UAE PDPL Article 18: AI Recruitment Checklist
If AI can filter, score, or reject a candidate, I treat it as in scope from day one. Under the UAE PDPL, that means I need four things before go-live: clear notice, a lawful basis or explicit consent where needed, human review before a final hiring outcome, and records that show what happened.
This article boils the job down to a short go-live test for hiring teams in the UAE. It covers where Article 18 hits AI-led recruitment, when Article 21 pushes me to run a DPIA, how I split duties across HR, Legal, and IT, and what I need to log if a candidate questions a decision later.
At a glance, I check:
- Notice: the recruitment privacy notice says where AI is used, in English and Arabic
- Consent: separate consent for CV ranking, interview recording and scoring, and talent-pool retention where used
- Lawful basis: each AI step is mapped and recorded
- Human review: no shortlist, rejection, or ranking goes out without a person checking it
- DPIA: done before go-live for high-risk hiring tools
- Audit trail: model version, decision logic, notice version, and timestamped consent are logged
- Data location: storage, processing, and transfers are mapped for UAE or KSA setups
One point matters most: a final hiring call should not come out of a black box. Or put another way: if your workflow runs across an ATS, interview tool, and cloud stack, I apply the same control set across the full chain, not one app at a time.

Checklist 1: Candidate Notice, Consent and Lawful Basis
Verify That the Recruitment Privacy Notice Covers AI Use Clearly
Most hiring teams get stuck here first. The notice exists, but it says almost nothing about how AI is used in practice.
Your recruitment privacy notice should name the controller, state the recruitment purpose, and explain any AI screening or profiling used in AI-assisted hiring decisions. It should also tell candidates about their right to object to automated decisions. This is the candidate-facing control that supports Article 18.
For UAE candidate journeys, provide the notice in English and Arabic.
Verify That Consent Flows Are Explicit, Separate and Easy to Withdraw
Don’t bundle consent into one catch-all tick box. If you do, people won’t know what they agreed to, and your team won’t have a clean record later.
Capture explicit, separate consent for each AI-assisted activity:
- CV parsing and ranking
- Interview recording and scoring
- Talent-pool retention
Link each consent record to the exact notice shown at the time. If the notice changes, the record should still show what the candidate saw on that date. Give candidates a simple way to withdraw consent at any time.
Verify That Each Recruitment Activity Has a Documented Lawful Basis
Not every hiring activity relies on consent. Under Article 6 of the UAE PDPL, processing may be lawful where it is necessary to take steps at the request of the data subject before entering into a contract. CV screening and assessment scoring for a specific role the candidate applied for will often sit under this basis.
Maintain a lawful-basis register for each AI-assisted recruitment step.
| Recruitment Activity | Lawful Basis |
|---|---|
| CV screening and assessment scoring for the applied role | Necessary to take steps at the candidate's request before entering into a contract |
| CV parsing and ranking at application stage | Explicit consent |
| Recording and scoring at interview stage | Explicit consent |
| Talent pool retention for future roles | Explicit consent |
Once lawful basis is mapped, move each AI step to a human-review point in the next checklist.
Checklist 2: Map Automated Decisions and Add Human Review Points
Once you’ve sorted the lawful basis, the next job is simple: find every place where AI can sway a hiring call.
Verify That Every AI-Assisted Hiring Step Is Mapped
Write down every tool and rule that screens, ranks, scores, or rejects candidates. That includes ATS ranking rules, chatbot screening, interview scoring engines, automatic rejection logic, talent pool profiling, and reference-check automation.
For each step, note one thing clearly: is the AI output just advice, or does it change who gets shortlisted, rejected, or moved forward?
Then add a documented human review point before any shortlist, rejection, or ranking is finalised. If a system can shape the outcome, a person needs to step in before that outcome becomes final.
Record:
- The decision point
- The output
- The human override
| AI-Assisted Step | Output Type | Human Review Point Required? |
|---|---|---|
| ATS ranking rules | Can affect the outcome | Yes - before shortlist is finalised |
| Chatbot screening | Can affect the outcome | Yes - before rejection or ranking is finalised |
| Interview scoring engines | Can affect the outcome | Yes - before rejection or shortlist is finalised |
| Automatic rejection logic | Final hiring decision | Yes - before rejection is issued |
| Talent pool profiling | Can affect later hiring decisions | Yes - before it informs a hiring decision |
| Reference-check automation | Can affect the outcome | Yes - before it informs a hiring decision |
Use this map to place the human override before any automated result reaches a recruiter.
Once the workflow is mapped, use it to place objection and fairness controls.
Checklist 3: DPIA, Policy Updates and Governance Ownership
Mapping the AI hiring flow is only half the job. Before go-live, the control side needs to be locked down too.
Verify That a PDPL DPIA Is Completed for High-Risk AI Hiring Tools
Complete a DPIA before go-live for recruitment workflows that rely on automated processing and materially affect candidates. That usually means AI-based candidate filtering, automated ranking, and other hiring decisions with a serious effect on the outcome.
Then assign a clear owner for each control the DPIA flags. If a risk is listed but no team owns it, it tends to sit there and drift.
Verify That HR, Legal and IT Responsibilities Are Assigned
Assign each control area to a named function before go-live.
| Function | Owns |
|---|---|
| HR | Candidate communication and human review |
| Legal | UAE PDPL Article 18, notices and consent |
| IT and Security | Access controls, hosting, change logs and residency checks |
This matters for a simple reason: when something goes wrong, vague ownership slows everything down. A named function makes the workflow easier to run and easier to check.
Verify That Policies and Procedures Are Updated
Update policies and procedures before go-live so they match the mapped AI hiring flow. That includes privacy notices, consent wording, recruiter workflows, retention rules, and vendor records.
Write the human-review rule into recruiter procedures. Don’t leave it as an informal step or a line in a slide deck.
If you run recruitment workflows on top of Microsoft 365, Google Workspace, SAP, or Odoo, include the AI layer in your vendor records. Also confirm in writing where candidate data is stored, processed, and transferred.
Use those rules to drive logging, access, and residency checks in the next step.
Checklist 4: Audit Trails and UAE or KSA Data Residency
Once governance is assigned, lock down evidence and data-location controls before go-live.
Verify That the Audit Trail Captures Each AI-Assisted Decision
The audit trail needs to show how the decision was made, not only the final result. That matters if a candidate asks what happened or needs to be informed about an automated step.
| Field | Record |
|---|---|
| Decision logic | The specific logic applied in the hiring step |
| Model version | The AI system or model version used |
| Notice version shown | The exact version shown to the candidate |
| Timestamped consent record | A timestamped, granular record of explicit consent for automated decision-making |
Treat these records as the evidence layer for the notice, consent, and human-review controls already mapped.
Verify That Access, Change Logs and Deletion Events Are Secured
Record immutable audit logs and role-based access control in procurement and security review.
In plain terms, you need a clear record of who accessed what, what changed, and when deletion events happened. If something goes wrong later, this is the trail your team will rely on.
Once the audit trail is in place, check where the data is stored, processed, and transferred.
Verify Where Data Is Stored, Processed and Transferred
Map each recruitment tool’s data flow. If any transfer goes outside the UAE or KSA, document the legal basis and the transfer safeguards in place.
If you’re assessing a platform for UAE or KSA operations, confirm whether data residency is available and documented.
These checks feed the final go-live standard in the conclusion.
Conclusion: UAE PDPL Article 18 AI Recruitment Checklist Summary
This checklist comes down to four control areas: notice and consent, automated decision mapping with human review, DPIA and governance ownership, and audit trails with data residency checks.
For AI hiring tools in the UAE, the bar is simple: they must be useful, documented, and reviewed by people.
Use the table below as the final go-live gate.
The Minimum Standard Before Go-Live
| Control Area | Minimum Requirement |
|---|---|
| Notice and consent | Privacy notice and consent records match the live AI workflow |
| Human review | Objection and human-review route is live and tested |
| DPIA | Completed for each high-risk tool before go-live |
| Policy and ownership | HR, legal and IT owners assigned; policies approved and version-controlled |
| Audit trail | Each AI-assisted step is logged and traceable |
| Data residency | Data location and transfers are documented and controlled |
If any control fails, stop deployment until the gap is fixed.
That rule applies across the whole workflow, not just one tool. If your recruitment process runs through Microsoft 365, Google Workspace, SAP, Odoo, or Zoho, apply the same controls across every connected system.
If your setup needs Gulf-specific data residency, check with the vendor whether UAE or KSA hosting is available. Get that confirmation in writing before go-live.
FAQs
Does Article 18 apply if AI only ranks candidates?
Yes. Article 18 of the UAE PDPL applies when AI is used to automate the processing of personal data, including candidate ranking.
That matters because a ranking decision produces an outcome about a person. In practice, organisations should be able to show transparency, data protection safeguards, human oversight, and a clear audit trail that aligns with UAE data processing standards.
When is a DPIA required for AI recruitment?
Under the UAE PDPL, a Data Protection Impact Assessment (DPIA) is required when AI recruitment involves high-risk processing. That usually means using new tools in ways that could put a person’s privacy or rights at risk.
A DPIA is also required before processing starts if your AI hiring setup includes:
- Large-scale systematic monitoring
- Automated decision-making that has a major effect on candidates
- Large-scale processing of sensitive personal data
In other words: if the system watches people at scale, makes calls that can shape hiring outcomes, or handles sensitive data in volume, you need to complete a DPIA first.
What should we log if a candidate challenges a decision?
Under UAE PDPL Article 18, every AI-influenced hiring decision needs a clear audit trail. If a candidate is screened, ranked, or filtered with AI, you should be able to show what happened and who stepped in.
Log:
- the AI criteria and logic used
- the data points processed
- any human oversight or final intervention
Keep this record in line with UAE data residency requirements. That gives you a clean paper trail for transparency, accountability, and compliance.