
Does your business currently process, store or otherwise handle information about its customers? If so, then it’s crucial that you clue up on GDPR and understand fully what your new responsibilities will be.
What is GDPR?
General Data Protection Regulation is a piece of legislation that will replace the current Data Protection Act 1998. GDPR is designed to update data protection in the UK, to give more protection to consumers and bring data protection regimes in line with the rest of the EU. Businesses are being advised to see it as a “step change” to existing data protection laws. GDPR is set to come into effect on 25th May 2018, once it passes through the House of Commons and House of Lords to become law.
Among others, the changes for your company include:
- Widening the definition of what constitutes ‘personal data’
- Tightening the rules for obtaining valid consent when it comes to using personal data
- Making it mandatory for organisations of certain sizes to have a designated Data Protection Officer
- Bringing in mandatory privacy impact assessments for data controllers when breach risks are deemed to be high
- A new requirement for notifying authorities of data breaches
- Introducing the right for an individual to be forgotten.

GDPR and Recruitment
The new data protection regulations will affect all businesses and organisations, as well as vital processes such as recruitment. If you are currently recruiting or set to start the search for new talent in 2018, you will need to:
- Review policy on using data from jobs boards
- Amend contractual relationships with all parties with whom you share data
- Start discussions about ‘candidate ownership’ now
- Offer individuals wider access to the data you hold on them and erase data where it is no longer required, where consent is withdrawn or if data processing is unlawful
- Review data security and confidentiality–you may need to take measures such as pseudonymisation or encryption, new data backup and restoration procedures and regular testing of the effectiveness of your security measures.

How can I prepare for GDPR?
Luckily for businesses, there is plenty of guidance available from the Information Commissioner’s Office (ICO) to help them on the road to full GDPR compliance in time for the May 2018 deadline. The Association of Professional Staffing Companies has also produced this handy list of key points to start you thinking along the right lines:
- Review policies and procedures
- Be accountable for your data cycle
- Name a dedicated person responsible for data protection
- Be transparent with your policies
- Justify the use of obtaining data through consent
- Respect the individual’s right to be forgotten
- Work with your suppliers and partners on GDPR compliance
Building Trust with Hiring Managers and Job Seekers
Preparing for GDPR isn’t just about compliance—it’s about building trust with your customers and candidates by ensuring their data is handled responsibly. By reviewing your data policies, securing consent processes, and working closely with your suppliers, your business can turn GDPR compliance into a competitive advantage rather than a burden. Taking proactive steps now will save you time, reduce risk, and help you avoid hefty fines in the future.
If you need guidance on how GDPR affects your recruitment process or want to ensure your hiring practices remain compliant, our team at Adria Solutions is here to help. We understand the complexities of data protection in recruitment and can offer expert advice to keep your business on the right track. Get in touch today to learn more about how we can support you.

Adria Solutions
20+ years supporting your growth
Find the right fit for you
We provide friendly, forward-thinking, 360° recruitment solutions. With two decades of experience in the tech sector, we focus on happy hiring.