Consent and Transparency: What Candidates Need to Know
Marcus runs talent acquisition at Northwind Cloud, an 800-person SaaS company headquartered in New York City with a satellite office in Dublin. For the company's busiest role, mid-market account executive, a typical req draws about 200 applicants. His team cannot read 200 resumes per role with any rigor, so the VP of People approved an AI screening step: a tool that ranks applicants on a 0-to-100 fit score by parsing their resume against the job description and scoring three weighted factors. Marcus is comfortable with the math. What he is not comfortable with is the email he got from his employment lawyer the week before go-live: "Before you turn this on, you owe every applicant a notice, a disclosure, and a way out. In New York that is not a courtesy. It is the law." This lesson is about that email, and about what candidates genuinely need to know when an algorithm helps decide their future.
Why Transparency Is Now a Legal Duty, Not a Courtesy
For years, AI in hiring lived in a gray zone. Vendors sold scoring tools, recruiters used them quietly, and candidates rarely knew. That era is ending. Three jurisdictions that touch Marcus's funnel have turned disclosure from a nice-to-have into a requirement with teeth, and the pattern they share is the one ethical recruiters should follow regardless of geography: tell candidates an automated tool is involved, tell them what it looks at, and give them a path to be evaluated by a human. The legal floor and the ethical floor have converged, which means you can build one process instead of arguing about which standard to hold yourself to.
The shift matters because the power imbalance in hiring is real. A candidate cannot negotiate with a black box. If a fit score quietly drops Marcus's applicant pool from 200 to a shortlist of 25, the 175 who were filtered out deserve to know that software, not a person, made the first cut, and what they could have done differently. Transparency restores a candidate's ability to act on their own behalf. It is also a reputational instrument: candidates who feel their data was collected without their knowledge lose trust, they warn people in their network, and you end up recruiting from a smaller and more suspicious pool than the one you started with.
The Transparency Principle and the Test That Enforces It
The baseline is not demanding. Candidates should understand what data you are collecting, why, and how you will use it. Most already expect exactly that level of openness and are surprised when they do not get it. Where organizations fall short is not in refusing to disclose anything; it is in being transparent about the easy parts and opaque about the parts that are harder to explain. The resume and the reference check get described in plain terms, while the scoring model and the "culture fit" assessment get described in language that sounds informative and conveys nothing. The test that catches this is simple to apply and uncomfortable to fail: could a candidate read your explanation and accurately understand what you are doing? If they could recite your sentence back and still not know what is being measured, the sentence is not transparent, however many words it contains. Below are four statements of the kind that appear in real hiring processes, graded against that test.
| What the candidate is told | Verdict | Why |
|---|---|---|
| "We'll collect your resume, run a background check, and verify employment references." | Transparent | Names each specific data collection. The candidate can picture exactly what happens. |
| "We use AI to analyze your communication patterns and behavioral signals to assess culture fit." | Opaque | Sounds specific but never says what is actually being looked at. The candidate cannot act on it. |
| "We interview with a panel, take notes, and use those notes to make hiring decisions." | Transparent | States the mechanism and what the output is used for. |
| "We'll assess you against our internal success criteria." | Opaque | The criteria are the entire content of the sentence, and they are withheld. |
Neither opaque example is a lie. Both are what a well-intentioned team writes when it wants to sound rigorous, and both leave the candidate unable to tell what is being evaluated, unable to prepare, and unable to challenge a result they do not understand.
New York City Local Law 144: Notice, Data, and an Alternative
Northwind is headquartered in Manhattan, so Local Law 144 governs Marcus directly. The law regulates what it calls an automated employment decision tool, or AEDT, defined as a computational process that issues a score, classification, or recommendation used to substantially assist or replace a hiring decision. A resume-ranking tool that produces a 0-to-100 fit score is squarely an AEDT.
The law imposes three obligations that Marcus has to build into his funnel. First, notice timing: candidates who live in NYC must be notified that an AEDT will be used at least ten business days before it is used on their application. Ten business days is roughly two calendar weeks, so Marcus cannot post the req on Monday and start scoring on Wednesday. He has to publish the notice on the posting or send it early enough that the clock runs out before the tool touches a single resume.
Second, the notice must disclose the job qualifications and characteristics the tool will use to evaluate the candidate, and the type or source of the data collected for the tool. For Northwind's three weighted factors, that means stating plainly that the tool scores relevant sales experience, evidence of quota attainment, and industry or product familiarity, drawn from the candidate's submitted resume and application form. Third, candidates must be able to request an alternative selection process or an accommodation: if a candidate asks not to be scored, the team must offer a route, in Marcus's case a manual resume review by a recruiter. Local Law 144 also requires a separate bias audit of the tool by an independent auditor within the year before use, with a summary of results published, but for the candidate-facing notice the three duties above are what Marcus must communicate.
GDPR for EU Candidates: Articles 13, 14, and 22
Northwind's Dublin office means some applicants are in the European Union, and the General Data Protection Regulation applies to them. Three articles shape what Marcus owes those candidates. Articles 13 and 14 set out the information that must be provided when personal data is collected, whether directly from the candidate (Article 13) or obtained from another source such as a sourcing database (Article 14). That information includes the identity of the data controller, the purposes of processing, and, importantly, the existence of automated decision-making.
Article 22 is the one that changes Marcus's design. It gives individuals the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and a hiring rejection generated by a fit score with no human looking at the result can fall into that category. Where automated decision-making is permitted, Article 22 requires meaningful safeguards, including the right to obtain human intervention, to express one's point of view, and to contest the decision.
The practical consequence: for EU candidates, Marcus cannot let the fit score auto-reject anyone. A recruiter reviews the tool's output before a rejection goes out, and the candidate is told they can ask for that review and challenge the result. This is why Northwind configures the tool to rank and recommend rather than reject. It is a design constraint, not a paperwork constraint; no notice, however well written, cures a workflow in which the software sends the rejection.
A US Example Beyond NYC: The Illinois AI Video Interview Act
Marcus's funnel also includes a recorded video interview stage for finalists, and his company experimented with a vendor that uses AI to analyze those recordings. Because some candidates apply from Illinois, the Illinois Artificial Intelligence Video Interview Act applies. The law requires three things before an employer uses AI to analyze a video interview: notify the applicant that AI may be used to analyze the interview and consider their fitness for the position, provide information explaining how the AI works and what general types of characteristics it uses to evaluate applicants, and obtain the applicant's consent before the AI analyzes the video.
The consent requirement here is explicit and prior: no consent, no AI analysis. That is a useful contrast with Local Law 144, where the candidate-facing requirement is notice plus an alternative rather than affirmative opt-in. Different laws draw the line in different places, which is why Marcus cannot rely on a single global notice and assume it satisfies everyone. The workable strategy is to build to the strictest duty that touches any part of your funnel, then add the jurisdiction-specific pieces that go beyond it, rather than maintaining a separate and separately rotting notice for every state.
The Five Things Every Candidate Needs to Know
Underneath the statutes is a simple checklist that works as an ethical floor everywhere, not just in regulated states. Whenever AI touches a hiring decision, a candidate should be told five things in language they can actually read.
- That AI is being used. Name the stage. "An automated tool helps us rank applications for this role." No euphemisms like "advanced matching technology" that obscure what is happening.
- What data it collects and uses. Be specific about the inputs and the source. "It analyzes the resume and application form you submit." If the tool pulls from anywhere beyond what the candidate gave you, say so.
- How decisions are made. Explain the factors at a level a non-technical person understands. "It scores relevant sales experience, evidence of meeting sales targets, and familiarity with our industry." The candidate does not need the model weights; they need to know what counts.
- Their rights. Access to the data held about them, correction of errors in it, a route to opt out in favor of an alternative human-reviewed process, and a way to appeal an adverse outcome. These four rights are the difference between disclosure and genuine recourse.
- Who to contact and when. A real name or role and an email, plus the timing of the notice, so the candidate has time to act before the tool runs.
Five Categories of Disclosure: Collection, Retention, Usage, Access, Special Processing
The checklist above covers the AI step. A complementary breakdown covers the whole recruiting process, because the AI screen is rarely the only place candidate data is handled. Marcus walked his funnel category by category and wrote one honest sentence for each, on the theory that a category he could not describe in a sentence was one he probably should not be collecting.
Data collection. What specifically are you collecting? Resume, work samples, portfolio, social media, background check, assessment results? Each category should be explicit. Many organizations collect more than they realize, because collection accumulates one reasonable-sounding decision at a time: the resume is one data set, the background check another, the AI analysis of writing samples another, the references another, the social media check another. By the time a candidate finishes the process you may hold five distinct categories of information about them, and they should know about each rather than discovering them piecemeal.
Retention. How long do you keep this data? Forever, until you hire someone else, six months, a year? Different categories can legitimately have different retention periods, but candidates should know the timeline. The default assumption many candidates carry is that you keep their data forever, because that is what most organizations appear to do. If you delete it after six months, tell them. Clarity here costs nothing and buys disproportionate goodwill, particularly from candidates you reject.
Usage. What will you do with the data? Evaluate their candidacy, contact them about future roles, feed recruiting research, share it with hiring managers, pass it to third parties? This is where most organizations get vague, usually because specificity forecloses options. "We may contact you about future opportunities" means anything. "If you're not selected for this role, we'll keep your profile for 12 months and may contact you about senior data engineer roles that come up in that period" is specific enough for a candidate to decide whether they want it. The second version is harder to write and much easier to trust.
Access. Who can see this data? The recruiter, the hiring manager, the whole team, HR, third-party vendors? Candidates routinely underestimate how many people read their application materials, and being explicit dissolves an anxiety that otherwise sits unspoken. "Your resume and interview notes will be seen by the hiring manager and the interview panel, 3 people, and they're confidential within our organization" answers the question in one sentence.
Special processing. Are you using AI to analyze their data, doing automated decision-making, running assessments, checking social media, buying from data brokers? Each is a form of special processing candidates are frequently not told about. The legal requirement in many jurisdictions, GDPR among them, is that you must inform candidates of automated processing; the ethical requirement goes further and asks you to explain why. In practice: "We use an AI tool to analyze writing samples. This helps us assess communication skills at scale. The AI is trained to identify clarity, structure, and technical accuracy. Your sample won't be used for any purpose other than evaluating your candidacy for this role." That is transparency. "We use AI to assess your communication," standing alone, is not, because it names the technology while withholding everything a candidate needs in order to respond.
Getting Genuine Consent, Not a Signature
Consent is not the act of getting someone to click "I agree." It is a state of mind on the candidate's side that your process either produces or fails to produce. Four conditions distinguish the real thing from its paperwork. Clear information means the person understands what they are consenting to, in the ordinary sense, not the legal fiction of having been given access to a document. Voluntary means declining an optional data collection does not automatically end their candidacy. Specific means they consent to identified uses rather than to whatever you may decide later. Freely given means no pressure or implied threat is attached to the choice.
Measured against those conditions, the standard implementation fails. "By applying, you consent to all data collection practices outlined in our privacy policy" is the canonical bad version: the candidate has almost certainly not read ten pages of policy, so the information condition fails and specificity fails with it. What survives is a record of a click, useful for looking compliant and useless for being compliant. The better version asks at the moment the data is about to be collected, in the words a person would use: "We'd like to run a background check as part of our evaluation. This includes criminal history, employment verification, and education verification. Is that okay?" If someone declines, you either find an alternative or tell them honestly that you cannot proceed without it, depending on how critical the check genuinely is. Either outcome is more defensible than a consent obtained by making the question unreadable.
The Transparency Spectrum
Candidates are not uniform in what they want to know. Some want a detailed account of your evaluation process, how the score works, what the panel weighs, why a criterion exists. Others want one thing only: whether they are moving forward. Both preferences deserve respect, and a process designed exclusively for one irritates the other. The workable default is standard transparency: for most candidates, share enough that they understand your basic process and how their data is used, without burying a person who wants a status update under an essay on methodology. The deeper material should exist and be easy to request, but it need not be pushed at everyone.
Plain Language Versus Legalese: A Sample Disclosure
A disclosure buried in a fifteen-page privacy policy satisfies a lawyer and nobody else. The test is whether a candidate reading it once, on their phone, understands what is happening and what they can do about it. Here is the notice Marcus published on Northwind's account executive posting, written to satisfy Local Law 144's substance while staying readable.
"To help us review the large number of applications for this role, we use an automated tool to rank candidates. The tool reviews the resume and application you submit and scores three things: your relevant sales experience, evidence that you have met sales targets, and your familiarity with our industry. A recruiter reviews the tool's recommendations before any decision is made; the tool does not reject anyone on its own. You have the right to ask for your application to be reviewed by a person instead of the tool, to see and correct the information we hold about you, and to ask us about the outcome. If you would like an alternative review or have questions, email [email protected] by [date], at least ten business days before we begin screening. Applicants in the EU also have the right to request human review of, and to contest, any automated decision."
Notice what that paragraph does. It names the tool, the data, and the three factors. It states the alternative-process right and the access and correction rights. It gives a contact and a deadline tied to the ten-business-day rule, and it flags the EU human-review right. It runs about 130 words, and a candidate can act on it without a lawyer. It works because every sentence answers a question a candidate would actually ask, which is a very different drafting instruction from the one that produces privacy policies.
The Data Minimization Connection
Transparency and data minimization pull in the same direction, and teams that treat them as separate projects make both harder. The less data you collect, the simpler your transparency story becomes, because every category is one you have to describe, justify, secure, retain on a schedule, and account for if someone asks. Collect five things and your notice is short and honest. Collect fifteen, several of them "nice to have," and your notice either grows into something nobody reads or quietly omits the awkward parts.
This is why the transparency audit and the collection audit are usually the same exercise. If you are gathering social media impressions, behavioral assessments, and reference checks you never consult, you have manufactured a transparency burden with no corresponding benefit, and you now have to explain what you are doing with data you are not using, which is a sentence nobody can write convincingly. A field you cannot explain to a candidate in one sentence was never earning its place, and removing it improves your privacy posture, your candidate experience, and your notice at once.
Building It Into the Funnel Without Slowing the Hire
Transparency that lives only in a policy document fails. Marcus operationalized it in four places. The notice sits at the top of the job description, so the ten-business-day clock starts when the req is posted. The confirmation email repeats the notice and the deadline. The alternative-process request is a single form field, "Request human review instead of automated screening," so opting out costs one click rather than a battle. And every rejection following an AI-assisted screen is reviewed and sent by a recruiter, never auto-generated, which keeps the human-in-the-loop promise GDPR Article 22 and good practice both demand.
The cost was not speed; it was lead time. Marcus had to post reqs about two weeks before screening began, which pushed planning earlier but did not lengthen the hiring cycle once it started. In exchange, Northwind can show an auditor exactly when each candidate was notified, what they were told, who opted out, and who reviewed each adverse decision. When a rejected candidate emailed to ask why, the team could answer honestly instead of hiding behind a score, and that candidate reapplied for a different role six months later. Transparency did not cost him the talent. It kept the door open.
Building Trust Through Transparency
The payoff is not primarily legal. It is that candidates trust you, including the ones you turn down. A rejected candidate who understood what you were looking for, understood that they did not match it, and can see that their data was handled respectfully has had a fundamentally different experience from one who applied into silence. That reputation compounds in the direction you want, because candidates talk to each other, and the thing they say about organizations that do this well is unglamorous and valuable: when you apply there, they are clear about what they are doing. Over time strong candidates apply, referrals increase, and the pool you draw from grows rather than shrinks. This is a slow-moving asset built through consistency rather than a campaign, which is precisely why the organizations that have it are hard to catch.
Anti-Patterns
The privacy policy assumption. The team assumes that because a privacy policy exists, transparency has been achieved. It happens because policies are legally required and producing one feels like completing the task. What goes wrong is that candidates do not read it, so nothing specific to recruiting is communicated: nobody learned that a scoring tool ranks them or that a recruiter sends the rejection. The fix is to separate general policy from recruiting-specific transparency and deliver the recruiting version on the posting and in the confirmation email, where a candidate meets it when it is relevant.
Consent theater. The team collects clicks on "I agree" from candidates who do not understand what they agreed to. It happens because it feels like compliance and produces a clean audit artifact. What goes wrong is that consent without understanding is not consent, legally or ethically, so the artifact documents a failure rather than curing it. The fix is a specific, readable request at the point of collection: a one-sentence "By applying, you agree to X" beats a link to a ten-page policy, and asking directly before collecting anything sensitive beats either.
Data hoarding. The team collects broadly because the data might be useful someday, then cannot describe what it holds or for how long. It happens because data feels like optionality and deleting feels irreversible. What goes wrong is privacy risk, compliance exposure, and a transparency burden the organization cannot discharge, while candidates do not know what is held about them. The fix is to collect only what you will use, and where you keep something just in case, say so and attach a deletion date rather than letting it sit indefinitely.
Practice
- Run a transparency audit. Write down everything you collect from candidates. For each category, write one sentence on why you collect it and how you use it. If you cannot write that sentence, you have found something you should not be collecting.
- Walk your own funnel as a candidate. Move through your application process step by step, and at each point where data is collected ask whether you would understand why. Everywhere the answer is no, transparency has to be added.
- Review your consent language. Read your consent text as a non-technical candidate would. Would that person understand what they are agreeing to? If not, rewrite it in shorter sentences and move it to the moment of collection.
- Write a data retention plan. For each category, decide how long you keep it, who has access, and when it is deleted. Write it down, because an undocumented retention policy is indistinguishable from no policy.
- Audit vendor transparency. List the third-party recruiting tools in your process. Do you know what data each collects and retains? Do your candidates know? Where you cannot answer, that is your next vendor conversation.
Reflection
- What is one category of candidate data you collect but rarely use to make a decision?
- If you had to explain your recruiting process to a candidate in plain language, without jargon and without pointing at a document, what would you say?
- Are there tools or vendors in your stack where you do not fully understand what data they collect or how long they keep it?
- What would change if you committed to collecting only the data you are genuinely using?
- What is your retention policy for candidates you do not hire, and could you explain it clearly to one of them?
Glossary
- Genuine consent. Informed, voluntary, specific, freely given agreement to data collection and use. Not the act of clicking "I agree."
- Special processing. Automated decision-making, AI analysis, or other processing that requires explicit candidate awareness in most jurisdictions.
- Consent theater. A record of consent obtained without genuine understanding on the candidate's side.
- Data minimization. Collecting only the data necessary for your recruiting decisions.
- Transparency. Clear explanation of what data you collect, why, how you use it, and how long you keep it.
- Automated employment decision tool (AEDT). Under NYC Local Law 144, a computational process issuing a score, classification, or recommendation used to substantially assist or replace a hiring decision.
- Alternative selection process. The route a candidate may request instead of automated evaluation, such as a manual resume review by a recruiter.
Related Lessons
- Data Privacy Fundamentals: GDPR, CCPA, FCRA, and Regional Requirements maps the wider regulatory landscape this lesson draws its notice and consent duties from.
- Data Minimization: Collecting Only What's Necessary turns the collection audit described here into a field-by-field decision about what to ask for at all.
- Privacy Boundaries: Data Sharing, Tool Selection, and Compliance covers what happens to candidate data once it leaves your systems and enters a vendor's.
- Retention and Deletion: Reasonable Timelines and Clean Data Practices converts the retention promises in your notice into an operational schedule.
- Hands-On Project: Audit a Recruiting Process for Privacy Risks applies all of this end to end against your own funnel.
Closing
Transparency is a practice, not a compliance exercise, and the difference shows up in where it lives. A compliance exercise lives in a document produced once, reviewed by counsel, and never read by a candidate. A practice lives in the job posting, the confirmation email, the opt-out checkbox, and the recruiter who reads the score before sending the rejection. Marcus's lawyer framed the obligation in legal terms because that is what got the project funded, but the version that survived contact with the funnel was simpler than the statute: tell people what you are doing, tell them what it looks at, and give them a way to be seen by a human.
Key Takeaways
- Disclosure is now a legal duty where AI assists hiring decisions. NYC Local Law 144, the GDPR, and the Illinois AI Video Interview Act each require some combination of notice, explanation, and a human-review or alternative path. Build to the strictest rule that touches your funnel rather than maintaining a separate notice per jurisdiction.
- Local Law 144 imposes three candidate-facing duties. Notify NYC applicants at least ten business days before an automated employment decision tool is used, disclose the qualifications and the data type and source it relies on, and offer an alternative selection process or accommodation on request.
- GDPR Article 22 keeps a human in the loop for EU candidates. Individuals have the right not to be subject to a decision based solely on automated processing with significant effects, with safeguards including human intervention, the chance to express their view, and the ability to contest the outcome. Articles 13 and 14 require disclosing that automated decision-making exists when you collect their data. The Illinois AI Video Interview Act goes further still for recorded interviews: notify, explain how the AI works, and obtain affirmative prior consent.
- Transparency is not a checkbox; it is a commitment to clarity. Apply the test: could a candidate read your explanation and accurately understand what you are doing? Language that sounds specific while withholding the actual criteria fails it.
- Five things every candidate should be told. That AI is used, what data it collects, how decisions are made, their rights (access, correction, opt-out to a human process, and appeal), and who to contact and by when. This checklist is an ethical floor everywhere, not only in regulated states.
- Disclose across all five categories, not just the easy ones. Collection, retention, usage, access, and special processing. Replace vague usage language such as "we may contact you about future opportunities" with a specific period and kind of role, and always give special processing a "why" alongside the "what."
- Genuine consent requires clear information, voluntariness, specificity, and freedom from pressure. A click on "I agree" attached to a ten-page policy documents a failure rather than curing one. Ask at the point of collection, in words a candidate can parse.
- Data you collect but do not use creates burden without benefit. Minimization and transparency are the same project approached from two directions.
- Plain language beats legalese, and operationalizing beats documenting. A 130-word notice a candidate can read on their phone satisfies the law's substance and earns trust. Put it on the posting to start the clock, repeat it in the confirmation email, make opting out a one-click form field, and require a recruiter to review every adverse decision so the human-in-the-loop promise is real.
- Transparency builds trust even with candidates you reject. Clear process beats vague rejection, that reputation compounds through candidate networks, and the organizations known for it recruit from a larger pool than the ones that are not.
Frequently Asked Questions
We have a privacy policy that covers all of this. Is that enough? No, and treating it as enough is the first anti-pattern in this lesson. A general privacy policy is written for a legal audience, and candidates do not read it. Nothing in it tells an applicant that a scoring tool ranks their resume, what factors it weighs, or how to request a human review. Keep the policy, and add recruiting-specific transparency where the candidate actually encounters it.
If a candidate opts out of automated screening, do we have to hire them? No. The alternative-process right under Local Law 144 is a right to a different evaluation route, not a different outcome. In Marcus's case, opting out means a recruiter reads the resume manually, and the candidate can still be declined on the merits. What you cannot do is treat the request itself as a negative signal, or make opting out so burdensome that nobody realistically does it, which is why he made it a single form field.
Can the AI send rejection emails if a recruiter configured the criteria? For EU candidates, treat this as off limits. GDPR Article 22 addresses decisions based solely on automated processing with legal or similarly significant effects, and a rejection nobody reviewed is the clearest example. Configuring thresholds in advance is not the same as a person reviewing the output, because the safeguards Article 22 requires, human intervention, the ability to express a point of view, and the ability to contest, all presuppose a human in the loop at decision time.
How specific does the notice have to be about how the tool works? Specific about what it evaluates, not about how the model computes it. Local Law 144 asks for the job qualifications and characteristics used and the type or source of the data. That is satisfied by naming the factors, in Marcus's case relevant sales experience, evidence of quota attainment, and industry familiarity, and naming the source, the resume and application form the candidate submitted. A candidate does not need the model weights; they need to know what counts, so they can decide whether their application reflects it and whether to ask for a human review.
Does any of this apply if we only use AI to draft outreach, not to score anyone? The statutes here attach to tools that substantially assist or replace a hiring decision, so a drafting assistant that never evaluates a candidate sits outside the AEDT definition. The five disclosure categories still apply to everything else you do, because candidates have the same interest in knowing what data you hold, who sees it, and how long you keep it whether or not a model scored them.
Skill.re