Consent to collect candidate ID and background information: what you actually need
A common recruitment myth is that you need signed consent for everything you collect from a candidate. You do not. For ordinary personal information, the rule is to collect only what is reasonably necessary, by lawful and fair means, and to give a collection notice. Consent is the higher bar, and it applies to sensitive information, most importantly the police checks and medicals that go with screening.
By Jon Oates, Founder of Privaproof · Last updated
General information, not legal advice. Privaproof is not a law practice.
Notice is the baseline, consent is the higher bar
Two different requirements often get merged:
- Collection notice (APP 5) applies whenever you collect personal information. APP 5.1 requires you to take such steps as are reasonable in the circumstances to notify the candidate, or otherwise ensure they are aware, of the APP 5.2 matters: who you are, why you are collecting, who you disclose to, and so on. This is notice, not consent. Read: the candidate collection notice
- Consent is a stronger step, required for particular things, most notably sensitive information, which under APP 3.3 needs consent as well as being reasonably necessary. The Act defines consent at s 6(1) as "express consent or implied consent", so nothing in the Privacy Act makes a signature the test. What a signature buys you is evidence.
So for ordinary candidate information, contact details, work history, an identity document you genuinely need, the requirement is usually to collect only what is reasonably necessary and to notify, not to obtain formal signed consent. The s 6(1) list of sensitive information is closed, and a driver licence or passport is not on it.
The collection rules for candidate ID and background
- Only what is reasonably necessary. APP 3.2 says an organisation must not collect personal information unless it is reasonably necessary for one or more of its functions or activities. Do not collect an identity document, a full date of birth, or background detail you do not actually need to source, assess or place the candidate.
- By lawful and fair means, and from the candidate. APP 3.5 requires lawful and fair means. APP 3.6 adds that an organisation may collect a candidate's information from someone else, a referee for example, only where it is unreasonable or impracticable to collect it from the candidate, and APP 5.2(b) then requires you to notify that you did. Ask it of each third-party source: could you have asked the candidate instead?
- Sensitive information needs consent. A criminal-history check is sensitive information because "criminal record" is in the closed s 6(1) list, and a pre-employment medical is because health information is on it too. APP 3.3 then requires consent and reasonable necessity, unless an APP 3.4 exception applies, the practical one being screening that is required or authorised by an Australian law. Read: police checks and medicals
What good consent looks like (where you do need it)
The Act itself says only that consent "means express consent or implied consent" (s 6(1)). The four elements people quote, that consent be voluntary, informed, specific and current and given by someone with capacity, come from the OAIC's APP Guidelines rather than the text of the Act. In practice that means telling the candidate plainly what you will collect and why before they agree, not burying it in a wall of text, and not treating a stale tick from years ago as ongoing consent for a new check.
This is general information and document templates you tailor to your own business, not legal advice.
Common questions
Do we need written consent to collect a candidate's ID document?
Usually not a formal consent, provided you genuinely need it and you notify. A licence or passport is not in the closed s 6(1) list of sensitive information, so the controls are necessity and notice: collect only what you need, by fair means, and cover it in your collection notice. Two limits worth knowing. Run that ID through automated face matching and the biometric information is sensitive under s 6(1)(d), so APP 3.3 applies. And writing is never the statutory test, it is your evidence, which is why the sensitive collections are the ones to get in writing.
Is a tick-box on the application form enough?
For a collection notice, a clear notice on the application path is the mechanism, not a tick-box. Where you do need consent (for sensitive screening), a bundled "I agree to everything" tick is weak, consent should be specific to what you are actually collecting.
Can we rely on consent the candidate gave last year?
Be careful. Consent should be current. A consent given for one purpose or a while ago may not cover a fresh check now. If in doubt, ask again for the specific collection.
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. For advice on your specific circumstances, consult a qualified Australian legal practitioner.