A practical read on what UK GDPR and the Data Protection Act 2018 actually require when a candidate's CV passes through your agency. Re-identified candidates, anonymous shortlists, what to put in your privacy notice, and what the ICO tends to act on.
It is a working summary for a recruitment-agency owner or operations lead who has to make decisions about CVs every week and would like a calmer read than the ICO guidance page. It is not legal advice. If a question here changes whether you can run a process, the answer is to ask a solicitor — UK GDPR is statutory and the case law moves.
Venditas is a CV reformatting tool that anonymises candidate CVs by default. Where the article describes what the law requires, it does so on its own merits. Where it describes what Venditas does, it says so plainly.
When a candidate sends their CV to a recruitment agency, the agency is the data controller. The agency decides why the data is being processed, what counts as a successful match, who sees the CV, how long it is held and when it is deleted. Any third party that handles the CV on the agency's behalf — including a CV formatting tool — is a data processor under Article 28 UK GDPR and needs a written contract that sets out what they can and cannot do with the data.
This matters because the controller has the obligations. The processor has fewer, but they are not nothing, and the contract (a Data Processing Agreement) is the bit the ICO actually checks when something goes wrong.
The lawful bases for processing candidate data are listed in Article 6(1) UK GDPR. For most recruitment work the relevant ones are:
Whichever basis you choose, two things follow. First, you must tell the candidate which basis you are relying on (in your privacy notice, at the point of collection, or both). Second, the basis has to be true — relying on legitimate interests when consent was clearly given, or vice versa, is a record-keeping failure the ICO will note.
Article 5(1)(c) UK GDPR requires that personal data be adequate, relevant and limited to what is necessary. A CV sent to a hiring client is almost always over-shared by default: it carries the candidate's home address, personal mobile, personal email, LinkedIn URL, sometimes a date of birth and a photograph. None of that is necessary for the client to assess suitability for a role. The Information Commissioner has been clear in published guidance that controllers are expected to take reasonable steps to minimise.
In practice this is what most UK agencies already do by hand: open the candidate's CV, delete the contact details, replace the candidate's name with a reference code, save and forward. The reason to talk about it as a GDPR question rather than a workflow question is that the manual approach is prone to being skipped on a Friday afternoon. The legal duty does not vary with the day of the week.
Anonymisation vs pseudonymisation. UK GDPR applies to personal data — data relating to an identified or identifiable person. Truly anonymous data is out of scope. Replacing a name with a reference code while leaving the rest identifiable is pseudonymisation, which is a security measure, not an exemption. The candidate is still a data subject; UK GDPR still applies. This is the technical point that catches a lot of well-intentioned policies.
CVs frequently contain data that is special-category under Article 9 — for example, photographs (biometric data when processed for identification), health disclosures, trade union membership, criminal-record declarations. The lawful basis for special-category processing is stricter (Article 9(2) plus a Schedule 1 condition under the Data Protection Act 2018). The short version: most agencies should not be passing this through to a client at the shortlist stage, and a tool that re-renders a CV should not be inventing, retaining or learning from it.
When an agency uses a third-party tool to handle CVs, that tool becomes a processor. If the tool in turn uses another provider — for storage, AI inference, hosting, email — those providers are sub-processors and must be listed in the DPA and, in practice, in the controller's own Article 30 record. The ICO is consistent on this point in its audit work: undisclosed sub-processors are a recurring finding.
For a CV-processing tool, the realistic list to expect is: a cloud host, an AI inference provider, an email provider for transactional messages, and (sometimes) a database for account data. Each is a separate processor relationship with its own safeguards, region and breach-notification terms. The agency's DPA with the tool needs to surface them.
If a candidate's CV leaves the UK — to a US-based AI inference endpoint, for example — that is an Article 46 restricted transfer and needs a transfer mechanism: the UK International Data Transfer Agreement (IDTA), the EU Standard Contractual Clauses, or reliance on an adequacy decision. The UK has an adequacy decision for the EU, and the EU has one for the UK (until June 2025 reviews); the US does not have a general adequacy decision, so transfers to US sub-processors are typically covered by SCCs or, for some providers, the EU-US Data Privacy Framework.
The agency does not have to repeat this paperwork for every sub-processor; the tool's DPA and the underlying contracts carry it. But the agency does need to know the regions and the mechanism, and to keep a record.
Candidates have the rights in Articles 15 to 22 — access, rectification, erasure, restriction, objection, portability, and (in some processing) no solely-automated decision-making. Anonymising the CV on the way to the client does not stop these rights applying to the CV the agency holds. Erasure in particular is the one that breaks sloppy processes: the agency has to be able to delete a candidate's CV from its systems, including from any processor or sub-processor that holds a copy.
Article 5(1)(e) requires that data be kept no longer than is necessary. The Information Commissioner's Employment Practices guidance and most sector practice point to a CV retention period in the order of six to twenty-four months, depending on the role and the candidate's expressed preference, with a clear end date and a documented deletion routine. A tool that holds CV content beyond the moment of processing is, in this framework, an unnecessary risk.
Most complaints the ICO receives about recruitment agencies are not about redaction. They are about three things: a candidate who asked to be forgotten and heard nothing; a CV forwarded to a client that contained data the candidate had asked to be removed; and a breach involving candidate CVs that was not reported within 72 hours. Reasonable steps in all three areas depend more on the agency's process than on any tool the agency uses.
Venditas is a processor. The agency remains the controller. What Venditas does, that is relevant to this article:
None of this makes an agency GDPR-compliant on its own. It is one piece of a process that the agency owns: lawful basis, candidate notice, retention, rights handling, breach response. Done well, the right tool saves time and removes the easy mistakes; it does not replace the harder ones.