Recruitment Agency Compliance Checklist for 2026 (US Perm-Placement Focus)

10 min read

Quick Answer: A recruitment agency compliance checklist for a US permanent-placement agency covers five areas:

  1. Anti-discrimination law — EEOC, ADA, and state ban-the-box rules in every screening question and job ad
  2. Pay transparency — salary ranges in job postings where state law requires it, including for third-party recruiters
  3. Background checks — FCRA consent and adverse-action notices if you run them
  4. Candidate data handling — retention limits, secure storage, and deletion on request, plus GDPR if you actively source or advertise to candidates in the EU
  5. Contracts and misclassification — getting perm-placement vs. contract/temp status right so you don't create an accidental employer relationship

Most of this is process and paperwork, not software.

JuggleHire's Pro plan ($149/mo) includes GDPR export, deletion, and retention controls plus an activity log with CSV export; it does not do background checks or EEOC/OFCCP reporting today.

Last Updated: September 11, 2026


Compliance isn't the fun part of running a placement agency. It's also the part that turns into a real problem at the worst possible time — a candidate complaint, a state audit, a client asking "can you prove you didn't discriminate against this applicant." This checklist is built for a small US permanent-placement agency (2–8 staff): what you're actually on the hook for, what a background-check gap looks like, and what a candidate-tracking tool can and can't do for you.

This is not legal advice. Laws vary by state and change often — verify anything time-sensitive with an employment attorney before you act on it.


#The Checklist

#1. Anti-discrimination — EEOC, ADA, and state law

  • [ ] Job ads and screening questions avoid protected-class language (age, race, sex, disability, national origin, religion) — including indirect proxies like "recent college grad" or "native English speaker"
  • [ ] Interview scorecards ask the same structured questions of every candidate for a role, so a rejection can be justified on job-related criteria
  • [ ] You know your state's ban-the-box rule — timing varies by jurisdiction (some bar the criminal-history question until after an interview, others until after a conditional offer), and only 15 states plus DC extend the rule to private employers (NELP), which is most agencies' entire client base
  • [ ] Reasonable-accommodation requests (ADA) have a documented process, even if you've never received one yet
  • [ ] Rejection reasons are logged somewhere retrievable — not just "no" with no record of why

#2. Pay transparency

  • [ ] Job postings include a salary range wherever you're posting into (or hiring remotely into) one of the 16 states plus DC with a pay-transparency law as of September 2026 — including 2026 additions like Massachusetts, Virginia (eff. 2026-07-01), and Maine (eff. 2026-07-29) — remote roles inherit the law of any covered state the role can be performed from
  • [ ] You know whether your state is one that explicitly binds third-party recruiters and staffing agencies posting on an employer's behalf — Illinois makes the third-party poster liable unless it can show the client never supplied the pay scale and benefits (get it in writing), and New Jersey explicitly names employment agencies as covered entities
  • [ ] You don't ask candidates for salary history in states with a salary-history ban

#3. Background checks (if you run them)

  • [ ] You have written candidate consent before pulling a background check — required under the Fair Credit Reporting Act (FCRA)
  • [ ] You issue a pre-adverse-action notice before rejecting someone based on the report — this notice must include a copy of the report and "Summary of Your Rights Under the Fair Credit Reporting Act" (FCRA §604(b)(3))
  • [ ] After a reasonable waiting period (5 business days is common practice), you issue the final adverse-action notice — it must state the CRA's name/address/phone, that the CRA did not make the hiring decision, and the candidate's right to dispute the report or get a free file disclosure from the CRA
  • [ ] Your background-check vendor is FCRA-compliant — most established providers (Checkr, Sterling (now part of First Advantage), HireRight) build the consent/notice flow in

#4. Candidate data — retention, security, deletion

  • [ ] You have a stated retention period for candidate data. Federal law sets the floor — the EEOC requires application and hiring records be kept at least 1 year (29 CFR 1602.14). Federal contractors face a separate OFCCP rule (41 CFR 60-1.12): 2 years only if you have 150+ employees and a federal contract of $150,000 or more; otherwise 1 year. Either way, records must be kept indefinitely once a charge or lawsuit is filed. State law can add more on top.
  • [ ] Candidates can request their data be deleted or exported, and you have a way to actually do it — not just a promise in a privacy policy
  • [ ] Resumes, notes, and interview scores are stored somewhere access-controlled, not a shared inbox or a spreadsheet everyone can edit
  • [ ] You know who on your team can see what — a growing agency with 5+ recruiters needs role-based access, not "everyone sees everything"
  • [ ] You can answer "who changed this candidate's status, and when" for any candidate, going back at least a year — activity logged automatically, not manually noted, since manual notes get skipped under deadline pressure
  • [ ] You can export the full activity log if a client or regulator ever asks for it

#5. GDPR (only if you touch EU candidates)

GDPR can apply if you actively source, advertise to, or screen candidates who are physically in the EU. It hinges on whether you target the EU market, not on where a candidate holds citizenship — incidental contact with one EU-based applicant usually doesn't trigger it on its own. If you run EU-facing sourcing campaigns, treat it as in scope.

  • [ ] Candidates can request export or deletion of their data
  • [ ] You have a Data Processing Agreement (DPA) in place with every sub-processor that touches candidate data (your ATS, your email tool, your background-check vendor), and your sub-processor list is disclosed somewhere a candidate can find it
  • [ ] Cookie consent is in place on your career page if it's public-facing in the EU — this is an ePrivacy/cookie-law obligation that sits alongside GDPR, not part of the GDPR articles themselves

Most US-only perm-placement agencies never trigger this. Tech and finance placements occasionally do, since remote candidates cross borders more than other verticals.

#6. Contracts and misclassification

  • [ ] Your placement agreements clearly state fee structure, guarantee period, and who employs the candidate post-placement (the client, in perm placement)
  • [ ] If you also run temp or contract placements, confirm who is employer of record on each placement — see the FAQ below for how that changes your compliance surface

#What a Compliance-Minded Recruitment CRM Should Give You

Capability Why it matters JuggleHire
Structured, consistent screening questions per role Defensible, job-related rejection criteria
Interview scorecards Same structured evaluation for every candidate
DPA + public sub-processor disclosure Required if any EU candidates Sold under Pro
Data export on request GDPR + general good practice Sold under Pro
Data deletion on request GDPR + general good practice Sold under Pro
Retention settings Auto-enforce a data-retention window Sold under Pro
Activity log with CSV export Answer "who did what, when" Sold under Pro
Background-check vendor integration (Checkr, First Advantage, etc.) Run the FCRA screen itself ✗ (not built)
EEOC/OFCCP reporting Federal contractor compliance reporting ✗ (not built)

Honest note on plans: the GDPR data-control features — export, deletion, retention settings, DPA and sub-processor disclosure — and the activity log are sold on JuggleHire's Pro plan ($149/mo, unlimited team members), not Light ($79/mo, up to 5 team members). If GDPR data controls or an audit trail are a real requirement for your agency, that's the case for Pro over Light. Both plans include the 14-day trial (credit card required).


#What This Checklist Doesn't Cover

  • Temp/contract staffing compliance — JuggleHire is built for perm placement only; it doesn't have timesheet or VMS functionality. See the FAQ for how that compliance surface differs.
  • State-by-state ban-the-box and pay-transparency specifics — these change often enough that a general checklist can't keep up. Check your state and any city-level ordinances directly.
  • Full FCRA procedural detail — if you run background checks in-house rather than through a compliant vendor, get counsel involved.

#FAQ

#Does a small staffing agency need a formal compliance program?

Yes, even at 2–8 staff. Title VII and the ADA normally apply at 15+ employees, but an employment agency is covered when it regularly places candidates with employers of that size — so a 3-person agency placing into mid-size clients is on the hook through that route, not its own headcount. A formal program (written policies, training) becomes more expected as you grow past a handful of recruiters, but the underlying legal obligations exist from day one.

#Is GDPR relevant to a US-only staffing agency?

Only if you actively source, advertise to, or screen candidates who are physically in the EU — remote tech and finance placements are the most common way this happens for a US agency. Incidental contact with one EU-based applicant usually doesn't trigger it on its own; running EU-facing sourcing campaigns does.

#Does JuggleHire run background checks?

No — no vendor integration and no place to store the consent form; keep it with your CRA. Checkr, First Advantage (Sterling), and HireRight all run outside JuggleHire. If you're running the actual screen, you're doing that step on whichever vendor platform you use, and tracking the consent and notice timing carefully regardless.

#What's the difference between compliance for perm placement vs. temp/contract staffing?

Perm placement's main compliance surface is anti-discrimination, pay transparency, background-check procedure, and candidate data handling — the client employs the candidate once placed. Temp/contract staffing adds payroll, timesheets, and worker-misclassification risk, because the agency itself may be the employer of record. That's a different compliance surface, not simply a bigger one, and JuggleHire is built for perm placement and doesn't cover the temp/contract layer.

#Which JuggleHire plan do I need for GDPR and audit-log compliance?

Pro ($149/mo, unlimited team members) — the GDPR data controls (export, deletion, retention), the DPA and sub-processor disclosure, and the activity log with CSV export are all Pro-only. Light ($79/mo) covers candidate database, AI ranking, scheduling, and offer e-signature, but not the Pro-only compliance controls.


#Bottom Line

Compliance for a small perm-placement agency is mostly discipline — consistent screening, documented decisions, a real retention policy — not software. But the tool you run candidates through determines whether "who touched this record and when" is a two-click export or a scramble through email threads. If GDPR data controls or an audit trail matter to your agency, JuggleHire's Pro plan covers both for one flat $149/month; Light ($79/month) is the right fit if those controls aren't a requirement yet. See pricing for the full breakdown of both plans.


#Related Resources

Zakir Hossen profile image

Zakir Hossen

Zakir, founder of JuggleHire - a Google Forms alternative for hiring. Bootstrapped entrepreneur and software engineer with 10+ years coding experience from BD.

More posts from Zakir Hossen

Related Posts