← Back to Blog
Ownership 15 June 2026 · 7 min read

Your data, your tenant: where do your candidate records actually live?

When you choose recruitment software you're not only choosing features. You're deciding whose building your candidate database lives in. It's the most consequential question on the table, and it almost never makes the demo. Here's the case for keeping it in your own Microsoft 365 tenant, and the honest caveats.

Every recruitment-software decision quietly answers a question most buyers never ask: who holds your data? Not who you log in to, or who sends the invoice, but who physically holds the candidate records your business runs on. It's worth asking out loud before you sign anything.

Rented software usually means rented data

Sign up for a typical SaaS recruitment platform and your candidate records (CVs, contact details, notes, salary history) sit on the vendor's servers, under the vendor's controls, governed by the vendor's terms. You rent access by the seat. That works right up until it doesn't: a price increase you can't walk away from without an export battle, a migration quote when you outgrow them, an outage that takes your desk offline, or a breach on their side that quietly becomes your problem. The features are yours to use; the data is theirs to hold.

The third-party risk you inherit

Every vendor you pour candidate data into is a link in your own breach chain. Verizon's 2024 Data Breach Investigations Report found that 15% of breaches involved a third party (partner infrastructure or software supply-chain issues), a 68% jump on the year before (Verizon DBIR 2024). Recruitment data is a rich target: CVs, ID documents, contact details, sometimes special-category data. When a vendor in your stack is breached, it's your candidates who get the letter, your reputation that takes the hit, and your name on the regulator's questions.

The GDPR chain nobody wants to map

Under GDPR, your agency is the controller of that candidate data. A SaaS platform is a processor, usually with sub-processors of its own (its hosting provider, its AI features, its support tooling), each of which needs a data-processing agreement and each of which is another place your data lives (GDPR Art. 28).

The more tools you copy candidate records into, the longer that chain gets, and the harder the basic principles become to actually honour: data minimisation, storage limitation, and security of processing (GDPR Art. 32). When a client's procurement team or your own lawyer asks you to map who touches your data, length is not your friend.

The alternative: build on the tenant you already own

There's another model. Instead of copying your data into someone else's platform, build the system inside the Microsoft 365 your firm already pays for. The candidate records live in your own SharePoint, in your own tenant. You're the controller and you hold the building.

Microsoft's compliance posture applies to your tenant directly, including the EU Data Boundary, under which customer data at rest stays within the EU/EFTA region for European tenants, a rollout completed in February 2025 at no additional cost (Microsoft EU Data Boundary). The chain gets shorter: fewer third parties, data residency you actually control, and a system you own outright.

The ownership test: if you stopped working with whoever built your system tomorrow, where would your data be? In the tenant model, the answer is "exactly where it is, with us." No per-seat licence to keep paying, no export battle to leave.

The honest caveats

This isn't a magic trick, and it isn't "SaaS is bad." A few things have to be true for it to be the right call:

The bottom line

When a client, a candidate, or your own counsel asks "where does our data live, and who can touch it," the cleanest answer is the shortest one: "in our own Microsoft 365, under our own controls." It's cheaper to defend, faster in due diligence, and it has the advantage of being true.

So before you sign anything, ask the question that rarely makes the demo: whose building is your database in?

Sorapis · Your tenant, your data

A system you own, on the Microsoft 365 you already pay for.

The recruitment systems I build live inside your own Microsoft 365 and SharePoint, so the data never leaves your tenant, and you own what you pay for. Send a short note about your setup and I'll send back a tailored concept.

Talk it through →
Anto Andrijanic · Sorapis · Custom CRM and operations systems for recruitment & staffing on Microsoft 365.

Sources

  1. Verizon: 2024 Data Breach Investigations Report (third-party / supply-chain involvement)
  2. GDPR: Article 28: Processor
  3. GDPR: Article 32: Security of processing
  4. Microsoft: What is the EU Data Boundary?