GDPR
Recruitment agencies placing candidates in the EU need their tools to meet GDPR requirements — not as an afterthought, but as a basic condition of doing business. This page covers how IntelligencesTest supports GDPR compliance for agencies and their candidates.
Why this matters specifically for candidate assessment data
Candidate assessment results are personal data under the GDPR, and in many cases the kind of data that requires extra care: it reflects a real person’s abilities and behaviour, and it’s used to make a decision that affects their livelihood. Two GDPR principles apply directly. Purpose limitation means data collected for one recruitment process shouldn’t be quietly reused for an unrelated one. Data minimisation means only the data actually needed for the assessment and the decision it supports should be collected and retained, not gathered simply because it might be useful someday. Both principles shape how an agency should configure and use the assessment process, not just how the underlying platform stores data.
Where responsibility sits between the agency and the platform
GDPR compliance isn’t something a platform can fully deliver on its own — the agency using it makes decisions the GDPR treats as its responsibility, like establishing a legal basis for processing and giving candidates proper notice before an assessment. The platform’s role is to support those decisions with the technical and organisational practices GDPR expects — scoped data visibility, retention tied to purpose, a documented data processing agreement — but an agency still needs its own process for consent and candidate notice, since that’s a decision about the agency’s relationship with the candidate, not something the platform can decide on the agency’s behalf.
GDPR-relevant practices
- Agencies are expected to establish a clear legal basis and give candidates appropriate notice before they complete an assessment
- Candidate right to access, correct, or request deletion of their data
- Data processing agreements available for agencies operating in the EU
See Data Privacy and Security & Data Protection for related detail, or contact us for a data processing agreement.
Frequently asked questions
Who is responsible for candidate consent and notice — the agency or the platform?
The agency — establishing a legal basis and giving candidates appropriate notice is the agency’s responsibility as the party with the direct candidate relationship.
Can a candidate request their data be deleted?
Yes — candidates have the right to access, correct, or request deletion of their data.
Is a data processing agreement available for EU agencies?
Yes — contact us to request one.
Does data minimisation mean less useful assessment results?
No — it means only collecting and retaining what’s actually needed for the assessment and decision it supports, not limiting what’s measured within that scope.
