ARTIFICIAL INTELLIGENCE IN RECRUITMENT: PERSONAL DATA PROTECTION
Artificial intelligence (Artificial intelligence, hereinafter – AI) is no longer just science fiction. As the European Commission has correctly noted, it is a part of our lives – from virtual assistants for organizing daily tasks to smartphone applications that suggest songs according to each of our individual tastes.1
On a global scale, the impact of AI is felt in many sectors, including recruitment. AI is widely used to facilitate the recruitment process, for example, for automated screening of candidates’ social networks or AI-driven video interviews where facial expressions can be analyzed. Although the use of AI in recruitment is not yet a widespread phenomenon in Latvia, given Latvia’s narrow recruitment market as well as other reasons, it is valuable to follow global trends.2 AI tools can be extremely effective, helping companies save both money and time. This is especially true for global corporations. Jobvite – a company offering AI solutions – has indicated that in large companies, more than 250 applications are submitted for a standard competitive employee position, and approximately 65% of them are left ignored.3 Illustratively, Unilever operates in 190 countries worldwide, where it hires more than 30,000 employees annually and processes approximately 1.8 million job applications. The use of AI tools in such and, consequently, smaller-scale situations undoubtedly facilitates the review of applications and helps select the best talent whose applications might otherwise remain buried in a pile of CVs.4
THE ESSENCE OF AI
Before turning to the aspects of recruitment, it is essential to define the concept of AI. 1956. In 1956, John McCarthy (John McCarthy), a professor of mathematics at Dartmouth College, defined AI as every aspect of learning or any other feature of intelligence which can in principle be so precisely described that a machine can be made to simulate it. Today, many definitions of AI exist; however, it is generally considered that AI systems are capable of collecting, processing, interpreting, and learning from external data to achieve specific goals.5
In order for AI algorithms to learn and progress, they require a large volume of information. The Norwegian Data Protection Authority states that most AI tools require a massive amount of data to learn and make informed decisions.6 Namely, regarding AI, the saying “less is more” (less is more) is not applicable; therefore, companies using AI need to collect, store, and process a large volume of data, including personal data. Inevitably, this has sparked discussions about personal data protection.7
It is essential to understand how AI works and what its characteristics are to prevent problems related to potential deficiencies and errors regarding the possible discrimination of less protected groups. Law professor Shlomit Yanisky-Ravid (Shlomit Yanisky-Ravid) highlights ten important characteristics of AI:
1) autonomy and independence (AI is capable of independently performing high-level tasks);
2) unpredictability and the ability to achieve new results (AI finds various paths to optimal solutions);
3) creativity (AI is capable of creating new and original works, such as paintings or songs, rather than just copying existing ones);
4) ability to communicate with external data (AI “searches” for external data);
5) ability to learn (AI improves results by learning from feedback);
6) evolution (AI consistently finds new patterns and similarities, thereby changing results);
7) rationally intelligent system (AI analyzes data and decides which actions would increase the probability of success);
8) efficiency (AI is capable of accurately and efficiently processing large amounts of data);
9) “free choice” (AI has the possibility to choose between alternatives);
10) goal-oriented (functions based on specific goals).8
These AI properties demonstrate that AI tools are “independent,” and often even the creators of these systems are unable to explain the process that led to a specific AI decision. However, this does not mean that algorithms are “immune” to the subjectivity so familiar to humans. Given that AI is not excluded from the scope of the General Data Protection Regulation (hereinafter – GDPR), the aforementioned characteristics are essential for understanding the impact of the GDPR on AI applications. For example, Article 22 of the GDPR regulates automated decision-making, including profiling, and stipulates that the data controller must implement suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests – at least the right to obtain human intervention on the part of the controller – so that the data subject can express their point of view and contest the decision. Given the lack of transparency in AI decisions, several questions arise. Who will take responsibility in situations where things “go wrong”? Can AI tools be held accountable if they are independent? How can a company explain decisions made by AI if the system operates autonomously? Would an explanation of the AI’s operating principles be considered sufficient, rather than how the specific decision regarding the individual was reached?9
THE RIGHT TO PRIVACY IN THE WORKPLACE
Unlike the United States, where each case is assessed individually and the employer’s right to control employees is much greater,10 the concept of privacy in Europe also applies to the workplace and the recruitment process. Namely, the Article 29 Working Party11 has stated that workers do not abandon their right to privacy and data protection every morning at the workplace door. Employees have a legitimate expectation of a certain degree of privacy in the workplace, as a significant portion of relationships with fellow human beings is formed precisely at the workplace.12 This principle does not lose its force even in situations where the employer provides communication devices.
For example, in the European Court of Human Rights case “Bărbulescu v. Romania,” the applicant worked for a private company in Romania as a sales engineer. At the employer’s request, he created a Yahoo Messenger account for work purposes – namely, to answer client inquiries. As an employee, he signed an agreement to comply with internal regulations prohibiting the use of work computers and the internet for private purposes; however, the applicant did not comply with the internal regulations and used the aforementioned Yahoo Messenger account to communicate with family members. The employer conducted an internal investigation, after which the applicant’s employment was terminated because the investigation revealed the personal and sometimes even intimate content of the messages. The Grand Chamber of the European Court of Human Rights held that the applicant’s privacy was violated and that the Romanian national courts failed to strike a fair balance between the employee’s right to privacy and the employer’s rights. Namely, the Romanian courts had not considered the fact that the employee had not been sufficiently informed about the nature and extent of the monitoring. Furthermore, it was not clearly indicated that the employer had access to the actual content of the correspondence, rather than just the metadata. This decision of the European Court of Human Rights does not mean that employers may never monitor employees’ electronic communications or terminate employment if an employee uses the internet for private purposes during working hours. However, if an employer takes measures to monitor employees’ electronic correspondence, these measures must be appropriate and proportionate.13 Consequently, it can also be concluded that the right to privacy of employees and candidates means, among other things, that the GDPR applies to them, as well as the personal data protection principles that will be discussed further in this article.
AI APPLICATION IN RECRUITMENT
The most common reasons why employers choose to use AI tools are saving time resources, reducing costs, the desire to improve the competence of hired employees, and promoting diversity within the company.14
The application of AI tools can be diverse. For example, in the early stages of recruitment, AI tools can create job advertisements and analyze where and how to place them to make them as attractive as possible to a specific audience. After the application process concludes, AI tools can help employers automatically rank candidates by priority, review, or even disqualify unsuitable candidates. Employers can also use AI tools to connect candidates with chatbots (Chat Box), etc. Currently, AI tools rarely make completely independent decisions about hiring employees; however, they are quite often used in automating rejections.15
Technology-driven companies offer a wide range of services. For example:
– HireVue offers facial feature analysis software that analyzes the applicant’s facial expressions, revealing their enthusiasm for the vacancy during a virtual interview. The algorithm analyzes candidates’ expressions and gestures and compares them with data available in a database consisting of more than 25,000 units of information (e.g., voice tone, vocabulary usage, chin lift, smile, eyebrow raising, lip tightening, etc.). The database compiles data from previous “success stories,” and HireVue indicates that this AI tool can speed up the recruitment process by 90%. Approximately 700 companies worldwide have used this opportunity, including well-known companies such as Vodafone, Delta, PwC, Hilton, and Urban Outfitters;16
– Mya is an advanced AI chatbot that communicates with candidates and analyzes their responses;17
– Textio Hire helps companies evaluate how competitive and attractive a job vacancy sounds to potential employees, offering better alternatives. Meanwhile, Textio Flow helps create job advertisements based on phrases and keywords that would appeal to the specific target audience;18
– Entelo helps “lure” the best employees away from competitors. This AI tool predicts the likelihood that an employee wants to change their workplace. For example, it analyzes whether a person has recently updated their LinkedIn profile, and also takes into account general trends in the respective company and field by analyzing factors such as employee turnover in a specific company, collective redundancies, stock market fluctuations, mergers and acquisitions, and other factors;19
– DeepSense analyzes the personality traits of potential employees. Given that most members of society have a certain level of virtual presence, DeepSense utilizes this fact and compiles information from more than 30 social networks. With the help of such a “digital fingerprint,” the company offers answers to questions that often interest employers, such as alcohol and drug use habits, political or religious fanaticism, risks of sexual harassment, etc.20
IMPACT OF THE GDPR
Although the use of AI in recruitment is generally quite effective, the negative consequences of using these tools (e.g., automatic rejections) are felt more heavily by minorities and less protected groups, as the results provided by AI are not always 100% accurate for them. Given that AI learns from the dataset at its disposal, the characteristics of this set also affect the final result. If the initial data is not sufficiently diverse and objective, the final result will also be subjective. For example, the results provided by the AI algorithm used by LinkedIn demonstrated that men were more frequently shown notifications for well-paid high-level jobs than women. This is explained by the fact that initially, such positions were predominantly searched for by men, while women, for various reasons (e.g., low professional self-esteem), did not apply for such job positions.21
A similar situation occurred at Amazon, which introduced an experimental AI tool to evaluate candidates based on their suitability for a position on a scale of one to five. However, in 2015, Amazon discovered that regarding technical positions, the AI tool had not evaluated candidates’ gender in a neutral manner. Based on the male dominance in the industry, the AI learned to “discard” women’s CVs and also downgraded a candidate’s rating if it seemed that the graduate came from an educational institution that was too “feminine” or had a high proportion of women.22
Although many employers state that AI tools help promote diversity in the company, in certain situations, this claim is also questionable. If an AI tool relies on data about candidates selected in the past, it means that in the future, employers are likely to hire candidates similar to those previously considered suitable.23 For example, the IT industry is generally dominated by white men, and the proportion of women in this sector in the European Union is only 17%.24 Accordingly, if an AI tool relies on this data, it becomes biased; namely, it is better suited to recognize traits possessed by white men, leaving women and representatives of other skin colors in a less favorable situation, which could be particularly relevant during a video interview.
It is also worth remembering that the developers of AI algorithms are most often men. This means there is also a risk of subconscious subjectivity, with system developers promoting biases without even realizing it.25 One solution to mitigate these risks is to increase diversity in AI algorithm development groups. Diverse groups tend to find better and more comprehensive solutions, and research in this field shows that scientific articles co-authored by women cover a wider range of issues, including aspects of gender neutrality and fairness.26
According to the GDPR, companies must comply with the principle of accuracy, which stipulates that personal data must be accurate and, where necessary, kept up to date; however, in this case, the accuracy of the conclusions sparks discussion. For example, if an AI tool expects a successful candidate to smile a lot and maintain eye contact during a video interview, it may negatively evaluate people from other cultures where different social norms prevail. A practical example can be found where people of Asian descent had problems using smart phone cameras because, when posing for photos, the cameras failed to perceive their gaze and assumed their eyes were closed;27 consequently, it is considered that this group of persons may be placed at a disadvantage during video interviews. Finally, it must be noted that often the meaning of specific facial expressions is not unambiguous. Namely, there is a possibility for AI to make mistakes, for example, by incorrectly interpreting whether an individual is dissatisfied with a question or feels physically unwell due to a cold room, stomach ache, or other reasons.28
The accuracy of AI tools is improved by data diversity and volume. At the same time, this can potentially create a conflict with the principle of data minimization, which stipulates that personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed. Can it be considered that in order to hire an employee, all information available about the person on the internet or a detailed analysis of facial expressions is needed?
According to the principle of purpose limitation, personal data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes. Meanwhile, the principle of storage limitation provides that personal data must be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. Regarding video interviews, it is considered that the processing of personal data has several purposes. Firstly, personal data is needed to analyze the candidate, and secondly, after the interview process concludes, the data is needed for database maintenance so that the AI tool is capable of learning and improving. A contradiction to the aforementioned is found in Article 17 of the GDPR, which provides for the right to erasure or the “right to be forgotten.” Is it possible for a person to exercise this right in such a case if the data continues to be needed? Furthermore, what does the right to be erased mean in this case? For example, the Article 29 Working Party indicated that the destruction of hardware would likely not be considered erasure under the GDPR.29 Meanwhile, the Austrian data supervisor indicates that companies have some flexibility regarding the technical means and methods used for data erasure, including anonymization.30
According to the principles of lawfulness, fairness, and transparency, personal data must be processed lawfully, fairly, and in a transparent manner in relation to the applicant. The processing of personal data is lawful only if it has a legal basis under Article 6 of the GDPR (e.g., consent or legitimate interests).31 Processing must be transparent to applicants; namely, applicants must be informed about what type of personal data is being collected, by what means it is done, how the data will be used, etc. In the field of recruitment, transparency requirements apply throughout the entire period of personal data processing, including the recruitment stage.32 Information must be clear, in understandable language, and easily accessible to potential employees.
Social media screening is a widespread practice among employers worldwide. For example, a 2017 survey by CareerBuilder shows that 70% of employers in the United States check potential employees’ social networks, and 54% of employers have rejected an applicant based on content discovered on social networks.33 Similarly, a 2017 survey by YouGov shows that 36% of UK employers have rejected an applicant based on information found on their social media profiles. As a reason for rejection, employers also mention the excessive posting of self-portraits or “selfies,” not just commonly cited reasons.34 It should be noted that discovering seemingly inappropriate content is not difficult at all. For example, a 2008 study found that approximately 50% of students’ social media profiles show photos indicating parties with alcohol consumption.35
For every employer, not only the employee’s knowledge and qualifications are important, but also their personality and ability to fit into the team. The demand for researching such qualities has created a supply, and companies like DeepSense use AI solutions to analyze and predict a candidate’s personality. Based on an email address, this AI tool characterizes the candidate using data available on the internet and compiling information about the applicant from more than 30 social networking sites. The characterization includes an analysis of tendencies to use alcohol and drugs, religious fanaticism, inclinations toward sexual harassment, etc.36 Although there could undoubtedly be a demand for such candidate characterizations among employers, such an approach could contradict the European understanding of privacy. According to default settings or user preferences, many social media profiles are publicly viewable; however, employers in the European Union cannot use this information for their own purposes and at their own discretion. The processing of such personal data also requires a legal basis, such as consent or legitimate interests. To determine whether legitimate interests can serve as an appropriate legal basis, it is necessary to balance and weigh them against the interests and freedoms of the data subject that require protection. Thus, before evaluating social networks, a potential employer must assess the purpose of the social network – namely, whether the candidate’s profile was created for business and employment or private purposes.37 It is likely that a candidate’s LinkedIn profile is intended for business needs, while an Instagram profile is intended for personal purposes and use. Thus, services provided by companies like DeepSense could be in conflict with GDPR requirements.
Furthermore, the decision on the legal basis for personal data processing must be made by the company before the processing begins. The legal basis cannot be determined retroactively. Although the desire of potential employers to justify social media monitoring based on the need to conclude a contract is understandable, concluding a contract is not an appropriate legal basis, as according to the opinion of the Article 29 Working Party, this concept must be interpreted strictly. Processing must be truly necessary to perform the contract with the data subject. In the context of human resources, this legal basis can be used, for example, to process bank account data necessary for salary transfers.38 Furthermore, before collecting this type of information, it must be determined whether an excessive amount of personal data is being collected and whether this data is truly necessary to evaluate the candidate’s suitability for the specific vacancy. Social media screening is possible only if it is necessary to assess clearly predefined risks associated with the specific position, and if a legal basis exists and the applicant is properly informed of such screening (e.g., through a job advertisement).39
Finally, no matter how revolutionary the GDPR may sound, technology and legislation are never on the same level, as the legislator always follows in the footsteps of technological solutions,40 creating extensive discussions about the application of the regulatory framework.
SEARCH BLOG
SEARCH BY TOPICS
Was this useful? Share this article!
ANNA BOGDANOVA
ASSOCIATE
As an Associate and certified personal data protection specialist, Anna specializes in European Union law, personal data protection, and information technology issues. Anna is included in the list of data protection specialists maintained by the Data State Inspectorate, and she also holds a CIPP/E certificate, confirming that Anna is a Certified Information Privacy Professional. On a daily basis, Anna conducts data audits, develops internal documentation on personal data processing issues, trains organization employees, and advises clients on various data protection and information technology matters.