Skip to main content
All posts

Agency Operations

Recruiting Compliance: A 2026 Checklist for Staffing Agencies

Recruiting compliance is no longer just a data-protection checkbox. GDPR, anti-discrimination law, and now the EU AI Act all touch how agencies handle candidates. Here is what each one actually requires, and how to stay compliant without slowing your desks down.

Written by: Saply Team

Recruiting Compliance: A 2026 Checklist for Staffing Agencies

Recruiting compliance is the set of legal obligations a staffing agency or in-house team must meet when it sources, screens, stores, and submits candidates. In 2026 it spans four areas: data protection (how you hold candidate data), anti-discrimination law (how you select), regulation of AI hiring tools (the newest and fastest-moving), and worker classification (how contractors are engaged). Getting it wrong is not abstract risk: it is fines, disqualification from client frameworks, and lost placements.

Most agencies treat compliance as a data-protection question and stop there. That was defensible three years ago. It is not now, because the tools recruiters use every day to screen and rank candidates have themselves become regulated. This guide covers what recruiting compliance means today, what each area requires, and how to build the checks into your workflow instead of bolting them on after an audit.

The four areas recruiting compliance covers

Compliance is not one rule, it is four separate bodies of law that happen to meet on the same desk. Treating them as one blurry obligation is how agencies miss the specific thing each one demands.

Data protection How you hold and retain candidate data. GDPR Anti- discrimination How you select, and whether it has adverse impact. EEO, Equality Act AI hiring tools How your screening and ranking software is governed. EU AI Act, LL144 Worker classification How contractors are engaged and taxed. IR35, AWR

The rest of this article works through each pillar in turn, then covers how to run the checks without turning every submission into a legal review.

Data protection: hold less, for a clear reason, and delete on schedule

For European agencies the governing text is the General Data Protection Regulation. A candidate CV is personal data the moment it lands in your inbox, and everything you do with it (parsing, storing, sharing with a client, keeping it for a future role) is processing that needs a lawful basis and a retention limit.

Three obligations matter most on a recruitment desk:

  • A lawful basis for each use. Submitting a candidate to the role they applied for is usually straightforward. Keeping them in a talent pool for future vacancies is a separate purpose that needs its own basis, most often consent, and consent has to be freely given and withdrawable at any time.
  • Storage limitation. The GDPR does not name a fixed number of months. It requires you to keep data only as long as necessary for the purpose you collected it for, then delete or anonymize it. That means you need a written retention schedule you actually enforce, not a database that grows forever.
  • Candidate rights. Access, correction, and erasure requests have to be answerable. If you cannot find every copy of a candidate’s data across your ATS, your inbox, and three shared drives, you cannot honor a deletion request, which is itself the breach.

The most common agency mistake is keeping every CV forever “just in case”. A recruiting database with a clear retention policy and consent status on each record is an asset. The same database with no retention rules is a liability that grows every day, and it is the first thing a data protection authority asks to see.

Where data is processed and stored is a compliance question in its own right, not just an IT preference. For agencies serving European clients, EU data residency is one of the first things a client’s data protection officer will check before signing. (Saply processes and stores candidate data in the EU; see our security overview for the specifics.)

Anti-discrimination: your process has to survive an adverse-impact test

Selection has to be based on ability to do the job, not on protected characteristics. That principle is old. What has changed is that regulators increasingly look at outcomes, not just intent, and outcomes are measurable.

In the United States the reference test is the four-fifths rule, set out in the EEOC’s Uniform Guidelines guidance: if the selection rate for any protected group is less than 80% of the rate for the highest-selected group, that may indicate adverse impact and invites scrutiny. A worked example makes it concrete.

GroupApplicantsAdvancedSelection rateRatio to top group
Group A1006060%reference (highest)
Group B1004545%75%
Group C1003030%50%

Group B and Group C both fall below the 80% threshold, so a screening step producing these numbers would signal potential adverse impact even if no one intended it. The practical takeaway for a staffing agency is that you should be able to look at your own funnel this way. If you cannot, you are relying on the assumption that your process is fair rather than the evidence.

One structural way to reduce bias at the first pass is to remove identifying details before a human or a tool ranks candidates. That is the logic behind blind recruitment: strip the name, photo, age, and other signals that correlate with protected characteristics so the shortlist is built on skills and experience. It does not make your process compliant on its own, but it removes an obvious source of first-impression bias.

AI hiring tools are now regulated, and the tool becomes your risk

This is the pillar most agencies have not caught up on. The software you use to screen and rank candidates is no longer just a productivity choice, it is a regulated system in a growing number of jurisdictions.

AI used to screen or rank candidates Annex III = high-risk system Documentation and record-keeping Human oversight of every decision Monitoring and adverse-impact checks

Under the EU Artificial Intelligence Act, AI systems used for recruitment and candidate evaluation are listed in Annex III as high-risk. That classification carries real duties: the provider of the tool and the agency deploying it both have obligations around technical documentation, human oversight, data quality, and ongoing monitoring. The Act applies on a staged timeline, with high-risk obligations phasing in over the period set out in the regulation itself, so the correct move is to check the current dates in the official text rather than assume you have unlimited runway.

In the United States there is no single federal AI hiring law, but city and state rules are appearing. New York City’s Local Law 144 requires an independent bias audit of an automated employment decision tool before it is used for hiring or promotion, plus notice to candidates that the tool is in use. The EEOC has also made clear that using an AI tool is not a defense: if the tool produces a discriminatory outcome, the employer is still liable under Title VII.

The honest implication for agencies: adopting an AI screening or matching tool does not offload compliance risk, it adds a system you now have to govern. Ask any vendor where the model runs, whether it supports human review of every ranking, and whether it can produce the documentation an audit needs. A tool that ranks candidates in a black box is a liability wearing the costume of efficiency.

This is exactly why AI candidate matching should surface why a candidate scored the way they did and keep a recruiter in the decision, rather than auto-rejecting. Explainability and human oversight are not just good practice now, they are close to what the regulation expects.

Worker classification: who is actually the employer

The fourth pillar is quieter but expensive when it goes wrong. When an agency places contractors, someone has to determine the worker’s employment status for tax, and in some engagements someone has to operate payroll deductions.

In the UK, the off-payroll working rules (IR35) put the obligation to determine status on medium and large private-sector clients, and where the rules apply the fee-payer is responsible for deducting income tax and National Insurance through PAYE. HMRC’s Check Employment Status for Tax tool is the reference point. The compliance question for an agency is a chain of specifics: is the client small, are you the fee-payer, and is the engagement inside or outside IR35. Getting the answer wrong shifts a tax liability onto your business.

The equivalent question exists in every market: whether a placed worker is an employee, an agency worker with specific protections, or a genuine contractor. The rules differ by country, but the discipline is the same. Document the determination, keep the paperwork, and do not let a client push a classification that the facts do not support.

How to run the checks without slowing your desks down

Recruiters will route around compliance the moment it costs them placements, so the goal is to make the compliant path the fast path. A few principles keep it workable:

  • Build consent and retention into intake, not into an annual cleanup. Capture consent status and a deletion date when the candidate enters your system, so retention enforces itself.
  • Make your funnel measurable. If you can pull selection rates by stage, you can run an adverse-impact check in minutes instead of discovering a pattern in a complaint.
  • Standardize the submission. A consistent candidate format that strips identifying data by default supports both blind screening and clean client-facing documents. This is one place CV formatting and compliance overlap: the same step that makes a submission look professional can also remove the fields you do not want influencing a decision.
  • Vet your AI tools like a regulated system. Before adopting anything that screens or ranks, ask for its documentation, its data-residency answer, and proof that a human stays in the loop.

None of this replaces legal advice for your specific jurisdictions, and this article is not that advice. What it does is give you the map: four areas, each with a concrete obligation, none of which you can safely ignore in 2026. For the wider operational picture, see our staffing agency best practices guide.

Frequently asked questions

What does recruiting compliance actually cover?

It covers four areas: data protection (holding candidate data lawfully, with a retention limit), anti-discrimination (selecting on ability, with outcomes that survive an adverse-impact test), regulation of AI hiring tools (the EU AI Act, NYC Local Law 144, and EEOC guidance), and worker classification (correctly determining contractor status, such as under IR35). Data protection alone is no longer enough.

How long can a recruitment agency keep candidate data under GDPR?

The GDPR does not set a fixed period. It requires you to keep data only as long as necessary for the purpose you collected it for, then delete or anonymize it. In practice you need a written retention schedule and a separate lawful basis (usually consent) if you want to hold candidates for future roles rather than the one they applied to.

Is using an AI recruiting tool against compliance rules?

No, but it makes the tool part of your compliance surface. Under the EU AI Act, recruitment AI is classified as high-risk with obligations for documentation, human oversight, and monitoring. In some US jurisdictions, such as New York City, an automated employment decision tool needs an independent bias audit before use. Adopting AI does not remove liability for a discriminatory outcome.

What is the four-fifths rule in recruiting?

It is a screening test from the EEOC’s Uniform Guidelines. If the selection rate for a protected group is less than 80% of the rate for the highest-selected group, that may indicate adverse impact and invites scrutiny. Agencies can apply it to their own funnel by comparing advance rates across groups at each stage.

Does recruiting compliance differ for staffing agencies versus in-house recruiters?

The core obligations are shared, but agencies carry extra load in two areas: they are data controllers or processors for candidates they may never place, and they sit inside worker-classification rules like IR35 as the potential fee-payer. In-house teams face the same data-protection and anti-discrimination duties without the classification complexity of supplying contractors.