Skip to content
HRaizon Subscribe

A Privacy Notice Explains Hiring AI. It Does Not Automatically Authorise It

A notice explains data use; consent is only one possible mechanism. Employers must separately identify a lawful basis and assess added safeguards.

Share X in f
Priya Ellison

Guidance date: 19 September 2026

No. In UK recruitment, giving a candidate a privacy notice is not the same as obtaining consent, and neither step automatically makes an AI-assisted hiring process lawful. The notice explains how personal information is processed. The organisation must separately identify an appropriate lawful basis for the processing. If special-category information or a consequential automated decision is involved, further conditions or safeguards may apply. The ICO treats transparency, lawful basis and controls for automated decision-making as distinct issues in its recruitment-AI material (ICO recruitment-AI considerations).

The short answer: notice, lawful basis and consent are three different things

A privacy notice serves transparency. It should help a candidate understand who is processing their information, why it is being processed, what role an AI tool plays and what rights or choices may be available.

A lawful basis serves justification. An employer, recruiter or other controller must identify an appropriate basis for processing personal information. The ICO names consent and legitimate interests as examples in its recruitment-AI material, but not as an exhaustive list or a recommendation for every recruitment workflow.

Consent is one possible mechanism—not another name for a privacy notice. Reading a notice, acknowledging receipt or continuing an application may show that information was presented. Those actions should not automatically be treated as proof that any consent required for a particular activity is valid.

Issue Function Question to answer Practical evidence
Privacy notice Explains the processing What happens to candidate information, why, by whom and for how long? Candidate-facing notice covering purposes, data, AI functions, recipients, retention and rights
Lawful basis Justifies a processing purpose What basis supports this particular use of personal information? Purpose-by-purpose record and supporting assessment
Consent Records agreement where processing genuinely depends on it What specified activity requires agreement, and what happens after refusal or withdrawal? Separate request, consent record and withdrawal route
Additional safeguards for consequential automated decisions Addresses heightened risks and possible restrictions How is the decision made, how significant is it and what recourse exists? Workflow evidence, review procedure, explanation and challenge route

Consent does not repair a process that collects more information than necessary, quietly reuses candidate data, retains it indefinitely, produces inaccurate or biased outputs, or lacks adequate security. The ICO’s recruitment-AI recommendations address lawful basis alongside fairness, transparency, minimisation, retention, accuracy, bias and governance.

Source status as at 19 September 2026

The ICO’s recruitment and selection guidance is still draft. Its consultation has closed, but the final version has not been published. The ICO says the guidance is under review because of changes made by the Data (Use and Access) Act and may change. Check the ICO’s live recruitment and selection guidance page before relying on it.

The available evidence for this guide does not establish the complete operative post-Act rules for significant automated decisions, including commencement or transitional arrangements. That issue requires separate verification against current legislation and updated ICO material.

Start with the processing, not the consent checkbox

Do not begin by asking, “Do we need a consent box for AI?” Begin by mapping what the configured system actually does.

  1. Identify each purpose. Separate CV summarisation, applicant ranking, assessment scoring, interview-note generation, eligibility checks and automatic rejection. “Using AI in recruitment” is too broad to analyse as one activity.
  2. List the information involved. Include information collected from candidates, obtained elsewhere, generated by the tool or inferred from other information. Scores, summaries and classifications may themselves relate to identifiable candidates.
  3. Identify every party. Map the employer, recruitment agency, assessment provider, applicant-tracking platform, AI vendor and relevant subprocessors.
  4. Determine the roles. Establish who decides the purposes and essential means of processing rather than relying only on labels in a vendor contract.
  5. Select and document the appropriate lawful basis. Assess the actual purpose and workflow instead of inserting a generic list of every conceivable basis.
  6. Check for additional conditions and safeguards. Give separate attention to special-category information and consequential automation.
  7. Draft the candidate-facing explanation. Make the notice reflect the deployed configuration, not generic product marketing.

The correct basis depends on the activity, relationship and current law. Consent, legitimate interests and contract-related grounds should not be treated as universal defaults. The ICO tells organisations considering recruitment AI to identify an appropriate basis, clarify controller and processor roles, minimise information, address retention, and monitor fairness, accuracy and bias.

Where an organisation intends to rely on consent, it should define the relevant purpose, record when and how agreement was obtained and provide a simple withdrawal route. A separate invitation to retain an unsuccessful applicant’s information for future vacancies is clearer than burying that request in the original application.

Employer notices in the evidence illustrate that organisations sometimes stop the consent-dependent purpose while claiming another basis for limited processing. That is a disclosed practice, not a universal rule: the controller must verify whether another basis actually applies and explain the practical consequences clearly.

What candidates should be told about an AI hiring tool

Use this as an AI-notice review checklist, not an exhaustive statement of every statutory field that applies to every workflow:

  • the specific processing purpose;
  • information collected directly from the candidate;
  • information obtained from agencies, public sources or other parties;
  • information generated or inferred, such as rankings, summaries or suitability assessments;
  • the AI tool’s function in the workflow;
  • who receives the information, including providers and subprocessors;
  • whether a provider reuses information for its own databases or model development;
  • how long source data, transcripts, scores, rankings and summaries are retained;
  • international transfers, where relevant;
  • applicable candidate rights and how to exercise them;
  • contact details for the controller or its privacy team; and
  • how the output influences review, progression or rejection.

For consequential predictions or outputs, “AI may be used” provides little practical insight. ICO material expects clearer information about how and why an automated tool is used and, under its older automated-decision guidance, discusses meaningful information about logic, significance and envisaged consequences, together with possible routes for human intervention and challenge. The exact mandatory disclosures and safeguards must be checked against the current workflow and post-Act law.

An AI-disclosure quality ladder

  1. Vague: “We may use AI during recruitment.”
  2. Functional: “We use software to rank applications” or “to generate interview notes.”
  3. Specific: The notice identifies the main inputs and the output produced.
  4. Consequential: It explains whether the output prioritises review, contributes to a score, triggers a check or determines progression.
  5. Actionable: It adds retention, review and challenge details, plus what happens if a candidate refuses or withdraws from a use presented as optional.

A notice can accurately report an employer’s stated position without proving that its chosen basis is appropriate, its consent mechanism is valid or its human oversight is meaningful. A notice is a disclosure, not a regulator’s approval certificate.

Candidate request script

Please confirm whether AI or automated tools were used in my application, what data and inferences they handled, what output they produced, and how that output affected my progression. Please also identify the lawful basis relied upon for each relevant purpose, how long the inputs and outputs will be retained, which activities depend on my consent, and whether human reconsideration is available.

Sensitive candidate information requires a separate check

The ICO says that processing special-category information, including data about racial or ethnic origin or health, requires a specific condition under the law in addition to identifying an ordinary lawful basis. Choosing consent as the general basis does not, by itself, complete that separate analysis.

Diversity monitoring shows why purposes should be separated. Some employer notices describe monitoring questions as voluntary and consent-based, with responses separated from hiring decisions or reported in aggregate. These notices illustrate organisational practices; they do not establish an authoritative UK rule or a ready-made legal solution.

HR should document:

  • the exact monitoring purpose;
  • whether identifiable responses are necessary;
  • who can access those responses;
  • whether they are separated from selection records;
  • when they will be aggregated or anonymised;
  • how long identifiable information will be retained; and
  • the applicable lawful basis and special-category condition.

Information supplied for optional diversity monitoring should not then be fed into ranking, scoring or selection merely because the candidate agreed to provide it for monitoring. That would be a different use requiring its own assessment.

Recruitment may also involve criminal-conviction information. The ICO’s draft recruitment guidance identifies criminal-conviction details as part of the sensitive information that can arise during recruitment. The precise requirements depend on the processing and current law, so a general application consent clause should not be treated as a complete legal test.

When automated-decision safeguards may become relevant

Not every AI-assisted rejection necessarily falls within a heightened regime for significant automated decisions. The answer depends on the real decision path, the substance of any human involvement and the effect on the candidate. However, the evidence available for this guide does not establish the complete post-Data (Use and Access) Act statutory test in force on 19 September 2026.

Consider two workflows:

  • An AI tool ranks applicants, after which a recruiter examines the applications and makes an independent decision.
  • A score below a configured threshold sends a rejection without substantive human review.

The second workflow plainly warrants closer assessment as a consequential automated decision. But calling a recruiter the “final decision-maker” does not resolve the first. HR should examine what the person actually sees, whether they can disagree with the tool and whether they conduct an individual assessment.

As a practical governance diagnostic—not a definitive legal test—ask:

  • Does the reviewer have authority to change the outcome?
  • Do they have enough time to evaluate the individual case?
  • Can they see relevant evidence beyond the AI output?
  • Do they understand the output’s limits?
  • Can they depart from it without exceptional approval?
  • Do they genuinely assess the case rather than routinely confirming a score?

Older ICO guidance described Article 22 as applying additional rules to solely automated decisions with legal or similarly significant effects. It listed contract necessity, domestic-law authorisation and explicit consent as routes for such processing, alongside safeguards involving information, human intervention and challenge. Because the supplied evidence does not confirm how the Data (Use and Access) Act changed that framework, those routes should not be treated here as a current deployment checklist.

Regardless of whether a heightened automated-decision regime applies, an organisation still needs to address the ordinary data-protection work identified by the ICO: lawful basis, transparency, minimisation, retention, accuracy, security, fairness, purpose limitation and applicable rights. Human participation is not a substitute for those controls.

Worked examples: what consent changes—and what it does not

Scenario Privacy information needed Possible consent question Processing that may continue Unresolved legal checks
Future-opportunities pool Extended-retention purpose, duration, users and contact plans “May we retain your details for future roles?” Limited records might remain if another documented basis applies Consent validity, justified retention, withdrawal and deletion
Optional AI pre-screen with recruiter route Inputs, interaction record, generated assessment, effect and alternative route Agreement to the specified pre-screen Ordinary application handling may continue through the non-AI route Disadvantage from refusal, route equivalence, sensitive data and review
AI ranking for recruiter prioritisation Ranking inputs, output and influence on review order Consent may not be the claimed basis Recruitment processing under the separately identified basis Necessity, fairness, accuracy, bias and substantive oversight
Automatic rejection Inputs, threshold, consequence, explanation and challenge process Do not assume consent is sufficient Limited recordkeeping might continue if another basis applies Current statutory regime, permitted processing and required safeguards

For the second scenario, Coveo’s applicant notice is a labelled practice example. The notice does not independently prove that the consent is valid or that the two routes are equivalent in timing, accessibility, standards or prospects.

For ranking, the notice should explain which inputs influence prioritisation, what the output means and how recruiters use it. A statement that humans make final decisions is useful context, but it is not operational evidence that reviewers independently assess applications.

For automatic rejection, HR should inspect the system configuration and full decision path rather than relying on a vendor’s product category. It should then verify the current statutory position and determine what explanation, reconsideration or challenge arrangements apply.

Employer notices show what organisations say they do. They may group several purposes and bases together or use ambiguous consent language. They are not regulator-approved templates, independent audits or proof of compliance.

Two action lists: questions for candidates and checks for HR

Questions for candidates

  • Was AI or automated processing used?
  • What information did it receive from me or another source?
  • What score, summary, classification or inference did it generate?
  • How did that output affect review, ranking or progression?
  • Which specific activity does the organisation say depends on my consent?
  • What happens if I refuse or later withdraw?
  • Does refusal affect timing, assessment standards or prospects of progression?
  • Who receives my information?
  • Does a vendor reuse it, add it to a candidate database or use it for model development?
  • How long are the source information and generated outputs retained?
  • Can I request an explanation or human reconsideration?
  • Which processing does the organisation say would continue under another basis?

Checks for HR and procurement

  • Map every purpose, dataset, inference and output.
  • Distinguish summarisation, ranking, scoring, note generation and automatic rejection.
  • Determine controller and processor roles from actual decisions and activities.
  • Document the proposed lawful basis for each purpose.
  • Identify any applicable special-category condition.
  • Treat criminal-conviction information as a separate issue.
  • Verify the current rules for consequential automated decisions.
  • Complete and maintain an appropriate DPIA analysis as the configuration and risks change.
  • Remove unnecessary fields and derived attributes.
  • Set and enforce retention periods for source information and generated outputs.
  • Examine vendor reuse, model-development and candidate-database practices.
  • Identify subprocessors and international transfers.
  • Allocate instructions, assistance, deletion and security responsibilities contractually.
  • Test whether human reviewers have authority, time, relevant evidence and practical freedom to depart from outputs.
  • Monitor accuracy, fairness and bias after deployment.
  • Explain refusal, consent withdrawal, objection, erasure and application withdrawal as distinct actions.
  • Confirm the current statutory position and updated ICO guidance before deployment.

These checks respond to documented regulatory findings. In November 2024, the ICO reported that audits of several recruitment-AI providers and developers produced almost 300 recommendations, all accepted or partially accepted. It highlighted practices including collecting more personal information than necessary and retaining information indefinitely to build candidate databases without candidates’ knowledge (ICO recruitment-AI considerations).

The practical rule is simple: tell candidates what the AI does, but do not confuse that explanation with permission to process their information. HR must separately justify each purpose, address sensitive information and consequential automation, and control minimisation, retention, fairness and vendor responsibilities. Candidates should ask which uses require agreement, what changes if they refuse or withdraw, and how they can seek meaningful reconsideration.

This guide reflects the sources reviewed on 19 September 2026. It is informational only, not legal, HR or employment advice, and is offered without a guarantee of accuracy or fitness for a particular purpose. Because UK law and the relevant ICO recruitment guidance are being updated, confirm the current legislation and ICO materials and obtain advice from qualified UK data-protection counsel before making a decision about a particular tool or workflow.