Security

PDPO Compliance at BEST

June 9, 2026 · 9 min read

A white line-art padlock at the centre of four icons — a soundwave, a database, a person, and an eye — connected on a purple gradient, representing candidate personal data protected under Hong Kong's PDPO at BEST.

In short: When a candidate takes a BEST assessment, they share real personal data — their name, their photo, their voice, and their scores. BEST protects that data with encryption, strict access controls, a tamper-evident audit log, a clear retention schedule, and signed agreements with every subprocessor. Candidates can access, correct, or delete their data at any time. This is how BEST's PDPO compliance works, principle by principle.

When a candidate takes a BEST assessment, they give some of the most personal data in your whole hiring process. Their name and email. A photo. A recording of their voice. And a record of how well they speak under pressure.

If you hire in Hong Kong, protecting that data is not optional. The Personal Data (Privacy) Ordinance (PDPO) has been in force since December 1996, and it is one of Asia's oldest data-protection laws. It makes your organisation accountable for the personal data you collect — even when a vendor like BEST processes it for you.

So before you trust an assessment tool with your candidates' data, you should know exactly how that tool handles it. This post explains BEST's PDPO compliance in plain terms. We will explain what BEST collects, where it lives, who can see it, how long we keep it, and the rights every candidate has. Then we will map each control to the six principles the PDPO is built on.

What BEST collects — and what it does not

BEST collects only the data it needs to run and score a speaking assessment. Nothing more.

For each candidate, that means:

  • Identity: name, email, country, and the job profession they are testing for.
  • A photo: captured at check-in to confirm the right person took the test.
  • Voice recordings: the audio of their spoken answers across the assessment's three sections.
  • Results: the AI-generated and examiner-reviewed scores, plus the structured record behind them.
  • Integrity signals: lightweight activity data (such as tab-switching) used to flag possible cheating.

We do not ask for data we have no use for. There is no marketing tracking, no resale of candidate data, and no profiling beyond the assessment itself. The purpose is narrow, and we tell every candidate what we collect and why before they begin. That purpose is simple: assess their Business English speaking ability, and give your team a result you can defend.

Five labelled tiles showing the data BEST collects: Identity, Photo, Voice, Results, and Integrity signals.
The five types of data BEST collects — and nothing more.

Where your candidates' data lives

Your candidates' core data is stored in a single, access-controlled database hosted in Seoul, South Korea. It does not sit on a laptop or an unsecured server.

To run the product, BEST relies on a small set of specialist subprocessors. We hold a signed Data Processing Agreement (DPA) with every one of them. A DPA is a contract that legally binds each provider to protect the data we share, and to use it only on our instructions. A subprocessor without a signed DPA does not touch candidate data.

Here is the full list. We name all of them on purpose, because being open about who handles your data is part of compliance.

SubprocessorWhat it does for BESTSigned DPA
SupabasePrimary database + file storage (Seoul region)Yes
VercelApplication hostingYes
CloudflareContent delivery + network protectionYes
ClerkStaff sign-in and identityYes
ResendTransactional email (invites, notifications)Yes
OpenAIReal-time AI for the roleplay sectionYes
Google (Gemini)AI topic and scenario generationYes
ElevenLabsText-to-speech for spoken questionsYes
SentryError monitoring (with personal data scrubbed out)Yes

Two of these — the live AI voice services — process audio in the United States. That is a cross-border transfer, and we disclose it plainly rather than hide it. Because that data leaves Hong Kong, the signed DPA with each provider is the contractual safeguard that keeps it protected to PDPO standards. This is the approach Hong Kong's privacy regulator recommends for transfers abroad. Our core infrastructure providers are also independently audited. Supabase and Vercel both hold SOC 2 Type II and ISO 27001 certifications — the recognised industry standards for security and data handling.

How we keep it secure

BEST protects candidate data in transit, at rest, and at the point of access. Security is not one feature — it is several layers working together:

  • Encryption. All traffic runs over HTTPS, enforced by a strict transport-security policy, and stored data is encrypted at rest by our database provider. In plain terms: data is scrambled both while it travels and while it sits still. If it is intercepted or stolen, it is not readable in plain form.
  • A hardened application. BEST sends a set of security response headers that restrict what the browser can do. They stop the app from being embedded in other sites, disable device permissions like camera and location at the page level, and limit what code can run on the page. These are quiet defences against the most common attacks.
  • Strict access control. Only authorised staff can reach candidate results, and each one signs in through a dedicated identity provider. When a candidate is given direct access to their own data, we issue a single-use secure link. Its token is hashed with bcrypt and expires after 14 days. Tokens can be revoked at any time.
  • A tamper-evident audit log. Every time a person reads candidate audio, a photo, or a result, BEST records it in an append-only access log. "Append-only" means entries can be added but never quietly edited or deleted — enforced at the database level. If you ever need to know who saw a candidate's data and when, there is a record, and that record is tamper-evident.

How long we keep it

BEST does not keep candidate data forever. The PDPO is clear that personal data must not be held longer than necessary, so every record carries a retention date.

A daily automated sweep checks that date and acts on it. When a record reaches the end of its retention period, the sweep does one of two things. It anonymises the record — removing the identifying fields but keeping non-identifying data for uses like examiner calibration. Or it deletes the record outright, including the related files in storage. For example, support tickets are cleared 90 days after they are resolved, and integrity-monitoring data is held for around 12 months.

Every deletion and anonymisation is written to a log, so the record of what we removed remains even after the data itself is gone. The result is simple: data that is no longer needed is removed on schedule.

A retention timeline showing four stages connected by arrows: Collected, In Use, Deleted, then Logged.
Every record follows the same path: collected, used for its purpose, then deleted and logged.

The rights every candidate has

Under the PDPO, the person behind the data is in control — and BEST builds for that. A candidate (or your HR team acting for them) can exercise four rights:

  • Access — receive a complete copy of their personal data. BEST assembles every record we hold for that candidate into a single structured file, including time-limited secure links to their photo and audio.
  • Correction — fix data that is wrong.
  • Erasure — have their data permanently deleted. BEST removes every personal-data record tied to the candidate across the database and purges the matching files from storage.
  • Appeal — challenge a cheating flag, with the request logged and reviewed.

Each request follows a clear process: receive, verify, then respond. Data is only ever released or removed once we confirm who the requester is. The PDPO gives an organisation 40 days to answer an access or correction request, and BEST tracks every request against that deadline. Candidates reach these rights through a secure personal link, and a named Data Protection Officer is responsible for every request.

How BEST's PDPO compliance maps to the six principles

The PDPO is built on six Data Protection Principles (DPPs). Here is how BEST meets each one.

PrincipleWhat the PDPO requiresHow BEST meets it
DPP1 — CollectionCollect only what is necessary, by fair means, with the purpose made clearWe collect only assessment data and state the purpose up front
DPP2 — Accuracy & retentionKeep data accurate; do not keep it longer than neededCandidates can correct their data; a daily sweep deletes or anonymises on a set schedule
DPP3 — UseUse data only for the purpose it was collected forCandidate data is used to run and score the assessment — nothing else
DPP4 — SecurityTake all practicable steps to protect the dataEncryption, hardened headers, strict access control, tamper-evident audit logging
DPP5 — OpennessBe transparent about your data practicesWe publish what we collect, name every subprocessor, and disclose cross-border transfers
DPP6 — Access & correctionLet individuals access and correct their dataSelf-service access, correction, and erasure within the PDPO's 40-day window, owned by a named DPO

Built on diligence, not assumptions

These controls are not a checklist we completed once. BEST has been through a structured audit against all six PDPO Data Protection Principles. The audit examined every point where personal data is collected, stored, shared, and deleted. That audit is what shaped the controls above.

We are also preparing for changes in the law. Hong Kong has debated PDPO reforms — still proposals, not yet law — that would make data-breach notification mandatory. BEST already keeps a retention policy, a breach-response plan, and a signed agreement with every processor. So these changes will not catch your candidates' data unprepared.

Frequently asked questions

Is BEST PDPO compliant? BEST is built to meet all six Data Protection Principles of Hong Kong's Personal Data (Privacy) Ordinance — collection, accuracy, retention, use, security, openness, and access. Compliance under the PDPO is an ongoing posture rather than a one-off certificate, and we treat it that way.

Where is candidate data stored? Core candidate data is stored in an access-controlled database hosted in Seoul, South Korea. A small number of AI voice services process audio in the United States, which we disclose as a cross-border transfer.

How long does BEST keep candidate data? Only as long as it is needed for the assessment. Every record has a retention date, and a daily automated sweep anonymises or deletes data once that date passes.

Can a candidate see or delete their data? Yes. Candidates can request a full copy of their data, correct it, or have it permanently erased. A named Data Protection Officer handles every request.

Who can access candidate recordings? Only authorised staff, through a dedicated sign-in. Every access to audio, photos, or results is recorded in a tamper-evident, append-only audit log.

The short version

  • BEST collects only the data needed to run and score a speaking assessment.
  • Core data lives in an access-controlled database in Seoul; every subprocessor is named and under a signed DPA.
  • Data is encrypted in transit and at rest, access is strictly controlled, and every read is logged in a tamper-evident audit trail.
  • Nothing is kept longer than needed — a daily sweep anonymises or deletes data on schedule.
  • Candidates can access, correct, or delete their data at any time, through a named Data Protection Officer.

That is how BEST protects the people behind every assessment — and how we meet Hong Kong's PDPO, principle by principle.

Questions about how BEST handles personal data? Our Data Protection Officer can be reached at privacy@languagekey.com.

By BEST · Security

  • PDPO compliance
  • candidate data protection
  • data security
  • Hong Kong PDPO
  • data privacy
  • data protection
  • HR assessment

Keep reading

View all →