Repurposing hiring assessment results for team development is generally permitted, but it's not automatic. Under GDPR and broadly equivalent data protection frameworks, reusing pre-employment assessment data for a new purpose (coaching, learning plans, onboarding, succession) counts as "further processing." That triggers a specific set of obligations before you proceed.
This document walks through what you need to verify, document, and implement to use hiring assessment results for employee development in a legally sound way.
The UK ICO states clearly that you must only reuse personal information for a new purpose if it is compatible with your original purpose. The same principle applies under EU GDPR Article 6. So the first question isn't "can we ask for consent?", it's "is this new use compatible with what we told people when we collected the data?"
Run a compatibility assessment and document it. Consider:
If the original privacy notice mentioned only selection, the compatibility assessment needs to address that gap explicitly.
Don't default to consent here. In employment contexts, consent is widely considered a weak lawful basis because of the inherent power imbalance between employer and employee. The European Data Protection Board's Guidelines 1/2024 on Article 6(1)(f), published October 8, 2024, provide updated guidance on legitimate interests as a basis for processing. Documented legitimate interest, a contractual basis (where the development activity is tied to employment terms), or a legal obligation (in some jurisdictions) are more defensible options.
Whatever basis you select, document it. The basis chosen for the development purpose may differ from the one used during hiring, and both need to appear in your Record of Processing Activities (ROPA).
Work through these steps before repurposing any assessment data:
Once you've confirmed compatibility and lawful basis, update your documentation:
Platforms like Selection Lab handle this transition point directly. Per the Selection Lab Main Deck 2026, results are first shown to the candidate, and consent is requested again before results are shared with the hiring organization. That built-in consent checkpoint supports transparent handoffs. Selection Lab also stores all personal data in Frankfurt and establishes consent and retention periods per processing purpose, which gives HR teams a cleaner starting point for documenting purpose-specific data governance.
Role-based access is not optional here. Structure access in at least three tiers:
Keep development analytics off broad organizational visibility. If your assessment platform integrates with an ATS or HRIS (as Selection Lab does natively), verify that only the intended fields sync into development modules. Audit logs should record who accessed which records and when.
For AI-based intake data (for example, SmartChat conversations conducted via WhatsApp or webchat), confirm what conversation content is retained and under what processing controls before that data feeds into development workflows.
For team-level reporting (e.g., aggregate competency gaps across a department), use pseudonymized or anonymized data. Avoid distributing identifiable individual results across management layers.
A practical two-tier approach:
Selection Lab's Development module already produces reports along these lines: Leadership, Competencies, Motives, and Culture reports generated from assessment data. That structure maps naturally onto the two-tier model above.
Where full anonymization isn't feasible (such as in one-to-one coaching), document why and record what compensating safeguards are in place.
Set a defined retention period for each data category used in development:
Data category Example retention trigger Raw assessment responses Delete at end of hiring process unless repurposed Computed scores/profiles Retain for duration of development program Manager coaching notes Retain per HR records policy Video/audio (if collected) Delete unless separately justifiedDeletion triggers should include: end of the development program, employee departure, or a valid erasure request under GDPR. The ICO's storage limitation guidance is clear that individuals have a right to erasure when data is no longer needed for the stated purpose.
Document how your team handles data subject rights requests for both the original hiring records and the repurposed development records: access, rectification, objection, and erasure.
Three audiences need clear, separate communications:
Employees: Explain what data is being used, for what development purpose, who can see it, how long it will be kept, and what their rights are (including the right to object under GDPR Article 21).
Managers: Clarify that development results are for coaching guidance only, are confidential, and must not be used as the basis for disciplinary or performance management decisions beyond what is formally supported by your employment framework.
HR internal SOP: Document the workflow: request to repurpose, verify lawful basis, restrict access, confirm notice is updated, set retention period, and log in ROPA.
A short FAQ for employees covers the most common concerns:
Getting the communication layer right reduces objections and builds trust in using assessment insights for genuine development, which is where the data generates the most long-term value anyway.

Repurposing hiring assessment results for team development is generally permitted, but it's not automatic. Under GDPR and broadly equivalent data protection frameworks, reusing pre-employment assessment data for a new purpose (coaching, learning plans, onboarding, succession) counts as "further processing." That triggers a specific set of obligations before you proceed.
This document walks through what you need to verify, document, and implement to use hiring assessment results for employee development in a legally sound way.
The UK ICO states clearly that you must only reuse personal information for a new purpose if it is compatible with your original purpose. The same principle applies under EU GDPR Article 6. So the first question isn't "can we ask for consent?", it's "is this new use compatible with what we told people when we collected the data?"
Run a compatibility assessment and document it. Consider:
If the original privacy notice mentioned only selection, the compatibility assessment needs to address that gap explicitly.
Don't default to consent here. In employment contexts, consent is widely considered a weak lawful basis because of the inherent power imbalance between employer and employee. The European Data Protection Board's Guidelines 1/2024 on Article 6(1)(f), published October 8, 2024, provide updated guidance on legitimate interests as a basis for processing. Documented legitimate interest, a contractual basis (where the development activity is tied to employment terms), or a legal obligation (in some jurisdictions) are more defensible options.
Whatever basis you select, document it. The basis chosen for the development purpose may differ from the one used during hiring, and both need to appear in your Record of Processing Activities (ROPA).
Work through these steps before repurposing any assessment data:
Once you've confirmed compatibility and lawful basis, update your documentation:
Platforms like Selection Lab handle this transition point directly. Per the Selection Lab Main Deck 2026, results are first shown to the candidate, and consent is requested again before results are shared with the hiring organization. That built-in consent checkpoint supports transparent handoffs. Selection Lab also stores all personal data in Frankfurt and establishes consent and retention periods per processing purpose, which gives HR teams a cleaner starting point for documenting purpose-specific data governance.
Role-based access is not optional here. Structure access in at least three tiers:
Keep development analytics off broad organizational visibility. If your assessment platform integrates with an ATS or HRIS (as Selection Lab does natively), verify that only the intended fields sync into development modules. Audit logs should record who accessed which records and when.
For AI-based intake data (for example, SmartChat conversations conducted via WhatsApp or webchat), confirm what conversation content is retained and under what processing controls before that data feeds into development workflows.
For team-level reporting (e.g., aggregate competency gaps across a department), use pseudonymized or anonymized data. Avoid distributing identifiable individual results across management layers.
A practical two-tier approach:
Selection Lab's Development module already produces reports along these lines: Leadership, Competencies, Motives, and Culture reports generated from assessment data. That structure maps naturally onto the two-tier model above.
Where full anonymization isn't feasible (such as in one-to-one coaching), document why and record what compensating safeguards are in place.
Set a defined retention period for each data category used in development:
Data category Example retention trigger Raw assessment responses Delete at end of hiring process unless repurposed Computed scores/profiles Retain for duration of development program Manager coaching notes Retain per HR records policy Video/audio (if collected) Delete unless separately justifiedDeletion triggers should include: end of the development program, employee departure, or a valid erasure request under GDPR. The ICO's storage limitation guidance is clear that individuals have a right to erasure when data is no longer needed for the stated purpose.
Document how your team handles data subject rights requests for both the original hiring records and the repurposed development records: access, rectification, objection, and erasure.
Three audiences need clear, separate communications:
Employees: Explain what data is being used, for what development purpose, who can see it, how long it will be kept, and what their rights are (including the right to object under GDPR Article 21).
Managers: Clarify that development results are for coaching guidance only, are confidential, and must not be used as the basis for disciplinary or performance management decisions beyond what is formally supported by your employment framework.
HR internal SOP: Document the workflow: request to repurpose, verify lawful basis, restrict access, confirm notice is updated, set retention period, and log in ROPA.
A short FAQ for employees covers the most common concerns:
Getting the communication layer right reduces objections and builds trust in using assessment insights for genuine development, which is where the data generates the most long-term value anyway.