Recruitment & AI

AI-assisted recruitment: how to stay GDPR compliant

Deploying AI in your hiring process does not exempt you from GDPR — it strengthens the need for transparency and traceability. This practical guide helps HR teams stay compliant without blocking innovation.

Unlike a legal overview, this article focuses on operations: what to do concretely before, during, and after deploying a tool like HiLucy.

Personal data protection in AI-assisted recruitment.
GDPR compliance protects candidates and secures your organisation.

Five GDPR pillars for AI hiring

  • Inform — candidates know who processes what and why.
  • Limit — collect only data needed for assessment.
  • Secure — encryption, restricted access, governed hosting.
  • Retain — defined periods, automatic deletion of obsolete data.
  • Accountable — human oversight and operational candidate rights.

Before deployment: foundations

Choose the legal basis

Most common: pre-contractual steps (Art. 6.1.b) and legitimate interest (Art. 6.1.f) after balancing test.

Update the privacy policy

Explicitly mention AI use, data types, retention, and rights. See our privacy policy.

Sign the DPA (Article 28)

HiLucy acts as processor. The DPA must cover object, duration, data types, security, and breach procedures.

Run a DPIA if required

Algorithmic hiring is often high-risk. A DPIA documents risks, mitigations, and justification.

Secure GDPR-compliant data flow in an AI recruitment process.
Every candidate journey step must be documented: collection, processing, human review, retention, deletion.

During the candidate journey

  • Display an information notice before the AI interview starts.
  • Explain that AI assists evaluation — it does not decide alone.
  • Provide a channel to exercise rights (access, rectification, erasure, objection).
  • Do not record beyond what is needed for role assessment.
  • Ensure recruiters can review raw data (transcript, audio) if contested.

After the interview: retention and rights

  • Successful candidates — retain during process + legal post-hire period.
  • Unsuccessful candidates — delete or anonymise within 6–12 months.
  • Audio recordings — shorter retention than full profile unless legally required.

Operational GDPR checklist

  • Processing register updated with purpose, legal basis, and retention.
  • Candidate privacy policy mentioning AI.
  • Signed DPA with AI interview vendor (Article 28).
  • Candidate notice displayed before each automated interview.
  • No final rejection without contestable human review.
  • Documented procedure for rights requests.
  • Defined and automatically applied retention periods.
  • DPIA completed if processing is high-risk.
  • Annual audit of criteria and outcomes for bias.

GDPR + AI Act: complementary

GDPR protects data; the AI Act governs high-risk systems. Read EU AI Act for recruiters in 2026 and Is AI in recruitment legal in Europe?. Our GDPR and AI in recruitment overview covers Article 22 automated decisions.

How HiLucy embeds GDPR compliance

HiLucy is built for European employers scaling pre-screening without compromising data protection. Explore the HiLucy platform or contact us to discuss your GDPR framework.

Want to move from reading to action? See how Hi Lucy automates your voice AI interviews and your approach to interviews powered by artificial intelligence.