GDPR and AI Act compliance

Recruitment AI and compliance: what the GDPR and the AI Act require

A recruitment AI tool is governed by two European texts: the GDPR, which in principle prohibits fully automated decisions on an application (Article 22), and the AI Act, which classifies recruitment among high-risk AI systems (Annex III). This page summarises what the texts say, the application timeline, the employer's obligations, and how Seeqle meets them.

A recruitment agency in France stays GDPR compliant by using agentic AI to prepare the decision, never to make it: Article 22 of the GDPR in principle prohibits fully automated decisions on an application, and the AI Act classifies recruitment among high-risk AI systems (Annex III). At Seeqle, the Match Agent enriches the profile, predicts skills and returns an explained score in the candidate record of the ATS: the recruiter keeps the decision. Data is hosted in the European Union, targeting excludes discriminatory criteria, and candidates must be informed and able to request human intervention.

GDPR

Does the GDPR allow automated screening of applications?

Yes, on one central condition: the final decision must not be fully automated. Article 22 of the GDPR sets out the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, which is the case for rejecting an application.

The CNIL (the French data protection authority) defines a fully automated decision as one taken “without any human being involved in the process”. Three exceptions allow a fully automated decision: the person's explicit consent, contractual necessity, or a specific legal provision. None of these exceptions comfortably covers the automatic rejection of a candidate: the safe practice, effectively recommended by the CNIL framework, is a tool that prepares the decision (screening, scoring, enrichment) and a human who makes it.

Sources: Regulation (EU) 2016/679, Article 22 (EUR-Lex, 2016) · CNIL, guidance on profiling and fully automated decision-making (cnil.fr).

Article 22

What does Article 22 of the GDPR say about application scoring?

An application score is profiling within the meaning of the GDPR: an automated evaluation of personal aspects. Scoring is lawful as long as it remains a decision aid. It becomes prohibited in principle if the score alone triggers rejection, without any real human review of the application.

In practice, the framework grants candidates three rights:

One point highlighted by CNIL doctrine: a purely formal human validation (clicking “validate” without examining the file) is not enough to fall outside the scope of Article 22. The human must have the competence and the latitude to depart from the score.

Sources: Regulation (EU) 2016/679, Article 22 and Recital 71 (EUR-Lex, 2016) · CNIL, guidance on profiling and fully automated decision-making (cnil.fr).

Employer obligations

What GDPR obligations apply to an employer recruiting with AI?

The employer remains the data controller: it must define a legal basis, inform candidates that an automated tool is used, limit the data collected to what is relevant for assessing the application, and set retention periods. The CNIL has published a recruitment guide detailing these obligations.

Main obligations, as documented by the CNIL in its recruitment guide (2023):

Informing candidates
State which data is collected, why and for how long, and disclose the use of automated processing.
Data minimisation
Collect only the data relevant to assessing suitability for the role.
Retention period
Set a limited period for the data of unsuccessful candidates and stick to it.
Processors
Put a contract in place with the tool's vendor (Article 28 of the GDPR).
Security
Guarantee the confidentiality of applications, including at the processor.
Individuals' rights
Enable access, rectification, objection and human review.

Source: CNIL, recruitment guide (cnil.fr, 2023).

AI Act

Why does the AI Act classify recruitment as high risk?

Because Annex III of the European AI regulation (Regulation (EU) 2024/1689) explicitly lists, under employment, AI systems intended for the recruitment or selection of people: targeted distribution of job offers, application screening and candidate evaluation.

Annex III, point 4, covers systems used:

The high-risk classification does not ban these systems: it imposes stricter requirements on their providers (risk management, data quality, documentation, transparency, human oversight, robustness) and obligations on their professional users.

Source: Regulation (EU) 2024/1689, Annex III, point 4 (EUR-Lex, 2024).

Timeline

What is the AI Act application timeline?

The AI Act entered into force on 1 August 2024 and applies in stages: prohibitions since 2 February 2025, general-purpose AI since 2 August 2025, most of the rules since 2 August 2026. The obligations for Annex III high-risk systems, including recruitment, have been postponed to 2 December 2027.

1 August 2024
Regulation enters into force.
2 February 2025
General provisions and prohibited AI practices.
2 August 2025
Rules on general-purpose AI models, governance.
2 August 2026
Most of the regulation's rules, transparency obligations (Article 50).
2 December 2027
Obligations applicable to Annex III high-risk systems, including recruitment.

The postponement from 2 August 2026 to 2 December 2027 for Annex III results from the “Digital Omnibus” on AI, which entered into force in July 2026. The postponement removes no requirement: it shifts their application date, and the GDPR already applies in full.

Sources: European Commission, official AI Act implementation timeline (ai-act-service-desk.ec.europa.eu) · Gibson Dunn, “EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines” (2026) · K&L Gates, “EU Digital Omnibus on AI Enters Into Force” (July 2026).

Deployer

What obligations apply to an employer deploying a high-risk system?

The AI Act distinguishes the provider (the system's vendor) from the deployer (the employer using it). The employer will have to use the system in line with its instructions, entrust oversight to competent people, keep the logs generated, and inform employees and their representatives before the system goes live.

Deployer obligations (Article 26 of the regulation) applicable to recruitment:

These obligations add to the GDPR, they do not replace it: informing candidates, the legal basis and access rights are already due today.

Source: Regulation (EU) 2024/1689, Article 26 (EUR-Lex, 2024).

Seeqle

How does Seeqle meet these requirements?

Seeqle hosts data in the European Union, produces a score that is explainable criterion by criterion, and never makes an automated decision: the Match Agent qualifies and prioritises applications, and the decision to accept or reject always rests with a human. The platform is designed for GDPR and EU AI Act compliance.

What this means in practice:

The details of our security commitments, and how to verify them, are published on the site's Security and data page.

FAQ

Frequently asked questions

Does the GDPR prohibit screening applications with AI?

No. It prohibits in principle fully automated decisions with a significant effect, such as a rejection. A tool that scores and prioritises applications remains lawful if a human genuinely reviews the files and makes the final decision.

Can a candidate contest a score?

Yes. The GDPR gives them the right to be informed of the logic of the processing, to obtain human intervention and to contest the decision. An explainable score, broken down by criteria, is what makes it possible to answer that request.

Is recruitment a high-risk use case under the AI Act?

Yes. Annex III, point 4, of Regulation (EU) 2024/1689 lists recruitment and selection: targeted distribution of job offers, application screening, candidate evaluation. The corresponding obligations will apply on 2 December 2027, after the postponement decided by the Digital Omnibus.

Does Seeqle make automated decisions about candidates?

No. The Match Agent enriches and scores applications with an explainable score, but rejects no candidate: the decision always rests with the recruiter. It is an architecture choice, not an option.

Where is the data processed by Seeqle hosted?

In the European Union. Your campaign data is only used to optimise your own campaigns, and our security commitments are detailed on the Security and data page.

Sources cited: Regulation (EU) 2016/679 (GDPR), Article 22 (eur-lex.europa.eu, 2016) · CNIL, guidance on profiling and fully automated decision-making (cnil.fr) · CNIL, recruitment guide (cnil.fr, 2023) · Regulation (EU) 2024/1689 (AI Act), Annex III point 4 and Article 26 (eur-lex.europa.eu, 2024) · European Commission, AI Act implementation timeline (ai-act-service-desk.ec.europa.eu) · Gibson Dunn (2026) and K&L Gates (July 2026) on the Digital Omnibus postponement.

See how compliance works inside the tool

Explainable score, human decision, EU hosting: a 15-minute demo shows how the Match Agent prepares the decision without ever making it.