Legal

Data processing summary

A plain-English summary of how yournextjob processes applicant data on behalf of employers. It sets out who does what, how we protect the data, and what you can ask us to do.

Last updated: 10 July 2026

The short version. When a jobseeker applies to your advert, you are the controller for their data (you decide what happens to it) and yournextjob is your processor (we handle it on your instructions to run the service). This page summarises that relationship. It forms part of the employer and advertiser terms and applies to every employer who receives applicant data through the platform.

Who is the controller and who is the processor

Under the UK GDPR, the controller decides why and how personal data is used, and the processor acts on the controller's instructions.

  • For jobseekers using the site, running accounts and gathering applications, yournextjob is the controller. That is covered by our privacy policy.
  • Once you receive an application, you (the employer) are the controller for that applicant's data, because you decide how to assess, contact and keep it.
  • For the parts of the service where we handle that applicant data on your behalf, such as storing applications in your dashboard, passing messages between you and candidates, and helping you organise your pipeline, yournextjob is your processor.

Scope of processing

  • Subject matter and duration. Processing applicant data so you can receive, review, respond to and manage applications, for as long as you use the service or until the data is deleted as described below.
  • Nature and purpose. Storing, organising, displaying and transmitting applicant data, and enabling messaging between you and candidates, so you can run your recruitment.
  • Types of data. Applicant name, email address, phone number, CV and its contents, cover notes, screening answers, application status and messages.
  • Categories of people. Jobseekers who apply to your adverts, and candidates you contact through the talent database who reply to you.

Acting on your instructions

We process applicant data only on your documented instructions, which are given through the way you use the platform and through these terms, unless the law requires otherwise. Our staff and anyone acting for us are bound by a duty of confidentiality. We will tell you if we believe an instruction breaks data protection law. We do not use applicant data you control for our own purposes, and we do not sell it.

Security measures

We take appropriate technical and organisational measures to protect personal data, including:

  • encryption of data in transit using HTTPS across the site;
  • hashed passwords, never stored in plain text;
  • protection against cross-site request forgery on forms, and rate limiting to block abuse;
  • access controls, so only authorised people can reach personal data, scoped so an employer only ever sees their own jobs, applicants and messages;
  • segregation of each employer's data from other employers';
  • regular backups and measures to help restore availability after an incident;
  • ongoing review of our security as the service changes.

No online service can be completely secure, but we work to keep the risk low and to match our measures to the sensitivity of the data.

Sub-processors

We use a small number of trusted providers to help run the service, for example hosting, email delivery and payment processing. These act as our sub-processors, receive only the data they need, and are bound by written terms that require them to protect it to a standard at least as strict as this summary. We remain responsible to you for what our sub-processors do. If we plan to add or change a sub-processor that handles applicant data, we will make the current list available on request and give you a fair chance to object on reasonable data-protection grounds before the change takes effect.

International transfers

We store and process applicant data in the UK or the European Economic Area wherever we can. If a sub-processor processes data outside those areas, we rely on the safeguards allowed under UK data protection law, such as approved standard contractual clauses, so the data keeps an equivalent level of protection.

Breach notification

If we become aware of a personal data breach affecting applicant data we process for you, we will notify you without undue delay after becoming aware of it. We will give you the information you reasonably need to meet your own obligations, including what happened, the likely consequences, the data and people affected as far as we know, and the steps we are taking. As the controller, you are responsible for deciding whether the breach must be reported to the ICO or to the people affected, and for making any such report.

Data-subject requests

If an applicant contacts us to exercise their rights (for example access, correction, deletion or objection) about data you control, we will pass the request on to you and help you respond, taking into account the nature of the processing and the information available to us. Where you need to act on a request, you can use the tools in your dashboard, and we will assist where those tools do not cover it. If an applicant asks us directly, we may confirm that we act as a processor and direct them to you as the controller.

Return and deletion on request

You control how long you keep applicant data, subject to your own retention obligations. You can delete applications and candidate messages from your dashboard. When you ask us to, or when you close your account, we will delete or return the applicant data we hold for you within a reasonable period, and delete existing copies, unless the law requires us to keep some of it. Deletion from live systems happens promptly; residual copies in backups are removed on our normal backup cycle.

Records and cooperation

We keep records of the processing we carry out for you, and we will make available the information reasonably needed to show we meet these obligations, and cooperate with audits or inspections you or a regulator may reasonably require, on reasonable notice and subject to confidentiality.

Changes to this summary

We may update this summary from time to time. When we do, we will change the "last updated" date above, and for significant changes we will make it clear to employers.

Contact us

For anything about how we process applicant data, email hello@yournextjob.co.uk. yournextjob is operated by [Registered company name], company number [Company number], registered office [Registered office address], ICO registration number [ICO registration number].