Job Applicant Privacy Notice
The wording in this document reflects the requirements of the General Data Protection Regulation (GDPR), effective in the UK on 25 May 2018.
Data controller: BaseKit Platform Limited, One Castlepark, Tower Hill, Bristol, BS2 0JA
As part of any recruitment process, BaseKit collects and processes personal data relating to job applicants. BaseKit is committed to being transparent about how it collects and uses that data and to meeting its data protection obligations.
What information does BaseKit collect?
BaseKit collects a range of information about you. This includes:
- your name, address and contact details, including email address and telephone number;
- details of your qualifications, skills, experience and employment history;
- information about your current level of remuneration, including benefit entitlements;
- whether or not you have a disability for which BaseKit needs to make reasonable adjustments during the recruitment process;
- information about your entitlement to work in the UK;
- information about your marital status, next of kin, dependants and emergency contacts;
- equal opportunities monitoring information, including information about your ethnic origin, sexual orientation, health and religion or belief.
BaseKit collects this information in a variety of ways. For example, data might be contained in application forms, CVs or resumes, obtained from your passport or other identity documents, or collected through interviews or other forms of assessment, including online tests.
BaseKit will also collect personal data about you from third parties, such as references supplied by former employers, information from employment background check providers and information from criminal records checks.
BaseKit will seek information from third parties only once a job offer to you has been made and will inform you that it is doing so.
Data will be stored in a range of different places, including on your application record, in HR management systems and on other IT systems (including email).
Why does BaseKit process personal data?
BaseKit needs to process data to take steps at your request prior to entering into a contract with you. It also needs to process your data to enter into a contract with you.
In some cases, BaseKit needs to process data to ensure that it is complying with its legal obligations. For example, it is required to check a successful applicant’s eligibility to work in the UK before employment starts.
BaseKit has a legitimate interest in processing personal data during the recruitment process and for keeping records of the process. Processing data from job applicants allows BaseKit to manage the recruitment process, assess and confirm a candidate’s suitability for employment and decide to whom to offer a job. BaseKit may also need to process data from job applicants to respond to and defend against legal claims.
Where BaseKit relies on legitimate interests as a reason for processing data, it has considered whether or not those interests are overridden by the rights and freedoms of employees or workers and has concluded that they are not.
BaseKit processes health information if it needs to make reasonable adjustments to the recruitment process for candidates who have a disability. This is to carry out its obligations and exercise specific rights in relation to employment.
Where BaseKit processes other special categories of data, such as information about ethnic origin, sexual orientation, health or religion or belief, this is for equal opportunities monitoring purposes.
For some roles, BaseKit is obliged to seek information about criminal convictions and offences. Where BaseKit seeks this information, it does so because it is necessary for it to carry out its obligations and exercise specific rights in relation to employment.
If your application is unsuccessful, BaseKit will keep your personal data on file in case there are future employment opportunities for which you may be suited. BaseKit will ask for your consent before it keeps your data for this purpose and you are free to withdraw your consent at any time.
Who has access to data?
Your information will be shared internally for the purposes of the recruitment exercise. This includes members of the HR team, interviewers involved in the recruitment process, managers in the business area with a vacancy and IT staff if access to the data is necessary for the performance of their roles.
BaseKit will not share your data with third parties, unless your application for employment is successful and it makes you an offer of employment. BaseKit will then share your data with former employers to obtain references for you, employment background check providers to obtain necessary background checks and where relevant the Disclosure and Barring Service to obtain necessary criminal records checks.
How does BaseKit protect data?
BaseKit takes the security of your data seriously. It has internal policies and controls in place to ensure that your data is not lost, accidentally destroyed, misused or disclosed, and is not accessed except by our employees in the proper performance of their duties:
- Data stored on printed paper is kept in a secure place where unauthorised personnel cannot access it.
- Printed data is shredded when no longer required
- Data stored on a computer is protected by strong passwords which are regularly changed.
- Data stored on CDs or memory sticks must be locked away securely when not in use
- Any cloud-based storage provision must be company approved
- Data is regularly backed up in line with company procedures
- Data should never be saved directly to mobile devices such as laptops, tablets or smartphones
- All servers containing sensitive data must be approved and protected by security software and strong firewall.
Where BaseKit engages third parties to process personal data on its behalf, they do so on the basis of written instructions, are under a duty of confidentiality and are obliged to implement appropriate technical and organisational measures to ensure the security of data.
For how long does BaseKit keep data?
If your application for employment is unsuccessful, BaseKit will hold your data on file for 6 months after the end of the relevant recruitment process. If you agree to allow BaseKit to keep your personal data on file, BaseKit will hold your data on file for a further 3 months for consideration for future employment opportunities. At the end of that period or once you withdraw your consent, your data is deleted or destroyed.
If your application for employment is successful, personal data gathered during the recruitment process will be transferred to your personnel file and retained during your employment. The periods for which your data will be held will be provided to you in a new privacy notice.
As a data subject, you have a number of rights. You can:
- access and obtain a copy of your data on request;
- require BaseKit to change incorrect or incomplete data;
- require BaseKit to delete or stop processing your data, for example where the data is no longer necessary for the purposes of processing;
- object to the processing of your data where BaseKit is relying on its legitimate interests as the legal ground for processing; and
- ask BaseKit to stop processing data for a period if data is inaccurate or there is a dispute about whether or not your interests override BaseKit’s legitimate grounds for processing data.
If you would like to exercise any of these rights, please contact HR Manager on email@example.com. You can make a subject access request by completing BaseKit’s form for making a subject access request available in Appendix 1 below.
If you believe that BaseKit has not complied with your data protection rights, you can complain to the Information Commissioner.
What if you do not provide personal data?
You are under no statutory or contractual obligation to provide data to BaseKit during the recruitment process. However, if you do not provide the information, BaseKit may not be able to process your application properly or at all.
Recruitment processes are not based solely on automated decision-making.
Appendix 1 – Subject Access Request
Daytime telephone number:
By completing this form, you are making a request under the General Data Protection Regulation (GDPR) for information held about you by BaseKit that you are eligible to receive.
Required information (and any relevant dates):
By signing below, you indicate that you are the individual named above. BaseKit cannot accept requests regarding your personal data from anyone else, including family members. We may need to contact you for further identifying information before responding to your request. You warrant that you are the individual named and will fully indemnify us for all losses, cost and expenses if you are not.
Please return this form to the HR Manager.
Please allow 28 days for a reply.
Data subject’s signature: