14Jul 2026

Job seeker privacy in the UK: your 2026 guide

Legal documents on UK job privacy on office desk


TL;DR:

  • Job seekers in the UK have a legal right to transparent and lawful handling of their personal data during recruitment. They can access, correct, or delete their data and request human review if automated decisions negatively affect them. Understanding these rights helps candidates hold employers accountable and protect their privacy throughout the hiring process.

Job seeker privacy is defined as the right of candidates to have their personal data collected, processed, and stored lawfully and transparently throughout the recruitment process. In the UK, this right is governed primarily by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, with the Information Commissioner’s Office (ICO) acting as the principal regulator. Understanding what is job seeker privacy matters because every CV you submit, every interview you attend, and every online assessment you complete generates personal data that an employer holds about you. The Data (Use and Access) Act 2026 has strengthened these protections further, making this one of the most significant moments for candidates to understand their rights.


What is job seeker privacy and why does it matter?

Job seeker privacy covers every stage of recruitment, from the moment you submit an application to the point your data is deleted or retained for future roles. Employers collect a wide range of personal information during hiring, and UK GDPR sets strict rules on how that data must be handled. Recruitment privacy notices must identify the data controller, the purposes for processing, the lawful basis, data sharing arrangements, retention periods, and your rights as a candidate. Failure to provide this information breaches Articles 13 and 14 of UK GDPR.

BEST Virtual Address Services for PRIVACY (+ how to use them)

The importance of job seeker privacy goes beyond legal compliance. When employers handle your data carelessly, the consequences range from your CV circulating to third parties without your knowledge to your interview notes being used in ways you never agreed to. Transparency is the clearest signal of a trustworthy employer. Vague legitimate interest claims for processing your data are a red flag for non-compliance and worth challenging before you proceed with an application.


How employers collect and use your data during recruitment

Employers gather more personal data during recruitment than most candidates realise. The categories typically include:

  • CVs and covering letters, containing your work history, qualifications, and contact details
  • Interview notes and scoring sheets, recording assessors’ observations and ratings
  • Assessment results, including psychometric tests, video interviews, and written exercises
  • Background check data, such as criminal record checks, right-to-work documents, and references
  • Correspondence, including emails and messages exchanged during the process

Each category requires a lawful basis under UK GDPR. The two most common bases in recruitment are “steps prior to entering a contract” (processing your application) and “legitimate interests” (retaining data for legal defence). Employers must state which basis applies to each type of processing in their privacy notice.

Data sharing is a particular area of concern. Employers routinely share applicant data with recruitment agencies, background screening providers, and occupational health assessors. Each third party must be named or described in the privacy notice, along with the purpose of sharing. Applicant data retention typically runs from 6 to 12 months for unsuccessful candidates, giving employers a window to defend against discrimination claims. Beyond that period, employers need your explicit consent to keep your details, for example, to add you to a talent pool for future vacancies.

Recruiter reviewing applicant data paperwork UK office

Pro Tip: Before applying for any role, locate the employer’s recruitment privacy notice. If none exists or it is vague about retention and data sharing, contact the HR team directly and ask for clarification before submitting your CV.


What rights do job seekers have regarding their recruitment data?

UK GDPR grants candidates a clear set of statutory rights over their personal data. These rights apply from the moment an employer collects your information and continue until it is deleted.

  1. Right of access. You can submit a Subject Access Request (SAR) to obtain copies of all personal data an employer holds about you, including interview notes, scoring sheets, and assessment feedback. SARs need not be formally worded or labelled as such to be valid. A plain email asking “please send me all personal data you hold about me” is sufficient.
  2. Right to rectification. If your data is inaccurate, for example, a misrecorded qualification, you can request a correction.
  3. Right to erasure. You can ask an employer to delete your data once the legitimate purpose for holding it has ended.
  4. Right to restriction. You can ask an employer to pause processing your data while a dispute is resolved.
  5. Right to object. You can object to processing based on legitimate interests, and the employer must stop unless it can demonstrate compelling grounds.
  6. Right to be informed about automated decisions. If a solely automated process makes a significant decision about your application, you have the right to know and to request human review.

Employers must respond to SARs within one calendar month of receiving the request. That deadline is firm. Under the Data (Use and Access) Act 2026, employers must also provide an internal complaint mechanism with a response time of 30 days before a complaint escalates to the ICO. This creates a faster resolution route for candidates without requiring immediate regulatory involvement.

Pro Tip: Keep a copy of every application you submit, including the job description, the privacy notice, and any correspondence. If you later submit a SAR, this paper trail helps you verify whether the employer’s records are accurate and complete.

Infographic of UK job seeker data rights steps


Automated decision-making and AI in recruitment: what you need to know

Automated decision-making (ADM) in recruitment refers to processes where software, without meaningful human input, determines whether your application progresses. Examples include CV screening algorithms that filter out candidates based on keyword matching, video interview platforms that score facial expressions and speech patterns, and psychometric tools that rank candidates automatically.

UK GDPR Article 22 gives you the right to opt out of solely automated decisions that produce significant effects, such as rejection from a role. The ICO’s 2026 guidance makes clear that employers using such tools must:

  • Notify candidates that automated decision-making is in use
  • Explain the logic behind the process in plain language
  • Allow candidates to request human review of any automated decision
  • Demonstrate that bias monitoring is carried out regularly to prevent discriminatory outcomes

The human review requirement is where many employers fall short. Tokenistic reviews do not exempt a process from being treated as solely automated decision-making. A recruiter who glances at an algorithm’s output for thirty seconds and clicks “approve” is not providing genuine human oversight. The ICO’s position is that human involvement must be consistent, substantive, and capable of actually changing the outcome.

Automated recruitment tools can introduce bias at scale. The ICO emphasises that organisations must regularly test and monitor their AI hiring tools for discriminatory outcomes, and that genuine human oversight is a legal requirement, not an optional safeguard.

If you are rejected from a role and suspect an automated system made the decision, you have the right to request human review. Submit this request in writing to the employer’s HR or data protection contact. If they refuse or fail to respond, escalate to the ICO.


Practical steps to protect your privacy as a job seeker

Protecting your personal data during a job search requires deliberate choices at each stage of the process. The following steps reduce your exposure and strengthen your position if a dispute arises.

  • Read the privacy notice before applying. Every compliant employer publishes one. Check who processes your data, how long they keep it, and whether it is shared with third parties. If the notice is missing or vague, that tells you something important about the employer’s approach to compliance.
  • Share only what is relevant. You are not obliged to include your date of birth, marital status, or a photograph on a CV unless the role specifically requires it. Limiting personal information reduces the risk of data being misused.
  • Keep records of every application. Save the job advert, the privacy notice, your submitted CV, and all correspondence. This documentation supports any SAR or complaint you may need to make later.
  • Use your right of access proactively. Accessing your recruitment data through SARs is becoming more common and gives you genuine insight into how hiring decisions were made. You may discover inaccurate notes or scoring that you can then challenge.
  • Challenge automated assessments. If you complete a video interview or AI-scored test, ask the employer in writing whether the outcome was determined solely by automated means. Request the logic behind the decision and, if relevant, a human review.

Pro Tip: When reviewing a job listing on any platform, check whether the employer links to a GDPR-compliant privacy notice alongside the application. Platforms that surface this information upfront signal a higher standard of data handling.


Key takeaways

Job seeker privacy in the UK is a legally enforceable right under UK GDPR and the Data Protection Act 2018, and the 2026 regulatory updates make it more important than ever to exercise that right actively.

Point Details
Privacy notices are mandatory Employers must publish a recruitment privacy notice covering data controller, purposes, retention, and your rights.
SARs are your strongest tool A Subject Access Request gives you access to interview notes, scores, and assessments within one calendar month.
Automated decisions carry extra rights You can request human review of any solely automated hiring decision under UK GDPR Article 22.
Retention has a time limit Employers typically hold unsuccessful applicant data for 6–12 months; longer retention requires your explicit consent.
The 2026 Act adds complaint routes The Data (Use and Access) Act 2026 requires employers to resolve data complaints internally within 30 days.

Why I think most job seekers underestimate their data rights

Having followed recruitment practices in the UK security sector closely, I find that most candidates treat privacy notices as legal small print to scroll past. That is a costly mistake. The information in those notices tells you exactly how an employer views its obligations to you, and a vague or missing notice is a genuine warning sign about how the organisation operates.

The automated hiring issue is the one that concerns me most right now. The ICO’s 2026 guidance on ADM is clear, but enforcement depends on candidates actually raising objections. Many job seekers assume that because a human signed off on a decision, the process was fair. The reality is that tokenistic human review is widespread, and the law does not accept it as genuine oversight.

My advice is simple. Read the privacy notice. Submit a SAR if you are rejected and want to understand why. Do not assume that a polished recruitment process is a compliant one. The candidates who understand their rights are the ones who can hold employers accountable, and that benefits every job seeker in the long run. For those in the security sector specifically, working with platforms that take GDPR compliance seriously is one of the most practical ways to protect yourself from the start.

— Rob


Securityjobsboard: a privacy-conscious platform for security job seekers

https://www.securityjobsboard.co.uk

Securityjobsboard is built specifically for the UK security sector, and data protection is central to how the platform operates. Every employer listing on the site is subject to GDPR compliance standards, and the platform’s affiliation with the BSIA adds an additional layer of credibility for candidates who want to know their data is handled responsibly.

If you are searching for security roles and want to apply through a platform that takes job application confidentiality seriously, browse the current security jobs in Northern Ireland listings as a starting point. Securityjobsboard is free to use for candidates, mobile-friendly, and designed to connect you with employers who meet the standards you deserve. You can also read more about candidate data protection in the platform’s dedicated GDPR guide for 2026.


FAQ

What is job seeker privacy under UK law?

Job seeker privacy is the right of candidates to have their personal data processed lawfully, transparently, and fairly during recruitment, as defined by UK GDPR and the Data Protection Act 2018.

How long can an employer keep my application data?

Employers typically retain unsuccessful applicant data for 6–12 months for legal protection. Keeping your data beyond that period requires your explicit consent.

Can I see my interview notes and assessment scores?

Yes. A Subject Access Request gives you access to all personal data an employer holds, including interview notes and scoring sheets, and the employer must respond within one calendar month.

What should I do if I think an algorithm rejected my application?

Request confirmation in writing of whether solely automated decision-making was used. Under UK GDPR Article 22, you have the right to request human review of any such decision.

No. Formal legal vocabulary is not required. A clear, plain-English email asking for your personal data or requesting a correction is fully valid under UK GDPR.