Module 4: AI Ethics and GDPR

Audio navigation

Use the controls or a voice command to understand and navigate the page structure.

Ready.

3. Everyday “AI Ethics” and GDPR Presented in Layman’s Terms

The impact of Ethical AI use and effective Data Management is most visible not in legislation, but in the daily experiences of workers, employers, and job seekers. As far as everyday people are concerned, the widespread integration of AI technology in all aspects of everyday life is not only affecting and transforming industries, but it is also redefining the nature of work and access to employment.

Admittedly, the modern job market is becoming increasingly dependent on digital platforms and automated candidate processing systems. Employers are now using AI to streamline the recruitment process in terms of filtering and evaluating candidates, and managing staff performance throughout the entire employment cycle. In addition to benefits such as increased efficiency and productivity, this shift has created complex, multilayered challenges related to AI system fairness, data processing transparency, data management and equal access to employment.

Furthermore, the integration of AI into modern work environments has become a “must” if one is to be able to keep up with rapid work pacing and client demands. Even the freely available AI tools offer significant benefits in the workplace; they can help automate repetitive tasks, reduce human error, generate visual content (graphics, logos, videos etc,) and provide data-driven insights that support better strategic decisions.

3. a. Use of AI in the Job Market: An Ethical Challenge

AI Technology helps recruiters scan and filter hundreds of applications in just a few seconds and can also help optimise job descriptions and rank candidates based on predefined “success” criteria. Additionally, video interview platforms use AI to analyse the emotional, intellectual and bodily responses and reaction of candidates to targetted questions, while also analysing the tone of voice, word choice, and microexpressions. In other words, hiring decisions and interactions that were once made/facilitated solely by humans are now often influenced (or even entirely determined) by artificially intelligent automated systems.

It is important to remember that even though AI can help enhance candidate matching and reduce time-to-hire, some of the time saved by AI must be spent on overseeing its use in the recruiting process in order to mitigate associated risks such as “algorithmic bias”.

Case Study Vignette on Algorithmic Bias from an Inclusive Employment Perspective

AI learns from humans, so it tends to be as biased as the data it is learning from (JOBSHARK 2025). Especially in the case of inclusive employment and hiring processes which concern job-seekers with disabilities, the “bias” problem becomes even more prominent.

Algorithmic Bias refers to what happens when AI models reinforce biases present in the data they were trained on. To understand the problem of Algorithmic Bias, picture this:

A job applicant with stuttering sits at a desk facing a laptop and video camera during a recorded online interview, illustrating an AI-based hiring process in which speech patterns, facial expressions, and response timing may be automatically assessed.- George, a job seeker with a stutter, applied for a graphic designer role. George has a Bachelor Degree in Graphic Design and a Master Degree in Digital Marketing.

- As part of their digital recruitment strategy, the employer introduced HIREVIEW, an AI-based asynchronous video interview tool to screen candidates after CV submission. Applicants were asked to record short video responses to predefined questions. The AI system analysed verbal fluency, response timing, facial expressions, and speech patterns to generate a candidate suitability score.

Image created with BING AI Image Generator

- George, who met all technical and experiential requirements for the role, disclosed a speech impairment only after receiving an automated, generic rejection email. The rejection occurred before any human interaction, based solely on the AI-generated evaluation. George’s explanation and Screenshot of a generic rejection email addressed to George, informing him that the company will not proceed with his application for the Graphic Designer position and providing no reason for the decision. disclosure was never followed-up by the employer.

Real example of an automated job application rejection email

In this case, “Algorithmic Bias” refers to non-inclusive hiring preferences used to train the AI interview system, which do not consider individual characteristics of candidates. This vignette shows that despite seeking candidates for a technical role such as graphic design, an AI interview system may overvalue fluent speech and fast responses. Regardless of market sector, such biases position candidates with speech impairments at a severe disadvantage, despite having all the necessary technical skills to excel.

Algorithmic Bias is considered an inherent technical flaw of AI tools, however companies and individuals who deploy such tools in recruitment have the responsibility to ensure that they are tested, monitored, and adjusted to prevent discriminatory outcomes. Additionally, it is essential to maintain human oversight and transparency; this means that recruiters and employers should inform candidates about when AI is being used, what factors are being assessed, and how those assessments may influence hiring decisions. If applicants can understand the recruitment process, they can prepare themselves better and communicate directly with employers in order to disclose disabilities that may not be considered otherwise.

3. c. AI Use in Day-to-Day Work: A Gift to the People, But with a Caveat

AI can be used by anyone, anywhere, anytime; with just a few prompts, we now have a “personal assistant” that can help us retrieve information, make decisions, create content, write content, create images and videos. However, the convenience and accessibility of generative AI tools has encouraged excessive dependence and reliance upon them; the homogenisation of ideas and content have oversaturated the intellectual/creative space, with severe impacts to the creative thinking, idea generation and problem-solving skills of people. When AI is used as a substitute rather than a tool, such skills gradually weaken, leading to reduced independence and decreased satisfaction in the results we deliver.

Case Study Vignette on the Overreliance on AI

- Sophia, an experienced illustrator has been employed at a digital marketing agency for the past 12 years. Since 2022, the agency management have been encouraging employees to use AI tools such as DALL-E and ADOBE Firefly in order to speed up content production.

- At first, Sophia and her colleagues were impressed by the potential of AI, as it greately reduced their workload.

- Over time, she has seen the termination of numerous colleagues, leading to the reduction of her team size from ten people, down to just three. The agency management insist that there is no longer a reason to keep so many illustrators on the payroll. Sophia now worries she might be the next one to go.

- To keep up with the demand of large volumes of illustrations, Sophia is now working for extended working hours, has reduced breaks and has a strong feeling of creative stagnation as most of her illustration work is now handled by automated AI image generators.

llustration of a worried illustrator working at a desk with a laptop and drawing tablet, reflecting the pressure, job insecurity, and creative exhaustion caused by overreliance on AI image-generation tools.This vignette shows how AI can enhance productivity in the creative industry, but without sustainable working patterns it ultimately contributes to staff layoffs and occupational burnout. When organisations prioritise speed, cost-cutting, and output above human creativity and well-being, AI can shift from being a support tool to a source of pressure, insecurity, and creative decline. Ultimately, employers are responsible to introduce AI tools in an ethical and sustainable way, which ensures the protection of workers and that such tools enhance work rather than diminish the people performing it.

Image created with BING AI Image Generator

3. d. Detection and Management of Malicious Content during Day-to-Day Work

“Phishing” attacks against home users and professionals are one of the most frequent causes of data breaches. These attacks use a varied methods to reach victims, such as phone calls (also referred to as “social engineering”) and email, which is the most common one. Such messages appear to come from trusted sources, such as colleagues, banks, couriers, or internal company departments, and attempt to trick recipients into clicking malicious links or downloading infected attachments in order to reveal their login credentials, or give access to their local devices to hackers. If successful, phishing attacks can give cybercriminals access to confidential, financial and personal data, leading to serious violations of GDPR principles. Awareness and early detection of phishing attempts are the best way to prevent unauthorised access and ensure that organisations and people who handle personal data remain compliant with GDPR requirements.

Case Study Vignette on a Failed Phishing Attempt

Screenshot of a suspected phishing email addressed to Pavlos, sent by the suspicious display name ‘861DocITNo-Reply.’ It requests urgent review of a pending payment document and contains an unprofessional message and a deceptive Google redirect link; sensitive details are redacted.- Pavlos, a project manager working in a Vocational Education Institution has received a suspicious email, requesting his attention and to check an invoice for a “pending payment”.

Real example of a Phishing attempt.

Many parts in the link have been hidden, to prevent accidental or intentional redirections to the phishing website.

- Without a second throught, Pavlos immediately flagged the email as “Spam”, and blocked the sender’s email address.

- Pavlos also notified the IT expert in charge of the company email server, and requested to add the fraudulent email address into the mail server “block list” in order to prevent all other staff from receiving similar messages.

What indicators (“red flags”) led Pavlos to these actions?

  1. The sender’s display name and email address looked suspicious; display names such as “861DocITNo-Reply” are highly suspicious. Real display names usually include the actual name and surname of the sender.

  2. The company “LootahGroup” is not a company that the recipient ever did business with, therefore no payments were expected from them.

  3. The formatting of the actual message is not professional and inconsistent

  4. The link leading to the document “review” represents a common example of phishing links sent by attackers. Attackers tend to use Google’s redirect endpoint, in hopes that recipients see “google.com” in the link and therefore, trust that it is legitimate. The actual destination is hidden within the fraudulent link.

  5. The actual email address of the recipient, in this case “pavlos@*********.eu” was included at the end of the fraudulent link. Most likely this means that the link redirected to a prefilled login page with the intention to steal e-banking login credentials, while allowing the attacker to see who clicked on the link itself.

Cyber-attacks such as the one described above constitute one of the most common and effective threats faced by organisations and professionals worldwide, because they rely on human error rather than weaknesses in cyber-security software. More than 70% of succesful cyber-attacks involve employees clicking on suspicious links or interacting with fraudulent messages. When staff awareness is low, even the wealthiest organistions with the best cyber-security software remain vulnerable.

For this reason, employees at all levels should be regarded as the first line of defence against malicious content and cyber-attack attempts. If they are able to recognise warning signs such as unusual sender details, unexpected payment requests, poor formatting, urgent language, and misleading links, unauthorised access can be prevented and therefore, the personal and financial data of people and companies will remain safe.

Download Module

Download Module 4 (DOCX, 0.7 MB)