Personality data is among the more personal things a company will hold about someone who does not work there yet, and most buyers have never asked where it goes.
Candidate data protection in a hiring assessment is the set of decisions about what data is collected, where it is processed, who can read it, how it is shared, and what happens when the hire is made or rejected. Personality data needs special attention because it describes behaviour, not just work history.
A CV is already written for an employer. It is selective. It is edited. It usually says where someone worked, what they did, and which tools they know.
A personality assessment is different. It asks about patterns in behaviour, attention, sociability, emotion, persistence and preference. It may be useful for a manager preparing an interview or planning onboarding. It is also among the more personal information a company may hold about someone who does not yet work there.
That does not mean a company should never use it. It means the questions should be asked before the assessment is sent, not after a candidate complains. Where does the data go. Who sees it. Is the raw answer set stored. Can the candidate withdraw access. What happens after rejection.
This guide is not legal advice. It does not summarise the GDPR, the PDPA, the CPRA, the UK GDPR or any other regime. Take the questions in it to a qualified adviser for the jurisdictions and candidates involved.
Most hiring tools talk about the assessment as if it is one object. It is not. There are several kinds of data, with different risks and different useful lives.
| Kind of data | What it is | Who can see it | How long it plausibly persists |
|---|---|---|---|
| Identity and contact details | Name, email, phone number, application role, CV file or parsed CV fields. | The candidate, the hiring organisation, and the vendor systems used to run the process. In some products this also includes recruiters, interviewers and administrators. | Depends on the vendor and the hiring organisation. It often persists in applicant tracking systems, inboxes, spreadsheets, exports and backups unless there is a deletion process. |
| Item-level answers | The raw answers to each assessment question, such as agreement or disagreement with a statement. | Depends on the vendor. In many assessment products the vendor receives and stores the answers. In HyperPersonal’s Big Five Test, item-level answers are never uploaded; the assessment runs on the candidate’s own phone. | Depends on the architecture. If uploaded, it depends on the vendor. In HyperPersonal, raw item answers are private by architecture because they are not sent to the organisation or uploaded as a record. |
| Calculated profile | The scored result, such as continuous dimensions across the Big Five domains and facets. | Depends on consent and access controls. In HyperPersonal, an organisation sees a profile only because the individual scanned a code and authorised a grant. What is shared is the calculated profile, not the raw responses. | Depends on the vendor, the organisation’s settings, and any withdrawal or deletion process. In HyperPersonal, a grant can be withdrawn. |
| Role comparison and report | How the profile is read against a role the organisation has defined, including interview prompts and management notes. | Hiring managers and other named people with access to the role or candidate record. In HyperPersonal, every person who can read a record appears in a list with the reason they are on it. | Depends on the vendor and the organisation. It may persist with the hiring record unless removed or access is withdrawn where the product allows it. |
| Notes written by colleagues | Comments added by interviewers, recruiters or managers during the process. | Usually the hiring team and administrators. This is controlled by the organisation and the vendor’s permissions model. | Depends on the hiring organisation. Notes often outlive the assessment because people copy them into emails, meeting documents or applicant tracking systems. Ask where copies can be made. |
Most uncomfortable answers in this category are not hidden in the scoring model. They are in ordinary product plumbing. Forms. Logs. Admin accounts. Exports. Backups. Shared links. Default permissions.
HyperPersonal has three parts. CV Cat structures every candidate’s CV into the same columns. Our own assessment runs in a free iPhone app, where a candidate answers the IPIP-300 over days rather than in one sitting. The portal reads a completed profile against a role the company has defined.
The architecture matters. The Big Five assessment runs on the candidate’s own phone. Item-level answers are never uploaded. What can be shared is the calculated profile, not the raw response set.
The profile is based on the public-domain IPIP-300 item pool. It measures 5 domains and 30 facets. Scores are continuous dimensions, never types or categories. A score is a location on a dimension rather than a bracket the person has been sorted into.
An organisation holds a profile because the individual scanned a code and authorised it. That grant is explicit and revocable. Every person who can read a record appears in a list, with the reason they are on it.
This is not a slogan that the data is completely private. Some things are private by architecture — the raw answers. Other things are governed by access controls a human configures — the shared profile, role comparison and colleague access.
Good practice is to tell candidates enough to make a real choice. Not a wall of policy text. Not a vague sentence saying results may be used for recruitment purposes. Plain words, before the assessment starts.
The point is not to turn a hiring manager into a lawyer. The point is to avoid surprising a candidate after they have answered personal questions. Surprise is usually the sign that the explanation was too late or too thin.
This is the question almost nobody asks. The company hires one person and rejects twenty. The selected person becomes an employee and enters normal company systems. The rejected candidates are different. They may have shared identity data, a CV, assessment results, interview notes and manager comments, then never hear from the company again.
There is no useful general answer across vendors. Some products leave the record in the same candidate list. Some archive it. Some allow deletion. Some keep exports outside the product. Some have backups that behave differently from live records. Some organisations copy the report into an applicant tracking system or a hiring spreadsheet.
Ask the vendor and ask your own team. A clean vendor deletion process does not remove a screenshot in a Slack channel or a PDF saved in a manager’s downloads folder. Access control inside the tool matters. So does the discipline around what people copy out of it.
For HyperPersonal, the organisation’s access to a profile comes from the candidate’s grant. That grant can be withdrawn. The organisation should still decide what it does with its own notes, exports and hiring records. That is an operational decision, and it should be made before the first assessment is sent.
Do not rely on this page to decide legal duties. Take the workflow, the candidate locations, the company location, the vendor location and the data map to a qualified adviser. Ask them which regimes apply and what your obligations are.
For HyperPersonal’s own product privacy information, read the privacy page. Read HyperPersonal privacy information
For a separate guide on the legal questions around pre-employment personality testing, use this page as the next step. Read the guide to pre-employment personality test legality
In a ten-, thirty- or hundred-person company, candidate data often moves through a founder’s inbox, a hiring manager’s notes, a shared drive and a vendor portal. That is the real system. A written policy helps only if the Tuesday behaviour matches it.
Use fewer tools. Name the people who can see the record. Write down why they can see it. Do not export assessments unless there is a reason. Tell candidates what is being shared. Decide what happens after rejection. Keep the assessment as decision support, never an automated decision.
It depends on the product, but you should ask directly. Raw answers are more sensitive than a calculated profile because they show the person’s response to each statement. In HyperPersonal’s Big Five Test, item-level answers are never uploaded; the assessment runs on the candidate’s phone.
In HyperPersonal, yes. A candidate shares a profile with an organisation through an explicit grant, and that grant can be withdrawn. Other vendors may handle this differently, so ask what withdrawal changes in the live record, exports and backups.
Only people with a clear role in the hiring process should read it. For a small company, that may be the founder, hiring manager and one interviewer. HyperPersonal shows every person who can read a record, with the reason they are on it.
HyperPersonal is decision support, not an automated decision-maker. A human makes the decision. The output should help a manager ask better questions and plan onboarding, not replace judgement.
Decide before the role opens. Ask your adviser what applies, ask your vendor what is technically possible, and tell your team where not to copy reports. The rejected candidate’s data is usually where weak processes show first.
If you want to test the workflow on one real role before changing your hiring process, run a small pilot. Run a pilot on a real role
Operated by Alano Tech Pte. Ltd., Singapore.
Terms of Service Privacy Policy
Also from us: Alano.ai Opptymizer Omu Labs