AEPD (Spain) - PS/00009/2026
Spain's AEPD issues a warning over an AI tool used for hiring and promotions.
Summary
Spain's Data Protection Agency (AEPD) has issued a warning to a company regarding its implementation of an AI tool for screening and evaluating job candidates and internal mobility processes. The AI system analyzes resumes, assigns scores, and prioritizes candidates, potentially influencing employment and promotion decisions. The AEPD emphasized the controller's obligations for data protection by design and default, the need for risk assessments and Data Protection Impact Assessments (DPIAs) if high risks are identified, and the importance of transparency with data subjects regarding the tool's functioning and human intervention.
Full text
Help AEPD (Spain) - PS/00009/2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 14:28, 8 October 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators112 edits Tag: Decisions [1.0] (No difference) Latest revision as of 14:28, 8 October 2026 AEPD - PS/00009/2026 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 5(1)(a) GDPR Article 12 GDPR Article 13 GDPR Article 14 GDPR Article 22 GDPR Article 24 GDPR Article 25 GDPR Article 35 GDPR Type: Other Outcome: n/a Started: Decided: 23.09.2026 Published: Fine: n/a Parties: n/a National Case Number/Name: PS/00009/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Spanish Original Source: AEPD (in ES) Initial Contributor: sf The DPA issued a warning concerning the implementation by a controller of an AI tool intended to be used employment and promotion purposes. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA received a letter by an enterprise (the controller) who reported the implementation of an AI tool intended to be used for the screening and evaluation of candidates in recruitment and internal mobility processes. The system will seek to analyse resumes, assign scores and prioritise candidates which may have a direct influence on the decisions regarding employment and promotions. Clarified was that final decision was to be made by a human. The controller notified its employees of the implementation of this system in December. The DPA started an investigation. The controller clarified that it is part of a group of undertakings which is carrying out the evaluation and development of the system including compliance with data protection at a central level. Regardless, the controller emphasised it would analyse the established data protection implications and take appropriate measures prior to putting the system into operation. Holding Following the investigation, the DPA issued a warning to the controller. The DPA addressed the controller’s obligation to ensure data protection by design and default and to implement appropriate technical and organisational measures to ensure data protection compliant processing in accordance with Articles 24 and 25 GDPR. More specifically, the DPA addressed the necessity for a risk assessment posed by the system, and if the processing is likely to result in a high-risk, to also implement the necessary DPIA pursuant to Article 35 GDPR. Furthermore, the DPA warned of the principle of transparency in relation to data subjects and their rights. That means providing them clear, accessible and understandable information regarding their personal data and the way it is processed. In this regard the controller is to take into account the functioning off the tool, and degree of human intervention throughout the process. Particularly, the controller must assess the possibility of Article 22 GDPR application and corresponding necessary limitations and safeguards. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details. 1/5 Ref.: EXP202600427 Subject: Warning FIRST. - On January 6, 2026, the Spanish Data Protection Agency (AEPD) received a letter informing it of the implementation by ***ENTERPRISE.1 of an Artificial Intelligence tool called “***TOOL.1” intended for the screening and evaluation of candidates in recruitment and internal mobility processes. This would be a system for analyzing resumes, assigning scores, and prioritizing candidates, which could directly influence decisions regarding access to employment and professional advancement. According to information obtained by the AEPD, the enterprise notified the workers’ legal representatives on December 1, 2025, of the implementation of the system, stating that it is a support tool and that the final decision in these processes is always made by a human. SECOND. — On January 16, 2026, the Presidency of the Spanish Data Protection Authority agreed to initiate an investigation pursuant to the functions assigned to supervisory authorities under Article 57.1 and the powers granted under Article 58.1 of Regulation (EU) 2016/679 (the General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Article 67 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter, LOPDGDD). The following, in particular, can be inferred from these provisions: - ***GROUP.1, to which ***ENTERPRISE.1 belongs, is evaluating the implementation of an Artificial Intelligence tool called “***TOOL.1,” designed to screen and evaluate candidates in recruitment and internal mobility processes. - The tool has not yet been implemented in Spain. However, ***ENTERPRISE.1 informed its employees in December 2025, pursuant to the provisions of Article 64.4 of the Workers’ Statute, about its upcoming implementation in the selection and recruitment processes of ***ENTERPRISE.1 in Spain. - According to the information provided by ***ENTERPRISE.1: o The tool is intended to improve the efficiency, consistency, and objectivity of the initial evaluation of applicants. o It is also noted that the system provides a score based on how well applicants meet the requirements of the position, with the final decision to screen or reject applicants resting with a person. o It is also indicated that the system excludes the analysis of sensitive attributes and is subject to periodic audits. - Although the tool is not an initiative of ***ENTERPRISE.1 but rather of the group of undertakings to which it belongs—which is carrying out its development in a , as well as the analysis of the implications regarding data protection for personal data, ***ENTERPRISE.1 has confirmed that, once the C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 2/5 the group’s results, it will analyze them and, if necessary, take the appropriate measures before the tool is eventually put into operation. THIRD. - Article 55(1) of Regulation (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, GDPR) provides that “each supervisory authority shall be competent to carry out the tasks and exercise the powers assigned to it in accordance with this Regulation within the territory of its Member State.” Article 58(2) of the GDPR establishes that each supervisory authority shall have all the corrective powers listed below, including the power set forth in subparagraph (a) to issue a warning to any controller or processor where the processing is carried out planned processing operations may infringe the provisions of said Regulation. In accordance with Article 47 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter, LOPDGDD), the AEPD is responsible, among other powers, for exercising the powers provided for in Article 58 of the GDPR. FOURTH. — Furthermore, as is clear from the settled case law of the Court of Justice of the European Union, the objective of the GDPR (see, for example, paragraph 53 of the Judgement of the Court of Justice (Fourth Chamber) of March 7, 2024, C- 604/22) is to “ensure a high level of protection of the fundamental rights and freedoms of natural persons, in particular their right to private life in relation to the processing of personal data, as enshrined in Article 8, paragraph 1, of the CFR and in Article 16 TFEU, paragraph 1 [judgement of May 4, 2023, Bundesrepublik Deutschland (Electronic Judicial Mailbox), C-60/22, EU:C:2023:373, paragra