GDPR and privacy in practice
Knows privacy legislation requirements for own work, which legal basis and retention period apply and recognises when notification is required.
How hrmforce measures this
- Assessment method
- Knowledge test · rho 0.40 (SD 0.13)
- hrmforce instrument
- Knowledge test (client-specific)
- Competency (50-framework)
- Integrity
- Trainability
- high
- Demand outlook 2026 to 2030
- rising
Test of declarative job knowledge, usually assembled per client.
Behavioural anchors
| Level | Behaviour at this level |
|---|---|
| N1 Guided | Processes personal data only according to the applicable work instruction and refers doubtful cases to the privacy officer. works under supervision and follows instruction · routine, one variable at a time · own task |
| N3 Proficient | Judges in own processes whether a legal basis exists, applies data minimisation and handles requests from data subjects correctly. sets own approach and seeks input proactively · several variables, some ambiguity · own team or process |
| N5 Leading | Sets privacy policy, decides on high risk processing operations and represents the organisation towards the supervisory authority. sets the standard and the policy · strategic, under high uncertainty · organisation, value chain or profession |
N2 and N4 are deliberately not anchored. Raters place them between the anchors, following the O*NET convention.
Underlying skills
These skills inherit the assessment route and the behavioural anchors of this construct.
| T | Skill | Definition | Demand outlook 2026 to 2030 |
|---|---|---|---|
| K | Determining a GDPR legal basis Legal basis · GDPR | Determines on which legal basis a processing activity rests and records the justification for that choice. | rising |
| K | Maintaining a processing register Processing register · ROPA | Records purpose, data categories, recipients and retention per processing activity in the register of processing activities. | stable |
| V | Conducting a DPIA DPIA · Privacy impact assessment | Carries out a data protection impact assessment, names risks for data subjects and records measures and residual risk. | rising |
| V | Drafting a data processing agreement Data processing agreement · DPA | Drafts a data processing agreement with arrangements on purpose, security, subprocessors, notification duty and return of data. | rising |
| V | Handling a data subject request Data subject request · DSAR | Handles a request for access, correction or deletion within the deadline and documents what was provided. | rising |
| V | Reporting a data breach Data breach notification | Assesses whether an incident is notifiable, reports it to the regulator in time and informs data subjects where needed. | rising |
| V | Applying data minimisation Data minimisation | Limits requested and stored data to what is necessary for the purpose and removes unnecessary fields. | rising |
| V | Drafting a privacy statement Privacy notice | Writes in plain language which data is processed, why, for how long and which rights people have. | stable |
| K | Assessing international data transfers International data transfer | Assesses whether transfer outside the European Economic Area is allowed and which additional safeguards are needed. | rising |