Form

HR AI Checklist

Jersey Office of the Information Commissioner (JOIC) · Jersey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is a practical self-assessment checklist published by the Jersey Office of the Information Commissioner (JOIC) to help HR professionals and organisations evaluate, document and approve the use of AI systems in recruitment and employee monitoring before deployment. It is a form/tool rather than binding law, but it is built around specific requirements of the Data Protection (Jersey) Law 2018 (DPJL 2018) and flags where sign-off, documentation or DPIA/JOIC consultation is legally required.

  • Use case and necessity: Requires organisations to document the specific problem the AI solves, confirm a non-AI solution is inadequate, and record business owner, DPO, deployment and review dates.
  • Lawful basis and fairness: Requires identification of a Schedule 2 Part 1 condition (and Part 2 condition if special category or inferred special category data is involved), a legitimate interests assessment if relied on, and caution against relying on employee consent.
  • Transparency: Requires updating privacy notices and telling candidates/employees before AI processing or monitoring begins, including plain-language explanation of logic, factors weighed, and any right to object to solely automated decisions.
  • Automated decision-making and human oversight: Requires genuine, documented human review (not a rubber stamp) before decisions with legal or similarly significant effects, and a process for individuals to request human intervention or contest a decision, per Article 38 DPJL 2018.
  • DPIA: Requires a DPIA before deployment where processing is likely high risk (systematic profiling, large-scale special category processing, systematic monitoring), and JOIC consultation if high residual risks cannot be mitigated.
  • Bias, discrimination and testing: Requires bias/proxy-discrimination testing of scoring, ranking and psychometric tools, and cross-checking against equality/discrimination law in addition to data protection bias testing.
  • Monitoring safeguards: Requires distinguishing covert from overt monitoring (with senior sign-off for covert monitoring), identifying monitoring categories, and assessing BYOD/out-of-hours proportionality.
  • Data minimisation and retention: Requires defined, enforced retention periods for AI inputs/outputs/logs, a specific shorter retention period for unsuccessful candidate data, and updated records of processing activities.
  • Vendor and international transfer controls: Requires processor contracts covering deletion, sub-processors and model training use, plus assessment and appropriate safeguards for any international data transfers.
  • Governance: Requires a senior accountable owner, staff training, controls against unapproved (shadow) AI use, and documented approval decisions.

The checklist itself imposes no new legal rules beyond DPJL 2018 but operationalises existing obligations for HR use of AI; organisations should treat unchecked items as unresolved compliance gaps before go-live.

Key obligations

  • Complete a Data Protection Impact Assessment before procurement, configuration or deployment where AI processing is likely to result in high risk (e.g. systematic profiling, large-scale special category processing, systematic monitoring).
  • Consult the JOIC before processing starts if the DPIA identifies high risks that cannot be adequately mitigated.
  • Identify and document a lawful basis (Schedule 2 Part 1 DPJL 2018) before processing begins, and a Schedule 2 Part 2 condition where special category data is processed or inferred.
  • Tell candidates or employees before AI processing or monitoring begins, and provide meaningful information about the logic and likely consequences of any automated decision-making.
  • Ensure genuine, documented human review of AI outputs before any decision with legal or similarly significant effects, and provide a process for individuals to request human intervention or contest a decision (Article 38 DPJL 2018).
  • Require senior, documented sign-off before any covert employee monitoring.
  • Conduct bias testing (including proxy/indirect discrimination testing) on AI scoring, ranking or screening tools and cross-check against equality/discrimination law, not only data protection bias testing.
  • Define and enforce retention periods for AI inputs, outputs, logs and profiles, including a specific shorter retention period for unsuccessful candidate data, and ensure vendor contracts enforce the same and require deletion or return of data.
  • Update privacy notices and internal AI/data protection policies before deployment, and update the record of processing activities to reflect AI-driven processing.
  • Assess and, where required, implement an appropriate transfer mechanism before any personal data is transferred outside Jersey.

Applies to

employers, data controllers, HR departments/professionals, organisations using AI for recruitment or employee monitoring

Topics

Version history

2026-07-30

source file (current)