Guide · Recruitment and compliance
Recruitment is one of the CNIL's priority inspection themes for 2026. This guide brings together what applies to an application screening tool in France: fiche 13 of the CNIL recruitment guide, GDPR Article 22, the retention periods published in April 2026, the French Labour Code and the AI Act, with a compliant workflow step by step.
The principle
A tool can rank applications. The decision to reject must stay with a recruiter who has looked at the file.
In short
Use is growing fast. According to APEC (May 2026), 13% of mid-sized and large French companies used AI to recruit managers and professionals (cadres) in 2025, up from 6% in 2024, mainly to write job ads. On the candidate side, 31% of cadres who recently looked for a job used AI, up from 15% at the end of 2024, and 2 companies in 10 already value AI skills when selecting candidates. For the wider HR context, see our guide to AI in human resources.
CNIL
Each year the CNIL, France's data protection authority, picks a few priority inspection themes. The 2026 themes, published on 3 April, are recruitment, the single electoral register and sports federations. The CNIL says about 20% of its annual inspections fall under these themes.

For recruitment, the page lists three things inspectors will check:
Inspections target large companies and recruitment firms first, because they receive and screen the most applications. The CNIL adds that this theme prefigures its future role as AI market surveillance authority in the employment field. Smaller companies are still in scope: the CNIL can inspect any organisation and also acts on complaints.
Recruitment guide
The CNIL recruitment guide, published on 30 January 2023, has 19 fiches (practical sheets). Fiche 13 covers software for sorting, ranking and assessing applications (pages 69 to 74 of the PDF). It is the text inspectors work from in 2026, and news articles cite it without going into detail.
A decision based solely on automated processing is prohibited in principle under the GDPR. The CNIL specifies that a ranking tool falls into this category when the recruiter only looks at the top-ranked profiles. The tool formally rejects nobody, yet candidates at the bottom of the list are never read, so the algorithm has made the decision.
| Situation described by the CNIL | What happens | Verdict |
|---|---|---|
| Small firm, 10 applications | It buys an off-the-shelf CV ranking tool and hires the top-ranked candidate. | Bad practice: the volume does not justify an automated decision. |
| Job with several hundred applications | Structured form, candidates told about the processing in advance, a set window during which they can ask for review by a human. | Good practice cited by the CNIL. |
For a self-learning algorithm, the recruiter must check that it stays relevant, including how it was trained. A vendor that will not explain its training data leaves you exposed on this point.
GDPR
GDPR Article 22 sets the principle: a person has the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects them. Rejecting an application qualifies. The three exceptions (explicit consent, contract, law) come with safeguards: human intervention, the right to express one's view and the right to contest the decision.
A DPIA is almost always required. The CNIL list of processing that requires an impact assessment (deliberation 2018-327 of 11 October 2018) covers processing that profiles individuals for HR management. Its example is processing that makes recruitment easier through a selection algorithm. A CV scoring or matching tool fits that description.
The DPIA must be done before go-live. It describes the data processed, the tool's logic, the risks (discrimination, error, leaks) and the measures taken. Technical safeguards for AI agents (access, logs, data separation) are covered in our guide to AI agent security.
Retention
On 2 April 2026, updated on 20 May 2026, the CNIL published a retention framework for HR management. Its recruitment section gives precise periods, and these are what the 2026 inspections will compare against your databases.
| Data | Active storage | Intermediate archiving | Why |
|---|---|---|---|
| Application in progress | Length of the process, until the candidate gets an answer | Depends on the outcome (next rows) | Needed for recruitment |
| Rejected candidate | End of the process | 5 years from the date the position was filled | Evidence in case of a discrimination claim (Labour Code, L1134-5) |
| Talent pool (CV database) | Up to 2 years after the last contact (CNIL recommendation) | Then 5 years | Only for candidates who have not objected or who agreed |
Two practical consequences. First, the 5-year archive exists as evidence: it sits apart from active storage, and rejected candidates should not reappear in recruiters' searches. Second, an AI tool that keeps CVs to "improve matching" must follow the same deadlines: check in the contract what the vendor keeps and for how long.
Sanctions

EXTIA, €300,000. In a decision of 21 July 2026, published on 9 September 2026, the CNIL fined this engineering and IT consultancy. In 2024 it received 265 erasure requests, mostly from candidates. More than three quarters were not handled or were handled badly: 12 never processed, 166 people never told the outcome, 27 told late. The breaches concern GDPR Articles 12 and 17, and the company had already been reminded of its obligations twice. As of 15 September 2026, it is the most recent CNIL sanction involving candidates.
Formal notice of 25 April 2024. The CNIL ordered a company to stop asking candidates for their place of birth, nationality, family situation and previous salary. The case was closed after the company complied.
For scale: in 2025 the CNIL issued 259 decisions, including 83 sanctions, for a total of €486,839,500 in fines (report published on 9 February 2026). None was specific to recruitment. A screening tool that stores thousands of CVs must therefore also be able to erase them on request, within the one-month deadline set by the GDPR.
Labour Code
| Article | What it requires | Consequence for a screening tool |
|---|---|---|
| L1221-6 | Information requested from a candidate may only serve to assess their ability to do the job or their professional skills, with a direct and necessary link to the job. | The form and scoring criteria contain only job-related items. |
| L1221-8 | The candidate is expressly informed, before use, of the recruitment methods and techniques applied. Results are confidential. Methods must be relevant. | The AI tool is mentioned on the job ad or form, before the CV is submitted. |
| L1221-9 | No personal information about a candidate may be collected by a device the candidate was not told about. | No hidden profile enrichment (social networks, third-party databases) by the tool. |
| L1132-1 | Bans excluding a person from a recruitment process on discriminatory grounds: origin, sex, age, family situation, health, disability, place of residence, physical appearance, among others. | Algorithmic bias engages the employer, even when the tool comes from a vendor. |
| L2312-38 | The works council (CSE) is informed, before use, of recruitment methods and techniques and changes to them, and of automated HR processing. | Inform the CSE before deployment. Consultation is added only if the tool also monitors employee activity. |
The works council point is often misreported. For recruitment methods, the text requires prior information. The stronger "informed and consulted" duty covers tools that monitor employees' activity. A tool that screens external applications and also scores internal performance falls under both.
AI Act

Annex III, point 4(a), of Regulation (EU) 2024/1689 classifies as high-risk AI systems intended for the recruitment or selection of people, in particular to place targeted job ads, analyse and filter applications, and evaluate candidates. An applicant tracking system (ATS) that scores or ranks CVs is directly concerned.
The date has changed. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026. It moves Annex III high-risk obligations to 2 December 2027. Some content published since, including a French ATS vendor blog dated 30 July 2026, still presents these rules as applying from August 2026. The full timeline is in our AI Act guide for businesses.
The company using the tool is a "deployer". Article 26, in the 2024 version shown on the Commission's Service Desk, requires it to:
Check the consolidated text after the Omnibus before fixing your procedures: the Service Desk page had not been updated as of 15 September 2026.
The Omnibus also allows sensitive data to be processed to detect and correct bias, under set conditions. That is directly relevant to the bias tests described below.
Discrimination
The risk described by the CNIL and the French Défenseur des droits has been measured. Two cases are the usual references.
| Study or case | Method | Result |
|---|---|---|
| University of Washington (Wilson and Caliskan, AIES, October 2024) | More than 550 real CVs, more than 500 job listings, more than 3 million comparisons, three models (Mistral AI, Salesforce, Contextual AI), names varied | White-associated names preferred 85% of the time versus 9% for Black-associated names. Male names preferred 52% of the time versus 11% for female names. Black male names were never preferred over white male names. |
| Amazon (reported in October 2018) | Internal tool rating candidates from 1 to 5 stars, trained on CVs received in previous years | The tool penalised the word "women's" and downgraded graduates of two all-women's colleges. Amazon dropped the project. |
These results concern specific models and settings; they do not prove that a given tool is biased. They show that a language model applied to CVs reproduces gaps without being asked to, and that testing before go-live is the only way to know. The Défenseur des droits published a report with the CNIL on the automation of discrimination (31 May 2020) and a sheet on discrimination produced by algorithms and AI, updated on 1 February 2024. Its decision 2025-182 of 10 October 2025 concerns the targeting of job ads on Facebook, a use also covered by Annex III.
Vendors
ATS vendors active in France publish very uneven information on compliance. The table reports their own statements, without judging the products.
| Vendor | What the AI does (per the vendor) | What is published on compliance |
|---|---|---|
| Teamtailor | Co-pilot based on OpenAI GPT models, suggestions of existing candidates | States that some of its AI features will fall under the AI Act definition of high-risk and that it will meet provider obligations. |
| SmartRecruiters (SAP group) | Winston Chat, Match, Screen and Companion | AI addendum of 18 June 2025: the tools do not independently evaluate, score or rank candidates, and the customer must provide human oversight. |
| Workday HiredScore | Spotlight gives A, B, C or D match grades | Independent audit by Secretariat (March 2026) found no evidence of disparate impact, limited to New York roles. |
| Taleez | Matching ranked by relevance, job ad writing, interview summaries | Says the AI never decides in the recruiter’s place. Hosted in France. Nothing on the AI Act. |
| Beetween | CV parsing, scoring, "Préqualification AI" | Presents AI as informing the decision. Mentions GDPR, traceability and human oversight. Nothing on the AI Act. |
| Flatchr | Matching that brings the most relevant profiles to the top | Says no profile is excluded. GDPR and DPA links. Nothing on the AI Act. |
Note SmartRecruiters' position: the vendor states in writing that human oversight is the customer's job. Under both the GDPR and the AI Act, the employer answers for the decision. And a ranking with no formal exclusion can still become an automated decision if nobody reads the bottom of the list. To compare providers who integrate these tools, see our comparison of AI agencies for recruitment and HR.
Method

This workflow can be built inside an existing ATS or as a custom AI agent connected to your tools. The same traceability then applies when the hired candidate arrives, as described on our page about the onboarding agent.
Decision
| Your situation | Assessment | What to do |
|---|---|---|
| A few dozen applications per job, automatic ranking | Avoid. The 10-application case is the bad practice cited by the CNIL. | A human reads every application; AI can summarise or extract information. |
| Several hundred applications, AI pre-sort | Possible with safeguards. | Structured form, prior notice, human decision, review window, DPIA. |
| Automatic rejection below a score | Solely automated decision (Article 22). | Remove automatic rejection, or demonstrate an exception and put all safeguards in place. |
| Recruiter only reads the top of the ranking | Can be an automated decision under fiche 13. | Have every rejection confirmed by a person who saw the file, and log it. |
| CV parsing without a score | Lower risk. | Candidate information, retention periods, register. |
| Video interview analysis that infers emotions | Banned since 2 February 2025 (AI Act, Article 5(1)(f)). | Switch the feature off or change tools. |
| Chatbot that pre-qualifies candidates | Transparency required since 2 August 2026 (Article 50). | Disclose the AI in the first message and do not let it close an application. |
| Talent pool with no last-contact date | Not compliant with the 2026 HR framework. | Date contacts, purge after 2 years, archive separately. |
If you are weighing several tool configurations, AI consulting can map the processing before you buy or build.
About
Lumyniq is an AI automation agency based in Paris. It builds custom AI agents, Claude integrations, n8n workflows and Twenty CRM setups for small and mid-sized businesses, with a focus on real estate, legal, healthcare and HR. Every project starts with an audit of the existing process, before any quote.
FAQ
Related guides
The providers that integrate these tools, compared.
The full timeline after the Digital Omnibus.
The sector guide: recruitment, onboarding, training.
Links verified at publication. Regulatory texts change — always defer to the official source.
A question, a project, an idea? We respond within 24h. Free audit, no commitment.