Last reviewed: 4 October 2026. This guide is general information, not legal advice. UK GDPR and the Data Protection Act 2018 apply across the UK.
TL;DR
- MCP lets an AI assistant query and act in your CRM. For data protection, it is a new flow of candidate data to a new provider, so treat it like any new supplier.
- The Data (Use and Access) Act 2025 is now fully in force for data protection, according to the ICO. It amends the UK GDPR rather than replacing it.
- Automated decisions about candidates now have their own rules (Articles 22A to 22D UK GDPR, in force since 5 February 2026): safeguards are mandatory, with stricter limits for special category data.
- Check two providers, not one: the CRM vendor and the AI provider the assistant sends data to, including where each is located.
- Below: a checklist to run before any recruiter connects an assistant to your CRM.
What MCP changes for your candidate data
The Model Context Protocol is an open standard that lets an AI assistant call tools in another application. Connected to a recruitment CRM, the assistant can search your candidate pool, read a profile or a CV, summarise a pipeline and, if the server allows it, create records, enrol people in a sequence or send messages.
Two consequences follow for UK GDPR:
- Data leaves your CRM for the assistant. Each answer is built from candidate data that the CRM sends to the AI provider's model. That provider is now part of your processing.
- The assistant can act, not just read. A badly scoped connection can write, message or delete at scale, with your recruiter's permissions.
The ICO's own work on AI tools used in recruitment (November 2024) highlighted risks for people's privacy and information rights in AI sourcing, screening and selection tools. Its guidance on recruitment and selection is aimed explicitly at "recruitment agencies, head-hunters or consultancies", though it is under review following the Data (Use and Access) Act and its final version is still to come.
The Data (Use and Access) Act 2025: what is in force
The Act received Royal Assent on 19 June 2025 (legislation.gov.uk, 2025 c. 18). Its commencement was staged (DSIT, plans for commencement). On 19 June 2026, the ICO updated its guide The DUAA: what does it mean for organisations? to reflect that "all data protection provisions" of the Act "are now in force".
The ICO stresses that the Act "amends, but does not replace" the UK GDPR, the Data Protection Act 2018 and PECR. The points that matter most to an agency using AI:
- Automated decision-making: the full range of lawful bases is now open for significant automated decisions, "so long as you continue to apply appropriate safeguards". This does not apply to special category data.
- Complaints: you must help people make data protection complaints, acknowledge them within 30 days and respond "without undue delay".
- Subject access requests: searches must be "reasonable and proportionate". Expect candidates to ask what an AI tool did with their data.
- Transfers: the test for sending data outside the UK has been reworded.
- Recognised legitimate interests: a new lawful basis for a closed list of purposes, such as protecting public security. It is unlikely to cover routine recruitment.
Automated decisions about candidates
Articles 22A to 22D of the UK GDPR, as substituted by the Act, apply to significant decisions based solely on automated processing. Legislation.gov.uk records them in force since 5 February 2026. Under Article 22C, the controller must put safeguards in place that:
- give the person information about the decision;
- let them make representations;
- let them obtain human intervention;
- let them contest the decision.
Article 22B restricts solely automated decisions based on special category data, such as health or ethnicity, to narrow conditions, including explicit consent.
In recruitment, rejecting an application or ranking someone out of a shortlist with no meaningful human review is a likely candidate for a "significant decision". The ICO is consulting on updated guidance on automated decision-making (draft of 31 March 2026). The simplest policy for an agency: the assistant suggests, a recruiter decides, and that decision is recorded.
International transfers: two hops to check
The ICO's brief guide to international transfers says every restricted transfer must be covered by UK adequacy regulations, appropriate safeguards or an exception. When you connect an AI assistant to a CRM, map both hops.
- To the CRM vendor. If it is in the EEA, the transfer is covered: the Data Protection Act 2018 specifies "an EEA state" for UK adequacy purposes (Schedule 21, paragraph 5).
- To the AI provider. If the model runs outside the UK and EEA, check the mechanism. For the United States, the UK adequacy regulations only cover organisations taking part in the UK Extension to the EU-US Data Privacy Framework. Otherwise, the provider's contract needs appropriate safeguards, such as the ICO's international data transfer agreement.
Also check what the AI provider does with the data: retention, use for model training, and whether your plan comes with a data processing agreement. Business and enterprise plans usually differ from consumer ones on these points, so read the terms of the plan your recruiters actually use.
Checklist before connecting an assistant to your CRM
Governance
- Decide which AI assistants are allowed, on which plan, and who approves new ones.
- Record the use in your record of processing and update your candidate privacy notice.
- Run a data protection impact assessment: UK GDPR Article 35 requires one for processing "likely to result in a high risk", and new technology is a listed factor.
Suppliers
- Get the CRM vendor's DPA and its list of sub-processors, including AI providers and where they are.
- Get the AI provider's terms: data processing agreement, retention, training on your data, location.
- Identify the transfer mechanism for each hop outside the UK.
Access and actions
- Each recruiter connects with their own account, never a shared token.
- The assistant only sees what that recruiter can see in the CRM.
- Bulk or destructive actions (mass messages, deletions, pipeline closures) require a preview or a confirmation.
- You can revoke a connection when a recruiter leaves.
Candidates' rights
- A human makes, and records, every decision that rejects or excludes a candidate.
- Your process can answer an access request about AI use, and acknowledge a complaint within 30 days.
- Special category data (health, diversity monitoring) is kept out of AI prompts unless you have assessed it.
How Marvin's MCP server works
What follows describes Marvin, and only Marvin.
- Hosting: your data is hosted in France (Scaleway, Paris). Our sub-processors, including AI providers, are listed in our DPA, available on request with the rest of our compliance pack. Read more on our security page.
- Your assistant, your contract: Marvin's MCP server works with Claude, ChatGPT and other MCP-compatible assistants. The MCP is included in Marvin plans, and the AI subscription stays your own: the assistant and its model are the ones your agency chose and contracts with, so the checks on the AI provider above apply to it.
- Per-user OAuth: each recruiter connects with their own Marvin account (OAuth 2.1). Every request is filtered by firm and respects the user's role, so the assistant sees no more than the recruiter does.
- Previews before mass actions: several bulk or destructive tools, such as deleting a record, closing a pipeline or processing applications, return a preview by default before they act.
Marvin does not decide on candidates for you, and the MCP does not change who is the controller of your candidate data: your agency is. If you also run a contract desk, see how Marvin handles contract and temp recruitment and timesheets for recruitment agencies. For other compliance changes this year, read our guide to right to work checks since October 2026. Or book a demo to see the MCP on your own data.
Frequently asked questions
What is an MCP server for a recruitment CRM?
MCP (Model Context Protocol) is an open standard that lets an AI assistant such as Claude or ChatGPT call tools in another application. A recruitment CRM's MCP server lets the assistant search candidates, read records and, depending on the tools, create records or send messages, within the permissions of the user who connected it.
Is the Data (Use and Access) Act 2025 in force?
Yes, for data protection. It received Royal Assent on 19 June 2025 and the ICO states that all its data protection provisions are now in force (update of 19 June 2026). It amends, but does not replace, the UK GDPR, the Data Protection Act 2018 and PECR.
Can we let an AI assistant reject candidates automatically?
A solely automated decision with a significant effect on a person, such as rejecting an application, must come with safeguards: information about the decision, a way to make representations, human intervention and a way to contest it. Stricter limits apply where special category data is involved. Keeping a recruiter as the decision-maker is the simplest approach.
Is sending candidate data to an AI provider an international transfer?
It is a restricted transfer if the provider receiving the data is outside the UK. Transfers to the EEA are covered by UK adequacy rules. For the United States, UK adequacy only covers organisations certified under the UK Extension to the EU-US Data Privacy Framework; otherwise you need safeguards such as the ICO's international data transfer agreement.
Where is Marvin hosted, and where are its AI providers listed?
Your data is hosted in France (Scaleway, Paris). Our sub-processors, including AI providers, are listed in our DPA. When you use Marvin through MCP, the assistant and its model are the ones you chose and contract with yourself.
