Compliance Guide

The Complete Guide to AI Hiring Compliance (2026)

GDPR, EU AI Act, and Right to Work rules for employers using AI in recruitment. What the high-risk classification means for your hiring process and how to build a compliant screening workflow.

Updated September 202624 min readZyverno Compliance Team

What Is AI Hiring Compliance?

AI hiring compliance refers to the set of legal obligations employers must meet when using artificial intelligence, algorithms, or automated tools at any point in the recruitment process. This includes CV screening software, chatbot-based interviews, scoring models, and any tool that filters or ranks candidates without direct human judgement.

As of 2026, three regulatory frameworks shape hiring compliance for most employers in the UK and EU: the General Data Protection Regulation (GDPR), the EU AI Act, and Right to Work legislation. Together, they create specific obligations around how candidate data is collected, how automated decisions are made, and who is allowed to work.

Compliance is not a checkbox exercise. The fines are material (up to 6% of global turnover under the EU AI Act), and enforcement activity is rising. In 2023, the Irish Data Protection Commission fined LinkedIn 310 million euros for unlawful processing of personal data for targeted advertising, a signal that regulators are applying serious scrutiny to algorithmic systems that process personal data.

Why 2026 is the inflection point

The EU AI Act obligations for high-risk AI systems, which explicitly include employment AI, became applicable in August 2026 for most organisations. This is not a future requirement. If you are using AI to screen, rank, or shortlist candidates today and you operate in the EU, the clock has already started.

Simultaneously, UK ICO enforcement of algorithmic decision-making in hiring is increasing, and candidate awareness of their GDPR rights is growing. Building a compliant process now protects you from fines, candidate complaints, and reputational damage.

The EU AI Act and Employment AI

The EU AI Act creates a four-tier risk classification system for AI. Employment AI sits in the highest regulated tier: high-risk. Annex III of the Act explicitly lists AI used for recruitment and selection, including CV screening, candidate ranking, and interview assessment, as high-risk applications.

August 2026

The date high-risk AI obligations became applicable for employment AI systems. If your screening tool processes candidates in the EU, mandatory requirements apply now.

What high-risk classification means in practice

Employers and HR tech vendors who deploy high-risk AI in recruitment must comply with a demanding set of obligations. These are not optional guidelines, they are legal requirements with teeth.

First, a conformity assessment must be completed before deploying the AI system. This involves documenting the system's purpose, the data it was trained on, its known limitations, and the measures taken to mitigate bias and errors. For employers buying off-the-shelf tools, you should request this documentation from your vendor.

Human oversight requirement

Every high-risk AI system must be designed to allow human review and override. In the context of hiring, this means no candidate should be rejected or advanced to the next stage based solely on an AI decision without a human having the meaningful ability to review and reverse that decision.

This is not satisfied by a rubber-stamp process where a human approves AI outputs without genuinely engaging with the candidate's materials. The oversight must be substantive. The human must have access to the AI's reasoning and the underlying candidate data, and must be capable of reaching a different conclusion.

Transparency to candidates

Candidates must be informed that AI is being used in their assessment. This disclosure should appear before the AI interaction begins, in the job posting, application flow, or a dedicated notice. The disclosure should explain what type of AI is used, what it assesses, and how its output is used in the selection decision.

GDPR and Candidate Data

GDPR applies to every employer processing personal data from candidates resident in the EU or UK, regardless of where the employer is based. Recruitment is one of the highest-risk areas of GDPR compliance because it involves large volumes of sensitive personal data from individuals who have no existing relationship with the employer.

Lawful basis for processing

Processing candidate data during active recruitment typically relies on legitimate interests (Article 6(1)(f)) or the performance of a contract (Article 6(1)(b), in pre-contractual steps). Consent is rarely the right basis for recruitment: it must be freely given, which is compromised by the power imbalance between employer and job seeker.

Special category data, including health, disability, ethnic origin, and religious belief, requires an additional lawful basis under Article 9, most commonly explicit consent or necessity for employment law obligations. If your screening questions or psychometric tools inadvertently collect special category data, you need this additional basis documented.

Data minimisation and purpose limitation

You may only collect candidate data that is necessary for the recruitment decision. This principle catches several common practices: asking for date of birth when age is not a genuine requirement, requesting a photograph before interview, or collecting extensive social media information without a clear link to the role. Keyword-based screening tools can also introduce unintentional bias when they collect proxy data that correlates with protected characteristics.

Purpose limitation means data collected for one role cannot be freely repurposed for a different one without a fresh lawful basis. If you want to retain rejected candidates for future opportunities, this requires explicit consent, and you must honour withdrawal of that consent promptly.

Retention periods

There is no single GDPR-mandated retention period for candidate data. However, the principle of storage limitation requires you to delete data when it is no longer needed. In practice, most organisations set a retention period of six months from the end of recruitment. Some extend to 12 months to accommodate potential discrimination claims.

Whatever period you choose, document it in your privacy notice and enforce it. A retention period you state but do not apply is worse than having no stated period. It demonstrates to regulators that you knew what you should do and chose not to do it.

Automated Decisions and Article 22 GDPR

Article 22 GDPR gives individuals the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. In a hiring context, a rejection or shortlisting decision made entirely by an algorithm without meaningful human involvement triggers this right.

What triggers Article 22

The key test is whether the decision is based solely on automated processing and produces a significant effect. Rejection from a job application is a significant effect. Being ranked below the interview threshold by an algorithm and therefore never reviewed by a human is also a significant effect, even if the employer characterises the process as AI-assisted rather than AI-decided.

Critically, Article 22 applies even when the employer believes a human is involved, if that human review is cursory or nominal. The ICO has clarified that a human who simply accepts AI outputs without genuinely engaging with the underlying information does not constitute meaningful human involvement.

Required safeguards

Where automated decision-making is used lawfully, either with candidate consent or as necessary for entering a contract, three safeguards must be in place. First, candidates must be informed that automated decision-making is occurring and given meaningful information about the logic involved. Second, candidates must be able to request human review of any automated decision. Third, candidates must be able to contest the decision and express their view.

In practice this means building a candidate-facing mechanism: a clear notice in the application flow, a contact route for review requests, and an internal process for handling those requests with a genuine human evaluation.

How Zyverno handles this

Lina, our AI screening assistant, is designed with human oversight at its core. Every AI recommendation is reviewed by a recruiter before any candidate advances or is rejected. Candidates are informed about AI use before their screening begins.

Right to Work Checks

Right to Work legislation requires employers to verify that every employee has permission to work in the relevant country before employment begins. Failing to conduct the check correctly eliminates the statutory excuse against illegal working penalties, which in the UK reach up to 60,000 pounds per illegal worker.

Digital identity verification

In the UK, the Home Office approved Identity Document Validation Technology (IDVT) for Right to Work checks from April 2022 for British and Irish nationals. Digital checks must be conducted through a certified Identity Service Provider (IDSP). Employers cannot run their own IDVT check. Using a certified provider gives a statutory excuse if the check is conducted correctly.

Digital checks are not mandatory: employers can still conduct manual document checks. However, digital checks are faster, more consistent, and less prone to human error in document verification, factors that matter when hiring at volume.

Biometric data rules

Several digital ID verification products use biometric facial comparison, comparing a live selfie against the photo on a document. Biometric data is special category data under GDPR, requiring an explicit lawful basis. For Right to Work checks, this typically relies on the employment law necessity basis under Article 9(2)(b).

If you are collecting biometric data as part of your hiring process, this must be disclosed in your privacy notice. Candidates must understand what biometric data is collected, how it is used, and how long it is retained. Biometric templates should be deleted as soon as the verification is complete.

EU/EEA nationals post-Brexit

EU, EEA, and Swiss nationals living in the UK can evidence their Right to Work using the Home Office online checking service, a share code system. Employers cannot request physical EU identity documents from EEA nationals settled in the UK. Insisting on this is direct discrimination under the Equality Act.

Building a Compliant AI Screening Process

A compliant process does not mean a slower one. GDPR and the EU AI Act define obligations, not workflow designs. With the right foundations, you can run a fast, high-volume screening process that meets every requirement. Here are the six steps to build it.

1

Document your AI tools

Inventory every AI or algorithmic tool used in your recruitment process. For each tool, document its purpose, the vendor, how it processes candidate data, whether it produces decisions or rankings, and what documentation the vendor provides under the EU AI Act.

2

Establish your lawful basis

For each stage where you process candidate data, document the lawful basis. Legitimate interests is common for early screening. Consent may be needed for storing data beyond the active recruitment period. Special category data requires an additional Article 9 basis.

3

Update your privacy notice

Your candidate-facing privacy notice must disclose what data you collect, your lawful basis, how long you retain it, whether automated decision-making is used and what logic is involved, and how candidates can exercise their rights including access, erasure, correction, and objection.

4

Build in human review

Design your process so a human genuinely reviews AI outputs before a decision with significant effects is made. This means the human must see the underlying candidate materials, have the AI reasoning explained, and have the practical ability to override the AI output.

5

Create a candidate rights handling process

Establish a documented process for handling Article 22 review requests, Subject Access Requests, and erasure requests. GDPR response timelines are strict: one month for SARs, extendable to three in complex cases. Candidates in active recruitment frequently submit SARs, so you need a process ready.

6

Set retention and deletion schedules

Configure your ATS or HR system to automatically flag or delete candidate data at your defined retention period. Manual deletion processes fail consistently. Automation is the only reliable way to enforce retention at scale.

Going further

A compliant process and a quality hiring process are not in tension. Read our guide on how to improve quality of hire for practical steps that work alongside your compliance framework.

Compliance Audit Checklist

AI tool inventory documented

Every AI/algorithmic tool in the recruitment process listed with vendor, purpose, and EU AI Act classification.

Lawful basis documented per stage

Lawful basis recorded for each processing activity: screening, interview, reference checks, offer, and retention.

Privacy notice updated

Candidate privacy notice discloses AI use, lawful basis, retention periods, and candidate rights including Article 22.

Human review in place

No candidate rejected or shortlisted based solely on automated output. Human reviewer has access to AI reasoning and can override.

Candidate rights process operational

Documented process for SARs, Article 22 review requests, and erasure requests with an assigned owner and GDPR-compliant timelines.

Retention schedule enforced automatically

System-enforced deletion or flagging at the defined retention period. Not reliant on manual action.

Penalties and Enforcement

Both GDPR and the EU AI Act carry substantial financial penalties. Understanding the penalty structure calibrates the business case: the cost of a compliance programme is a fraction of the cost of a material enforcement action.

GDPR penalties

GDPR enforcement operates on a two-tier system. Less serious violations, such as inadequate records and missing privacy notices, attract fines of up to 10 million euros or 2% of global annual turnover, whichever is higher. More serious violations, including processing without lawful basis, breaching data subject rights, and inadequate security, attract fines of up to 20 million euros or 4% of global annual turnover.

EU AI Act penalties

The EU AI Act applies separate penalties. Using prohibited AI applications carries fines of up to 35 million euros or 7% of global annual turnover. Violations relating to high-risk AI systems, including non-compliance with transparency, human oversight, or documentation requirements, attract fines of up to 15 million euros or 3% of annual turnover.

For a company with 50 million euros in annual revenue, a 4% GDPR fine is 2 million euros. A 3% EU AI Act fine is 1.5 million euros. These are not theoretical maximums. They are the actual penalty structure regulators apply when they find material non-compliance.

Common Compliance Mistakes

Treating AI vendor compliance as your compliance

A vendor being GDPR-compliant in their own data processing does not make your use of their tool compliant. You are the data controller. You are responsible for establishing your lawful basis, providing the privacy notice, and ensuring the data is not kept longer than necessary.

Relying on consent as the lawful basis for screening

Consent must be freely given. Candidates who need a job and want to be considered for it are not in a position to freely refuse consent. The ICO guidance on employment data makes clear that consent is rarely appropriate as a lawful basis for recruitment processing.

Nominal human review that does not satisfy Article 22

Building a review step where a human clicks approve on every AI recommendation without engaging with the underlying data does not satisfy the human oversight requirement. If the human review is not genuine, you are still making decisions based solely on automated processing.

Not updating the privacy notice when AI tools change

Introducing a new AI screening tool, or changing the one you use, triggers an obligation to update your candidate privacy notice. Candidates have the right to know, at the point of application, what automated processing will be applied to their data.

No process for Right to Work check failures

Employers sometimes conduct Right to Work checks but have no documented process for what to do when a check fails or returns an unclear result. Without a documented process, individual managers make inconsistent decisions, some of which may constitute unlawful discrimination.

Frequently Asked Questions

Does the EU AI Act apply to UK employers?
Can we use AI screening legally without candidate consent?
How long can we keep rejected candidate CVs?
Does psychometric testing count as high-risk AI?
What is a Subject Access Request and how quickly must we respond?
Does Right to Work need to be checked before the offer or before start date?

Up next in the series

ATS with AI Screening: A Buyer's Guide

How to evaluate ATS platforms with native AI screening versus add-on tools, and what to look for when compliance is a requirement.

Back to all guides

Ready to make hiring effortless?

See how Zyverno unifies your entire recruitment workflow into one calm, intelligent platform, in a 30-minute personalized walkthrough.