Guide8 min read

AI in HR: Applicant Data and the GDPR

AI can screen applications but, under GDPR Art. 22, must not decide alone. What HR needs to know about applicant data, legal basis and special categories.

By Alexis de ONYRI
Worried about your data? Anonymize it before AI

In short: AI can screen applications, but it must not decide on its own. Applicant data is personal data. The GDPR applies in full. What matters most is purpose, necessity and data minimisation. An automatic rejection with no human is not allowed under Art. 22 GDPR.

What the GDPR requires for applicant data

You may only process applicant data when it is needed for the hiring process. Ask only for what you truly need to assess a candidate. Less data means less risk.

  • Purpose limitation: use data only for this hiring process.
  • Necessity: collect only what the role really requires.
  • Data minimisation: as little data as possible (Art. 5 GDPR).
  • Transparency: inform candidates about the processing.
  • Legal basis: check Art. 6 GDPR before you start.

No fully automated rejection (Art. 22)

A decision with legal effects must not rest on automated processing alone. A rejection by algorithm, with no human, falls under this rule. A person must review and own the decision.

  • AI may shortlist and summarise, not reject for good.
  • A human reviews each suggestion and decides.
  • Candidates can ask for an explanation and object.
  • Document who makes the final decision.
  • Exceptions are narrow and need safeguards.

Avoiding bias and discrimination

Generative AI can repeat patterns from past data. That can create bias against certain groups. Discrimination in hiring is unlawful.

  • Check AI suggestions for bias on a regular basis.
  • Do not let it weigh factors unrelated to the job.
  • Spot-check the results by hand.
  • Define clear, fair criteria in advance.
  • Keep a human in charge of the shortlist.

Do not enter special categories (Art. 9)

Some data is specially protected. Art. 9 GDPR lists these categories exhaustively: health, origin, religion, union membership, biometrics and more. A plain name, phone number or address is not on that list.

  • Never enter health or origin data into the AI.
  • Leave out religion or union membership.
  • Avoid photos and biometric data.
  • Name and contact are protected, but not under Art. 9.
  • When in doubt, remove the data before input.

How to use AI the compliant way

Clear rules make AI safer in recruiting. Write the steps down. That keeps the process easy to audit.

  1. 1Set the legal basis and purpose up front.
  2. 2Add the processing to your records.
  3. 3Run a DPIA when the risk is high.
  4. 4Inform candidates clearly.
  5. 5Reduce personal data before the AI step.
Data typeExamplePseudonymise before AI?
Name & contactJohn Smith, emailYes, pseudonymise
Special categories (Art. 9)Health, originDo not enter
CV contentSkills, experienceYes, pseudonymised
Final decisionOffer or rejectionHuman decides
Legal basisArt. 6 GDPR, local lawCheck first

This is where ONYRI Sanitize helps. The tool spots sensitive data such as names and contact details, then swaps them for reversible tokens before the text reaches the AI. The map between token and value stays in your browser and is never sent to a server. After the AI replies, the real values are restored. To be honest: this is pseudonymisation, not anonymisation. Pseudonymised data is still personal data (GDPR Recital 26). ONYRI reduces data exposure, but it does not replace a data processing agreement (DPA) or a legal basis.

AI can take work off HR's plate. But a human decides, and the GDPR sets the frame. Less data in the AI means less risk.

Frequently asked questions

Can AI reject an application automatically?
No. Under Art. 22 GDPR, a decision with legal effects cannot rest on automated processing alone. A human must review and own each rejection.
Which data must not be entered into the AI?
Special categories under Art. 9 GDPR: health, origin, religion, union membership, biometrics. A plain name or phone number is not on that list.
Do we need a DPIA?
Often yes. When AI screening is likely to pose a high risk to candidates, a data protection impact assessment is required before you start.
Do we have to inform candidates?
Yes. Transparency is a core GDPR duty. Tell candidates that AI supports the process and how their data is used.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Read next