1 Identify the need for a DPIA
Recruitment-related processing using AI for ranking, profiling, or automated decision-making is high-risk processing under both UK GDPR Article 35 and the EU AI Act Annex III §4. A DPIA is required.
Project / processing name
e.g. "Implementing Vault Hire for our 2026 graduate recruitment cohort"
________________________________________________________________
Date assessment started
________________________________________________________________
DPIA owner (name & role)
________________________________________________________________
Reviewed by Data Protection Officer? (Y/N) — if Y, name & date
________________________________________________________________
2 Describe the processing
2.1 Nature, scope, context, purpose
Pre-filled (Vault Hire side): Vault Hire is an applicant-tracking platform for regulated hiring. The candidate creates a vault containing their employment history, qualifications, references and (optionally) regulated identifiers (as a salted hash only — never raw). The deployer uses this data to recruit for specific roles.
Add: your-specific scope & volume
e.g. roles in scope, expected candidate volume per quarter, integrations with your HRIS, retention periods you require.
________________________________________________________________
2.2 Data flows
Pre-filled: Candidate → Vault Hire (encrypted in transit). Vault Hire → Anthropic (only AI features; prompt excludes name/email/phone/address). Vault Hire → Deployer (only after candidate consent). Deployer → its own HRIS (only after offer accepted). Full schema diff & sub-processor list available via /legal/sub-processors.html.
2.3 AI features in scope (tick all that apply)
See IfU §2. Vault Hire allows the deployer to disable AI globally, per workflow, or per candidate via the AI Controls panel.
- □ Candidate AI Profile generation
- □ AI Job Description writer
- □ AI Compliance Response
- □ AI PM Summary
- □ AI Candidate overview for recruiters
3 Consultation
Internal stakeholders consulted (name, role, date)
e.g. CHRO, CIO, CISO, Head of Recruitment, DPO, Legal.
________________________________________________________________
External stakeholders consulted (e.g. unions, employee reps)
________________________________________________________________
Have you informed potential data subjects (candidates) about this processing? How?
e.g. updated careers-site privacy notice, applicant pack, employee privacy notice.
________________________________________________________________
4 Assess necessity & proportionality
4.1 Lawful basis
For most recruitment processing the lawful basis is Article 6(1)(b) (necessary for steps prior to entering into a contract) and/or (f) (legitimate interest, balanced). For AI features, the candidate's explicit Article 6(1)(a) consent is captured by Vault Hire on first use.
Your lawful basis for the processing (Art. 6)
________________________________________________________________
If special category data — your Article 9 condition
________________________________________________________________
4.2 Necessity
Why this processing is necessary for your hiring purpose. Could the purpose be achieved with less data?
________________________________________________________________
4.3 Proportionality
Pre-filled: Vault Hire is architecturally minimal — it stores a salted hash of regulated identifiers rather than the identifier itself, and isolates AI inputs from any ranking mechanism. This makes the processing more proportionate than most alternatives.
Your assessment of proportionality given your candidate volume + risk profile
________________________________________________________________
5 Identify risks to individuals
| Risk | Likelihood (L / M / H) | Severity (L / M / H) |
|---|---|---|
| Bias in AI-derived candidate profile producing discriminatory shortlist | ____ | ____ |
| Personal-data breach via Vault Hire or sub-processor | ____ | ____ |
| Unauthorised access by employer staff outside the hiring team | ____ | ____ |
| Inaccurate AI output influencing a hiring decision | ____ | ____ |
| Candidate unable to exercise Article 22 opt-out effectively | ____ | ____ |
| Inappropriate retention of unsuccessful-candidate data | ____ | ____ |
| Cross-border transfer to a non-adequate jurisdiction | ____ | ____ |
Additional risks specific to your deployment
________________________________________________________________
6 Identify measures to reduce risk
The following measures are built into Vault Hire — your DPIA can cite them directly:
- AI-input PII exclusion (full name / email / phone / address never sent to model providers) — verified by automated test.
- Per-tenant + per-data-subject AI opt-out honoured at the request boundary (see IfU §5).
- Audit log with 6-year retention covering every access to personal data.
- Sub-processors operating under EU SCCs / UK IDTA, no-training contractual terms.
- Right-to-erasure (Article 17) workflow accessible to every Data Subject from their own Settings panel.
- Tamper-evident audit log of every AI inference.
- Mandatory human-in-the-loop on every AI output (candidate & recruiter approval steps).
Additional measures you will deploy
e.g. quarterly access review, manager training on AI-output review, calibration sessions for hiring panels.
________________________________________________________________
7 Sign off & record outcomes
| Question | Answer |
|---|---|
| Residual risk: high? | □ Yes (consult supervisory authority) □ No |
| DPO advice (where applicable) | __________________________ |
| DPIA approved by | __________________________ |
| Date of approval | __________________________ |
| Date of next review | __________________________ |
8 EU AI Act Article 27 supplement (Fundamental Rights Impact Assessment)
Where you deploy Vault Hire in the EU and use any AI feature, Article 27 of the EU AI Act requires a Fundamental Rights Impact Assessment. Complete the following in addition to the GDPR DPIA above:
8.1 Description of the deployer's intended use within the scope of the high-risk AI system
Pre-filled context: recruitment ranking / shortlisting / profiling is Annex III §4. Cite which workflows you have enabled.
________________________________________________________________
8.2 Description of the period and frequency of use
________________________________________________________________
8.3 Categories of natural persons / groups likely to be affected
________________________________________________________________
8.4 Specific risks of harm likely to impact the persons / groups identified in 8.3
Consider age, sex, gender, ethnicity, disability, socio-economic background, geography.
________________________________________________________________
8.5 Implementation of human oversight measures (per IfU §5)
________________________________________________________________
8.6 Measures to be taken if risks materialise — incident response, complaint mechanism, escalation route
________________________________________________________________
Notify the EU AI Office
If your FRIA identifies risks that are likely to occur in practice, you must notify the relevant market surveillance authority under Article 26(5). Vault Hire is happy to assist with that notification on your written request.
DPIA owner
Name
Role · date
Approved by (DPO or senior accountable)
Name
Role · date