Good GDPR tooling helps an agency record why it holds candidate information, review how long it keeps it and respond to individual rights requests. Buying an ATS does not transfer those decisions to the software supplier: the agency must understand and carry out its own responsibilities.
This article is informational, not legal advice. It focuses on UK GDPR guidance from the Information Commissioner's Office, checked on 24 September 2026; agencies subject to EU GDPR or other laws should confirm the rules that apply to their circumstances.
That distinction matters because the UK's guidance has changed following the Data (Use and Access) Act 2025. An old checklist copied into a new ATS is not necessarily a current procedure.
What remains the agency's responsibility?
An agency will often act as a controller for its candidate database because it determines why and how that information is used. Roles depend on the actual processing arrangement, however, so establish them rather than assuming a software label answers the question.
Where an ATS supplier processes information on the agency's behalf, the controller-processor arrangement needs the required contractual terms. The ICO's guidance covers areas such as instructions, security, sub-processors and assistance with individual rights.
Software can record a lawful basis, calculate a deadline or assemble an export. It cannot decide that your original reason for collecting the information was valid simply because a field contains a value. Someone in the agency must own the policy and the decisions behind it.
Do you need consent for every candidate record?
Consent is one possible lawful basis, not the automatic answer to every recruitment activity. Select an appropriate basis for the specific purpose before processing the information, and explain your processing transparently to the individual.
Legitimate interests may be relevant to some recruitment activity, but it is not a blanket permission to keep or use any information. The assessment must address the purpose, necessity and the individual's interests. The correct basis depends on what you are actually doing.
If you rely on consent, you need to understand the conditions that make it valid and how withdrawal will be handled. A timestamp is useful evidence of an event; it does not establish that the wording, choice and surrounding process met every legal requirement.
Sensitive information may require an additional condition under the rules for special category data. Do not assume that the basis used for ordinary contact details settles the position for health information or other sensitive material in interview notes.
What should the ATS record?
A useful system lets you associate the basis and relevant evidence with the candidate. Recruiters should be able to understand what the record means without reconstructing it from an old inbox.
Crumblelead supports a lawful basis per candidate and consent requests through a secure link, with a timestamped consent log. The agency still needs to choose the correct basis, maintain appropriate notices and act on the information recorded.
How long can an agency keep candidate data?
UK GDPR does not provide one universal retention period for every recruitment database. The ICO's storage limitation guidance requires a period justified by the purpose and the need to retain the information, with review and deletion or anonymisation when appropriate.
Set a schedule that reflects the different reasons you hold records. A current candidate relationship, an old speculative CV and information retained for a specific legal purpose may need different consideration. Do not treat the last system migration as a fresh justification for keeping everything.
A retention date should trigger a meaningful review or the agreed action. If every overdue record is simply given a new date without a reason, the software is documenting delay rather than managing retention.
Crumblelead provides retention windows, overdue flags and a quarterly review digest. Those help organise the work; they do not replace a retention policy or guarantee that somebody completes the review.
What does a useful privacy workflow look like?
The comparison below separates the agency's decision from the software's supporting role. It reflects the ICO guidance checked in September 2026 and is not a legal compliance certification.
| Task | Agency responsibility | Useful ATS support |
|---|---|---|
| Lawful basis | Identify and document an appropriate basis for the purpose | Candidate-level record and supporting evidence |
| Consent | Meet the applicable consent conditions and handle withdrawal | Request process, status and dated evidence |
| Retention | Set justified periods and act when information is no longer needed | Review dates, overdue visibility and deletion workflow |
| Subject access | Recognise the request, assess scope and provide an appropriate response | Search, export and deadline tracking |
| Erasure | Assess the right and applicable exceptions, then carry out the decision | Removal or anonymisation across relevant records and files |
Use the table to test a vendor demonstration. Ask the demonstrator to follow one candidate through the process rather than showing five unrelated settings pages.
How should you handle a subject access request?
Make sure staff can recognise a request even if it does not use the term “SAR”. Route it promptly to the person responsible, record receipt and establish what identity checks or clarification are reasonably necessary.
The ICO's updated UK guidance generally requires a response without undue delay and within one calendar month. It allows an extension of up to two further months for complexity or multiple requests, subject to the applicable conditions and notification within the initial period. Do not turn “one month” into a blanket 30-day deadline.
The updated guidance also addresses pausing the clock where clarification is reasonably required. That is not permission to demand that a requester narrow their request for your convenience. Apply the current rules to the particular request rather than building an automatic delay into the process.
Searches and disclosure need human review. Information about other people, exemptions and the precise scope of the right can affect the response. A downloaded ZIP is preparation for a response, not necessarily something to send unchecked.
Crumblelead's SAR export contains a PDF summary, JSON data and all files in a ZIP, with the deadline tracked. The agency remains responsible for reviewing the response, adding any required information and delivering it appropriately.
Is erasure the same as deleting a profile?
Not necessarily. Candidate information may also exist in attachments, parsed CV content, notes and other systems. Establish the relevant locations before deciding that removing a visible profile has completed the task.
The right to erasure is not absolute. The ICO describes circumstances where it applies and exceptions, including certain legal obligations and legal claims. Assess the request and explain the outcome appropriately rather than promising automatic deletion in every case.
Crumblelead's erasure process removes files, anonymises the profile and parsed CV, redacts notes and the audit trail, and sends confirmation with a reference number. That describes the product workflow; it does not determine the agency's legal response to every request.
Ask suppliers separately how erasure is handled in backups and connected services. Do not assume a live-system action means every copy in every environment disappears immediately. Document the procedure and seek appropriate advice where the treatment is unclear.
What should you check in the supplier agreement?
Obtain the DPA and establish the assistance the supplier provides when your agency must respond to a request or investigate an issue. Check the sub-processor arrangements and how changes are communicated.
Crumblelead makes a DPA available, publishes its sub-processor list and gives 30 days' notice before adding a new sub-processor. Those are useful facts for the supplier review, but signing a DPA does not automatically make the agency's own processing compliant.
Also establish what happens when you leave the ATS. Data access, export and deletion should be considered together. Retaining an unused copy indefinitely because it might be useful later is a different decision from arranging a controlled handover.
Put the process where recruiters can use it
Keep the operational instructions short enough to follow during a busy day. Recruiters need to know where to record a concern, how to route a request and who decides what happens next.
- Name the person responsible for privacy requests and their cover.
- Keep the retention schedule and lawful basis decisions accessible.
- Test a subject access workflow with an authorised sample record.
- Check how files and notes are treated in an erasure demonstration.
- Record unresolved supplier questions and the agreed answers.
Review the process when the law, your activities or the software changes. An ATS can make the work easier to manage, but accountability still needs a person with time and authority to act.
Where Crumblelead fits
Crumblelead provides candidate-level lawful basis records, logged consent requests, retention reviews, SAR exports and an erasure workflow. These tools support perm-focused independent and small-to-mid agencies in carrying out their own privacy processes.
It is not built for large temp or contract staffing firms needing timesheets, payroll or VMS integrations. No ATS, including ours, substitutes for an agency's policies, decisions and appropriate legal advice.
FAQ
Is consent always the correct lawful basis for recruitment?
No, the appropriate basis depends on the purpose and circumstances. Decide and document it before processing, and obtain advice where the position is unclear.
Does GDPR require deletion after a fixed number of years?
There is no single retention period for every candidate record. Your schedule must reflect the purpose and a justified need to retain the information.
Can we send an ATS export straight to a requester?
Review it first for scope, other people's information and any applicable exceptions. The response may also require information beyond the exported records.
Is this legal advice?
No, it is practical information based on the cited UK guidance. Take advice appropriate to your agency's jurisdiction and circumstances.
Sources
ICO guide to lawful basis. Checked 24 September 2026.
ICO storage limitation. Checked 24 September 2026.
ICO guide to subject access updated July 2026. Checked 24 September 2026.
ICO right to erasure. Checked 24 September 2026.
ICO controller and processor contracts. Checked 24 September 2026.