Skip to main content
Category: Impact Assessments & Documentation

Evaluation or Scoring

Also known as: Profiling and scoring, Evaluation and scoring
Simply put

Evaluation or scoring refers to processing that involves assessing, rating, or making predictions about people based on their personal data, such as running a credit check or profiling someone's behaviour. It is one of the factors that regulators, including the ICO, use to flag processing as higher risk. Where this kind of activity is involved, an organisation generally needs to consider whether a Data Protection Impact Assessment is required.

Formal definition

"Evaluation or scoring" is one of the criteria used to identify processing likely to result in a high risk to individuals, and therefore potentially triggering the requirement to carry out a Data Protection Impact Assessment (DPIA). It typically covers processing that profiles or evaluates individuals or makes predictions about them from their personal data, including aspects of their performance, economic situation, health, preferences, behaviour, location, or movements; examples cited in guidance include credit checks. This criterion derives from regulatory guidance on DPIA screening (notably ICO guidance building on the DPIA provisions of the UK GDPR) rather than being an independently defined term in the Regulation text, and it is generally weighed together with other high-risk indicators such as automated decision-making with legal or similarly significant effect, systematic monitoring, and processing of sensitive or highly personal data. The presence of evaluation or scoring does not automatically mandate a DPIA in every case; the overall assessment is context- and risk-dependent, and readers should verify the current criteria and any regulator- or member-state-specific lists against the applicable official guidance. This entry addresses evaluation or scoring in the DPIA context and should not be conflated with the general use of "evaluation score" as a performance metric for AI systems or models, which is a separate, non-legal usage.

Why it matters

Evaluation or scoring sits at the front line of DPIA screening because it captures a broad range of everyday processing that can materially affect people's lives. When an organisation assesses, rates, or predicts something about an individual from their personal data, the outcome can shape whether they get a loan, a job, insurance, or access to a service. That potential for consequential decisions is precisely why regulators, including the ICO, list evaluation or scoring as one of the indicators that processing may result in a high risk to individuals.

Treating this criterion correctly matters for compliance and accountability. Overlooking evaluation or scoring can lead an organisation to skip a DPIA that was in fact warranted, leaving risks to individuals unassessed and undermining the demonstrable accountability that regulators expect. At the same time, its presence does not automatically mandate a DPIA in every case; the assessment is context- and risk-dependent, and evaluation or scoring is generally weighed alongside other high-risk indicators such as automated decision-making with legal or similarly significant effect, systematic monitoring, and processing of sensitive or highly personal data.

It is also worth flagging a common source of confusion. "Evaluation or scoring" in the DPIA sense should not be conflated with an "evaluation score" used as a performance metric for an AI system, model, or workflow, which is a separate, non-legal usage. Because DPIA screening criteria and any regulator- or member-state-specific lists can evolve, readers should verify the current criteria against the applicable official guidance rather than relying on a single snapshot.

Who it's relevant to

Data Protection Officers and privacy leads
DPOs and privacy teams use evaluation or scoring as part of their DPIA screening process, weighing it against other high-risk indicators to decide whether a DPIA is required and to document that reasoning as part of demonstrable accountability.
Compliance and legal teams
Compliance and legal professionals need to distinguish this DPIA screening criterion from other concepts and confirm the current criteria against applicable official guidance, since regulator- and member-state-specific lists can vary and evolve over time.
Product managers and engineers building profiling systems
Teams designing systems that profile individuals or make predictions from personal data, such as credit-checking or behaviour-based tools, should flag these activities early so that the need for a DPIA can be considered before deployment.
Financial services and credit organisations
Organisations conducting credit checks or similar assessments of individuals' economic situations are directly implicated, as credit checks are an example cited in guidance under the evaluation or scoring category.

Inside Evaluation or Scoring

Systematic and extensive evaluation
Evaluation or scoring generally involves assessing personal aspects of an individual, often in a systematic and extensive manner. This concept features prominently in the criteria used to determine when a Data Protection Impact Assessment may be required under Article 35, particularly where evaluation is based on automated processing including profiling.
Profiling relationship
Evaluation or scoring is closely related to profiling as defined in Article 4, which refers to any form of automated processing of personal data to evaluate certain personal aspects of a natural person. Scoring is typically a form or output of profiling, though not all evaluation necessarily meets the full profiling definition; this should be assessed case by case.
Assessed personal aspects
The concept typically concerns predicting or assessing aspects such as performance at work, economic situation, health, personal preferences, reliability, behaviour, location, or movements. The specific aspects evaluated should be identified precisely, as the sensitivity of what is inferred affects the risk assessment.
Legal basis requirement
Evaluation or scoring involving personal data requires an Article 6 legal basis. Consent is only one of six possible bases and is not automatically required; legitimate interests, contract, or another basis may apply subject to assessment. Where special category data under Article 9 is involved, an additional Article 9 condition is generally needed.
Automated decision-making overlap
Where scoring produces a decision based solely on automated processing that has legal or similarly significant effects, additional safeguards under the automated individual decision-making provisions (Article 22) may apply. Not all evaluation or scoring triggers these provisions; it depends on the degree of human involvement and the significance of the effect, subject to assessment.

Common questions

Answers to the questions practitioners most commonly ask about Evaluation or Scoring.

Does every form of evaluation or scoring require consent from the individual?
No. Consent is only one of the Article 6 legal bases, and evaluation or scoring activities may rely on other bases such as contract, legal obligation, or legitimate interests, depending on the context. The appropriate basis must be assessed for the specific processing operation. Where the scoring involves special category data under Article 9, an additional Article 9 condition is required on top of the Article 6 basis. Treating consent as the default requirement is a common misconception; in many commercial or risk-management contexts consent may not be the most appropriate basis, and its suitability should be evaluated case by case.
Is all evaluation or scoring the same as automated decision-making that produces legal or similarly significant effects?
Not necessarily. Evaluation or scoring is a form of profiling that assesses personal aspects of an individual, but it does not automatically fall within the specific regime governing solely automated decisions that produce legal or similarly significant effects. Whether a particular scoring activity triggers that regime depends on the degree of human involvement and the nature of the effect on the individual, which requires case-specific assessment. Conflating the two can lead to applying the wrong safeguards, so the distinction between profiling generally and solely automated decision-making with significant effects should be assessed for each use case.
How should an organisation identify and document the legal basis for a scoring activity?
Generally, the organisation should map the specific scoring operation, identify the purpose, and select the most appropriate Article 6 basis for that purpose, documenting the reasoning as part of its accountability records. Where legitimate interests is relied upon, a balancing assessment is typically expected. If the scoring uses special category data, an additional Article 9 condition must be identified. The analysis should be revisited if the purpose or data changes. Because national implementing laws and member state derogations can affect the position, the reader should verify the specifics against the applicable law and current official text.
When is a Data Protection Impact Assessment relevant to evaluation or scoring?
A DPIA under Article 35 is generally relevant where the scoring is likely to result in a high risk to the rights and freedoms of individuals, and systematic and extensive evaluation of personal aspects is among the situations commonly associated with that threshold. The assessment of whether a DPIA is required should be made against the criteria in the Regulation and any relevant supervisory authority lists, which can differ between member states. Where a DPIA is carried out, it should be documented and kept under review as the processing evolves.
What transparency information should individuals receive about scoring that affects them?
In most cases, individuals should be informed about the existence of the profiling or scoring, the purposes, and the relevant legal basis, in line with the transparency obligations of the Regulation. Where the scoring falls within the regime for solely automated decisions with significant effects, additional information about the logic involved and the significance and envisaged consequences may be required. The precise content and manner of providing this information should be assessed against the applicable transparency provisions and current regulatory guidance, which continue to evolve.
What safeguards should be considered where scoring may significantly affect individuals?
Subject to assessment, appropriate safeguards may include mechanisms to enable the individual to obtain human intervention, to express their point of view, and to contest the outcome, particularly where the activity falls within the regime for solely automated decisions with significant effects. Organisations should also consider measures to address data accuracy, model or logic review, and the handling of data subject rights requests. The specific safeguards depend on the nature and impact of the scoring and on applicable guidance, so the appropriate measures should be determined case by case rather than applied uniformly.

Common misconceptions

Any evaluation or scoring of individuals always requires their consent.
Consent is one of several Article 6 legal bases and is not universally required. Depending on the context, controllers may rely on legitimate interests, performance of a contract, or another basis, each subject to its own conditions and a balancing or necessity assessment. The appropriate basis should be determined case by case.
Evaluation or scoring is the same as fully automated decision-making and is therefore prohibited unless an exception applies.
Evaluation or scoring and solely automated decision-making are distinct. Scoring may inform a decision that involves meaningful human involvement, in which case the specific restrictions on solely automated decisions with legal or similarly significant effects would generally not apply. The two should not be conflated.
Evaluation or scoring by itself automatically means a DPIA is legally mandatory.
Evaluation or scoring is one factor pointing toward the need for a DPIA under Article 35, particularly when systematic, extensive, and used as a basis for significant decisions. Whether a DPIA is required depends on the overall risk assessment and relevant supervisory authority lists, which can vary between member states.

Best practices

Identify precisely which personal aspects are being evaluated or scored and document whether the processing meets the profiling definition, as this affects the applicable obligations.
Select and document the appropriate Article 6 legal basis rather than defaulting to consent, and confirm an additional Article 9 condition where special category data is involved.
Assess whether the scoring feeds into a decision that is solely automated with legal or similarly significant effects, and put in place appropriate safeguards where the relevant provisions apply.
Conduct and record a screening for whether a Data Protection Impact Assessment is required, taking account of the systematic and extensive nature of the evaluation and any applicable supervisory authority lists, which may differ by member state.
Maintain clear documentation and transparency information explaining the logic and consequences of the evaluation to data subjects, calibrated to the significance of the effects.
Review the assessment periodically and against current official guidance, since regulator expectations on evaluation, profiling, and DPIA thresholds can evolve and diverge.