What this is for
Monitoring how a candidate takes an assessment is processing that a Customer, as controller, may need to assess in a data protection impact assessment (DPIA) under Article 35 UK GDPR, particularly where webcam photos are used. This pack sets out the facts of the processing so a DPIA can be completed quickly. It does not replace the Customer's own assessment, and it is not legal advice.
It is provided under section 5.2 of the Data Processing Addendum. For anything not covered here, contact [email protected].
1. Description of the processing
Modes and checks
The Customer starts each assessment from one of three modes - Unmonitored (every check off), Standard Monitoring (everything except webcam photos and requiring a single screen) or Proctor Mode (everything on) - and can switch any check on or off. Candidates are told which checks apply before they start.
| Check | What is recorded | What the candidate experiences |
|---|---|---|
| Always, on every assessment | IP address, approximate location (country and city only, from an offline geolocation database - no precise coordinates) and browser, captured once the test begins and every few minutes during it. Not captured from the assessment introduction page. | Told in the invitation email and on the assessment page. |
| Time away from the test | When the candidate leaves the assessment window (by switching tab or application), and for how long. | Warned on screen when time away is recorded. |
| Pastes from outside the test | Text pasted that did not come from inside the assessment, with its length and the question it was pasted into. Copying and pasting within the assessment is not recorded, and copying is never recorded. | Nothing is blocked. |
| Require fullscreen | Each time fullscreen is left, and the total time spent outside it. | A prompt to return appears whenever fullscreen is left. |
| Detect a second screen | Whether a second screen is connected during the assessment, where the browser can tell us (Chrome and Edge). | Warned on screen; nothing is blocked. |
| Require a single screen | That only one screen is connected at the start, and any second screen during the assessment. | Asked to disconnect extra screens before starting, and to use Chrome or Edge. |
| Webcam photos | If the candidate consents, still photos (not video, no audio) every 2, 5 or 10 minutes. Also whether the candidate chose not to use the webcam, and whether capture stopped during the assessment. | Told before signing in. Chooses, before starting, whether to use the webcam, and can take the same assessment without it. The browser shows its own camera-in-use indicator. |
What is not done
- No video or audio recording, and no screen recording.
- No facial recognition, biometric matching, or emotion or behaviour analysis of photos. No AI processes photos.
- No keystroke logging or typing-pattern analysis.
- No automated decision. The platform presents what happened with a risk score and a suggested review; the Customer's reviewers decide what, if anything, it means.
Data flow
- The candidate's browser sends integrity events to the CyberHire API (hosted on Fly.io, primary region London) while the assessment runs.
- Events are stored against the candidate's result in MongoDB Atlas (UK or EEA).
- Webcam photos are uploaded to a private Supabase storage bucket (EEA), in a folder scoped to the Customer. The result stores only the storage path.
- Authorised reviewers at the Customer see integrity information on the candidate's result page and in reports. Photos are shown through signed links that expire after one hour, generated only after checking the reviewer belongs to the Customer that owns the result.
2. Necessity and proportionality
- Choice of intensity. The Customer chooses the least intrusive checks that meet its need, per assessment. Standard Monitoring is the default; webcam photos are opt-in.
- Webcam is optional for the candidate. Consent is requested before capture, with a genuine alternative: the same assessment without the webcam. The candidate is told the Customer will see that choice.
- Data minimisation. Only pastes from outside the assessment are recorded, not everything copied or typed. Location is city-level only. Photos are stills at an interval of minutes.
- Retention. Webcam photos are deleted 90 days after they are taken. Other assessment data is deleted 24 months after the assessment closes unless the Customer instructs otherwise.
- Transparency. The checks that apply are listed in the invitation email, on the assessment page before sign-in, and in the Candidate Privacy Notice.
3. Risks to candidates, and measures
| Risk | Measures in the platform | What the Customer should do |
|---|---|---|
| A candidate feels unable to refuse the webcam in a recruitment context, so consent is not freely given. | The alternative is built in and immediate. Declining is recorded neutrally, never scored, and never shown as a concern. | Do not treat declining, or switching the camera off during the assessment, as a negative factor. This is a contractual commitment in the Terms of Service and DPA. |
| An integrity signal is read as proof of cheating when there is an innocent explanation. | Signals are described as what happened, not why. A single signal is low weight; "not checked" is shown where a check could not run; unmonitored attempts are never shown as clean. | Treat signals as prompts for a conversation, not conclusions. Give candidates a chance to explain before relying on them. |
| Photos incidentally reveal special category information (for example health or religion). | No analysis of photos of any kind. Access restricted to the Customer's authorised users. Deleted after 90 days. | Identify an Article 9 condition for any incidental processing (DPA section 4.4). Limit who in your team reviews photos. |
| Unauthorised access to photos or signals. | Private storage, Customer-scoped folders, ownership checks before any access, one-hour signed links, encryption in transit and at rest, audit logging. See Annex II of the DPA. | Manage your team's access and remove leavers promptly. |
| Data kept longer than needed. | Automatic deletion of photos at 90 days. Deleting a candidate also deletes their photos. | Delete candidates you no longer need, and set your own retention for anything you export. |
| Candidates using assistive technology or unusual setups are disadvantaged. | Nothing is blocked unless a single screen or fullscreen is required, and each check can be switched off. Time accommodations can be applied per invitation. | Offer adjustments on request, and consider switching checks off, or Unmonitored, where a candidate's needs make monitoring unfair. |
4. Candidate rights
Candidates can access, correct, and ask for deletion of their data, object to processing based on legitimate interests, and withdraw webcam consent at any time. Requests about assessment data go to the Customer as controller; CyberHire assists under the DPA. Deleting a candidate in the platform deletes their result, integrity data and webcam photos.
5. Lawful basis - points for the Customer to decide
- Standard Monitoring checks: commonly legitimate interests (Article 6(1)(f)) in a fair assessment process, supported by a legitimate interests assessment.
- Webcam photos: consent (Article 6(1)(a)), which the platform collects and records, relying on the no-detriment alternative described above.
These are the Customer's decisions as controller. Take advice where you are unsure.