Privacy compliance for Australian recruitment agencies: the employee-records exemption does not cover the people you actually hold data on.
A recruitment or staffing agency's files are full of candidates, and candidates are not your employees. The Privacy Act's employee-records exemption covers a business's own current and former staff, so it does very little for an agency whose core data is other people's job applicants. On top of that, from 10 December 2026, if your applicant-tracking system scores, ranks or auto-rejects candidates, that is an automated decision the law now expects you to disclose. This page is about the privacy obligations that come with holding candidate data, honestly and without inventing a deadline you do not face.
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
Are you covered by the Privacy Act? The honest answer for recruiters
There is no anti-money-laundering trigger for recruitment and no single 2026 switch-on date. But the common assumption, "we are a small agency, so we are exempt", is weaker here than in most industries, for two reasons:
- The employee-records exemption is about your own staff, not candidates. It covers records directly related to your current or former employees' employment. Job applicants and candidates are not your employees, so the exemption generally does not reach the data you hold about them. The Office of the Australian Information Commissioner has said the exemption is unlikely to apply to organisations providing recruitment or human-resource-management services under contract to an employer . So the very data an agency is built on, candidate files, sits under the Australian Privacy Principles.
- The small-business exemption may not save you either. A business under A$3 million turnover is often outside the APPs (s 6D), but that exemption can be lost if you disclose personal information about someone to another person for a benefit, or provide a service to collect it. A recruitment agency that provides candidate information to employer clients for a fee engages those words. The carve-out matters though, and it usually helps you: s 6D(7) takes out disclosures the individual consented to, and a candidate who asked to be put forward has consented to exactly that. So the limb bites mainly where you go beyond the consent, which is one of the things that removes the small-business exemption . Read: does the Privacy Act apply to recruitment agencies?
So the honest first step is not to assume you are exempt. Read: employee records vs candidate records, what the Privacy Act actually covers
Why a recruiter's data is unusually exposed
You hold a concentrated pool of other people's most sensitive career and identity information: identity and right-to-work documents, CVs and references, background and police checks, pre-employment medicals, and increasingly candidate scores and rankings produced by your tools. Two categories raise the bar:
- Police checks and pre-employment medicals are sensitive information under the Privacy Act, which carries a higher consent and handling standard than ordinary personal information. Read: police checks and medicals, handling sensitive candidate information
- Candidate data often crosses borders, through offshore recruiters, overseas screening providers or virtual assistants, which brings APP 8 into play. Read: offshore recruiters and overseas screening, your APP 8 duty
A breach of these files exposes people who trusted you with their livelihood. Read: a data-breach response plan for recruitment agencies
The two issues no generic template handles
1. Your ATS and the 10 December 2026 automated-decision rule. From 10 December 2026, if you use automated decision-making that significantly affects a person, your privacy policy must disclose it (APP 1.7). Hiring is squarely in scope: an applicant-tracking system that scores, ranks, shortlists or auto-rejects candidates is making an automated decision about them. This is a transparency and disclosure duty, not a ban, but a generic privacy policy will not mention it, and from that date it is expected to. Read: the ADM rule and your ATS, what recruiters must disclose
2. Employee records versus candidate records. The line between the staff you employ (partly covered by the employee-records exemption) and the candidates you place (under the APPs) is the single most misunderstood point in recruitment privacy, and it changes what notice, consent and access obligations you owe for each. Most templates blur the two. Read: employee records vs candidate records
What a recruitment agency actually needs
1. A privacy policy written for a recruitment or staffing business, including the APP 1.7 automated-decision disclosure for your ATS, not a generic website template. 2. A candidate collection notice (APP 5) for the real collection points: the job ad, the application form, the ATS, and information you gather about a candidate from third parties such as referees. 3. A sensitive-information procedure for police checks and medicals, with the higher consent standard built in. 4. A data-breach response plan for the Notifiable Data Breaches scheme, tuned to candidate identity and background data. 5. A retention and destruction schedule. There is no AML record-keeping floor here and, for unsuccessful candidates, generally no statutory minimum at all, so the risk is keeping candidate files far longer than you can justify. Your own employee records are a separate matter (Fair Work record-keeping applies to staff). Read: how long should a recruitment agency keep candidate records?
A blanket privacy-policy generator covers none of this: not the ATS disclosure, not the candidate-versus-employee line, not sensitive screening, not the retention problem.
What Privaproof is building for recruitment agencies
A dedicated, recruitment-specific privacy document set, written for agency and staffing work, and kept current as the law changes.
- Written for recruiters: candidates, screening, the ATS and its automated decisions, offshore providers, the employee-versus-candidate line.
- Practical, plain-English documents you tailor to your business, with guidance built in.
- Kept current: while your subscription is active, we monitor the law and aim to provide updated versions as it changes, including the 10 December 2026 automated-decision-making rule. This is not a guarantee of compliance, and does not replace your own legal advice.
These are compliance tools and templates you tailor to your own business. They are general information, not legal advice, and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner.
Join the founding list
Be first to know when the Recruitment Kit opens, and get the plain-English updates as the 2026 changes land. No cost, no obligation.
✓ You’re on the founding list. We’ll email you as the changes land.
We never sell your data. See our Privacy Policy.
Keep reading
- Does the Privacy Act apply to recruitment agencies?
- The ADM rule and your ATS: what recruiters must disclose (from 10 December 2026)
- Employee records vs candidate records: what the Privacy Act actually covers
- What a recruitment agency's privacy policy must cover
- The candidate collection notice you need at application
- Police checks and medicals: handling sensitive candidate information
- Offshore recruiters and overseas screening: your APP 8 duty
- A data-breach response plan for recruitment agencies
- How long should a recruitment agency keep candidate records?
- In-house HR vs recruitment agency: who is covered?
- Consent to collect candidate ID and background information
- What does privacy compliance cost a recruitment agency?
- Do labour-hire firms need a privacy policy?
General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether the Privacy Act 1988 (Cth) applies to your business depends on your turnover, structure and how you handle candidate data; the employee-records exemption applies to your own staff, not to job candidates. Privaproof's recruitment documents are self-authored and are not independently reviewed by a solicitor. The law changes over time, so check you are working from a current version.