Governance
Does a recruitment AI agent require a DPIA?
Almost always yes. France’s CNIL names algorithmic candidate screening explicitly, and a missing DPIA is a priority enforcement theme for 2026.
Yes, in almost every case, and that is not lawyerly caution, it is a mechanical consequence of two rules.
First: France’s data protection authority publishes a list of processing operations for which an impact assessment is mandatory, and processing intended to facilitate recruitment through a selection algorithm is named on it. Second: failing that, a DPIA is required as soon as processing meets at least two of the nine criteria set by the European Data Protection Board.
Why a recruitment agent mechanically ticks several
The nine criteria are: evaluation or scoring, automated decision with legal effect, systematic monitoring, sensitive data, large-scale processing, matching of datasets, vulnerable subjects, innovative use, and blocking a right or service. Two are enough.
Count them for an agent that screens or ranks applications.
Evaluation. Ranking is evaluating. Even a plain “here are the twelve profiles closest to the requirement” is scoring, however it is presented. First criterion, met immediately.
Matching of datasets. As soon as the agent reads the ATS and the inbox, or the ATS and a public profile, it combines data collected for different purposes. Second criterion. You are already within the obligation.
Large scale. A pool of a few thousand people is ample, and most staffing firms hold far more.
Innovative use. An agent that performs tasks is still, in 2026, a technology whose effects are not settled. The criterion exists precisely for that.
Three or four criteria out of nine, when the threshold is two. So the practical question is not “do we need a DPIA” but “who writes it, and with what information”.
What the CNIL is looking for in 2026
A missing DPIA on an AI screening tool is among the priority enforcement themes announced for 2026. That is operational information more than a threat: it means the subject is looked for, not stumbled upon following a complaint.
And it is a standalone breach. You can have perfectly proportionate processing, correct retention periods and well-informed candidates: the absence of an impact assessment is sanctionable in itself, because the obligation bears on the exercise, not on its conclusion.
Three other points recur in HR audits, and each can be checked in half a day: the retention periods actually applied, two years after last contact for an unsuccessful candidate is the usual reference: the information given to individuals about the existence of algorithmic processing, and the legal basis relied on for sourcing profiles who never applied.
Article 22, which is not negotiable
Independently of the DPIA, Article 22 GDPR forbids a decision producing a significant effect from being taken solely on the basis of automated processing. Rejecting an application is one.
The authority applies this without particular flexibility, and the operative word is “meaningful”: a human approval that consists of clicking through a list without reading it is not involvement, it is a signature. That is exactly the subject of the approval line, and it is a point where compliance and product quality say the same thing.
The design consequence: an agent should return a ranked list and its reasoning, never a shortened list. The difference is invisible in use and decisive in law.
What you need from the vendor
The DPIA falls to the controller, you, but it cannot be written without the vendor, who is a processor under Article 28. Five items are required, and a serious vendor supplies them without being pressed.
The inventory of data categories processed, by purpose. Not “recruitment data”: the fields.
Downstream sub-processors, in full chain. This is the most commonly missing item. An agent relies on a model provider, a host, sometimes a transcription service: each is a sub-processor, each must be documented, and you must be able to object to a change.
The hosting location, and how transfers outside the EU are handled. Hosting in the EU with European sub-processors shortens legal review by weeks: it has become a purchasing criterion in its own right for large-account procurement teams.
A contractual no-training commitment, extended to downstream model providers. A line in an FAQ is worth nothing.
Retention periods applied by the tool itself, including for logs and intermediate data.
A vendor unable to supply those five items does not merely inconvenience you: they materially prevent you from meeting your own obligation.
How long it takes, and where to start
DPIAs have a reputation as a major undertaking. For a recruitment agent in a staffing firm it is two to three weeks of spread-out work, and most of the delay is not the writing: it is waiting for the vendor’s answers.
The method has five steps, and the French authority publishes free software that structures them.
Describe the processing. Purposes, data, recipients, retention, flows. This is the longest and most useful part, because it forces you to write down what the tool actually does rather than what you assume it does.
Assess necessity and proportionality. Every field collected must be justified by the purpose. The question that eliminates the most fields: “which decision does this data serve?” Many do not survive it, and removing them cuts both risk and cost.
Identify risks to individuals. Illegitimate access, unwanted modification, loss, applied to candidates, not to the company. That shift of perspective is what the exercise imposes.
Define the measures. Partitioning, logging, human approval, narrowed scope. This is where the analysis becomes a specification.
Obtain the DPO’s opinion, and that of the people concerned or their representatives where relevant, which usefully overlaps with the works council file.
Two common mistakes. The first is doing it too late, when nothing can still be changed. The second is treating it as final: a DPIA is revised when the processing changes, and adding a data source or a new task to the agent is a change. Plan an annual review; it takes half a day when the first one was done properly.
A note for firms operating outside France. The nine criteria come from the EDPB and apply across the EU, so the reasoning transfers unchanged; what varies is the national list of processing operations for which a DPIA is compulsory, published by each supervisory authority. Check yours before concluding the obligation does not apply, recruitment screening appears on most of them.
A DPIA is a design decision, not a document
That is the inversion that makes the exercise useful rather than tedious.
A well-run impact assessment asks three questions whose answers change the product: which data is genuinely necessary, and therefore which not to collect; who can see what, and therefore what partitioning to impose; what happens when the processing gets it wrong, and therefore which decision must stay human.
Run afterwards, it describes what exists and serves nothing. Run while evaluating solutions, it becomes a requirements document, and it produces exactly the documentation the works council will ask for, whose consultation is now a precondition to deployment.
It is also the foundation of what the AI Act will require from 2 December 2027 for recruitment tools: technical documentation, risk management, human oversight, logging. The two exercises overlap substantially. Whoever writes their DPIA seriously in 2026 will have done half the work, and done it while it was still a choice.
Frequently asked questions
When is a DPIA mandatory?
In two cases. Either the processing appears on the supervisory authority’s published list of operations requiring an impact assessment, and algorithmic candidate screening is named there explicitly. Or it meets at least two of the EDPB’s nine criteria: evaluation or scoring, automated decision with legal effect, systematic monitoring, sensitive data, large scale, matching of datasets, vulnerable subjects, innovative use, blocking of a right or service.
Does an agent that only ranks profiles escape the obligation?
No. Ranking is evaluation, and evaluation is the first of the nine criteria. Add large scale as soon as the pool exceeds a few thousand people, and dataset matching as soon as the agent reads both the ATS and the inbox: three criteria out of nine, when two are enough.
Who writes the DPIA, us or the vendor?
You. The DPIA falls to the controller: the company that decides the purpose, not to the vendor, who is a processor. The vendor must, however, supply the raw material: categories of data processed, retention periods, downstream sub-processors, hosting location and security measures. A vendor who does not document them puts you in breach.
What is the risk of not doing one?
It is a standalone breach, sanctionable in itself, regardless of how sound the processing is. The CNIL made it a priority enforcement theme for HR tools in 2026, which means the subject is actively looked for rather than stumbled upon.
Sources
Read next
Governance
Must you consult the works council before deploying AI?In France, yes. A court suspended two HR tools in January 2026, an appeal court two more in May, with daily penalties, and no need to prove urgency.Governance
Who approves what when an AI writes to your candidatesNo, approving everything is the same as delegating nothing. The rule that holds: approval whenever a message leaves the company or closes a door.
