For customers carrying out a Data Protection Impact Assessment under Article 35 GDPR. Provider: AMISCON GLOBAL S.L. Last updated 19 August 2026.
The DPIA is the customer's, because the customer is the controller. This pack supplies the facts about the platform that the assessment needs, so nobody has to reverse-engineer them.
In Spain, the AEPD's Article 35(4) list requires a DPIA when two or more of its criteria are met. An AI-assisted hiring process typically meets at least:
Often also criterion 4 (data allowing inference of special categories), criterion 7 (large scale) and criterion 8 (combining datasets).
Other supervisory authorities publish similar lists. Recruitment scoring appears on most of them.
Nature. Automated analysis of application material to produce advisory scores, summaries and rankings that a human hiring team acts on.
Scope. Applicants to the customer's vacancies. Volume is the customer's own figure.
Context. Employment. There is an inherent power imbalance between applicant and employer, which is why consent is usually a weak legal basis here and why the EDPB and Article 29 Working Party have said so repeatedly.
Purposes. Screening, ranking, assessing answers, transcription for assessment, semantic search over the talent pool, and where enabled, automated progression through pipeline stages.
| Category | Source | Reaches the model |
|---|---|---|
| Name, email, phone | Applicant | Name yes, contact details no |
| CV text | Applicant upload | Yes |
| Skills, seniority, years of experience | Derived from CV | Yes |
| City, country | Applicant or CV | Yes |
| Interview answers, transcripts | Applicant | Yes |
| Call recordings | Voice interview | Converted to text; audio to the transcription engine only |
| Vacancy text | Customer | Yes |
Special categories are not collected as structured fields. Where an applicant's free text contains them, that text reaches the model as part of the document.
Points an assessment usually has to address, with the platform's position:
The customer decides. In practice:
Article 22 is the one to think hardest about. Where a score is relied on heavily, C-634/21 (SCHUFA) indicates the score itself can be the decision, even if a person formally signs it off. This is why automated rejection is off by default and produces a proposal for human confirmation.
| Risk | Mitigation in the platform | What the customer must add |
|---|---|---|
| Discriminatory outcome | Prompts exclude name, gender, age, origin, employment gaps; controlled-comparison bias testing before every model change | Do not put protected characteristics in vacancy text; monitor your own outcomes |
| Decision with no meaningful human involvement | Automated rejection off by default; proposals require confirmation; the reviewer is recorded | Assign reviewers with authority and enough time per decision |
| Opacity to the applicant | Notice before interview and at application; token-based explanation page; decision log | Answer review requests; name a contact |
| Excessive retention | Automatic deletion on a daily schedule; erasure clears transcripts, AI analyses, embeddings and vectors | Set retention to your own policy |
| Inaccurate inference | Scores are advisory; every score links to the evidence | Train reviewers on automation bias |
| Unauthorised access | Tenant isolation, role-based access, audit logging | Manage your own user access |
| International transfer | EU storage; SCCs plus transfer impact assessment for model processing; EU-resident inference in progress | Record the transfer in your Article 30 register |
| Data | Default |
|---|---|
| Call recordings | 180 days |
| Interview media and transcripts | 365 days after the application closes |
| Rejected candidate records | 365 days, then anonymised |
| Inactive candidate records | 730 days |
| AI assistant conversations | 90 days |
| Audit logs | 3 years |
| AI decision logs | 12 months |
| After consent expiry or withdrawal | 30 days, then anonymised |
| Right | How |
|---|---|
| Access (Art. 15) | Token-based export including AI scores, analyses, transcripts and decision history |
| Explanation (Art. 15(1)(h), Art. 86 AI Act) | Decision page showing inputs used, factors, and every AI step |
| Rectification (Art. 16) | Through the customer |
| Erasure (Art. 17) | Request through the token page; execution clears AI artifacts and vectors, not only the profile row |
| Portability (Art. 20) | Structured JSON export |
| Object / human intervention (Art. 21, 22) | Human review request from the decision page, routed to the customer |
Article 36 requires prior consultation with the supervisory authority only where a DPIA indicates a high residual risk that the controller cannot mitigate. With automated rejection off and human review in place, residual risk is normally manageable without consultation. A customer that enables fully automated rejection should reassess that conclusion.
Instructions for Use, sub-processor list, bias audit summary, decision log export for any candidate, DPA with Standard Contractual Clauses, and a written statement that no feature infers emotions from biometric data.