En este modulo
- The legal framework for AI in HR
- GDPR Art. 22: automated decisions in employment
- AI Act Annex III.4: concrete obligations for HR
- Informing employees (AI Act Art. 26.7)
- DPIA for AI systems in HR
- Consultation with worker representatives
- Activity logging and records
- Contracts with AI vendors for HR
- Compliance checklist for AI in HR
- Ejercicio practico
- Puntos clave
The legal framework for AI in HR
HR is the most regulated department when it comes to AI use. And for good reasons: employment decisions directly affect people's fundamental rights (right to work, non-discrimination, privacy, dignity). An algorithm that decides who is hired, promoted or fired has an impact comparable to that of a judge.
The legal framework applicable to AI in HR in the EU consists of three pillars:
- GDPR (General Data Protection Regulation, 2018): regulates personal data processing, including automated decisions (Art. 22).
- AI Act (AI Regulation, 2024): classifies AI in employment as high-risk (Annex III.4) and imposes specific obligations.
- National employment law: labor statutes, collective agreements, and worker representatives' information and consultation rights.
This module guides you through each of these pillars with practical instructions. It is not a legal document (you need a lawyer for that). It is a working guide for the HR manager who wants to use AI without breaking the law.
The cost of non-compliance
GDPR fines can reach 4% of global annual turnover or 20 million EUR (whichever is greater). AI Act fines for high-risk systems can reach 3% of global turnover or 15 million EUR. Besides the reputational cost, which in a competitive talent market can be even more damaging than the fine.
GDPR Art. 22: automated decisions in employment
GDPR Art. 22 establishes a fundamental right: "The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her."
What it means in practice for HR
- Hiring: you cannot reject candidates fully automatically without meaningful human intervention. A human who simply "approves" what the algorithm says without reviewing it does not count as meaningful intervention.
- Performance evaluation: if the evaluation score is automatically generated and has consequences (bonus, promotion, dismissal), you need real human intervention in the decision.
- Monitoring: if you monitor employee performance with AI and the conclusions affect their employment situation, Art. 22 applies.
- Turnover prediction: if you use prediction to take measures that affect the employee (not renewing contract, changing team), you need a legal basis and transparency.
The 3 exceptions under Art. 22
Automated decisions are permitted when:
- It is necessary for a contract between the data subject and the controller.
- It is authorized by EU or Member State law.
- It is based on the data subject's explicit consent.
In all three cases, you must implement measures to safeguard the data subject's rights: at minimum, the right to obtain human intervention, the right to express their point of view, and the right to contest the decision.
What is "meaningful human intervention"
The EDPB (European Data Protection Board) guidance clarifies that human intervention must be real, not simulated. Criteria:
- The reviewing person has authority and ability to change the decision.
- They have access to all relevant information (not just the algorithm's output).
- They dedicate sufficient time to the review (not an automatic click).
- They can bring criteria the algorithm does not have (context, personal circumstances).
AI Act Annex III.4: concrete obligations for HR
We covered the AI Act classification in HR02. Here we go deeper into the practical obligations it creates for the HR department.
Deployer obligations (the company using the AI system)
The AI Act distinguishes between provider (who develops the system) and deployer (who uses it). Your company is the deployer. Your obligations as a deployer of a high-risk system include:
- Assign human oversight (Art. 26.1): designate persons with competence, authority and resources to oversee the system. Simply saying "HR monitors it" is not enough. You need specific people with training.
- Use the system per instructions (Art. 26.1): read and follow the provider's usage instructions. If the provider says "do not use for automatic rejection" and you use it for that, you are liable.
- Ensure relevant input data (Art. 26.4): the data you feed the system must be representative of the context in which you use it.
- Inform employees (Art. 26.7): before using a high-risk system, you must inform workers and their representatives.
- Conduct DPIA (Art. 26.9): data protection impact assessment before putting the system in use.
- Retain logs (Art. 26.6): maintain automatic records generated by the system for at least 6 months.
- Monitor the system (Art. 26.5): watch its operation and report serious incidents to the provider and authority.
Application timeline
- February 2025: prohibitions on unacceptable practices (e.g. social scoring).
- August 2025: obligations for general-purpose AI models (GPAI).
- August 2026: obligations for Annex III high-risk systems (includes HR).
- August 2027: obligations for high-risk systems integrated into regulated products.
Informing employees (AI Act Art. 26.7)
AI Act Art. 26.7 establishes that "deployers shall inform workers and their representatives that they will be subject to the use of a high-risk AI system". This obligation is independent of GDPR and adds to existing transparency obligations.
What information to provide
- Which AI system is used: name, provider, purpose.
- What it is used for: in which HR process stage and for what purpose (screening, evaluation, prediction).
- What data it processes: what employee/candidate information feeds the system.
- What type of decisions it produces: recommendations, scores, classifications.
- What human intervention exists: who reviews decisions and how the employee can challenge them.
- Employee rights: right to explanation, right to challenge, right to have the decision reviewed by a human.
Format and channel for information
The AI Act does not specify the format, but best practices include:
- AI policy document for HR accessible to all employees (intranet, employee handbook).
- Specific communication when introducing a new system (email, informational meeting).
- Notice within the process itself (e.g.: at the start of an online application: "This process uses AI for...").
- Query channel (email, form) for questions and complaints.
Not just obligation, also opportunity
Informing employees about AI use is not just compliance. It is an opportunity to build trust. Companies that are transparent about how they use AI generate greater acceptance than those that do it silently. Opacity generates distrust. Transparency generates collaboration.
DPIA for AI systems in HR
The DPIA (Data Protection Impact Assessment) is mandatory when data processing presents a "high risk to the rights and freedoms" of individuals. Using AI in employment decisions always falls into this category.
When is DPIA mandatory
According to EDPB guidelines, a DPIA is mandatory when 2 or more of these criteria are met:
- Evaluation or scoring (including profiling)
- Automated decision-making with legal or significant effect
- Systematic monitoring
- Sensitive or highly personal data
- Large-scale processing
- Combination of datasets
- Data of vulnerable persons (employees = power relationship)
- Innovative use of technology
- Processing that prevents exercise of a right
An AI system for CV screening meets at least 4 of these criteria. The DPIA is not optional.
DPIA content
- Processing description: what data, what system, what purpose, what flow.
- Necessity and proportionality: why is this processing necessary? Is there a less invasive alternative?
- Risks to rights: discrimination, lack of transparency, data loss, unjust decisions.
- Mitigation measures: for each risk, what measure reduces the impact or probability.
- DPO consultation: the Data Protection Officer must be consulted.
- Stakeholder consultation: when possible, consult employees or their representatives.
Prompt to start a DPIA
"Generate the outline of a DPIA for an AI system used in [CV screening / performance evaluation / turnover prediction]. Data processed: [list]. Purpose: [description]. Responsible: [department]. For each DPIA section (description, necessity, risks, mitigation): generate 3-5 relevant points. Include the applicable GDPR and AI Act articles. NOTE: this is an initial draft for DPO review, not a final legal document."
Consultation with worker representatives
In EU member states, employment law generally recognizes the right of worker representatives to be informed and consulted about the introduction of new work systems that may affect workers. This explicitly includes AI systems.
Recommended consultation process
- Prior information: at least 15 days before implementing an AI system, deliver a document to the works council/representatives with: system description, purpose, data processed, impact on working conditions.
- Consultation period: give representatives the opportunity to ask questions and raise objections.
- Reasoned response: if representatives raise objections, respond with reasons (accepting or justifying why they are not accepted).
- Documentation: record the entire process (dates, documents delivered, questions, responses).
Activity logging and records
Both GDPR (Art. 30) and the AI Act (Art. 12 and 26.6) require maintaining records of AI system use. In the HR context, this means:
- Decision log: for each AI-assisted decision (candidate rejected, evaluation generated, turnover score), record: date, input, output, final decision, and who made the final decision.
- Retention period: at least 6 months per the AI Act. GDPR may require more depending on the legal basis.
- Accessibility: logs must be available to the supervisory authority and for internal audits.
- Integrity: logs must not be retroactively modifiable.
Contracts with AI vendors for HR
If you use an external AI provider for HR (an ATS with AI, an evaluation platform, a screening service), your contract with that provider must include specific clauses.
Essential clauses
- GDPR role: the provider is a data processor. You need a processor agreement (Art. 28 GDPR).
- Algorithmic transparency: the provider must give you sufficient information about how the system works to fulfill your transparency obligations.
- Audits: right to audit the system (or have a third party audit it) to verify fairness and compliance.
- Incidents: provider obligation to notify you of incidents affecting the system's accuracy, bias or security.
- Data portability: right to extract your data if you change providers.
- Data location: where data is processed (within the EU is a requirement in many cases).
- Data use for training: the provider must NOT use your employee/candidate data to train AI models (unless you explicitly authorize it).
Compliance checklist for AI in HR
Use this checklist before implementing any AI system in HR:
GDPR
- Legal basis identified for data processing (Art. 6)?
- DPIA conducted and documented?
- DPO consulted?
- Information to data subjects (Art. 13/14) updated?
- If automated decision-making (Art. 22): meaningful human intervention implemented?
- Processor agreement with the provider (Art. 28)?
- Record of processing activities updated (Art. 30)?
AI Act
- System classified as high-risk (Annex III.4)?
- Human oversight assigned (specific people with training)?
- Employees and representatives informed (Art. 26.7)?
- Automatic logs functioning and stored (min. 6 months)?
- Provider usage instructions read and followed?
- Incident procedure defined?
Employment law
- Works council informed and consulted?
- Consultation process documentation archived?
- Employee complaint channel enabled?
- Collective agreements reviewed (are there AI clauses)?
Ejercicio practico
- Make an inventory of all AI systems your HR department uses or plans to use. For each: name, provider, purpose, data processed, HR process stage where it applies.
- Classify each system per the AI Act: high-risk (Annex III.4), limited risk, or minimal risk. Justify the classification.
- For a high-risk system, generate the DPIA outline using this module's prompt.
- Draft a communication to employees about AI use in HR (what system, for what purpose, what rights they have). Use AI to generate the first draft.
- Review the contract with your ATS or HR platform provider. Does it have the essential clauses listed in this module? Identify the missing ones.
- Complete this module's compliance checklist. Identify gaps and prioritize the 3 most urgent.
Bonus: Consult with your DPO (or privacy officer): are they aware of the AI systems HR uses? If not, that conversation is urgent.
Puntos clave
Puntos clave from HR08
- HR is the most regulated department for AI: GDPR Art. 22 prohibits automated decisions without meaningful human intervention, the AI Act classifies AI in employment as high-risk, and employment law requires worker representative consultation.
- DPIA is mandatory for any AI system in HR that makes or assists decisions about people. It is not optional and must be done before implementing the system.
- AI Act Art. 26.7 requires informing employees and representatives before using high-risk systems. Do it proactively: transparency builds trust.
- Contracts with AI vendors for HR must include specific clauses: algorithmic transparency, audit rights, no data use for training, EU data location.
- Compliance is not an obstacle to using AI in HR. It is a framework that requires you to use it well: with transparency, human oversight, and respect for people's rights.
Guia de estudio — Conceptos clave de HR08
El marco legal de la IA en RRHH
- RGPD (Reglamento General de Proteccion de Datos, 2018):regula el tratamiento de datos personales, incluyendo las decisiones automatizadas (Art. 22).
- AI Act (Reglamento de IA, 2024):clasifica la IA en empleo como alto riesgo (Annex III.4) e impone obligaciones especificas.
- Legislacion laboral nacional:Estatuto de los Trabajadores, convenios colectivos, y derechos de informacion y consulta de los representantes de los trabajadores.
- El coste de no cumplir: Las multas del RGPD pueden alcanzar el 4% de la facturacion global anual o 20 millones de EUR (lo que sea mayor). Las multas del AI Act para sistemas de alto riesgo pueden alcanzar el 3% de la facturacion global o 15 millones de EUR. Ademas del coste reputacional, que en un mercado de talento competitivo puede ser aun mas danino que la multa.
Art. 22 RGPD: decisiones automatizadas en empleo
- ### Que significa en la practica para RRHH
- Contratacion:no puedes descartar candidatos de forma completamente automatica sin intervencion humana significativa. Un humano que simplemente "aprueba" lo que dice el algoritmo sin revisarlo no cuenta como intervencion significativa.
- Evaluacion del desempeno:si el score de evaluacion se genera automaticamente y tiene consecuencias (bonus, promocion, despido), necesitas intervencion humana real en la decision.
- Monitorizacion:si monitorizas el rendimiento de los empleados con IA y las conclusiones afectan a su situacion laboral, aplica el Art. 22.
- Prediccion de rotacion:si usas la prediccion para tomar medidas que afectan al empleado (no renovar contrato, cambiar de equipo), necesitas base legal y transparencia.
- Es necesaria para un contrato entre el interesado y el responsable del tratamiento.
AI Act Annex III.4: obligaciones concretas para RRHH
- Asignar supervision humana(Art. 26.1): designar personas con competencia, autoridad y recursos para supervisar el sistema. No vale decir "RRHH lo vigila". Necesitas personas concretas con formacion.
- Usar el sistema conforme a las instrucciones(Art. 26.1): leer y seguir las instrucciones de uso del proveedor. Si el proveedor dice "no usar para descarte automatico" y tu lo usas para eso, eres responsable.
- Asegurar datos de entrada relevantes(Art. 26.4): los datos que alimentas al sistema deben ser representativos del contexto en que lo usas.
- Informar a los empleados(Art. 26.7): antes de usar un sistema de alto riesgo, debes informar a los trabajadores y sus representantes.
- Realizar DPIA(Art. 26.9): evaluacion de impacto en proteccion de datos antes de poner el sistema en uso.
- Conservar logs(Art. 26.6): mantener los registros automaticos generados por el sistema durante al menos 6 meses.
Informacion a empleados (Art. 26.7 AI Act)
- Que sistema de IA se usa:nombre, proveedor, proposito.
- Para que se usa:en que fase del proceso de RRHH y con que finalidad (screening, evaluacion, prediccion).
- Que datos procesa:que informacion del empleado/candidato alimenta al sistema.
- Que tipo de decisiones produce:recomendaciones, scores, clasificaciones.
- Que intervencion humana existe:quien revisa las decisiones y como puede el empleado impugnarlas.
- Derechos del empleado:derecho a explicacion, derecho a impugnacion, derecho a que la decision sea revisada por un humano.
DPIA para sistemas de IA en RRHH
- Evaluacion o scoring (incluido profiling)
- Toma de decisiones automatizada con efecto legal o significativo
- Monitorizacion sistematica
- Datos sensibles o de naturaleza personal
- Tratamiento a gran escala
- Combinacion de conjuntos de datos
Consulta con representantes de los trabajadores
- Ser informado sobre los parametros, reglas e instrucciones en los que se basan los algoritmos o sistemas de IA que afectan a la toma de decisiones sobre condiciones de trabajo, acceso y mantenimiento del empleo.
- Esto incluye: profiling, perfiles de empleados, evaluaciones de rendimiento, seleccion de personal, y cualquier decision laboral algoritmicamente asistida.
- Informacion previa:al menos 15 dias antes de implementar un sistema de IA, entregar al comite un documento con: descripcion del sistema, finalidad, datos tratados, impacto en condiciones de trabajo.
- Periodo de consulta:dar al comite la oportunidad de formular preguntas y objeciones.
- Respuesta motivada:si el comite plantea objeciones, responder motivadamente (aceptando o justificando por que no se aceptan).
- Documentacion:registrar todo el proceso (fechas, documentos entregados, preguntas, respuestas).
Siguiente: HR09 - Employer Branding with AI
You now know how to use AI in HR legally. Now, how to use it to attract talent: value proposition, careers page content, Glassdoor, social recruiting and candidate nurturing.
Ir al modulo HR09