Data Protection Impact Assessment: summary
AI that helps evaluate job applicants needs a Data Protection Impact Assessment. Here is a summary of ours. Customers and their DPOs can request the full document.
What we assessed
BeCareers' AI-assisted first-stage screening of job applicants, and the GetMeHired.uk job board and employer dashboard. Employers are the controllers of their applicants' data and BeCareers is their processor. BeCareers is the controller of GetMeHired.uk candidate accounts.
Why a DPIA is needed
The processing uses new technology to evaluate job applicants, at scale, and can feed into decisions that significantly affect people - including knock-out rules that employers set. UK GDPR requires a DPIA for processing like this.
How the processing works
Applicants apply through GetMeHired.uk or an employer's careers site. Their CV is read against the employer's criteria and they complete a short screening conversation, in their own language, conducted by BeCareers' own AI models hosted on AWS in London. The employer receives a transcript, a summary and a score. People at the employer make every hiring decision. Data is held in the UK and deleted at the end of the retention period - 180 days by default.
Safeguards in place
- AI output is advisory; people make hiring decisions. Any knock-out rules are set by the employer.
- Only what the applicant submits and says is used - no social media or public-profile analysis.
- Every result records the AI model and rubric that produced it; results with no identified model are flagged for human review.
- A tamper-evident audit trail records every change to an application, who made it and why.
- UK hosting, role-based access control, multi-factor authentication available for every user, and automated tests that block changes bypassing these controls.
- Built-in tools to export and erase an applicant's data, record consent and apply retention automatically.
- No AI model has been trained on personal data. Any future use of anonymised screening data needs the customer's authorisation and a documented anonymisation standard.
Main risks and actions
The assessment identified 19 risks, each with an action and an owner. The most significant areas are:
- Automated knock-out decisions - applicants must be told about them and be able to ask a person to review the outcome.
- Bias in AI screening - job-related criteria, the same questions for everyone, and monitoring of outcomes.
- Erasure and retention - making sure deletion covers every copy of screening data.
- Access security and independent testing - hardening access controls and commissioning an external penetration test.
With the priority actions completed, we do not expect any residual risk to remain high, and prior consultation with the ICO should not be needed. We review the DPIA at least every six months, and whenever the processing changes.
Request the full DPIA
For customers, prospective customers and their DPOs or procurement teams. We will send the full assessment - data flows, lawful basis, risk register and action plan.