AITACS Talent — Recruiting Calendar & CRM Suite  ·  Terms · Privacy · Informed Consent
AITACS Talent — Legal Documentation

Recruitment Data Sharing Agreement

Controller-to-Controller Agreement governing a Recruiter's disclosure of Candidate data to a Client Employer for a specific Vacancy

Effective Date: 2026-07-13  ·  Last Updated: 2026-07-13  ·  Version: 0.1-draft

GDPR
What This Document Is — And Is Not

This Agreement governs the disclosure of a Candidate's personal data by a Recruiter to a Client Employer — the company on whose behalf an agency or third-party Recruiter is sourcing candidates for a given Vacancy. It is not a processor/sub-processor agreement — the Recruiter and the Client Employer act as two independent data controllers with respect to that disclosure, each responsible for its own compliance. It does not apply to the relationship between the Recruiter and the Platform (the Provider), which is instead governed by the Data Processing Agreement.

1. Definitions

"Agreement" means this Recruitment Data Sharing Agreement, as amended from time to time.
"Recruiter" means the agency or third-party recruiter using the Platform who discloses Candidate data to a Client Employer for a specific Vacancy.
"Client Employer" means the company on whose behalf the Recruiter is sourcing Candidates for a given Vacancy, and to whom the Recruiter discloses Candidate data under this Agreement.
"Candidate" means the natural person whose personal data is disclosed under this Agreement, as defined in the Terms of Service.
"Vacancy" means the specific open position for which the Recruiter is sourcing Candidates on behalf of the Client Employer, as defined in the Terms of Service.
"Independent Controllers" means that the Recruiter and the Client Employer each independently determine the purposes and means of their own processing of Candidate data, and are not joint controllers within the meaning of GDPR Article 26 unless they expressly agree otherwise in writing for a specific engagement.
"Breach" means the unauthorized acquisition, access, use, or disclosure of Candidate personal data that compromises its security, confidentiality, or integrity (GDPR Art. 4(12)).

2. Parties

Disclosing Party

The Recruiter

An agency or third-party recruiter using the Platform to source Candidates on behalf of a Client Employer, who discloses Candidate data to that Client Employer for a specific Vacancy.

Receiving Party

The Client Employer

The company on whose behalf the Recruiter is sourcing Candidates, who receives Candidate data from the Recruiter for the purpose of evaluating and, where applicable, hiring for the Vacancy.

2.1. This Agreement applies whenever a Recruiter discloses a Candidate's personal data to a Client Employer through or in connection with the Platform. It supplements, and does not replace, each party's own obligations under applicable data-protection law.

2.2. The Platform (operated by the Provider) is not a party to this Agreement and does not review, enforce, or become responsible for the disclosure it governs; the Platform's own obligations to the Recruiter are set out separately in the Data Processing Agreement.

3. Purpose Limitation

3.1. The Client Employer may use Candidate data disclosed under this Agreement solely for the purpose of evaluating that Candidate for the specific Vacancy for which it was disclosed.

3.2. The Client Employer shall not use Candidate data disclosed under this Agreement for any other purpose, including but not limited to: building a general marketing or recruitment database, sourcing the Candidate for a different, unrelated Vacancy without a fresh disclosure and legal basis, or sharing the data with any other third party except as strictly necessary to run its own hiring process for that Vacancy (e.g., its own internal hiring managers or interview panel).

3.3. Where the Client Employer wishes to consider the Candidate for a different Vacancy, it must obtain the data afresh through the Recruiter (or directly from the Candidate with an independent legal basis) — this Agreement does not authorize repurposing.

4. Anti-Discrimination Obligations

No Protected Characteristics

The Platform's Candidate data schema does not collect date of birth, gender, race, ethnicity, religion, marital status, or health information (see Privacy Policy §1). The Client Employer shall not request that the Recruiter supplement disclosed Candidate data with any such information, and shall not independently seek it from the Candidate as a condition of considering them for the Vacancy, except where a specific, narrow exception under applicable equal-employment-opportunity or accessibility law applies (e.g., a lawfully requested accommodation).

4.1. Both parties remain independently responsible for complying with applicable anti-discrimination and equal-employment-opportunity law in their use of Candidate data disclosed under this Agreement.

5. Obligations of Both Parties

Confidentiality. Each party shall keep Candidate data disclosed under this Agreement confidential and shall not disclose it to any third party except as strictly necessary to run its own hiring process for the Vacancy, or as required by law.
Security. Each party shall implement appropriate technical and organizational measures to protect Candidate data against unauthorized access, loss, or disclosure, proportionate to the sensitivity of the data involved.
Accuracy. The Recruiter shall take reasonable steps to ensure Candidate data disclosed to the Client Employer is accurate and up to date at the time of disclosure.
Data Subject Rights. Where a Candidate exercises a right under GDPR Articles 15–22 (or equivalent local law) with respect to data held by the Client Employer, the Client Employer is responsible for responding as an independent controller; where the request concerns data held only by the Recruiter or the Platform, the Recruiter (as the Platform's Controller) is responsible, per the Privacy Policy §6.
Retention and Deletion. The Client Employer shall not retain Candidate data disclosed under this Agreement for longer than necessary to complete its hiring process for the Vacancy, and in any event shall delete or return the data once a hiring decision has been made and any legally required retention period for that decision has elapsed (see Section 6 below).

6. Retention Period

6.1. Absent a longer or shorter period required by applicable employment or data-protection law, the Client Employer should retain Candidate data disclosed under this Agreement for no longer than 12 months by default after the hiring decision for the Vacancy (hire or reject), after which it should be deleted. This is a recommended default for the Client Employer's own retention of disclosed data — a separate question from how long the Candidate's record remains in the Platform itself, which the Recruiter controls (see Privacy Policy §10).

6.2. Where the Client Employer is subject to a specific statutory retention requirement for hiring records (which varies by jurisdiction and by whether the Candidate was hired), that requirement controls instead of the 12-month default.

6.3 Reserved — United States

[РЕЗЕРВ: строки зберігання записів про найм за федеральним/штатним трудовим правом США (наприклад, EEOC record-keeping вимоги) — буде додано перед виходом продукту на ринок США.]

6.4 Reserved — Canada

[РЕЗЕРВ: строки зберігання записів про найм за федеральним/провінційним трудовим правом Канади — буде додано перед виходом продукту на канадський ринок.]

6.5 Reserved — United Kingdom

[РЕЗЕРВ: строки зберігання записів про найм за трудовим правом Великої Британії — буде додано перед виходом продукту на ринок Великої Британії.]

7. Breach Notification

7.1. If either party becomes aware of a Breach affecting Candidate data disclosed under this Agreement, it shall notify the other party without undue delay, and in any event no later than 72 hours after becoming aware of the Breach, consistent with GDPR Art. 33.

7.2. The notification shall include, to the extent available: the nature of the Breach, the categories and approximate number of Candidates affected, the likely consequences, and the measures taken or proposed to address it.

7.3. Each party remains independently responsible for its own notification obligations to supervisory authorities and to affected Candidates under applicable law; this Section only governs notification between the two parties.

8. Further Disclosure

8.1. Where the Client Employer engages a further third party (e.g., a background-check provider or an internal ATS) to process Candidate data disclosed under this Agreement, the Client Employer remains responsible for ensuring that third party is bound by data-protection obligations at least as protective as those in this Agreement.

8.2. This Agreement does not authorize the Client Employer to disclose Candidate data to any party outside its own hiring process for the Vacancy without the Candidate's knowledge or an independent legal basis.

9. Term and Termination

9.1. This Agreement applies for as long as the Client Employer holds Candidate data disclosed under it, regardless of whether the Recruiter's engagement with the Client Employer or the Recruiter's subscription to the Platform has ended.

9.2. Upon completion of the hiring process for the Vacancy (or upon the Candidate's valid request, where applicable), the Client Employer shall, at its own election: (a) return the Candidate data to the Recruiter in a structured, machine-readable format; or (b) delete the data and confirm deletion upon request — subject to the retention period in Section 6.

9.3. The obligations in Sections 3 (Purpose Limitation), 4 (Anti-Discrimination), 5 (Obligations of Both Parties), 6 (Retention Period), and 7 (Breach Notification) survive for as long as either party retains Candidate data disclosed under this Agreement.

10. Miscellaneous Provisions

10.1. Amendment. This Agreement may be amended by the Provider upon thirty (30) days' prior written notice to Recruiters through the Platform. Continued use of the Platform's Client Employer disclosure feature after such notice constitutes acceptance of the amended Agreement.

10.2. No Third-Party Beneficiaries. Nothing in this Agreement confers any rights, remedies, or claims upon the Candidate directly against either party beyond the Candidate's own statutory rights under applicable data-protection law.

10.3. Severability. If any provision of this Agreement is found unenforceable or invalid under applicable law, that provision shall be modified to the minimum extent necessary to make it enforceable, and all remaining provisions remain in full force and effect.

10.4. Force Majeure. Neither party is liable for delays or failures in performance caused by events beyond its reasonable control, provided that this does not excuse either party's breach notification obligations under Section 7.

10.5. Electronic Acceptance. This Agreement may be accepted electronically; continued use of the Platform's Client Employer disclosure feature after notice of this Agreement is deemed legally equivalent to a handwritten signature, to the extent permitted by applicable law.

10.6. Governing Law. This Agreement is governed by the laws of the State of Israel, consistent with Terms of Service §9, without prejudice to the mandatory data-protection law described in §9.1 of that document, which applies in parallel where relevant.

11. Contact

For questions about this Agreement:

Artem Chukov — Provider
Email: talent@aitacscrm.app
Web: aitacscrm.app/talent

Related Compliance Documents

Terms of Service · Privacy Policy · Informed Consent Template · Cookie Policy · Data Processing Agreement (DPA) · Recruitment Data Sharing Agreement · Subprocessor List · Security Requirements · Incident Response Policy · Security Overview · Refund Policy · Copyright Policy · Contact Us