GDPR and the EU AI Act: using Ductio responsibly
Understanding privacy, AI transparency and human responsibility in executive intelligence.
Last reviewed: 6 October 2026
Ductio brings professional information and AI analysis together to support executive search and leadership decisions. Responsible use means respecting individuals’ privacy, understanding the limits of AI analysis and keeping people accountable for decisions.
What is the difference between GDPR and the EU AI Act?GDPR governs the processing of personal data. The EU AI Act regulates AI systems according to their purpose and risk. Both can apply to the same activity. In the UK, the UK GDPR and Data Protection Act 2018 apply, as amended. EU rules may also apply to relevant cross-border activities.
Does publicly available professional data fall under GDPR?Yes. Information about an identifiable executive can be personal data even when it appears on a company website, professional profile or public register. Public availability does not give unrestricted permission to collect, analyse or share it.
Each use needs an appropriate lawful basis. Where legitimate interests are considered, the organisation must assess the purpose, necessity and balance against the individual’s rights. Consent is not the only possible basis, and legitimate interests are not an automatic permission.
What if information was collected indirectly?When data comes from public or third-party sources, privacy information generally needs to explain the sources, data categories, purposes, lawful basis, retention and individual rights. Under EU GDPR Article 14, it is normally provided within one month, or earlier at first communication or disclosure where applicable.
A public privacy policy alone does not automatically satisfy every notification obligation. Any applicable exception must be assessed and documented.
How does the EU AI Act affect executive search?AI used to evaluate, rank or select recruitment candidates can fall within the Act’s high risk category. Keeping a human involved does not automatically change that classification. The intended purpose and actual function of each feature matter.
The European Commission’s current timetable places Annex III high risk requirements at 2 December 2027. Article 50 transparency requirements began applying on 2 August 2026, subject to relevant transitional provisions. These dates do not suspend existing privacy obligations.
How should customers use AI assessments?Treat assessments as evidence to examine, rather than instructions to follow. Review the underlying information, check important claims and consider missing context. A person reviewing a recommendation must have the authority and ability to challenge it.
Do not use scores as automatic rejection thresholds or use information to discriminate unlawfully. Significant solely automated decisions require a separate legal assessment and applicable safeguards.
Who is responsible for personal data?Responsibilities depend on the activity. An organisation deciding why and how personal data is used acts as a controller. An organisation processing it on that controller’s instructions acts as a processor. Ductio and its customers may have different roles across different workflows; the relevant privacy information and contractual arrangements should explain them.
Where can I get help?Consult Ductio’s Privacy Policy and relevant contractual terms for details of the service and privacy contact route. Use that route to raise an accuracy concern, ask about processing or exercise applicable data protection rights. Rights depend on the circumstances and may include access, correction, objection, restriction and erasure.
For questions about responsible platform use, contact Ductio Customer Support.