Legal
IWPA Benchmarking and Data Use Policy
Effective: 2 August 2026 · Version: 2026-08
1. Purpose
This Policy explains how IWPA may use assessment data to calculate aggregate averages, validate and improve the assessment, monitor fairness, and develop future population-comparison benchmarks.
The purpose is to learn from patterns across many assessments without publishing or using participant names in research or benchmark outputs.
2. Current position
IWPA must not display a population percentile, population rank, z-score, T-score, or similar norm-referenced claim unless an approved benchmark dataset exists for the applicable assessment version, scoring version, population, and subgroup.
Where no legitimate benchmark is available, IWPA may show:
- normalized scores and bands;
- rank order within the participant's own profile;
- strengths and contrasts across the participant's own dimensions;
- the statement that a normative percentile is unavailable.
It must not invent or estimate a population comparison.
3. Optional participation
Where required by the applicable consent model, participation in research and benchmarking is optional and separate from the processing necessary to deliver the assessment.
A participant who does not agree to optional research use may still take the assessment and receive the applicable profile.
4. Information that may be used
With applicable consent or another valid legal basis confirmed for the relevant activity, the research dataset may include:
- assessment responses;
- computed subscale and domain scores;
- occupational-interest ranks;
- response-quality indicators;
- assessment, scoring, and profile-template versions;
- broad background information such as country, language, role level, employment status, field of work, education level, age band where collected, and gender where collected;
- technical quality information needed to remove test, duplicate, incomplete, fraudulent, or invalid records.
5. Information excluded from the research dataset
The dataset used to calculate averages and benchmark statistics must not contain:
- participant names;
- email addresses;
- phone numbers;
- payment-card information;
- postal addresses;
- assessment token secrets;
- free-text support messages;
- direct profile-download links.
A random or pseudonymous identifier may be used to manage quality, consent, deletion, deduplication, and audit requirements.
Any reversible link between that identifier and an operational participant record must be stored or controlled separately and accessible only to authorized personnel or systems.
6. Pseudonymised, de-identified, and anonymous data
Pseudonymised data replaces direct identifiers with a random identifier but may still be linked back using separately held information. It remains personal data where the link is reasonably available.
De-identified data has direct identifiers removed and indirect identifiers reduced, but re-identification may still be possible in unusual circumstances.
Anonymous aggregate data contains statistics across groups and no longer contains an individually addressable participant record.
IWPA will not describe pseudonymised data as anonymous.
7. Permitted uses
Approved research data may be used to:
- calculate means, medians, distributions, and other aggregate statistics;
- assess reliability, consistency, and measurement quality;
- identify items or scoring rules requiring review;
- test potential scoring changes without retroactively changing existing profiles;
- improve AI-supported interpretation while keeping deterministic scores unchanged;
- detect technical, language, or response-quality issues;
- study whether results differ materially across regions, languages, roles, industries, education levels, or demographic groups;
- monitor fairness and possible adverse-impact patterns;
- build candidate norm groups for future population comparisons;
- improve report design and usefulness.
Research data must not be used to:
- publicly identify a participant;
- create an advertising profile;
- sell identifiable assessment responses;
- make an undisclosed employment or other consequential decision;
- publish a small or rare group where re-identification is reasonably possible;
- create a benchmark that has not passed the required review.
8. Data-quality exclusions
A benchmark sample should exclude, as appropriate:
- internal tests and quality-assurance attempts;
- duplicate attempts where inclusion would distort the sample;
- attempts that do not meet approved completion or response-quality requirements;
- corrupted or technically invalid records;
- records produced under incompatible assessment or scoring versions unless a qualified review approves pooling;
- data collected without the required notice or consent.
Exclusion rules must be documented and applied consistently.
9. Minimum sample sizes
No norm table may be approved below N = 300 valid participants.
A broad general norm should preferably contain N = 500 or more valid participants before publication.
No subgroup-specific percentile may be published below N = 150 valid participants in that subgroup, regardless of the size of the parent sample.
A general norm approved between N = 300 and N = 499 must be clearly marked provisional wherever it is shown.
Meeting a numeric threshold does not automatically make a group safe or valid. Rare combinations and unrepresentative samples still require review.
10. Candidate norm groups
Potential norm groups may include:
- general working adults;
- early-career or graduate participants;
- managers;
- senior leaders;
- university students;
- role-family or occupational groups;
- industry groups;
- geographic or language groups where evidence supports separation.
Each group must independently meet the required sample and governance standards.
11. Required review before approval
Before a norm set is approved, IWPA must document:
1. the assessment and scoring versions; 2. the target population and inclusion criteria; 3. the sample size and subgroup sizes; 4. the collection period; 5. data-cleaning and exclusion rules; 6. response-quality requirements; 7. sample representativeness and known limitations; 8. regional and language differences; 9. occupational and education differences where relevant; 10. fairness and adverse-impact review; 11. re-identification risk; 12. the calculation method; 13. qualified human review and approval; 14. publication date and review date; 15. recalibration or retirement plan.
AI may assist analysis or documentation but may not be the sole reviewer or approver of a norm set.
12. Benchmark lifecycle
Each benchmark or norm set must have a controlled status such as:
- draft;
- reviewed;
- approved;
- retired.
Only an approved and currently applicable norm set may be shown in a participant or organization output.
Approved norm sets are versioned and immutable. A correction or recalibration creates a new version rather than silently changing the historical dataset.
A norm set must be blocked where:
- it is unpublished or unapproved;
- the assessment version does not match;
- the scoring version does not match;
- the sample or subgroup is too small;
- the population criteria do not match;
- it has expired or been retired.
13. Calculating population position
Where approved, population position should be calculated from the empirical distribution of the approved reference group rather than assuming that scores follow a normal distribution unless qualified review supports another method.
Every displayed comparison should identify or link to:
- the reference population;
- sample size;
- benchmark version;
- publication or effective date;
- provisional status where applicable;
- important limitations.
14. Small groups and re-identification
IWPA will not publish a group statistic merely because the group reaches the numeric minimum.
A review must consider whether a participant could be identified through combinations such as:
- employer and job title;
- small location and seniority;
- rare field of study;
- unusual demographic combination;
- free-text descriptions;
- a narrow organizational cohort.
Where risk is too high, IWPA may suppress the statistic, combine categories, remove fields, increase the minimum group size, or decline to publish the comparison.
15. Organizational access
An organization may receive only the benchmark or aggregate information permitted by its product, contract, campaign disclosure, consent model, and applicable law.
An organization does not receive:
- names or contact details from a cross-customer benchmark dataset;
- identifiable records belonging to another organization;
- unrestricted access to raw benchmark data;
- a small-group output that creates an unreasonable re-identification risk.
16. Withdrawal and deletion
A participant may withdraw optional research consent by contacting privacy@iwpa.io.
Where required and reasonably possible, the participant's pseudonymised research record will be excluded from future research processing.
Withdrawal does not affect lawful processing performed before withdrawal and may not allow removal of a contribution from an already-created, irreversibly anonymous aggregate statistic.
Operational assessment and transaction records may remain subject to the retention rules in the Privacy Policy.
17. Publication and transparency
Any public research or benchmark publication must:
- avoid names and direct contact information;
- describe the sample honestly;
- disclose material limitations;
- avoid overstating validity or causation;
- undergo re-identification and fairness review;
- receive authorized human approval.
18. Changes to this Policy
We may update this Policy as IWPA's research governance and international operations evolve. The published version will show its version and effective date.
Material changes to optional research use will be reflected in the participant notice and consent process where required.
19. Contact
Research, privacy, or withdrawal requests: privacy@iwpa.io Legal enquiries: legal@iwpa.io
Postal address: The Fourth Dimension Training & Consultancy FZ LLC Meydan Grandstand, 6th Floor Dubai, United Arab Emirates
