Compliance — EU AI Act & GDPR
Scope
Scope: obligations of the Deployer (you, as a customer), obligations of the Provider (Omogen), and product-level implementation of the EU AI Act and GDPR for the AI voice pre-screening interview agent (Mio) and the AI CV scanner (CV Screener).
Intended audience: compliance and legal officers (Parts 1 and 2, full document), and recruiters / end users (Part 3, practical guide).
Classification: internal and customer use — confidential.
| Document version | 1.0 |
| Date | July 2, 2026 |
| Prepared for | Omogen — Compliance & Legal |
| Systems covered | Mio (AI voice pre-screening interview agent), AI CV Scanner |
| Classification (EU AI Act) | High-risk AI system — Annex III, point 4(a) (employment/workforce management) |
| Next review | July 2, 2027 |
How to use this page
This page describes, in three parts, the compliance obligations applicable to the deployment of Omogen's AI systems (Mio and CV Screener) in recruitment, as well as how these obligations are implemented in the product.
- Part 1 is primarily addressed to your compliance and legal teams, and describes the obligations you assume as a Deployer of a high-risk AI system under the EU AI Act, as well as the related GDPR obligations as a Data Controller.
- Part 2 is addressed to Omogen's internal compliance and legal function, and describes Omogen's obligations as a Provider of a high-risk AI system, as well as the related GDPR obligations as a Data Processor.
- Part 3 translates Parts 1 and 2 into concrete product features and daily best practices, for recruiters and other end users of the platform, as well as for compliance officers who need to verify that the product's behavior matches the legal obligations.
Note
This page is a compliance reference document. It does not constitute legal advice. You should consult independent legal counsel to confirm how these obligations apply to your specific organization and jurisdiction.
Quick reference: who is responsible for what
| Area | Customer (Deployer / Data Controller) | Omogen (Provider / Data Processor) |
|---|---|---|
| Legal role, AI Act | Deployer of a high-risk AI system (art. 26-27) | Provider of a high-risk AI system (art. 8-21, 43, 47-49, 72-73) |
| Legal role, GDPR | Data Controller | Data Processor (+ independent controller for its own billing/analytics) |
| Candidate information | Informs candidates of AI use, and that phone interviews via Mio are recorded | Provides the consent script, transparency materials |
| Final hiring decision | Always the customer, never Omogen | Provides a decision-support tool only |
| System compliance (CE marking, risk management, technical documentation) | N/A | Full responsibility |
| Data hosting and security | N/A | Full responsibility |
| GDPR DPIA (art. 35) | Customer's responsibility — likely applies to most deployments | Provides system-level information to support the Customer's DPIA |
| FRIA (art. 27) — conditional, see §1.2.7 | Customer's responsibility, only if the Customer is a public-law body / public service provider | Provides system-level factual data on request; does not complete the FRIA |
Part 1 — Your obligations as Deployer of the AI system
This part is addressed to your compliance and legal officers. It sets out, article by article, what the EU AI Act and GDPR require of an organization deploying Omogen's Mio or CV Screener in its recruitment process.
1.1 Legal qualification
Under Regulation (EU) 2024/1689 (the "AI Act"), any organization that uses Mio or CV Screener under its own authority, in the course of a professional activity, is a Deployer within the meaning of Article 3(4).
Since Mio and CV Screener are used to make or support decisions that have a material impact on the outcome of a recruitment process — including shortlisting, filtering, and evaluating candidates — the systems fall under Annex III, point 4(a) of the AI Act ("AI systems intended to be used for the recruitment or selection of natural persons, notably to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates"). This means the AI system is classified as high-risk, and Customers using it acquire the full set of Deployer obligations set out in Articles 26 and 27.
Legal basis: AI Act, Articles 3(4), 6(2), and Annex III, §4(a).
At the same time, for GDPR purposes, you are the Data Controller for all processing of candidates' personal data carried out via the Service, since you determine the purposes of the processing (who to recruit) and the essential means (which candidates to contact, which criteria to apply). Omogen is the Data Processor, acting only on your documented instructions.
Legal basis: GDPR, Articles 4(7) and 4(8), 24, 28.
1.2 Core Deployer obligations under the AI Act
Article 26 of the AI Act sets out a closed list of obligations for deployers of high-risk AI systems. Each is addressed below with its practical translation for recruitment.
1.2.1 Use the system in accordance with the instructions for use
Requirement: you must operate Mio and CV Screener strictly in accordance with the Instructions for Use (IFU) provided by Omogen, including the intended purpose, operating conditions, and configuration guidance.
In practice: job criteria must be defined honestly and specifically; the system must not be configured to ask prohibited questions; the system must not be used for job categories or purposes outside its documented intended use.
Legal basis: AI Act, Article 26(1).
1.2.2 Assign human oversight to competent, trained, and authorized natural persons
Critical obligation
You must designate specific individuals with the competence, training, and authority necessary to exercise human oversight, and ensure they exercise it in practice — not just on paper.
Requirement: human oversight must be meaningful. The reviewer must have the authority to overturn the AI's recommendation and the training necessary to do so knowledgeably.
In practice: you must complete Omogen's Customer Training Pack / "Playbook" before any user (e.g., a recruiter) is granted access to review candidate results. The reviewer's identity is recorded for every decision (see Part 3.2).
Legal basis: AI Act, Article 26(2), and Article 14.
1.2.3 Ensure input data is relevant and sufficiently representative
Requirement: where you exercise control over input data (e.g., by defining job criteria, uploading CVs, selecting candidate pools), you must ensure the data is relevant to the system's intended purpose.
In practice: job criteria must reflect real, job-related requirements. Criteria must not be defined in a way that functions as an indirect proxy for a protected characteristic (e.g., "must live within 2 km of the office" as an indirect way to exclude candidates with disabilities or from certain backgrounds).
Legal basis: AI Act, Article 26(4).
1.2.4 Monitor the system's operation and inform the provider of risks
Requirement: you must monitor the system's operation based on the instructions for use and, where you have reason to consider that use in accordance with the instructions may lead the AI system to present a risk, inform Omogen and the relevant distributor without delay, and suspend use.
In practice: if a recruiter observes a consistent pattern of poor transcription for a given accent group, unexpected scoring behavior, a confirmed data leak, or any output that appears discriminatory, this must be reported to Omogen (support@omogen.ai or by contacting your CSM) and use of the affected feature must be suspended pending investigation.
Legal basis: AI Act, Article 26(5).
1.2.5 Retain automatically generated logs
Requirement: where logs are under your control, they must be retained for a period appropriate to the system's intended purpose, of at least six months, unless otherwise provided by applicable law.
In practice: human review records (reviewer, date, decision, reasoning) must be retained by you for five (5) years. Since the AI tool is used for recruitment, you are exposed to potential discrimination claims. Under French labor law, the limitation period for discrimination claims is five years and only starts running from the discovery of the discrimination, which means you must keep this evidence to defend your hiring decisions.
Legal basis: AI Act, Article 26(6); French Labour Code, Articles L1471-1 and L1134-5.
1.2.6 Inform workers and their representatives
Requirement: before putting a high-risk AI system into service in the workplace, deployer employers must inform the workers/candidates concerned and, where applicable, worker representatives, that they will be subject to the use of the high-risk AI system.
In practice: candidates must be informed, before or at the start of the interaction, that an AI system (Mio and/or CV Screener) is being used, and directed to your privacy policy. A default transparency notice template is provided by Omogen.
Legal basis: AI Act, Article 26(7).
1.2.7 Carry out a Fundamental Rights Impact Assessment (FRIA) — where applicable
Scope — read before acting
Unlike the other obligations in this part, the Article 27 FRIA does not apply to all customers. You should carefully check whether it applies to your organization before assuming so — most private-sector employers using Mio or CV Screener to recruit their own staff will not be covered, although the GDPR DPIA below will still apply.
Who is covered: under Article 27(1), a FRIA is strictly mandatory only for:
- public-law bodies, or private entities providing public services (e.g., public administrations, public hospitals, utility services);
- deployers of certain specific high-risk systems in the banking/insurance sectors (credit scoring and risk pricing).
Note: recruitment tools fall under Annex III, §4(a), which means a private recruitment company is exempt unless it acts under public law or explicitly provides a delegated public service.
The requirement: where you determine that you are covered, you must carry out a FRIA assessing your specific processes, the categories of candidates concerned, the risks of harm, human oversight measures, and post-market mitigation measures. The assessment, as well as the decision on whether Article 27 applies to your organization, is your own legal determination to make, ideally with your own counsel.
Omogen's role: in accordance with Article 27(5), the EU AI Office provides the official, standardized FRIA template; Omogen does not provide a proprietary template. On request, Omogen will provide you with the system-level technical indicators (accuracy rates, known limitations, oversight anchor points) needed to complete the official EU questionnaire. Omogen does not complete the FRIA on your behalf.
Legal basis: AI Act, Article 27(1) and (5).
1.2.8 Cooperate with competent authorities
Requirement: you must fully cooperate with national supervisory authorities regarding any regulatory action taken in connection with the high-risk AI system. This includes providing the operational information and documentation requested, in the language reasonably requested.
Legal basis: AI Act, Article 26(9).
1.2.9 Register in the EU database (public bodies only)
Requirement: where you are a public authority, public body, or a private entity acting on their behalf, you must register your specific deployment of the high-risk system in the official EU database referred to in Article 71, before putting it into service.
Note: this is distinct from Omogen's own obligation to register the underlying software. Traditional private-sector recruitment agencies are exempt from this requirement.
Legal basis: AI Act, Article 26(8), and Article 49.
1.3 Related GDPR obligations as Data Controller
Independently of the AI Act, you bear full Data Controller responsibility under the GDPR for the processing of candidates' personal data carried out via the Service.
| Obligation | Requirement | GDPR Article |
|---|---|---|
| Legal basis | Identify and document a legal basis for processing (typically legitimate interest for shortlisting, or consent for voice recording and optional steps) | Art. 6 |
| Special categories of data | Must not seek to process sensitive data (health, religion, ethnic origin, etc.); must cooperate with Omogen's detection/deletion protocol in case of inadvertent capture | Art. 9 |
| Transparency | Provide candidates with a privacy notice covering AI use, purposes, retention, and rights | Art. 13 |
| Automated decision-making | Ensure that no decision producing legal effects or significantly affecting a person is based solely on automated processing, without meaningful human intervention | Art. 22 |
| Data subject rights | Respond to candidates' access, rectification, erasure, objection, and explanation requests within legal deadlines | Art. 15–22 |
| DPIA | Carry out or contribute to a data protection impact assessment prior to deployment (automated screening + large-scale shortlisting creates a strong legal presumption of this requirement) | Art. 35 |
| Records of processing | Maintain, or contribute data-flow information to, a record of processing activities | Art. 30 |
| Breach notification | Notify the supervisory authority of qualifying breaches within 72 hours of discovery (Omogen will inform you without delay to enable this) | Art. 33 |
1.4 Consequences of non-compliance
WARNING
AI Act and GDPR penalties apply cumulatively and independently. A single incident (e.g., an unreviewed discriminatory rejection) can trigger exposure under both frameworks, as well as under French labor law.
| Infringement | Regulatory fine | Other exposure |
|---|---|---|
| Breach of Deployer obligations (e.g., total absence of human oversight) — AI Act | Up to €15 million or 3% of total worldwide annual turnover, whichever is higher | Civil liability, permanent contract termination, and severe reputational damage |
| GDPR breach (e.g., unlawful processing of biometric voice data, absence of a DPIA) | Up to €20 million or 4% of total worldwide annual turnover, whichever is higher | Formal notice from the CNIL, mandatory public audits, or immediate processing ban |
| Hiring discrimination (French Labour Code) | Up to €45,000 fine for individuals, plus possible imprisonment | Civil damages, mandatory candidate reinstatement orders, and company blacklisting |
| Unlawful voice recording (French Criminal Code, art. 226-1) | Up to €45,000 fine and up to 1 year imprisonment | Direct criminal prosecution of the responsible individuals or executives |
Part 2 — Omogen's obligations as Provider
This part is addressed to Omogen's internal compliance and legal function. It sets out Omogen's own obligations as Provider of a high-risk AI system, and as Processor of candidates' personal data.
2.1 Legal qualification
Omogen SAS is the Provider, within the meaning of Article 3(3) of the AI Act, of Mio and CV Screener: it develops these high-risk AI systems and places them on the market under its own name. As Provider, Omogen bears the most extensive set of obligations under the Regulation, set out in Articles 8 to 21 (substantive requirements and general provider obligations), Article 43 (conformity assessment), Articles 47 to 49 (EU declaration of conformity, CE marking, and registration in the EU database), and Articles 72 to 73 (post-market monitoring and serious incident reporting).
For GDPR purposes, Omogen acts as Data Processor for personal data processed on behalf of Customers in the course of providing the Service, and as an independent Data Controller for its own account management, billing, and product-improvement analytics.
2.2 Core Provider obligations under the AI Act
2.2.1 Risk management system
Requirement: establish, implement, document, and maintain a risk management system as a continuous, iterative process throughout the AI system's lifecycle, identifying known and foreseeable risks to health, safety, and fundamental rights.
Implementation at Omogen: risks identified, assessed using a probability/impact matrix, documented mitigation plans, owner, and timeline. Risk register continuously monitored — and reviewed quarterly.
Legal basis: AI Act, Article 9.
2.2.2 Data and data governance
Requirement: training, validation, and testing datasets must be subject to appropriate data governance, be relevant, sufficiently representative, and, as far as possible, free of errors; examine biases likely to affect health, safety, or fundamental rights.
Implementation at Omogen: data governance policy covering data quality controls, monthly bias testing across accent/name/format dimensions, prohibition of special category data with automatic detection and a 48-hour deletion protocol, and documented data lineage for training datasets.
Legal basis: AI Act, Article 10.
2.2.3 Technical documentation
Requirement: draw up technical documentation before the system is placed on the market and upon significant internal/system changes, demonstrating compliance and providing authorities with the information needed to assess compliance.
Implementation at Omogen: technical documentation file maintained in accordance with Annex IV, covering system description, development process, risk management outcomes, performance metrics, and human oversight design.
Legal basis: AI Act, Article 11 and Annex IV.
2.2.4 Documentation retention
Requirement: keep the technical documentation referred to in Article 11, the quality management system documentation referred to in Article 17, and any decisions taken by notified bodies (where applicable), available to competent national authorities for a period of 10 years after the system is placed on the market or put into service.
Implementation at Omogen: technical documentation, QMS records, and conformity assessment documents retained for 10 years from placing on the market, in a controlled, version-tracked repository, accessible on written request from a competent authority.
Legal basis: AI Act, Article 18.
2.2.5 Automatically generated logging
Requirement: design the system to enable the automatic recording of events ("logs") throughout its lifecycle, appropriate to its intended purpose (art. 12). Providers must further retain logs automatically generated by their own high-risk AI system, insofar as such logs are under their control, for a period appropriate to the intended purpose, of at least 6 months, unless otherwise provided by applicable Union or national law, in particular Union data protection law (art. 19).
Implementation at Omogen: system logs retained for a minimum of 6 months (technical/operational logs) and up to 10 years (bias testing and compliance records). Human override records are retained for 3 years by the Customer (see Part 1.2.5).
Legal basis: AI Act, Articles 12 and 19.
2.2.6 Transparency and provision of information to deployers
Requirement: design the system to ensure sufficiently transparent operation, and accompany it with instructions for use containing concise, complete, correct, and clear information.
Implementation at Omogen: Instructions for Use (IFU) / "Playbook" provided to users, covering identification, intended purpose, technical specifications, deployment, operating conditions, human oversight requirements, known limitations, reasonably foreseeable misuse, and incident reporting.
Legal basis: AI Act, Article 13.
2.2.7 Human oversight by design
Requirement: design the system, including through appropriate human-machine interface tools, so that it can be effectively overseen by natural persons during the period it is in use, with a view to preventing or minimizing risks.
Implementation at Omogen: workflow blocking that prevents rejection notification until human review is recorded; override mechanism with mandatory reason entry; "Reviewed by [Name]" audit trail; monitoring of the override rate to detect deployer non-compliance.
Legal basis: AI Act, Article 14.
2.2.8 Accuracy, robustness, and cybersecurity
Requirement: achieve an appropriate level of accuracy, robustness, and cybersecurity, and perform consistently in these respects throughout the lifecycle.
Implementation at Omogen: documented performance benchmarks, regular penetration testing; AES-256 encryption at rest, TLS 1.3 in transit; multi-provider LLM failover for resilience.
Legal basis: AI Act, Article 15.
2.2.9 Quality management system
Requirement: implement a quality management system proportionate to the size of the organization, ensuring compliance, covering strategy, design control, examination and testing procedures, and post-market monitoring.
Implementation at Omogen: QMS documenting organizational structure, document control, change management, internal audit procedures, management review, and continuous improvement.
Legal basis: AI Act, Article 17.
2.2.10 Conformity assessment, CE marking, EU database registration
Requirement: carry out the applicable conformity assessment procedure (internal control, in accordance with Annex VI, for this category), affix the CE marking, and register the system in the EU database before placing it on the market.
Legal basis: AI Act, Article 16(e)–(h), Article 43(1)(a)/Annex VI, Articles 48 and 49.
2.2.11 Post-market monitoring and serious incident reporting
Requirement: implement a post-market monitoring system proportionate to the AI system, and report serious incidents to the market surveillance authority — generally within 15 days, or 2 days in the case of a widespread infringement or a serious incident as defined in Article 3(49)(b).
Implementation at Omogen: monthly bias testing, quarterly accuracy validation, continuous availability/error monitoring, and a documented incident classification and notification procedure with defined timelines.
Legal basis: AI Act, Articles 72 and 73.
2.2.12 Corrective action and duty to inform
Requirement: where Omogen has reason to consider that the system is no longer compliant, it must immediately take corrective action to bring it into compliance, withdraw it, or recall it as appropriate, and inform Customers and competent national authorities.
Legal basis: AI Act, Article 20.
2.2.13 Cooperation with competent authorities
Requirement: on the reasoned request of a competent authority, provide all information and documentation necessary to demonstrate compliance, in an easily understandable language, and, on request, give access to automatically generated logs, insofar as they are under Omogen's control.
Implementation at Omogen: single point of contact (DPO/Compliance — gillian@omogen.ai) designated for regulator requests; documented internal procedure to gather and provide requested documents within the requested timeframe.
Legal basis: AI Act, Article 21.
2.3 Related GDPR obligations of Omogen as Processor
| Obligation | Requirement | GDPR Article |
|---|---|---|
| Processing only on instructions | Process candidates' personal data only on the Customer's documented instructions, including regarding transfers of data outside the EEA | Art. 28(3)(a) |
| Confidentiality | Ensure that all Omogen personnel authorized to access or process candidate data are bound by strict contractual or statutory confidentiality obligations | Art. 28(3)(b) |
| Security measures | Implement robust technical and organizational measures to protect candidate data, including AES-256 encryption at rest, TLS 1.3 in transit, and strict role-based access control | Art. 32 |
| Sub-processing | Obtain the Customer's prior written authorization (general or specific) before engaging sub-processors, and contractually flow down equivalent data protection obligations | Art. 28(2) and (4) |
| Assistance with data subject rights | Provide the technical and operational anchor points necessary to help the Customer respond to candidates' access, erasure, rectification, and explanation requests | Art. 28(3)(e) |
| Breach notification | Notify the Customer without undue delay (contractual target: within 24 hours) after becoming aware of any personal data breach concerning candidates | Art. 33(2) |
| DPIA and consultation assistance | Provide the system architecture, data-flow information, and security documentation necessary for the Customer to carry out its mandatory GDPR DPIA | Art. 28(3)(f) |
| International transfers | Ensure appropriate transfer mechanisms (such as standard contractual clauses) and carry out transfer impact assessments (TIA) for any sub-processor outside the EEA | Art. 44–49 |
| Fate of data at contract end | At the Customer's choice, return or securely delete all candidates' personal data at the end of the service, certifying deletion in accordance with NIST SP 800-88 | Art. 28(3)(g) |
| Facilitating AI transparency | Provide user-interface elements (e.g., built-in notifications or warnings) ensuring candidates are clearly informed they are interacting with an AI system, satisfying joint compliance needs | GDPR art. 13 & AI Act art. 50(1) |
2.4 The review-rate monitoring mechanism
INFO
This is a control specific to Omogen's compliance model, going beyond the literal text of the AI Act, designed to give Omogen visibility into whether Customers are actually exercising the human oversight required by Article 26(2).
Since Article 26 places the obligation to exercise human oversight on the Deployer, Omogen — as Provider — has no direct control over whether a Customer's reviewers actually engage with the review workflow, or simply click "accept" on every AI recommendation ("rubber-stamping"). To manage this residual risk, Omogen monitors, per Customer, the percentage of interview reports reviewed by a human reviewer and the AI recommendations that are overturned (the "override rate").
| Override rate | Interpretation | Omogen's action |
|---|---|---|
| 5%–30% | Healthy range — indicates real, substantial human review | Routine monitoring |
| Below 5%, sustained over 2 months | Possible risk of rubber-stamping / automated decision-making | Automated alert to the Customer; documented follow-up |
| Above 30%, sustained over 2 months | Possible system miscalibration for this Customer's use case | Automated alert; root-cause investigation with the Customer |
| No improvement after alert + remediation period | Ongoing risk of non-compliance with art. 26(2) for both parties | Exercise of suspension rights under DPA art. 4.6 (14-day remediation period) |
Part 3 — In practice: product features & best practices
This part translates the legal obligations set out in Parts 1 and 2 into concrete features built into Mio and CV Screener, as well as into daily practices expected of recruiters using the platform. It is written to be directly usable by recruiters, while giving compliance officers a way to verify that the product's behavior matches the legal obligations.
3.1 Obligation → feature mapping
The table below shows, for each major legal obligation, the specific product feature that implements it. This is the primary reference for compliance officers auditing the platform against Parts 1 and 2.
| Legal obligation | Source | Product feature |
|---|---|---|
| Prohibited practice: no emotion/behavior inference | AI Act, art. 5(1)(f) — a prohibited practice, not just high-risk | Mio only assesses the factual content of answers; no analysis of tone, emotion, micro-expressions, or behavioral signals. Disclosed on the report: "No emotion recognition" |
| Human oversight (100% review of rejections) | AI Act, art. 14, 26(2) | Workflow blocking: "Not recommended" results are locked until reviewed; cannot be sent to the candidate without review. The interview report is flagged "to review" in Omogen and there is no automatic move in the ATS to a rejection stage |
| Human oversight (sampling of accepted results) | Internal best practice / art. 26(2) | Random 10% sampling queue automatically generated every month |
| Audit trail of human decisions | AI Act, art. 12, 26(6) | "Reviewed by [Name]" indicator + timestamped decision log (compliance tab: reviewer, date/time of review), retained for 3 years |
| Override rate monitoring | Art. 26(2) (Omogen control — see §2.4) | Override rate dashboard; automated alerts at <5% / >30% |
| Consent to voice recording | Criminal Code, art. 226-1, GDPR art. 7 | Mandatory voice consent script at the start of every Mio call; retained for 10 years; status shown in the compliance tab ("Consent obtained") |
| Transparency to candidates (AI use disclosed) | AI Act, art. 26(7), GDPR art. 13 | In-call disclosure + email/portal notice before the interview; the report banner confirms no automated decision was made |
| No hidden or undisclosed evaluation criteria | AI Act, art. 26(4), art. 13 | The compliance tab discloses the exact number of criteria and confirms all were configured and validated by the recruiter ("No hidden or implicit criteria") |
| Protection of special category data | GDPR art. 9 | Automatic NLP detection → DPO alert (24h) → deletion (48h) → audit log |
| Data minimization and pseudonymization | GDPR art. 5(1)(c), art. 32 | Candidate identifiers are replaced with pseudonyms before any LLM API call |
| Storage limitation | GDPR art. 5(1)(e) | Automated deletion: 30 days (voice), 6 months (transcripts/data), 3 years (review logs); retention basis shown in the compliance tab |
| Candidate's right to human-only review | GDPR art. 22 | Voice opt-out flagging system available to candidates during the interview, automatically triggering an email to the recruiter requesting human review |
| Candidate's right to an explanation | GDPR art. 22, AI Act art. 86 | Per-criterion "Scores & Verbatims" explainability: exact transcript excerpt justifying each score, with "Listen in transcript" playback; explanation-request workflow generating a human-readable summary within 10 days |
| Flagging low transcription confidence | AI Act, art. 14 (effective oversight) | Reports below 80% STT confidence are automatically flagged for priority human review |
| Technical performance monitoring (accuracy and robustness) | AI Act, art. 15 | Per-call technical sheet (audio quality — agent/candidate, average latency) feeding the confidence signal and monthly system-level accuracy validation |
| Transparency on sub-processors | GDPR art. 28(2) | Live list of sub-processors on the Trust Center; 30-day change notification |
3.2 Best practices for recruiters
Recruiter tip
This section is written for you as a recruiter. It explains, in simple terms, what you're required to do when using Mio and CV Screener, and why it matters both for candidates and for protecting Omogen and your organization legally.
3.2.1 Before launching a campaign
- Define job criteria clearly and specifically. Vague criteria ("good communicator") produce vague, less reliable AI assessments. Specific criteria ("minimum 3 years of B2B sales experience") produce better results and are easier to justify if challenged.
- Never define a criterion that could function as an indirect proxy for a protected characteristic — for example, strict geographic restrictions (particularly under French recruitment law, subject to legal exceptions), graduation-year thresholds used as an age proxy, or name-based filtering.
- Make sure candidates are informed, before the Mio call or CV submission, that AI will be used as part of the process.
- Review the AI-generated interview script and refine it if needed. Never launch a campaign on real candidates before testing a call yourself.
3.2.2 Reviewing "Not recommended" results — mandatory, every time
Mandatory step
You must review 100% of candidates flagged "Not recommended" before any rejection communication. This is not optional and is enforced by the platform — the rejection action is blocked until your review is recorded.
- Open the candidate's full report: read the entire transcript, not just the summary score.
- Check the low-confidence signal. If transcription confidence was below 80%, treat the AI's recommendation with increased caution; poor audio quality or the candidate's accent may have caused transcription errors, not a genuine mismatch with the role.
- Ask yourself: does this candidate genuinely fail to meet the criteria, based on what they said, rather than how they said it?
- Make your decision: accept the AI's recommendation, or override it. If overriding, select a reason and add a brief note.
3.2.3 Monthly sampling of "Recommended" results
What to do: each month, review the random 10% sample of "Recommended" candidates shown in your queue.
Why it matters: this catches the reverse error (candidates overrated by the AI) and demonstrates to regulators and to Omogen that oversight is real, not limited to rejections.
3.2.4 Handling candidate requests
| The candidate requests… | What to do | Timeline |
|---|---|---|
| A human-only interview instead of Mio | Honor the request without penalizing the application | Immediate |
| An explanation of the non-recommendation based on the AI's evaluation | Forward to Omogen support; Omogen will help generate a compliant explanation | 10 business days |
| Access to their data | Forward to the data subject rights process via Omogen | 30 days |
| Deletion of their data | Forward the request; do not attempt to handle the deletion manually outside the process | 30 days |
3.2.5 What to do if something seems off
When in doubt, report it
If you notice a concerning pattern, or unexpected system behavior — report it immediately and suspend use of the affected feature. Do not try to work around the issue or informally adjust criteria to compensate.
| Situation | Contact | Response time |
|---|---|---|
| Technical error or bug | support@omogen.ai | < 24 hours |
| Suspected bias or discrimination pattern | gillian@omogen.ai (DPO) | < 48h acknowledgment, investigation < 10 days |
| Suspected data breach / security incident | gillian@omogen.ai | < 24 hours |
| Any candidate complaint | support@omogen.ai | < 5 business days acknowledgment |
3.2.6 Training and certification
Requirement: no user may access Mio or CV Screener candidate results before completing Omogen's Customer Training Pack / Playbook.
3.3 Checklist for compliance and legal officers
This checklist supports periodic internal audit of the deployment against Parts 1 and 2 of this page.
3.3.1 Before deployment
- DPIA carried out or contributed to for this deployment (GDPR art. 35 — applies to most Customers, see §1.3)
- Confirmation of whether the Article 27 FRIA applies to your organization (public-law body / public service provider only, or a use case falling under Annex III §5(b)/(c) — see §1.2.7); if applicable, carried out and validated
- DPA signed with Omogen, including the Article 4 human oversight obligations
- Candidate privacy notice updated to reference AI use
- All prospective reviewers have completed Customer Training and obtained certification
- Job criteria reviewed for indirect (proxy) discrimination risk
3.3.2 Ongoing (monthly)
- Confirm that 100% of "Not recommended" results were reviewed within the appropriate timeframe
- Confirm that the 10% sampling queue was processed
- Review your own override rate — is it within the healthy 5–30% range? If not, investigate the cause
- Review any escalation or candidate complaint raised during the period
- Confirm no unresolved special-category data flag remains open beyond 48 hours
3.3.3 Ongoing (quarterly / annual)
- Internal audit of a sample of human review records for quality and consistency
- Confirm compliance with retention schedules (spot-check automated deletion logs)
- Review any post-market monitoring or bias testing report shared by Omogen during the period
- Update the DPIA, and the FRIA where applicable, if the deployment's scope, volume, or candidate population has changed significantly
- Confirm the sub-processor list (Trust Center) has not changed without appropriate notification
Last updated: 2026-07-15