- Regulation (EU) 2016/679 — GDPR, Article 27
- Regulation (EU) 2024/1689 — AI Act, Annex III employment
- Directive 2019/1152 on transparent working conditions
Who has to appoint one
Providers established outside the Union offering recruitment or HR systems to employers in the EU. The employer is usually the controller and the vendor a processor, but any use of candidate data for model training or benchmarking makes the vendor a controller for that purpose and triggers its own obligations.
Thresholds and exemptions
No GDPR threshold. Under the AI Act, systems used to recruit, filter applications, evaluate candidates, allocate tasks or monitor performance are high-risk under Annex III, with obligations applying from 2 August 2026.
What must appear on the label
Not physical. The representative's identity in the privacy notice and in the contractual documentation given to employer customers. Where AI is used, candidates must be informed and the employer must be able to explain the logic involved.
Marketplace fields
EU employers ask for the AI Act classification, the transfer analysis and the representative in procurement, and works councils in Germany, Austria and the Netherlands frequently block deployment where the answers are unsatisfactory.
Documentation you must hold
Article 30 records, Article 28 processing terms, the Article 27 designation, a data protection impact assessment covering candidate profiling, retention rules distinguishing unsuccessful applicants from hires, and the transfer mechanism. For high-risk AI: technical documentation, risk management, data governance addressing bias, logging and the conformity assessment.
Standards and testing
Bias and accuracy evaluation is effectively required: the AI Act obliges providers to examine training data for bias and to declare accuracy levels, and discrimination law applies independently.
Language requirements
Candidate-facing information in the language of the applicants, and employer documentation in the language of the market.
When it applies
The representative before processing begins. AI Act high-risk obligations from 2 August 2026, with the employer as deployer also carrying duties including informing workers.
How long records are kept
Unsuccessful candidate data only as long as necessary, which several authorities interpret as six to twelve months absent a specific claim period. Indefinite talent pools without a basis are a recurring finding.
What happens if you do not comply
Up to €20 million or 4% of turnover under the GDPR, and up to €15 million or 3% under the AI Act for high-risk obligations. Discrimination claims run in parallel through national employment courts.
Who enforces it
Data protection authorities, AI Act market surveillance authorities, equality bodies and, in practice, works councils.
Where the boundary lies
Automated rejection without human involvement engages Article 22 GDPR, which restricts solely automated decisions with legal or similarly significant effects. Emotion inference in interviews is prohibited in the workplace context under Article 5 of the AI Act, so some products marketed today cannot lawfully be sold in the Union.
Questions we are asked
- We are only a processor for employers — do we need a representative?
- If you process candidate data of people in the Union and you have no EU establishment, yes. And any use of that data for your own purposes makes you a controller.
- Is CV screening high-risk?
- Filtering or ranking applications is listed in Annex III, so yes, with obligations from August 2026.
Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom