What makes AI recruitment GDPR compliant?
A recruitment tool is not “GDPR compliant” in isolation. Compliance depends on how an employer or agency collects candidate information, chooses a lawful basis, explains the processing, configures the product, oversees decisions, handles rights and deletes data. Vendor controls can support that process; they cannot transfer the organisation’s legal responsibility to the software.
For a resume screening tool, a defensible 2026 workflow normally includes:
- a documented purpose and lawful basis for each use of candidate data;
- a data protection impact assessment where the processing is likely to create high risk;
- a clear candidate privacy notice covering the tool and its role;
- data minimisation, access controls, retention and deletion rules;
- meaningful human review of consequential recommendations;
- a route for candidates to ask questions, correct data, object where applicable and challenge a decision;
- a data processing agreement, subprocessor review and valid international-transfer arrangements;
- testing and monitoring for accuracy, fairness and unexpected outcomes.
This guide explains operational controls for UK and EU recruitment teams. It is general information, not legal advice. The correct lawful basis, controller/processor roles and safeguards depend on your organisation, candidates, countries and exact use of the system.
The 2026 regulatory position
UK: GDPR still applies, with DUAA changes now in force
The UK GDPR and Data Protection Act 2018 continue to govern recruitment data. The Data (Use and Access) Act 2025 amended parts of that framework, and the ICO confirmed on 19 June 2026 that all of its data-protection provisions are now in force. Organisations must now also provide a clear data-protection complaints process, acknowledge complaints within 30 days, investigate them and communicate the outcome.
One important change concerns significant decisions made solely by automated processing. The DUAA allows a wider range of lawful bases for this processing than the previous UK regime, but it does not remove safeguards. The ICO’s summary says organisations must inform the person about the decision and enable them to make representations, obtain human intervention and contest it. Stricter conditions remain for special-category data.
As of 26 July 2026, the ICO had completed consultation on updated automated-decision guidance but had not yet published the final version. Teams should therefore check the current ICO position when implementing or materially changing an automated decision workflow.
The ICO is actively focused on recruitment. Its 2026 Recruitment rewired report, based on discussions with more than 30 employers, found that many were likely using solely automated significant decisions without sufficient safeguards. It specifically called for better transparency, consistent meaningful human involvement and stronger fairness monitoring.
EU: GDPR plus the AI Act
EU GDPR obligations apply independently of the EU AI Act. The AI Act identifies certain employment tools, including CV-sorting software used for recruitment, as potentially high-risk depending on their intended use.
Following the May 2026 political agreement on the AI Omnibus, the European Commission says high-risk rules for stand-alone systems in areas including employment are scheduled to apply from 2 December 2027. Some AI Act provisions already apply, and the classification and timeline should be checked against the final legal text and current Commission guidance. Preparing risk management, documentation, logging, human oversight, accuracy and monitoring controls now reduces last-minute remediation.
Controller and processor roles in recruitment
Do not accept a generic contract label without mapping the real activity.
- An employer will usually determine why candidate information is used for its vacancy and is therefore likely to be a controller for that processing.
- A recruitment agency may be an independent controller for some activities, a joint controller in some arrangements or a processor for a tightly instructed service.
- A software provider often acts as a processor when it handles CVs only on the customer’s documented instructions, but it could become a controller for a separate purpose of its own.
Record the role for each data flow. An agency working for several clients should also document which party gives the privacy information, handles candidate rights, sets retention and responds to an incident. The contract should match that allocation.
Choose a lawful basis—do not default to consent
Consent is not automatically the best lawful basis for ordinary recruitment processing. It must be freely given, specific, informed and easy to withdraw, which may be difficult where a candidate perceives an imbalance or cannot realistically continue without agreeing.
Depending on the context, an organisation might assess steps at the candidate’s request before entering a contract, legitimate interests, a legal obligation or another basis. That choice must be made and documented by the controller. Special-category information—such as health, ethnicity or some diversity data—requires both an Article 6 basis and an additional Article 9 condition. Criminal-offence data has separate rules.
Do not collect sensitive attributes “just in case”. If equal-opportunities monitoring is necessary, separate it from selection access where possible and document the condition, purpose and retention.
When to complete a DPIA
A data protection impact assessment is required before processing that is likely to result in a high risk to people. Recruitment uses that deserve careful assessment include large-scale profiling, novel AI, systematic evaluation, combining datasets, sensitive information or a workflow capable of excluding candidates without meaningful review.
A useful DPIA should describe:
- the decision and how the tool influences it;
- categories and sources of information;
- candidates, including potentially vulnerable groups;
- lawful basis and necessity of each data field;
- accuracy, discrimination, security and opacity risks;
- vendor, hosting region, subprocessors and transfers;
- human involvement and candidate challenge routes;
- tests, owners, residual risk and review dates.
Do not treat the DPIA as a procurement form completed after the system is live. Use it to decide whether the proposed workflow should proceed and what must change first.
Transparency: what to tell candidates
A candidate notice should be easy to find before or when the data is collected. Explain in plain language:
- who controls the information and how to contact them;
- what information is used and where it came from;
- why an AI or automated tool is used;
- the lawful basis and relevant legitimate interests;
- whether the output ranks, recommends or decides;
- who receives the data and where it is processed;
- retention and deletion periods;
- relevant rights and how to request human review or challenge an outcome;
- how to complain to the organisation and regulator.
Avoid describing a consequential score as mere “administration”. If a low score means nobody reviews an application, the practical effect matters more than the label.
Meaningful human involvement in resume screening
Human involvement is meaningful when a trained reviewer can understand the relevant inputs, consider other information and change the result. A recruiter who automatically accepts a ranked shortlist is not providing a useful safeguard simply because they clicked a button.
Build review into the workflow:
- Show criterion-level evidence, not only a total score.
- Let the reviewer inspect the original CV.
- Include borderline and sampled low-ranked candidates in quality checks.
- Give reviewers authority to override and record why.
- Apply the same review standard to everyone at the same stage.
- Escalate errors and pause the workflow where necessary.
The complete guide to AI resume screening explains how to turn job requirements into a reviewable shortlist without relying on a keyword cutoff.
What to ask a resume screening vendor
The observed search for “resume screening tools GDPR compliance” often leads to vendor badges rather than an implementation answer. Ask for evidence across four areas.
Data handling
- Which entities process candidate documents, and for what purposes?
- Are customer CVs or outputs used to train general models?
- Where are source files, derived fields, logs and backups hosted?
- What transfer mechanism applies outside the UK or EEA?
- Can retention be configured, and what does deletion remove?
Security
- Is data encrypted in transit and at rest?
- Can access be limited by role, client and workspace?
- Are access and administrative actions logged?
- Which independent assurance reports or certifications are current, and what is their scope?
- What are the notification and cooperation terms for an incident?
Decision support
- Can a recruiter see the evidence behind each recommendation?
- Can criteria and weights be reviewed before processing?
- Can users override the ranking and audit changes?
- How does the provider test accuracy and disparate outcomes?
- What happens when the model or processing method changes?
Contracts and rights
- Is a data processing agreement available before purchase?
- Is the current subprocessor list incorporated with change notice?
- Can the provider support access, correction, objection, restriction and deletion requests?
- On termination, when are active data and backups deleted or returned?
“GDPR ready”, ISO certification and a European server location are useful signals, not a complete answer. Review the scope and contract, then configure the system to match your documented process.
Agencies managing several client datasets should also apply the separation and due-diligence checks in our AI tools for staffing agencies guide.
Product controls versus customer obligations
| Product capability | What it supports | What your organisation still owns |
|---|---|---|
| Encryption | Reduces exposure in storage and transit | Device security, user access, exports and incident response |
| Role-based access | Limits who can see records | Correct roles, leaver removal and regular access review |
| Configurable deletion | Helps apply retention rules | Choosing and documenting the retention period |
| Evidence-based scoring | Makes recommendations more reviewable | Job-related criteria, human review and final decisions |
| Audit logs | Creates an activity record | Monitoring the logs and acting on anomalies |
| Regional hosting | Helps with data-location requirements | Controller/processor mapping and lawful transfers |
Hire Forge appears in this guide because it is our product. That commercial interest does not change the checklist: buyers should ask Hire Forge the same questions, review the applicable terms and verify controls against their own needs. Our About and editorial standards page explains how we distinguish product statements from independent sources.
Fairness and accuracy checks
Using identical criteria is not proof of fairness. A criterion may disadvantage a group without being necessary for the role; a model may interpret career gaps or unfamiliar titles inconsistently; source CVs may contain errors.
Before launch and at regular intervals:
- test representative CV formats and non-standard career paths;
- compare recommendations with trained human review;
- inspect false negatives, not only selected candidates;
- analyse selection and override rates where lawful and appropriate;
- investigate material disparities and change the criterion or workflow;
- document model, prompt, rubric and threshold changes;
- provide a route to correct inaccurate information.
For practical assessment criteria, see the skills-based hiring guide. For risk patterns, read AI recruitment bias in 2026.
A 30-day implementation checklist
Week 1: map and govern
Document data flows, controller/processor roles, lawful basis, notices, owners and current retention. Identify whether the workflow makes or supports a significant decision.
Week 2: assess the vendor
Review the DPA, subprocessors, security evidence, hosting, transfers, training-data policy, deletion process and assistance with rights. Use synthetic or appropriately authorised test data until terms are approved.
Week 3: test the decision process
Run representative applications through the proposed criteria. Check accuracy, unusual CVs, disparities, explanations and reviewer overrides. Train reviewers on what meaningful involvement requires.
Week 4: launch narrowly
Start with one role family or client. Publish the candidate notice, monitor results, sample excluded candidates and provide a visible contact route. Set a review date and a stop condition.
Screen 100 CVs free—no integration required
Upload a job description and supported PDF, DOC, DOCX or TXT files. Hire Forge ranks the batch for recruiter review, with OCR for image-based PDFs.
5 CVs before signup. 100 more free. No card.
GDPR and AI recruitment FAQs
Does a GDPR-compliant recruitment tool guarantee compliance?
No. A provider can supply useful contractual, security and deletion controls, but the employer or agency must choose a lawful purpose, configure the workflow, inform candidates, oversee decisions and respond to rights.
Do we need candidate consent to screen a CV with AI?
Not necessarily. Consent is one possible lawful basis but may not be appropriate or valid in every recruitment context. The controller should document the correct Article 6 basis and any additional condition for special-category data.
Can AI automatically reject candidates in the UK?
The 2025 DUAA expanded when solely automated significant decisions can be used, but appropriate safeguards, a lawful basis, transparency, representation, human intervention and challenge rights remain important. Special-category data is more restricted. Obtain advice for the exact workflow and follow the current ICO guidance.
Does the EU AI Act replace GDPR?
No. The regimes overlap but address different obligations. GDPR continues to apply to personal-data processing; the AI Act adds requirements for AI systems according to risk and role.
How long can we retain candidate CVs?
GDPR does not set one universal recruitment retention period. Keep data no longer than necessary for the documented purpose, account for legal claims and client obligations, tell candidates the period or criteria, and apply deletion consistently across source files, derived data and exports.
Sources
- ICO, 2026: Recruitment rewired. View source
- ICO, updated June 2026: What the Data (Use and Access) Act 2025 means for organisations. View source
- ICO, June 2026: New data protection complaints law now in force. View source
- ICO: Employment practices and data protection: recruitment and selection. View source
- European Commission, May 2026: EU agrees to simplify AI rules. View source
- EUR-Lex: Regulation (EU) 2016/679 (GDPR). View legal text
Keep exploring
Related guides
AI Resume Screening Bias Risk: The SMB Compliance Guide (2026)
A practical 2026 guide to AI resume-screening bias: test job-related criteria, audit outcomes, challenge vendor claims and meet UK, US and EU duties.
Skills-Based Hiring in 2026: AI Screening Guide for SMBs
Build a skills-based hiring process for SMBs: define evidence-based criteria, screen consistently, validate ability and avoid weak proxies.
Complete Guide to AI Resume Screening for SMBs (2026)
51% of organisations use AI for recruiting. This SMB-first guide covers how resume screening works, how to choose a tool, and the bias risks to manage.
About the author
Ben Lovis·Founder, Hire Forge AIA professional recruiter who built and deployed AI-powered screening systems internally before founding Hire Forge AI. He now designs AI recruitment systems for hiring teams worldwide.
Review candidates with consistent criteria
Apply the same job-related criteria across the applicant batch, inspect the evidence behind each score and keep recruiters responsible for the final decision.
Start free5 CVs before signup. 100 more free. No card.
