AI in HR Guide
AI and employee data privacy

Employee Data Protection and AI Tools: Rules HR Must Follow

Every AI tool that touches employee data brings data protection duties with it. These eight rules cover most of what HR needs to get right.

By the HRight Talks editorial teamUpdated 3 minute read

Short answer

To comply with data protection when using AI tools, HR should establish a lawful basis other than consent where possible, limit data to what is necessary, apply extra protection to special category data such as health, avoid solely automated decisions with significant effects unless an exception and safeguards apply, carry out data protection impact assessments for higher-risk uses, put strong data processing agreements in place with vendors, enforce retention limits, and enable employees to exercise their rights, including access to data and inferences about them.

Key takeaways

  • Eight rules cover most HR AI data protection duties.
  • Special category data needs an additional legal condition.
  • Inferences generated by AI can themselves be personal data.
  • Vendor contracts must address model training, location and deletion.

Eight rules

RuleWhat it requires
1. Lawful basisIdentify and document a lawful basis; avoid relying on employee consent where it is not freely given
2. MinimisationUse only data necessary for the purpose; pseudonymise where possible
3. Special category dataMeet an additional condition for health, biometric, ethnicity and similar data
4. Automated decisionsAvoid solely automated decisions with legal or similarly significant effects unless an exception and safeguards apply
5. Impact assessmentsConduct DPIAs for processing likely to be high risk
6. VendorsData processing agreements; restrictions on model training; security; location
7. RetentionKeep data and AI outputs only as long as needed
8. RightsEnable access, correction, objection and human review

A DPIA outline for HR AI

  1. Describe the processing: purpose, data, AI system, people affected.
  2. Assess necessity and proportionality.
  3. Identify risks to employees: bias, inaccuracy, intrusion, security, loss of control.
  4. Define measures: minimisation, oversight, transparency, testing, access controls.
  5. Consult the data protection officer and, where appropriate, employees.
  6. Record the decision and review date.

Under the EU AI Act, deployers of high-risk systems should use information from providers to support these assessments. See EU AI Act employer obligations.

Vendor contract essentials

  • Processing only on your documented instructions.
  • No training of vendor models on your data without explicit agreement.
  • Data location and international transfer safeguards.
  • Security standards and breach notification.
  • Sub-processor controls.
  • Deletion or return of data at contract end.
  • Audit and information rights.

AI inferences are personal data

When AI produces scores, predictions or labels about an employee, such as an attrition risk or skills profile, these outputs are generally personal data. Employees may have rights to access and correct them. Treat them with the same care as source data. See how AI predicts attrition.

This is general information, not legal advice. Employee privacy and monitoring law varies significantly by country and state; take qualified advice for your jurisdictions.

Frequently asked questions

What data protection rules apply to HR AI tools?

Lawful basis, data minimisation, extra protection for special category data, limits on solely automated decisions, impact assessments, vendor contracts, retention limits and employee rights.

Are AI-generated scores about employees personal data?

Generally yes. Scores, predictions and labels about identifiable employees are personal data and may be subject to access and correction rights.

What should an HR AI vendor contract include?

Processing only on instructions, no model training on your data without agreement, data location and transfer safeguards, security, breach notification, sub-processor controls, deletion at end and audit rights.

Can HR use AI for solely automated decisions?

Under the GDPR, solely automated decisions with legal or similarly significant effects are restricted unless an exception applies, with safeguards including the right to human intervention.

Sources and further reading

  1. GDPR (Regulation (EU) 2016/679), EUR-Lex
  2. European Data Protection Board: Guidelines 05/2020 on consent under Regulation 2016/679
  3. Regulation (EU) 2024/1689 (EU AI Act), EUR-Lex