Skip to content

The employee-records exemption does not cover the candidates you place

Place candidates?

10 Dec 2026automated decisions
must be disclosedin your privacy policy

The employee-records exemption covers your own staff records. It does not reach the candidates you place, so their information sits under the Australian Privacy Principles.

Your privacy policy is one of the fourteen. The other thirteen are what your team actually does.

14 documentsGuided tailoringKept current
13Grounded in the
Privacy Act & 13 APPs
Australian-made for
Australian recruitment agencies

The Recruitment Kit

Fourteen editable Word documents, built around what a recruitment agency actually holds and does.

Handle information properlyPolicy, collection, screening consent and retentionView 4 documentsHide documents
  • Privacy Policy
  • Collection Notice
  • Candidate Screening and Sensitive-Information Procedure
  • Document Retention and Destruction Schedule
Give your team clear directionTraining, roles, and what you holdView 3 documentsHide documents
  • Staff Privacy Training and Confidentiality Agreement
  • Privacy Officer Role and Internal Privacy Procedure
  • Data Inventory / "What We Hold" Map
Respond when something happensBreach, access and complaintsView 3 documentsHide documents
  • Data Breach Response Plan
  • Access and Correction Procedure
  • Privacy Complaint Handling Procedure
Your ATS, suppliers and marketingAutomated decisions, suppliers, consent and marketingView 4 documentsHide documents
  • Automated Decision Making and ATS Transparency Notice
  • Service Provider and Overseas Disclosure Clauses
  • Candidate Consent Form
  • Direct Marketing and Opt-Out Procedure

A$449 / year incl GST

No lock-in

When the privacy rules change, the updated documents are in your account. You do not write them again.

Includes the updates we make to the kit while your membership is active. Those track the Privacy Act and the Australian Privacy Principles, including the automated-decision transparency rule that starts on 10 December 2026. See what has changed

Get the Recruitment Kit →

Built for recruitment, not adapted from a generic small-business set. The screening-consent procedure and the ATS transparency notice are the two documents no generic template carries.

Fourteen documents. Not fourteen projects.

Four documents carry most of the tailoring. The rest use recurring business details, clear prompts and the order in the Start Here sheet.

  1. 1

    Two decisions, before you open a document

    Who your Privacy Officer is, and where the line falls between your own employee records and the candidate records you hold. The Start Here sheet settles the second in one table, and it changes what notice, consent and access obligations you owe for each.

  2. 2

    Nine details, filled in once

    Your business name, ABN, Privacy Officer and contact details are among the nine that recur across the kit. Fill them in once, then find and replace carries them through all fourteen documents in a few minutes.

What the work actually looks like

4Tailor carefully
6Fill in and read
2Adopt as they are
2Delete if they don't apply

14 documents

The Start Here sheet gives you the order to work in and an indication of the time involved. You receive the complete kit.

Three privacy checks for your agency

You can check all three today.

Collect

When a candidate applies, do you tell them what you collect, who you give it to, and what a reference or background check involves?

Protect

Could you list every place candidate CVs and screening results sit, including your ATS and anything a client or offshore contractor can reach?

Disclose

Does your ATS score, rank, shortlist or auto-reject candidates, and does your privacy policy say so?

A recruitment agency holds work history, referee comments, screening results and often identity documents for people who never became employees, and the employee-records exemption does not reach any of it.

Privacy Act 1988 (Cth), APP 1.7, APP 3, APP 5, APP 8, APP 11 and APP 11.2; the employee-records exemption in s 7B(3).

Privacy is part of candidate trust

87% of Australians are more concerned about their privacy than they were five years ago.

Candidates hand you their work history, their referees and often their identity documents, at a point in their lives when they have little leverage. A practical privacy system helps your team handle that with the care they increasingly expect.

Source: Office of the Australian Information Commissioner, Australian Community Attitudes to Privacy Survey 2026

A privacy policy is one document.

You may already have one. It is one of the fourteen.

Privacy policy

Says what you do

A statement for candidates, clients and your website.

vs

Practical procedures

Tell your team how

The steps behind privacy in everyday work.

The Recruitment Kit gives you the policy and the procedures behind it.

Automated decisions, from 10 December 2026

The rule your ATS brings forward

From 10 December 2026, if you use automated decision-making that significantly affects a person, your privacy policy must disclose it. Hiring is squarely in scope.

What the rule does not do

Ban automated screening · Require a human reviewer · Require candidate consent

Check your position if your ATS

Scores or ranks candidates
Shortlists automatically
Auto-rejects on set criteria
Matches candidates to roles without a person deciding

If it does, from 10 December 2026 your privacy policy has to say so, in terms a candidate can understand.

It is a transparency duty, not a ban, and it does not require you to change how you screen.

What does my ATS have to disclose? →

Legal detail and sources

APP 1.7 requires an APP entity's privacy policy to disclose the use of automated decision-making where a computer program is used to make, or do a thing substantially and directly related to making, a decision that significantly affects an individual's rights or interests. An applicant-tracking system that scores, ranks, shortlists or auto-rejects candidates is making an automated decision about them. Whether a particular use significantly affects rights or interests is fact-specific. The duty is disclosure in the policy; it does not prohibit automated screening and it does not by itself require consent or a human reviewer.

Privacy Act 1988 (Cth), APP 1.7, commencing 10 December 2026.

Put a practical privacy baseline in place

One complete 14-document privacy kit for Australian recruitment agencies. Guided tailoring for your agency, kept current as the privacy rules change.

A$449/year incl GST

General information and document templates you tailor, not legal advice. Written by Privaproof.

The detail, if you want it

The practical answer is above. The legal detail is here when you need it.

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

Are you covered by the Privacy Act? The honest answer for recruitersThe small-agency assumption is weaker here than in most industries, and the employee-records exemption is the reason.Read detailHide detail

There is no anti-money-laundering trigger for recruitment and no single 2026 switch-on date. But the common assumption, "we are a small agency, so we are exempt", is weaker here than in most industries, for two reasons:

  • The employee-records exemption is about your own staff, not candidates. It covers records directly related to your current or former employees' employment. Job applicants and candidates are not your employees, so the exemption generally does not reach the data you hold about them. The Office of the Australian Information Commissioner has said the exemption is unlikely to apply to organisations providing recruitment or human-resource-management services under contract to an employer . So the very data an agency is built on, candidate files, sits under the Australian Privacy Principles.
  • The small-business exemption may not save you either. A business under A$3 million turnover is often outside the APPs (s 6D), but that exemption can be lost if you disclose personal information about someone to another person for a benefit, or provide a service to collect it. A recruitment agency that provides candidate information to employer clients for a fee engages those words. The carve-out matters though, and it usually helps you: s 6D(7) takes out disclosures the individual consented to, and a candidate who asked to be put forward has consented to exactly that. So the limb bites mainly where you go beyond the consent, which is one of the things that removes the small-business exemption . Read: does the Privacy Act apply to recruitment agencies?

So the honest first step is not to assume you are exempt. Read: employee records vs candidate records, what the Privacy Act actually covers

Why a recruiter's data is unusually exposedWork history, referee comments, screening results and identity documents for people who never became employees.Read detailHide detail

You hold a concentrated pool of other people's most sensitive career and identity information: identity and right-to-work documents, CVs and references, background and police checks, pre-employment medicals, and increasingly candidate scores and rankings produced by your tools. Two categories raise the bar:

A breach of these files exposes people who trusted you with their livelihood. Read: a data-breach response plan for recruitment agencies

The two issues no generic template handlesThe 10 December 2026 automated-decision rule as it applies to your ATS, and the line between employee and candidate records.Read detailHide detail

1. Your ATS and the 10 December 2026 automated-decision rule. From 10 December 2026, if you use automated decision-making that significantly affects a person, your privacy policy must disclose it (APP 1.7). Hiring is squarely in scope: an applicant-tracking system that scores, ranks, shortlists or auto-rejects candidates is making an automated decision about them. This is a transparency and disclosure duty, not a ban, but a generic privacy policy will not mention it, and from that date it is expected to. Read: the ADM rule and your ATS, what recruiters must disclose

2. Employee records versus candidate records. The line between the staff you employ (partly covered by the employee-records exemption) and the candidates you place (under the APPs) is the single most misunderstood point in recruitment privacy, and it changes what notice, consent and access obligations you owe for each. Most templates blur the two. Read: employee records vs candidate records

What a recruitment agency actually needsA policy, collection notices, a screening-consent procedure, an ATS transparency notice, a breach plan and a retention schedule.Read detailHide detail
  • A privacy policy written for a recruitment or staffing business, including the APP 1.7 automated-decision disclosure for your ATS, not a generic website template.
  • A candidate collection notice (APP 5) for the real collection points: the job ad, the application form, the ATS, and information you gather about a candidate from third parties such as referees.
  • A sensitive-information procedure for police checks and medicals, with the higher consent standard built in.
  • A data-breach response plan for the Notifiable Data Breaches scheme, tuned to candidate identity and background data.
  • A retention and destruction schedule. There is no AML record-keeping floor here and, for unsuccessful candidates, generally no statutory minimum at all, so the risk is keeping candidate files far longer than you can justify. Your own employee records are a separate matter (Fair Work record-keeping applies to staff). Read: how long should a recruitment agency keep candidate records?

A blanket privacy-policy generator covers none of this: not the ATS disclosure, not the candidate-versus-employee line, not sensitive screening, not the retention problem.

What the Recruitment Kit covers

A dedicated, recruitment-specific privacy document set, written for agency and staffing work, and kept current as the law changes.

These are compliance tools and templates you tailor to your own business. For advice on your specific circumstances, consult a qualified Australian legal practitioner.

Keep up with the changes

Not buying today? Get the plain-English updates as the privacy rules change, and the notes on what they mean in practice. No cost, no obligation.

We never sell your data. See our Privacy Policy.

Keep reading


General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether the Privacy Act 1988 (Cth) applies to your business depends on your turnover, structure and how you handle candidate data; the employee-records exemption applies to your own staff, not to job candidates. The law changes over time, so check you are working from a current version.