Complying with privacy and data protection
Processes personal data according to the applicable privacy rules, knows the legal bases and acts on requests and data breaches by procedure.
How hrmforce measures this
- Assessment method
- Knowledge test · rho 0.40 (SD 0.13)
- hrmforce instrument
- Knowledge test (client-specific)
- Competency (50-framework)
- Integrity
- Trainability
- high
- Demand outlook 2026 to 2030
- rising
Test of declarative job knowledge, usually assembled per client.
Behavioural anchors
| Level | Behaviour at this level |
|---|---|
| N1 Guided | Shares personal data only through the approved systems and reports a suspected data breach immediately to the contact person. works under supervision and follows instruction · routine, one variable at a time · own task |
| N3 Proficient | Tests a new working method against the privacy rules, names the legal basis and records the processing in the register. sets own approach and seeks input proactively · several variables, some ambiguity · own team or process |
| N5 Leading | Sets the privacy policy of the organisation, decides on processing agreements and is the contact point for the supervisory authority. sets the standard and the policy · strategic, under high uncertainty · organisation, value chain or profession |
N2 and N4 are deliberately not anchored. Raters place them between the anchors, following the O*NET convention.
Underlying skills
These skills inherit the assessment route and the behavioural anchors of this construct.
| T | Skill | Definition | Demand outlook 2026 to 2030 |
|---|---|---|---|
| K | Applying GDPR legal bases GDPR legal basis | Determines on which legal basis a processing operation rests and records that choice traceably. | rising |
| K | Maintaining a processing register Processing register | Records purpose, legal basis, data categories, recipients and retention period per processing activity. | rising |
| K | Concluding a data processing agreement Data processing agreement | Concludes an agreement with a supplier on purpose, security, subprocessors and return of data. | rising |
| K | Reporting a data breach by procedure Data breach notification | Assesses an incident, records it and notifies the regulator and data subjects within the deadline. | rising |
| K | Handling a data subject request Data subject request | Handles requests for access, correction, deletion or transfer within the statutory deadline. | rising |
| K | Applying retention periods Retention periods | Determines how long data may be retained and ensures they are deleted afterwards. | rising |
| K | Carrying out a data protection impact assessment DPIA | Assesses the impact on data subjects for high risk processing and names control measures. | rising |
| K | Data minimisation in work processes Data minimisation | Limits the data requested in forms and systems to what is genuinely necessary. | rising |
| K | Setting up cookie policy and consent Cookie consent | Configures a consent banner and cookie statement that meet the statutory requirements. | rising |
| K | Assessing transfers outside the EU International data transfer | Assesses whether data may go to a third country and which additional safeguards are required. | rising |