Saltar al contenido principal
Back to blog
Human ResourcesAI in Public Administration

AI for managing human resources in local government

September 13, 20264 min readOptimTech
Share:

Why consider AI in HR now (and with caution)

AI can improve human resources processes in town halls and public entities: automate initial applicant screening, prioritize training according to real needs, optimize shift scheduling and spot turnover risk. But potential benefits come with legal obligations (GDPR, EU AI Act), security requirements (ENS Royal Decree 311/2022) and reputational risks. This guide offers a practical, actionable approach to get started with control.

Concrete uses and their operational value

  • Initial applicant screening: structured extraction from CVs and filtering by objective requirements (degree, minimum experience) to reduce administrative time.
  • Complementary assessments: standardized tests and continuous training recommendations based on detected skills gaps.
  • Workforce and shift planning: demand models to allocate resources in essential services (cleaning, emergency services, shifts and on-call duties).
  • Detection of turnover risk or long-term absences: early alerts for retention interventions.
  • Automation of administrative tasks: generation of performance reports and training tracking.

Each use requires an impact assessment and proportionate controls: not every project should begin with candidate screening.

Key regulatory risks (what to assess beforehand)

  • EU AI Act: systems used to select, evaluate or classify people in access to employment are listed as high-risk. That entails requirements for risk management, technical documentation, an operations register and pre-market assessment.
  • GDPR: processing personal data requires lawfulness and transparency, and when there is automated profiling that significantly affects an individual, a Data Protection Impact Assessment (DPIA) is required.
  • ENS (Royal Decree 311/2022): public administration information systems must meet security and continuity requirements. This requires information classification, access controls and cybersecurity measures.
  • Law 9/2017 on Public Sector Contracts: when acquiring AI services or solutions you must ensure public procurement principles and include mandatory technical clauses (including, where applicable, security requirements and data rights).

Essential technical and organizational controls

  • Risk and scope classification: document whether the solution qualifies as “high risk” under the EU AI Act and whether a DPIA is required.
  • DPIA: identify purposes, categories of data, legal bases, third parties involved and measures to mitigate risks (e.g., limiting sensitive attributes).
  • Human-in-the-loop: keep human review for final decisions (selection, disciplinary actions, promotions).
  • Traceability and logs: decision logs for the model, versioning and training data records; these expose decisions for audits.
  • Transparency to individuals: clear notices in job announcements and forms, providing information about AI use and GDPR rights.
  • Bias testing and fairness metrics: evaluate disparate impact by gender, age, disability or other protected attributes; document mitigations.
  • Security and data sovereignty: encryption in transit and at rest, hosting compliant with the ENS or in an authorized cloud, access control, backups and continuity planning.
  • Contractual clauses: require model cards, information on training data, audit rights and obligations not to reuse personal data without authorization in supplier contracts.

Operational integration: processes and governance

  • Local governance committee: include HR, legal, data protection and IT. Define risk thresholds and approval processes.
  • Controlled pilot: test with a reduced volume and non-critical data; for example, use AI to classify CVs only in early stages, with mandatory manual checks.
  • Staff training: train HR technicians to interpret recommendations and spot anomalies.
  • Involve employee representation: consult unions and staff representatives to explain controls and gather feedback.

KPIs to monitor from day one

  • Average time per case (hours/person) before and after.
  • False positive/false negative rates in applicant screening (assessed by human review).
  • Equity indicators (percentage selected by protected groups vs. baseline).
  • Security incidents and GDPR requests related to AI systems.
  • Average response time to audits and information requests.

Recommended step-by-step (initial 3 months)

  1. Map use cases and classify risk (day 1–7).
  2. Conduct a preliminary DPIA and an EU AI Act conformity assessment (weeks 2–4).
  3. Select a provider or solution that meets ENS requirements and includes standard contractual clauses (month 2).
  4. Run a limited pilot with minimized data and mandatory human review (months 2–3).
  5. Validate KPIs, bias tests and technical documentation; decide on scaling or rethinking (end of month 3).

At OptimTech we support municipalities in structuring these stages in compliance with the ENS and GDPR, integrating governance and traceability controls.

Takeaway / Immediate action

Before automating any HR process, perform a risk classification and a DPIA. Start with a limited pilot that always keeps the final decision in human hands and document technical and contractual controls (ENS, EU AI Act, GDPR). A phased approach reduces legal risk and improves internal acceptance.