
July 22, 2026
Subscribe to Vretta Buzz
Applying Privacy by Design in Assessment Organizations
The Role of Assessment Technology Providers
Designing for a desired outcome is a well-established principle across many disciplines. In educational assessment, for example, the concept of Validity by Design emphasizes that the validity of an assessment should be considered throughout the design process rather than evaluated only after the assessment has been developed.[1] The same philosophy applies to privacy. As education systems become increasingly digital, Privacy by Design encourages organizations to consider data protection from the outset, embedding privacy into the design of systems, processes, and technologies rather than treating it as an afterthought.
As education systems become increasingly digital, assessment environments rely on interconnected platforms such as student information systems, cloud hosting providers, assessment applications, and numerous other external services. Each connection improves efficiency, but also increases the importance of how personal data is handled and treated across the entire ecosystem.
This is where Privacy by Design becomes essential. The process requires organizations to consider data protection when designing processes and configuring systems. This design-first approach is equally relevant to educational assessment, where decisions made during the design phase have a lasting impact on the validity, reliability, and overall quality of the assessment.[2] The same principle applies to privacy: rather than addressing data protection after a system has been developed, Privacy by Design embeds it into the way systems are conceived, configured, and implemented from the outset.
This approach is reflected in the General Data Protection Regulation (GDPR), which requires data protection by design and by default.[3] Beyond compliance, it has become a practical framework for both the assessment organization and the technology provider that supports them, helping to ensure that privacy is consistently embedded in system configuration and use.
In this article, I explore Privacy by Design from two perspectives: first, from the perspective of assessment organizations and the decisions they make when processing personal data; and second, from the perspective of assessment technology providers, whose platforms should enable those privacy decisions to be implemented effectively in practice.
Privacy by Design means that privacy and data protection are considered at the moment a system, process, or service is being designed, not after it is already in use. In practice, this means asking early questions about what data is needed, who should have access to it, how long it should be retained, and how it will move between systems.
This approach is reflected in Article 25 of the GDPR, which requires organizations to implement appropriate technical and organizational measures to integrate data protection into processing activities “by design and by default.”[4] In other words, privacy should not depend on later fixes, workarounds, or user intervention where it can instead be built into the structure of the system itself.
For organizations using or providing assessment technology, this matters because many privacy risks are shaped by design decisions made before the system goes live. Privacy by Design therefore provides a practical framework for making these decisions more deliberately from the start.
For assessment organizations, Privacy by Design begins long before an assessment is delivered. It starts with carefully considering what information is needed, who should have access to it, and how it will be used throughout the assessment lifecycle.
The first step towards Privacy by Design is being intentional about the data that is collected. Every piece of information should have a clear purpose. Before adding a new data field or requesting additional information, organizations should ask a simple question: do we really need this to deliver the assessment? If the answer is no, it is usually better not to collect it. Doing so reduces privacy risks from the outset and makes data management considerably simpler.[5]
Privacy should also shape how information is accessed within the organization. Not everyone involved in the assessment process needs to see the same information. For example, teachers, administrators, and reporting staff all have different responsibilities, and their access to personal data should reflect those differences. Restricting access to what is genuinely needed helps to protect information while reducing the likelihood of accidental disclosure.
Finally, Privacy by Design extends beyond a single system. Assessment platforms often exchange information with student information systems and complementary technology vendors to support assessment delivery. Before enabling these communications, organizations should consider whether all of the data being shared is actually required. In many cases, limiting the amount of information exchanged is one of the simplest and most effective ways to reduce privacy risk.[6]
While assessment organizations define how personal data should be used, technology providers, including indeed the assessment platform providers, play an equally important role in ensuring that these decisions can be implemented in practice. Privacy by Design should therefore be reflected in the way assessment platforms are developed, configured, and maintained.
Assessment organizations can only put Privacy by Design into practice if the technology they use makes it possible. A well-designed assessment platform should therefore give organizations the flexibility to make its own decisions about the data being processed. Rather than imposing a single way of working, the platform should allow these decisions to be configured to reflect each organization's legal obligations, operational processes, and privacy expectations.[7]
At the same time, Privacy by Design is not achieved when a system is first deployed, it should rather continue throughout its lifecycle. Technology providers have an important role in maintaining that foundation by following secure development practices and delivering timely security updates. These capabilities help organizations to maintain privacy as their systems and operational needs evolve.[8]
Ultimately, Privacy by Design is a shared responsibility. Assessment organizations determine the objectives and rules for processing personal data, while technology providers deliver the tools and functionality needed to put those decisions into practice.
Privacy by Design is more than a regulatory requirement. It is a practical approach to building systems that protect personal data from the outset. By considering privacy during the design stage, rather than after deployment, organizations can reduce unnecessary risks, strengthen governance, and secure public trust.
For assessment organizations, this means making deliberate decisions about what data is collected, who can access it, and how information is shared throughout the assessment lifecycle. For assessment technology providers, it includes developing platforms that enable these decisions through configurable privacy settings and secure integrations.
When both perspectives are considered from the outset, privacy becomes an integral part of the ecosystem rather than an afterthought, benefiting to compliance, security, and public image.

Jana Begun is an EU-based legal professional specializing in data protection and privacy, with a focus on regulatory compliance. She holds an LL.M. from Stockholm University and is a Certified Information Privacy Professional/Europe (CIPP/E). At Vretta, she supports GDPR compliance and integrates privacy and security principles into the company’s day-to-day operations and digital learning platforms.
Her work centers on making complex legal requirements practical. She enjoys transforming privacy and security into actionable frameworks, helping build a culture where these topics are not just policies, but integral parts of everyday decision-making.
If you are interested in discussing data protection developments and explore how to strengthen security practices, please feel free to get in touch with Jana Begun at: dpo@vretta.com | LinkedIn