What Is AI Hiring Compliance?
AI hiring compliance refers to the set of legal obligations employers must meet when using artificial intelligence, algorithms, or automated tools at any point in the recruitment process. This includes CV screening software, chatbot-based interviews, scoring models, and any tool that filters or ranks candidates without direct human judgement.
As of 2026, three regulatory frameworks shape hiring compliance for most employers in the UK and EU: the General Data Protection Regulation (GDPR), the EU AI Act, and Right to Work legislation. Together, they create specific obligations around how candidate data is collected, how automated decisions are made, and who is allowed to work.
Compliance is not a checkbox exercise. The fines are material (up to 6% of global turnover under the EU AI Act), and enforcement activity is rising. In 2023, the Irish Data Protection Commission fined LinkedIn 310 million euros for unlawful processing of personal data for targeted advertising, a signal that regulators are applying serious scrutiny to algorithmic systems that process personal data.
Why 2026 is the inflection point
The EU AI Act obligations for high-risk AI systems, which explicitly include employment AI, became applicable in August 2026 for most organisations. This is not a future requirement. If you are using AI to screen, rank, or shortlist candidates today and you operate in the EU, the clock has already started.
Simultaneously, UK ICO enforcement of algorithmic decision-making in hiring is increasing, and candidate awareness of their GDPR rights is growing. Building a compliant process now protects you from fines, candidate complaints, and reputational damage.
The EU AI Act and Employment AI
The EU AI Act creates a four-tier risk classification system for AI. Employment AI sits in the highest regulated tier: high-risk. Annex III of the Act explicitly lists AI used for recruitment and selection, including CV screening, candidate ranking, and interview assessment, as high-risk applications.
The date high-risk AI obligations became applicable for employment AI systems. If your screening tool processes candidates in the EU, mandatory requirements apply now.
What high-risk classification means in practice
Employers and HR tech vendors who deploy high-risk AI in recruitment must comply with a demanding set of obligations. These are not optional guidelines, they are legal requirements with teeth.
First, a conformity assessment must be completed before deploying the AI system. This involves documenting the system's purpose, the data it was trained on, its known limitations, and the measures taken to mitigate bias and errors. For employers buying off-the-shelf tools, you should request this documentation from your vendor.
Human oversight requirement
Every high-risk AI system must be designed to allow human review and override. In the context of hiring, this means no candidate should be rejected or advanced to the next stage based solely on an AI decision without a human having the meaningful ability to review and reverse that decision.
This is not satisfied by a rubber-stamp process where a human approves AI outputs without genuinely engaging with the candidate's materials. The oversight must be substantive. The human must have access to the AI's reasoning and the underlying candidate data, and must be capable of reaching a different conclusion.
Transparency to candidates
Candidates must be informed that AI is being used in their assessment. This disclosure should appear before the AI interaction begins, in the job posting, application flow, or a dedicated notice. The disclosure should explain what type of AI is used, what it assesses, and how its output is used in the selection decision.
GDPR and Candidate Data
GDPR applies to every employer processing personal data from candidates resident in the EU or UK, regardless of where the employer is based. Recruitment is one of the highest-risk areas of GDPR compliance because it involves large volumes of sensitive personal data from individuals who have no existing relationship with the employer.
Lawful basis for processing
Processing candidate data during active recruitment typically relies on legitimate interests (Article 6(1)(f)) or the performance of a contract (Article 6(1)(b), in pre-contractual steps). Consent is rarely the right basis for recruitment: it must be freely given, which is compromised by the power imbalance between employer and job seeker.
Special category data, including health, disability, ethnic origin, and religious belief, requires an additional lawful basis under Article 9, most commonly explicit consent or necessity for employment law obligations. If your screening questions or psychometric tools inadvertently collect special category data, you need this additional basis documented.
Data minimisation and purpose limitation
You may only collect candidate data that is necessary for the recruitment decision. This principle catches several common practices: asking for date of birth when age is not a genuine requirement, requesting a photograph before interview, or collecting extensive social media information without a clear link to the role. Keyword-based screening tools can also introduce unintentional bias when they collect proxy data that correlates with protected characteristics.
Purpose limitation means data collected for one role cannot be freely repurposed for a different one without a fresh lawful basis. If you want to retain rejected candidates for future opportunities, this requires explicit consent, and you must honour withdrawal of that consent promptly.
Retention periods
There is no single GDPR-mandated retention period for candidate data. However, the principle of storage limitation requires you to delete data when it is no longer needed. In practice, most organisations set a retention period of six months from the end of recruitment. Some extend to 12 months to accommodate potential discrimination claims.
Whatever period you choose, document it in your privacy notice and enforce it. A retention period you state but do not apply is worse than having no stated period. It demonstrates to regulators that you knew what you should do and chose not to do it.
Automated Decisions and Article 22 GDPR
Article 22 GDPR gives individuals the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. In a hiring context, a rejection or shortlisting decision made entirely by an algorithm without meaningful human involvement triggers this right.
What triggers Article 22
The key test is whether the decision is based solely on automated processing and produces a significant effect. Rejection from a job application is a significant effect. Being ranked below the interview threshold by an algorithm and therefore never reviewed by a human is also a significant effect, even if the employer characterises the process as AI-assisted rather than AI-decided.
Critically, Article 22 applies even when the employer believes a human is involved, if that human review is cursory or nominal. The ICO has clarified that a human who simply accepts AI outputs without genuinely engaging with the underlying information does not constitute meaningful human involvement.
Required safeguards
Where automated decision-making is used lawfully, either with candidate consent or as necessary for entering a contract, three safeguards must be in place. First, candidates must be informed that automated decision-making is occurring and given meaningful information about the logic involved. Second, candidates must be able to request human review of any automated decision. Third, candidates must be able to contest the decision and express their view.
In practice this means building a candidate-facing mechanism: a clear notice in the application flow, a contact route for review requests, and an internal process for handling those requests with a genuine human evaluation.
How Zyverno handles this
Lina, our AI screening assistant, is designed with human oversight at its core. Every AI recommendation is reviewed by a recruiter before any candidate advances or is rejected. Candidates are informed about AI use before their screening begins.
Right to Work Checks
Right to Work legislation requires employers to verify that every employee has permission to work in the relevant country before employment begins. Failing to conduct the check correctly eliminates the statutory excuse against illegal working penalties, which in the UK reach up to 60,000 pounds per illegal worker.
Digital identity verification
In the UK, the Home Office approved Identity Document Validation Technology (IDVT) for Right to Work checks from April 2022 for British and Irish nationals. Digital checks must be conducted through a certified Identity Service Provider (IDSP). Employers cannot run their own IDVT check. Using a certified provider gives a statutory excuse if the check is conducted correctly.
Digital checks are not mandatory: employers can still conduct manual document checks. However, digital checks are faster, more consistent, and less prone to human error in document verification, factors that matter when hiring at volume.
Biometric data rules
Several digital ID verification products use biometric facial comparison, comparing a live selfie against the photo on a document. Biometric data is special category data under GDPR, requiring an explicit lawful basis. For Right to Work checks, this typically relies on the employment law necessity basis under Article 9(2)(b).
If you are collecting biometric data as part of your hiring process, this must be disclosed in your privacy notice. Candidates must understand what biometric data is collected, how it is used, and how long it is retained. Biometric templates should be deleted as soon as the verification is complete.
EU/EEA nationals post-Brexit
EU, EEA, and Swiss nationals living in the UK can evidence their Right to Work using the Home Office online checking service, a share code system. Employers cannot request physical EU identity documents from EEA nationals settled in the UK. Insisting on this is direct discrimination under the Equality Act.
Building a Compliant AI Screening Process
A compliant process does not mean a slower one. GDPR and the EU AI Act define obligations, not workflow designs. With the right foundations, you can run a fast, high-volume screening process that meets every requirement. Here are the six steps to build it.
Document your AI tools
Inventory every AI or algorithmic tool used in your recruitment process. For each tool, document its purpose, the vendor, how it processes candidate data, whether it produces decisions or rankings, and what documentation the vendor provides under the EU AI Act.
Establish your lawful basis
For each stage where you process candidate data, document the lawful basis. Legitimate interests is common for early screening. Consent may be needed for storing data beyond the active recruitment period. Special category data requires an additional Article 9 basis.
Update your privacy notice
Your candidate-facing privacy notice must disclose what data you collect, your lawful basis, how long you retain it, whether automated decision-making is used and what logic is involved, and how candidates can exercise their rights including access, erasure, correction, and objection.
Build in human review
Design your process so a human genuinely reviews AI outputs before a decision with significant effects is made. This means the human must see the underlying candidate materials, have the AI reasoning explained, and have the practical ability to override the AI output.
Create a candidate rights handling process
Establish a documented process for handling Article 22 review requests, Subject Access Requests, and erasure requests. GDPR response timelines are strict: one month for SARs, extendable to three in complex cases. Candidates in active recruitment frequently submit SARs, so you need a process ready.
Set retention and deletion schedules
Configure your ATS or HR system to automatically flag or delete candidate data at your defined retention period. Manual deletion processes fail consistently. Automation is the only reliable way to enforce retention at scale.
Going further
A compliant process and a quality hiring process are not in tension. Read our guide on how to improve quality of hire for practical steps that work alongside your compliance framework.
Compliance Audit Checklist
AI tool inventory documented
Every AI/algorithmic tool in the recruitment process listed with vendor, purpose, and EU AI Act classification.
Lawful basis documented per stage
Lawful basis recorded for each processing activity: screening, interview, reference checks, offer, and retention.
Privacy notice updated
Candidate privacy notice discloses AI use, lawful basis, retention periods, and candidate rights including Article 22.
Human review in place
No candidate rejected or shortlisted based solely on automated output. Human reviewer has access to AI reasoning and can override.
Candidate rights process operational
Documented process for SARs, Article 22 review requests, and erasure requests with an assigned owner and GDPR-compliant timelines.
Retention schedule enforced automatically
System-enforced deletion or flagging at the defined retention period. Not reliant on manual action.
Penalties and Enforcement
Both GDPR and the EU AI Act carry substantial financial penalties. Understanding the penalty structure calibrates the business case: the cost of a compliance programme is a fraction of the cost of a material enforcement action.
GDPR penalties
GDPR enforcement operates on a two-tier system. Less serious violations, such as inadequate records and missing privacy notices, attract fines of up to 10 million euros or 2% of global annual turnover, whichever is higher. More serious violations, including processing without lawful basis, breaching data subject rights, and inadequate security, attract fines of up to 20 million euros or 4% of global annual turnover.
EU AI Act penalties
The EU AI Act applies separate penalties. Using prohibited AI applications carries fines of up to 35 million euros or 7% of global annual turnover. Violations relating to high-risk AI systems, including non-compliance with transparency, human oversight, or documentation requirements, attract fines of up to 15 million euros or 3% of annual turnover.
For a company with 50 million euros in annual revenue, a 4% GDPR fine is 2 million euros. A 3% EU AI Act fine is 1.5 million euros. These are not theoretical maximums. They are the actual penalty structure regulators apply when they find material non-compliance.
Common Compliance Mistakes
Treating AI vendor compliance as your compliance
A vendor being GDPR-compliant in their own data processing does not make your use of their tool compliant. You are the data controller. You are responsible for establishing your lawful basis, providing the privacy notice, and ensuring the data is not kept longer than necessary.
Relying on consent as the lawful basis for screening
Consent must be freely given. Candidates who need a job and want to be considered for it are not in a position to freely refuse consent. The ICO guidance on employment data makes clear that consent is rarely appropriate as a lawful basis for recruitment processing.
Nominal human review that does not satisfy Article 22
Building a review step where a human clicks approve on every AI recommendation without engaging with the underlying data does not satisfy the human oversight requirement. If the human review is not genuine, you are still making decisions based solely on automated processing.
Not updating the privacy notice when AI tools change
Introducing a new AI screening tool, or changing the one you use, triggers an obligation to update your candidate privacy notice. Candidates have the right to know, at the point of application, what automated processing will be applied to their data.
No process for Right to Work check failures
Employers sometimes conduct Right to Work checks but have no documented process for what to do when a check fails or returns an unclear result. Without a documented process, individual managers make inconsistent decisions, some of which may constitute unlawful discrimination.
Frequently Asked Questions
Up next in the series
ATS with AI Screening: A Buyer's Guide
How to evaluate ATS platforms with native AI screening versus add-on tools, and what to look for when compliance is a requirement.
Back to all guides