Evaluation or Scoring
Evaluation or scoring refers to processing that involves assessing, rating, or making predictions about people based on their personal data, such as running a credit check or profiling someone's behaviour. It is one of the factors that regulators, including the ICO, use to flag processing as higher risk. Where this kind of activity is involved, an organisation generally needs to consider whether a Data Protection Impact Assessment is required.
"Evaluation or scoring" is one of the criteria used to identify processing likely to result in a high risk to individuals, and therefore potentially triggering the requirement to carry out a Data Protection Impact Assessment (DPIA). It typically covers processing that profiles or evaluates individuals or makes predictions about them from their personal data, including aspects of their performance, economic situation, health, preferences, behaviour, location, or movements; examples cited in guidance include credit checks. This criterion derives from regulatory guidance on DPIA screening (notably ICO guidance building on the DPIA provisions of the UK GDPR) rather than being an independently defined term in the Regulation text, and it is generally weighed together with other high-risk indicators such as automated decision-making with legal or similarly significant effect, systematic monitoring, and processing of sensitive or highly personal data. The presence of evaluation or scoring does not automatically mandate a DPIA in every case; the overall assessment is context- and risk-dependent, and readers should verify the current criteria and any regulator- or member-state-specific lists against the applicable official guidance. This entry addresses evaluation or scoring in the DPIA context and should not be conflated with the general use of "evaluation score" as a performance metric for AI systems or models, which is a separate, non-legal usage.
Why it matters
Evaluation or scoring sits at the front line of DPIA screening because it captures a broad range of everyday processing that can materially affect people's lives. When an organisation assesses, rates, or predicts something about an individual from their personal data, the outcome can shape whether they get a loan, a job, insurance, or access to a service. That potential for consequential decisions is precisely why regulators, including the ICO, list evaluation or scoring as one of the indicators that processing may result in a high risk to individuals.
Treating this criterion correctly matters for compliance and accountability. Overlooking evaluation or scoring can lead an organisation to skip a DPIA that was in fact warranted, leaving risks to individuals unassessed and undermining the demonstrable accountability that regulators expect. At the same time, its presence does not automatically mandate a DPIA in every case; the assessment is context- and risk-dependent, and evaluation or scoring is generally weighed alongside other high-risk indicators such as automated decision-making with legal or similarly significant effect, systematic monitoring, and processing of sensitive or highly personal data.
It is also worth flagging a common source of confusion. "Evaluation or scoring" in the DPIA sense should not be conflated with an "evaluation score" used as a performance metric for an AI system, model, or workflow, which is a separate, non-legal usage. Because DPIA screening criteria and any regulator- or member-state-specific lists can evolve, readers should verify the current criteria against the applicable official guidance rather than relying on a single snapshot.
Who it's relevant to
Inside Evaluation or Scoring
Common questions
Answers to the questions practitioners most commonly ask about Evaluation or Scoring.