"Speculative CV forwarding" to drum up client interest isn't a recruiting technique — under GDPR, it's an unlawful processing activity, and you have a direct financial remedy against both the agency and the client.
Lawful Bases for Processing Under Article 6 GDPR
In European recruitment markets, third-party recruitment agencies frequently collect candidate CVs and forward them to potential client companies. Doing this without clear legal authorization is unlawful processing under Article 6 GDPR — regardless of how routine the practice may feel within the industry.
The prohibited practice, sometimes called "speculative spec'ing": forwarding an unredacted candidate CV to third-party clients without the candidate's knowledge, purely to generate prospective business opportunities for the agency.
The lawful protocol (Article 6(1)(a) and (b)): recruitment intermediaries must obtain clear authorization or explicit consent before disclosing an identifiable candidate profile to any specific external third party.
Joint Controllership vs. Data Processor Relationships
When an agency shares your data with a client company, their respective regulatory obligations depend on the structural relationship between them under Articles 26 and 28 GDPR:
- Independent data controllers: if the agency and the client each independently determine the purposes and means of processing your data, both entities are individually accountable.
- Joint controllers (Article 26): if both entities jointly determine the processing objectives, they're required to have a transparent arrangement defining their respective compliance responsibilities — and critically, that arrangement doesn't reduce either party's accountability to you.
Your Remedies If This Happens to You
- Filing a complaint (Article 77 GDPR): you can lodge an official complaint with your national Supervisory Authority — the AEPD in Spain, the DPC in Ireland, the CNIL in France, or the equivalent in your country.
- Administrative penalties (Article 83 GDPR): supervisory authorities can impose fines of up to €20 million or 4% of the company's total worldwide annual turnover, whichever is higher, for breaches of fundamental processing principles like this one.
- Compensation for damages (Article 82 GDPR): you have a statutory right to seek court-ordered material and non-material compensation from both the agency and the client company for the privacy infringement — this is a direct financial remedy, not just a regulatory penalty that goes to the state.
What This Means for You
If you discover your CV was forwarded to a company you never applied to or authorized, you have a genuine, actionable claim — this isn't just poor recruiting etiquette. Request confirmation from the agency of exactly who your CV was shared with and on what legal basis.
Generate a formal complaint using our Employment Data Access Request tool, which covers exactly this scenario.
Related Kibbo Tools
- Employment Data Access Request (GDPR/Privacy) →
- GDPR Job Application Privacy Checklist →
- Privacy & Data Protection (Directory) →
Sources
- EUR-Lex — Regulation (EU) 2016/679 (GDPR), Article 6. eur-lex.europa.eu
- European Data Protection Board — Guidelines 07/2020 on the concepts of Controller and Processor. edpb.europa.eu