Data Governance & the EU AI Act: What CPOs Must Know
This is the pillar HR functions underestimate most, and the one carrying the heaviest weight in the Index. Employment is a named high-risk domain, which means the obligations are specific rather than aspirational.
Why most HR AI counts as high-risk
The EU AI Act classifies AI used in employment and worker management as high-risk: recruitment and selection, decisions on promotion or termination, task allocation, and monitoring or evaluating performance and behaviour.
That classification does not depend on how sophisticated the tool is. A screening filter inside an ATS can fall in scope while a general drafting assistant does not. The question is what the output is used to decide.
Key obligations
For high-risk systems the duties sit across the provider and the organisation deploying them. As a deployer, HR carries a real share.
- Risk management: identify and document foreseeable harms, including discrimination.
- Data governance: relevant, representative training and input data, with known limitations.
- Human oversight: a named person who can understand, override and stop the system.
- Transparency: tell workers and their representatives when a high-risk system is used on them.
- Record keeping: logs, technical documentation and evidence of monitoring in use.
How GDPR interacts
GDPR has not gone anywhere, and in the employment context it is often the sharper instrument. Consent is rarely a valid basis between employer and employee because of the power imbalance, so you need a defensible legitimate-interest or contractual basis and a completed DPIA.
Article 22 also matters: individuals have rights where a decision is made solely by automated means with legal or similarly significant effects. Keep a meaningful human in the loop, and be able to show what that human actually did.
Building an HR AI governance framework
A workable framework is short and owned, not long and unread.
- An inventory of every AI system touching employment decisions, with its risk classification.
- A clear policy on acceptable use, including what must never be pasted into a public tool.
- Vendor due diligence questions covering training data, bias testing, logging and documentation.
- Named roles: business owner, data protection contact, and the person who can switch it off.
- A bias testing and review cadence with results recorded.
Timeline and why acting now matters
Obligations phase in over several years, with high-risk employment duties among the later stages — but the preparation work is slow. Building an inventory, renegotiating vendor terms and agreeing oversight with works councils takes quarters, not weeks.
Penalties are significant, and reputationally an unexplainable hiring decision is costly well before any regulator becomes involved.
How the Index scores this pillar
Data Governance & Legal Compliance carries 20% of your composite score — the heaviest weighting — across five questions on GDPR practice, AI Act classification, DPIAs, bias and transparency, and data subject rights.
See where you actually stand
The assessment takes about 25 minutes, scores you across all six pillars and gives you a peer benchmark and a set of things worth exploring.
Start your assessmentRelated pillars
- Pillar 2 — People Data & AnalyticsThe data estate these obligations apply to.
- Pillar 3 — AI Adoption, Value & OperationsThe systems most likely to fall in scope.
- Pillar 6 — Leadership & the CPOWhere accountability for all of this ultimately sits.