A GDPR breach in recruitment doesn't always look like a major cyberattack. It can start with something much more ordinary: candidate data kept for too long, unclear access to CVs, an AI system making decisions without meaningful human involvement, or personal information being transferred without the right safeguards.
For recruiters using AI and recruitment software, understanding these GDPR breach risks is just as important as choosing the right tools.
EdgeTal runs its AI directly on the recruiter's device using a private LLM, so CVs don't need to be sent to a cloud server for AI processing. This can reduce some of the external processing and transfer considerations that come with cloud-based recruitment software.
1. No Clear Legal Basis for Candidate Data
Recruiters need a lawful basis for processing personal data. Legitimate interests, consent and other lawful bases can apply, but the basis should be identified and documented.
If nobody can explain why candidate CVs are being collected, stored or analysed, that's a potential GDPR breach.
Check: Do you know the lawful basis for the candidate data you're processing?
2. Keeping Resumes for Too Long
Candidate databases can grow quickly. Without a clear retention policy, CVs can remain in an applicant tracking system GDPR workflow long after there is a reason to keep them.
Data shouldn't be kept indefinitely simply because a candidate might be useful later.
A retention schedule can support GDPR compliance HR and reduce the risk of a GDPR breach caused by unnecessary retention.
Check: When is candidate data actually deleted?
3. Treating AI Decisions as Automatically Correct
AI can support recruitment decisions, but recruiters shouldn't assume an AI-generated ranking is automatically appropriate.
Current UK guidance stresses meaningful human involvement where automated decision-making has significant effects. Human review shouldn't simply be a rubber stamp.
This is where automated decision making GDPR requirements become relevant. Recruiters need to understand what role AI is playing in candidate decisions.
Otherwise, the process could create a GDPR breach risk.
Check: Is someone genuinely reviewing the AI output before an important decision?
4. Not Knowing Who Processes Candidate Data
Cloud recruitment software can involve more organisations than recruiters initially realise.
An AI tool might rely on hosting providers, storage services or other processors, making it important to understand who has access to candidate information.
This matters when evaluating GDPR HR software or an applicant tracking system GDPR setup.
If you don't know who processes your candidates' information, it's harder to assess whether your processes are GDPR compliant.
Check: Can your software provider explain who processes candidate data and why?
5. Making Deletion Requests Difficult
One of the important individuals' rights under GDPR is the right to request erasure where it applies.
This can become complicated when candidate information exists across multiple systems, exports and connected services.
Deleting someone from the main database doesn't necessarily remove every copy.
That's another potential GDPR breach risk.
Check: If a candidate requested deletion today, could you identify where their data exists?
6. Ignoring Data Residency and International Transfers
Where candidate data is processed matters.
If recruitment software sends personal information to infrastructure in another country, organisations may need to consider international transfer rules and appropriate safeguards.
This makes data residency an important question when choosing recruitment software.
It also makes cross border data transfer something recruiters should understand rather than simply assume their vendor has handled.
Knowing where candidate information goes can reduce the risk of a GDPR breach caused by an overlooked transfer.
Check: Where is your candidate data processed, and what safeguards apply?
7. Trusting a "GDPR Compliant" Claim Without Checking
A GDPR compliant label doesn't tell you everything about how a recruitment platform handles candidate data.
Ask what the software actually does. Does it minimise unnecessary data movement? Does it support retention and deletion? Can the vendor explain its processors and security measures?
This is where data protection by design becomes important. Privacy should be considered as part of how a system is built, not added afterwards.
For HR teams evaluating gdpr compliance hr, looking at the actual architecture can reveal more than a badge.
Check: Can the vendor explain its privacy approach in specific terms?
8. Assuming Privacy Is Only About Policies
A privacy policy matters, but so does the technology behind the recruitment workflow.
Cloud AI may require candidate information to move between systems. An on-device AI approach can instead process information locally, reducing some external processing and transfer considerations.
EdgeTal uses a private LLM that runs on the recruiter's device, so candidate CVs don't need to be sent to a cloud server for AI processing.
That doesn't make EdgeTal automatically GDPR compliant or eliminate every GDPR breach risk. Retention, access controls, lawful basis and how recruiters use candidate information still matter.
But the architecture can remove some external data-processing steps from the workflow.
Conclusion
Most GDPR breach risks come from simple gaps in how candidate data is stored, accessed, processed and reviewed. Being GDPR compliant isn't just about choosing the right software label; it's about understanding how your recruitment technology handles candidate data and spotting potential risks before they become bigger problems.
FAQs
What is a GDPR breach in recruitment?
A GDPR breach in recruitment can occur when candidate data is processed, stored, accessed, or transferred without meeting applicable GDPR requirements.
How long can recruiters keep candidate CVs?
Recruiters should not keep candidate CVs indefinitely. Personal data should generally be retained only for as long as there is a valid reason to keep it.
Does using AI in recruitment create GDPR risks?
Yes. AI recruitment can create additional considerations around automated decision-making, data processing, transparency, and human oversight.
How does EdgeTal handle candidate data?
EdgeTal processes candidate CV data directly on the recruiter's device using on-device AI, so CVs don't need to be sent to a cloud server for AI processing.
