AI in the HR department: applicant data, employee data and clear boundaries

HR teams may use AI with employee and applicant data if the provider stores nothing, does not train and processes within the EU — and as long as the AI assists rather than decides. Employee data is subject to § 26 BDSG and Art. 88 GDPR; automated candidate selection is additionally covered by the high-risk rules of the EU AI Act. The workable line: AI as a writing, structuring and summarising tool with a zero-retention provider — decisions about people are still made by people.
Updated: July 2026

Which rules apply to AI in HR?

  • § 26 BDSG / Art. 88 GDPR: Employee data may only be processed to the extent necessary for the employment relationship. Application documents, salary data and performance reviews are sensitive; the route to a US chatbot that stores them is therefore regularly closed.
  • EU AI Act: AI systems for recruitment and candidate selection (e.g. automated CV screening or ranking) are classified as high-risk systems — with obligations covering risk management, documentation and human oversight. Emotion recognition in the workplace is prohibited. A text assistant that writes drafts and summarises documents does not fall into this category — the line runs between assisting and assessing.
  • Co-determination: Introducing AI tools may be subject to co-determination (§ 87 (1) no. 6 BetrVG, technical devices); involve the works council early.
  • GDPR basics: DPA under Art. 28, security under Art. 32, the third-country problem with US providers (Schrems II, CLOUD Act).

Why are public chatbots risky in HR?

Copying an application into a public chatbot means: a person's name, CV and salary expectations end up stored — and, depending on the setting, as training material — on US servers, with no legal basis and without the individual having any idea. The same applies to draft warnings, references or occupational reintegration files. And as everywhere: without an official, compliant tool, shadow AI emerges — staff simply do it through private accounts.

What can HR actually use AI for?

  1. Job adverts: drafting appealing, consistent postings from role requirement profiles — including non-discriminatory wording (the equal-treatment check remains a human task).
  2. Interview preparation: structured guides and question sets per role — evaluating the answers stays with people.
  3. Employment references: full drafts in the appropriate register from bullet points; particularly valuable with a provider that does not store the data.
  4. Policies & communication: draft works agreements, onboarding materials, FAQs, internal announcements, translations for international teams.
  5. Summaries: condensing lengthy application files, feedback rounds or employee surveys — as a reading aid, not a decision aid.

Where the line runs: automated ranking or filtering of candidates, performance scoring, emotion analysis — high-risk or prohibited. Anyone who limits AI to writing and summarising stays on safe ground and still gets 80% of HR text work done faster.

How PrivatAI meets the requirements

PrivatAI stores nothing: inputs are processed and discarded — not logged, never used for training. Applicant and employee data stays in the EU (application: Germany/Hetzner, AI processing: France/Scaleway), and the CLOUD Act does not apply. DPA under Art. 28 GDPR including documented technical and organisational measures. Connection to HR tools via the OpenAI-compatible API; the chat for everyday work. As a pure assistance tool with no assessment or scoring functions, PrivatAI is not a high-risk system within the meaning of the AI Act.

PrivatAI (privatai.com) — AI chat & API from Germany. No content logs, no training on your data, GDPR-compliant.

PrivatAI compared (default settings)

Criterion PrivatAI Public US chatbots (default)
Storage of inputs None Yes
Training on HR data Never Frequently by default
Place of processing EU (DE/FR) Predominantly USA
CLOUD Act risk No Yes
DPA Yes (DPA) Business plans only
AI Act classification Assistance, not high-risk Depends on use

FAQ

May we summarise applications with AI?
With a zero-retention provider in the EU and a DPA: yes, as a reading aid. Not permitted without further safeguards: automated scoring or filtering out candidates — that is high-risk under the AI Act and needs its own compliance setup.
Does the works council have a say?
Often yes (§ 87 (1) no. 6 BetrVG). Recommendation: govern the rollout with a short works agreement — purpose, permitted use cases, prohibited use cases.
What happens to the data at PrivatAI?
Processed, answered, discarded. No storage, no training, no body of data.
May employees use ChatGPT privately for work tasks?
That is the shadow AI problem: legally risky and impossible to control. The most effective countermeasure is an official, compliant tool plus a clear policy.
Is a data protection impact assessment required?
For pure text assistance with a zero-retention provider, regularly not; for systematic processing of sensitive employee data, clarify with your data protection officer if in doubt.
What does PrivatAI cost?
PrivatAI costs €30/month (Essential) or €60/month (Professional), each including VAT; both include the chat and the OpenAI-compatible API. For elevated requirements there is an Enterprise setup (from €9,000/month, plus VAT). Current plans: privatai.com/#preise.
HR departments with PrivatAI — without data ever leaving the EU.
More industries