Data Privacy in AI-Driven HR

Meaning & Definition

Data Privacy in AI-Driven HR

Data privacy in AI-driven HR is the set of controls that ensure employee and candidate data used by AI systems is collected with a lawful basis, limited to what the use case needs, protected from unauthorized access, and retained no longer than necessary. It covers data entered or stored in the system of record, the content retrieved to ground answers, prompts and responses, and the outputs the system produces.

Strong practice includes anonymizing or pseudonymizing data before input, tenant-level isolation of retrieval sources, real-time masking of personal information in prompts, explicit consent for any use beyond fulfilling the request, and user-visible history that employees can delete. Data ownership should sit with the customer contractually. Darwinbox enforces these controls through its LLM Gateway, does not store prompts for non-conversational features by default, doesn't use any data for training, scopes retrieval per customer, and defines customer ownership of inputs and outputs.