Start free trial of Lex HR →

EurEporter explains jobseeker rights under EU AI Act and GDPR

An EU explainer outlines how the AI Act and GDPR protect candidates: transparency duties, bans on emotion inference and rights to human review.

3 September 2026

EurEporter published an explainer on 2 September 2026 outlining what jobseekers in the EU can expect when employers use AI in recruitment, flagging legal protections under the EU AI Act and the GDPR.

The piece, dated 2 September, sets out three core protections it says candidates should rely on: firms must be transparent about automated tools used in hiring, certain uses — notably inferring emotional states — are barred, and candidates retain rights to human review of decisions made or assisted by AI.

Under the EU AI Act, systems used for recruitment are captured as high-risk where they influence people’s access to employment, the explainer says, triggering a suite of compliance duties for vendors and employers. Those duties include providing clear information about the AI system’s purpose and limitations and implementing human oversight measures to prevent erroneous or unfair outcomes. The law also introduces conformity assessments and documentation requirements designed to make high-risk tools auditable.

Separately, the GDPR continues to govern how personal data are processed in hiring. The explainer reminds candidates that the GDPR requires data controllers to give individuals meaningful information about automated processing, and preserves rights to object to or obtain review of decisions that have "legal" or "similarly significant" effects on them. It urges applicants to ask employers whether profiling or fully automated decision-making was used, and — where applicable — to request a human review of outcomes.

EurEporter highlights an explicit restriction that has particular relevance to talent technology: the AI Act places strict limits on systems that infer or classify emotional states when those inferences are used to evaluate people. The explainer frames this as a direct answer to vendors that market tools claiming to read candidate emotions in video interviews or on the basis of biometric cues.

For HR teams, the obligations mean more than new paperwork, the article notes. Transparency duties require employers to update privacy notices and candidate communications to explain when AI is in use and what role it plays in screening. Human oversight obligations are likely to force changes in how screening outputs are acted on — firms will need documented processes showing a human has reviewed or validated AI recommendations before adverse decisions are finalised.

The explainer places these legal obligations in a wider context: regulators across the EU have been sharpening scrutiny of hiring technologies after high-profile bias findings and consumer complaints, and the dual framework of the AI Act and the GDPR aims to combine systemic risk controls with individual access and remedy rights.

What the explainer does not settle is how enforcement will unfold in practice. It does not detail the timelines for conformity assessments for existing vendors, how national data protection authorities will coordinate cross-border investigations, or what burden of proof employers will face when defending the fairness of an AI screening tool. It also stops short of explaining how small and medium-sized employers should demonstrate compliance when they buy third-party applicant screening services.

The guidance nonetheless signals a shift that HR leaders cannot ignore: recruitment technologies will be legally framed as systems that require both technical safeguards and processes that uphold candidate rights. That will push talent teams to renegotiate contracts with vendors, tighten audit trails on automated decisions and make candidate-facing transparency part of standard hiring communications — a change that could reshape how early-stage screening is designed and explained to applicants across Europe.

Sources
  1. Jobseekers: know your rights in the age of AI hiring
  2. The European approach to artificial intelligence
  3. Regulation (EU) 2016/679 (General Data Protection Regulation)