If your hiring process uses a digital assessment to screen candidates and an automated score triggers a rejection, you need to know whether GDPR Article 22 applies. The answer isn't simply "yes, because you used automation." Two conditions must both be present. This guide walks you through how to test your process, what to do when Article 22 does apply, and how to build the candidate communications and operational safeguards that keep you compliant.
Who this is for: Recruitment managers, HR leads, and talent acquisition teams using assessment-based pre-screening with automated score thresholds. Prerequisites: Basic familiarity with your ATS workflow and the point in your funnel where rejected candidates receive a final rejection notification. Expected time: 30-45 minutes to complete the applicability test and draft your safeguard checklist.
GDPR Article 22 states that "the data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her" (GDPR, Article 22, via gdpr-info.eu). Two conditions must both be true for the article to apply. Work through each in order.
Ask yourself these three questions before moving on:
If a human sees the score only after the rejection message has already been sent, or if the process is designed so that low scores automatically close the candidate's application without any review step, the decision is solely automated.
The rubber-stamp question is the one most teams get wrong. Clicking "confirm rejection" in an ATS while looking only at a traffic-light indicator is not meaningful human involvement. The EDPB's Guidelines on Automated Individual Decision-Making and Profiling make clear that human involvement must be genuine, not a formality layered on top of an automated outcome.
"Legal effects" in an employment context would include, for example, a contractual right being affected. "Similarly significant effects" is the more common trigger in recruitment. The CJEU's December 7, 2023 ruling in Case C-634/21 (SCHUFA Holding and Others / OQ v Land Hessen) confirmed that the automated establishment of a probability value, where a third party relies on it to make a consequential decision, can fall within Article 22 scope.
In recruitment, rejecting a candidate based on a score threshold blocks them from progressing to any further stage. That prevents access to an employment opportunity. Regulators and legal commentary treat that as "similarly significant." If your process sends an automated rejection after a below-threshold assessment score, this condition is very likely met.
Result of the test:
Where Article 22 applies, it creates a default prohibition. You can proceed only under one of three exceptions:
Contract necessity is the most commonly relied-upon exception in pre-employment screening. Document which exception you're relying on. That documentation will be relevant if a candidate challenges the decision or a regulator asks.
Where an exception applies, Article 22 mandates three specific safeguards: the right to obtain human intervention, the right to express a point of view, and the right to contest the decision. Each one needs an operational design, not just a policy statement.
Human intervention workflow
Designate a named role (for example, the lead recruiter or hiring manager for the vacancy) as the competent reviewer. That person must receive the candidate's full assessment report, the score, and any contextual information the candidate has submitted. They must have the authority to overturn the automated outcome and reinstate the candidate to the process. Build this as a named workflow step in your ATS, not an ad hoc escalation.
Right to express point of view
Before the reviewer finalizes a decision, candidates must be able to submit relevant context. For example, a candidate may have had a technical issue during the assessment, or relevant circumstances that affected their performance. Create a simple submission channel, an email address, a form, or a reply path in your messaging workflow, and make sure reviewers see that information before deciding.
Right to contest
This is distinct from the initial human review. If a candidate is unhappy with the outcome of the human review, they need a further escalation path. This could be a DPO referral or a formal complaints process. The key is that it's separate from the original automated decision path.
Where Article 22 applies, candidates must be informed. Include an Article 22 notice in your job application form or privacy notice. Below are working templates.
"Some stages of our application process use automated assessment scoring to evaluate candidate suitability. Where a decision based solely on this automated processing has legal or similarly significant effects for you, you have the right to request human review of the decision, to submit additional information or context before the review is finalized, and to contest the outcome. To exercise any of these rights, contact [recruiter email/address] within [X] business days of receiving your rejection notification."
"Thank you for completing the assessment. Based on the results, we won't be progressing your application for [Role] at this stage. Under GDPR Article 22, you have the right to request human review of this decision. To do so, reply to this message or email [address] within [X] business days, and include your name, the role you applied for, the date you received this message, and any context you'd like the reviewer to consider."
Acknowledge receipt of a review request within 2 business days. Complete the human review within 5 business days of acknowledgment. Communicate the outcome to the candidate in writing. Log the request, the reviewer, the inputs considered, and the outcome in your ATS or a dedicated audit record.
Before you sign off on your compliance setup, check each of the following scenarios against your current process:
Teams using Selection Lab's SmartChat and assessment platform should map exactly where in their configured workflow the "final rejection" point occurs. Selection Lab's candidate journey design (WhatsApp/chat intake, assessment, role match, invited interview) processes data stored in Frankfurt and is designed with GDPR compliance and EU AI Act alignment in mind. Where the automation sends candidates forward to interview automatically, the Article 22 question becomes most pressing at the rejection exit point for those who don't progress. Confirm with your implementation that the human override and safeguard steps are active at that stage, and read our guide to the EU AI Act in recruitment for the system-level obligations that sit alongside GDPR.
You've now identified whether Article 22 GDPR applies to your automated rejection workflow, established the correct lawful basis, built the three mandatory safeguards into your process, and created the candidate-facing communications required to support those rights.
The next step is to test the workflow with a sample case. Trigger a mock rejection, confirm the notice reaches the candidate correctly, submit a review request through your own form, and verify it reaches the right reviewer with the right information. Log the result and set a calendar reminder to re-test any time your assessment configuration or ATS workflow changes.
For broader guidance, refer to the EDPB's Guidelines on Automated Individual Decision-Making and Profiling and Article 22 of the GDPR directly (available at gdpr-info.eu). Both remain the authoritative sources for interpreting the scope of this obligation.

If your hiring process uses a digital assessment to screen candidates and an automated score triggers a rejection, you need to know whether GDPR Article 22 applies. The answer isn't simply "yes, because you used automation." Two conditions must both be present. This guide walks you through how to test your process, what to do when Article 22 does apply, and how to build the candidate communications and operational safeguards that keep you compliant.
Who this is for: Recruitment managers, HR leads, and talent acquisition teams using assessment-based pre-screening with automated score thresholds. Prerequisites: Basic familiarity with your ATS workflow and the point in your funnel where rejected candidates receive a final rejection notification. Expected time: 30-45 minutes to complete the applicability test and draft your safeguard checklist.
GDPR Article 22 states that "the data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her" (GDPR, Article 22, via gdpr-info.eu). Two conditions must both be true for the article to apply. Work through each in order.
Ask yourself these three questions before moving on:
If a human sees the score only after the rejection message has already been sent, or if the process is designed so that low scores automatically close the candidate's application without any review step, the decision is solely automated.
The rubber-stamp question is the one most teams get wrong. Clicking "confirm rejection" in an ATS while looking only at a traffic-light indicator is not meaningful human involvement. The EDPB's Guidelines on Automated Individual Decision-Making and Profiling make clear that human involvement must be genuine, not a formality layered on top of an automated outcome.
"Legal effects" in an employment context would include, for example, a contractual right being affected. "Similarly significant effects" is the more common trigger in recruitment. The CJEU's December 7, 2023 ruling in Case C-634/21 (SCHUFA Holding and Others / OQ v Land Hessen) confirmed that the automated establishment of a probability value, where a third party relies on it to make a consequential decision, can fall within Article 22 scope.
In recruitment, rejecting a candidate based on a score threshold blocks them from progressing to any further stage. That prevents access to an employment opportunity. Regulators and legal commentary treat that as "similarly significant." If your process sends an automated rejection after a below-threshold assessment score, this condition is very likely met.
Result of the test:
Where Article 22 applies, it creates a default prohibition. You can proceed only under one of three exceptions:
Contract necessity is the most commonly relied-upon exception in pre-employment screening. Document which exception you're relying on. That documentation will be relevant if a candidate challenges the decision or a regulator asks.
Where an exception applies, Article 22 mandates three specific safeguards: the right to obtain human intervention, the right to express a point of view, and the right to contest the decision. Each one needs an operational design, not just a policy statement.
Human intervention workflow
Designate a named role (for example, the lead recruiter or hiring manager for the vacancy) as the competent reviewer. That person must receive the candidate's full assessment report, the score, and any contextual information the candidate has submitted. They must have the authority to overturn the automated outcome and reinstate the candidate to the process. Build this as a named workflow step in your ATS, not an ad hoc escalation.
Right to express point of view
Before the reviewer finalizes a decision, candidates must be able to submit relevant context. For example, a candidate may have had a technical issue during the assessment, or relevant circumstances that affected their performance. Create a simple submission channel, an email address, a form, or a reply path in your messaging workflow, and make sure reviewers see that information before deciding.
Right to contest
This is distinct from the initial human review. If a candidate is unhappy with the outcome of the human review, they need a further escalation path. This could be a DPO referral or a formal complaints process. The key is that it's separate from the original automated decision path.
Where Article 22 applies, candidates must be informed. Include an Article 22 notice in your job application form or privacy notice. Below are working templates.
"Some stages of our application process use automated assessment scoring to evaluate candidate suitability. Where a decision based solely on this automated processing has legal or similarly significant effects for you, you have the right to request human review of the decision, to submit additional information or context before the review is finalized, and to contest the outcome. To exercise any of these rights, contact [recruiter email/address] within [X] business days of receiving your rejection notification."
"Thank you for completing the assessment. Based on the results, we won't be progressing your application for [Role] at this stage. Under GDPR Article 22, you have the right to request human review of this decision. To do so, reply to this message or email [address] within [X] business days, and include your name, the role you applied for, the date you received this message, and any context you'd like the reviewer to consider."
Acknowledge receipt of a review request within 2 business days. Complete the human review within 5 business days of acknowledgment. Communicate the outcome to the candidate in writing. Log the request, the reviewer, the inputs considered, and the outcome in your ATS or a dedicated audit record.
Before you sign off on your compliance setup, check each of the following scenarios against your current process:
Teams using Selection Lab's SmartChat and assessment platform should map exactly where in their configured workflow the "final rejection" point occurs. Selection Lab's candidate journey design (WhatsApp/chat intake, assessment, role match, invited interview) processes data stored in Frankfurt and is designed with GDPR compliance and EU AI Act alignment in mind. Where the automation sends candidates forward to interview automatically, the Article 22 question becomes most pressing at the rejection exit point for those who don't progress. Confirm with your implementation that the human override and safeguard steps are active at that stage, and read our guide to the EU AI Act in recruitment for the system-level obligations that sit alongside GDPR.
You've now identified whether Article 22 GDPR applies to your automated rejection workflow, established the correct lawful basis, built the three mandatory safeguards into your process, and created the candidate-facing communications required to support those rights.
The next step is to test the workflow with a sample case. Trigger a mock rejection, confirm the notice reaches the candidate correctly, submit a review request through your own form, and verify it reaches the right reviewer with the right information. Log the result and set a calendar reminder to re-test any time your assessment configuration or ATS workflow changes.
For broader guidance, refer to the EDPB's Guidelines on Automated Individual Decision-Making and Profiling and Article 22 of the GDPR directly (available at gdpr-info.eu). Both remain the authoritative sources for interpreting the scope of this obligation.