HRBlade
Compliance documents
Data protection impact assessment support
The facts about the platform a controller needs to carry out its own assessment under Article 35 GDPR.

For customers carrying out a Data Protection Impact Assessment under Article 35 GDPR. Provider: AMISCON GLOBAL S.L. Last updated 19 August 2026.

The DPIA is the customer's, because the customer is the controller. This pack supplies the facts about the platform that the assessment needs, so nobody has to reverse-engineer them.

1. A DPIA is almost certainly mandatory here

In Spain, the AEPD's Article 35(4) list requires a DPIA when two or more of its criteria are met. An AI-assisted hiring process typically meets at least:

  • Criterion 1, evaluation or scoring, including profiling and prediction, expressly covering assessment of performance at work;
  • Criterion 2, decisions that are automated or that contribute to a large degree to such decisions, including access to a contract;
  • Criterion 10, innovative use of technology.

Often also criterion 4 (data allowing inference of special categories), criterion 7 (large scale) and criterion 8 (combining datasets).

Other supervisory authorities publish similar lists. Recruitment scoring appears on most of them.

2. Description of the processing

Nature. Automated analysis of application material to produce advisory scores, summaries and rankings that a human hiring team acts on.

Scope. Applicants to the customer's vacancies. Volume is the customer's own figure.

Context. Employment. There is an inherent power imbalance between applicant and employer, which is why consent is usually a weak legal basis here and why the EDPB and Article 29 Working Party have said so repeatedly.

Purposes. Screening, ranking, assessing answers, transcription for assessment, semantic search over the talent pool, and where enabled, automated progression through pipeline stages.

3. Data categories

CategorySourceReaches the model
Name, email, phoneApplicantName yes, contact details no
CV textApplicant uploadYes
Skills, seniority, years of experienceDerived from CVYes
City, countryApplicant or CVYes
Interview answers, transcriptsApplicantYes
Call recordingsVoice interviewConverted to text; audio to the transcription engine only
Vacancy textCustomerYes

Special categories are not collected as structured fields. Where an applicant's free text contains them, that text reaches the model as part of the document.

4. Necessity and proportionality

Points an assessment usually has to address, with the platform's position:

  • Could the purpose be achieved less intrusively? Scoring assists rather than replaces review. The customer can run the platform with every AI feature off and still operate a full applicant tracking process, which is the honest baseline for a necessity test.
  • Is the data minimised? The platform does not request demographic data. The customer controls which profile fields are mandatory in the application form.
  • Is retention limited? Yes, with defaults listed in section 7, all configurable.

5. Lawful basis

The customer decides. In practice:

  • Article 6(1)(b), steps at the request of the data subject prior to entering a contract, covers core processing of an application.
  • Article 6(1)(f), legitimate interests, is commonly used for the assessment itself, with a documented balancing test.
  • Consent is fragile in this context because of the power imbalance. Where a customer relies on it for talent-pool retention, it must be separable from applying for the role.
  • Article 9(2) would be needed for any special-category processing. The platform is not designed to process special categories and customers should not configure it to.

Article 22 is the one to think hardest about. Where a score is relied on heavily, C-634/21 (SCHUFA) indicates the score itself can be the decision, even if a person formally signs it off. This is why automated rejection is off by default and produces a proposal for human confirmation.

6. Risks to data subjects, and what the platform does about them

RiskMitigation in the platformWhat the customer must add
Discriminatory outcomePrompts exclude name, gender, age, origin, employment gaps; controlled-comparison bias testing before every model changeDo not put protected characteristics in vacancy text; monitor your own outcomes
Decision with no meaningful human involvementAutomated rejection off by default; proposals require confirmation; the reviewer is recordedAssign reviewers with authority and enough time per decision
Opacity to the applicantNotice before interview and at application; token-based explanation page; decision logAnswer review requests; name a contact
Excessive retentionAutomatic deletion on a daily schedule; erasure clears transcripts, AI analyses, embeddings and vectorsSet retention to your own policy
Inaccurate inferenceScores are advisory; every score links to the evidenceTrain reviewers on automation bias
Unauthorised accessTenant isolation, role-based access, audit loggingManage your own user access
International transferEU storage; SCCs plus transfer impact assessment for model processing; EU-resident inference in progressRecord the transfer in your Article 30 register

7. Retention defaults

DataDefault
Call recordings180 days
Interview media and transcripts365 days after the application closes
Rejected candidate records365 days, then anonymised
Inactive candidate records730 days
AI assistant conversations90 days
Audit logs3 years
AI decision logs12 months
After consent expiry or withdrawal30 days, then anonymised

8. Data subject rights, and how they are served

RightHow
Access (Art. 15)Token-based export including AI scores, analyses, transcripts and decision history
Explanation (Art. 15(1)(h), Art. 86 AI Act)Decision page showing inputs used, factors, and every AI step
Rectification (Art. 16)Through the customer
Erasure (Art. 17)Request through the token page; execution clears AI artifacts and vectors, not only the profile row
Portability (Art. 20)Structured JSON export
Object / human intervention (Art. 21, 22)Human review request from the decision page, routed to the customer

9. Consultation

Article 36 requires prior consultation with the supervisory authority only where a DPIA indicates a high residual risk that the controller cannot mitigate. With automated rejection off and human review in place, residual risk is normally manageable without consultation. A customer that enables fully automated rejection should reassess that conclusion.

10. What we will supply on request

Instructions for Use, sub-processor list, bias audit summary, decision log export for any candidate, DPA with Standard Contractual Clauses, and a written statement that no feature infers emotions from biometric data.