Skip to content

What a recruitment agency's privacy policy must cover

A recruitment agency's privacy policy is an APP 1 document, but a generic website template will miss the things that actually matter for a recruiter: that you collect candidate data from referees and other third parties, that you disclose it to client employers, that you may send it offshore for screening, that some of it is sensitive information, and, from 10 December 2026, that your applicant-tracking system may be making automated decisions about candidates. This is what a policy written for a recruitment business needs to address.

By Jon Oates, Founder of Privaproof · Last updated

General information, not legal advice. Privaproof is not a law practice.

The baseline every APP 1 policy needs

Under APP 1, a covered organisation must have a clear, up-to-date privacy policy that sets out, in general terms, what personal information it collects and holds, how and why it collects it, how it is used and disclosed, how a person can access and correct it and make a complaint, and whether information is likely to be disclosed overseas. That baseline applies to a recruiter like anyone else. What follows is what a recruiter has to add on top.

The recruitment-specific parts a generic template leaves out

Where the coverage question fits

A privacy policy only bites if the APPs apply to you, but in recruitment they usually do, because candidate data is not covered by the employee-records exemption and trading in candidate data can remove the small-business exemption. So the safer assumption for most agencies is that you need a compliant policy. Read: does the Privacy Act apply to recruitment agencies?

Common questions

Can we just use a generic online privacy-policy generator?

You can generate the baseline, but it will not cover third-party collection, disclosure to client employers, sensitive screening, overseas screening, or the automated-decision disclosure, which are the parts that make a recruiter's policy accurate. A policy that describes a business you are not is arguably worse than none.

Do we need a separate policy for candidates and for our own staff?

Your own genuine employee records may fall under the employee-records exemption, but your candidate handling generally does not, so the policy that matters for the APPs is the one covering candidates and other non-employee personal information. Keep the candidate side clearly addressed.

How often should the policy change?

Whenever your practice or the law changes. The automated-decision rule on 10 December 2026 is a concrete example: many recruiters will need a policy update by then. This is what a kit that is kept current as the law changes is meant to handle for you.


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Privaproof's recruitment documents are self-authored and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner.

Keep reading