Security and compliance

Cyber security and GDPR basics for recruitment firms.

Part of our complete guide to IT support for recruitment firms.

An ATS full of CVs, contact details, and sometimes salary history is personal data under UK GDPR, whether or not anyone at the firm thinks of it that way day to day. This is not a legal deep dive, it's the practical baseline most independent recruitment firms are missing.

Multi factor authentication, everywhere it's offered

This single control blocks the majority of account takeover attempts. If email, CRM, and any finance tools don't already have it switched on, it's the fastest security improvement available and usually free.

One identity system for everything

Consolidating logins under a single identity provider, such as Microsoft 365 or Google Workspace, means access can be granted and revoked in one place. Without it, offboarding and security both get harder, as covered in our guide to stopping a leaving consultant taking candidate data with them.

Backups that are actually tested

A backup nobody has tried to restore from is a backup you don't actually have. Microsoft 365 and Google Workspace do not fully back up your data by default in the way most owners assume.

A written offboarding process

Given how much turnover recruitment sees, an ad hoc approach to leavers is a live data protection risk, not just an operational inconvenience.

What GDPR actually requires, in plain terms

This is general guidance, not legal advice. If you're unsure where your firm stands, a data protection specialist can confirm what applies to your specific setup.

Find out where your IT stands in 20 minutes.

Free IT health check for London recruitment firms. No commitment, no sales pitch.

Take the free health check →