GDPR compliance isn't just a concern for large companies. Small businesses handle personal data every day, and simple mistakes can create real problems. For recruiters, the risk is even higher because CVs contain a lot of personal information. Here are six GDPR mistakes worth checking before they become expensive.
EdgeTal is built with privacy in mind, keeping candidate data on the device rather than sending it to a cloud server for AI processing. That can reduce some of the data-handling risks recruiters need to consider, while the business remains responsible for its wider GDPR obligations.
6 GDPR Mistakes Small Businesses Shouldn't Ignore
Mistake 1: Assuming You're Too Small to Matter
There is no general small-business exemption from the GDPR rules. A five-person recruitment agency still has obligations around lawful processing, data security and individuals' rights under GDPR.
The rules don't disappear because you have fewer employees. The potential fines may take turnover into account, but small businesses can still face significant consequences.
The cost: For certain serious infringements, fines can reach up to €20 million or 4% of total worldwide annual turnover, depending on the applicable provision. Beyond the fine, a compliance failure can damage trust with candidates and clients.
Mistake 2: Treating Personal Data as Just Names and Emails
GDPR personal data covers much more than contact details. CVs can contain employment history, education, location, qualifications and other information that identifies a candidate.
Recruiters also need to be careful with GDPR special category data. A CV might reveal information about health, religious beliefs, ethnicity or political opinions without the recruiter specifically asking for it.
The cost: Special category data has additional requirements under the GDPR. Processing it casually can create a much bigger compliance issue than simply storing a candidate's contact details.
Mistake 3: Having No Process for Data Subject Rights
Individuals' rights under GDPR include rights such as accessing, correcting and, in certain circumstances, deleting their personal data.
The problem for many small businesses isn't knowing these rights exist. It's knowing what to do when someone actually makes a request. If a candidate asks for their information, could you quickly find where their data is stored and determine what needs to be removed or corrected?
The cost: A weak process can turn a straightforward request into a complaint. You should know who handles requests, where candidate data is stored and what steps need to be followed.
Mistake 4: Rubber-Stamping AI-Assisted Decisions
Using AI to screen or rank candidates requires more thought than simply checking the results and clicking approve.
Automated decision making under GDPR has specific requirements, particularly where decisions are based solely on automated processing and have legal or similarly significant effects on an individual. Human involvement also needs to be meaningful rather than just a rubber stamp.
For recruitment businesses, this also overlaps with the EU AI Act, where certain AI systems used in employment and recruitment are classified as high-risk. The compliance timeline has changed, but preparation and appropriate oversight still matter.
The cost: Treating AI output as a final decision without proper human oversight can create both GDPR and AI governance problems.
Mistake 5: Trusting a Vendor's "GDPR Compliant" Claim
Seeing GDPR compliant on a software website doesn't tell you everything you need to know.
Before using a tool that handles candidate information, look at how it actually processes data. Check its Data Processing Agreement, subprocessors, security measures and data protection by design approach.
You should also understand what your business remains responsible for. Choosing a GDPR compliant vendor doesn't automatically make every use of the software compliant.
The cost: If the vendor's privacy controls don't match its claims, your business may still have responsibilities as the organisation deciding how the personal data is processed.
Mistake 6: Not Knowing Where Your Data Goes
It's easy to forget about data location once you start using cloud software.
But if candidate information is sent to servers in another country, you need to understand where it goes and what safeguards apply. This is particularly important when reviewing an applicant tracking system GDPR setup or any recruitment software handling personal data.
Cross-border data transfers can create additional obligations, and they're often difficult to notice during everyday recruiting work.
The cost: A transfer can become a compliance problem simply because nobody checked where the data was being processed or which safeguards were in place.
What On-Device Processing Changes?
Some privacy risks can be reduced through the way software is built.
For example, a private LLM running locally on a device doesn't require candidate information to be sent to a shared cloud server for AI processing. This can reduce exposure around cloud processing and cross-border transfers.
That doesn't make the business automatically compliant. Retention, access requests, lawful processing and human oversight still need to be handled properly. The useful distinction is between risks you manage through processes and risks that can be reduced through data protection by design.
Final Thoughts
For small businesses, GDPR problems often start with simple assumptions: being too small to matter, trusting a GDPR compliant label, or not knowing where candidate data goes. Recruitment businesses handle particularly sensitive amounts of gdpr personal data, so it's worth checking these areas before a small process gap becomes a much bigger problem.
FAQs
What are the most common GDPR mistakes for small recruitment businesses?
Common mistakes include assuming small businesses are exempt, misunderstanding what counts as personal data, having no process for data subject requests, relying too heavily on AI decisions, trusting GDPR compliant claims without checking them, and not knowing where candidate data is processed.
Do small recruitment businesses need to comply with GDPR?
Yes. Being a small recruitment business does not generally remove GDPR obligations. Recruiters still need to consider lawful processing, data security, data subject rights, and how candidate information is handled.
Does using GDPR compliant recruitment software make a business GDPR compliant?
No. A GDPR compliant vendor can support your compliance, but the business using the software still has responsibilities for how candidate data is collected, processed, stored, and managed.
Can on-device AI help with recruitment data privacy?
On-device AI can reduce some privacy risks by processing candidate information directly on the device instead of sending it to an external cloud server. It does not, by itself, satisfy every GDPR obligation.
