The Legal Landscape
GDPR (in force since 2018) and the EU AI Act (in force since August 2024). Scope, timeline, who carries the risk — and the €35m / 7% turnover ceiling.
Your team is already inside a legal framework. The EU AI Act names recruitment as high-risk. Parts of it are already in force; the rest lands in August 2026. This is a calm, practical session that tells your TA team what's active now, what's coming, and exactly what to do at the desk.
or 7% of global annual turnover — whichever is higher. The penalty ceiling for non-compliance under the EU AI Act.
I run this training privately for whole talent acquisition teams who want a shared baseline — and as an open-cohort session for individual recruiters and TA leads who want to send one or two people, not the whole department. Either works. Both are live, facilitated, and built for people who actually open candidate profiles.
GDPR (in force since 2018) and the EU AI Act (in force since August 2024). Scope, timeline, who carries the risk — and the €35m / 7% turnover ceiling.
Lawful bases, data minimisation, special category data, retention periods, and what your privacy notice actually needs to say.
What's prohibited (emotion recognition, banned Feb 2025), what's high-risk, and what must be in place before deploying any AI screening tool.
Article 14 requires genuine oversight — not rubber-stamping AI recommendations. Automation bias and the CJEU SCHUFA ruling.
Subject Access Requests, the right to an explanation of AI decisions, retention and deletion obligations, and the Dun & Bradstreet ruling (2025).
A daily compliance checklist from job brief to rejection — plus a group case study with multiple compliance failures to debug live.
A working summary of what the training covers. Tick things off as you confirm them with your DPO, ATS vendor, or legal team. Nothing is saved or sent — your boxes live in your browser session only.
GDPR & EU AI Act for TA teams hiring in the EU and U.K.
The EU AI Act obligations (Art. 26, Art. 12) do not apply to U.K. hires by their own force. If your company is EU-based, both laws apply through your establishment. The GDPR obligations apply regardless via UK GDPR.
Tell me your team size and whether you'd like the whole team in one room or a couple of seats in the next open cohort. I'll send dates within a working day.
Built from official EU legal sources. Does not constitute legal advice — consult your DPO and legal team before acting on any content.