Skip to content
HR & Recruitment calendar_today Updated: 28 August 2026 schedule 5 min read

Can AI Automatically Reject a Job Applicant?

verified Last reviewed 31 August 2026 · GDPRWise legal team

Article 22 GDPR is a prohibition in principle, not a right candidates have to invoke. What that means before you switch on automated rejection.

summarize Key Takeaways
  • check_circle Article 22 is a prohibition in principle: you need an exception before you deploy, not after a candidate complains
  • check_circle A human who clicks confirm without real authority does not take the decision outside Article 22
  • check_circle An AI score that in practice determines the outcome can be the automated decision, even with a human at the end
  • check_circle Recruitment AI is high-risk under the EU AI Act, with those obligations applying from 2 December 2027

An employer receives 1,000 applications. Software scores each CV and automatically rejects everyone below a certain threshold. Efficient? Certainly. Lawful? Almost never, without work you have to do first.

Article 22 is a prohibition, not a complaint procedure

This is the point employers most often get wrong.

Article 22(1) GDPR is frequently read as a right: the candidate may object to a fully automated decision, and until they do, the employer can proceed. That reading is wrong.

In its judgment in SCHUFA (C-634/21, 7 December 2023), the Court of Justice held that Article 22(1) lays down a prohibition in principle on decisions based solely on automated processing that produce legal effects or similarly significantly affect a person. The individual does not have to invoke anything for the prohibition to apply.

For an employer, the practical consequence is concrete: you cannot switch on automated rejection and wait to see whether a candidate objects. You need to establish, before deployment, that one of the exceptions in Article 22(2) applies and that the safeguards are in place.

Rejection for a job clearly counts as significantly affecting the person, so there is no useful argument to be had about the threshold. The rights candidates have around automated decisions sit on top of that prohibition; they do not replace it.

What does “solely automated” mean?

The question is whether meaningful human involvement exists.

If software gives every applicant a score and rejects everyone below 70% with nobody reviewing them, the decision is automated. That case is easy.

The harder case is the one most recruitment tools actually create: the system produces a ranking or a score, and an HR employee makes the formal decision.

SCHUFA matters here too. The Court held that producing the score can itself be the decision covered by Article 22 where the party using it draws strongly on that score to determine the outcome. Applied to recruitment: if the AI ranking effectively decides who is invited and the human contributes no genuine assessment, inserting that human does not take the processing outside Article 22.

Ask three questions about your reviewer:

  • Do they see the underlying application, or only the score?
  • Do they have the authority to reach a different conclusion?
  • Do they have the time to do so across the volume of applications you send them?

If the honest answer to any of these is no, treat the process as solely automated.

When can it be lawful?

Article 22(2) provides three exceptions, and only three:

  • Necessary for entering into or performing a contract between the candidate and the employer. Necessity is a strict test; that you receive a high volume of applications and would prefer to filter them cheaply is a business convenience, not a necessity.
  • Authorised by Union or Member State law, which must lay down suitable safeguards. This varies by country and is rare in recruitment.
  • The candidate’s explicit consent. Consent in an employment or recruitment relationship is difficult to make freely given, because the candidate is not in a position to refuse without cost.

Where you do rely on the first or third exception, Article 22(3) requires safeguards: at minimum the right to obtain human intervention, to express a point of view and to contest the decision. If the processing involves special category data, Article 22(4) restricts it further.

Our practical position for employers: do not build a recruitment process that depends on establishing an Article 22 exception. Build one where a person genuinely makes the decision, and use the tooling to prepare that decision rather than to make it.

Candidates need to be told

Where Article 22 applies, transparency is not optional and not generic.

Articles 13(2)(f) and 14(2)(g) require you to tell candidates that automated decision-making takes place, and to provide meaningful information about the logic involved and the significance and envisaged consequences of the processing. Article 15(1)(h) requires the same information again if the candidate makes an access request.

“Technology may be used in our recruitment process” does not meet that standard. Explain what the system assesses, what role its output plays and how a candidate can ask for a human to look again. Where this belongs is set out in what a candidate privacy notice should contain.

What does the AI Act add?

The EU AI Act classifies AI systems used to filter applications or evaluate candidates as high-risk under Annex III.

High-risk systems carry a substantial framework: risk management, data governance, documentation, logging, transparency, human oversight, accuracy, robustness and cybersecurity, with obligations depending on whether you are a provider or a deployer.

Regulation (EU) 2026/1744 deferred the application date for these standalone high-risk systems from 2 August 2026 to 2 December 2027. That moves your AI Act deadline. It changes nothing about your GDPR position: Article 22 applies today. How the two frameworks sit together is covered in GDPR and the AI Act in recruitment.

Watch for discriminatory outcomes

A system can look neutral and still disadvantage particular groups.

Historical recruitment data reflects historical bias, and a model trained on that data reproduces those patterns. Test whether your criteria are genuinely relevant to the job and whether the system produces unfair outcomes.

GDPR compliance does not replace employment equality law. A tool can be documented, transparent and lawful under Article 22 and still expose you to a discrimination claim.

Human oversight has to be real

A reviewer who adds something to the process:

  • Understands what the system does and what it does not measure
  • Has access to the underlying application, not just the output
  • Can question and override the result
  • Has the time and the authority to make an independent assessment
  • Is not measured on how fast they clear the queue

“Computer says no” is not oversight.

Treat automated rejection as high-risk governance

Automated evaluation of candidates falls squarely within Article 35(3)(a), so a Data Protection Impact Assessment is the starting point rather than an afterthought. Involve privacy, HR, legal, security and AI governance before deployment, not after the first complaint.

GDPRWise helps organisations document processing activities and assess privacy risks, providing the GDPR foundation needed before higher-risk recruitment technologies are introduced.

auto_awesome Ready to let software decide who gets rejected?

GDPRWise documents your recruitment processing and the privacy risks attached to it, so you can judge an automated selection tool before it goes live.

Share share LinkedIn mail Email
GW
GDPRWise Editorial

This article was written by the GDPRWise team and reviewed by our privacy experts. We regularly review our content for accuracy and legal correctness.