Recruitment Privacy Policy
About us
Our commitment to you
- Lawful, fair and transparent;
- Compatible with the purposes that we have told you about;
- Adequate and necessary, we only use the data we need to use for the reason we told you;
- Accurate and up to date;
- Not excessive, we only keep your data for as long as we need it; and
- Secure and protected.
Why we process your personal data
Who is the Applicant Privacy Notice addressed to?
- a job applicant, whether applying directly to us, via a job board or via a recruitment agency;
- a successful applicant, prior to the confirmation of your appointment with us;
- a referee or a recruitment agent.
Ways we collect your personal data
- From you directly where you contact us in writing, by e-mail, when you meet with our team in person or by video call, by telephone, through our online portal, website or social media platform. You may contact us to provide a reference, enquire about a role, submit an application, schedule an interview, participate in recruitment exercises, provide pre-screening employment information or to express an interest to work with us;
- From a recruitment agent we have engaged to match candidates to our vacancies, or through an online recruitment platform we used to advertise the role;
- From your current and/ or former employers and/ or referees as part of our reference checks;
- From providers of psychometric, skills, and aptitude tests as part of our recruitment exercise;
- From providers of identity verification and compliance services as part of our onboarding background checks;
- Via CCTV operating in any of our office sites or buildings;
- From the devices you use when you access our website;
- From publicly available information about you such as your LinkedIn profile or your current employer website profile.
What personal data do we process for Applicants, Recruiters and Referees?
Data Type | Information Collected |
---|---|
Enquiry Data | Personal data you provide when you make an enquiry to us regarding a role. |
Applicant’s Contact Personal Data | Full Name Postal address Email address (personal and/or business) Phone Numbers Occupation |
Recruitment Data (including special category data) | CVs and covering letters. Completed application forms which may include contact details, career history, qualifications and skills, hobbies and interests. Information communicated in job interviews or through our recruitment processes. |
Equality Monitoring Data (including special category data) | We may collect and process gender, gender identity, ethnic origin, disability, religion and sexual orientation information at the application stage to ensure meaningful equal opportunity monitoring and reporting. |
Health and Medical Data (also special category data) | We may collect information about your health e.g. your disability status in order to provide appropriate adjustments during the recruitment process. |
Financial Data | In the course of the recruitment process, we may collect information relating to your current/previous salary and salary expectations. |
Criminal Convictions Data |
At the application stage, you may be asked to disclose the following:
Convictions (as well as spent convictions, if applying for an Advocate and Solicitor’s role).
In accordance with the Rehabilitation of Offenders Act 1974, you will not be asked to disclose any spent convictions, unless the job you are applying for falls into the following category: Advocates and Solicitors.
In accordance with the Exclusions and Exceptions (Scotland) Order 2003, these jobs are exempted from the right not to declare spent convictions.
Convictions/offences in the past 5 years in relation to driving records. This information is required for insurance purposes and only if relevant for the post for which you are applying.
|
Right to Work in the UK | British citizen status, UK work permit status or right to live in the UK status. Proof of status will be required for successful candidates. This information is legally needed to prove you have a right to work in the UK. |
Psychometric Data | We use recruitment aptitude tests, involving profiling, as part of our selection. No automated decision-making takes place as we do not solely rely on the output of these tests to make a recruitment decision. |
CCTV Data | Our office locations may operate CCTV and where they do this is clearly signposted. If you visit our offices your images may be captured on CCTV for security purposes. |
Personal Data within correspondence | Copies of letters, e-mails received or sent by us, and information you have provided to us in letters, e-mails, texts and audio recordings taken in relation to the recruitment process and employment. We may also keep notes and records of matters we discuss. |
Website Data | Includes internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website. Our external website uses cookies and we may collect information about how you use our website. |
Video telecommunication and collaborative platform data |
When invited and participating to a virtual meeting, the following types of information may be recorded:
|
Recruiters and referees’ personal data | Name Occupation Company/ organisation Business or personal email address Business or personal phone number Business or personal postal address Your relationship to the applicant Any information provided to us in emails, letters, calls in relation to the recruitment process of an applicant. We only process referees’ and recruiters’ data in connection with a candidate’s application, and will not use it for any unrelated purposes. |
What additional personal data do we process for successful candidates?
Data Type | Information Collected |
---|---|
Applicant’s Contact Personal Data | Full Name Postal address Email address (personal and/or business) Phone Numbers Occupation Your relationship to other persons Your emergency contacts |
Identity Verification Data | Date of birth Gender Photograph/Video Photographic ID document Address history Credit data Other identity evidence as required to meet our regulatory obligations. |
Health and Medical Data (also special Category Data) | In the course of your onboarding, we may process additional information about your health in order to provide equal access and workplace adjustments and to ensure meaningful equal opportunity monitoring and reporting. |
Biometric Data (also special category data) | Facial similarity checks are run when completing your ID verification with our identity verification and compliance services provider. The biometric technology compares an image of your face to the image on your ID document. |
Other screening information held in public records | Information held in public records, such as registers of insolvency, death, public offices held and any adverse information in the public domain for specific role types, or type of work undertaken. |
Financial and Credit Data | Information about your bank details to facilitate remuneration UK National Insurance number for taxation reasons Credit reports (hard credit checks) for specific role types |
Criminal Convictions and offences Data | As the nature of our work requires a high degree of trust and integrity we undertake a disclosure of your criminal records for certain role types. |
References | Information on your previous employment and reference details for this. Information provided by the referees regarding your employment and/ or character. For certain roles this will include all engagements within the previous 6 years. References are given in confidence, and not disclosable to the job applicant in most cases. |
Professional regulation data | Any relevant professional and academic qualifications, professional registration and disciplinary checks. |
Enquiry Data | Personal data you provide when you make an enquiry to us regarding a role via our website or via social media. |
Recruitment Data (including sensitive data) | Any information communicated through our recruitment processes. Information about any other adjustments required and scheme enrolments, such as benefits and flexible working preference. |
If you fail to provide personal data
Why we use your personal data
- comply with our legal obligations; or
- enter into and perform a contract with you; or
- fulfil our legitimate interests.
Data Protection Impact Assessments (DPIAs)
Purposes of Processing
Purpose | Lawful Basis of Processing (with GDPR Article) |
---|---|
To communicate with candidates, recruitment agencies and websites advertising our vacancies, regarding applications, interviews, feedback and role offer. |
Performance of an Employment Contract (Article 6(1)(b))
Legitimate Interests – to contact you to respond to communications from you. (Article 6(1)(f))
|
To populate our internal directory and systems with a picture of the successful candidate. | Consent (Article 6(1)(a)) |
To assess your skills, qualifications, employment history and suitability for the role. |
Consent (Article 6(1)(a))
Legitimate Interests – to support the assessment of your suitability for the role. (Article 6(1)(f))
|
To make decisions on your suitability for shortlisting for interview, interview and offer of the role. |
Consent (Article 6(1)(a))
Performance of an Employment Contract. (Article 6(1)(b))
|
To provide equal opportunity monitoring and reporting |
Explicit consent (Article 9(2)(a))
You have the right to withdraw your consent at any time.
|
To provide equal access and workplace adjustments during the recruitment process | Employment – processing that is necessary for carrying out obligations or exercising rights, imposed or conferred by law in connection with employment. (Article 6(1)(c), Article 9(2)(b)) |
Financial management and planning, including payroll |
Performance of an Employment Contract. (Article 6(1)(b))
Legal obligation (Article 6(1)(c))
|
To comply with pre-employment vetting checks, which may vary depending on role type, including reference checks, identity verification, prevention of financial crime, probity checks (criminal convictions, credit reports), right to work. |
Performance of an Employment Contract (Article 6(1)(b))
Legal Obligation to ensuring our business is carried out in compliance with the law or with our regulators’ guidance. (Article 6(1)(c))
When processing special category data:
• For reasons of substantial public interest – processing that is necessary for preventing fraud and suspicion of terrorist financing or money laundering. (Article 9(2)(g)) • Employment – processing that is necessary for carrying out obligations or exercising rights, imposed or conferred by law in connection with employment. (Article 9(2)(b))
Criminal convictions and offences data:
We process criminal convictions and offences data in accordance with Article 10 of the UK GDPR and Schedule 1 of the Data Protection Act 2018.
The specific lawful bases for processing are:
· Article 6(1)(b) – performance of an employment contract
· Article 6(1)(c) – compliance with a legal obligation
In line with Schedule 1, Part 1, Paragraph 1 (employment law), and Part 2, Paragraph 12 (substantial public interest – preventing fraud), we may process criminal convictions data where necessary for:
· verifying suitability for certain regulated roles,
· complying with regulatory or insurance requirements, or
· assessing trust and integrity in high-risk positions.
|
Record-keeping |
Legal obligation – we are required to retain certain information about you to comply with legal requirements. (Article 6(1)(c))
Legitimate Interests – to establish, exercise and/or defend any legal claims that may be brought by or against us in connection with your recruitment (i.e. discrimination claims). (Article 6(1)(f))
|
Cookies – we use cookies that are essential for the functionality of our website and we also use non-essential cookie which help us to understand how our website is used by visitors. Both essential and non-essential cookies use certain personal data. More information on our use of Cookies can be found in our Cookies policy.
|
Legitimate Interests – functional cookies which are necessary for the operation of our website. (Article 6(1)(f))
Consent – cookies which track how you interact with our website. (Article 6(1)(a))
|
IT and Security – we may use personal data to administer and protect our business and our website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) and to carry out system upgrade or system replacement. |
Performance of an Employment Contract (Article 6(1)(b))
Legitimate Interests – to ensure our website is secure and functioning. (Article 6(1)(f))
Legitimate Interests – to ensure we use the most appropriate systems. (Article 6(1)(f))
|
To support shortlisting with AI-assisted analysis | Legitimate Interests (Article 6(1)(f)) |
Where we store your personal data and information security
- Using secure cloud-based servers to store your personal data, based in the UK and the EU.
- Verifying the identity of individuals who access your personal data.
- Regular review of our Information Security Management System.
- Utilising a number of anti-virus and anti-malware systems at the gateway, on email and on endpoints to protect against cyber threats and encryption technologies to protect personal data where appropriate.
- Deploy data loss prevention as part of our software to help detect and mitigate the risk of data loss.
- Restricting access only to those employees who need to know the information to deliver the service to you.
- Providing regular data protection and information security training to all our employees.
Using Artificial Intelligence during Recruitment
Sharing personal data
- Where we are obliged by law or regulatory obligations.
- Where we share your information with third party service providers.
- Where we share your information with third parties who provide essential services.
- Where some or all of our assets are purchased by a third party.
- act only on our documented instructions,
- implement appropriate technical and organisational measures to ensure data security,
- assist us in fulfilling data subject rights and breach notification obligations, and
- do not engage sub-processors without our prior written approval.
- suppliers and service providers used by us to conduct the recruitment exercise, such as call, video telecommunication and messaging platforms; cloud-based servers and systems for data storage, secure file sharing; employment agencies.
- suppliers and service providers used by us to manage the relationship with applicants, recruiters and referees, such as; cloud-based servers and systems (i.e. for network security monitoring, HR recruitment management, such as applicant tracking, contextual recruitment, employment vetting management such as digital identity and criminal records verification providers, credit reference agencies).
- financial organisations.
- government departments.
- the courts.
- other professional advisers and consultants such as recruitment/consulting agencies, external law firms.
- regulatory authorities.
International transfers
We may transfer your personal information outside the UK, and when we do, we ensure appropriate safeguards are in place to protect your personal data and maintain an adequate level of protection.
Where personal data is transferred outside the UK, for example, when using Microsoft Teams, we implement suitable safeguards. These include the use of the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses (SCCs), or reliance on adequacy regulations where applicable. For further details, see the global Teams Data Processing Addendum here.
We also carry out Transfer Risk Assessments (TRAs) where required and can make summaries available to the Information Commissioner’s Office (ICO) or data subjects upon request.
How long we will keep your personal data for
Changes in personal information
Questions and concerns
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Your rights
Individual Right | What it means |
---|---|
Right to be informed
|
This Privacy Notice provides you with details as to how we collect and use your personal data. |
Right to access
|
You have a right to request access to the personal data we hold about you by making a “subject access request”. You will be provided with a copy of all personal information that we hold about you. There will be no charge for providing you with this information. |
Right of rectification
|
You have a right to request that we correct or complete any inaccurate or incomplete personal data we hold about you. |
Right of erasure
|
You have the right to ask us to delete your personal data where it is no longer necessary for us to use it, you have withdrawn consent, or where we have no lawful basis for retaining it. If we are required to keep your personal data to comply with our legal or regulatory obligations or legitimate interests in legal proceedings or claims, then we may have to decline your request. |
Right to restrict processing
|
You have the right to request that we restrict the processing of your personal data that we hold about you for specific reasons. If we are required to keep your personal data to comply with our legitimate interests in legal proceedings or claims, or the protection of the rights of another person, or for an important public interest, then we may have to decline your request. |
Right to data portability
|
You have a right to obtain and reuse the personal data that we hold about you for your own purposes in certain circumstances. |
Right to object
|
You have a right to object to us processing your personal data. If we are required to keep your personal data to comply with our legitimate interests in legal proceedings or claims, or can demonstrate our compelling legitimate interests or our appropriate safeguards in place for the specific purpose of scientific, historic research or statistics necessary for the performance of a task carried out in the public interest, then we may have to decline your request. |