Welcome back

Sign in to your screening dashboard

New to HireQwik? Book a demo

Book a demo

Tell us a little about your hiring — we'll reply within one business day.

Prefer email? interview@hireqwik.in
compliancehr-techindiarecruiting

France's Privacy Regulator Is Auditing Recruitment AI in 2026. Here's What It's Actually Checking For.

HireQwik August 4, 2026 4 min read

France’s Privacy Regulator Is Auditing Recruitment AI in 2026. Here’s What It’s Actually Checking For.

France’s data protection authority, the CNIL, has named recruitment one of its priority control themes for 2026. That’s not a routine inspection sweep. It’s a deliberate follow-up: three years after the CNIL published its January 2023 guide on recruitment data, a 19-sheet reference document covering everything from candidate profiling to discrimination screening, the regulator is now checking whether large companies and recruitment firms, the ones processing the highest applicant volumes, actually did what the guide told them to. The controls target three things specifically: automated decision-making systems, candidate information, and data retention periods. If your screening pipeline touches a French entity’s hiring, all three land directly on an AI voice or resume-scoring tool.

Two obligations, not one

Most compliance conversations Indian teams have been having this year collapse into a single question: does the EU AI Act apply, and if so, what’s the documentation checklist. France adds a second, older layer on top of that one. Article L1221-8 of the French Code du travail requires that a candidate be expressly informed, before it’s used against them, of any recruitment assistance method or evaluation technique, and that method has to be relevant to the job in question, not a generic scoring pass. Article L1221-9 goes further: no information about a candidate can be collected through a device or process that wasn’t disclosed to them beforehand. Layer GDPR Article 22 on top, and an AI-scored screening decision counts as automated decision-making, which means a rejected candidate has a standing right to demand human review and an explanation of how the system reached its verdict.

None of that is new law. What’s new for 2026 is that CNIL is actively going out and checking whether companies built those rights into their process, rather than waiting for a candidate complaint to trigger an investigation. And CNIL’s role in this space just got broader: as of 2025 it holds four distinct functions under the EU AI Act framework, including acting as the market surveillance authority for a significant share of high-risk AI systems, with employment and biometrics named specifically as areas within its remit. A screening tool that’s fully EU AI Act-documented but skipped the Article L1221-8 disclosure or the Article 22 human-review pathway isn’t halfway compliant in France. It’s failing the specific thing CNIL said it would check for this year.

Where India’s GCCs carry the exposure

France runs a substantial Global Capability Centre relationship with India, and not only through IT-services names. Schneider Electric’s Bengaluru centre does product design, R&D, and IoT engineering work for the group globally. Société Générale has run banking, insurance, and investment-management operations out of Bengaluru and Chennai since 2000. Sanofi operates GCC capacity in India as part of its broader European footprint. Any of these centres that builds, configures, or operates recruiting or screening technology used to fill roles inside the French parent is squarely inside CNIL’s remit for that hiring decision, regardless of which country wrote the code or hosts the servers. The 2026 controls are aimed at “large companies,” and a French multinational with an India-run recruitment pipeline is exactly that scale.

What actually needs to change

The practical fix here is narrower than a full compliance program: a disclosure statement candidates see before an AI screen begins, naming the method and its relevance to the role; a working, not theoretical, path for a rejected candidate to request human review of an automated decision; and a defined, disclosed retention period for interview data and scores rather than an indefinite hold. None of that requires a French stakeholder to co-design the tool the way a works-council consent process would. It requires the tool itself to expose those three things by default, because CNIL’s stated 2026 checklist is exactly those three things.

The honest limit

This applies specifically to hiring decisions inside French entities, and CNIL’s audit focus this year is explicitly on large-volume recruiters, not every employer with a handful of open roles. It also doesn’t replace the EU AI Act’s separate high-risk documentation requirements; the two obligations run in parallel; satisfying one doesn’t excuse the other. But for any India GCC running screening technology into a French hiring pipeline, the CNIL’s 2026 priority list is about as direct a signal as a regulator gives before it starts making calls.

The take

Most AI-hiring compliance work in India right now is being built around the EU AI Act’s August 2026 deadline, and that’s the right instinct. France is the reminder that the deadline isn’t the only clock running. CNIL told the market in plain language what it’s checking for this year, and automated decision-making, candidate disclosure, and retention limits are not new obligations, they’re three-year-old ones the regulator is now confirming got implemented.

If your team is running screening technology into a French entity’s hiring pipeline and wants a straight read on whether it clears CNIL’s 2026 checklist, talk to us.

Sources: Les contrôles en 2026 : recrutement, répertoire électoral unique et fédérations sportives — CNIL, Le guide du recrutement — CNIL, Article L1221-8 - Code du travail — Légifrance

See HireQwik in action

Book a 30-minute demo — bring a live JD and we'll screen your own candidates against it.