All Blogs / SOC 2 and GDPR for Recruiting Firms: What You Actually Need to Know

SOC 2 and GDPR for Recruiting Firms: What You Actually Need to Know

SOC 2 and GDPR for Recruiting Firms

Somewhere in your sales cycle, a client’s procurement team will send a security questionnaire. It will ask whether your ATS is SOC 2 compliant, how you handle GDPR, and where candidate data is stored.

Most recruiting firms answer that questionnaire by forwarding it to their software vendor and hoping.

That works until it doesn’t. Because the uncomfortable truth is that under GDPR, your firm is usually the one legally on the hook, not the software.

Your vendor’s certifications reduce your risk. They do not transfer it.

This post covers what SOC 2 and GDPR actually mean for a recruiting firm, which obligations are yours rather than your vendor’s, the questions worth asking any ATS provider, and where Recruiterflow stands.

One caveat before we start: this is a practical guide, not legal advice. If you are working through a specific compliance obligation, take advice from someone qualified to give it.

TL;DR

  • SOC 2 is an attestation report, not a certification. Type I checks control design at a point in time. Type II tests whether controls actually worked over months. Ask which one you are being shown.
  • ISO 27001 is a genuine certification issued by an accredited body, and covers the management system rather than a single audit window.
  • Under GDPR your firm is almost always the data controller for candidate data. Your ATS is the processor. That distinction decides who carries the obligation.
  • The vendor questions that matter are about evidence and process, not badges.
  • Recruiterflow is SOC 2, ISO 27001 and GDPR compliant, with role-based permissions and SLA-backed support.

SOC 2: what it is and what it is not

SOC 2 is a reporting framework from the American Institute of CPAs. An independent auditor examines a vendor’s controls against the Trust Services Criteria and issues a report.

There are five criteria: Security, Availability, Processing Integrity, Confidentiality and Privacy. Only Security is mandatory.

A vendor can hold a valid SOC 2 report covering Security alone, which is common and perfectly legitimate, but it means the report says nothing about the other four.

The Type I and Type II distinction is the one that matters.

A Type I report assesses whether controls are appropriately designed at a single point in time. It is a snapshot. It says the locks look right.

A Type II report tests whether those controls actually operated effectively across a period, typically three to twelve months. It says the locks were checked repeatedly and held.

Type II is meaningfully harder and meaningfully more useful. When a vendor says “we’re SOC 2”, the correct follow-up is “Type I or Type II, over what period, and by which auditor?”

One more thing worth knowing. SOC 2 is not a certification and there is no such thing as being “SOC 2 certified”, however often the phrase appears in marketing. It is an attestation. What exists is a report, and you should ask to read it.

ISO 27001: the other half of the answer

Where SOC 2 is an American attestation, ISO/IEC 27001 is an international standard, and it genuinely is a certification, issued by an accredited certification body after an audit.

The difference in substance is scope. SOC 2 examines controls. ISO 27001 examines whether the organisation runs a functioning information security management system: documented risk assessment, a Statement of Applicability explaining which controls apply and why, defined responsibilities, and a cycle of review and improvement.

Put simply, SOC 2 asks whether the controls work. ISO 27001 asks whether the organisation is set up to keep them working.

Neither replaces the other, and a vendor holding both is telling you something reasonably substantial about operational maturity.

GDPR: the part that is actually your problem

Here is where most recruiting firms get the risk allocation wrong.

GDPR distinguishes between a controller, who decides why and how personal data is processed, and a processor, who processes it on the controller’s instructions.

When your firm sources a candidate, decides to hold their CV, chooses how long to keep it and determines who to send it to, your firm is the controller. Your ATS is the processor acting on your instructions.

That means the core obligations sit with you.

Lawful basis. You need one for every candidate record you hold. Recruiting firms commonly rely on legitimate interests for sourcing, which requires you to have actually carried out and documented a balancing test rather than simply asserting it.

Transparency. Candidates you source without their knowledge still have a right to be told you hold their data, generally within a month of you obtaining it.

Retention. GDPR sets no fixed retention period. It requires that you can justify the one you chose and that you apply it. A database of CVs from 2016 that nobody has reviewed is difficult to defend.

Data subject rights. Access, rectification, erasure, portability and objection. You generally have one month to respond, extendable by two further months for complex requests.

Your ability to meet that deadline depends heavily on whether your system can actually find everything you hold on one person.

International transfers. Moving EU personal data outside the EEA needs a lawful transfer mechanism, usually Standard Contractual Clauses or an adequacy decision.

The penalties are the reason this gets attention: up to €20 million or 4% of total worldwide annual turnover, whichever is higher.

What your vendor owes you is an Article 28 data processing agreement, sufficient security, transparency about sub-processors, and help meeting these obligations. What your vendor cannot do is hold the lawful basis on your behalf.

What your ATS actually needs to give you

Judged against the obligations above, four things separate a system that helps you comply from one that quietly makes it harder.

Find everything about one person, quickly. A subject access request is an exercise in retrieval. If candidate data is scattered across an ATS, a spreadsheet, a phone system and someone’s inbox, the one-month clock becomes a real problem. Consolidation is a compliance feature before it is a productivity feature.

Delete properly. Erasure means erasure, including in the places records were copied to. Ask what deletion actually does and whether it propagates.

Control who sees what. Role-based permissions limit exposure and make a breach smaller when one happens.

Show what happened. Audit trails covering who accessed, changed or exported a record are what turn an assertion into evidence.

The questions worth asking any vendor

Take these into your next vendor conversation. The answers are more revealing than the badges.

On SOC 2: Is it Type I or Type II? What period does the report cover? Which Trust Services Criteria are in scope? Can we read the report under NDA, and how recent is it?

On ISO 27001: Which certification body issued it, what is the certificate number, and what is the scope statement? Scope matters, because a certificate can cover part of an organisation.

On GDPR: Can we have your standard DPA? Where is data hosted, and is EU residency available? Who are your sub-processors, and how are we notified of changes? What is your breach notification commitment and timeline?

On the practical side: How do we export everything held on one candidate? What does deletion actually remove? What audit logs can we access ourselves?

A vendor who answers these crisply has done the work. A vendor who reaches for the badge row has not.

Where Recruiterflow stands

Recruiterflow is SOC 2, ISO 27001 and GDPR compliant, with role-based permissions, SLA-backed support and dedicated implementation for firms that need it.

Beyond the compliance posture, the architecture matters for the obligations above. Because Recruiterflow keeps candidate records, activity history, communications and pipeline data in one system rather than scattered across a stack, retrieval for a subject access request is a search rather than an archaeology project.

The same consolidation that makes AI agents useful makes compliance tractable, for the same underlying reason: the data is in one place.

If your security team needs the underlying documentation, request it through your Recruiterflow contact or book a demo and ask. Our privacy terms are published in the Recruiterflow privacy policy.

Frequently asked questions

Is SOC 2 a certification?

No. SOC 2 is an attestation report issued by an independent auditor, not a certification. There is no certifying body and no certificate. The correct thing to request is the report itself, usually under NDA.

What is the difference between SOC 2 Type I and Type II?

Type I assesses whether controls are suitably designed at a single point in time. Type II tests whether those controls operated effectively over a period, typically three to twelve months. Type II is the stronger assurance and the one most enterprise buyers ask for.

Does GDPR apply to a recruiting firm outside the EU?

It can. GDPR applies based on whose data you process, not where your office is. If you handle personal data of people in the EU or EEA in connection with offering services to them or monitoring their behaviour, it applies regardless of where your firm is based.

Is our firm the controller or the processor for candidate data?

Almost always the controller. You decide why the data is collected, how long it is kept and who it is shared with. Your ATS is the processor acting on your instructions, which means the lawful basis, retention policy and response to data subject requests remain your responsibility.

How long can a recruiting firm keep candidate data under GDPR?

There is no set period. You must define a retention period you can justify for your purpose, document it, tell candidates, and actually apply it. An indefinitely held database with no review cycle is the position hardest to defend.

What should we ask an ATS vendor about security?

Ask for the SOC 2 report and its type and period, the ISO 27001 certificate scope and issuing body, the standard DPA, the sub-processor list, the data hosting location and whether EU residency is available, and the breach notification timeline.

Badges are the beginning of the conversation

A trust badge row tells you a vendor has invested in security. It does not tell you whether their controls were tested over twelve months, what the report scope was, or whether your own retention policy would survive a regulator’s question.

For a recruiting firm the practical position is straightforward. Choose vendors who can produce evidence rather than logos, then get your own house in order, because the obligations that carry the fines are mostly yours.

The firms that handle this well are not the ones with the longest compliance page. They are the ones who can answer, in a single search, exactly what they hold on one person and why.

Ask us about SOC 2, ISO 27001 and GDPR - book a Recruiterflow demo

Recruitment

Leave a Comment

Schedule a personalized demo

Get Demo