Applicant Privacy Notice
1 Purpose
1.1.1 Datapharm Limited (“Datapharm”, “we”, “us”, “our”) are committed to protecting your privacy and meeting our legal obligations when you apply for a job or you (or an agent acting on your behalf) share your employment details with us.
1.1.2 This privacy notice explains what personal data we collect and use relating to employment and associated candidates (“you”, “your”) during the recruitment process.
1.1.3 We place great importance on ensuring the quality, confidentiality, integrity, and availability of the data we hold, and in meeting our data protection obligations where we process personal data. We are committed to protecting the security of your personal data. We use a variety of technical and organisational measures to help protect your personal data from unauthorised access, use or disclosure.
1.1.4 We update this privacy notice from time to time in response to changes in applicable laws and regulations, to our processing practices and to products and services we offer. When changes are made, we will update the effective date at the top of this document.
2 Policy Statement
2.1 What Personal Data do we process?
2.1.1 Personal data means any information about an individual from which that person can be identified, therefore, this does not include data where the identity of the person has been removed (anonymous data). There are “special categories” of more sensitive personal data which require a higher level of protection. Datapharm Limited is the controller of the personal data we hold about you, registered as such with the Information Commissioner’s Office (“ICO”) under registration reference ZA532747.
2.1.2 When you apply for a position (whether as an employee or consultant) or submit your CV (or similar employment information) to us, whether directly or through an agency, or attend an interview in person or by remote means, we will collect your personal data. This includes (but is not limited to):
• Name and contact details (address, mobile phone number and email address)
• Company details (where applicable)
• Date of birth and gender
• Work history and employment positions held
• Salary, other compensation, and benefits information
• Nationality / visa / work permit information (where applicable)
• Academic and professional qualifications, education, and skills
• Photographs you may submit with your application
• Demographic information
• Records we create during interviews or correspondence with you
• Results of pre-employment screening checks such as references or DBS checks (where applicable)
• Your performance on any psychometric tests or assessments
• If you visit our Career Site, we will collect information about your device, such as IP address, browser type and version, session behaviour, traffic source, screen resolution, preferred language, geographic location, operating system and device settings/usage
• Any ‘cookie’ information collected by our Applicant Tracking Software platform, Teamtailor
• Any information you post in public forums, including social media platforms
• Any other information you choose to give us
• Please note, when we receive/disclose references we do so on a confidential basis. As such, we will not provide you with a copy of your reference from a referee, or a reference we have submitted in response to a reference request.
2.1.3 Please note, when we receive/disclose references we do so on a confidential basis. As such, we will not provide you with a copy of your reference from a referee, or a reference we have submitted in response to a reference request.
2.1.4 We may also collect special category data in accordance with the Equality Act 2010. We will only do this, for example, to make reasonable adjustments to enable all candidates to apply for vacancies, attend interviews and to commence employment. This is also necessary to ensure we meet our legal obligations when recruiting.
3 Purposes and bases for using your personal data
3.1.1 We will process your personal information for the following purposes and under the following lawful bases:
Purpose - To assess your suitability for the role
Lawful Basis for Processing - Processing is necessary for taking steps to enter into a contract with you or for the performance of our contract with you (Article 6(1)(b) of the UK GDPR)
Purpose - To make reasonable adjustments for you during the interview process and comply with our legal obligations under the Equality Act 2010
Lawful Basis for Processing - Processing is necessary for us to comply with our legal obligations (Article 6(1) (c) of the UK GDPR)
For special category data, the additional basis that we rely on relates to our obligations in the field of employment and the safeguarding of your fundamental rights (Article 9(2) (b) of the UK GDPR and Schedule 1 Part 1(1) of the DPA 2018)
Purpose - To conduct pre-employment screening checks including checking your identity and your right to work in the UK
Lawful Basis for Processing -Processing is necessary for us to comply with our legal obligations (Article 6(1) (c) of the UK GDPR)
For special category data, the additional basis that we rely on relates to our obligations in the field of employment and the safeguarding of your fundamental rights (Article 9(2) (b) of the UK GDPR and Schedule 1 Part 1(1) of the DPA 2018)
Purpose - To contact unsuccessful applicants about future suitable vacancies
Lawful Basis for Processing -Processing is necessary for our legitimate interest of searching for suitable candidates for future vacancies based on their skills set out in the records we hold on candidates (Article 6(1) (f) of the UK GDPR) OR We will carry out this processing where you have consented to us retaining your data and contacting you about future vacancies based on the skills set out in the records we hold about you (Article 6(1)(a) of the UK GDPR)
4 Sensitive personal data
4.1.1 We will only process sensitive ‘special category’ personal data where we meet one of the conditions required by law for doing so. This includes complying with legal obligations or exercising specific rights in the field of employment law. We may also ask for your explicit consent to process some special categories of personal data.
4.1.2 We process special categories of personal data when we collect or process information about your physical or mental health, or disability status, to ensure your health and safety in the workplace and to assess your fitness to work and to provide appropriate workplace adjustments.
5 Sharing of your information
5.1.1 We may share your data with service providers and suppliers to our business who process data on our behalf. In such cases, our service providers and suppliers are processors and may only use the data in line with our instructions and not for any other purpose. This and other obligations are agreed in the contract between Datapharm Limited and the service providers and suppliers.
5.1.2 Your Personal Data may be processed outside of the UK. Where this is the case, we have taken appropriate steps to ensure that the Personal Data processed outside the UK has an essentially equivalent level of protection to that guaranteed in the UK. We do this by ensuring that:
• Your Personal Data is only processed in a country which the Secretary of State has confirmed has an adequate level of protection (an adequacy regulation), or
• We enter into an International Data Transfer Agreement (“IDTA”) with the receiving organisation and adopt supplementary measures, where necessary. (A copy of the IDTA can be found here international-data-transfer-agreement.pdf (ico.org.uk)).
6 How long will we retain your information?
6.1.1 We will retain your personal data for only as long as is necessary for the recruitment process. If your candidacy is successful and you are employed or hired by us, your data will be processed and retained as set out in our employee privacy notice, provided to you with your employment paperwork.
6.1.2 If your candidacy is not successful, we will retain your CV, application details and interview notes for 12 weeks (from the date we notified you we would not move forward with your application) in order to inform you about any future vacancies we have that may be of interest to you. Please let us know if you would like us to delete your records before our retention period lapses and we will do so.
6.1.3 We will also retain personal data where it is necessary to comply with our legal obligations or as necessary in relation to legal claims. This is rare but may mean we need to retain your data for longer than 12 weeks.
7 Your rights
7.1.1 Individuals whose personal data we process have the following rights:
• You have the right of access to your personal data and can request copies of it and information about our processing of it.
• If the personal data we hold about you in incorrect or incomplete, you can ask us to rectify or add to it.
• Where we are using your personal data with your consent, you can withdraw your consent at any time.
• Where we are using your personal because it is in our legitimate interests to do so, you can object to us using it this way.
• In some circumstances, you can restrict our processing of your data, request a machine-readable copy of your personal data to transfer to another service provider and compel us to erase your personal data.
7.1.2 If you wish to exercise any of your rights, please contact us at gdpr@datapharm.com or write to us at the following address:
Cassini Court, Randalls Way, Leatherhead, KT22 7TW
7.1.3 You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.
7.1.4 In addition to the above, please note that you have the right to make a complaint at any time to the ICO if you are concerned about the way in which we are handling your personal data.
8 Contact
8.1.1 You can contact Datapharm Limited in relation to data protection and this privacy notice by emailing us at gdpr@datapharm.com
9 Review
9.1.1 A review of this notice will be undertaken by the People team annually or more frequently as required and will be approved by the Senior Leadership Team.