Skip to content

What a recruitment agency's privacy policy must cover

If the Australian Privacy Principles apply to your agency, your privacy policy is an APP 1 document, and a generic website template will miss the things that actually matter for a recruiter: that you collect candidate data from referees and other third parties, that you disclose it to client employers, that you may send it offshore for screening, that some of it is sensitive information, and, from 10 December 2026, that your applicant-tracking system may be making automated decisions about candidates (APP 1.7). This is what a policy written for a recruitment business needs to address.

By Jon Oates, Founder of Privaproof · Last updated

General information, not legal advice. Privaproof is not a law practice.

The baseline every APP 1 policy needs

APP 1.3 requires an APP entity to have a clearly expressed and up-to-date privacy policy, and APP 1.4 sets out the seven things it must contain: the kinds of personal information you collect and hold, how you collect and hold it, the purposes for which you collect, hold, use and disclose it, how a person accesses and corrects it, how a person complains and how you will deal with that, whether you are likely to disclose personal information to overseas recipients, and if so the countries those recipients are likely to be in, where it is practicable to specify them. That baseline is not decorative: APP 1.3 and APP 1.4 are both named in s 13K(1)(b) of the Privacy Act, the civil penalty provision the Commissioner can act on by infringement notice, with a maximum of 200 penalty units under s 13K(4). What follows is what a recruiter has to add on top.

The recruitment-specific parts a generic template leaves out

Where the coverage question fits

A privacy policy duty only arises if the APPs reach you, and you may genuinely be outside them. Two things push a recruiter in. The employee-records exemption in s 7B(3) is scoped to an organisation "that is or was an employer of an individual", so it covers your own staff records and never the candidates you place. And s 6D(4)(c) and (d) take a business outside the small-business exemption where it discloses personal information about someone for a benefit, service or advantage, or provides a benefit, service or advantage in order to collect it, which is close to the shape of a placement fee. But s 6D(7) and (8) carve out disclosures and collections the individual consented to, and a candidate who registers with you and asks to be put forward has consented to that disclosure, so the trading limbs bite less often than the bare words suggest. The question worth answering is whether your consents actually cover what you do with candidate data, including clients the candidate never asked to be sent to, and talent-pool records built from third-party sources. Read: does the Privacy Act apply to recruitment agencies?

Common questions

Can we just use a generic online privacy-policy generator?

You can generate the baseline, but it will not cover third-party collection, disclosure to client employers, sensitive screening, overseas screening, or the automated-decision disclosure, which are the parts that make a recruiter's policy accurate. And accuracy is the duty, not a nicety: APP 1.4(a) and (c) require the policy to state the kinds of personal information you actually collect and hold and the purposes for which you actually disclose it, so a policy describing a business you are not is a policy that does not meet APP 1.4.

Do we need a separate policy for candidates and for our own staff?

Section 7B(3) exempts acts of an organisation "that is or was an employer of an individual" where they are directly related to that employment relationship and to an employee record. It is scoped to your own current and former staff. It does not reach candidates, and it does not shield you when you handle a host employer's or client's staff data either, because you are not their employer. The OAIC says the same in its Employee records exemption guidance: the exemption "is unlikely to apply to organisations that provide recruitment, human resource management services ... under contract to an employer". So the policy that matters for the APPs is the one covering candidates and other non-employee personal information.

How often should the policy change?

Whenever your practice or the law changes. The automated-decision rule on 10 December 2026 is a concrete example: does your current policy say anything about how your ATS scores, ranks or shortlists candidates? If it does not, and the APPs apply to you, that is a gap with a date already attached to it. This is what a kit that is kept current as the law changes is meant to handle for you.


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. For advice on your specific circumstances, consult a qualified Australian legal practitioner.

Keep reading