Skip to main content
Back to blog
gdprai assessmentdata protectionhuman oversightretention

AI Assessment and GDPR: What Actually Matters

Adam Broons14 August 202610 min read

This is a plain-language overview for assessment teams, not legal advice. Nothing here says any product or organisation is compliant - compliance is a property of what you do in your own circumstances, and only your adviser can reach that conclusion. What this piece does is separate the GDPR questions that genuinely bite when AI enters assessment from the ones that get more attention than they deserve.

The difficult questions are lawful basis, retention, respondent rights in practice, and whether a decision is effectively automated. Residency matters but is usually easiest to settle - our earlier piece on data residency and tenant isolation covers that infrastructure side. This one is about the obligations that sit with you.

You are the controller. That is the whole frame.

In almost every assessment setup your organisation is the data controller and the platform is a processor acting on your instructions. The obligations that matter - lawful basis, informing respondents, honouring their rights, deciding retention - are yours. A vendor can make them easier or harder to discharge, but cannot discharge them for you. Which is why "is your tool GDPR compliant" is the wrong opening question. The better one: what does this tool let me do, prevent me from doing, and record, so I can meet obligations that are mine either way.

Lawful basis: the question people skip

You need a lawful basis for processing assessment responses, and consent is usually the wrong one.

Consent has to be freely given. An employee asked to consent to an assessment their manager has set is not in a position to refuse, and nor is a learner whose qualification depends on it. Relying on consent there is fragile, with an awkward consequence: consent can be withdrawn, and you would then have to stop processing work you may be required to retain for audit.

The bases that tend to fit are contract - the assessment is necessary to deliver the training or employment relationship - legal obligation where a regulator requires assessment records, or legitimate interests with a documented balancing assessment. Which applies is worth twenty minutes with an adviser rather than a guess.

Note too that special-category data can appear in responses without you asking for it - a candidate mentioning a health condition in a scenario answer - and that needs a higher bar.

Transparency: tell people AI is involved

Respondents should know, before they submit, that their response will be analysed by an AI system, what it will be used for, who will see it, and how long it will be kept. This is a straightforward disclosure obligation, met with a paragraph in the assessment introduction and in your privacy notice. The reason to do it properly is not only legal: discovering after the fact that an assessment was AI-marked turns a routine result into a complaint.

Automated decision-making: the one that constrains design

GDPR gives people the right not to be subject to a decision based solely on automated processing where it produces legal effects or similarly significant effects on them. An assessment that determines whether someone passes a qualification, keeps a job, or gains a certification is comfortably in that territory.

The word doing the work is "solely". A human in the loop takes you out of the restriction, but only a real one - a reviewer approving in bulk without opening results is not meaningful oversight, and a person clicking a button does not make the decision non-automated in substance.

What meaningful oversight looks like in practice:

  • The reviewer can see what the AI proposed and the evidence behind it, so review is possible rather than nominal.
  • The reviewer has actual authority and competence to change the outcome.
  • Overrides happen and are recorded. A zero override rate across a large cohort is evidence nobody is really looking.
  • The respondent has a route to contest the result and get a human re-examination.

Design for this rather than documenting around it - the oversight has to be genuine to be worth anything, and the override record is how you show it was.

Retention: two obligations pulling against each other

Data minimisation says keep personal data no longer than necessary. Your regulator, appeals policy, and audit obligations may say keep assessment records for years. Both are real and pull in opposite directions.

The resolution is a documented retention period per data type, with a reason. Assessment decisions and criteria may need keeping for the full regulatory period. Raw media - the recorded video answer, the uploaded file - often does not, and is the highest-risk thing to keep by default; many organisations reasonably keep the transcript and the assessed record while deleting the recording once the appeals window closes.

The failure mode is retention by inertia: nothing is deleted because nobody decided what should be. That is a breach of the principle even when it feels like caution, and it enlarges the harm of any future incident. Whatever period you set, the platform has to enforce it rather than leaving it as a policy nobody executes.

Respondent rights, tested against reality

Rights on paper are easy. The question is whether you could actually honour them next Tuesday.

  • Access. Could you produce everything you hold about one respondent - submissions, scores, evidence, reviewer comments - within the statutory window? Note that a request may reach comments the assessor assumed were internal, which is worth telling assessors.
  • Rectification. Correcting factual errors in personal data is distinct from disagreeing with a grade. A grade dispute goes through appeals, not a rectification request, and being clear about that boundary prevents a lot of confusion.
  • Erasure. Not absolute. Where you have a legal obligation or a legitimate overriding need to retain assessment records, erasure can be refused - but you have to be able to state which and why, and you should decide the position before the first request arrives.
  • Objection and human review. Where a decision was AI-assisted, the respondent should have a clear route to ask for human re-examination and to contest the outcome.

Test these: pick one respondent and try to fulfil an access request end to end.

Residency, processors and transfers

GDPR does not prohibit personal data leaving the EU - it requires that transfers be accounted for with an appropriate mechanism, so the simplest defensible position is knowing where the data sits and having chosen it. Ask a vendor: which region does the data rest in, what sub-processors are involved including the model provider, is there a data processing agreement covering them, and is our content used to train models. That last should be a clear no, in the contract rather than only on a webpage.

Build a documented controls register

The artefact that pulls this together is a short register - one page is often enough - stating for your assessment processing: the lawful basis and why, what personal data is processed, which processors and sub-processors are involved and where, the retention period per data type with its justification, how respondents are informed, how human oversight is implemented, and how rights requests are handled.

It is worth the hour it takes for two reasons. It is the accountability principle in concrete form - you have to be able to demonstrate compliance, not merely achieve it - and it converts vague anxieties into a list of decisions, most of which turn out to be straightforward once written down. Where the register cannot be completed, you have found your actual gap.

What Scorafy provides toward this

Stated as capabilities rather than compliance claims. Data rests in the EU by default, with Australian residency available. Each organisation's data is isolated at the database layer. Retention is configurable, so you set the period your policy requires rather than accepting a default. Results require explicit human release before a respondent sees them, and both the AI-proposed score and any reviewer override are retained with identity and timestamp, so oversight is evidenced rather than asserted. An Audit Pack export produces the complete record for a result. Assessment content is not used to train models.

None of that makes an organisation compliant and we would not claim it does. It is the set of controls that makes your own obligations practical to meet and demonstrable when someone asks. The security overview has the technical detail; the audit-trail side is in the buyer checklist for AI assessment audit trails.

See it live

See AI-powered assessments in action.

Try the interactive demo - no sign-up required.