Security Measures

How Selection Lab protects (special) personal data and the privacy of participants.

Reference: SEC-MEAS-01
Organisation: The Selection Lab B.V.
Version: Version 2026.9
Address: Sint Pieterspoortsteeg 19, 1012 HM Amsterdam
Contact: [email protected] · www.selectionlab.com · +31 (0)20 - 2443212

This document outlines the various security measures taken by The Selection Lab B.V. to ensure the safety of (special) personal data as well as the privacy of the participants.

1 General Protection Measures

  1. Pseudonymization of employees' personal data. See the pseudonymization process for details.
  2. Anonymization of employees' personal data before it is used to improve the general algorithm.
  3. Automated deletion of special categories of personal data from Typeform, whose response store is in the United States. The unique personal data is held on Amazon Web Services servers in Frankfurt, with the backup copy in Stockholm; the reporting datasets behind the internal sales and finance dashboards are held in Ireland (Athena) and in Frankfurt and Ireland (QuickSight). The services that hold data outside the EEA, and the safeguards, are listed in the DPIA §12.1.
  4. Multi-factor authentication is required for access to all databases and the mail server.
  5. Deletion of personal data (name and email) from third parties such as, but not limited to, Typeform.
  6. Confidentiality obligations for everyone who may come into contact with confidential data: article 12 of the employment contract for employees, and a standalone confidentiality agreement for contractors and for interns whose agreement lacks an equivalent clause.
  7. Within the organization, only a very limited number of individuals have access to special categories of personal data.
  8. All stakeholders with access to unique personal data use software (1Password) to protect their passwords.
  9. Data processing agreements are in place with the processors of personal data; the vendor register records the basis for each.
  10. The protection of employees' and candidates' privacy is explicitly legally defined in all agreements.

2 Protocol for Pseudonymizing Employee Data

Purpose of pseudonymization

To protect the personal data of employees of an organization without losing the ability to add additional data from the organization (such as whether someone is labeled as talent) to the employee data.

Step-by-step plan for pseudonymization

  1. One month after the fit algorithm is delivered, the names of the employees are replaced with 'anonymized' in the database. The email addresses are removed from all databases (including, but not limited to: AWS and Typeform).
  2. At the same time, a file is created for the organization in which each name and email address is linked to a unique URL that serves as an identifier. This file, also called the 'key', is handed over to the organization. The individuals whose data has been processed also have this same URL, as it was previously provided via email.
  3. Selection Lab deletes this key within one week of handing it over to the organization. Under no circumstances may Selection Lab regain access to this key. This ensures that Selection Lab cannot trace data back to any individual.
  4. If an individual wishes to have their data deleted, they can refer to their unique URL and the associated password. Selection Lab will then delete all data linked to this URL from the database.

3 Protocol for Preventing Submission Under Coercion

Measures for each user type to protect the voluntary consent of participants regarding special categories of personal data.

Employees

  1. There is extensive communication regarding the voluntary nature of participation.
  2. Individual data is never shared by Selection Lab with the organization under any circumstances.
  3. It is never disclosed who has completed the questionnaire and who has not.
  4. Data is communicated to the organization only on an aggregated level.

Candidates

  1. Candidates have the option to either not take the assessment or choose not to share their results.
  2. After the assessment, candidates will receive a further explanation, and explicit consent will be requested to share the results.
  3. Organizations we collaborate with are informed that candidates can freely choose whether to participate in the assessment and/or share their results. Additionally, candidates should not face any disadvantages for deciding not to participate or share their results.

Job Seekers

  1. Participation is entirely voluntary for students, as there is no employment relationship, and they must choose to participate on their own accord.
  2. Students receive comprehensive information about their rights, including the ability to withdraw their consent at any point in the process.

4 Neutrality of the Selection Algorithm

To ensure that our selection algorithm remains neutral and bias-free, we implement the following measures:

  1. We utilize validated scientific personality questionnaires without biases.
  2. Irrelevant personal data such as gender, age, ethnicity, and religion are not processed when calculating a candidate's fit score with an organization.
  3. We use a transparent algorithm, meaning it is always possible to trace why a specific candidate receives a particular score (i.e., no black box).
  4. We analyze employee performance across different departments, focusing on character traits, motivations, and cultural preferences. This analysis helps us identify candidates whose traits align with successful outcomes in specific organizations, effectively preventing the institutionalization of human biases.
Example
If an organization is predominantly composed of white men, they will appear in both average and top-performing groups. Therefore, factors such as ethnicity and gender cannot serve as reliable predictors of above-average performance.

5 Protocol on Retention Periods

To maintain compliance with data privacy regulations and ensure the proper retention of personal data, the following steps will be performed every six months, in April and in the October review week:

  1. Review the privacy statement to verify its completeness regarding personal data processing.
  2. Identify any personal data that needs to be deleted.
  3. Proceed with the removal of any identified personal data.

6 Data Encryption

We prioritize the security of our data through encryption, both during transmission and at rest. Below is a summary of how encryption is implemented with each partner:

PartnerEncryption measuresReference
HerokuDoes not store personal data. All data connections in transit use HTTPS and TLS.heroku.com/policy/security
Auth0Data encryption at rest and in transit. All network communication uses transport layer security (TLS) with at least 128-bit advanced encryption standard (AES) encryption. The connection uses TLS, and it is encrypted and authenticated using AES_128_GCM and uses ECDHE_RSA as the key exchange mechanism.auth0.com/security
TypeformIn transit: end-to-end encryption, including within the virtual private cloud at AWS, using secure TLS cryptographic protocols (TLS 1.2). At rest: Advanced Encryption Standard (AES) with a 256-bit key, including the backups of the information.help.typeform.com, "Security at Typeform" and "What happens to my data"
AWS DynamoDBIn transit: all data in DynamoDB is encrypted in transit (except the data in DAX). By default, communications to and from DynamoDB use the HTTPS protocol, which protects network traffic by using Secure Sockets Layer (SSL) / Transport Layer Security (TLS) encryption. Data in use can additionally be protected with client-side encryption. At rest: AWS owned CMK, the default encryption type; the key is owned by DynamoDB (no additional charge), using the 256-bit Advanced Encryption Standard (AES-256).Amazon DynamoDB documentation, "Encryption at Rest" and "DynamoDB Encryption Client"
BrevoEncrypted data during transmission via HTTPS, SSL and VPN. Data at rest is stored on secure servers in Tier 3 and PCI DSS certified data centers.n/a
CloudflareTLS terminates on Cloudflare's edge for both domains; the connection to the origin is encrypted and the origin certificate is validated (encryption mode Full (strict)).cloudflare.com/trust-hub
PapertrailLogs are sent over TLS and stored by SolarWinds under its SOC 2 Type II and ISO 27001 controls.n/a

Reference documents

DocumentVersion used
Data Protection Impact Assessment (DPIA), PRIV-DPIA-012026.9
Technical and Organisational Measures (TOMs), SEC-TOM-012026.9
Privacy Statement, PRIV-PS-012026.9
Data Management and Retention Policy1.9
Vendor register, VEN-REG-011.0