Every recruitment AI system runs on personal data, and much of it is exactly the kind the GDPR protects most carefully. A CV can reveal health, ethnicity, religion or trade-union membership; an assessment can profile a person; an automated screen can decide their access to work. This is why recruitment sits at the sharpest edge of data protection law — and why "the vendor handles compliance" is never a complete answer. As the employer, you are the controller. The obligations are yours.
This checklist walks through what the GDPR actually requires when AI touches hiring, and how those duties now interlock with the EU AI Act's high-risk regime. It is not legal advice, but it is the set of questions you should be able to answer before a candidate — or a regulator — asks them.
1. Establish a lawful basis — and know it is not "consent"
Every processing of personal data needs a lawful basis. In recruitment, consent is usually the wrong one: consent must be freely given, and a candidate who feels they must agree to be considered is not freely consenting. Most organisations rely on legitimate interests or the steps-necessary-to-enter-a-contract basis instead. The checklist item is simple to state and easy to skip: can you name your lawful basis for each processing activity, and have you documented why it applies?

2. Handle special category data with explicit care
CVs and interviews routinely expose special category data — health, disability, ethnic origin, religious belief. The GDPR forbids processing this unless a specific condition is met. Two risks dominate in AI recruitment. The first is processing special data without a valid condition. The second, subtler one is proxy inference: a model that deduces protected characteristics from innocent-looking inputs — a career gap, a postcode, a name. If your system infers or acts on protected traits, even indirectly, you are processing special category data whether you intended to or not.
3. Respect Article 22 — the right not to be subject to purely automated decisions
Article 22 gives people the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects — and being rejected for a job qualifies. If a system auto-rejects candidates with no meaningful human involvement, you are likely in breach. The remedy is not a human who rubber-stamps the machine, but genuine human oversight: a person with the authority, competence and information to reach a different conclusion. This obligation now maps directly onto the EU AI Act's human-oversight requirement for high-risk systems, so meeting one helps meet the other.
4. Be transparent about the AI
The GDPR requires that people are told how their data is used, and where automated decision-making under Article 22 is involved, they are entitled to meaningful information about the logic and the consequences. In practice this means candidates should know that AI is used, broadly what it evaluates, and how to seek human review. Transparency duties are converging from multiple directions — data protection, the AI Act, and jurisdiction-specific rules such as New York City's notice requirement and the Illinois Video Interview Act's consent rules — all pointing the same way: tell candidates, in advance, in plain language.
5. Apply data minimisation and purpose limitation
Collect only what you need for the role, and use it only for the purpose you collected it. AI creates pressure in the opposite direction, because more data can mean better models. Resist it. Feeding a screening model every field you hold — social media, inferred traits, data from unrelated processes — is both a minimisation breach and a bias risk, because irrelevant data is exactly where spurious correlations hide.
6. Run a Data Protection Impact Assessment
Large-scale automated evaluation of people for hiring is a textbook trigger for a mandatory DPIA. The assessment should describe the processing, test its necessity and proportionality, and identify and mitigate risks to candidates' rights. A DPIA is not a form to file; it is the document that proves you thought about the harm before it happened. Under the AI Act, deployers of high-risk systems face a related fundamental-rights assessment duty, and a well-run DPIA does much of that groundwork.
7. Honour data subject rights
Candidates can ask what data you hold, request correction, seek erasure, and — where Article 22 applies — obtain human intervention and contest the decision. Your process and your vendor arrangements must make these operationally possible. If a candidate asks why they were rejected and no one can explain what the model weighed, you have a rights problem and an assurance problem at once.
8. Set and enforce retention limits
Personal data may not be kept longer than necessary. Recruitment generates large volumes of it, and AI pipelines tend to hoard training data. Define how long candidate data is kept, justify it, and delete on schedule — including copies held by processors. The Illinois rule requiring deletion of interview videos within 30 days of a request is a concrete reminder that retention is enforceable, not aspirational.
9. Pin down the controller-processor relationship
Your AI vendor is almost always a processor acting on your instructions, and the GDPR requires a contract governing that relationship. But the AI Act adds a second axis: you are the deployer and typically the vendor is the provider, each with distinct duties. Your contracts should secure what both regimes require — documented instructions and security under the GDPR, and the technical documentation, accuracy metrics and instructions for use you need to meet your deployer obligations under the AI Act.
10. Verify, do not assume
The thread running through every item is that compliance is something you must be able to evidence, not merely assert. A vendor's assurance that a tool is "GDPR-compliant" and "bias-tested" is a starting point, not proof. Independent validation — of the lawful basis in practice, the reality of human oversight, the absence of proxy discrimination, the accuracy of the model — is what turns a claim into a defensible position. When a regulator or a rejected candidate asks for evidence, the organisation that verified will have it, and the one that trusted will not.
The bottom line
The GDPR and the EU AI Act are not two separate compliance projects; they are two views of the same obligation. Both demand lawful, transparent, fair, overseen and documented processing of people's data in decisions that affect them. Recruitment AI is where those demands are most concentrated. Treat this checklist as a set of questions you can answer with evidence — not intentions — and you will be in a genuinely defensible position rather than a hopeful one.
