Every recruitment-software decision quietly answers a question most buyers never ask: who holds your data? Not who you log in to, or who sends the invoice, but who physically holds the candidate records your business runs on. It's worth asking out loud before you sign anything.
Rented software usually means rented data
Sign up for a typical SaaS recruitment platform and your candidate records (CVs, contact details, notes, salary history) sit on the vendor's servers, under the vendor's controls, governed by the vendor's terms. You rent access by the seat. That works right up until it doesn't: a price increase you can't walk away from without an export battle, a migration quote when you outgrow them, an outage that takes your desk offline, or a breach on their side that quietly becomes your problem. The features are yours to use; the data is theirs to hold.
The third-party risk you inherit
Every vendor you pour candidate data into is a link in your own breach chain. Verizon's 2024 Data Breach Investigations Report found that 15% of breaches involved a third party (partner infrastructure or software supply-chain issues), a 68% jump on the year before (Verizon DBIR 2024). Recruitment data is a rich target: CVs, ID documents, contact details, sometimes special-category data. When a vendor in your stack is breached, it's your candidates who get the letter, your reputation that takes the hit, and your name on the regulator's questions.
The GDPR chain nobody wants to map
Under GDPR, your agency is the controller of that candidate data. A SaaS platform is a processor, usually with sub-processors of its own (its hosting provider, its AI features, its support tooling), each of which needs a data-processing agreement and each of which is another place your data lives (GDPR Art. 28).
The more tools you copy candidate records into, the longer that chain gets, and the harder the basic principles become to actually honour: data minimisation, storage limitation, and security of processing (GDPR Art. 32). When a client's procurement team or your own lawyer asks you to map who touches your data, length is not your friend.
The alternative: build on the tenant you already own
There's another model. Instead of copying your data into someone else's platform, build the system inside the Microsoft 365 your firm already pays for. The candidate records live in your own SharePoint, in your own tenant. You're the controller and you hold the building.
Microsoft's compliance posture applies to your tenant directly, including the EU Data Boundary, under which customer data at rest stays within the EU/EFTA region for European tenants, a rollout completed in February 2025 at no additional cost (Microsoft EU Data Boundary). The chain gets shorter: fewer third parties, data residency you actually control, and a system you own outright.
The ownership test: if you stopped working with whoever built your system tomorrow, where would your data be? In the tenant model, the answer is "exactly where it is, with us." No per-seat licence to keep paying, no export battle to leave.
The honest caveats
This isn't a magic trick, and it isn't "SaaS is bad." A few things have to be true for it to be the right call:
- Your own tenant isn't automatically secure. You're the controller, so you still set up access controls, MFA, retention and backups. Owning the building doesn't lock the doors for you.
- It isn't always cheaper than an inexpensive SaaS for a very small firm. The argument here is ownership, control and risk, not always price. If you're happy on a cheap tool and the data question doesn't keep you up, stay.
- Good SaaS is a legitimate choice. If you want fully-managed software with minimal responsibility and a solid DPA, that's a real trade-off some firms should make. The point isn't to fear vendors; it's to choose consciously.
- Whoever builds it still touches your data during the build. So vet them and sign a DPA with them too. (I'm a processor while the work is underway, so hold me to the same standard.)
The bottom line
When a client, a candidate, or your own counsel asks "where does our data live, and who can touch it," the cleanest answer is the shortest one: "in our own Microsoft 365, under our own controls." It's cheaper to defend, faster in due diligence, and it has the advantage of being true.
So before you sign anything, ask the question that rarely makes the demo: whose building is your database in?
A system you own, on the Microsoft 365 you already pay for.
The recruitment systems I build live inside your own Microsoft 365 and SharePoint, so the data never leaves your tenant, and you own what you pay for. Send a short note about your setup and I'll send back a tailored concept.
Talk it through →Sources
- Verizon: 2024 Data Breach Investigations Report (third-party / supply-chain involvement)
- GDPR: Article 28: Processor
- GDPR: Article 32: Security of processing
- Microsoft: What is the EU Data Boundary?