A vendor tells you their platform is hosted in the UK. The procurement box gets ticked, the security questionnaire passes, and everyone moves on. Six months later someone asks where the AI model processing the CVs actually runs, and the answer turns out to be an API endpoint in Virginia. The application was hosted in London. The candidate data was not.
This is the recurring failure in how recruitment software with UK data residency gets assessed. A cloud region on a console is an infrastructure fact. Data residency is a claim about everywhere the data goes, everyone who can reach it, and what sits in the processing path. For buyers in legal, financial and government settings, those are very different questions, and only the second one matters.
Region Is Not Residency
"Hosted in the UK" typically means the primary application servers and database run in a UK cloud region. That is necessary and nowhere near sufficient. Candidate data routinely travels well beyond the primary region through paths nobody mentions in a sales conversation.
The Seven Places Data Actually Goes
- Backups and disaster recovery. Primary in London, replica somewhere else. Cross-region replication is good engineering and a residency question, and it is frequently configured by default without the customer being told which region received the copy.
- Model inference. The big one for anything described as AI. If the platform calls a third-party model API, your candidate data is transmitted to wherever that API terminates. A UK-hosted application calling a US inference endpoint has exported every CV it processed.
- Support access. Round-the-clock support means engineers in multiple time zones. If a support engineer overseas can open a customer record to investigate a ticket, data is accessible from outside the UK even though it never moved.
- Logs, telemetry and error tracking. Error monitoring and observability tooling is usually a third-party service in its own region, and error payloads often contain request data. This is one of the most common unnoticed leaks of personal data out of a compliant primary region.
- Email and notification delivery. Transactional email providers process recipient data and message content wherever they operate.
- Analytics and product instrumentation. Behavioural analytics on an admin interface can carry identifiers and sometimes content into another jurisdiction.
- Encryption key custody. Data encrypted at rest in the UK with keys held elsewhere is a meaningfully different control position from keys held in the same jurisdiction.
A genuine residency answer addresses all seven. A weak one addresses the first line of the first bullet.
The Legal Frame, Briefly and Without Drama
Under UK data protection law, personal data can be transferred outside the UK where the destination is covered by adequacy regulations, or where an appropriate safeguard is in place, such as the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses. Where you rely on a safeguard rather than adequacy, a transfer risk assessment is expected. There is a specific data bridge arrangement covering certified organisations in the United States.
The practical point for a buyer: international transfer is not prohibited; it is conditional and documented. If a supplier transfers data, they need a lawful mechanism and you need to have seen it. What you should not accept is a supplier who states there are no transfers while operating one of the seven paths above.
For some regulated buyers the calculation goes further than paperwork. Where a supplier or its parent is subject to a foreign legal regime that can compel disclosure, contractual safeguards do not eliminate that exposure. Whether that risk is acceptable is a judgement for your legal and risk functions, informed by the sensitivity of the data. Recruitment data is more sensitive than it is usually treated as: employment history, qualifications, sometimes health information disclosed in an adjustment request, and increasingly detailed assessment records.
What to Actually Verify Before Procurement
Replace the residency question on your security questionnaire with these. They are harder to answer vaguely.
- Name the region for primary storage, and the region for every backup and replica.
- List every sub-processor with the personal data each one touches and the region it operates in. A supplier who cannot produce this list on request does not have adequate control of their own supply chain.
- Where does inference run? For every AI feature, name the model provider and the endpoint region. If models are self-hosted, name the region they run in.
- Is our data used for training? Ask about the platform's own models and about any third-party provider in the path. You want a contractual no, not a policy page.
- Who can access production data, from where? Support, engineering and any third-party contractor, with the jurisdictions named and the access controls described.
- Where do logs and error reports go, and can they contain candidate data?
- Who holds the encryption keys, and in which jurisdiction?
- If transfers occur, show the mechanism and the transfer risk assessment.
- What is the deletion position? On instruction and on contract termination, including backups, with a stated timeframe.
- What independent assurance exists? Recognised information security certification, and where relevant the baseline government-backed schemes your own framework expects.
Question three is the one that most often changes the answer, and it is the one least often asked. Any vendor describing AI-powered screening should be able to answer it immediately. Hesitation is informative.
Why AI Screening Makes This Sharper
Traditional recruitment software stored data and let people read it. The residency question was about storage. AI-assisted screening actively transmits candidate content to a model for processing, which introduces two new exposures.
Transmission. Every assessed CV is sent somewhere for inference. If that somewhere is a third-party API in another jurisdiction, the volume of exported personal data is the volume of your entire applicant flow.
Training. Data submitted to a model provider may be retained or used to improve models depending on the terms in force, and those terms vary by product tier and change over time. For a law firm screening candidates whose CVs name clients and matters, or a government body handling applications for sensitive posts, that is not a theoretical concern.
This is why architecture matters more than assurance language here. A platform that performs inference within its own UK infrastructure, on models it controls, has a structurally different exposure profile from one that is a well-designed wrapper around someone else's overseas endpoint. Both may be perfectly legitimate. They are not interchangeable for a regulated buyer, and the difference is invisible unless you ask.
Frequently Asked Questions
Is UK Data Residency a Legal Requirement for Recruitment Software?
No. UK law permits international transfers subject to adequacy or an appropriate safeguard plus a transfer risk assessment. Residency requirements usually come from the buyer's own policy, sector regulation, procurement framework or client contracts rather than from data protection law itself. Many regulated organisations impose them as a risk control.
Does Hosting in a UK Cloud Region Mean the Data Stays in the UK?
Not necessarily. Backups and replicas may sit in other regions, model inference may call an overseas endpoint, support staff abroad may have access, and logging or analytics tooling may export data. Verify each path individually rather than accepting a single hosting statement.
What Is the Most Commonly Missed Residency Gap?
Model inference location for AI features, followed by error tracking and logging. Both routinely move personal data out of a nominally compliant primary region, and neither appears on most standard security questionnaires.
Should We Require ISO 27001 or Cyber Essentials?
Recognised certification is a reasonable baseline and demonstrates a managed security programme, but it certifies process rather than data location. A fully certified supplier can still transfer your data overseas. Ask about certification and residency separately.
How Does This Affect Public Sector Procurement?
Public buyers typically operate under framework requirements and departmental policy that address data location, security classification and supply chain transparency. The practical effect is that sub-processor lists and transfer mechanisms need to be documented rather than asserted, so a supplier who cannot produce them will struggle regardless of product quality.
The Short Version
Ask where the data rests, where it is copied, where it is processed, who can reach it and from where, and whether anyone's model learns from it. A supplier who answers all six precisely is telling you something real. A supplier who answers "we're UK-hosted" has answered a narrower question than the one you asked.
CVSense was built for UK buyers with these constraints as design inputs rather than as a compliance afterthought: localised architecture, a screening pipeline that does not hand candidate data to third parties for training, and a documented position on where data rests and who can access it. If you are working through a security review and need those answers in writing rather than in a demo, that is a straightforward request to make.
Sources
Information Commissioner's Office. International Transfers.
https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/
National Cyber Security Centre. Cloud Security Guidance.
https://www.ncsc.gov.uk/collection/cloud
Information Commissioner's Office. Guidance on AI and Data Protection.
https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/
Data Protection Act 2018.
https://www.legislation.gov.uk/ukpga/2018/12/contents
InsightCircle



