Skip to content

Privacy compliance for Australian recruitment agencies: the employee-records exemption does not cover the people you actually hold data on.

A recruitment or staffing agency's files are full of candidates, and candidates are not your employees. The Privacy Act's employee-records exemption covers a business's own current and former staff, so it does very little for an agency whose core data is other people's job applicants. On top of that, from 10 December 2026, if your applicant-tracking system scores, ranks or auto-rejects candidates, that is an automated decision the law now expects you to disclose. This page is about the privacy obligations that come with holding candidate data, honestly and without inventing a deadline you do not face.

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

Are you covered by the Privacy Act? The honest answer for recruiters

There is no anti-money-laundering trigger for recruitment and no single 2026 switch-on date. But the common assumption, "we are a small agency, so we are exempt", is weaker here than in most industries, for two reasons:

So the honest first step is not to assume you are exempt. Read: employee records vs candidate records, what the Privacy Act actually covers

Why a recruiter's data is unusually exposed

You hold a concentrated pool of other people's most sensitive career and identity information: identity and right-to-work documents, CVs and references, background and police checks, pre-employment medicals, and increasingly candidate scores and rankings produced by your tools. Two categories raise the bar:

A breach of these files exposes people who trusted you with their livelihood. Read: a data-breach response plan for recruitment agencies

The two issues no generic template handles

1. Your ATS and the 10 December 2026 automated-decision rule. From 10 December 2026, if you use automated decision-making that significantly affects a person, your privacy policy must disclose it (APP 1.7). Hiring is squarely in scope: an applicant-tracking system that scores, ranks, shortlists or auto-rejects candidates is making an automated decision about them. This is a transparency and disclosure duty, not a ban, but a generic privacy policy will not mention it, and from that date it is expected to. Read: the ADM rule and your ATS, what recruiters must disclose

2. Employee records versus candidate records. The line between the staff you employ (partly covered by the employee-records exemption) and the candidates you place (under the APPs) is the single most misunderstood point in recruitment privacy, and it changes what notice, consent and access obligations you owe for each. Most templates blur the two. Read: employee records vs candidate records

What a recruitment agency actually needs

1. A privacy policy written for a recruitment or staffing business, including the APP 1.7 automated-decision disclosure for your ATS, not a generic website template. 2. A candidate collection notice (APP 5) for the real collection points: the job ad, the application form, the ATS, and information you gather about a candidate from third parties such as referees. 3. A sensitive-information procedure for police checks and medicals, with the higher consent standard built in. 4. A data-breach response plan for the Notifiable Data Breaches scheme, tuned to candidate identity and background data. 5. A retention and destruction schedule. There is no AML record-keeping floor here and, for unsuccessful candidates, generally no statutory minimum at all, so the risk is keeping candidate files far longer than you can justify. Your own employee records are a separate matter (Fair Work record-keeping applies to staff). Read: how long should a recruitment agency keep candidate records?

A blanket privacy-policy generator covers none of this: not the ATS disclosure, not the candidate-versus-employee line, not sensitive screening, not the retention problem.

What Privaproof is building for recruitment agencies

A dedicated, recruitment-specific privacy document set, written for agency and staffing work, and kept current as the law changes.

These are compliance tools and templates you tailor to your own business. They are general information, not legal advice, and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner.

Join the founding list

Be first to know when the Recruitment Kit opens, and get the plain-English updates as the 2026 changes land. No cost, no obligation.

We never sell your data. See our Privacy Policy.

Keep reading


General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether the Privacy Act 1988 (Cth) applies to your business depends on your turnover, structure and how you handle candidate data; the employee-records exemption applies to your own staff, not to job candidates. Privaproof's recruitment documents are self-authored and are not independently reviewed by a solicitor. The law changes over time, so check you are working from a current version.