An employer trains an automated hiring screen on historical HR data and rejects EU candidates with no human review path, DPIA, or bias assessment, despite significant effects on applicants. Which GDPR-aware concern is most accurate?
Select an answer to reveal the explanation.
Short Explanation
If a model trained on yesterday's biases quietly rejects people with no appeal hatch, GDPR's automated-decision and fairness alarms should ring. Hiring AI is still personal-data processing with human stakes. Do the DPIA-level thinking and keep meaningful human oversight where required.
Full Explanation
Automated hiring screens process personal data and can produce legal or similarly significant effects under Art. 22, triggering restrictions and safeguards such as human intervention and contest rights unless an exception applies. Fairness, accuracy, transparency, and DPIA duties also bite when profiling or novel technologies pose high risk. CIPP/E expects GDPR-centric analysis of AI/ML in employment—not a substitute deep-dive into separate AI-governance certifications.