Skip to main content
Stage 4 · Your progress

0/4 steps

Recruitment Agency Launch Programme · Stage 4 of 10

Data Protection & the ICO

Handle candidate data properly — you’re a data controller from your very first CV.

≈ 3 hrs hands-on · 4 steps

How long

2–3 hours

You’ll have

Lawful candidate-data handling

Steps

4 steps

Resources

1 resources

  1. 01 Step 01

    Step 01

    Pay the ICO data-protection fee

    Almost every agency must pay it — processing candidate data without registering is itself a breach.

    Do it yourself

    • Most new agencies are Tier 1 (£52): under £632k turnover or 10 staff.
    • Move to Tier 2 (£78) as you grow.
    • Set it to renew annually.

    Common mistake · Processing CVs for months without ever registering with the ICO.

    Time~20 min Cost£52/yr DifficultyEasy

    Resource for this step

    LINK

    Pay the ICO data-protection fee

    Register your agency and pay the annual fee.

    Open the ICO
  2. 02 Step 02

    Step 02

    Publish a privacy notice

    Candidates and clients need to know what you collect, why, and on what basis — and the law requires it.

    Do it yourself

    • State what data you collect and why.
    • Set the lawful basis — usually legitimate interests for sourcing.
    • Make it genuinely findable on your site.

    Common mistake · A privacy notice buried three clicks deep that nobody could find.

    Time~1 hour CostFree DifficultyMedium
    The privacy, cookie and consent pages on your site are something we build.
  3. 03 Step 03

    Step 03

    Set retention and a DSAR process

    Keeping data forever is a liability; being unable to answer a request is a breach.

    Do it yourself

    • Set a retention period — typically 2–3 years from last meaningful contact.
    • Have a process to answer data-subject access requests within one month.
    • Diary a periodic clear-out of stale records.

    Common mistake · Hoarding every CV forever “just in case”.

    Time~30 min CostFree DifficultyEasy
  4. 04 Step 04

    Step 04

    Put data-processing agreements in place

    Every tool that touches candidate data shares your responsibility for it.

    Do it yourself

    • List every third-party tool that holds candidate data — ATS, email, job boards.
    • Get a data-processing agreement with each.
    • Gather them as you set up each tool, not after a breach.

    Common mistake · Discovering after an incident that no processor agreements were ever in place.

    Time~1 hour CostFree DifficultyMedium

What you’ll have after this stage

  • Your ICO data-protection fee paid
  • A published privacy notice with a lawful basis
  • A retention policy and a DSAR process
  • Data-processing agreements with your tools

A law-firm website, wireframed

Click through the pages to see the shape a credible firm site takes — structure first, words and design later.

yourfirm.co.uk/

Grey blocks are placeholders — they show where things go, not how they look.