Personal Data JudgmentPersonal Data Judgment. Privacy training tests whether people remember the rules. Incidents are caused by what they do at four o'clock on a Friday.
Personal data judgment is what a person actually does with other people's information: how much they collect, who they let see it, how long they keep it, and how they answer the person it belongs to. It is measured on ordinary working situations and no item depends on any country's law.
The principle, not the rulebook — and over-refusal scored as the error it is
A spreadsheet with more columns than the task needs. A colleague asking for a list just to have it. A leaving employee's mailbox. A shared drive nobody has pruned in four years. A form that asks for a date of birth because the old form did. Somebody asking what you hold about them. Twenty situations of that kind, four selection exercises and eight self-check statements - and not one statute, regulator, acronym or deadline anywhere in it, because the principle is the thing that travels and the rulebook is the thing that changes.
Nine of the twenty situations key the LESS restrictive action, and that is the design decision the rest of this market has not made. Refusing a colleague something they needed to do their job, deleting what a person was entitled to keep, or making somebody prove themselves three times to get their own information are all failures, and they are the failures that get called caution. An instrument where sharing less always wins can be passed by ticking the careful box, and it teaches a team to be unhelpful in the name of compliance. So the report draws both directions of error opposed, names them in the instrument's own words, and lets the absolute count decide the reading.
The report says everything twice from one source: the sentence for you, and the same finding written as an instruction for whoever coaches you. One data structure, so the two versions cannot drift apart the way two separately maintained reports always do - and the coaching column is shown to you first, which is the opposite of how these reports usually work. It also prints the reliability table in full, and that table is where the report refuses to give you four numbers it cannot support: eight exercises cannot reach the point at which a figure is defensible, so each capability carries a classification and the composite carries the number.
What you walk away with
The sentence for you and the same finding written for whoever is coaching you, generated from one data structure so they cannot contradict each other.
Chance-corrected against the declared choice rates, with the assumed reliability and the spread it was computed from printed beside it.
Gave or kept more than needed, against withheld where it was not called for. Both are failures here and only one of them is usually reported.
Why no number appears against any of the four capabilities, with the arithmetic and the weighting decision stated rather than implied.
How often you pulled in more than belonged, and how often you left out what did — the habit behind most ordinary incidents.
Inside your report
Illustrative sample - your report is generated from your own responses.
Send the row rather than the sheet: convenience is what puts a whole list into a message.
Give her the rule as a question: what is the smallest thing that answers this?
Both columns come from one data structure, so the two versions cannot drift apart.
Diamond: what the evidence supports. Dot: what you let it count for.
Built for
- Compliance, privacy and HR teams who need something more diagnostic than an annual rules module with a quiz on the end
- Any team that handles other people's information — support, sales, marketing, operations, clinical admin, school offices, small businesses
- Training providers running data-protection or information-handling programmes in more than one country
Find out what you would actually do with somebody else's information
32 scored exercises - about 38 minutes - a full bespoke report with every finding said twice, both directions of error, and the reliability table in full.
₹999 (incl. GST) · assessment and full report, nothing further to pay
Frequently asked questions
What a person actually does with other people's information in ordinary working situations: how much they collect, who they let see it, how long they keep it, and how they respond when the person it belongs to asks about it. It does not measure knowledge of any country's data-protection law, technical security skill, IT competence, or honesty.
No, and that is the point. No statute, regulator, acronym, deadline or fine appears anywhere in it. Every item is written around the principle - only what is needed, only who needs to see it, only as long as it is useful, and the person can ask - so it reads the same in any market and does not go out of date when a regulation is amended. It complements a jurisdiction-specific course rather than replacing it.
Because it is one, and because leaving it out is how these instruments get gamed. Nine of the twenty situations key the less restrictive action: refusing a colleague something they need, deleting what a person was entitled to keep, or demanding three proofs of identity from somebody asking about their own record all cost somebody something. An assessment where sharing less always wins can be passed without reading it.
Because eight exercises cannot support one. The report prints the reliability estimate for each area, and each sits below the level at which a number rather than a band is defensible, so each carries a three-way classification instead. The whole instrument does clear that level, so the composite carries a number and its band. The report shows the arithmetic and states that the reliability is an assumed target, not yet a measurement.
Rs 999 in India including GST, or US$9.99 elsewhere, one time, for one full sitting and report. Privacy e-learning is sold per seat per year and examines recall of a rulebook; privacy-management platforms price by organisation and measure programme status rather than a person's judgment. Nothing on the market scores this construct for an individual. Organisations can use AssessAll credits at 26 credits per person.
Each one takes a single capability, puts you inside the situations where it is actually tested, and scores your choices against published evidence — with a report designed for that capability alone, not a template. They span hiring, compliance, education, operations and personal skill.
Browse the catalogue →Methodology: Measures behaviour with other people's information in ordinary working situations, through original situational, selection and self-report items keyed to published construct areas rather than to any country's rules. Construct statement: it measures what a person actually does with other people's information in ordinary working situations - how much they collect, who they let see it, how long they keep it, and how they respond when the person it belongs to asks about it - and it does not measure knowledge of any country's data-protection law, technical security skill, IT competence, or a person's honesty. Declared response instruction: behavioural tendency throughout - every situational stem asks what the respondent is most likely to do, not what should be done, because instructed-behaviour framing measures knowledge of the espoused answer and is easy to fake. Item format: twenty four-option situational items with graded partial credit, four select-three items graded on over- and under-selection, and eight self-report statements with balanced keying, half of them worded so that agreement is unflattering. Two situational pairs probe the same behaviour through different cover stories, so that an inconsistent pair flags instinctive rather than settled responding. Every option is an action a capable, well-meaning colleague could defend, and over-restriction is keyed as an error wherever it costs the business or the person their own information. Scoring design: a reliability-weighted composite in which each competency's weight is set by its own reliability estimate. Where the spread of reliability across the four competencies falls below the threshold at which differential weighting earns its keep, unit weights are used and the report says so. Any competency whose reliability estimate falls below that threshold is reported as a three-way classification rather than a number, because a point score on a subscale that thin would be read as more precise than it is. Construct areas drawn on: data minimisation and purpose limitation treated as design principles rather than legal tests; privacy by design and the behaviour of default settings; the privacy paradox between stated concern and observed behaviour; contextual integrity, the idea that a disclosure is appropriate or not according to the norms of the context the information came from; research on secondary use and function creep; insider-risk work showing that most losses are ordinary staff acting conveniently rather than maliciously; over-collection in forms and its effect on completion rates and on risk; de-identification and re-identification risk in small datasets; transparency and notice-comprehension research showing that people do not read notices and what follows from that; and work treating subject-access and complaint handling as a trust event rather than a process step. All items are original works, no jurisdiction, statute, regulator or trademarked instrument is named or reproduced, and no affiliation with any source is claimed. AssessAll original design.