What a recruitment agency's privacy policy must cover
A recruitment agency's privacy policy is an APP 1 document, but a generic website template will miss the things that actually matter for a recruiter: that you collect candidate data from referees and other third parties, that you disclose it to client employers, that you may send it offshore for screening, that some of it is sensitive information, and, from 10 December 2026, that your applicant-tracking system may be making automated decisions about candidates. This is what a policy written for a recruitment business needs to address.
By Jon Oates, Founder of Privaproof · Last updated
General information, not legal advice. Privaproof is not a law practice.
The baseline every APP 1 policy needs
Under APP 1, a covered organisation must have a clear, up-to-date privacy policy that sets out, in general terms, what personal information it collects and holds, how and why it collects it, how it is used and disclosed, how a person can access and correct it and make a complaint, and whether information is likely to be disclosed overseas. That baseline applies to a recruiter like anyone else. What follows is what a recruiter has to add on top.
The recruitment-specific parts a generic template leaves out
- Candidate data collected from third parties. You do not only collect from the candidate. You take references, verification results, and sometimes information from a candidate's current or former employer. Your policy has to be honest that you collect personal information about a candidate from other people, and your collection notice has to reflect it. Read: the candidate collection notice
- Disclosure to client employers. The core of your business is passing candidate information to the employers you recruit for. The policy must say that you disclose candidate personal information to prospective employers, and for what purpose.
- Sensitive information from screening. Police and criminal-history checks and pre-employment medicals are sensitive information under the Act, which generally needs consent to collect and a higher standard of care. The policy should acknowledge that you handle sensitive information and on what basis. Read: police checks and medicals
- Overseas disclosure. If you use offshore recruiters, virtual assistants or screening providers, candidate data crosses borders and APP 8 applies. The policy must disclose the likelihood of overseas disclosure and, where practical, the countries involved. Read: offshore recruiters and overseas screening
- Automated decision-making (from 10 December 2026). This is the big new one. If your ATS or screening tools score, rank, shortlist or auto-reject candidates, that is automated decision-making, and from 10 December 2026 your privacy policy must disclose it: the kinds of decisions, the kinds of personal information used, and that automation is involved. A policy written before this rule will not mention it. Read: the ADM rule and your ATS
- Retention of candidate files. There is no anti-money-laundering record-keeping floor here, and for unsuccessful candidates often no statutory minimum at all, so your policy and your practice should reflect a real retention limit rather than keeping every candidate forever. Read: how long to keep candidate records
Where the coverage question fits
A privacy policy only bites if the APPs apply to you, but in recruitment they usually do, because candidate data is not covered by the employee-records exemption and trading in candidate data can remove the small-business exemption. So the safer assumption for most agencies is that you need a compliant policy. Read: does the Privacy Act apply to recruitment agencies?
Common questions
Can we just use a generic online privacy-policy generator?
You can generate the baseline, but it will not cover third-party collection, disclosure to client employers, sensitive screening, overseas screening, or the automated-decision disclosure, which are the parts that make a recruiter's policy accurate. A policy that describes a business you are not is arguably worse than none.
Do we need a separate policy for candidates and for our own staff?
Your own genuine employee records may fall under the employee-records exemption, but your candidate handling generally does not, so the policy that matters for the APPs is the one covering candidates and other non-employee personal information. Keep the candidate side clearly addressed.
How often should the policy change?
Whenever your practice or the law changes. The automated-decision rule on 10 December 2026 is a concrete example: many recruiters will need a policy update by then. This is what a kit that is kept current as the law changes is meant to handle for you.
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Privaproof's recruitment documents are self-authored and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner.