Data Processing Agreement

Processing of Personal Data
Annex to the Main Agreement
GDPR Article 28(3) controller–processor agreement

Reference: PRIV-DPA-01
Organisation: The Selection Lab B.V.
Version / Period: Version 2026.9 · September 2026
Address: Sint Pieterspoortsteeg 19, 1012 HM Amsterdam
Data Protection Officer: Ondřej Sloup (independent)
Chamber of Commerce: 71341730
Contact: [email protected]

This Data Processing Agreement ("DPA") governs all processing of personal data performed by Selection Lab in the context of its assessment, selection, and recruitment technology services, in accordance with Article 28(3) of the General Data Protection Regulation ("GDPR").

Incorporation, no separate signature required
This DPA is attached as an annex to, and forms an integral part of, the agreement(s) between the Parties under which Selection Lab provides its services (the "Main Agreement"). By signing the Main Agreement, each Party also agrees to and enters into this DPA. No separate signature of this DPA is required. This DPA enters into force on the effective date of the Main Agreement.

Parties

This DPA applies between:

  • The Selection Lab B.V., trading as Selection Lab, a private limited liability company registered in the Netherlands (Chamber of Commerce no. 71341730), with its registered office at Sint Pieterspoortsteeg 19, 1012 HM Amsterdam ("Selection Lab" or "Processor"); and
  • the party identified as the client in the Main Agreement ("Client" or "Controller"), whose corporate details, registered office and registration number are as stated in the Main Agreement.

Hereinafter collectively referred to as the "Parties", and individually as a "Party".

Recitals

A. The Parties have entered into the Main Agreement, under which Selection Lab provides services that involve the processing of personal data.

B. In the context of the GDPR, Selection Lab acts as an independent Data Controller for the assessment processing: it determines the purposes and means of processing candidates' assessment data, obtains their consent and handles their requests to exercise their rights. The Client acts as an independent Data Controller for its own recruitment process, including the decision whether to make an offer. For tasks Selection Lab performs strictly on the Client's instructions, such as sending assessment invitations on the Client's behalf, Selection Lab acts as Data Processor and this DPA applies, as described in Annex 1.

C. The Parties wish to set out their respective rights and obligations regarding such processing in this DPA. The specific processing details are described in Annex 1.

1 Definitions

The terms "Personal Data", "Processing", "Data Subject", "Controller" and "Processor" have the meanings given in the GDPR. Other capitalised terms have the meanings assigned below:

TermDefinition
Data BreachAny breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.
EU Standard Contractual ClausesThe European Commission's standard clauses for transferring Personal Data to third countries under Article 46(2)(c) and (d) GDPR.
Main AgreementThe agreement(s) between the Parties under which Selection Lab provides its services and to which this DPA is annexed.
Privacy LegislationAll applicable laws governing data protection and privacy, including the GDPR and the Dutch GDPR Implementation Act (UAVG).
Sub-ProcessorAny third party engaged by the Processor to process Personal Data on behalf of the Controller.

2 General principles and incorporation

2.1 Each Party shall comply with all applicable Privacy Legislation and process Personal Data only for legitimate business purposes.

2.2 This DPA forms an integral part of the Main Agreement. In case of conflict between this DPA and the Main Agreement with respect to the processing of Personal Data, this DPA shall prevail.

2.3 Acceptance of the Main Agreement (by signature or by any other means of acceptance provided for in the Main Agreement) constitutes acceptance of this DPA by both Parties. No separate signature of this DPA is required for it to be valid and binding.

3 Technical and organisational measures

3.1 The Processor shall maintain appropriate and auditable technical and organisational measures ("TOMs") to ensure the security, integrity, and availability of Personal Data.

3.2 These measures include, at minimum: confidentiality obligations, role-based access control, encryption, network protection, logging, and incident response. A summary is included in Annex 1, section 5.

3.3 The Processor shall periodically review and improve its TOMs to ensure continued compliance with the GDPR.

4 Processing instructions and Sub-Processors

4.1 The Processor shall process Personal Data only on documented instructions from the Controller, unless otherwise required by law.

4.2 The Processor shall promptly inform the Controller if, in its opinion, an instruction infringes Privacy Legislation.

4.3 Sub-Processors may be engaged only with the Controller's prior written approval. The Sub-Processors listed in Annex 1, section 4 are deemed approved by the Controller upon acceptance of the Main Agreement.

4.4 The Processor shall inform the Controller in advance of any intended addition or replacement of Sub-Processors, giving the Controller the opportunity to object on reasonable grounds.

4.5 The Processor remains fully liable for the performance of its Sub-Processors.

5 International data transfers

Personal Data is transferred outside the EEA only to the Sub-Processors listed in Annex 1, section 4, on the basis stated there for each, being an adequacy decision or the European Commission's Standard Contractual Clauses, and in full compliance with Chapter V GDPR. Approval of that list under Article 4.3 is the Controller's written authorisation.

6 Assistance and DPIA

The Processor shall assist the Controller in performing data protection impact assessments and in consultations with supervisory authorities when required.

7 Audit rights

The Controller may audit the Processor's compliance with this DPA once annually, or upon reasonable suspicion of non-compliance. The Processor shall cooperate fully and provide all necessary evidence.

8 Supervisory authority access

The Parties shall cooperate fully with competent supervisory authorities and provide access to systems and documentation as legally required.

9 Data Breaches

9.1 The Processor shall notify the Controller of any Data Breach within 24 hours of discovery.

9.2 The notification shall include all relevant details, including the nature of the breach, the affected data, the potential impact, and remedial actions.

9.3 The Processor shall not contact Data Subjects or authorities regarding a Data Breach without the Controller's prior approval, unless legally required to do so.

10 Data Subject rights

The Processor shall assist the Controller in responding to Data Subject requests under Articles 15 to 22 GDPR (access, rectification, erasure, restriction, portability, and objection).

11 Retention and deletion

Upon termination of the Main Agreement, the Processor shall return or delete all Personal Data as instructed by the Controller, unless retention is legally required.

12 Liability and insurance

Each Party is responsible for its own actions and omissions. The Processor shall maintain adequate insurance and shall be liable up to the limits set forth in the Main Agreement.

13 Duration

This DPA enters into force on the effective date of the Main Agreement and remains in effect for as long as the Processor processes Personal Data on behalf of the Controller, including after termination of the Main Agreement to the extent such processing continues.

14 Governing law and jurisdiction

This DPA is governed by Dutch law. Disputes shall be submitted exclusively to the competent court in Rotterdam, the Netherlands.

Annex 1 Description of processing

1. Contact details

  • Controller: the contact person designated by the Client in the Main Agreement or, in the absence thereof, the Client's signatory of the Main Agreement.
  • Processor: Ondřej Sloup, Data Protection Officer, [email protected].

2. Nature and purpose of processing

The Processor invites candidates on behalf of the Client to complete an online assessment used for recruitment or development purposes.

  • Categories of Data Subjects: job applicants of the Client.
  • Categories of Personal Data: name, email address, (optional) phone number, assessment data (psychometric responses and results).
  • Purpose: to enable the Client to assess the suitability of candidates for employment or development programs.

3. Clarification of roles

Selection Lab acts as an independent Data Controller for the assessment: the assessment content and psychometric methodology, the processing of candidates' responses and results, the consent candidates give, and their rights requests. The Client acts as an independent Data Controller for its own recruitment process, including the decision whether to make an offer. Selection Lab acts as Data Processor on the Client's behalf only for tasks it performs strictly on the Client's instructions, such as sending assessment invitations; this DPA governs those tasks.

4. Approved Sub-Processors

The following Sub-Processors are approved by the Controller upon acceptance of the Main Agreement. Sub-Processors process Personal Data within the EEA unless the table states otherwise; in that case the transfer rests on the European Commission's Standard Contractual Clauses (SCCs). The current list is also published in Selection Lab's privacy statement at www.selectionlab.com/pages/privacy.

Sub-ProcessorLocationRole
Amazon Web ServicesGermany (Frankfurt)Database and file storage.
Heroku (Salesforce)Ireland (Dublin)Application hosting.
Auth0GermanyAuthentication and login management.
BrevoFranceEmail delivery.
CloudflareGlobal network; United States (SCCs)DNS, TLS termination and content delivery.
TypeformSpain; responses hosted in the United States (SCCs)Assessment questionnaires.
VideoAskSpain; responses hosted in the United States (SCCs)Video-based assessment forms.
TestportalPolandHard-skill tests.
Redis CloudGermany (Frankfurt)Temporary data storage.
CloudAMQPEUMessage processing.
Papertrail (SolarWinds)United States (SCCs)Central application log storage.
SentryGermany / EUApplication logging.
HubSpotGermany / IrelandCommunication platform and customer support.
PendoEuropeUser statistics and analytics.
Google WorkspaceEuropeEmail and file storage.
SuperhumanUnited States (SCCs)Email client for staff mailboxes.

Applicable only where the Client uses the assessment concerned:

Sub-ProcessorLocationRole
AivyGermanyGame-based psychometric assessment.
BrghtEUIQ and personality assessment with proctoring.
CapprNetherlandsAssessment, under a pseudonymous identifier only.
CriteriaCorpUnited States and Australia (SCCs)Cognitive aptitude test; existing clients only.
Talogy (Cubiks)EUIQ assessment.
IxlyNetherlandsPsychometric assessment.
NOANetherlands / GermanyPsychometric assessment and talent portal.

Applicable only to Clients using SmartChat (AI chat screening):

Sub-ProcessorLocationRole
OpenAIUnited States (SCCs)Language model processing for AI chat screening (SmartChat). Personal identifiers are filtered through a PII gateway before processing.
LangfuseIrelandPrompt management and monitoring of the language model calls.
360dialogGermanyWhatsApp Business API.
WhatsApp Ireland (sub-processor of 360dialog)IrelandWhatsApp message delivery.

The Sub-Processors in this table apply exclusively where the Client has contracted SmartChat under the Main Agreement. For Clients without SmartChat, no Personal Data is processed by them.

5. Security measures

Selection Lab maintains security aligned with ISO 27001 standards, including:

  • Access control and authentication;
  • Encryption of data at rest and in transit;
  • Logging and monitoring;
  • Incident response and breach management procedures;
  • Secure hosting within the EEA, except where the Sub-Processor tables in item 4 state otherwise;
  • Annual external audits (ISAE 3000 type II or equivalent).

Reference documents

DocumentVersion used
Main Agreementper client, no version
Data Protection Impact Assessment (DPIA), PRIV-DPIA-012026.9
Privacy Statement, PRIV-PS-012026.9
Technical and Organisational Measures (TOMs), SEC-TOM-012026.9; available to the Client on request

Document control. This DPA is version 2026.9, September 2026, prepared by The Selection Lab B.V., Amsterdam, the Netherlands. Contact: [email protected] | www.selectionlab.com. Amendments to this DPA are made in accordance with the amendment provisions of the Main Agreement.