---
title: "Is AI CV Screening Legal in the EU? (GDPR + AI Act)"
description: "AI CV screening is legal in the EU, but two laws apply: the GDPR and the EU AI Act. Both require a human, not the software, to make the decision. Here is what that means."
url: https://zjcv.com/journal/is-ai-cv-screening-legal-in-the-eu/
canonical: https://zjcv.com/journal/is-ai-cv-screening-legal-in-the-eu/
author: "Zen Job CV Team"
published: 2026-06-21
updated: 2026-06-21
category: "Research"
tags: ["hiring compliance", "ai screening", "eu ai act", "gdpr", "cv screening"]
lang: en
---

# Is AI CV Screening Legal in the EU? (GDPR + AI Act)

> **TL;DR** AI CV screening is legal in the EU but regulated on two fronts. The GDPR governs candidate data and, through Article 22, restricts decisions made solely by a machine. The EU AI Act classifies application-filtering AI as high-risk, with obligations that apply from 2 August 2026. Neither bans AI screening; both require that a human with real authority makes the actual reject-or-advance decision and that you can explain what the system does. Zen Job CV is deliberately an assistant, ranking and explaining while a person decides, which is the human-in-the-loop shape both laws require. This is not legal advice.

Yes, AI CV screening is legal in the EU, but it is regulated on two fronts at once, and using it lawfully means satisfying both. The GDPR governs how you handle candidate data and, through Article 22, restricts decisions made solely by a machine. The EU AI Act, separately, classifies software used to filter job applications as high-risk and attaches its own obligations. Neither law bans AI screening. Both draw a firm line around one thing: a human, not the software, must make the actual reject-or-advance decision, and you must be able to explain what the system does. Screen with AI as an assistant to a person and you are on solid ground; let it decide alone and you are not.

The practical upshot is that the legality of an AI screening setup depends far less on the cleverness of the model than on how the decision is wired: whether a person with the authority and the information to disagree actually looks before anyone is rejected.

## The two laws that apply

Most confusion about AI screening comes from treating it as one legal question when it is two, governed by two different instruments with two different focuses.

| Law | What it governs | The key rule for AI screening |
|---|---|---|
| GDPR | Candidate personal data | Lawful basis, minimisation, retention, and Article 22 on automated decisions |
| EU AI Act | High-risk AI systems | Application-filtering AI is high-risk, with duties on providers and deployers |

The two overlap but do not duplicate. The GDPR asks whether you may process this candidate's data this way and whether a machine may decide their outcome. The AI Act asks whether this category of system is safe, documented, and overseen. You have to answer both, and answering one does not excuse the other.

## What Article 22 actually requires

This is the article that decides whether your AI screening is a routine data question or a serious one. [Article 22 of the GDPR](https://gdpr-info.eu/art-22-gdpr/) gives a person the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects them. Being screened out of a job qualifies as a significant effect. The load-bearing word is "solely."

A system that ranks candidates and hands the shortlist to a recruiter who reviews it, checks the near-misses, and decides who to interview is not making a solely automated decision, because a human is meaningfully in the loop. A system that auto-rejects everyone below a score, sends the rejection, and never surfaces those people to a person is. The difference is not how advanced the AI is; it is whether a human with real authority and the reasons in front of them actually reviews before a candidate is turned away. Three things follow: keep a human in the loop and make the review real, never configure a silent auto-reject, and be able to explain any individual outcome. This is the same reason a fast pass should [sort candidates rather than decide their outcome](/journal/review-cv-in-10-seconds/), whether the speed comes from a recruiter or a model. The full set of GDPR duties around this is set out in [the rules on GDPR CV screening](/journal/gdpr-rules-for-cv-screening/).

## What the EU AI Act adds, from 2 August 2026

The AI Act is the newer layer, and recruitment is named in it explicitly rather than caught by implication. [Annex III, point 4(a)](https://artificialintelligenceact.eu/annex/3/) classifies as high-risk any AI system intended to be used "for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates." Filtering applications is the worked example the legislators chose, not an edge case.

On timing, [Article 113](https://artificialintelligenceact.eu/article/113/) sets general application from 2 August 2026, and recruitment systems fall under that date because they are classified through Annex III, not through the separate product-safety route that carries a later 2027 deadline. So a hiring team using AI screening should treat 2 August 2026 as the date the high-risk obligations bite.

Most of those obligations, risk management, data governance, technical documentation, logging, accuracy, and human oversight by design, sit with the provider that builds the system. But the employer deploying it is not passive: you are expected to use the system according to its instructions, assign human oversight to people with the competence and authority to exercise it, keep the logs it generates, and inform workers and their representatives before putting it into use.

## Provider versus deployer: who does what

Because the duties split between the company that makes the tool and the company that uses it, it helps to see which are yours.

| Obligation | Provider (the tool vendor) | Deployer (you, the employer) |
|---|---|---|
| Risk management and documentation | Yes | Review what they provide |
| Accuracy and bias testing | Yes | Ask for the evidence |
| Human oversight | Designed in | Assigned to competent people |
| Logging | Enabled by the system | Retained by you |
| Informing candidates and workers | Supports it | Actually do it |

The practical move for a hiring team is therefore a procurement question as much as a legal one: before an AI screening tool goes live, ask the vendor which side of the high-risk line they sit on, what documentation they will give you, and what they expect of you as deployer. A vendor who has not thought about this by mid-2026 has told you something useful about whether to trust them with candidate data.

## What makes an AI screening setup lawful

Pulling the two laws together, a compliant setup is less about the algorithm and more about the wiring around it. There must be a lawful basis for processing the candidate data, usually the pre-contract-steps basis with legitimate interests for the surrounding records. The system must never be the sole decision-maker: a human reviews the ranking and the near-misses and makes every reject and hire. You must be able to describe, in plain language, what the system evaluates, which candidates are told about under the GDPR's transparency duties. You keep only job-relevant data, on a documented retention schedule. And from August 2026 you meet the deployer duties: competent oversight, retained logs, and informing the people affected.

A tool built for that shape makes compliance easier rather than harder. Zen Job CV is deliberately an assistant, not a decider: it ranks candidates against your plain-language criteria with the reasons each one met and missed attached, keeps a near-miss list so nobody is silently dropped, holds an audit trail, and stores data in the EU. A person reviews the shortlist and makes every call, which is exactly the human-in-the-loop shape both laws require. It cannot, and should not, make the hiring decision for you, and that limitation is the point.

## Bias, and why the AI Act cares about it

One reason recruitment AI was singled out as high-risk is that a screening model learns from data, and data carries the patterns of past hiring, including its discrimination. A model trained on who was hired before can quietly reproduce the very bias that a fair process is meant to remove, and do it at scale and behind a score that looks objective. That is why the AI Act's provider duties include data governance and bias testing, and why an employer's transparency duty matters: a screening criterion you cannot explain is one you cannot check for unfair effect.

For a deployer this has a practical edge beyond the paperwork. Ask a vendor not just whether their tool is accurate but how they test it for disparate impact, and prefer systems whose logic you can read over ones that score candidates through a black box. Screening on explicit, plain-language criteria you set is easier to audit for fairness than a model that infers its own, which is a compliance argument for readable rules as much as an ethical one. Blinding the first pass to names, photos, ages and schools, the approach set out in [bias-aware blind screening](/journal/bias-aware-blind-cv-screening/), reduces one well-documented channel of bias at exactly the stage a high-volume AI pass runs, and it costs nothing.

The point is that legal and fair are not separate projects here. The AI Act treats a discriminatory screening system as a high-risk failure, not just an ethical lapse, so building fairness into the setup, explainable criteria, a blind first pass, a human decision, is also how you meet the obligation.

## The honest caveat

None of this is legal advice, and the details vary by country and by how your specific tool works. High-risk AI in employment is a live, YMYL area where the safe move is to verify against the primary sources and, for a significant deployment, take qualified legal advice rather than rely on a guide. What a guide can do is get the shape right: AI screening is legal in the EU when a human makes the decision, the processing has a basis, the system is transparent, and, from August 2026, the AI Act's high-risk duties are met. What it cannot do is replace checking your own setup against the law.

## How to use AI CV screening legally in the EU

Start from the decision, not the algorithm. Make sure a human with real authority reviews the ranking and the near-misses and makes every reject and hire, so no candidate is turned away by software alone, which is the line Article 22 draws. Give the processing a lawful basis, keep only job-relevant data on a retention schedule, and be able to explain in plain language what the system evaluates. Before August 2026, confirm your vendor's high-risk documentation and assign competent human oversight, because that is when the EU AI Act's obligations for application-filtering systems apply. Do those, and AI screening is a lawful assistant; skip the human decision, and it is not.

## Quick answers

**Is AI CV screening legal in the EU?** Yes, but it is regulated by both the GDPR and the EU AI Act. Neither bans it. The firm line both draw is that a human, not the software, must make the actual reject-or-advance decision, and you must be able to explain what the system does. Used as an assistant to a person with a lawful basis and transparency, AI screening is lawful; used as the sole decision-maker, it is not.

**Does GDPR Article 22 ban AI screening?** No, it restricts decisions based solely on automated processing that significantly affect someone, and being screened out of a job qualifies. The key word is solely: a system that ranks candidates for a human to review and decide on is not a solely automated decision, while one that auto-rejects with no human involvement is. Keep a meaningful human review before any rejection and Article 22 is satisfied.

**When does the EU AI Act apply to recruitment?** From 2 August 2026. Annex III, point 4(a) classifies AI used to analyse and filter job applications as high-risk, and Article 113 sets general application from that date; recruitment systems fall under it rather than the later 2027 product-safety deadline. Most duties sit with the provider that builds the tool, but employers must follow the instructions for use, assign competent oversight, and retain the logs.

**Who is responsible for AI screening compliance, the vendor or the employer?** Both, in different roles. The provider that builds the system carries the bulk of the AI Act duties: risk management, documentation, accuracy testing, and human oversight by design. The employer deploying it must use it according to instructions, assign oversight to competent people, keep the logs, inform candidates and workers, and hold a GDPR lawful basis for the processing. Compliance is shared, not delegated entirely to the vendor.

**What is the biggest legal risk with AI CV screening?** Letting the software decide alone. A rejection made solely by software, with no human involvement, is exactly the automated decision GDPR Article 22 restricts, and it also cuts against the human-oversight expectations of the EU AI Act for high-risk recruitment systems. The lawful pattern is a tool that ranks and explains while a person reviews the shortlist and the near-misses and makes every reject and hire decision themselves.

---

Source: https://zjcv.com/journal/is-ai-cv-screening-legal-in-the-eu/
Author: Zen Job CV Team
