Cyber security and GDPR basics for recruitment firms.
An ATS full of CVs, contact details, and sometimes salary history is personal data under UK GDPR, whether or not anyone at the firm thinks of it that way day to day. This is not a legal deep dive, it's the practical baseline most independent recruitment firms are missing.
Multi factor authentication, everywhere it's offered
This single control blocks the majority of account takeover attempts. If email, CRM, and any finance tools don't already have it switched on, it's the fastest security improvement available and usually free.
One identity system for everything
Consolidating logins under a single identity provider, such as Microsoft 365 or Google Workspace, means access can be granted and revoked in one place. Without it, offboarding and security both get harder, as covered in our guide to stopping a leaving consultant taking candidate data with them.
Backups that are actually tested
A backup nobody has tried to restore from is a backup you don't actually have. Microsoft 365 and Google Workspace do not fully back up your data by default in the way most owners assume.
A written offboarding process
Given how much turnover recruitment sees, an ad hoc approach to leavers is a live data protection risk, not just an operational inconvenience.
What GDPR actually requires, in plain terms
- Only hold candidate data you have a legitimate reason to hold, and for as long as you need it.
- Be able to explain, if asked, what data you hold on someone and why.
- Have a way to delete a candidate's data on request.
- Report a serious data breach within the required timeframe if one happens.
This is general guidance, not legal advice. If you're unsure where your firm stands, a data protection specialist can confirm what applies to your specific setup.
Find out where your IT stands in 20 minutes.
Free IT health check for London recruitment firms. No commitment, no sales pitch.
Take the free health check →