Human Resources / Staffing
The Security Questionnaire Is Standing Between You and the Contract
For a staffing agency, security is not overhead. It is a revenue gate - the enterprise client's vendor management system asks for evidence before onboarding, and agencies that cannot answer lose the placement to one that can.
Meanwhile the data you hold is as sensitive as anything a bank holds: Social Security numbers, dates of birth, and direct deposit details for people who never became your employees.
The operational reality
What Makes Human Resources / Staffing Different
You hold complete identity kits for people you never hired. Every candidate who applied. Most agencies have no retention schedule, so the exposure compounds every quarter.
Recruiter turnover is your access control problem. High internal churn produces shared logins, credentials that outlive employment, and candidate data living in spreadsheets and email threads outside the applicant tracking system.
The loss event is payroll redirect, not ransomware. A compromised recruiter mailbox is used to change direct deposit details or to invoice a client. It is quiet, it is fast, and email security plus verification procedure is what stops it - not another endpoint tool.
Your client's vendor management system is your auditor. Beeline, SAP Fieldglass, and similar platforms gate onboarding on a security review. A SIG Lite questionnaire or a SOC 2 report is frequently the requirement, and a smaller agency that cannot respond simply does not get onboarded.
Placements in other states import other states' laws. Biometric timeclocks in Illinois placements are the clearest example, and the question of who is legally responsible when the agency does not own the device is actively litigated.
Frameworks
Your Compliance Landscape
Little of this is industry-specific regulation. Most of it arrives through contracts, through state law where you place workers, and through the nature of the data you hold.
Almost always applies
- Your baseline and the vocabulary most client questionnaires are written in (NIST CSF).
- Fla. Stat. §501.171Candidate and employee records contain personal information as the statute defines it, which brings a 30-day notification obligation on breach (flsenate.gov).
Applies in some cases
- Not a law - a contractual gate. Enterprise vendor management programs ask for it, and for many agencies it is the single highest-return compliance investment because it directly unlocks revenue.
- Illinois' Biometric Information Privacy Act (740 ILCS 14) governs collection of fingerprints and other biometric identifiers, including timeclocks used at client sites. Whether liability attaches to an agency that does not own or control the device has been litigated recently and the case law is still moving - do not rely on a summary, including this one, without current counsel.
- Only if you accept card payments. Payroll data is not card data (PCI SSC).
- California placements bring California residents' data - including employee and applicant data - into scope (California Attorney General on CCPA).
- Contested and fact-specific. Payroll and professional employer arrangements handling banking data at scale should get a written determination from counsel rather than an assumption in either direction (16 CFR Part 314).
- Requested by enterprise and government clients, particularly on multinational programs.
The information provided here is for educational purposes only and should not be considered legal advice. Requirements change and applicability depends on your specific circumstances - for specific compliance concerns, consult a qualified legal professional.
Failure patterns
What Usually Goes Wrong
- A recruiter mailbox is compromised and a direct deposit change goes through on a real thread with a real signature block.
- Candidate spreadsheets live in email. Names, Social Security numbers, and dates of birth, exported for a client submission two years ago and never deleted.
- Departed recruiters keep access to the applicant tracking system and to the shared drives.
- The agency loses a contract on the questionnaire. Not on price. On the inability to evidence multi-factor authentication, retention, and breach notification commitments.
- Email security is under-built while endpoint tools are over-bought, which inverts the actual risk.
- Biometric timeclocks at client sites are treated as the client's problem with nothing in the contract allocating it.
- There is no retention schedule, so every candidate record ever collected is still there.
- Florida's employment eligibility verification rules are applied by rumor rather than by reading the statute.
Our services
How We Work With Human Resources / Staffing
Cyber Risk Management
Email authentication and anti-impersonation controls, multi-factor across the applicant tracking system and payroll, and identity protection aimed at the compromise pattern that actually costs agencies money.
Governance, Risk & Compliance (GRC)
The written security program, the retention schedule, and the documentation that lets you answer a client questionnaire from evidence rather than from memory.
Third-Party Assessments
Diligence on your ATS, payroll, and background check vendors - and support when a client's vendor management program assesses you.
Helpdesk Support
Onboarding and offboarding executed reliably, which for a high-churn business is a security control rather than an administrative task.
Fractional CIO, CTO & CISO
Someone accountable for security decisions and able to speak to an enterprise client's risk team directly.
Digital Forensics & Incident Response
Business email compromise response - mailbox forensics, containment, and the notification analysis under Florida's 30-day clock.
Questions people ask
Frequently Asked Questions
- Do staffing agencies need SOC 2?
- No law requires it. Enterprise vendor management programs increasingly do, as a condition of onboarding. Treat it as a sales requirement and evaluate it against the contracts it would unlock rather than as a compliance cost.
- What is required to satisfy a client's VMS security requirements?
- Usually a completed questionnaire - SIG Lite, CAIQ, or the client's own - covering multi-factor authentication, encryption, access management and offboarding, data retention, subprocessor lists, breach notification timelines, training, and insurance. Some programs accept a documented program in place of an audit report; some do not.
- Is our payroll data PCI compliant?
- PCI DSS governs payment card data. Payroll information - Social Security numbers, bank account and routing numbers - is sensitive personal information governed by state breach law and contract, not by PCI. Applying the wrong framework here leaves the real exposure unaddressed.
- Is biometric timeclock data protected under state law?
- In several states, yes. Illinois' BIPA is the most consequential, with notice, written consent, and retention schedule requirements. Where the agency does not own the timeclock, who bears responsibility has been the subject of recent Illinois appellate litigation and remains an area to check with current counsel before relying on any summary.
- Does BIPA apply outside Illinois?
- BIPA is an Illinois statute, and its reach in cases involving out-of-state entities and Illinois residents has been litigated repeatedly. A Florida agency placing workers in Illinois should not assume distance provides protection. The statute text is at ilga.gov.
- Do I need to run E-Verify for my staffing agency in Florida?
- Florida's employment eligibility verification requirement at Fla. Stat. §448.095 distinguishes between public employers, contractors and subcontractors, and private employers, with different obligations and thresholds. Read the statute at flsenate.gov and confirm with employment counsel - this is the requirement most commonly described incorrectly in both directions.
- What happens if a candidate's Social Security number leaks from our ATS?
- A Social Security number is personal information under Fla. Stat. §501.171, so a breach triggers notice to affected individuals within 30 days of determination and, above the statutory threshold, notice to the Department of Legal Affairs. Your client contracts may impose additional and faster notification duties.
- Do I need a data processing agreement with my ATS vendor?
- Your enterprise clients will expect their data flow to be governed by contract, including subprocessors and breach notification. Whether it is called a DPA or a security addendum, the substance is what gets audited.
- Is my staffing agency a financial institution under GLBA?
- Generally no for ordinary staffing services. The analysis changes for payroll and professional employer arrangements handling banking data at scale, and it is genuinely contested. Get a written determination from counsel rather than adopting a position from a vendor.
- Do we have to notify candidates of a breach?
- If their personal information was involved, yes - candidates are individuals under state breach notification law regardless of whether they were ever placed or paid.
Florida & the Treasure Coast
Human Resources / Staffing on the Treasure Coast
Florida employers should read Fla. Stat. §448.095 directly rather than working from summaries, because it treats public employers, government contractors and subcontractors, and private employers differently. Breach notification runs under §501.171 on a 30-day clock and applies to candidate and employee records.
On the Treasure Coast, agency work is concentrated in light industrial, construction, hospitality, and healthcare placement across Martin, St. Lucie, and Palm Beach counties - sectors where client-site timeclocks, high-volume seasonal onboarding, and multi-state placements are all normal. That combination is precisely what turns an administrative process gap into a legal exposure.
[NEEDS: client proof for this vertical]
