Processing of Personal Data
Annex to the Main Agreement
GDPR Article 28(3) controller–processor agreement
Reference: PRIV-DPA-01
Organisation: The Selection Lab B.V.
Version / Period: Version 2026.9 · September 2026
Address: Sint Pieterspoortsteeg 19, 1012 HM Amsterdam
Data Protection Officer: Ondřej Sloup (independent)
Chamber of Commerce: 71341730
Contact: [email protected]
This Data Processing Agreement ("DPA") governs all processing of personal data performed by Selection Lab in the context of its assessment, selection, and recruitment technology services, in accordance with Article 28(3) of the General Data Protection Regulation ("GDPR").
Incorporation, no separate signature required
This DPA is attached as an annex to, and forms an integral part of, the agreement(s) between the Parties under which Selection Lab provides its services (the "Main Agreement"). By signing the Main Agreement, each Party also agrees to and enters into this DPA. No separate signature of this DPA is required. This DPA enters into force on the effective date of the Main Agreement.
This DPA applies between:
Hereinafter collectively referred to as the "Parties", and individually as a "Party".
A. The Parties have entered into the Main Agreement, under which Selection Lab provides services that involve the processing of personal data.
B. In the context of the GDPR, Selection Lab acts as an independent Data Controller for the assessment processing: it determines the purposes and means of processing candidates' assessment data, obtains their consent and handles their requests to exercise their rights. The Client acts as an independent Data Controller for its own recruitment process, including the decision whether to make an offer. For tasks Selection Lab performs strictly on the Client's instructions, such as sending assessment invitations on the Client's behalf, Selection Lab acts as Data Processor and this DPA applies, as described in Annex 1.
C. The Parties wish to set out their respective rights and obligations regarding such processing in this DPA. The specific processing details are described in Annex 1.
The terms "Personal Data", "Processing", "Data Subject", "Controller" and "Processor" have the meanings given in the GDPR. Other capitalised terms have the meanings assigned below:
| Term | Definition |
|---|---|
| Data Breach | Any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data. |
| EU Standard Contractual Clauses | The European Commission's standard clauses for transferring Personal Data to third countries under Article 46(2)(c) and (d) GDPR. |
| Main Agreement | The agreement(s) between the Parties under which Selection Lab provides its services and to which this DPA is annexed. |
| Privacy Legislation | All applicable laws governing data protection and privacy, including the GDPR and the Dutch GDPR Implementation Act (UAVG). |
| Sub-Processor | Any third party engaged by the Processor to process Personal Data on behalf of the Controller. |
2.1 Each Party shall comply with all applicable Privacy Legislation and process Personal Data only for legitimate business purposes.
2.2 This DPA forms an integral part of the Main Agreement. In case of conflict between this DPA and the Main Agreement with respect to the processing of Personal Data, this DPA shall prevail.
2.3 Acceptance of the Main Agreement (by signature or by any other means of acceptance provided for in the Main Agreement) constitutes acceptance of this DPA by both Parties. No separate signature of this DPA is required for it to be valid and binding.
3.1 The Processor shall maintain appropriate and auditable technical and organisational measures ("TOMs") to ensure the security, integrity, and availability of Personal Data.
3.2 These measures include, at minimum: confidentiality obligations, role-based access control, encryption, network protection, logging, and incident response. A summary is included in Annex 1, section 5.
3.3 The Processor shall periodically review and improve its TOMs to ensure continued compliance with the GDPR.
4.1 The Processor shall process Personal Data only on documented instructions from the Controller, unless otherwise required by law.
4.2 The Processor shall promptly inform the Controller if, in its opinion, an instruction infringes Privacy Legislation.
4.3 Sub-Processors may be engaged only with the Controller's prior written approval. The Sub-Processors listed in Annex 1, section 4 are deemed approved by the Controller upon acceptance of the Main Agreement.
4.4 The Processor shall inform the Controller in advance of any intended addition or replacement of Sub-Processors, giving the Controller the opportunity to object on reasonable grounds.
4.5 The Processor remains fully liable for the performance of its Sub-Processors.
Personal Data is transferred outside the EEA only to the Sub-Processors listed in Annex 1, section 4, on the basis stated there for each, being an adequacy decision or the European Commission's Standard Contractual Clauses, and in full compliance with Chapter V GDPR. Approval of that list under Article 4.3 is the Controller's written authorisation.
The Processor shall assist the Controller in performing data protection impact assessments and in consultations with supervisory authorities when required.
The Controller may audit the Processor's compliance with this DPA once annually, or upon reasonable suspicion of non-compliance. The Processor shall cooperate fully and provide all necessary evidence.
The Parties shall cooperate fully with competent supervisory authorities and provide access to systems and documentation as legally required.
9.1 The Processor shall notify the Controller of any Data Breach within 24 hours of discovery.
9.2 The notification shall include all relevant details, including the nature of the breach, the affected data, the potential impact, and remedial actions.
9.3 The Processor shall not contact Data Subjects or authorities regarding a Data Breach without the Controller's prior approval, unless legally required to do so.
The Processor shall assist the Controller in responding to Data Subject requests under Articles 15 to 22 GDPR (access, rectification, erasure, restriction, portability, and objection).
Upon termination of the Main Agreement, the Processor shall return or delete all Personal Data as instructed by the Controller, unless retention is legally required.
Each Party is responsible for its own actions and omissions. The Processor shall maintain adequate insurance and shall be liable up to the limits set forth in the Main Agreement.
This DPA enters into force on the effective date of the Main Agreement and remains in effect for as long as the Processor processes Personal Data on behalf of the Controller, including after termination of the Main Agreement to the extent such processing continues.
This DPA is governed by Dutch law. Disputes shall be submitted exclusively to the competent court in Rotterdam, the Netherlands.
The Processor invites candidates on behalf of the Client to complete an online assessment used for recruitment or development purposes.
Selection Lab acts as an independent Data Controller for the assessment: the assessment content and psychometric methodology, the processing of candidates' responses and results, the consent candidates give, and their rights requests. The Client acts as an independent Data Controller for its own recruitment process, including the decision whether to make an offer. Selection Lab acts as Data Processor on the Client's behalf only for tasks it performs strictly on the Client's instructions, such as sending assessment invitations; this DPA governs those tasks.
The following Sub-Processors are approved by the Controller upon acceptance of the Main Agreement. Sub-Processors process Personal Data within the EEA unless the table states otherwise; in that case the transfer rests on the European Commission's Standard Contractual Clauses (SCCs). The current list is also published in Selection Lab's privacy statement at www.selectionlab.com/pages/privacy.
| Sub-Processor | Location | Role |
|---|---|---|
| Amazon Web Services | Germany (Frankfurt) | Database and file storage. |
| Heroku (Salesforce) | Ireland (Dublin) | Application hosting. |
| Auth0 | Germany | Authentication and login management. |
| Brevo | France | Email delivery. |
| Cloudflare | Global network; United States (SCCs) | DNS, TLS termination and content delivery. |
| Typeform | Spain; responses hosted in the United States (SCCs) | Assessment questionnaires. |
| VideoAsk | Spain; responses hosted in the United States (SCCs) | Video-based assessment forms. |
| Testportal | Poland | Hard-skill tests. |
| Redis Cloud | Germany (Frankfurt) | Temporary data storage. |
| CloudAMQP | EU | Message processing. |
| Papertrail (SolarWinds) | United States (SCCs) | Central application log storage. |
| Sentry | Germany / EU | Application logging. |
| HubSpot | Germany / Ireland | Communication platform and customer support. |
| Pendo | Europe | User statistics and analytics. |
| Google Workspace | Europe | Email and file storage. |
| Superhuman | United States (SCCs) | Email client for staff mailboxes. |
Applicable only where the Client uses the assessment concerned:
| Sub-Processor | Location | Role |
|---|---|---|
| Aivy | Germany | Game-based psychometric assessment. |
| Brght | EU | IQ and personality assessment with proctoring. |
| Cappr | Netherlands | Assessment, under a pseudonymous identifier only. |
| CriteriaCorp | United States and Australia (SCCs) | Cognitive aptitude test; existing clients only. |
| Talogy (Cubiks) | EU | IQ assessment. |
| Ixly | Netherlands | Psychometric assessment. |
| NOA | Netherlands / Germany | Psychometric assessment and talent portal. |
Applicable only to Clients using SmartChat (AI chat screening):
| Sub-Processor | Location | Role |
|---|---|---|
| OpenAI | United States (SCCs) | Language model processing for AI chat screening (SmartChat). Personal identifiers are filtered through a PII gateway before processing. |
| Langfuse | Ireland | Prompt management and monitoring of the language model calls. |
| 360dialog | Germany | WhatsApp Business API. |
| WhatsApp Ireland (sub-processor of 360dialog) | Ireland | WhatsApp message delivery. |
The Sub-Processors in this table apply exclusively where the Client has contracted SmartChat under the Main Agreement. For Clients without SmartChat, no Personal Data is processed by them.
Selection Lab maintains security aligned with ISO 27001 standards, including:
| Document | Version used |
|---|---|
| Main Agreement | per client, no version |
| Data Protection Impact Assessment (DPIA), PRIV-DPIA-01 | 2026.9 |
| Privacy Statement, PRIV-PS-01 | 2026.9 |
| Technical and Organisational Measures (TOMs), SEC-TOM-01 | 2026.9; available to the Client on request |
Document control. This DPA is version 2026.9, September 2026, prepared by The Selection Lab B.V., Amsterdam, the Netherlands. Contact: [email protected] | www.selectionlab.com. Amendments to this DPA are made in accordance with the amendment provisions of the Main Agreement.