Data processing agreement for a recruitment agency

A data processing agreement for a recruitment agency providing managed or outsourced recruitment services, drafted for the agency with the privacy notice, for a fixed fee of £795 in five working days.

Share

Data processing agreement for a recruitment agency

A data processing agreement for a recruitment agency where one is needed, drafted for the agency, covering why most recruitment is controller work and when a DPA is needed at all, the services that make an agency a processor, the mandatory terms for managed and outsourced recruitment, the client's applicant tracking system and whose it is, candidate data flowing both ways and the data sharing alongside, and the end of a managed service and the candidates in the system. £795 with the privacy notice, delivered in five working days.

Buy now, £795

A recruitment agency is usually a controller of its candidates' data, deciding whom to approach, what to hold and which roles to put them forward for, so that most of its relationships with clients are controller-to-controller and need a data sharing arrangement rather than a data processing agreement; but where the agency runs the client's recruitment process, manages the client's applicant tracking system or provides an outsourced recruitment function on the client's instructions, it is a processor for that service and the client is legally required to have a DPA with it. The agreement has to say which services it covers, carry the mandatory terms for them, deal with the client's systems and the candidates in them, and sit alongside the data sharing terms for the rest. I draft both documents (the data processing agreement and the privacy notice) for the business, with a note on the operational steps they assume, for £795 fixed in five working days.

Who this is for

Recruitment agencies, recruitment process outsourcing providers, managed service providers for contingent labour and executive search firms in England and Wales providing services on clients' instructions.

What matters in a recruitment agency's data processing agreement

Why most recruitment is controller work and when a DPA is needed at all

An agency that finds candidates, holds them on its database, decides which to put forward and introduces them to clients determines the purposes and means of that processing and is a controller, as the Conduct of Employment Agencies and Employment Businesses Regulations 2003 assume, so that the client receiving an introduction is a separate controller and the two need a data sharing arrangement (which the agency's terms of business can contain) rather than a DPA; a client that insists on a DPA for ordinary introductions has misunderstood the roles, and the agency should explain why.

The services that make an agency a processor

The agency becomes a processor where it provides a service on the client's instructions using the client's data or process: running the client's recruitment campaigns through the client's applicant tracking system, managing the client's candidate pipeline, screening the client's own applicants, providing an outsourced recruitment function, administering a contingent workforce programme, or onboarding and referencing on the client's behalf; A written contract with the terms listed in Article 28 of the UK GDPR is mandatory for every controller and processor relationship for those services, and the DPA should define the processor services precisely and say that the agency's own sourcing and database remain controller activities covered by its own notice.

The mandatory terms for managed and outsourced recruitment

For the processor services the DPA must set out the processing's subject matter, how long it lasts, its nature and purpose, which data and which people are concerned, and the controller's obligations and rights, with the schedule describing the client's applicants, candidates and hires, their application, assessment, referencing and onboarding data (including special category data where the client's process collects it), the screening, scheduling, communication and administration the agency performs, and the instructions (the service agreement and the client's process); the agency must process only on documented instructions, keep confidentiality, secure the data as Article 32 requires, use authorised sub-processors on matching terms, assist with rights requests and with the client's security, breach and impact assessment duties, return or delete the data at the end, and make compliance demonstrable through information and audit.

The client's applicant tracking system and whose it is

Where the agency works in the client's applicant tracking system, the system's provider is the client's processor under the client's subscription and the agency's staff are the client's authorised users, bound by the DPA's confidentiality and security obligations and removed on termination; where the agency uses its own system for the client's process, the system provider is the agency's sub-processor needing authorisation and flow-down under Article 28(2) and (4), with the international transfers under Article 46 of the UK GDPR stated; the DPA should say which, should treat the agency's own tools as sub-processors, and should address the automated screening the tools perform under Article 22 as amended by the Data (Use and Access) Act 2025, which the client as controller must have assessed.

Candidate data flowing both ways and the data sharing alongside

A managed service usually involves candidates the agency sourced as a controller entering the client's process where the agency is a processor, and the DPA should say that the agency's own database remains its own, that candidates the agency introduces are shared with the client under the data sharing terms in the agency's terms of business (purpose, the client's own notice, the client's use limited to the recruitment, no retention beyond it), and that the client's applicants screened by the agency are not added to the agency's database without the client's agreement and the candidate's notice under Article 14; the two sets of terms should be consistent, and the Information Commissioner's data sharing code of practice under section 121 of the Data Protection Act 2018 is the standard for the sharing side.

The end of a managed service and the candidates in the system

At the end the DPA should provide for the hand-over of the client's pipeline and records in the client's system or in a usable export, the removal of the agency's access, the deletion of the client's data the agency holds within a set period and certified on request, the retention the agency needs under the 2003 Regulations and its own legitimate interests, and the position of candidates in the agency's own database who were also in the client's process (they stay with the agency as its own candidates where they were sourced by it); data protection liability sits within the service agreement's cap and each party is liable under Article 82 of the UK GDPR for its own breaches, and the agency's own privacy notice covers the controller side.

What it costs

DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.

Review of a customer's DPA, £495. They sent theirs and you need to know what you are accepting. Returned marked up with the changes to ask for and an explanation. Three working days.

Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
  • A privacy notice written for people to read rather than to be scrolled past
  • Clear allocation of controller and processor roles, which is where most confusion starts
  • International transfer provisions where you use overseas suppliers
  • Sub-processor and security provisions proportionate to what you do
  • A note on the operational steps the documents assume you are taking

What is not included

  • Full compliance audits and data mapping exercises
  • ICO registration, which you do yourself
  • Breach response and regulatory correspondence
  • Cyber security certification such as Cyber Essentials
  • Advice on data protection law outside the UK and EU

Questions I am often asked

A client wants a DPA before we introduce any candidates. Do we need one?

Not for ordinary introductions, where the agency is a controller and the client is another; that needs data sharing terms, which the agency's terms of business can contain. A DPA is for services run on the client's instructions, such as managing the client's system or process.

We run our client's recruitment in their applicant tracking system. What is our role?

A processor for that service, with the client's system provider as the client's processor and the agency's staff as authorised users. The DPA covers the service and says that the agency's own database stays its own.

Can we add the client's applicants to our own database?

Only with the client's agreement and the candidate's notice, because the applicants came to the client. The DPA says so, and candidates the agency sourced itself remain its own.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.