Recruitment & AI
GDPR and AI in recruitment: what you absolutely need to know
Using AI to pre-screen, run, or analyse interviews is not banned by default — nor is it automatically a legal grey zone. Recruitment processes personal data under the GDPR, and some AI use cases fall under the EU AI Act. The good news: with clear governance, compliance becomes a competitive advantage, not a blocker.
This article summarises what HR and legal teams must know: which obligations apply, what regulators such as the CNIL focus on, how the AI Act classifies hiring tools, and how to deploy a platform like HiLucy without unnecessary risk.

The essentials in 30 seconds
- GDPR applies to all candidate data (CVs, audio, transcripts, scores).
- The AI Act treats certain recruitment systems as high-risk: stronger transparency, human oversight, and documentation requirements.
- Compliance rests on informing candidates, minimising data, tracing decisions, and keeping humans in the loop.
- A well-designed tool — explicit criteria, no opaque “emotion engine” — reduces both legal risk and bias.
Why this topic is exploding in 2025–2026
Between GDPR enforcement, CNIL guidance, and the phased rollout of the AI Act, algorithmic hiring is under intense scrutiny.
European regulators stress that hiring combines two risks: large-scale personal data processing and direct impact on access to employment. The CNIL has issued guidance on recruitment systems and AI; the EDPB has worked on automated decision-making; the AI Act sets specific duties for systems that filter or rank applicants.
Search interest for “GDPR AI recruitment”, “CNIL automated interview”, and “EU AI Act employment” is soaring — and candidates ask the same questions. A clear policy reassures both sides.
Which data is in scope?
As soon as a candidate enters a digital hiring flow, you process personal data under the GDPR:
- identity and contact details (name, email, phone);
- professional data (CV, career history, declared skills);
- interview content (text or audio transcripts, answers);
- assessments and scores (fit, soft skills, behavioural signals);
- technical metadata (timestamps, logs, session identifiers).
In some cases, more sensitive categories may appear (origin, apparent disability in a voice recording, etc.). Apply data minimisation: collect only what you need to assess the role.
GDPR foundations
1. Legal basis and purpose
Each processing activity needs a lawful basis (pre-contractual steps, legitimate interest, sometimes consent for optional features) and a defined purpose: assess role fit — not open-ended profiling.
2. Informing candidates
Before or at collection, candidates must know who processes their data, why, how long it is kept, whether AI is involved, and which rights they can exercise. An accessible privacy policy and a clear candidate journey are mandatory.
3. Security and subprocessors
Encryption, access control, EU hosting where possible, and an Article 28 GDPR agreement with your AI vendor are baseline requirements — not IT-only details.
4. Retention periods
Do not keep interview recordings or rejected candidate profiles forever. Set retention aligned with legal duties and HR policy.
Automated decisions: GDPR Article 22
Article 22 governs decisions based solely on automated processing that produce legal or similarly significant effects. In hiring, automatic rejection with no human review is the high-risk scenario.
Standard practice — and the position of serious vendors:
- AI assists the decision (scoring, summary, flags to investigate);
- a recruiter or hiring manager confirms or overrides the recommendation;
- the candidate can request human intervention, state their view, and contest the outcome.
EU AI Act: what changes for hiring
The EU AI Act classifies certain HR systems as high-risk (Annex III). Specific obligations for recruitment AI have been postponed to 2 December 2027; AI Literacy has applied since February 2025.
Systems that filter, rank, or prioritise candidates from personal data — for example scoring CVs or interviews to decide who advances — typically face heightened duties, including:
- risk management and technical documentation;
- relevant, representative training data practices;
- transparency for users (recruiters) and data subjects (candidates);
- effective human oversight;
- accuracy, robustness, and cybersecurity;
- EU database registration for certain systems.
The AI Act does not ban AI in recruitment — it demands rigour. That is exactly what mature employers want, and what candidates fear when tools are opaque.
What CNIL and EDPB guidance keeps repeating
No black-box processing without explanation. No invasive biometric or emotion claims without solid justification. No final decision without meaningful human review. And test tools across diverse profiles to avoid indirect discrimination — closely tied to cognitive bias in hiring.
Compliance checklist for HR teams
- Publish or update the candidate privacy policy and show it before the AI interview starts.
- Document purpose, legal basis, and retention for each data type (audio, transcript, score).
- Verify the vendor DPA (Article 28) and data location.
- Ensure no final rejection is fully automated without contestable human review.
- Tell candidates how AI is used — not only that it is.
- Provide a channel to exercise GDPR rights (access, rectification, erasure, objection).
- Run a DPIA where processing is high-risk — common in algorithmic hiring.
- Audit criteria and outcomes regularly for discriminatory effects.
How HiLucy fits this framework
HiLucy is built to structure pre-screening and interviews — not to replace human judgment or read hidden emotions. In practice:
- guided interviews on job criteria you define;
- explainable outputs (summary, scores, answer excerpts);
- final human decision on every application;
- transparent candidate journey and operational GDPR rights (see our privacy policy);
- hosting and processing governed contractually for European clients.
For more on what AI can — and cannot — measure in interviews, read behavioural analysis in interviews: myth or reality. To deploy a compliant pre-screening flow, see our complete guide to automating prequalification interviews.
Quick FAQ
Is AI in recruitment banned in Europe?
No. It is governed by the GDPR and, for certain systems, the AI Act. A documented, transparent rollout is entirely feasible.
Do we always need candidate consent?
Not always. Bases often include pre-contractual steps or the recruiter's legitimate interest. Consent is still required for optional processing unrelated to the application.
Who is data controller: the employer or HiLucy?
The hiring company is generally controller for candidate data. HiLucy acts as processor for processing performed on its behalf, under the agreed contract.
Is a voice interview recording problematic?
It is lawful if the candidate is informed, purpose is clear, retention is limited, and security measures are in place. Audio must serve role assessment — not generalised profiling.
What if a candidate complains to the CNIL?
Be ready to show your processing register, legal bases, subprocessors contracts, rights-handling procedures, and decision traceability. A structured tool makes that much easier.
Conclusion: compliance as a trust signal
GDPR and the AI Act are not anti-innovation barriers in hiring — they set the quality floor candidates and regulators no longer accept falling below. Employers that document, explain, and keep humans in the loop turn compliance into a commercial argument.
If you are evaluating an AI interview platform, ask these questions before the pilot — then compare with HiLucy: transparency, job-based criteria, human oversight, and respect for candidate rights.
Want to move from reading to action? See how Hi Lucy automates your voice AI interviews and your approach to interviews powered by artificial intelligence.