Site icon The ANSI Blog

Do your Candidates and Certificants Know What You’re Doing with their Data?

Candidate taking secure online certification exam with data privacy protection.

Introduction

When I began working as a certification director at IAPP (International Association of Privacy Professionals), I learned very quickly that IAPP members were particularly vigilant about how their personal data was being collected, used, and retained. So we made sure our team is up-to-date on policy and prepared to answer questions about how their personal data is used.

If your organization is accredited under ISO/IEC 17024:2012 Conformity assessment — General requirements for bodies operating certification of persons, you are familiar with its required record control plan. But that is merely a starting point. By taking it another step and creating a Privacy FAQs page on your website that clearly and comprehensively describes what happens to your candidates’ and certificants’ personal data throughout their certification journey will go a long way.

Other important steps are outlined below to ensure proper data handling and building trust in data collection and use.

Be a Responsible Data Steward

Building trust with your candidates and certificants begins by training your staff in the best practices for data management, which includes:

Be Transparent about Data Policies

The testing process is a repository of some of the most sensitive personal data for candidates. Whether they go to test centers or test remotely in their homes, your testing vendor will process your candidates’ biometric data, recordings of their testing events (including images of their residence), driver’s license or passport images, and sensitive health data (for testing accommodations). Here are some things your candidates should know:

Conclusion

Data protection is not a burden. It is a business enabler that sets you apart from less responsible organizations. Showing your candidates and certificants that you care about data stewardship as well as their privacy will foster goodwill and make them feel comfortable engaging with you. This will become even more critical as organizations begin or increasingly use large language models or agentic AI in their certification process.  


[1] See more information on GDPR at https://gdpr-info.eu/.

Exit mobile version