The Recruitment Kit
Fourteen editable Word documents, built around what a recruitment agency actually holds and does.
Handle information properlyPolicy, collection, screening consent and retentionView 4 documentsHide documents
- Privacy Policy
- Collection Notice
- Candidate Screening and Sensitive-Information Procedure
- Document Retention and Destruction Schedule
Give your team clear directionTraining, roles, and what you holdView 3 documentsHide documents
- Staff Privacy Training and Confidentiality Agreement
- Privacy Officer Role and Internal Privacy Procedure
- Data Inventory / "What We Hold" Map
Respond when something happensBreach, access and complaintsView 3 documentsHide documents
- Data Breach Response Plan
- Access and Correction Procedure
- Privacy Complaint Handling Procedure
Your ATS, suppliers and marketingAutomated decisions, suppliers, consent and marketingView 4 documentsHide documents
- Automated Decision Making and ATS Transparency Notice
- Service Provider and Overseas Disclosure Clauses
- Candidate Consent Form
- Direct Marketing and Opt-Out Procedure
A$449 / year incl GST
When the privacy rules change, the updated documents are in your account. You do not write them again.
Includes the updates we make to the kit while your membership is active. Those track the Privacy Act and the Australian Privacy Principles, including the automated-decision transparency rule that starts on 10 December 2026. See what has changed
Get the Recruitment Kit →Built for recruitment, not adapted from a generic small-business set. The screening-consent procedure and the ATS transparency notice are the two documents no generic template carries.
Fourteen documents. Not fourteen projects.
Four documents carry most of the tailoring. The rest use recurring business details, clear prompts and the order in the Start Here sheet.
- 1
Two decisions, before you open a document
Who your Privacy Officer is, and where the line falls between your own employee records and the candidate records you hold. The Start Here sheet settles the second in one table, and it changes what notice, consent and access obligations you owe for each.
- 2
Nine details, filled in once
Your business name, ABN, Privacy Officer and contact details are among the nine that recur across the kit. Fill them in once, then find and replace carries them through all fourteen documents in a few minutes.
What the work actually looks like
14 documents
The Start Here sheet gives you the order to work in and an indication of the time involved. You receive the complete kit.
Three privacy checks for your agency
You can check all three today.
Collect
When a candidate applies, do you tell them what you collect, who you give it to, and what a reference or background check involves?
Protect
Could you list every place candidate CVs and screening results sit, including your ATS and anything a client or offshore contractor can reach?
Disclose
Does your ATS score, rank, shortlist or auto-reject candidates, and does your privacy policy say so?
A recruitment agency holds work history, referee comments, screening results and often identity documents for people who never became employees, and the employee-records exemption does not reach any of it.
Privacy Act 1988 (Cth), APP 1.7, APP 3, APP 5, APP 8, APP 11 and APP 11.2; the employee-records exemption in s 7B(3).
Privacy is part of candidate trust
87% of Australians are more concerned about their privacy than they were five years ago.
Candidates hand you their work history, their referees and often their identity documents, at a point in their lives when they have little leverage. A practical privacy system helps your team handle that with the care they increasingly expect.
A privacy policy is one document.
You may already have one. It is one of the fourteen.
Privacy policy
Says what you do
A statement for candidates, clients and your website.
Practical procedures
Tell your team how
The steps behind privacy in everyday work.
The Recruitment Kit gives you the policy and the procedures behind it.
Automated decisions, from 10 December 2026
The rule your ATS brings forward
From 10 December 2026, if you use automated decision-making that significantly affects a person, your privacy policy must disclose it. Hiring is squarely in scope.
What the rule does not do
Ban automated screening · Require a human reviewer · Require candidate consent
Check your position if your ATS
If it does, from 10 December 2026 your privacy policy has to say so, in terms a candidate can understand.
It is a transparency duty, not a ban, and it does not require you to change how you screen.
What does my ATS have to disclose? →
Legal detail and sources
APP 1.7 requires an APP entity's privacy policy to disclose the use of automated decision-making where a computer program is used to make, or do a thing substantially and directly related to making, a decision that significantly affects an individual's rights or interests. An applicant-tracking system that scores, ranks, shortlists or auto-rejects candidates is making an automated decision about them. Whether a particular use significantly affects rights or interests is fact-specific. The duty is disclosure in the policy; it does not prohibit automated screening and it does not by itself require consent or a human reviewer.
Privacy Act 1988 (Cth), APP 1.7, commencing 10 December 2026.
Put a practical privacy baseline in place
One complete 14-document privacy kit for Australian recruitment agencies. Guided tailoring for your agency, kept current as the privacy rules change.
A$449/year incl GST
General information and document templates you tailor, not legal advice. Written by Privaproof.
The detail, if you want it
The practical answer is above. The legal detail is here when you need it.
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
Are you covered by the Privacy Act? The honest answer for recruitersThe small-agency assumption is weaker here than in most industries, and the employee-records exemption is the reason.Read detailHide detail
There is no anti-money-laundering trigger for recruitment and no single 2026 switch-on date. But the common assumption, "we are a small agency, so we are exempt", is weaker here than in most industries, for two reasons:
- The employee-records exemption is about your own staff, not candidates. It covers records directly related to your current or former employees' employment. Job applicants and candidates are not your employees, so the exemption generally does not reach the data you hold about them. The Office of the Australian Information Commissioner has said the exemption is unlikely to apply to organisations providing recruitment or human-resource-management services under contract to an employer . So the very data an agency is built on, candidate files, sits under the Australian Privacy Principles.
- The small-business exemption may not save you either. A business under A$3 million turnover is often outside the APPs (s 6D), but that exemption can be lost if you disclose personal information about someone to another person for a benefit, or provide a service to collect it. A recruitment agency that provides candidate information to employer clients for a fee engages those words. The carve-out matters though, and it usually helps you: s 6D(7) takes out disclosures the individual consented to, and a candidate who asked to be put forward has consented to exactly that. So the limb bites mainly where you go beyond the consent, which is one of the things that removes the small-business exemption . Read: does the Privacy Act apply to recruitment agencies?
So the honest first step is not to assume you are exempt. Read: employee records vs candidate records, what the Privacy Act actually covers
Why a recruiter's data is unusually exposedWork history, referee comments, screening results and identity documents for people who never became employees.Read detailHide detail
You hold a concentrated pool of other people's most sensitive career and identity information: identity and right-to-work documents, CVs and references, background and police checks, pre-employment medicals, and increasingly candidate scores and rankings produced by your tools. Two categories raise the bar:
- Police checks and pre-employment medicals are sensitive information under the Privacy Act, which carries a higher consent and handling standard than ordinary personal information. Read: police checks and medicals, handling sensitive candidate information
- Candidate data often crosses borders, through offshore recruiters, overseas screening providers or virtual assistants, which brings APP 8 into play. Read: offshore recruiters and overseas screening, your APP 8 duty
A breach of these files exposes people who trusted you with their livelihood. Read: a data-breach response plan for recruitment agencies
The two issues no generic template handlesThe 10 December 2026 automated-decision rule as it applies to your ATS, and the line between employee and candidate records.Read detailHide detail
1. Your ATS and the 10 December 2026 automated-decision rule. From 10 December 2026, if you use automated decision-making that significantly affects a person, your privacy policy must disclose it (APP 1.7). Hiring is squarely in scope: an applicant-tracking system that scores, ranks, shortlists or auto-rejects candidates is making an automated decision about them. This is a transparency and disclosure duty, not a ban, but a generic privacy policy will not mention it, and from that date it is expected to. Read: the ADM rule and your ATS, what recruiters must disclose
2. Employee records versus candidate records. The line between the staff you employ (partly covered by the employee-records exemption) and the candidates you place (under the APPs) is the single most misunderstood point in recruitment privacy, and it changes what notice, consent and access obligations you owe for each. Most templates blur the two. Read: employee records vs candidate records
What a recruitment agency actually needsA policy, collection notices, a screening-consent procedure, an ATS transparency notice, a breach plan and a retention schedule.Read detailHide detail
- A privacy policy written for a recruitment or staffing business, including the APP 1.7 automated-decision disclosure for your ATS, not a generic website template.
- A candidate collection notice (APP 5) for the real collection points: the job ad, the application form, the ATS, and information you gather about a candidate from third parties such as referees.
- A sensitive-information procedure for police checks and medicals, with the higher consent standard built in.
- A data-breach response plan for the Notifiable Data Breaches scheme, tuned to candidate identity and background data.
- A retention and destruction schedule. There is no AML record-keeping floor here and, for unsuccessful candidates, generally no statutory minimum at all, so the risk is keeping candidate files far longer than you can justify. Your own employee records are a separate matter (Fair Work record-keeping applies to staff). Read: how long should a recruitment agency keep candidate records?
A blanket privacy-policy generator covers none of this: not the ATS disclosure, not the candidate-versus-employee line, not sensitive screening, not the retention problem.
What the Recruitment Kit covers
A dedicated, recruitment-specific privacy document set, written for agency and staffing work, and kept current as the law changes.
- Written for recruiters: candidates, screening, the ATS and its automated decisions, offshore providers, the employee-versus-candidate line.
- Practical, plain-English documents you tailor to your business, with guidance built in.
- Kept current: while your subscription is active, we monitor the law and aim to provide updated versions as it changes, including the 10 December 2026 automated-decision-making rule. This is not a guarantee of compliance, and does not replace your own legal advice.
These are compliance tools and templates you tailor to your own business. For advice on your specific circumstances, consult a qualified Australian legal practitioner.
Keep up with the changes
Not buying today? Get the plain-English updates as the privacy rules change, and the notes on what they mean in practice. No cost, no obligation.
✓ You’re on the list. We’ll email you as the changes land.
We never sell your data. See our Privacy Policy.
Keep reading
- Does the Privacy Act apply to recruitment agencies?
- The ADM rule and your ATS: what recruiters must disclose (from 10 December 2026)
- Employee records vs candidate records: what the Privacy Act actually covers
- What a recruitment agency's privacy policy must cover
- The candidate collection notice you need at application
- Police checks and medicals: handling sensitive candidate information
- Offshore recruiters and overseas screening: your APP 8 duty
- A data-breach response plan for recruitment agencies
- How long should a recruitment agency keep candidate records?
- In-house HR vs recruitment agency: who is covered?
- Consent to collect candidate ID and background information
- What does privacy compliance cost a recruitment agency?
- Do labour-hire firms need a privacy policy?
General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether the Privacy Act 1988 (Cth) applies to your business depends on your turnover, structure and how you handle candidate data; the employee-records exemption applies to your own staff, not to job candidates. The law changes over time, so check you are working from a current version.