PrivacySignal
GDPR / Intl

Deployment of AI Recruitment Tools in the EU: Employer Obligations Under GDPR and EU AI Act

Ogletree · · International · GDPR & International

Employers in the EU using AI-powered recruitment tools face obligations under both GDPR and the EU AI Act, which together impose rules on how candidate data is collected, processed, and used in automated hiring decisions.

Why this matters: If you have applied for a job recently, there is a reasonable chance an AI tool screened you before a human did. In the EU, that now triggers real legal obligations for employers. GDPR already covers candidate data. The AI Act adds a new layer, because hiring tools are classified as high-risk systems. That means employers cannot just plug in a vendor product and call it done. They have to document it, audit it, and take responsibility for outcomes. Job seekers rarely know any of this is happening, which is exactly why the rules exist.

Who should care: Lawyers · Privacy officers · AI governance · Administrators · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

The Attacker Did Not Need to Sleep

Spain received its first reported personal-data breach carried out by an AI agent. The techniques were familiar. The speed and autonomy were not.

· 4 min read Read →

Related stories

GDPR / Intl
T The National Law Review · · International

Amendments to Delaware’s Consumer Privacy Law Deepen the Morass of State Privacy Regulation

Delaware has amended its consumer privacy law, adding new layers to an already complex patchwork of state-level privacy rules across the United States. The changes make compliance more complicated for companies operating in multiple states.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#state-privacy#regulation#privacy Read original →
GDPR / Intl
SCOTUSblog · · US Federal

Trump blasts Supreme Court on social media

President Trump publicly criticized the Supreme Court on social media, while Attorney General Todd Blanche indicated the administration is planning further action on mail-in voting.

Who should care: Lawyers · Privacy officers · Compliance

#state-privacy Read original →
GDPR / Intl
The Guardian — Tech · · International

Blanche defends Trump’s tirade against supreme court after it blocked mail-in voting executive order – US politics live

The U.S. Supreme Court blocked a Trump executive order on mail-in voting, prompting the president to publicly criticize the justices. Attorney General Blanche responded by saying Trump should communicate his concerns through proper channels rather than public attacks.

Who should care: Lawyers · Privacy officers · Compliance

#state-privacy Read original →
GDPR / Intl
B Bloomberg.com · · International

Attorney General Blanche Opposes AI ‘Regulation by Prosecution’

U.S. Attorney General Blanche has publicly opposed the use of prosecutorial action as a tool for regulating artificial intelligence, signaling a position against agencies or officials using enforcement cases to effectively set AI policy.

Who should care: Lawyers · Privacy officers · Compliance · General readers · AI governance · Policy

#state-privacy#regulation#ai Read original →
GDPR / Intl
EDPS · · EU

TechDispatch on secure multi-party computation

The European Data Protection Supervisor has published a TechDispatch examining secure multi-party computation, a cryptographic method that allows organizations to jointly analyze data without exposing it to each other. The report explores potential uses in medicine and finance and clarifies that the technique does not replace obligations under EU data protection law.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →