
AI CV screening is allowed under European privacy law, but a person signing off at the end is not enough to make it safe. That is the message from Spain's data protection authority, the Agencia Española de Protección de Datos (AEPD), which on 23 September 2026 published a formal warning sent to a company that plans to use an AI tool to screen and score job applications. The company is not named, the tool is not yet in use, and the warning is preventive: it is not a finding that the law was broken. This article is general information, not legal advice.
What happened
The AEPD announced the step in a press note, La Agencia recuerda las garantías para utilizar IA en el análisis de currículums, and published the anonymised text of the warning (file reference EXP202600427).
According to the warning, the AEPD received a submission on 6 January 2026 about a company's plan to introduce an AI tool for screening and evaluating candidates in recruitment and internal moves. The system would analyse CVs, assign scores and prioritise candidates, so it could directly influence who gets a job or a promotion. The company had told its workers' legal representatives on 1 December 2025 that the tool was a support aid and that the final decision would always be made by a person.
The AEPD opened an investigation on 16 January 2026. It found that the tool is being developed centrally by the corporate group the company belongs to and had not yet been deployed in Spain. The company told the regulator the tool scores how well an application fits the job requirements, excludes sensitive attributes and is audited periodically. It also said it would review the group's data protection analysis and take any measures needed before switching the tool on.
The regulator then used a power in Article 58(2)(a) of the General Data Protection Regulation (GDPR), which lets a supervisory authority warn an organisation when planned processing may infringe the regulation. The press note stresses that a warning of this kind does not mean the recipient has committed an infringement.
Key details
| Safeguard | GDPR reference in the warning | What the AEPD told the company |
|---|---|---|
| Data protection by design and by default | Articles 24 and 25 | Build safeguards into the design, evaluation, selection, configuration and rollout of the tool, and be able to demonstrate compliance |
| Risk assessment | Article 35 | Assess the risks to candidates and workers; where the processing is likely to involve a high risk, carry out a data protection impact assessment before it starts |
| Transparency | Articles 12 to 14 | Give candidates and workers clear, accessible and understandable information about the purposes and about the role the tool plays in their evaluation |
| Automated decisions | Article 22 | Consider whether the right not to be subject to a solely automated decision applies, judged by how the decision process works in practice |
| Human involvement | Article 22 | It must be effective: the person must be able to weigh the score critically and decide without being bound in practice by the automated result |
The warning closes with a caution. If the company does not adopt the measures needed to bring the project into line with the law, it could commit an infringement, which could lead to further investigation or corrective action, including sanctions. It is signed by the AEPD's president, Lorenzo Cotino Hueso.
Why it matters
Three things stand out.
The regulator acted before the tool went live. The AEPD used its preventive power on a plan, not on an incident. The warning notes that its purpose is to draw attention to the risk so the organisation can adjust, not to punish.
"A human makes the final decision" was treated as a starting point. The company's assurance was noted as relevant, and then qualified. Put in practical terms, our reading is this: if a recruiter sees a ranked list and a score, has many applications to clear, and has no way to see why the tool scored someone low, the person is not really deciding.
The warning went to the local company, although head office is building the tool. The tool in this case is a group initiative, and the group is doing both the development and the data protection analysis. The AEPD still addressed its list of obligations to the company that would use the tool in its own recruitment in Spain.
The AEPD does not oppose the technology. The warning says AI tools can improve the efficiency and consistency of selection processes, and that the GDPR does not prevent their use but requires safeguards that match the risks. There is also a second layer coming: the European Commission's AI Act page lists employment among the high-risk areas whose rules apply from 2 December 2027. The Spanish warning shows that data protection law already reaches these tools today.
What this means for businesses
The warning is addressed to one company in Spain, and its reasoning rests on the GDPR, an EU regulation. If your business recruits people in the EU, or builds or sells recruitment software for customers there, ask an adviser whether and how the GDPR applies to you. For everyone else the warning is a sound checklist.
- Write down what the tool does. Does it parse, score, rank, shortlist or reject? Which of those outputs does a person see?
- Test the human review. The reviewer needs the time, the authority and the information to disagree with the score. If the tool's reasons are hidden from them, fix that before launch.
- Assess risk before you buy or switch on. Do the assessment first, record it, and do a full impact assessment where the risk is high.
- Tell candidates plainly. Say that a tool is used, what it is for and what part it plays in the assessment.
- Ask the vendor for evidence. What data does it use, which attributes are excluded, how is it audited and can you see the results?
- Do not rely on someone else's sign-off. A group or vendor assessment is an input to yours.
- Keep the records. You may be asked to show how a decision was reached.
Trust in candidate information is a wider theme in recruitment technology: Talent Tabloid, a recruitment and candidate verification platform, has human reviewers check employment records and qualifications. Where software scores a candidate, the AEPD's point is that the person deciding must be able to weigh that score critically.
Much of what the AEPD asks for is ordinary system design: showing a reviewer the evidence behind a score, logging who decided what, and sending candidates the right notice at the right step. We work with the recruitment industry on business systems and integrations and on custom software where an off-the-shelf product does not fit. If you are reviewing how your hiring tools handle candidate data, get in touch for a quote.
Key takeaways
- On 23 September 2026 Spain's AEPD published a preventive warning to an unnamed company planning an AI tool to screen and score job applications.
- The warning is not a fine or a finding of breach; the tool had not been deployed in Spain.
- The GDPR does not ban AI in recruitment, but it requires safeguards built in from the design stage, a risk assessment and clear information for candidates.
- Human review must be effective: the reviewer has to be able to assess the score critically and reach their own decision.
- The warning was addressed to the company that would use the tool in Spain, although its corporate group is developing it.
Frequently asked questions
Did the AEPD fine the company for using AI to screen CVs?
No. It issued a warning under Article 58(2)(a) of the GDPR, a preventive measure for planned processing that may infringe the regulation. The AEPD states that this does not mean an infringement has been committed.
Does the GDPR ban AI CV screening?
No. The warning says the GDPR does not prevent the use of these technologies in selection processes. It requires that the processing of personal data is carried out with safeguards suited to its characteristics and risks.
What counts as effective human review of an AI score?
The AEPD says human involvement must allow the person to assess the system's information or score critically and take the decision without being determined in practice by the automated result.
When is a data protection impact assessment needed for a hiring tool?
Under Article 35 of the GDPR, as applied in the warning, an impact assessment must be done before processing begins where the processing is likely to result in a high risk to people's rights and freedoms.
Does this affect Australian employers and recruiters?
The warning is addressed to one company in Spain. Australian businesses that recruit in the EU or supply recruitment software to EU customers should ask an adviser whether and how the GDPR applies to them. For others it is a practical standard for using AI fairly in hiring.