming the CV first keeps this in check.
5. When consent is withdrawn
UK GDPR requires that it must be as easy to withdraw consent as to give it, so offer candidates an easy way to withdraw at any time. If you relied on consent and the candidate withdraws it, the right to erasure applies, so stop processing on that basis and delete the CV, unless another lawful basis or a legal-retention exemption genuinely applies.
The sharing and minimisation duties are where a formatting workflow helps most. For practical steps, see what to remove from a CV before client submission and how to anonymise a CV for blind recruitment.
The groundwork behind the five
Those five duties sit on a few basics the ICO applies to any personal data. Keep them in view as you work.
A CV is personal data
The ICO defines personal data as any information relating to an identified or identifiable person. A CV contains a name and other identifying details, so it counts as personal data and data protection law applies whenever you process it.
Follow the seven principles
UK GDPR Article 5 sets out seven principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; security (integrity and confidentiality); and accountability. The ICO summarises the first as using personal data in a way that complies with the law and that people expect and have been told about.
Be transparent with a privacy notice
Candidates have the right to be informed. Give them privacy information that is concise, transparent, intelligible, and easily accessible, in clear and plain language. Cover your purposes, your retention periods, and who you will share the data with. Provide it at the time of collection, or within a reasonable period and no later than one month if you obtained the CV from a job board or other source.
Keep data minimal, accurate, and secure
Collect and use only the data you need for the role, and keep candidate details correct and up to date. Store CVs securely with appropriate technical and organisational measures on a risk-based approach, and limit who can access candidate files. Take extra care with any special category data, which needs a separate Article 9 condition on top of your lawful basis.
A compliance workflow, step by step
Step 1: Decide your lawful basis before you process
When a CV arrives, be clear why you are processing it and on what lawful basis. The ICO advises that organisations often have a choice between legitimate interests and consent. If you use legitimate interests, run the three-part balancing test and keep a record. If you use consent, make sure the candidate can withdraw it.
Step 2: Give the candidate privacy information
Tell the candidate what you are doing with their CV. If they sent it directly, provide your privacy notice at the time of collection. If you sourced it from a job board or third party, provide the privacy information within a reasonable period and no later than one month. Cover your purposes, retention, and who you share data with.
Step 3: Send clients only what they need
Apply data minimisation. Check the CV holds only data relevant to the role, and keep details accurate. When you submit a candidate to a client, send only the information the client needs to make a decision rather than everything you hold. Trimming or anonymising the CV before you send it keeps the sharing step in line.
Step 4: Store the CV securely
Apply appropriate technical and organisational measures to protect the CV. Take a risk-based approach covering cybersecurity, physical security, and organisational controls. Limit who can access candidate files and avoid sharing CVs over insecure channels.
Step 5: Handle rights and withdrawn consent
Be ready to respond if a candidate asks for a copy of their data, asks you to delete it, or withdraws consent. You have one month to respond, extendable by up to two further months for complex or numerous requests if you tell the candidate within the first month. If you relied on consent and it is withdrawn, the right to erasure applies. The right does not apply where you are legally required to keep the data, so check for an exemption before refusing.
Step 6: Review and delete on schedule
Apply your retention policy. Keep CVs only as long as you can justify. The ICO says you should not hold records for unsuccessful applicants beyond the statutory claim window without a clear business reason, so delete or anonymise them once that period passes. If you have no policy, the ICO says review the data regularly and delete or anonymise anything you no longer need.
Do this every time
- Identify and record a lawful basis before you process a candidate's CV.
- Give every candidate clear privacy information at the right time, covering your purposes, retention, and sharing.
- Send clients only the candidate data they need, not your full file.
- Write a retention policy that lists what you hold, why, and for how long, tied to the statutory claim window for unsuccessful applicants.
- Store CVs securely with access limited to people who need them.
- Respond to access and erasure requests within one month, extendable by two more for complex or numerous requests.
- Give candidates an easy way to withdraw consent, and delete the CV if you relied on consent and it is withdrawn.
- Keep candidate details accurate and correct or remove anything wrong.
- Check the current ICO guidance and take legal advice for your own situation.
Common mistakes to avoid
Keeping CVs indefinitely
Holding candidate CVs longer than you can justify works against the storage limitation principle. UK GDPR sets no fixed limit, but the ICO says you should not keep unsuccessful applicants beyond the statutory claim window without a clear business reason. Set a policy and delete or anonymise data you no longer need.
No privacy notice
Failing to tell candidates what you do with their data works against the right to be informed. Give clear, plain privacy information at collection, or within a month if you sourced the CV elsewhere.
Over-collecting data
Gathering or forwarding more than the role requires works against data minimisation. Collect and share only the candidate data you actually need for that position.
Relying only on consent
Treating consent as the only option can be limiting, because consent can be withdrawn and gives the candidate full control. The ICO notes organisations often have a choice between legitimate interests and consent. Pick the basis that genuinely fits and document it.
Sharing CVs insecurely
Sending CVs over unprotected channels or leaving files open to everyone works against the security principle. Use appropriate technical and organisational measures and limit access.
Ignoring erasure requests
Brushing off deletion requests works against the right to erasure. You have one month to respond, extendable by up to two further months for complex or numerous requests if you tell the candidate in time. The right does not apply where you are legally required to keep the data.
Frequently asked questions
Is a CV personal data under GDPR?
Yes. The ICO defines personal data as any information relating to an identified or identifiable person, who can be identified directly or indirectly by identifiers such as a name. A CV contains a candidate's name and other identifying details, so it is personal data and UK GDPR applies whenever you process it. That means the data protection principles cover how you collect, store, share, and delete it.
What is the lawful basis for processing a candidate's CV?
You must identify a lawful basis before you process. The ICO advises that organisations often have a choice between legitimate interests and consent. Legitimate interests is the most flexible but requires a three-part balancing test that weighs your interests against the candidate's rights and freedoms. If you use consent instead, the candidate must have full control, including the ability to withdraw it. Record the basis you rely on.
How long can a recruiter keep a candidate's CV?
UK GDPR sets no fixed time limit. You must keep a CV no longer than necessary and justify your own retention period. For unsuccessful applicants the ICO says you should not keep recruitment records beyond the statutory period in which a claim could be brought, unless there is a clear business reason. The base window for an Equality Act 2010 discrimination claim is three months less one day, and early conciliation or late claims can push that back, so many agencies keep unsuccessful CVs for around six months as a safe margin, then delete or anonymise. Write this into a retention policy that lists what you hold, why, and for how long.
Do I need a candidate's consent to send their CV to a client?
Not necessarily. Consent is one lawful basis, but the ICO advises that organisations often have a choice between legitimate interests and consent for processing. You need a valid lawful basis and you must be transparent through your privacy notice about who you share data with. Whatever basis you use, apply data minimisation and send the client only the candidate information they need. This is general guidance, so check the ICO and take advice for your situation.
What happens if a candidate withdraws consent or asks me to delete their CV?
UK GDPR says it must be as easy to withdraw consent as to give it, so offer candidates a simple way to withdraw at any time. If you relied on consent and it is withdrawn, the right to erasure applies, so you should delete the CV unless a legal-retention exemption applies. A candidate can also ask for erasure directly, verbally or in writing. You must respond within one month, extendable by up to two further months for complex or numerous requests if you tell them within the first month. Candidates also have a right of access to a copy of the data you hold about them.
What about sensitive details on a CV?
Some CVs include special category data, such as health, ethnicity, or religion. UK GDPR gives this extra protection, so you need a separate Article 9 condition in addition to your ordinary lawful basis before you process it. Apply the same principles of minimisation, security, and transparency, and avoid keeping sensitive information you do not need. Because this area is more involved, check the current ICO guidance and take legal advice before relying on it.
The bottom line
Handling candidate CVs well comes down to a few clear duties. Treat every CV as personal data. Identify a lawful basis. Tell candidates what you are doing through a clear privacy notice. Collect only what you need, keep it accurate, store it securely, and do not keep it longer than you can justify. Be ready to honour rights such as access and erasure. Doing these consistently addresses much of what UK GDPR asks of a recruiter.
This is general guidance, not legal advice. Your obligations depend on your specific facts, and the rules can change. Check the current ICO guidance and take professional legal advice before you act, and confirm your own obligations. If you work outside the UK, follow your local data protection law instead.
A formatting tool will not make your agency compliant, but it can help with the data minimisation step. RefineCV lets you reformat a candidate CV, remove details you do not need to send, and replace the candidate's direct contact with your agency's before you export a clean PDF or DOCX for the client. See transparent pricing or compare it with other CV formatting tools. Try it free on 10 CVs, no card.
Send clients only what they need
RefineCV reformats a CV and strips anything the client does not need before export. Start free with 10 CVs, no credit card, then $0.40 per CV or $50 a month for 200.
Related reading: what to remove from a CV before sending to a client, how to anonymise a CV for blind recruitment, and how to anonymise resumes for client submissions.
Sources
- ICO, What is personal data? (2025): A candidate's CV is personal data under UK GDPR because the ICO defines personal data as any information relating to an identified or identifiable person, who can be identified by identifiers such as a name.
- ICO, A guide to the data protection principles (2025): UK GDPR Article 5 sets out seven data protection principles, and the ICO summarises lawfulness, fairness and transparency as using data in a way that complies with the law and that people expect and have been told about.
- ICO, Employment practices and data protection: recruitment and selection (2025): The ICO's recruitment and selection guidance helps recruiters understand their data protection obligations under UK GDPR and the Data Protection Act 2018 when handling candidate information.
- ICO, A guide to lawful basis (2025): The ICO advises that organisations often have a choice between legitimate interests (which requires a three-part balancing test) and consent (which the individual can withdraw).
- ICO, What privacy information should we provide? (The right to be informed) (2025): Privacy information must be concise, transparent, intelligible, easily accessible and in clear plain language, covering purposes, retention and sharing, provided at collection or within one month if obtained from another source.
- ICO, Principle (e): Storage limitation (2025): Under storage limitation, UK GDPR does not set specific time limits, so recruiters must justify their own retention periods, and a retention policy helps demonstrate compliance.
- ICO, The employment practices code (2011): Recruitment records for unsuccessful applicants should not be kept beyond the statutory period in which a claim arising from the recruitment process could be brought, unless there is a clear business reason.
- Equality and Human Rights Commission, Time limits for discrimination claims (2025): The time limit to bring a discrimination claim under the Equality Act 2010 is normally three months less one day from the act complained of, though a tribunal may extend it where just and equitable.
- ICO, Right to erasure and right of access (2025): Candidates have a right of access to a copy of their data and a right to erasure, with organisations generally having one month to respond, and erasure not applying where the organisation is legally required to keep the data.
- ICO, A guide to subject access (2025): You must respond to a subject access request within one month, extendable by up to two further months for complex or numerous requests if you tell the person within the first month.
- ICO, Consent (2025): UK GDPR requires that it must be as easy to withdraw consent as to give it, and where you rely on consent and it is withdrawn, the right to erasure applies.
- ICO, Special category data (2025): Processing special category data on a CV, such as health or ethnicity, requires a separate Article 9 condition in addition to an Article 6 lawful basis.
- ICO, A guide to data security (2025): The security principle requires appropriate technical and organisational measures using a risk-based approach covering cybersecurity, physical and organisational measures.