Most HR and legal teams reach for this question once a vendor is already selected and rollout is imminent. That's the wrong sequence. Under GDPR Article 35, a Data Protection Impact Assessment (DPIA) must happen before processing begins, not after. If your organization uses AI-scored or game-based assessments in recruitment, the time to make this determination is now.
GDPR Article 35 requires a controller to carry out a DPIA prior to processing where a type of processing is "likely to result in a high risk to the rights and freedoms of individuals." Both the Information Commissioner's Office (ICO) and the European Commission confirm this framing: the threshold is likely high risk, not certain high risk.
The decision is risk-based, not tool-based. Using AI doesn't automatically mandate a DPIA. But it does raise the probability of meeting the threshold, especially when the processing involves systematic evaluation, profiling of personal aspects, or automated outputs that meaningfully affect people.
In recruitment, the practical question becomes: does your selection process use systematic scoring or profiling in a way that could materially affect an applicant's employment prospects? If the answer is yes to more than one risk factor, Article 35 almost certainly applies.
Game-based assessments are not exempt simply because they're engaging or indirect. They still produce scored outputs and behavioral inferences that feed into selection decisions. An AI-scored cognitive test, a situational judgment game, or an automated intake tool that filters CVs all share the same underlying characteristic: they generate structured data about individuals that influences who proceeds.
Map common assessment features to the EDPB's nine-criteria framework for identifying high-risk processing and the overlap becomes clear:
Any one of these can raise the risk level. Multiple criteria active simultaneously make a DPIA effectively unavoidable.
The EU AI Act adds a parallel layer of urgency. Under Annex III, AI systems used for the recruitment or selection of natural persons are explicitly classified as high-risk (employment/workers management category). This classification doesn't replace the GDPR DPIA obligation, but it does confirm the risk context and creates documentation expectations that reinforce the case for completing a DPIA.
Consider a platform like Selection Lab, which combines AI-driven SmartChat intake (CV check, initial screening, interview scheduling) with game-based and hard-skills assessments that produce match scores per role. That end-to-end flow involves systematic evaluation at multiple stages: automated pre-screening, behavioral inference through game outputs, and scored outputs that determine who advances. That's a strong case for completing a DPIA before deployment.
Run through these decision gates for each assessment or selection instrument in scope:
| Question | Yes / No |
|---|---|
| Do you systematically score or rank candidates using an automated tool? | |
| Does the tool profile personal aspects (cognitive ability, personality traits, behavioral tendencies, role fit)? | |
| Does the output meaningfully affect applicants (knock-outs, shortlisting, interview invites)? | |
| Is the decision largely automated or made with limited human review of the output? | |
| Does processing involve sensitive data or data that could infer sensitive characteristics? |
If two or more answers are "yes": a DPIA is likely required. Proceed with a formal assessment before deploying or continuing the processing.
If no gates are triggered: a DPIA may not be mandatory. Document your reasoning anyway. The accountability principle under GDPR requires you to demonstrate why processing is low-risk, not just assert it.
Higher-risk sub-features worth specific attention include: score-based knock-out criteria applied automatically, AI-generated interview recommendations with no recruiter override, and any proctoring or candidate monitoring functionality.
Start the DPIA before rollout, not during it. Involve the following stakeholders:
For the DPIA itself, you'll need to document: what personal data flows in and out of the assessment tool; where scored outputs are stored and who has access; the legal basis and necessity justification; proportionality relative to the hiring purpose; mitigation measures; and how applicants are informed.
Practical mitigations worth building in from the start include: a human review step before final decisions on assessment outputs; clear applicant notice explaining how scores are used; defined data retention limits; bias testing and validation documentation from the vendor; and confirmed security controls (data residency, encryption, access controls).
When using Selection Lab, supporting documentation for your DPIA inputs is available via the Selection Lab Trust Center, including processing descriptions, security measures, and consent and retention handling. Selection Lab stores personal data in Frankfurt, uses local LLMs to remove personal information from conversation flows, and maintains configurable retention periods. These governance details belong in your DPIA risk analysis and mitigation section.
Once completed, a DPIA covering a specific processing pattern (e.g., game-based assessment for logistics roles) can generally be reused across materially similar deployments. Review it when assessment logic changes, when you add new tool features, or when you switch vendors.
If you're uncertain whether your current assessment setup meets the threshold, run through the checklist above and escalate to your DPO or legal counsel for a formal DPIA determination. Documentation costs far less than the alternative.
Usually yes. GDPR Article 35 requires a DPIA where processing is likely to result in a high risk to individuals. Assessments that systematically score candidates, profile personal aspects and determine who advances meet several of the EDPB's high-risk criteria at once. If two or more checklist questions are answered yes, treat a DPIA as required.
Before processing starts, so well before rollout. Article 35 speaks of an assessment prior to processing. In practice, start the DPIA as soon as a vendor is seriously considered, so its findings still shape the configuration and the contract.
No. The playful format does not change the processing. A game-based assessment still produces scored outputs and behavioral inferences that feed into selection decisions, so it falls under the same risk assessment as a traditional test.
They run in parallel. The DPIA is a GDPR obligation about the risks of data processing to individuals. The EU AI Act classifies AI systems for recruitment and selection as high-risk and adds documentation, transparency and human oversight requirements. Neither replaces the other, and vendor documentation typically serves both.
The HR process owner, the Data Protection Officer or privacy counsel, the assessment vendor, and IT and legal. HR defines purpose and necessity, the DPO leads the assessment, the vendor supplies processing descriptions and security controls, and IT and legal review data flows and contracts.

Most HR and legal teams reach for this question once a vendor is already selected and rollout is imminent. That's the wrong sequence. Under GDPR Article 35, a Data Protection Impact Assessment (DPIA) must happen before processing begins, not after. If your organization uses AI-scored or game-based assessments in recruitment, the time to make this determination is now.
GDPR Article 35 requires a controller to carry out a DPIA prior to processing where a type of processing is "likely to result in a high risk to the rights and freedoms of individuals." Both the Information Commissioner's Office (ICO) and the European Commission confirm this framing: the threshold is likely high risk, not certain high risk.
The decision is risk-based, not tool-based. Using AI doesn't automatically mandate a DPIA. But it does raise the probability of meeting the threshold, especially when the processing involves systematic evaluation, profiling of personal aspects, or automated outputs that meaningfully affect people.
In recruitment, the practical question becomes: does your selection process use systematic scoring or profiling in a way that could materially affect an applicant's employment prospects? If the answer is yes to more than one risk factor, Article 35 almost certainly applies.
Game-based assessments are not exempt simply because they're engaging or indirect. They still produce scored outputs and behavioral inferences that feed into selection decisions. An AI-scored cognitive test, a situational judgment game, or an automated intake tool that filters CVs all share the same underlying characteristic: they generate structured data about individuals that influences who proceeds.
Map common assessment features to the EDPB's nine-criteria framework for identifying high-risk processing and the overlap becomes clear:
Any one of these can raise the risk level. Multiple criteria active simultaneously make a DPIA effectively unavoidable.
The EU AI Act adds a parallel layer of urgency. Under Annex III, AI systems used for the recruitment or selection of natural persons are explicitly classified as high-risk (employment/workers management category). This classification doesn't replace the GDPR DPIA obligation, but it does confirm the risk context and creates documentation expectations that reinforce the case for completing a DPIA.
Consider a platform like Selection Lab, which combines AI-driven SmartChat intake (CV check, initial screening, interview scheduling) with game-based and hard-skills assessments that produce match scores per role. That end-to-end flow involves systematic evaluation at multiple stages: automated pre-screening, behavioral inference through game outputs, and scored outputs that determine who advances. That's a strong case for completing a DPIA before deployment.
Run through these decision gates for each assessment or selection instrument in scope:
| Question | Yes / No |
|---|---|
| Do you systematically score or rank candidates using an automated tool? | |
| Does the tool profile personal aspects (cognitive ability, personality traits, behavioral tendencies, role fit)? | |
| Does the output meaningfully affect applicants (knock-outs, shortlisting, interview invites)? | |
| Is the decision largely automated or made with limited human review of the output? | |
| Does processing involve sensitive data or data that could infer sensitive characteristics? |
If two or more answers are "yes": a DPIA is likely required. Proceed with a formal assessment before deploying or continuing the processing.
If no gates are triggered: a DPIA may not be mandatory. Document your reasoning anyway. The accountability principle under GDPR requires you to demonstrate why processing is low-risk, not just assert it.
Higher-risk sub-features worth specific attention include: score-based knock-out criteria applied automatically, AI-generated interview recommendations with no recruiter override, and any proctoring or candidate monitoring functionality.
Start the DPIA before rollout, not during it. Involve the following stakeholders:
For the DPIA itself, you'll need to document: what personal data flows in and out of the assessment tool; where scored outputs are stored and who has access; the legal basis and necessity justification; proportionality relative to the hiring purpose; mitigation measures; and how applicants are informed.
Practical mitigations worth building in from the start include: a human review step before final decisions on assessment outputs; clear applicant notice explaining how scores are used; defined data retention limits; bias testing and validation documentation from the vendor; and confirmed security controls (data residency, encryption, access controls).
When using Selection Lab, supporting documentation for your DPIA inputs is available via the Selection Lab Trust Center, including processing descriptions, security measures, and consent and retention handling. Selection Lab stores personal data in Frankfurt, uses local LLMs to remove personal information from conversation flows, and maintains configurable retention periods. These governance details belong in your DPIA risk analysis and mitigation section.
Once completed, a DPIA covering a specific processing pattern (e.g., game-based assessment for logistics roles) can generally be reused across materially similar deployments. Review it when assessment logic changes, when you add new tool features, or when you switch vendors.
If you're uncertain whether your current assessment setup meets the threshold, run through the checklist above and escalate to your DPO or legal counsel for a formal DPIA determination. Documentation costs far less than the alternative.
Usually yes. GDPR Article 35 requires a DPIA where processing is likely to result in a high risk to individuals. Assessments that systematically score candidates, profile personal aspects and determine who advances meet several of the EDPB's high-risk criteria at once. If two or more checklist questions are answered yes, treat a DPIA as required.
Before processing starts, so well before rollout. Article 35 speaks of an assessment prior to processing. In practice, start the DPIA as soon as a vendor is seriously considered, so its findings still shape the configuration and the contract.
No. The playful format does not change the processing. A game-based assessment still produces scored outputs and behavioral inferences that feed into selection decisions, so it falls under the same risk assessment as a traditional test.
They run in parallel. The DPIA is a GDPR obligation about the risks of data processing to individuals. The EU AI Act classifies AI systems for recruitment and selection as high-risk and adds documentation, transparency and human oversight requirements. Neither replaces the other, and vendor documentation typically serves both.
The HR process owner, the Data Protection Officer or privacy counsel, the assessment vendor, and IT and legal. HR defines purpose and necessity, the DPO leads the assessment, the vendor supplies processing descriptions and security controls, and IT and legal review data flows and contracts.