[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fF3rnOQzmSxKfpszm-MEqzY1-mveKgkfoTCNn4tCPYyY":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"9881253e-d2e2-46c6-846c-75a7d1007ae0","AEPD (Spain) - PS\u002F00009\u002F2026","aepd-spain-ps-00009-2026-d1bad4","Created page with \"{{DPAdecisionBOX |Jurisdiction=Spain |DPA-BG-Color= |DPAlogo=LogoES.jpg |DPA_Abbrevation=AEPD |DPA_With_Country=AEPD (Spain) |Case_Number_Name=PS\u002F00009\u002F2026 |ECLI= |Original_Source_Name_1=AEPD |Original_Source_Link_1=https:\u002F\u002Fwww.aepd.es\u002Fdocumento\u002Fai-00009-2026-advertencia.pdf |Original_Source_Language_1=Spanish |Original_Source_Language__Code_1=ES |Original_Source_Name_2= |Original_Source_Link_2= |Original_Source_Language_2= |Original_Source_Language__Code_2= |Typ...\" New page {{DPAdecisionBOX |Jurisdiction=Spain |DPA-BG-Color= |DPAlogo=LogoES.jpg |DPA_Abbrevation=AEPD |DPA_With_Country=AEPD (Spain) |Case_Number_Name=PS\u002F00009\u002F2026 |ECLI= |Original_Source_Name_1=AEPD |Original_Source_Link_1=https:\u002F\u002Fwww.aepd.es\u002Fdocumento\u002Fai-00009-2026-advertencia.pdf |Original_Source_Language_1=Spanish |Original_Source_Language__Code_1=ES |Original_Source_Name_2= |Original_Source_Link_2= |Original_Source_Language_2= |Original_Source_Language__Code_2= |Type=Other |Outcome= |Date_Started= |Date_Decided=23.09.2026 |Date_Published= |Year=2026 |Fine= |Currency= |GDPR_Article_1=Article 5(1)(a) GDPR |GDPR_Article_Link_1=Article 5 GDPR#1a |GDPR_Article_2=Article 12 GDPR |GDPR_Article_Link_2=Article 12 GDPR |GDPR_Article_3=Article 13 GDPR |GDPR_Article_Link_3=Article 13 GDPR |GDPR_Article_4=Article 14 GDPR |GDPR_Article_Link_4=Article 14 GDPR |GDPR_Article_5=Article 22 GDPR |GDPR_Article_Link_5=Article 22 GDPR |GDPR_Article_6=Article 24 GDPR |GDPR_Article_Link_6=Article 24 GDPR |GDPR_Article_7=Article 25 GDPR |GDPR_Article_Link_7=Article 25 GDPR |GDPR_Article_8=Article 35 GDPR |GDPR_Article_Link_8=Article 35 GDPR |GDPR_Article_9= |GDPR_Article_Link_9= |GDPR_Article_10= |GDPR_Article_Link_10= |EU_Law_Name_1= |EU_Law_Link_1= |EU_Law_Name_2= |EU_Law_Link_2= |National_Law_Name_1= |National_Law_Link_1= |National_Law_Name_2= |National_Law_Link_2= |Party_Name_1= |Party_Link_1= |Party_Name_2= |Party_Link_2= |Appeal_To_Body= |Appeal_To_Case_Number_Name= |Appeal_To_Status= |Appeal_To_Link= |Initial_Contributor=sf | }} The DPA issued a warning concerning the implementation by a controller of an AI tool intended to be used employment and promotion purposes. == English Summary == === Facts === The DPA received a letter by an enterprise (the controller) who reported the implementation of an AI tool intended to be used for the screening and evaluation of candidates in recruitment and internal mobility processes. The system will seek to analyse resumes, assign scores and prioritise candidates which may have a direct influence on the decisions regarding employment and promotions. Clarified was that final decision was to be made by a human. The controller notified its employees of the implementation of this system in December. The DPA started an investigation. The controller clarified that it is part of a group of undertakings which is carrying out the evaluation and development of the system including compliance with data protection at a central level. Regardless, the controller emphasised it would analyse the established data protection implications and take appropriate measures prior to putting the system into operation. === Holding === Following the investigation, the DPA issued a warning to the controller. The DPA addressed the controller’s obligation to ensure data protection by design and default and to implement appropriate technical and organisational measures to ensure data protection compliant processing in accordance with Articles 24 and 25 GDPR. More specifically, the DPA addressed the necessity for a risk assessment posed by the system, and if the processing is likely to result in a high-risk, to also implement the necessary DPIA pursuant to [[Article 35 GDPR|Article 35 GDPR]]. Furthermore, the DPA warned of the principle of transparency in relation to data subjects and their rights. That means providing them clear, accessible and understandable information regarding their personal data and the way it is processed. In this regard the controller is to take into account the functioning off the tool, and degree of human intervention throughout the process. Particularly, the controller must assess the possibility of [[Article 22 GDPR|Article 22 GDPR]] application and corresponding necessary limitations and safeguards. == Comment == ''Share your comments here!'' == Further Resources == ''Share blogs or news articles here!'' == English Machine Translation of the Decision == The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details. 1\u002F5  Ref.: EXP202600427 Subject: Warning FIRST. - On January 6, 2026, the Spanish Data Protection Agency (AEPD) received a letter informing it of the implementation by ***ENTERPRISE.1 of an Artificial Intelligence tool called “***TOOL.1” intended for the screening and evaluation of candidates in recruitment and internal mobility processes. This would be a system for analyzing resumes, assigning scores, and prioritizing candidates, which could directly influence decisions regarding access to employment and professional advancement. According to information obtained by the AEPD, the enterprise notified the workers’ legal representatives on December 1, 2025, of the implementation of the system, stating that it is a support tool and that the final decision in these processes is always made by a human. SECOND. — On January 16, 2026, the Presidency of the Spanish Data Protection Authority agreed to initiate an investigation pursuant to the functions assigned to supervisory authorities under Article 57.1 and the powers granted under Article 58.1 of Regulation (EU) 2016\u002F679 (the General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Article 67 of Organic Law 3\u002F2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter, LOPDGDD). The following, in particular, can be inferred from these provisions: - ***GROUP.1, to which ***ENTERPRISE.1 belongs, is evaluating the implementation of an Artificial Intelligence tool called “***TOOL.1,” designed to screen and evaluate candidates in recruitment and internal mobility processes. - The tool has not yet been implemented in Spain. However, ***ENTERPRISE.1 informed its employees in December 2025, pursuant to the provisions of Article 64.4 of the Workers’ Statute, about its upcoming implementation in the selection and recruitment processes of ***ENTERPRISE.1 in Spain. - According to the information provided by ***ENTERPRISE.1: o The tool is intended to improve the efficiency, consistency, and objectivity of the initial evaluation of applicants. o It is also noted that the system provides a score based on how well applicants meet the requirements of the position, with the final decision to screen or reject applicants resting with a person. o It is also indicated that the system excludes the analysis of sensitive attributes and is subject to periodic audits. - Although the tool is not an initiative of ***ENTERPRISE.1 but rather of the group of undertakings to which it belongs—which is carrying out its development in a , as well as the analysis of the implications regarding data protection for personal data, ***ENTERPRISE.1 has confirmed that, once the C\u002F Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 2\u002F5 the group’s results, it will analyze them and, if necessary, take the appropriate measures before the tool is eventually put into operation. THIRD. - Article 55(1) of Regulation (EU) 2016\u002F679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, GDPR) provides that “each supervisory authority shall be competent to carry out the tasks and exercise the powers assigned to it in accordance with this Regulation within the territory of its Member State.” Article 58(2) of the GDPR establishes that each supervisory authority shall have all the corrective powers listed below, including the power set forth in subparagraph (a) to issue a warning to any controller or processor where the processing is carried out planned processing operations may infringe the provisions of said Regulation. In accordance with Article 47 of Organic Law 3\u002F2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter, LOPDGDD), the AEPD is responsible, among other powers, for exercising the powers provided for in Article 58 of the GDPR. FOURTH. — Furthermore, as is clear from the settled case law of the Court of Justice of the European Union, the objective of the GDPR (see, for example, paragraph 53 of the Judgement of the Court of Justice (Fourth Chamber) of March 7, 2024, C- 604\u002F22) is to “ensure a high level of protection of the fundamental rights and freedoms of natural persons, in particular their right to private life in relation to the processing of personal data, as enshrined in Article 8, paragraph 1, of the CFR and in Article 16 TFEU, paragraph 1 [judgement of May 4, 2023, Bundesrepublik Deutschland (Electronic Judicial Mailbox), C-60\u002F22, EU:C:2023:373, paragraph 64].” Consequently, the corrective powers and authority of supervisory authorities must be interpreted broadly. See, by analogy, paragraph 37 of the judgement of the Court of Justice of September 26, 2024, C-768\u002F21. FIFTH. — Furthermore, it should not be forgotten that among the powers established by the GDPR for supervisory authorities there is also a “precautionary” or “preventive” role. Thus, for example, paragraph 188 of the Opinion of Lawyer Dean Spielmann, dated September 23, 2025, in Case C-474\u002F24 states: 188. (…) Article 58(2) of the aforementioned Regulation lists the various corrective powers available to the supervisory authority, which enjoys, in this regard, a margin of discretion with respect to the selection of appropriate and necessary measures. (112) Among the powers of the supervisory authority set forth in Article 58(2)(a) of the GDPR, it may issue a “warning” to any controller when the “intended” processing operations “may” infringe the provisions of the GDPR, which is part of an approach that can be described as “precautionary” with respect to the data subject rights. (113) C\u002F Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 3\u002F5 SIXTH.—Furthermore, this precautionary or preventive power granted by the GDPR to supervisory authorities is expressed in broad terms in Art. 58(2)(a) of the GDPR, such that this provision has granted supervisory authorities the power to issue any controller or processor a warning, not necessarily when it has verified that the processing is contrary to the GDPR, but when the planned processing operations may infringe the provisions of this Regulation. The use of the term “may” is part of this precautionary or preventive function, which must be understood—when the supervisory authority decides to issue a warning, not as an established fact that such processing operations actually violate the GDPR, but rather that there is a possibility (as opposed to certainty) that such operations may violate the Regulation. Therefore, in exercising this precautionary function, the supervisory authority may, on the basis of the information received—and even information it has not received—issue a warning to the controller or processor regarding the possibility that such data processing operations may infringe the Regulation, so that the controller or processor may draw the appropriate lessons or guidelines from said warning and, in accordance with their obligation of proactive accountability, may adapt such data processing operations to comply with the Regulation. Finally, it cannot be ruled out that the information available to the supervisory authority may be incomplete, for whatever reason. This will not diminish the effectiveness of its warning—and therefore the Regulation’s objective of protecting data subjects—since since the purpose of the warning is not to sanction conduct by the controller or processor, but rather to warn (that is, to draw the attention of the controller or processor) that certain processing operations could infringe the Regulation, without the need for certainty that such processing operations violate the GDPR. SEVENTH. — Based on the information obtained as a result of the preliminary investigative actions carried out, this Authority makes the following observations: The incorporation of artificial intelligence tools into recruitment and human resources management processes can offer opportunities to improve their efficiency and consistency and provide support tools for evaluating candidates. Furthermore, when properly designed and used, these tools can help improve the effectiveness and quality of certain data processing operations and of the inferences derived from them. The GDPR does not prohibit the use of these technologies in such processes, but rather requires that the processing of personal data they involve be carried out with safeguards appropriate to their characteristics and risks. From this perspective, it is advisable to integrate these safeguards into the very process of designing, evaluating, selecting, configuring, and implementing the tool. This approach ensures that the development and adoption of innovative solutions can take place in a responsible manner, capitalizing on their potential benefits while preserving the rights and freedoms of candidates and employees. 6 Jorge Juan St. www.aepd.es 28001 – Madrid sedeaepd.gob.es 4\u002F5 This vision is reflected, in particular, through data protection by design and by default as provided for in Article 25 of the GDPR, which requires the effective integration of data protection principles and safeguards both when determining the means of processing and during its execution. Integrating data protection requirements from the initial phases of a technology project makes it possible to identify the risks associated with processing and to adopt the appropriate measures to manage them. Risk management is, therefore, an inherent element of the proactive accountability system and must accompany processing throughout its lifecycle. In cases where, given the nature, scope, context, or purpose of the processing, it is likely to result in a high risk to the rights and freedoms of natural persons, , a data protection impact assessment must be conducted prior to processing, in accordance with the terms set forth in Article 35 of the GDPR. In the case under review, the use of a tool designed to evaluate job applications and assign a score based on their suitability for a specific position makes it particularly important to ensure the principle of transparency with respect to the data subjects. In accordance with Articles 12 through 14 of the GDPR, candidates and employees must receive clear, accessible, and understandable information regarding the processing of their personal data and, in particular, regarding the purposes of such processing and the role the tool plays in the evaluation process, to the extent required in each case. When the conditions regarding the existence of automated decision-making referred to in Article 22 of the GDPR are met, the specific information obligations set forth in Articles 13(2)(f) and 14(2)(g) of the Regulation shall also apply. Furthermore, Article 22 of the GDPR recognizes the data subject’s right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning him or her or similarly significantly affects him or her, without prejudice to the exceptions and safeguards set forth in that provision itself. In this regard, the fact stated by ***ENTERPRISE.1 that the final decision is made by a person constitutes a relevant factor in assessing the functioning of the processing. Human intervention must be effective, in such a way as to allow for a critical assessment of the information or score provided by the system and to make the corresponding decision without being de facto determined by the automated result. The specific application of Article 22 must therefore be assessed based on the actual functioning of the decision-making process. In light of the foregoing, and in accordance with the powers granted to it under Article 58.2.a) of the GDPR, this Agency hereby issues the following WARNING to ***ENTERPRISE.1: - In the process of evaluating and implementing an artificial intelligence tool intended for the screening and evaluation of candidates in recruitment and internal mobility processes, ***ENTERPRISE.1 must comply with its data protection obligations by design and by default and adopt, in accordance with Articles 24 and 25 of the GDPR, the C\u002F Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 5\u002F5 appropriate technical and organizational measures to ensure and be able to demonstrate that the processing complies with personal data protection regulations. In particular, it must assess the risks that the processing may pose to the rights and freedoms of candidates and employees and, when the processing is likely to result in a high risk as defined in Article 35 of the GDPR, conduct the corresponding data protection impact assessment prior to processing. Furthermore, compliance with the principle of transparency with respect to the data subjects and, taking into account the actual operation of the tool and the degree of human intervention in the decision-making process, assess the possible application of Article 22 of the GDPR and, where applicable, comply with the limitations and safeguards provided for in that article. Finally, it should be noted that, should the necessary measures not be adopted— as may be required—to bring its actions into compliance with legal requirements, you could be committing a violation within this Agency’s jurisdiction, which could lead to the initiation of preliminary investigative proceedings and\u002For corrective actions, including sanctions. Lorenzo Cotino Hueso President of the Spanish Data Protection Agency C\u002F Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es","Spain's Data Protection Agency (AEPD) has issued a warning to a company regarding its implementation of an AI tool for screening and evaluating job candidates and internal mobility processes. The AI system analyzes resumes, assigns scores, and prioritizes candidates, potentially influencing employment and promotion decisions. The AEPD emphasized the controller's obligations for data protection by design and default, the need for risk assessments and Data Protection Impact Assessments (DPIAs) if high risks are identified, and the importance of transparency with data subjects regarding the tool's functioning and human intervention.","Spain's AEPD issues a warning over an AI tool used for hiring and promotions.","Help AEPD (Spain) - PS\u002F00009\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 14:28, 8 October 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators112 edits Tag: Decisions [1.0] (No difference) Latest revision as of 14:28, 8 October 2026 AEPD - PS\u002F00009\u002F2026 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 5(1)(a) GDPR Article 12 GDPR Article 13 GDPR Article 14 GDPR Article 22 GDPR Article 24 GDPR Article 25 GDPR Article 35 GDPR Type: Other Outcome: n\u002Fa Started: Decided: 23.09.2026 Published: Fine: n\u002Fa Parties: n\u002Fa National Case Number\u002FName: PS\u002F00009\u002F2026 European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Spanish Original Source: AEPD (in ES) Initial Contributor: sf The DPA issued a warning concerning the implementation by a controller of an AI tool intended to be used employment and promotion purposes. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA received a letter by an enterprise (the controller) who reported the implementation of an AI tool intended to be used for the screening and evaluation of candidates in recruitment and internal mobility processes. The system will seek to analyse resumes, assign scores and prioritise candidates which may have a direct influence on the decisions regarding employment and promotions. Clarified was that final decision was to be made by a human. The controller notified its employees of the implementation of this system in December. The DPA started an investigation. The controller clarified that it is part of a group of undertakings which is carrying out the evaluation and development of the system including compliance with data protection at a central level. Regardless, the controller emphasised it would analyse the established data protection implications and take appropriate measures prior to putting the system into operation. Holding Following the investigation, the DPA issued a warning to the controller. The DPA addressed the controller’s obligation to ensure data protection by design and default and to implement appropriate technical and organisational measures to ensure data protection compliant processing in accordance with Articles 24 and 25 GDPR. More specifically, the DPA addressed the necessity for a risk assessment posed by the system, and if the processing is likely to result in a high-risk, to also implement the necessary DPIA pursuant to Article 35 GDPR. Furthermore, the DPA warned of the principle of transparency in relation to data subjects and their rights. That means providing them clear, accessible and understandable information regarding their personal data and the way it is processed. In this regard the controller is to take into account the functioning off the tool, and degree of human intervention throughout the process. Particularly, the controller must assess the possibility of Article 22 GDPR application and corresponding necessary limitations and safeguards. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details. 1\u002F5  Ref.: EXP202600427 Subject: Warning FIRST. - On January 6, 2026, the Spanish Data Protection Agency (AEPD) received a letter informing it of the implementation by ***ENTERPRISE.1 of an Artificial Intelligence tool called “***TOOL.1” intended for the screening and evaluation of candidates in recruitment and internal mobility processes. This would be a system for analyzing resumes, assigning scores, and prioritizing candidates, which could directly influence decisions regarding access to employment and professional advancement. According to information obtained by the AEPD, the enterprise notified the workers’ legal representatives on December 1, 2025, of the implementation of the system, stating that it is a support tool and that the final decision in these processes is always made by a human. SECOND. — On January 16, 2026, the Presidency of the Spanish Data Protection Authority agreed to initiate an investigation pursuant to the functions assigned to supervisory authorities under Article 57.1 and the powers granted under Article 58.1 of Regulation (EU) 2016\u002F679 (the General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Article 67 of Organic Law 3\u002F2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter, LOPDGDD). The following, in particular, can be inferred from these provisions: - ***GROUP.1, to which ***ENTERPRISE.1 belongs, is evaluating the implementation of an Artificial Intelligence tool called “***TOOL.1,” designed to screen and evaluate candidates in recruitment and internal mobility processes. - The tool has not yet been implemented in Spain. However, ***ENTERPRISE.1 informed its employees in December 2025, pursuant to the provisions of Article 64.4 of the Workers’ Statute, about its upcoming implementation in the selection and recruitment processes of ***ENTERPRISE.1 in Spain. - According to the information provided by ***ENTERPRISE.1: o The tool is intended to improve the efficiency, consistency, and objectivity of the initial evaluation of applicants. o It is also noted that the system provides a score based on how well applicants meet the requirements of the position, with the final decision to screen or reject applicants resting with a person. o It is also indicated that the system excludes the analysis of sensitive attributes and is subject to periodic audits. - Although the tool is not an initiative of ***ENTERPRISE.1 but rather of the group of undertakings to which it belongs—which is carrying out its development in a , as well as the analysis of the implications regarding data protection for personal data, ***ENTERPRISE.1 has confirmed that, once the C\u002F Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 2\u002F5 the group’s results, it will analyze them and, if necessary, take the appropriate measures before the tool is eventually put into operation. THIRD. - Article 55(1) of Regulation (EU) 2016\u002F679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, GDPR) provides that “each supervisory authority shall be competent to carry out the tasks and exercise the powers assigned to it in accordance with this Regulation within the territory of its Member State.” Article 58(2) of the GDPR establishes that each supervisory authority shall have all the corrective powers listed below, including the power set forth in subparagraph (a) to issue a warning to any controller or processor where the processing is carried out planned processing operations may infringe the provisions of said Regulation. In accordance with Article 47 of Organic Law 3\u002F2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter, LOPDGDD), the AEPD is responsible, among other powers, for exercising the powers provided for in Article 58 of the GDPR. FOURTH. — Furthermore, as is clear from the settled case law of the Court of Justice of the European Union, the objective of the GDPR (see, for example, paragraph 53 of the Judgement of the Court of Justice (Fourth Chamber) of March 7, 2024, C- 604\u002F22) is to “ensure a high level of protection of the fundamental rights and freedoms of natural persons, in particular their right to private life in relation to the processing of personal data, as enshrined in Article 8, paragraph 1, of the CFR and in Article 16 TFEU, paragraph 1 [judgement of May 4, 2023, Bundesrepublik Deutschland (Electronic Judicial Mailbox), C-60\u002F22, EU:C:2023:373, paragra","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_PS\u002F00009\u002F2026&diff=53351&oldid=0","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F5\u002F59\u002FLogoES.jpg","2026-10-08T14:28:59+00:00","2026-10-08T16:00:40.570246+00:00",7,[18,21],{"name":19,"type":20},"AI tool","product",{"name":22,"type":23},"AEPD","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":24,"icon":26,"name":27,"slug":28},null,"Policy","policy",[30,35,40,45],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":41},{"id":42,"icon":26,"name":43,"slug":44},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":46},{"id":24,"icon":26,"name":27,"slug":28},[]]