← Back to analysis
Data protectionJuly 11, 20264 min read

‘Hired by an algorithm’: the AI Act does not free you from the GDPR

The EDPS and the EDPB put the spotlight on AI in hiring. The underlying reminder: over the same system the AI Act and the GDPR coexist, and one does not replace the other.

On 9 July 2026, the European Data Protection Supervisor (EDPS), together with the European Data Protection Board (EDPB), devoted an event to the growing role of AI in human resources, under a title that captures the moment well: "Hired by an algorithm". The focus was explicit: CV screening, video interview analysis and performance prediction. The signal for the sector is clear: the AI Act regulator is not the only one watching AI in hiring.

Two frameworks over the same system

Most employment and people-management tools (recruitment, screening and ranking of candidates, promotion, performance evaluation) are classified as high-risk under the AI Act, precisely because they directly affect people's livelihood. But that framing does not displace the General Data Protection Regulation: the GDPR applies fully in parallel, over the same system and the same data.

In practice, that means attending at the same time to a set of requirements that do not come from the AI Act:

  • The processing of candidates' personal data, with its corresponding legal basis.
  • The regime for automated individual decisions under Article 22 of the GDPR.
  • The data protection impact assessment (DPIA) where applicable.
  • The transparency and information duties towards the affected person.

Two regimes, and in Spain two authorities

The overlap is not theoretical. In Spain two authorities coexist over the same product: AESIA for the AI Act and the AEPD for data protection. Complying with one does not exempt you from the other, and an answer designed only for the AI Act leaves the GDPR front exposed, which is precisely the one with the longest enforcement track record. The good news is that much of the groundwork serves both.