AI sourcing is moving faster than the legal framework is settling. Between the GDPR, the French Labour Code and the European AI Act, a recruiter who uses AI to find or qualify candidates has precise obligations to meet, and the CNIL, the French data protection authority, has chosen 2026 to check who respects them. Here is what actually applies, article by article.
Does the GDPR apply to AI sourcing?
Yes, without exception. As soon as a tool processes candidates' personal data (identified or identifiable), whether a CV, a LinkedIn profile or a calculated score, the GDPR applies. An algorithm does not change the legal nature of the processing: it adds a further transparency obligation.
Articles 13 and 14 of the GDPR require the candidate to be informed, at the time of collection, of the identity of the controller, the purpose, the legal basis and the retention period. Article 22 specifically governs automated individual decisions: a score or ranking produced by an algorithm can never replace a hiring decision on its own.
What does the French Labour Code say about AI-assisted recruitment?
The Labour Code sets three simple rules: inform before using a sourcing or selection tool, collect only data directly related to the job offered, and never rely on data obtained without that prior information.
Article L. 1221-8 requires candidates to be informed in advance of the recruitment methods used, including automated ones. Article L. 1221-6 limits the data collected to what has a direct and necessary link with the position. Article L. 1221-9 prohibits using data obtained without respecting that information duty. The social and economic committee (CSE) must also be consulted before a new recruitment tool is deployed, under Article L. 2312-38.
Which obligations of the European AI Act already apply in 2026?
The European AI regulation classifies recruitment among high-risk uses, but the timetable changed this year. Regulation (EU) 2026/1744, known as the Digital Omnibus, came into force on 27 July 2026 and postpones the heaviest obligations (technical documentation, risk management, registration) to 2 December 2027.
This postponement does not suspend everything. The transparency obligations of Article 50 still apply: a candidate must know that they are interacting with an AI system or that AI is involved in processing their application. Article 5 also prohibits, absolutely and with immediate effect, emotion inference by biometric recognition systems in a work context. A firm or company already using AI for sourcing therefore has every interest in documenting its practices now rather than waiting for 2027: building the right processes takes time, and the postponed timetable does not shorten that lead time.
How long can the data of an unsuccessful candidate be kept?
The CNIL's constant rule sets a maximum retention period of two years after the last contact with the candidate, unless the candidate explicitly agrees to remain in a talent pool. After that period, the data must be deleted or anonymised.
A talent pool remains possible, but it requires documented and renewed consent, not retention by default. It is one of the points the CNIL checks first during its inspections.
What will the CNIL inspect in 2026?
The CNIL has listed recruitment among its priority inspection topics for 2026, announced on 3 April 2026. Three points are in its sights: the automated decision systems used to select candidates, the information actually given to candidates, and data retention periods.
Large companies and recruitment firms, which process the largest volume of applications, are targeted first. But the GDPR compliance obligation does not depend on company size: an SME that recruits with a non-compliant tool takes the same risk, on a different scale. The cost of a failed inspection also adds to an already heavy cost item: see our analysis of the cost of a hire in France.
How does an AI talent acquisition platform stay compliant?
Three principles structure Seeqle's approach on this subject: the hiring decision stays human, data is hosted in the European Union, and a campaign's data is only used to optimise that same campaign, never to feed cross-client profiling.
In practice, the Match Agent produces a decision-support score from public and declared data, never from biometric or emotional analysis. The recruiter stays in control at every step: they see the detail of the score, can set it aside, and remain the sole final decision-maker. This is a structural difference from a system that would automatically sort or reject applications without human intervention.
What remedies does a candidate who feels wronged have?
A candidate has several remedies, which can be combined. They can request access to their personal data and to the criteria that led to a decision. They can refer the matter to the CNIL in the event of a GDPR breach. If they suspect discrimination, they can alert the Défenseur des droits (the French rights ombudsman) or bring the case before the employment tribunal; the burden of proof then works in their favour, since they only need to present facts suggesting discrimination for the employer to have to justify a decision unrelated to any discrimination.
For a recruiter, the best protection is the same on both sides of the law: document the criteria used, keep a record of the final human decision, and be able to explain, at any time, why a profile was selected or set aside.
To learn more about Seeqle's AI technology, visit seeqle.com.
The next step
Fewer applications to sort, more good ones.
If you spend time turning down applicants, the problem sits upstream. The Match Agent analyses and scores every application as it arrives: you only read the ones that matter.
No credit card. 14 days free.



