Guide8 min read

AI in HR (France): What the CNIL Says About Employee Data

AI helps you screen and summarise. But pasting a CV or a payslip into an AI exposes HR data that France's CNIL regulates closely.

By Pierre de ONYRI

The answer fits in one line. AI can help you structure and rewrite, but do not hand it the raw data of your employees and candidates. A CV. A payslip. An annual review. Pasted into a consumer AI, these documents leave your HR system. Yet France's CNIL regulates HR data closely. And screening candidates with an automated tool touches a specific right: the automated decision. Good news: AI is not banned in HR. It requires a legal basis, informing people, keeping a human in the loop, and anonymising before any prompt.

The problem: HR pastes employee data into the AI

The gesture is ordinary. To sort a stack of applications, you paste CVs into an AI. To summarise a round of interviews, you give it the notes. To draft a letter, you add a payslip. HR saves time. But every document sent contains personal data of employees or candidates. A consumer AI is a third-party service. What you paste there can be retained, reviewed or reused to train the model.

An HR file concentrates exactly the data the CNIL watches. Here is what a poorly prepared prompt can expose.

  • The name and contact details of a candidate or an employee.
  • Pay elements: salary, bonuses, payslip.
  • Reviews, interview reports, appraisals.
  • Health data (a special category under the GDPR), for example in a sick note or a file.

This data is not trivial. The CNIL, France's data protection authority, has published a dedicated framework for human resources and recruitment. It sets clear principles: a legal basis for each processing, proportionality, informing people, and data minimisation. Minimisation means one simple thing: collect and process only what is necessary.

The stake: the CNIL regulates HR data closely

The CNIL also sets retention benchmarks. They are concrete. The data of a candidate who was not hired should not be kept beyond two years after the last contact, unless a deletion is requested. After an employee leaves, some data is archived to meet legal obligations, such as payslips. These benchmarks come from the CNIL's HR framework. They show one thing: HR data has a bounded lifespan, not an unlimited existence in a chat.

The stake rises with automated screening. The GDPR, in Article 22, grants a specific right. Everyone can refuse to be subject to a decision based solely on automated processing, including profiling. This right applies where the decision produces a legal effect or significantly affects them. Rejecting an application targets exactly this case. Profiling is defined by the GDPR in Article 4: automated processing that evaluates aspects of a person, such as their performance at work or their behaviour. Using an AI to rank candidates falls squarely within that definition.

One point reassures, provided you respect it. Even when an exception to Article 22 applies (contract, law, or explicit consent), the person keeps rights. They can obtain human intervention, express their view and contest the decision. In other words, a human must remain the decision-maker. Decision support screened by a real human eye falls, in principle, outside the strict scope of the ban. An AI deciding on its own does not.

Who is responsible? HR, not the AI

Responsibility cannot be delegated to the tool. The employer, HR team or recruitment agency, acts as the data controller. It defines the purposes and the means. It answers for compliance, including when the processing runs through a third-party AI. The AI provider remains a third party. Hence the value of reducing what leaves your machine before you even send.

Health data deserves separate care. A sick note, a medical mention in a file: these are sensitive data. The GDPR, in Article 9, bans their processing in principle, save strict exceptions. Exposing them to an external AI is therefore to be avoided.

AssumptionThe reality
“AI is banned in HR”No: the CNIL states the GDPR does not ban AI but frames it (legal basis, information, minimisation)
“Pasting a CV into the AI stays internal”A consumer AI is a third party; the content can be retained or reused to train the model
“An AI can screen candidates for me”The GDPR (Art. 22) grants the right not to face a solely automated decision: keep a human as decision-maker
“The AI vendor is the responsible one”HR is the data controller; it answers for compliance, even via a third-party tool
The risk isn't using AI — it's the identifying data left in the prompt and the absence of a human in the decision.

The fix: anonymise before the prompt, keep the human

Good news: AI is still useful to the HR team. It helps structure a grid, rewrite a job ad, summarise an interview outline. For that, it needs no real name. Work on anonymised data. Keep identities, pay figures and sensitive elements out of the prompt. And let a human decide every choice that concerns a person.

Diagram: a stack of candidate cards, each with a person glyph and CV rows; the top card, in amber, is exposed and flows toward an AI card through an anonymiser gate that turns its rows into cobalt token chips and adds a checkmark; beside the AI, a human validation hand stands for the human in the loop.
After the CNIL's HR and recruitment framework, the consolidated GDPR text (Art. 22, 4 and 9) on EUR-Lex, and the CNIL's AI and GDPR recommendations.

When you must describe a concrete case, anonymise it first. Replace each identifying element with a token. The AI reasons about the shape of a CV or a file, without ever seeing the real values. You then restore the real data, locally. Identities never leave your machine. Anonymising supports minimisation, a principle stressed by the CNIL. One caution, though: this care reduces the risk. It does not on its own make your processing GDPR-compliant. And it removes neither the legal basis, nor the duty to inform people, nor the human in the decision.

  1. 1Spot the identifying elements: names, contact details, pay, health mentions.
  2. 2Replace them with reversible tokens, in the browser.
  3. 3Send only the anonymised text to the AI.
  4. 4Restore the real values locally, then have a human validate every decision.

That's what ONYRI Sanitize is for. The engine detects sensitive data — names, contact details, salaries, health mentions — and replaces it with reversible tokens before sending. Detection and the mapping stay in your browser. Only anonymised text reaches the model. The AI finds only tokens, never your candidates' identity nor your employees' pay. You get AI's help, supporting the minimisation the CNIL expects, while keeping the human at the heart of the decision.

Frequently asked questions

AI in HR: what does the CNIL say about employee data?
The CNIL does not ban AI in HR, but it frames it. It has published a dedicated framework for human resources and recruitment, setting out the legal basis, proportionality, informing people and data minimisation. It also sets retention benchmarks: for example, two years after the last contact for a candidate who was not hired. Anonymise identifying data before any prompt and keep a human in the decision.
Can I screen candidates with an AI?
Yes, but with a safeguard. The GDPR, in Article 22, gives everyone a specific right. You cannot be subject to a decision based solely on automated processing that significantly affects you — which covers rejecting an application. Decision support validated by a real human eye stays possible. An AI deciding on its own does not. Keep the human as decision-maker and inform the people concerned.
Who is responsible if the AI gets an HR file wrong?
The HR team or the recruitment agency. As the data controller, it defines the purposes and the means, and it answers for compliance, even when the processing runs through a third-party AI. The AI provider remains a third party. Hence the value of anonymising data before sending, to reduce what leaves your machine.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Anonymize my prompt

Read next