Uklad.aiBlog

UAE PDPL Article 18: AI Recruitment Checklist

2026-08-31 · Uklad AI

If AI can filter, score, or reject a candidate, I treat it as in scope from day one. Under the UAE PDPL, that means I need four things before go-live: clear notice, a lawful basis or explicit consent where needed, human review before a final hiring outcome, and records that show what happened.

This article boils the job down to a short go-live test for hiring teams in the UAE. It covers where Article 18 hits AI-led recruitment, when Article 21 pushes me to run a DPIA, how I split duties across HR, Legal, and IT, and what I need to log if a candidate questions a decision later.

At a glance, I check:

  • Notice: the recruitment privacy notice says where AI is used, in English and Arabic
  • Consent: separate consent for CV ranking, interview recording and scoring, and talent-pool retention where used
  • Lawful basis: each AI step is mapped and recorded
  • Human review: no shortlist, rejection, or ranking goes out without a person checking it
  • DPIA: done before go-live for high-risk hiring tools
  • Audit trail: model version, decision logic, notice version, and timestamped consent are logged
  • Data location: storage, processing, and transfers are mapped for UAE or KSA setups

One point matters most: a final hiring call should not come out of a black box. Or put another way: if your workflow runs across an ATS, interview tool, and cloud stack, I apply the same control set across the full chain, not one app at a time.

UAE PDPL AI Recruitment: 4-Step Go-Live Checklist
UAE PDPL AI Recruitment: 4-Step Go-Live Checklist

Checklist 1: Candidate Notice, Consent and Lawful Basis

Verify That the Recruitment Privacy Notice Covers AI Use Clearly

Most hiring teams get stuck here first. The notice exists, but it says almost nothing about how AI is used in practice.

Your recruitment privacy notice should name the controller, state the recruitment purpose, and explain any AI screening or profiling used in AI-assisted hiring decisions. It should also tell candidates about their right to object to automated decisions. This is the candidate-facing control that supports Article 18.

For UAE candidate journeys, provide the notice in English and Arabic.

Verify That Consent Flows Are Explicit, Separate and Easy to Withdraw

Don’t bundle consent into one catch-all tick box. If you do, people won’t know what they agreed to, and your team won’t have a clean record later.

Capture explicit, separate consent for each AI-assisted activity:

  • CV parsing and ranking
  • Interview recording and scoring
  • Talent-pool retention

Link each consent record to the exact notice shown at the time. If the notice changes, the record should still show what the candidate saw on that date. Give candidates a simple way to withdraw consent at any time.

Verify That Each Recruitment Activity Has a Documented Lawful Basis

Not every hiring activity relies on consent. Under Article 6 of the UAE PDPL, processing may be lawful where it is necessary to take steps at the request of the data subject before entering into a contract. CV screening and assessment scoring for a specific role the candidate applied for will often sit under this basis.

Maintain a lawful-basis register for each AI-assisted recruitment step.

Recruitment ActivityLawful Basis
CV screening and assessment scoring for the applied roleNecessary to take steps at the candidate's request before entering into a contract
CV parsing and ranking at application stageExplicit consent
Recording and scoring at interview stageExplicit consent
Talent pool retention for future rolesExplicit consent

Once lawful basis is mapped, move each AI step to a human-review point in the next checklist.

Checklist 2: Map Automated Decisions and Add Human Review Points

Once you’ve sorted the lawful basis, the next job is simple: find every place where AI can sway a hiring call.

Verify That Every AI-Assisted Hiring Step Is Mapped

Write down every tool and rule that screens, ranks, scores, or rejects candidates. That includes ATS ranking rules, chatbot screening, interview scoring engines, automatic rejection logic, talent pool profiling, and reference-check automation.

For each step, note one thing clearly: is the AI output just advice, or does it change who gets shortlisted, rejected, or moved forward?

Then add a documented human review point before any shortlist, rejection, or ranking is finalised. If a system can shape the outcome, a person needs to step in before that outcome becomes final.

Record:

  • The decision point
  • The output
  • The human override
AI-Assisted StepOutput TypeHuman Review Point Required?
ATS ranking rulesCan affect the outcomeYes - before shortlist is finalised
Chatbot screeningCan affect the outcomeYes - before rejection or ranking is finalised
Interview scoring enginesCan affect the outcomeYes - before rejection or shortlist is finalised
Automatic rejection logicFinal hiring decisionYes - before rejection is issued
Talent pool profilingCan affect later hiring decisionsYes - before it informs a hiring decision
Reference-check automationCan affect the outcomeYes - before it informs a hiring decision

Use this map to place the human override before any automated result reaches a recruiter.

Once the workflow is mapped, use it to place objection and fairness controls.

Checklist 3: DPIA, Policy Updates and Governance Ownership

Mapping the AI hiring flow is only half the job. Before go-live, the control side needs to be locked down too.

Verify That a PDPL DPIA Is Completed for High-Risk AI Hiring Tools

Complete a DPIA before go-live for recruitment workflows that rely on automated processing and materially affect candidates. That usually means AI-based candidate filtering, automated ranking, and other hiring decisions with a serious effect on the outcome.

Then assign a clear owner for each control the DPIA flags. If a risk is listed but no team owns it, it tends to sit there and drift.

Verify That HR, Legal and IT Responsibilities Are Assigned

Assign each control area to a named function before go-live.

FunctionOwns
HRCandidate communication and human review
LegalUAE PDPL Article 18, notices and consent
IT and SecurityAccess controls, hosting, change logs and residency checks

This matters for a simple reason: when something goes wrong, vague ownership slows everything down. A named function makes the workflow easier to run and easier to check.

Verify That Policies and Procedures Are Updated

Update policies and procedures before go-live so they match the mapped AI hiring flow. That includes privacy notices, consent wording, recruiter workflows, retention rules, and vendor records.

Write the human-review rule into recruiter procedures. Don’t leave it as an informal step or a line in a slide deck.

If you run recruitment workflows on top of Microsoft 365, Google Workspace, SAP, or Odoo, include the AI layer in your vendor records. Also confirm in writing where candidate data is stored, processed, and transferred.

Use those rules to drive logging, access, and residency checks in the next step.

Checklist 4: Audit Trails and UAE or KSA Data Residency

Once governance is assigned, lock down evidence and data-location controls before go-live.

Verify That the Audit Trail Captures Each AI-Assisted Decision

The audit trail needs to show how the decision was made, not only the final result. That matters if a candidate asks what happened or needs to be informed about an automated step.

FieldRecord
Decision logicThe specific logic applied in the hiring step
Model versionThe AI system or model version used
Notice version shownThe exact version shown to the candidate
Timestamped consent recordA timestamped, granular record of explicit consent for automated decision-making

Treat these records as the evidence layer for the notice, consent, and human-review controls already mapped.

Verify That Access, Change Logs and Deletion Events Are Secured

Record immutable audit logs and role-based access control in procurement and security review.

In plain terms, you need a clear record of who accessed what, what changed, and when deletion events happened. If something goes wrong later, this is the trail your team will rely on.

Once the audit trail is in place, check where the data is stored, processed, and transferred.

Verify Where Data Is Stored, Processed and Transferred

Map each recruitment tool’s data flow. If any transfer goes outside the UAE or KSA, document the legal basis and the transfer safeguards in place.

If you’re assessing a platform for UAE or KSA operations, confirm whether data residency is available and documented.

These checks feed the final go-live standard in the conclusion.

Conclusion: UAE PDPL Article 18 AI Recruitment Checklist Summary

This checklist comes down to four control areas: notice and consent, automated decision mapping with human review, DPIA and governance ownership, and audit trails with data residency checks.

For AI hiring tools in the UAE, the bar is simple: they must be useful, documented, and reviewed by people.

Use the table below as the final go-live gate.

The Minimum Standard Before Go-Live

Control AreaMinimum Requirement
Notice and consentPrivacy notice and consent records match the live AI workflow
Human reviewObjection and human-review route is live and tested
DPIACompleted for each high-risk tool before go-live
Policy and ownershipHR, legal and IT owners assigned; policies approved and version-controlled
Audit trailEach AI-assisted step is logged and traceable
Data residencyData location and transfers are documented and controlled

If any control fails, stop deployment until the gap is fixed.

That rule applies across the whole workflow, not just one tool. If your recruitment process runs through Microsoft 365, Google Workspace, SAP, Odoo, or Zoho, apply the same controls across every connected system.

If your setup needs Gulf-specific data residency, check with the vendor whether UAE or KSA hosting is available. Get that confirmation in writing before go-live.

FAQs

Does Article 18 apply if AI only ranks candidates?

Yes. Article 18 of the UAE PDPL applies when AI is used to automate the processing of personal data, including candidate ranking.

That matters because a ranking decision produces an outcome about a person. In practice, organisations should be able to show transparency, data protection safeguards, human oversight, and a clear audit trail that aligns with UAE data processing standards.

When is a DPIA required for AI recruitment?

Under the UAE PDPL, a Data Protection Impact Assessment (DPIA) is required when AI recruitment involves high-risk processing. That usually means using new tools in ways that could put a person’s privacy or rights at risk.

A DPIA is also required before processing starts if your AI hiring setup includes:

  • Large-scale systematic monitoring
  • Automated decision-making that has a major effect on candidates
  • Large-scale processing of sensitive personal data

In other words: if the system watches people at scale, makes calls that can shape hiring outcomes, or handles sensitive data in volume, you need to complete a DPIA first.

What should we log if a candidate challenges a decision?

Under UAE PDPL Article 18, every AI-influenced hiring decision needs a clear audit trail. If a candidate is screened, ranked, or filtered with AI, you should be able to show what happened and who stepped in.

Log:

  • the AI criteria and logic used
  • the data points processed
  • any human oversight or final intervention

Keep this record in line with UAE data residency requirements. That gives you a clean paper trail for transparency, accountability, and compliance.

← All articles