What a recruitment agency's privacy policy must cover
If the Australian Privacy Principles apply to your agency, your privacy policy is an APP 1 document, and a generic website template will miss the things that actually matter for a recruiter: that you collect candidate data from referees and other third parties, that you disclose it to client employers, that you may send it offshore for screening, that some of it is sensitive information, and, from 10 December 2026, that your applicant-tracking system may be making automated decisions about candidates (APP 1.7). This is what a policy written for a recruitment business needs to address.
By Jon Oates, Founder of Privaproof · Last updated
General information, not legal advice. Privaproof is not a law practice.
The baseline every APP 1 policy needs
APP 1.3 requires an APP entity to have a clearly expressed and up-to-date privacy policy, and APP 1.4 sets out the seven things it must contain: the kinds of personal information you collect and hold, how you collect and hold it, the purposes for which you collect, hold, use and disclose it, how a person accesses and corrects it, how a person complains and how you will deal with that, whether you are likely to disclose personal information to overseas recipients, and if so the countries those recipients are likely to be in, where it is practicable to specify them. That baseline is not decorative: APP 1.3 and APP 1.4 are both named in s 13K(1)(b) of the Privacy Act, the civil penalty provision the Commissioner can act on by infringement notice, with a maximum of 200 penalty units under s 13K(4). What follows is what a recruiter has to add on top.
The recruitment-specific parts a generic template leaves out
- Candidate data collected from third parties. You do not only collect from the candidate. You take references, verification results, and sometimes information from a candidate's current or former employer. Your policy has to be honest that you collect personal information about a candidate from other people, and your collection notice has to reflect it. Read: the candidate collection notice
- Disclosure to client employers. The core of your business is passing candidate information to the employers you recruit for. The policy must say that you disclose candidate personal information to prospective employers, and for what purpose.
- Sensitive information from screening. A criminal-history check is information about a criminal record, which s 6(1) makes sensitive information, and a pre-employment medical is health information, which is sensitive too. Under APP 3.3 an organisation may collect sensitive information only with the individual's consent and only where it is reasonably necessary for its functions or activities, unless APP 3.4 applies. The policy should acknowledge that you handle sensitive information and on what basis. Read: police checks and medicals
- Overseas disclosure. Where you disclose candidate data to an overseas recipient, such as an offshore recruiter or a screening provider, APP 8 applies. Separately, APP 1.4(f) makes the policy state whether you are likely to disclose personal information to overseas recipients, and APP 1.4(g) adds the countries those recipients are likely to be in, if it is practicable to specify them. Read: offshore recruiters and overseas screening
- Automated decision-making (from 10 December 2026). This is the big new one. From 10 December 2026, APP 1.7 applies where an APP entity has arranged for a computer program to make, or do a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect a person's rights or interests. An ATS that scores, ranks, shortlists or auto-rejects candidates is squarely that kind of tool. APP 1.8 then requires the policy to state the kinds of personal information used, the kinds of decisions made solely by the program, and the kinds where the program does a substantially and directly related thing, so a part-automated shortlist that a human signs off is still caught. A policy written before this rule will not mention it. Read: the ADM rule and your ATS
- Retention of candidate files. There is no anti-money-laundering record-keeping floor here, and for unsuccessful candidates often no statutory minimum at all. APP 11.2 runs the other way: once you no longer need the information for a purpose permitted under the APPs, and no Australian law or court order requires you to keep it, you must take reasonable steps to destroy it or de-identify it. So your policy and your practice should reflect a real retention limit rather than keeping every candidate forever. Read: how long to keep candidate records
Where the coverage question fits
A privacy policy duty only arises if the APPs reach you, and you may genuinely be outside them. Two things push a recruiter in. The employee-records exemption in s 7B(3) is scoped to an organisation "that is or was an employer of an individual", so it covers your own staff records and never the candidates you place. And s 6D(4)(c) and (d) take a business outside the small-business exemption where it discloses personal information about someone for a benefit, service or advantage, or provides a benefit, service or advantage in order to collect it, which is close to the shape of a placement fee. But s 6D(7) and (8) carve out disclosures and collections the individual consented to, and a candidate who registers with you and asks to be put forward has consented to that disclosure, so the trading limbs bite less often than the bare words suggest. The question worth answering is whether your consents actually cover what you do with candidate data, including clients the candidate never asked to be sent to, and talent-pool records built from third-party sources. Read: does the Privacy Act apply to recruitment agencies?
Common questions
Can we just use a generic online privacy-policy generator?
You can generate the baseline, but it will not cover third-party collection, disclosure to client employers, sensitive screening, overseas screening, or the automated-decision disclosure, which are the parts that make a recruiter's policy accurate. And accuracy is the duty, not a nicety: APP 1.4(a) and (c) require the policy to state the kinds of personal information you actually collect and hold and the purposes for which you actually disclose it, so a policy describing a business you are not is a policy that does not meet APP 1.4.
Do we need a separate policy for candidates and for our own staff?
Section 7B(3) exempts acts of an organisation "that is or was an employer of an individual" where they are directly related to that employment relationship and to an employee record. It is scoped to your own current and former staff. It does not reach candidates, and it does not shield you when you handle a host employer's or client's staff data either, because you are not their employer. The OAIC says the same in its Employee records exemption guidance: the exemption "is unlikely to apply to organisations that provide recruitment, human resource management services ... under contract to an employer". So the policy that matters for the APPs is the one covering candidates and other non-employee personal information.
How often should the policy change?
Whenever your practice or the law changes. The automated-decision rule on 10 December 2026 is a concrete example: does your current policy say anything about how your ATS scores, ranks or shortlists candidates? If it does not, and the APPs apply to you, that is a gap with a date already attached to it. This is what a kit that is kept current as the law changes is meant to handle for you.
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. For advice on your specific circumstances, consult a qualified Australian legal practitioner.