TLDR: Hiring inside a regulated company is itself a regulated activity. Lawful data handling, criteria fixed before sourcing, human accountability over AI screening and a written decision record are what turn recruitment into a defensible process.
Candidate data attracts the same obligations as any other personal data you hold
Recruitment produces one of the densest personal-data sets a company ever touches. A single shortlist can contain employment histories, salary expectations, referee comments, interview notes, and — where permits are involved — nationality and residence status. Pharma, MedTech and finance employers run disciplined systems over clinical and transactional data, then frequently let candidate files accumulate in inboxes and spreadsheets outside all of them. The asymmetry has a structural cause worth naming: validated systems get built where an inspector is expected to look, and a hiring shortlist sits outside the scope of a GMP inspection or a FINMA supervisory review, so nothing ever forced the same rigour onto it. Four obligations carry most of the weight here: process for a stated purpose, collect only what the role requires, secure it properly, and delete it when the justification expires. Each is testable, and each is routinely failed by a shared mailbox.
The lawful basis for most recruitment processing is narrow. Handling an application is generally justified as a step taken at the candidate’s request before a contract, or under legitimate interests where the employer can show the processing is proportionate. That narrowness is the mechanism that catches employers out, because a basis attaches to a purpose rather than to a person and expires with that purpose. Searching a candidate’s social profiles, retaining a rejected applicant’s file for a future vacancy, or running a psychometric profile all extend beyond the original purpose, so each needs its own basis rather than inheriting the first one. Where the extension is genuinely optional for the candidate, separate and specific consent is the cleanest route, and it should be as easy to withdraw as it was to give. Consent buried inside an application flow rarely holds up, since a candidate hoping for an offer has little practical freedom to refuse it.
Minimisation deserves more attention than it usually gets, because a field on an application form rarely stays inert. It becomes a column in the applicant tracking system, then a filter, then a potential input to a ranking model, and finally a piece of evidence in any complaint about how the shortlist was formed. Date of birth, photograph, marital status, and nationality beyond a right-to-work check contribute nothing to a competency judgement while creating exactly that trail. Guidance published by the European Data Protection Board on lawful processing consistently returns to this point, and stripping the fields is the cheapest control available. It is also the only control that works retroactively: a field never captured cannot be filtered on later, cannot leak, and cannot become the disputed centre of a claim.
Swiss employers carry a second layer through the revised Federal Act on Data Protection, which raised transparency and record-keeping expectations to sit closer to the European regime. Retention is where the two frameworks bite hardest in practice. Keeping every CV indefinitely converts a lawful one-off processing into an open-ended one that needs its own justification and that nobody has documented. Set a defined retention window from the moment the process closes, ask explicitly whether the candidate wants to stay in a talent pool, and log the deletion. Cross-border storage adds a third question, since an EU, Swiss and US hiring footprint means candidate files routinely move between jurisdictions with different transfer requirements — often invisibly, through an applicant tracking system whose hosting region nobody has checked. Handling that cleanly makes a process lawful, a smaller claim than making it fair, and fairness is settled earlier, in how the role was defined.
Criteria fixed before sourcing are what make a rejection explainable
The decisive act in a defensible hiring process happens before a single CV arrives. When the hiring manager, the recruiter and any technical assessor agree in writing what competent looks like for the role — and what evidence would demonstrate it — every later judgement has a fixed reference point. Where that agreement is missing, the criteria form themselves gradually out of the candidates who happen to appear, which is comfortable for everyone involved and impossible to defend afterwards. A workable scorecard stays short: five or six competencies, one sentence defining each, and a named form of evidence that would count — a submission the candidate authored, an inspection they fronted, a validation protocol they wrote. Naming the evidence stops a competency from drifting into a personality trait during the panel discussion.
Criteria written after the interviews are unfalsifiable by construction. Once a panel has met a candidate it likes, the requirement set quietly reshapes itself around that person’s profile: the regulatory affairs role that needed submission experience becomes a role that needed stakeholder presence, because the strongest interviewee had the latter. Nobody experiences this as dishonesty. It happens because human judgement runs conclusion-first and reason-second, and an unfixed criteria list offers no friction against that. Dating and circulating the scorecard before sourcing begins creates the friction, and it also gives the recruiter something concrete to brief a market against. The dating matters as much as the content, because a document with a timestamp preceding the first application is the single artefact that demonstrates the standard was not written around the winner.
Structured interviewing then makes the criteria operational. Every candidate answers the same core questions in the same order, each interviewer scores each competency independently, and scores are recorded before the panel discusses anyone. That ordering matters more than the questions themselves. When a panel debates first and scores second, the first confident opinion anchors the room and the remaining scores converge toward it, so five assessments collapse into one. Independent scoring preserves genuine disagreement, which is the only signal a panel has that a candidate is a real risk rather than a stylistic mismatch. It also converts the interview into evidence: a set of per-competency scores from named assessors, captured before discussion, is a record that can be examined later, whereas a consensus reached in conversation leaves only a conclusion.
Structure has a failure mode worth naming. Scoring schemes built around a single expected career path screen out exactly the people regulated employers most need, because careers in this sector move sideways: a quality lead who spent four years at a notified body, a clinical scientist who moved into a MedTech start-up, a compliance officer who arrived through audit rather than law. The fix keeps the competency fixed and opens the evidence. Score whether the candidate can run an MDR technical documentation review, rather than whether they held a titled MDR role, and the structure begins filtering for capability instead of for a conventional CV. Consistent criteria and consistent scoring cover the human part of the funnel, and say nothing yet about the software that increasingly decides which applications a person ever reads.
| Stage | Data obligation | Evidence to retain |
|---|---|---|
| Role definition | None yet | Dated competency scorecard, agreed by panel |
| Application | Role-relevant fields only; stated purpose and retention period | Application form version and privacy notice shown |
| Screening | Human review of any automated ranking | Criteria applied, reviewer name, tool version |
| Interview | Notes confined to job-relevant evidence | Independent scores per competency, per interviewer |
| Decision | Reasons recorded against the agreed criteria | Signed decision summary naming the decision-maker |
| Close-out | Delete, or obtain consent for a talent pool | Retention and deletion log |
AI screening moves accountability onto the employer, never onto the vendor
Screening and ranking software has become ordinary infrastructure in talent teams, and the legal position around it has hardened accordingly. The pattern that creates risk is familiar from any regulated technology purchase: a buyer assumes that a compliant supplier delivers a compliant deployment. Recruitment tooling behaves the opposite way, because the obligations that matter attach to the organisation running the system on real candidates. Quality functions in pharma and MedTech already understand this shape from computerised system validation, where a vendor supplies a qualified product and the operating company still owns intended use, user requirements and ongoing verification. Talent teams that borrow that mental model — supplier documentation as an input, deployer responsibility as the obligation — arrive at the right governance far more quickly than teams treating the purchase as a software licence.
The European framework treats recruitment and selection systems as high-risk, placing duties on the organisation deploying a tool alongside those on the company that built it. Deployer duties centre on meaningful human oversight, on using the system within the purpose the provider documented, and on informing the people subjected to it. A procurement conversation therefore covers more than accuracy claims: it establishes what the model was validated against, which population it was validated on, and what documentation the provider will supply to support the employer’s own obligations. Talent teams that bring their legal and quality functions into that conversation reach a usable answer considerably faster. The documented purpose is the clause that most often bites later, since a tool validated for graduate volume screening carries no support for the employer who repurposes it against senior regulatory hires.
European data protection law adds a separate constraint on decisions taken by machine alone where they significantly affect a person, and rejection from a job qualifies comfortably. The operative word is solely, and it is judged on substance. A recruiter who receives a ranked list of two hundred applicants and progresses the top ten without reading the rest has added a signature to an automated outcome rather than a judgement. Genuine oversight requires a reviewer with the information to disagree, the authority to overturn, and enough time allocated to do it — which makes it a resourcing decision as much as a policy one. The practical test is whether the reviewer can see anything beyond the rank: given only an ordered list and no underlying evidence, no amount of reviewer seniority produces oversight, because there is nothing available to disagree with.
Testing for adverse impact closes the loop. Models fitted to a company’s historical hires learn the composition of those hires, so a tool trained on a decade of one demographic profile will reproduce it while reporting excellent predictive accuracy against its own training target. Measuring pass-through rates by group at each funnel stage surfaces that pattern in a way accuracy metrics never will, because accuracy is measured against the historical decision and the historical decision is the thing under suspicion. Recording the model version alongside each screening round matters just as much, since vendors update models continuously and an unannounced change can shift screening behaviour between two candidates in the same campaign. Oversight of this kind generates evidence only when someone writes it down, which is equally true of every human judgement in the funnel.
A written decision record is the only account that survives a challenge
Twelve months after a hire, institutional memory of why one finalist was chosen over another has usually evaporated. The panel has reorganised, the recruiter has moved on, and the surviving artefacts are a calendar invitation and an offer letter. A decision record written at the time, in a few hundred words, separates an employer that can explain itself from one that reconstructs a rationale under pressure. The difference is visible to anyone reading the two: a contemporaneous record cites specific evidence a panel could only have known then, while a reconstruction speaks in general terms about strength of fit. Where a candidate exercises an access right under the GDPR or the revised Swiss FADP, that distinction determines whether the employer is producing a file or drafting an explanation.
A useful record is short and specific. It names the criteria that were agreed, states how the chosen candidate evidenced each one, identifies where the runner-up scored differently, names the person who made the final call, and notes anything the panel decided to accept as a development gap. That last element carries surprising weight, because it converts a known weakness into a documented, managed choice rather than something the organisation later appears to have missed. Where an assessment tool contributed, the record cites the tool, its version and the person who reviewed its output. Naming a single decision-maker matters more than it looks: a decision attributed to a panel belongs to nobody, and a rationale nobody owns is the one that dissolves first when someone asks how the choice was actually made.
Writing the record also improves the decision it documents. Panels reach consensus on vague formulations far more easily than on precise ones, and a phrase such as not quite the right fit survives a discussion comfortably while collapsing the moment someone has to write down which competency the candidate failed to evidence. Forcing the articulation surfaces disagreements the panel had glossed over, and occasionally reverses the outcome. It takes ten minutes, and it happens while the evidence is still fresh enough to be accurate. The mechanism is the same one that makes structured scoring work: imprecise language lets several people believe they agreed when they did not, and writing is the cheapest available instrument for finding out whether the agreement was real.
Over a year, these records accumulate into a management asset most talent functions lack entirely. They show which hiring managers score consistently and which drift, which competencies predicted performance and which turned out to be decoration, and where offers were declined for reasons the organisation can actually address. A talent team holding two years of decision records can revise its scorecards from evidence, brief interviewers on their own calibration, and give a CHRO a defensible account of how the company selects people. The compliance benefit arrives as a by-product. That inversion is what makes the discipline durable, since a control that produces something the business wants survives budget scrutiny in a way a purely defensive one never does.
These four disciplines reinforce each other, and each is achievable within a quarter using tools most regulated employers already own. The harder question is which of them your current process would fail if a rejected candidate asked, in writing, for the reasons. That request is inexpensive for the candidate to make and increasingly normal, and it arrives as a deadline rather than an invitation. An employer that can answer it in a morning has a hiring process; an employer that needs a working group to assemble an answer has a set of habits. Running the test against a live vacancy, before anyone external asks, is the version of the exercise that costs nothing.
Edward Galle runs search for pharma, MedTech, life sciences and finance employers across Switzerland, the EU and the US on exactly this model: criteria agreed in advance, structured assessment, documented decisions. To pressure-test how your own process would hold up, speak with our team about a live vacancy ou review how we work with regulated employers.
References
- European Data Protection Board. https://www.edpb.europa.eu/
- European Commission — The EU Artificial Intelligence Act. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai