←
AI for Recruiters
Strategic · M8 · lesson 8 of 33 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
📖
in this lesson

Compliance and Legal Review: Documentation for FCRA, EEO, and GDPR

15 min

Maria runs talent acquisition operations at Meridian Logistics, a 1,200-person company hiring across the United States and the European Union, filling roughly 600 roles a year split between warehouse operations in Ohio and a software office in Berlin. Last spring her team rolled out an AI resume-screening tool to triage a backlog of applications, and within a month her general counsel asked a question Maria could not answer: "If a rejected candidate files a complaint, can you show me exactly how the decision was made and who made it?" The tool produced scores. It did not produce a record of human judgment. Maria spent the next quarter rebuilding her documentation, not because the law had changed, but because she finally understood that in a compliance challenge the thing on trial is not your intent. It is your paper trail. This lesson is about the review itself: what a reviewer asks for, what you hand over, and what a defensible file contains under FCRA, EEO and GDPR. It is a practical framework for working with your legal team, not legal advice. The laws below are summarized for context; confirm how they apply with qualified counsel.

When AI enters recruiting, the legal question shifts from "did you discriminate?" to "can you prove you did not, and can you show a human made the decision?" Defensibility lives in records, not in good intentions, which means a legal review is fundamentally a document request. Whether it comes from your own general counsel doing a proactive check, from a regulator, or from opposing counsel after a complaint, the reviewer is not asking what you believe about your process. They are asking you to produce specific artifacts and to demonstrate that those artifacts were created at the time of the decision rather than assembled afterward. The three frameworks that govern most AI-assisted recruiting in the US and EU, the Fair Credit Reporting Act, federal Equal Employment Opportunity law enforced by the EEOC, and the General Data Protection Regulation, are each, at their core, a documentation regime: each tells you what to record, what notice to give, and how long to keep it.

The unifying design principle for Maria, and for you, is separation. Your documentation should make three things distinguishable on the page: what the AI produced as input, what the human concluded as judgment, and the basis on which the final decision rested. When those three are blended into a single score, you have automation that looks like a decision. When they are separated, you have a human decision that used a tool. That distinction is what most of these laws are actually testing, and it is why a file that contains a rich vendor score and nothing else fails a review that a much thinner file would have passed. Before working through each regime, it helps to see the shape of the whole request.

FrameworkWhat the reviewer asks forWhat a defensible file contains
FCRAShow me that the candidate was told, consented, and had a real chance to dispute before you acted.Standalone disclosure, signed authorization with timestamp, pre-adverse action notice, copy of the report, summary of rights, the waiting gap, the final notice, and the named human who owned the decision.
EEOShow me you monitored this selection procedure for adverse impact and acted on what you found.Selection rates by group, the impact-ratio calculation, the date it was run, who ran it, what it showed, and the follow-up decision.
GDPRShow me your lawful basis, your retention limits, and that a human meaningfully decided.Recorded lawful basis per processing activity, Article 30 records naming the vendor as processor, the data processing agreement, the written retention schedule, and evidence of human involvement.

FCRA: The Sequence You Must Prove You Followed

The FCRA governs how employers use "consumer reports" from third-party background-check providers, and it covers not only criminal history but employment screening generally. It is procedural, which is good news: comply with the procedure and document it, and you are largely defensible. Meridian uses a vendor to run criminal and employment-history checks on finalists, so FCRA applies to that step. The reviewer's questions here are narrow and sequential, which means your file has to be sequential too.

The first requirement is disclosure and authorization. Before ordering a background check, the employer must give the candidate a clear, standalone written disclosure that a consumer report may be obtained, and must get the candidate's written authorization. The disclosure must be a separate document, not buried inside the job application or an offer letter, and the separateness is itself a thing a reviewer will check. Maria's record for each candidate stores the signed authorization with a timestamp, so the sequence of consent before collection is provable rather than asserted.

The second requirement is the two-step adverse action process, and this is where most employers stumble. If the report contains information that might lead to rejecting the candidate, the FCRA requires a pre-adverse action notice first: the employer sends the candidate the notice, a copy of the report, and a copy of the "Summary of Your Rights Under the FCRA," then waits a reasonable period, commonly understood as around five business days, so the candidate can dispute inaccuracies. Only after that waiting period, if the decision stands, does the employer send the final adverse action notice. Maria's documentation logs both notices with dates, the report copy provided, and the gap between them, because proving the candidate had a real window to dispute is the whole point. Handling the dispute process properly when a candidate does raise one belongs in the same file.

Where AI complicates this: if an automated tool flags a candidate based on background-check data such as employment history, you may have FCRA obligations attached to that flag, and the human reviewer must still own the adverse decision with the record showing it. Maria's template captures the AI flag as input, then a named recruiter's written rationale and sign-off as the decision. A background-check result should not silently override the evaluation without human consideration, and the file should demonstrate that the same standards were applied to every candidate rather than tightened for some. As for retention, employers should keep these records consistent with EEOC recordkeeping rules, generally at least one year, longer where other obligations or litigation holds apply; Maria standardized on a defined retention schedule confirmed with counsel rather than guessing.

EEO: Monitoring, and the Four-Fifths Rule Worked

Federal EEO law prohibits both intentional discrimination and practices that are neutral on their face but produce a disparate impact on a protected group. Its documentation demands are continuous rather than event-driven: recruit on equal terms for all candidates, maintain records of recruitment, selection and promotion, monitor for adverse impact, respond to investigations and EEOC charges, and do not discriminate based on protected characteristics. When an AI screening tool sits between applicants and interviews, it is exactly the kind of "selection procedure" the EEOC scrutinizes, which means the monitoring obligation attaches to the tool and the documentation of that monitoring becomes part of your file.

The standard rule of thumb regulators apply is the four-fifths rule, also called the 80 percent rule, drawn from the federal Uniform Guidelines on Employee Selection Procedures. Here it is worked with concrete numbers from Meridian's warehouse hiring funnel. Suppose the AI tool advances applicants to the interview stage at these rates. Group A: 60 of 100 applicants advance, a selection rate of 60 percent. Group B: 40 of 100 applicants advance, a selection rate of 40 percent. To apply the rule, divide the lower selection rate by the higher one: 40 percent divided by 60 percent equals 0.67, or about 67 percent. Because 67 percent falls below the 80 percent threshold, the result flags potential adverse impact and warrants investigation.

Two things matter about how Maria documents this. First, flagging adverse impact is not an automatic finding of illegal discrimination; it is a trigger to investigate whether the tool is job-related and consistent with business necessity, and whether a less discriminatory alternative exists. Second, the documentation must show that she ran the analysis, recorded the result, and acted on it. A recurring fear is that documenting a problem creates liability, on the theory that a written record proves you knew. The opposite is generally true: a contemporaneous record of monitoring, findings and corrective action demonstrates good faith. The genuine exposure comes from monitoring, finding a problem, and doing nothing, or from never monitoring at all. Maria runs this analysis quarterly per role family and keeps the numbers, the calculation and the follow-up decision in one file, so the reviewer can see not just the result but the practice.

GDPR: Lawful Basis, Data Rights, and Retention

For Meridian's Berlin hiring, the GDPR governs every resume, interview recording and assessment score, because all of it is personal data about identifiable people. Its general demands are familiar in outline: be transparent about how you use data, allow individuals access to their personal data, delete data when it is no longer needed, implement data security, and notify individuals if there is a breach. Four obligations in particular shape the documentation a reviewer will ask to see.

First, lawful basis. You cannot process candidate data without one of the GDPR's lawful bases. For recruiting, the basis is often "legitimate interests" or "necessary for taking steps prior to entering a contract," rather than consent, because consent freely given is hard to establish in an employment context where there is a power imbalance. Maria records the lawful basis relied on for each processing activity rather than reflexively collecting consent, which means the file answers the reviewer's question directly instead of producing a consent form that may not hold up.

Second, data subject rights. Candidates can request access to their data, correction, deletion (the "right to erasure"), and in defined cases object to automated decision-making. Article 22 gives individuals the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, with limited exceptions and safeguards. This is the strongest legal argument for Maria's separation principle: if a qualified human meaningfully reviews and owns the decision, it is not "solely" automated. Her documentation has to evidence that meaningful human involvement, not merely claim it, which is why a named reviewer and a written rationale sit in every record rather than a checkbox.

Third, retention limits. The GDPR's storage-limitation principle says you keep personal data no longer than necessary for the purpose. Meridian's Berlin policy, set with counsel, deletes rejected-candidate data after a defined period, for example six months to support handling any discrimination claim, unless the candidate consents to be kept in a talent pool. The retention schedule is written down and applied consistently, because a schedule that exists only in someone's head is indistinguishable, to a reviewer, from no schedule at all. Fourth, records of processing. Under Article 30, organizations must maintain records of processing activities describing what data is processed, why, the lawful basis, who it is shared with including the AI vendor as a processor, and retention periods. For Maria, the screening vendor is a processor, which means a data processing agreement and a clear record of the data flow are part of the file.

Beyond the Big Three: Building a Jurisdiction Matrix

The three frameworks above are the floor, not the ceiling, and a legal review will ask what else applies to your specific footprint. Three layers sit on top. Jurisdiction-specific requirements vary by state and country; some states, for instance, require specific pay-transparency language in job postings. Industry-specific requirements add further obligations, and financial services is the standard example, carrying hiring and background-check requirements beyond standard EEO. Company-specific policies form the third layer, and they are frequently stricter than the legal minimum, which matters because a reviewer will hold you to your own written policy as readily as to a statute.

Maria does not hire in New York City, but one of her peers does, and Local Law 144 is the cleanest example of a jurisdiction writing AI-specific rules. Effective for enforcement in July 2023, NYC Local Law 144 regulates "automated employment decision tools" used to screen candidates or employees for positions in the city. It requires three concrete things: an independent bias audit of the tool conducted within the prior year, publication of a summary of the audit results, and advance notice to candidates that such a tool is being used, along with the job qualifications and characteristics it assesses. The lesson for documentation is that the bias audit is a deliverable you must be able to produce, not a posture you can assert. If you operate anywhere with rules like this, your records need to include the audit report, the publication date and location, and proof that candidate notice was given. Because other jurisdictions are moving in similar directions, Maria's team keeps a simple jurisdiction matrix mapping where they hire to which rules apply, and revisits it rather than treating it as a one-time exercise.

What a Defensible File Looks Like

A defensible system does not require heroic effort; it requires that the right record gets created at the moment of decision rather than reconstructed under pressure. Maria's per-candidate decision record has a fixed shape. It captures the AI input clearly labeled as input, meaning the score or flag and the tool version; the human reviewer's name and written rationale; the final decision and its date; any notices sent with their dates; and the retention class that determines when the record is purged. The fixed shape is doing the work: because every record has the same fields, a gap is visible immediately rather than discovered by a reviewer.

The design goal is that an outside reviewer, reading the file cold, can answer Maria's general counsel's original question in under a minute: what did the AI suggest, what did the human conclude, who decided, and on what basis. Separation of AI input from human judgment is not a formatting preference; in an Article 22 challenge or an EEOC inquiry it is frequently the difference between a defensible decision and an indefensible one. Two practical failure modes are worth naming. The first is records that exist but cannot be retrieved or read, which are nearly as bad as no records at all, so design for retrieval and not merely for storage. Compliance is often treated as a question of whether records exist rather than whether they are organized and useful, and a reviewer who receives a box of unsorted material learns nothing helpful about your process. The second is documentation so burdensome that recruiters quietly stop doing it, which leaves you with policy on paper and nothing in the file. Build the record into the workflow so creating it is the path of least resistance.

Everything above is a framework for a conversation with counsel, not a substitute for it. The recruiting operations leader's job is not to be a lawyer; it is to bring legal a clear map of where you hire, which tools you use, what data flows where, and what you currently document, so legal can tell you what is missing and what is excessive. Both halves of that sentence matter: teams routinely discover they are under-documenting one regime while collecting material no rule requires and that becomes a liability to store. Bring legal in before you deploy a tool, not after a complaint arrives, and include them in discussions about tools, processes and corrective actions rather than surfacing only when something has gone wrong.

Ask them specifically to confirm your retention schedules, your adverse action templates, your lawful-basis determinations, and whether any jurisdiction-specific rule like Local Law 144 applies to your footprint. Ask, too, whether they share the view that monitoring is protective, because occasionally the advice runs the other way and it is worth resolving explicitly rather than by silence. A documentation system reviewed and signed off by counsel is itself a piece of defensible evidence that you took compliance seriously, and the sign-off is worth capturing with a date. The goal of the partnership is not permission. It is designing systems that are compliant and practical at once, because compliance that is too burdensome will not be followed and unfollowed policy is worse than no policy.

Five Common Compliance Mistakes

  • Not knowing which requirements apply. You recruit across several jurisdictions without a clear map of which rules govern which hire, so the question of compliance cannot even be asked coherently.
  • Avoiding documentation. Believing that recording bias monitoring creates risk, so the monitoring itself never happens, which converts an evidentiary gap into a substantive one.
  • Over-complicating compliance. Building a documentation regime so elaborate that nobody actually completes it, leaving you with an impressive policy and empty files.
  • Not partnering with legal. Going it alone and guessing at requirements rather than getting expertise that would have taken an hour to obtain.
  • Being reactive rather than proactive. Addressing compliance only when a problem surfaces, at which point the records you needed had to have been created months earlier.

Anti-Patterns

"We are compliant" without verification. A company assumes its recruiting process meets requirements and never checks with legal. When an issue arises and someone asks, the team discovers it missed major obligations. It happens because compliance is quietly assumed to be somebody else's responsibility, so nobody owns the question and it never gets asked. What goes wrong is that gaps surface at the worst possible moment, during a review rather than before one, and by then the missing records cannot be created retroactively without looking exactly like what they would be. The fix is to have legal review your process and your documentation and to get explicit confirmation, recorded and dated, rather than an absence of objection.

Compliance without practicality. Suppose the applicable rule requires detailed records for three years. The company duly maintains them, but they are unorganized and hard to retrieve, so when a question arrives the records technically exist and are useless. It happens because compliance gets framed as having records rather than having organized, retrievable, useful records, and the first framing is much easier to satisfy. What goes wrong is that you carry the full cost of documentation and receive none of its benefit: you cannot defend a decision with material you cannot find or interpret. The fix is to work with legal to design a system that satisfies the requirement and can actually be used, which usually means structure and retrieval, not more volume.

Treating monitoring as a legal risk. Legal advises against monitoring the AI for disparate impact on the theory that documenting a known problem creates liability. So the company does not audit, and bias goes undetected and uncorrected. It happens through a misunderstanding of where the risk actually sits, and it can come from either side of the table. What goes wrong is compounding: the underlying disparity persists, and the absence of monitoring is itself the harder fact to explain later. The fix is to work through it with legal explicitly, because documenting that you monitor is protective. Monitoring and then not acting is the position that creates exposure, and never monitoring at all is not a safe harbor.

Practice Prompts

  • Map your requirements. For your jurisdictions and the industries you hire into, list the legal requirements that apply to recruiting documentation. Then mark each one as met, partially met, or unknown against your current practice, and note where the divergences cluster.
  • Book the review. Meet with your legal team and walk them through your current documentation practices. Ask two questions explicitly: what is missing, and what are we collecting that we should not be?
  • Design the system. Draft a documentation system that meets FCRA, EEO, GDPR where applicable, and your local requirements, without being onerous. Test the draft by asking whether a busy recruiter would complete it under deadline pressure.
  • Write a pre-deployment checklist. Before any AI tool goes live, what boxes must be checked? Include fairness monitoring, bias audit trails, candidate notice where required, and documentation standards, and name who signs each one off.
  • Assemble the evidence packet. For each framework, identify precisely what documentation would demonstrate compliance in an audit or legal challenge. Then try to produce it from your current records and see how far you get.

Reflection

  • Do you know the legal requirements for recruiting in every jurisdiction where you hire, and in the industries you hire into? Where does that knowledge live?
  • What would your legal team say about your current documentation practices? Have you actually asked, or are you predicting?
  • If you were audited or faced a legal challenge tomorrow, would your documentation help you or hurt you?
  • Which compliance requirement feels most onerous to your team? How could you make it more practical without weakening it?
  • How would you explain to your recruiters why this matters, in terms of their daily work rather than in terms of liability?

Glossary

  • FCRA (Fair Credit Reporting Act). US law governing background checks and employment screening through third-party consumer reports, including disclosure, authorization and the adverse action sequence.
  • Adverse action process. The two-step FCRA sequence: a pre-adverse action notice with a copy of the report and the summary of rights, a reasonable waiting period for the candidate to dispute, then a final adverse action notice if the decision stands.
  • EEO (Equal Employment Opportunity). US law ensuring non-discrimination in employment, carrying obligations to recruit on equal terms, keep selection records, monitor for adverse impact and respond to EEOC charges.
  • Disparate impact. An outcome in which a facially neutral practice disproportionately affects a protected group. A flag is a trigger to investigate job-relatedness and business necessity, not an automatic finding of discrimination.
  • Four-fifths rule. The regulators' rule of thumb from the Uniform Guidelines on Employee Selection Procedures: divide the lower selection rate by the higher, and a result below 80 percent flags potential adverse impact.
  • GDPR (General Data Protection Regulation). EU law protecting personal data, requiring a lawful basis for processing, transparency, data subject rights, security, breach notification and storage limitation.
  • Lawful basis. The GDPR ground on which you process personal data. In recruiting this is often legitimate interests or steps prior to entering a contract, rather than consent, given the employment power imbalance.
  • Article 22. The GDPR provision giving individuals the right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects, subject to limited exceptions and safeguards.
  • Article 30 records of processing. The record describing what personal data you process, why, on what lawful basis, who it is shared with including processors such as an AI vendor, and for how long.
  • Automated employment decision tool. The category regulated by NYC Local Law 144, which requires an independent bias audit within the prior year, publication of a summary of results, and advance candidate notice.

Closing

Legal compliance is not only about avoiding liability. It is about building recruiting systems you can defend and would be willing to show anyone. Documenting your monitoring and your corrective actions is simultaneously the legally protective move and the operationally useful one, because the same records that answer a reviewer are the records that let you find and fix a problem before a reviewer arrives. The best recruiting organizations treat compliance not as a burden bolted onto the process but as the framework that makes the process fair and provable, and they partner with legal early enough that the requirements shape the system rather than indicting it. When your documentation is clear, your processes are consistent, and your monitoring is active and recorded, you have built something worth defending.

Key Takeaways

  • A legal review is a document request, not a conversation about intent. Defensibility lives in records created at the moment of decision. Reconstructing a file under a complaint is where organizations lose.
  • Separate AI input from human judgment on the page. Label the score or flag as input, name the human reviewer, record the written rationale and the basis for the final decision. Blended into one score, it reads as automation; separated, it reads as a human decision that used a tool.
  • FCRA is a sequence you must prove you followed. Standalone disclosure and written authorization before the check, then a pre-adverse action notice with a copy of the report and the summary of rights, a reasonable waiting window commonly understood as around five business days, and only then the final adverse action notice. Log every step with dates.
  • The four-fifths rule is a trigger, not a verdict. Divide the lower selection rate by the higher: 40 percent over 60 percent is about 67 percent, below the 80 percent threshold, so it flags potential adverse impact and warrants investigation of job-relatedness, business necessity and less discriminatory alternatives.
  • Monitoring and documenting is protective, not risky. A contemporaneous record of monitoring, findings and corrective action demonstrates good faith. The exposure comes from monitoring and doing nothing, or from never monitoring at all.
  • GDPR governs EU candidate data end to end. Record a lawful basis per processing activity rather than reflexively collecting consent, honor data subject rights including the Article 22 limit on solely automated decisions, apply written retention limits, and keep Article 30 records naming your AI vendor as a processor.
  • Keep a jurisdiction matrix, because the floor moves. Jurisdiction, industry and company-specific rules stack on top of the big three, and rules like NYC Local Law 144 make an independent bias audit, published results and candidate notice into deliverables you must be able to produce.
  • Design for retrieval and for human use. Records nobody can find or read, and documentation so heavy that recruiters abandon it, both fail in practice. Make the right record the path of least resistance inside the workflow.
  • This is a framework for legal, not a replacement for it. Bring counsel a map of jurisdictions, tools, data flows and current documentation before deploying, and have them confirm retention schedules, notice templates, lawful bases and jurisdiction-specific obligations.

Frequently Asked Questions

Does documenting a fairness problem create liability we would not otherwise have? This is the most common fear and it generally has the answer backwards. A contemporaneous record of monitoring, what you found, and what you did about it demonstrates good faith. The genuine exposure comes from monitoring, finding a problem, and doing nothing, or from never monitoring at all, since the obligation to avoid disparate impact does not disappear because you declined to look. If your counsel advises otherwise, resolve the disagreement explicitly rather than letting it settle by default into no monitoring.

Our vendor ran a bias audit. Is that our documentation? It is part of the file and worth keeping, particularly where a rule such as NYC Local Law 144 requires an independent bias audit within the prior year and publication of a summary of results. But the audit is a deliverable about the tool, not a record of your decisions. A reviewer asking how a specific candidate was rejected needs your per-candidate record: the AI input labeled as input, the named human reviewer, the written rationale, the date, and the notices sent. Keep both, and do not let one stand in for the other.

How long should we keep these records? Long enough to satisfy every obligation that applies to you, confirmed with counsel rather than remembered. For US hiring records, keep them consistent with EEOC recordkeeping rules, generally at least one year, and longer where other obligations or a litigation hold apply. For EU candidate data, the GDPR storage-limitation principle pulls the other way, so set a defined period tied to the purpose, for example six months for rejected candidates to support handling any discrimination claim, unless the candidate consents to a talent pool. Write the schedule down, assign each record a retention class, and apply it consistently.

The AI flagged a candidate on background-check data. Who owns that rejection? A named human, and the record must show it. If an automated tool flags a candidate based on data such as employment history, you may have FCRA obligations attached to that flag, and a background-check result should not override the evaluation without human consideration. The template Maria uses captures the flag as input and then a recruiter's written rationale and sign-off as the decision, which is also what makes the decision something other than "solely automated" under Article 22 for candidates covered by the GDPR.

What should we actually bring to the first meeting with legal? A map, not a question. Bring where you hire, which tools you use at which stage, what data flows where and to which vendors, what you currently document per decision, and how long you keep it. That lets counsel tell you what is missing and what is excessive in one pass, instead of spending the meeting establishing the facts. Ask them to confirm retention schedules, adverse action templates, lawful-basis determinations and whether any jurisdiction-specific rule applies to your footprint, and capture the sign-off with a date.