Psychometric testing has become a fixture in modern recruitment. Cognitive ability tests, personality questionnaires, situational judgment tools, and behavioral style inventories are now standard components of candidate selection pipelines across industries. With that widespread adoption comes a question that many CHROs and HR leaders have not fully resolved: does psychometric data qualify as special category personal data under GDPR Article 9, and what compliance obligations follow from that classification?
The answer is not a simple yes or no. It depends on what the assessment measures, how the results are interpreted, and how they are used in decision-making. Getting this classification wrong carries real regulatory risk, particularly given the ICO's active interest in employment data practices and the European Data Protection Board's (EDPB) emphasis on heightened obligations wherever special category processing is involved.
Under GDPR Article 9(1), processing special categories of personal data is prohibited by default. The prohibition is not merely a higher standard of care; it is an outright ban unless the controller can satisfy one of the specific conditions listed in Article 9(2). The categories covered include:
For recruitment purposes, the category that most frequently becomes relevant is data concerning health, which the ICO explicitly identifies as special category data requiring additional protections and conditions under UK GDPR (a framework that mirrors EU GDPR Article 9 in this respect).
In practice, organizations processing special category data face what practitioners often call the "dual lock." They must identify:
Both locks must be satisfied simultaneously. Neither alone is sufficient. The ICO's guidance on special category data rules confirms this two-layer structure clearly: even where an Article 6 basis exists, organizations still need to meet one of the Article 9(2) conditions before they can lawfully process special category data.
One common misconception among HR teams is that obtaining candidate consent resolves both requirements at once. It does not. Consent under Article 9(2)(a) requires explicit consent, which is a higher standard than ordinary consent. More practically, the ICO's guidance notes that consent is not always appropriate in employment or recruitment contexts precisely because of the power imbalance between employer and candidate. A candidate who believes their job prospects depend on agreeing to additional data processing cannot realistically give free, uncoerced consent. This is a significant constraint that many recruitment functions have not fully internalized.
A point that tends to be overlooked: special category classification is not determined by the label on the assessment tool. It is determined by what the data reveals or allows to be inferred. A questionnaire branded as a "personality inventory" can still capture or produce health-relevant inferences if its scoring methodology surfaces information about psychological disorders, mental health conditions, or clinically meaningful emotional states. The name on the test does not change the legal character of the data it generates.
Psychometric results are not automatically classified as GDPR special category personal data in recruitment. The classification depends on the nature of what is being measured and how results are used downstream.
The clearest framing is this: psychometric data becomes Article 9 data when it constitutes, or allows a reasonable inference about, one of the Article 9 categories. In recruitment, the most common trigger is "data concerning health," particularly mental health, psychological disorders, or clinically framed emotional functioning.
Most recruitment-grade psychometric assessments are designed to measure job-relevant traits: reasoning ability, communication style preferences, approach to teamwork, problem-solving tendencies, or cultural alignment. When the results are used exclusively for those purposes and do not produce clinically meaningful conclusions about a candidate's mental or physical health, they are typically not Article 9 special category data.
The risk emerges when assessments cross from measuring job-relevant behaviors into indicating health conditions. This can happen in two ways. First, the test itself may be designed to surface information about psychological wellbeing, stress tolerance at a clinical level, or emotional disorders. Second, even a test designed for job selection can become health data if the organization interprets and acts on the results as if they indicate health-related characteristics.
Edgecumbe Consulting, writing in a May 2023 analysis of GDPR and psychometric data handling, takes the position that psychometric data should be regarded as health data and therefore treated as subject to Article 9 special category safeguards in employment and recruitment contexts. That is a cautious interpretation, and while it is not the only credible view, it highlights the ambiguity that makes this area genuinely complex.
The EDPB's Guidelines 3/2025 on the interplay between the DSA and GDPR (v1.1, September 2025), though directed at digital services rather than recruitment specifically, reinforce a general principle relevant here: profiling and automated processing that generates inferences touching on special categories triggers heightened obligations, regardless of whether the underlying raw data was itself special category. Applied to psychometric assessment, this means organizations cannot assume they are outside Article 9 simply because they collected only job-competency scores if the processing pipeline converts those scores into health-relevant inferences.
Where a candidate is treated differently in the selection process based on results that a reasonable observer would read as health-related (e.g., being screened out because their "resilience score" implies vulnerability to mental health difficulties), the classification question becomes sharper. Using results as a proxy for health status is a path toward Article 9 classification even if that was not the original intent.
In all of these cases, the results address job performance-relevant dimensions and do not produce clinically meaningful health conclusions. Provided the organization processes results only for their stated selection purpose and does not repurpose them to draw health-related inferences, Article 9 obligations are unlikely to apply.
When results are stored, shared, or acted upon in ways that treat them as health data, the classification follows the practice, not the label.
Some assessment products sit in genuinely ambiguous territory. Tests marketed around "wellbeing," "stress resilience," or "mental capability" may start from a legitimate job-relevance rationale but produce scoring outputs that carry clinical weight. If a wellbeing index scores candidates on dimensions that meaningfully overlap with established measures of depression, anxiety, or burnout severity, the outputs may constitute health data regardless of the commercial framing.
Organizations should evaluate any such tool by examining its technical manual, the source constructs it draws from, and whether score interpretations are calibrated against clinical reference populations. If the answer to any of those questions suggests clinical health relevance, treat the data as Article 9 health data and apply the dual-lock compliance requirements accordingly.
Biometric data processed for unique identification purposes is a distinct Article 9 category, separate from health data. Organizations using facial recognition, fingerprint authentication, or voice biometrics as part of a hiring process must satisfy Article 9 conditions for biometric processing specifically. This is worth distinguishing because the legal basis and conditions available for biometric identification data are not identical to those available for health data. In most recruitment contexts, there is no compelling operational need for biometric identification processing, and organizations should apply strong data minimization discipline before introducing it.
The ICO's guidance on special category data rules (applying UK GDPR, which mirrors EU GDPR Article 9 in substance) establishes clearly that:
The ICO's separate guidance on data protection and workers' health information confirms that any health-related information about workers (or, by extension, candidates) falls squarely within the special category framework.
At the EU level, the European Commission's GDPR information portal provides the baseline rights and category definitions. The EDPB's evolving guidance on profiling and inferred special categories (reflected in documents including Guidelines 3/2025, even though those guidelines address the DSA-GDPR interplay rather than recruitment) supports the principle that inferred special category data should be treated with the same level of restriction as explicitly collected special category data. Organizations that build profiling pipelines in recruitment should take that principle seriously when their scoring logic or decision rules touch on Article 9-adjacent inferences.
The steps below give HR and legal teams a structured way to assess and document their position before deploying psychometric testing in recruitment.
Step 1: Classify each assessment by what it measures. Review the technical manual and scoring outputs of every tool in your recruitment pipeline. Determine whether the results are limited to job-relevant competencies or whether they generate health-related, biometric, or other Article 9-adjacent information.
Step 2: Assess how results are used. Even a job-competency tool can become health data if it is used in ways that treat outputs as health indicators. Audit how hiring managers interpret and act on results. Check internal documentation, interview guides, and rejection notes for language that signals health-related decision-making.
Step 3: Apply the dual-lock test. For any data that is, or could be, special category: identify your Article 6 lawful basis and your Article 9(2) condition. Document both explicitly. Do not assume consent will work in a recruitment context; assess whether Article 9(2)(b) (employment law obligations) or another condition is more appropriate.
Step 4: Apply data minimization. Collect only the psychometric data you need for the stated selection purpose. Do not retain raw scores, sub-scale results, or detailed profiles beyond the period necessary for the recruitment process. Establish clear retention schedules.
Step 5: Conduct a DPIA if required. Large-scale profiling using psychometric assessments, particularly where automated scoring influences selection decisions, is likely to constitute high-risk processing under Article 35 GDPR. A Data Protection Impact Assessment (DPIA for psychometric assessments) should be completed before deployment, with identified risks and mitigating controls documented.
Step 6: Govern access and sharing. Restrict access to psychometric results to those with a genuine selection-related need. Document who can access results, under what conditions, and for how long. Avoid sharing detailed profiles with line managers who are not trained to interpret them in context.
Step 7: Review vendor contracts and data processing agreements. Ensure your assessment provider is processing candidate data as a data processor under a compliant Data Processing Agreement (DPA). Confirm where data is stored, how it is secured, and under what conditions it can be used for the vendor's own purposes (e.g., normative research).
Organizations that take assessment design seriously from the outset are better positioned to stay outside Article 9 obligations where that is appropriate. Selection Lab's approach to recruitment assessment is built around measuring job-relevant competencies (soft skills, hard skills, cognitive ability, and cultural fit) in ways that generate explainable, defensible selection insights without producing unnecessary health-related inferences. Candidate data is processed on infrastructure based in Frankfurt, with retention controls and consent mechanisms designed to align with GDPR requirements from the ground up. That kind of privacy-by-design orientation does not eliminate the classification question, but it reduces the surface area where Article 9 obligations are likely to arise.
The practical takeaway for CHRO and HR leaders is this: psychometric data is not automatically special category data under GDPR Article 9, but the line is context-dependent and more easily crossed than many teams realize. The test is what the data reveals or allows to be inferred, not what the vendor calls the product. Where that line is crossed, the compliance burden is materially higher, and consent alone will not satisfy it. Investing time in classification, lawful basis analysis, and DPIA completion before deployment is substantially less costly than addressing a regulatory inquiry after the fact.

Psychometric testing has become a fixture in modern recruitment. Cognitive ability tests, personality questionnaires, situational judgment tools, and behavioral style inventories are now standard components of candidate selection pipelines across industries. With that widespread adoption comes a question that many CHROs and HR leaders have not fully resolved: does psychometric data qualify as special category personal data under GDPR Article 9, and what compliance obligations follow from that classification?
The answer is not a simple yes or no. It depends on what the assessment measures, how the results are interpreted, and how they are used in decision-making. Getting this classification wrong carries real regulatory risk, particularly given the ICO's active interest in employment data practices and the European Data Protection Board's (EDPB) emphasis on heightened obligations wherever special category processing is involved.
Under GDPR Article 9(1), processing special categories of personal data is prohibited by default. The prohibition is not merely a higher standard of care; it is an outright ban unless the controller can satisfy one of the specific conditions listed in Article 9(2). The categories covered include:
For recruitment purposes, the category that most frequently becomes relevant is data concerning health, which the ICO explicitly identifies as special category data requiring additional protections and conditions under UK GDPR (a framework that mirrors EU GDPR Article 9 in this respect).
In practice, organizations processing special category data face what practitioners often call the "dual lock." They must identify:
Both locks must be satisfied simultaneously. Neither alone is sufficient. The ICO's guidance on special category data rules confirms this two-layer structure clearly: even where an Article 6 basis exists, organizations still need to meet one of the Article 9(2) conditions before they can lawfully process special category data.
One common misconception among HR teams is that obtaining candidate consent resolves both requirements at once. It does not. Consent under Article 9(2)(a) requires explicit consent, which is a higher standard than ordinary consent. More practically, the ICO's guidance notes that consent is not always appropriate in employment or recruitment contexts precisely because of the power imbalance between employer and candidate. A candidate who believes their job prospects depend on agreeing to additional data processing cannot realistically give free, uncoerced consent. This is a significant constraint that many recruitment functions have not fully internalized.
A point that tends to be overlooked: special category classification is not determined by the label on the assessment tool. It is determined by what the data reveals or allows to be inferred. A questionnaire branded as a "personality inventory" can still capture or produce health-relevant inferences if its scoring methodology surfaces information about psychological disorders, mental health conditions, or clinically meaningful emotional states. The name on the test does not change the legal character of the data it generates.
Psychometric results are not automatically classified as GDPR special category personal data in recruitment. The classification depends on the nature of what is being measured and how results are used downstream.
The clearest framing is this: psychometric data becomes Article 9 data when it constitutes, or allows a reasonable inference about, one of the Article 9 categories. In recruitment, the most common trigger is "data concerning health," particularly mental health, psychological disorders, or clinically framed emotional functioning.
Most recruitment-grade psychometric assessments are designed to measure job-relevant traits: reasoning ability, communication style preferences, approach to teamwork, problem-solving tendencies, or cultural alignment. When the results are used exclusively for those purposes and do not produce clinically meaningful conclusions about a candidate's mental or physical health, they are typically not Article 9 special category data.
The risk emerges when assessments cross from measuring job-relevant behaviors into indicating health conditions. This can happen in two ways. First, the test itself may be designed to surface information about psychological wellbeing, stress tolerance at a clinical level, or emotional disorders. Second, even a test designed for job selection can become health data if the organization interprets and acts on the results as if they indicate health-related characteristics.
Edgecumbe Consulting, writing in a May 2023 analysis of GDPR and psychometric data handling, takes the position that psychometric data should be regarded as health data and therefore treated as subject to Article 9 special category safeguards in employment and recruitment contexts. That is a cautious interpretation, and while it is not the only credible view, it highlights the ambiguity that makes this area genuinely complex.
The EDPB's Guidelines 3/2025 on the interplay between the DSA and GDPR (v1.1, September 2025), though directed at digital services rather than recruitment specifically, reinforce a general principle relevant here: profiling and automated processing that generates inferences touching on special categories triggers heightened obligations, regardless of whether the underlying raw data was itself special category. Applied to psychometric assessment, this means organizations cannot assume they are outside Article 9 simply because they collected only job-competency scores if the processing pipeline converts those scores into health-relevant inferences.
Where a candidate is treated differently in the selection process based on results that a reasonable observer would read as health-related (e.g., being screened out because their "resilience score" implies vulnerability to mental health difficulties), the classification question becomes sharper. Using results as a proxy for health status is a path toward Article 9 classification even if that was not the original intent.
In all of these cases, the results address job performance-relevant dimensions and do not produce clinically meaningful health conclusions. Provided the organization processes results only for their stated selection purpose and does not repurpose them to draw health-related inferences, Article 9 obligations are unlikely to apply.
When results are stored, shared, or acted upon in ways that treat them as health data, the classification follows the practice, not the label.
Some assessment products sit in genuinely ambiguous territory. Tests marketed around "wellbeing," "stress resilience," or "mental capability" may start from a legitimate job-relevance rationale but produce scoring outputs that carry clinical weight. If a wellbeing index scores candidates on dimensions that meaningfully overlap with established measures of depression, anxiety, or burnout severity, the outputs may constitute health data regardless of the commercial framing.
Organizations should evaluate any such tool by examining its technical manual, the source constructs it draws from, and whether score interpretations are calibrated against clinical reference populations. If the answer to any of those questions suggests clinical health relevance, treat the data as Article 9 health data and apply the dual-lock compliance requirements accordingly.
Biometric data processed for unique identification purposes is a distinct Article 9 category, separate from health data. Organizations using facial recognition, fingerprint authentication, or voice biometrics as part of a hiring process must satisfy Article 9 conditions for biometric processing specifically. This is worth distinguishing because the legal basis and conditions available for biometric identification data are not identical to those available for health data. In most recruitment contexts, there is no compelling operational need for biometric identification processing, and organizations should apply strong data minimization discipline before introducing it.
The ICO's guidance on special category data rules (applying UK GDPR, which mirrors EU GDPR Article 9 in substance) establishes clearly that:
The ICO's separate guidance on data protection and workers' health information confirms that any health-related information about workers (or, by extension, candidates) falls squarely within the special category framework.
At the EU level, the European Commission's GDPR information portal provides the baseline rights and category definitions. The EDPB's evolving guidance on profiling and inferred special categories (reflected in documents including Guidelines 3/2025, even though those guidelines address the DSA-GDPR interplay rather than recruitment) supports the principle that inferred special category data should be treated with the same level of restriction as explicitly collected special category data. Organizations that build profiling pipelines in recruitment should take that principle seriously when their scoring logic or decision rules touch on Article 9-adjacent inferences.
The steps below give HR and legal teams a structured way to assess and document their position before deploying psychometric testing in recruitment.
Step 1: Classify each assessment by what it measures. Review the technical manual and scoring outputs of every tool in your recruitment pipeline. Determine whether the results are limited to job-relevant competencies or whether they generate health-related, biometric, or other Article 9-adjacent information.
Step 2: Assess how results are used. Even a job-competency tool can become health data if it is used in ways that treat outputs as health indicators. Audit how hiring managers interpret and act on results. Check internal documentation, interview guides, and rejection notes for language that signals health-related decision-making.
Step 3: Apply the dual-lock test. For any data that is, or could be, special category: identify your Article 6 lawful basis and your Article 9(2) condition. Document both explicitly. Do not assume consent will work in a recruitment context; assess whether Article 9(2)(b) (employment law obligations) or another condition is more appropriate.
Step 4: Apply data minimization. Collect only the psychometric data you need for the stated selection purpose. Do not retain raw scores, sub-scale results, or detailed profiles beyond the period necessary for the recruitment process. Establish clear retention schedules.
Step 5: Conduct a DPIA if required. Large-scale profiling using psychometric assessments, particularly where automated scoring influences selection decisions, is likely to constitute high-risk processing under Article 35 GDPR. A Data Protection Impact Assessment (DPIA for psychometric assessments) should be completed before deployment, with identified risks and mitigating controls documented.
Step 6: Govern access and sharing. Restrict access to psychometric results to those with a genuine selection-related need. Document who can access results, under what conditions, and for how long. Avoid sharing detailed profiles with line managers who are not trained to interpret them in context.
Step 7: Review vendor contracts and data processing agreements. Ensure your assessment provider is processing candidate data as a data processor under a compliant Data Processing Agreement (DPA). Confirm where data is stored, how it is secured, and under what conditions it can be used for the vendor's own purposes (e.g., normative research).
Organizations that take assessment design seriously from the outset are better positioned to stay outside Article 9 obligations where that is appropriate. Selection Lab's approach to recruitment assessment is built around measuring job-relevant competencies (soft skills, hard skills, cognitive ability, and cultural fit) in ways that generate explainable, defensible selection insights without producing unnecessary health-related inferences. Candidate data is processed on infrastructure based in Frankfurt, with retention controls and consent mechanisms designed to align with GDPR requirements from the ground up. That kind of privacy-by-design orientation does not eliminate the classification question, but it reduces the surface area where Article 9 obligations are likely to arise.
The practical takeaway for CHRO and HR leaders is this: psychometric data is not automatically special category data under GDPR Article 9, but the line is context-dependent and more easily crossed than many teams realize. The test is what the data reveals or allows to be inferred, not what the vendor calls the product. Where that line is crossed, the compliance burden is materially higher, and consent alone will not satisfy it. Investing time in classification, lawful basis analysis, and DPIA completion before deployment is substantially less costly than addressing a regulatory inquiry after the fact.