GDPR AI — HR Screening Agent (hr-screening-agent) — assessed 5/3/2026
GDPR AI Processing compliance: Partial Compliance (41%). DPIA has not been completed — this is likely required for AI processing of personal data. Automated decision-making with significant effects detected — Article 22 safeguards required.
Category: Partial Compliance
Assessment Inputs
Remediation Items (7)
Establish Lawful Basis for AI Processing
criticalDocument and validate the lawful basis under Article 6 for all personal data processing by this AI system.
Implement Data Minimization for AI
highEnsure only necessary personal data is used in AI training and inference.
Complete Data Protection Impact Assessment
criticalConduct a DPIA for this AI system's processing of personal data.
Implement Article 22 Safeguards
criticalEnsure safeguards for automated decision-making with legal or significant effects.
Enable Right to Explanation for AI Decisions
highProvide meaningful information about the logic of AI-driven decisions.
Support Data Subject Rights for AI Processing
highImplement mechanisms for access, erasure, and portability in the AI context.
Define AI Data Retention Policies
mediumEstablish and enforce retention periods for AI training data, inference logs, and model artifacts.
Discussion
Review
This action plan is generated based on GDPR AI Processing Assessment requirements. It should be reviewed by your legal and compliance team. For definitive guidance, consult the official GDPR AI documentation.