No items found.

Can AI reject candidates automatically? GDPR Article 22

By Jürgen Ulbrich

Short answer: AI should not automatically reject a candidate when the rejection is based solely on automated processing and has a legal or similarly significant effect on that person. That is the GDPR Article 22 test. In practice, either a human must make a real decision, or a narrow exception and its safeguards must apply.

AI support is not banned from recruitment. It can extract facts, summarise applications, flag missing information, or help a recruiter compare evidence. The key question is whether the tool’s output ends the candidate’s opportunity in the process.

The legal test is about the outcome, not the label AI

A solely automated decision is an individual decision made without meaningful human involvement. Under GDPR Article 22, a person has the right not to be subject to a decision based solely on automated processing, including profiling, where it produces legal effects or similarly significantly affects them. Recital 71 specifically identifies e-recruiting without human intervention as an example.

Rejecting an applicant solely because a model assigned a low score will often meet that test: the result concerns one person and excludes them from a job opportunity. Profiling means automated processing that evaluates personal aspects, such as performance at work, reliability, behaviour, interests, or location. Profiling is not automatically forbidden; turning it into the final decision is the risk point.

Article 22 contains limited exceptions, including necessity for entering into or performing a contract, authorisation by EU or Member State law with suitable safeguards, and explicit consent. A recruitment team should not assume that an acceptance box settles the issue. The exception, legal basis, safeguards, and the rest of the privacy framework must fit the actual workflow.

When does AI screening become an Article 22 decision?

Start by mapping what happens after the model produces an output. Resume parsing, a recommendation, or a ranked work queue will not normally be a solely automated decision if a recruiter reviews the underlying materials and can independently invite, reject, or redirect the applicant. That distinction matters especially when handling an application volume and CV-screening workflow.

The position changes where a score automatically closes the application, candidates below a threshold are never shown to a decision-maker, or a recruiter is expected merely to approve the system’s conclusion. Calling that stage a pre-screen does not change its legal effect if it is the last meaningful opportunity for the person.

Use this operational test: could an authorised reviewer realistically advance a rejected applicant after seeing the application and the relevant context? If not, the system is probably making the consequential decision. This test does not replace legal advice, but it exposes cosmetic human-in-the-loop designs quickly.

Meaningful human review is more than a confirm button

The GDPR requires human intervention but does not prescribe a particular screen or approval flow. A defensible process gives the reviewer the information, time, competence, and authority to make a different decision. Periodically sampling the model’s decisions is not the same as reviewing the individual applicant who was screened out.

  • Relevant evidence: reviewers see the application, answers, and material context – not just a red or green score.
  • Ability to interpret: they understand the role-specific criteria, the recommendation, and known limitations of the system.
  • Authority to override: they can reverse the outcome without seeking the tool’s approval.
  • Individual attention: errors, exceptions, accessibility needs, and disputed data receive a real reassessment.
  • Decision record: the final reason and any departure from the recommendation are recorded.

This design also reduces automation bias, the tendency to over-trust an automated suggestion. Where high-risk AI obligations apply, Article 26 of the EU AI Act requires deployers to assign human oversight to people with the necessary competence, training, authority, and support.

What must applicants be told and able to challenge?

Transparency is not satisfied by a vague privacy notice saying that AI may be used. GDPR Articles 13(2)(f), 14(2)(g), and 15(1)(h) require meaningful information about the logic involved, as well as the significance and envisaged consequences of automated decision-making. Recital 71 also refers to an explanation of the decision reached after such an assessment.

Before someone applies, explain in plain language whether the system assists a reviewer or can make an automated determination; which role-related data and rules matter; what an output changes in the process; and where the person can request a human review, express their view, or contest a result. For the Article 22(2)(a) and (c) exceptions, Article 22(3) expressly identifies those safeguards.

A useful explanation lets a person understand the factors that mattered and how to seek reconsideration. It is not necessarily a demand to publish source code or trade secrets. The precise balance depends on the circumstances, which is a reason to design the explanation route before the first rejection is sent.

The EU AI Act, GDPR, and German AGG answer different questions

The EU AI Act adds a separate compliance layer. AI intended for recruitment or selection of natural persons appears in Annex III. Whether a particular system is high-risk depends on its intended purpose and the Article 6 exceptions; an Annex III system that profiles natural persons cannot rely on the exception for systems that do not materially influence a decision. High-risk classification and an Article 22 decision are therefore related but separate assessments.

That makes procurement evidence part of recruitment governance. Ask for intended purpose, instructions, data requirements, human-oversight measures, logging, testing information, and change controls when assessing AI recruiting tools. The AI Act does not replace the GDPR; it makes the operational controls around higher-risk use more explicit.

For hiring in Germany, the General Equal Treatment Act (AGG) adds discrimination risk. It protects, among other grounds, ethnic origin, sex, religion or belief, disability, age, and sexual identity. A model does not need an explicit protected field to create risk: apparently neutral inputs can function as proxies. Keep a record of criteria, versions, changes, and outcomes by process stage, but do not collect sensitive data for a fairness review without first establishing an appropriate legal basis.

German employers should also assess works council involvement early. General assessment criteria and selection guidelines can trigger participation rules; section 95(2a) of the Works Constitution Act expressly preserves the rules on selection guidelines where AI is used.

Prefer transparent knock-out rules to opaque scores

A knock-out rule is a predefined, role-related, objectively verifiable minimum condition. It is usually easier to justify, explain, test, and correct than a single black-box score. Examples might include a professional licence that is genuinely mandatory for the specific job or a legally required permission to perform it.

Vague filters such as “culture fit”, a photo, the name of a school, an employment gap, or a personality judgement inferred from free text are poor candidates for automatic exclusion. They are difficult to explain and can conceal bias. A context-led CV-screening process should use clear role-related questions and a correction path instead of reducing a person to one aggregate score.

The crucial limit is that transparent rules are not an Article 22 exemption. If a rule alone triggers a final rejection with no effective human review, the organisation still has to assess the automated decision under GDPR. Transparency improves accountability; it does not substitute for a lawful basis or the applicant’s safeguards.

Build an evidence trail before you automate

Create a short decision record for each role. It should cover the tool and version, intended purpose, permitted inputs, role-specific criteria and rationale, thresholds or knock-out rules, known failure cases, test results, the human-review path, and the contest route. For a final outcome, retain what the reviewer considered, who decided, when, and the substantive reason.

The same principle applies to AI-supported interviews. A conversation can gather useful context, but it should not become a concealed rejection engine. The guide to AI interviews and voice recruiting explores that process step, while the voice-interview workflow example shows how an interview can be designed as a distinct stage rather than an automatic verdict.

Pre-launch checklist

  • Map the flow: identify every recommendation, lock, rejection, and automated message.
  • Run the Article 22 test: is a significant individual outcome solely automated in practice?
  • Assign named reviewers: give them training, evidence, time, and power to override.
  • Write applicant-facing notices: explain logic, consequences, rights, and the contact route.
  • Challenge the criteria: remove weak proxies and test role-related rules for errors and disparate effects.
  • Assess AI Act and AGG exposure: obtain supplier evidence, define documentation, and check local worker-representation duties.
  • Rehearse the appeal: process a correction request before live candidates receive decisions.

A stated boundary

This is practical orientation, not legal advice. Whether a particular configuration falls under Article 22, qualifies for an exception, or meets AI Act and local employment-law duties depends on the tool, data, role, jurisdiction, and how people actually work with the result. US-only employers should not read the German AGG discussion as US employment-law guidance; organisations recruiting in Europe should obtain advice before deploying or materially changing a decision workflow.

FAQ

Can AI automatically reject a candidate who fails a mandatory requirement?

Not merely because the requirement is clearly written. A final rejection triggered solely by the system may still fall within Article 22. Make the rule role-specific, allow applicants to correct factual errors, and make sure a qualified person can conduct a genuine final review where needed.

Does a human approving the AI recommendation make the process compliant?

Only if the review has substance. The reviewer needs access to the relevant evidence, the authority to depart from the recommendation, and a realistic opportunity to exercise judgment. A routine approval click or a periodic audit is weak evidence of an individual human decision.

Do we have to disclose the whole model to applicants?

Not necessarily. The GDPR requires meaningful information about the logic involved and the expected significance and consequences, rather than a blanket duty to publish source code. Applicants should be able to understand the relevant factors and how to obtain a human reconsideration.

Is a ranking score outside Article 22 if no rejection email is sent automatically?

It can still be in scope if the ranking in practice determines who will never be reviewed or cannot progress. A score used as one input to a genuine human assessment is different. The workflow’s real effect matters more than whether the email is sent by a person.

Does consent solve the problem?

No. Explicit consent is only one of the limited Article 22 exceptions and suitable safeguards remain necessary. Whether consent is informed, freely given, and valid in a specific recruitment process should be assessed carefully rather than assumed from a checkbox.

Jürgen Ulbrich

CEO & Co-Founder of Sprad

Jürgen Ulbrich has more than a decade of experience in developing and leading high-performing teams and companies. As an expert in employee referral programs as well as feedback and performance processes, Jürgen has helped over 100 organizations optimize their talent acquisition and development strategies.

Free Templates &Downloads

Become part of the community in just 26 seconds and get free access to over 100 resources, templates, and guides.

No items found.

The People Powered HR Community is for HR professionals who put people at the center of their HR and recruiting work. Together, let’s turn our shared conviction into a movement that transforms the world of HR.

Similar Posts