ENSEK's Job Applicant Privacy Notice

ENSEK LTD | PRIVACY NOTICE | JOB APPLICANTS

(V2.2 2023-04-27)

 

CONTENTS

1. WHO IS THIS PRIVACY NOTICE FOR?

2. WHAT THIS THIS PRIVACY NOTICE ABOUT?

3. WHO IS THE CONTROLLER OR PROCESSOR OF YOUR DATA?

4. WHAT DATA DO WE HOLD ABOUT YOU?

5. HOW DO WE OBTAIN YOUR DATA?

6. WHAT IS OUR LAWFUL BASIS FOR PROCESSING YOUR DATA??

7. WHAT PURPOSES DO WE PROCESS YOUR DATA FOR?

8. WHO DO WE SHARE YOUR DATA WITH?

9. WHERE DO WE KEEP YOUR DATA?

10. HOW LONG DO WE KEEP YOUR DATA FOR?

11. HOW DO WE KEEP YOUR DATA SECURE?

12. WHAT ARE YOUR RIGHTS?

13. USEFUL LINKS

 

1. WHO IS THIS PRIVACY NOTICE FOR?

This privacy notice is addressed to the types of individuals listed below (the data subjects). PLEASE ENSURE THAT YOU READ THIS NOTICE.

Job Applicants

(1) This privacy notice applies to individuals who are applying for or are being considered as candidates for a job with us.

(2) We are a controller in respect of your data.

Not Listed?

(1) We have separate privacy notices for staff, contractors, and the public.

(2) These are available on request.

Any Questions?

If you have any questions, please contact our HR team in the first instance, and then our data protection officer if your question has not been resolved.

 

2. WHAT THIS THIS PRIVACY NOTICE ABOUT?

This privacy notice explains what personal data we hold about you, how we collect it, how we use it, who we share it with, and what your rights are. We are required to notify you of this information, under data protection legislation. Set out below are some general points to note before reading further.

What is the applicable law?

(1) This document is a privacy notice is published to comply with Article 13 and Article 14 of the UK GDPR.

(2) You can find our more information here: (a) Information Commissioner's Office; (b) UK GDPR; (c) Data Protection Act 2018.

What is our commitment as controller?

(1) The controller of your data is the person ultimately responsible for the processing of your data.

(2) As the controller of your data, we are committed to complying with our legal obligations as controller of your personal data, and to transparency about what we use your data for.

(3) Our legal obligations are set out in: the UK GDPR and DATA PROTECTION ACT 2018 (supplements the UK GDPR).

(4) As controller, we comply with the DATA PROTECTION PRINCIPLES when gathering and using personal information. We seek to ensure that our information collection and processing is always proportionate.

(5) We will inform you of any material changes to information we collect or to the purposes for which we collect and process it.

Recruitment Agents

(1) If you apply for a role with us through a third party recruiter, then they will also process your data in accordance with their own privacy notice.

(2) They will be the data controller for their processing, and we will be the data controller for our processing.

(3) Please contact them to ask for a copy of their privacy notice.

Must you provide data?

(1) We need you to provide the personal data, in order to operate the recruitment process, verify your identity and right to work, check your background, obtain references, and assess your suitability, and negotiate any employment contract.

(2) If you do not provide the personal data we reasonably ask for, we may terminate the recruitment process.

No automated decision making

We do not use automated decision-making tools or processes to arrive at employment related decisions.

Contracts

When we refer to a contract in this privacy notice, we mean the employment contract you are applying for.

Processor and Controller

This privacy notice sets out whether we, or any person we transfer your data to, are: (a) controller (ultimately responsible); (b) processor (handle data for someone else).

 

3. WHO IS THE CONTROLLER OR PROCESSOR OF YOUR DATA?

The controller (or where applicable, processor) of your data is ENSEK LTD, and our contact details are set out blow.

Our Company Name

ENSEK Ltd

Our Company Number

UK Companies House: 07167027

Our Country of Registration

England and Wales

Our Registered Office

(1) Hounds Gate, 30-34 Hounds Gate, Nottingham, England, NG1 7AB.

(2) This is also our postal address and head office.

Our Website

https://ensek.com/

Our HR Emails

hr@ensek.co.uk

careers@ensek.co.uk

Data Protection Email

dataprotection@ensek.co.uk

Our Data Protection Officer

Our Data Protection Officer can be contacted through the email address provided above

 

4. WHAT DATA DO WE HOLD ABOUT YOU?

This section lists what data we hold about you in connection with your job application.

Assessments

Assessments, opinions, judgements, and decisions made in respect of your job application and suitability for the job.

Application

Your application details, including cover letter, and the location and role applied for.

Academic History

Information about your academic history, including schools and higher education, degrees and post-graduate education, and vocational training.

Biography

Biographical details, including hobbies, interests, and background, from your CV.

Claims

Information relating to any legal claims made by you in connection with your recruitment for use in dealing with and defending or settling those claims.

Contact Details

(1) Your contact details.

(2) Your personal and work email addresses.

(3) Your personal and work telephone and mobile numbers.

CV

The information contained in your CV, including employment and education history, and leisure, interests, skills, and hobbies.

Employment History

(1) Your employment history.

(2) You previous employers and your role with those previous employers.

(3) Start and end dates of previous employments.

(4) Salary, benefits, and notice period with current / previous employer.

Health

Information regarding your health, medical conditions, disabilities, if included in your CV, or where needed in order to make appropriate adjustments and arrangements for interviews to account for these.

Identity Details

(1) Your name, home location, address, date of birth, and age.

(2) Your image, in photographic form, if you chose to provide it in your CV or in our online application system.

(3) We use these at the interview stage simply to establish initially who is applying for the role. Full verification checks are carried out if you are offered the job.

Recruitment Agency

(1) The recruitment agency you were introduced through.

(2) Any other channel you were introduced or applied through.

References

(1) Details of your referees.

(2) If you are offered the job, then we may also take up and store references.

Right to work

(1) Information about your right to work in the country where the role is based.

(2) At the interview stage this is to give us an indicative view.

(3) If you are offered the job, then we will also ask for proof (including your share code from HMRC).

Social Media

Details about you from your LinkedIn account as published by you, to help us prepare for interviews with you and assess you for the role applied for.

Skills and Qualifications

Your professional qualifications, skills, and experience.

Tests and Assessments

Tests and assessments we administer with you, to test your skills and capabilities, including scores.

 

5. HOW DO WE OBTAIN YOUR DATA?

This section sets out how we obtain your data.

From Forms You Complete

(1) We obtain it from forms you complete.

(2) You may have provided it through a job application form online.

(3) You may have provided it through an online job board or other third party recruitment service (such as LinkedIn jobs).

(4) You may have provided it in a computer file you have filled in.

(5) You may have provided it through a paper form you have completed.

From Your Messages and Documents

(1) We obtain it from any CV you provide, or from any other documents or documentary evidence you provide, such as passports and proofs of address, identity and right to work.

(2) We obtain it also from emails and written messages you send to us (including enquiries you may send about jobs and placements).

(3) We obtain it from your public LinkedIn account.

From Conversation With You

We obtain it from conversation with you, which may include phone calls, video calls, interviews, emails, and instant messaging.

From A Recruitment Professional

We obtain data from a recruitment professional that was involved in your recruitment with us, or who put you forward as a candidate.

From Our Own Staff

We may obtain information about you where our own staff provide us with your CV and/or other details, as part of any referral scheme we operate internally.

From Third Parties

We may obtain information about you from the following third parties:

(1) Recruitment professionals involved in your recruitment with us.

(2) Our own staff referring you as a potential job candidate.

Verification By Third Parties

Also, if you are offered the job, we may obtain information from third parties for verification purposes including:

(1) HMRC

(2) Home Office

(3) Referees.

 

6. WHAT IS OUR LAWFUL BASIS FOR PROCESSING YOUR DATA??

To be able to process your data we need to have a lawful basis for doing so under the law.

Contract

(1) We need to use your data to enter into or perform a contract with you.

(2) This includes entering into and performing any employment contract or service contract.

Criminal Records

(1) We only process criminal convictions if you are awarded the job.

(2) We carry out background checks on all our staff, covering criminal convictions, credit check, global watch list , electoral roll, and 5 years address and employment history.

(3) This is because our business handles a lot of security sensitive data, and can access smart meters.

(4) This will be covered by our employee privacy notice.

Legal Obligation

We need to do so to comply with a legal obligation or exercise a legal right. This could be a statute.

Our Legitimate Interest

(1) We do so for our "legitimate interests".

(2) This is flexible ground which we must prove.

(3) It requires a judgement on our part, but is typically doing something you would normally expect, or there is a compelling justification.

(4) You have a right to object if you don't agree with our judgement (see later in this notice), and we must stop if it is clear you have overriding reasons for asking us to stop.

(5) Most of our processing would fall within the following legitimate interests in the field of recruitment: (a) to verify your identity, address, history, suitability, reliability and right to work; (b) to operate a fair recruitment process; (c) to make an informed decision and select the right person for our business; (d) to operate our equal opportunities obligations and policies; (e) to comply with legal obligations and carry out statutory background and right to work checks / provide data to third parties as required by law; (f) to insure our business.

Sensitive Data

(1) More restrictive rules apply to sensitive data about "racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; genetic data, biometric data for the purpose of uniquely identifying a natural person; data concerning health; and data concerning a natural person's sex life or sexual orientation".

(2) We can only process it for one of the following reasons: (a) Employment Law - The processing is in the field of employment and social security and social protection law and be authorised by law; (b) Occupational Health - The processing is necessary for preventative or occupational medicine, assessing your fitness to work, provision of health or social care; (c) Public Data - You placed the data into the public domain intentionally; (d) Claims - The processing is needed to make or defend a legal claim; (e) Consent - If none of the above apply, you have given a clear explicit and informed consent to the specific use.

(3) In your case, we only process health data, for the purposes of assessing your fitness to work and any reasonable adjustments we may have to make if you have a disability.

Your Consent

(1) If the above do not apply, we would need to get your consent to the specific use.

(2) This could be an explicit documented consent, or it could be implicit because you have requested some action to be taken involving your data.

Your Interests

We need to do so, to protect you vital interests. This could include care for your health and safety.

 

7. WHAT PURPOSES DO WE PROCESS YOUR DATA FOR?

This part sets out the key purposes we use your data for.

Administration

(1) PURPOSE | To administer the recruitment process.

(2) EXAMPLES | (a) Keeping a record of your application. (b) Arranging and holding interviews, making decisions, informing you and keeping records. (c) Auditing our recruitment and other processes and reviewing decisions made.

(3) LAWFUL BASIS | (a) Contract- Preparing for a contract with you. (b) Legitimate Interest- Operating a fair and well run recruitment process.

Assessment

(1) PURPOSE | To make an assessment of your suitability and a decision as to your appointment.

(2) EXAMPLES | (a) Considering your skills, experience, and qualifications. (b) Assessing your general aptitude and attitude and personal qualities. (c) Comparing you with other applications.

(3) LAWFUL BASIS | (a) Contract- Preparing for a contract with you. (b) Legitimate Interest- Operating a fair and well run recruitment process.

Contacting You

(1) PURPOSE | Contacting you and your next of kin.

(2) EXAMPLES | (a) We may contact you by letter, email, or phone where appropriate in relation to your application. (b) We may arrange interviews and inform you of the outcome at all stages.

(3) LAWFUL BASIS | (a) Contract- To enter into an employment or services contract with you. (b) Legitimate Interest- To properly deal with your application.

Entitlement to Work

(1) PURPOSE | (a) To record your entitlement to work, but without verifying it at the interview stage. (b) If you are offered employment, then we may also require proof of your entitlement to work.

(2) LAWFUL BASIS | Legitimate Interest- To ensure that we are lawfully employing our staff.

Health and Fitness To Work

(1) PURPOSE | (a) At the interview stage we would use health data to make reasonable adjustments for interviews. (b) If you are offered the job, then we would process health data to assess fitness to work and make reasonable adjustments in the workplace.

(2) EXAMPLES | (a) To assess your medical conditions and allergies. (b) To assess any disabilities and reasonable adjustments we may need to make.

Identity

(1) PURPOSE | (a) To record your identity and address, but without verifying this at the interview stage. (b) If you are offered the job, then we may verify your identity and address and require proofs of this.

(2) EXAMPLES | If we verify your identity, we may check identity documents, such as a passport and driving licence, and check your address, including through utility bills.

(3) LAWFUL BASIS | (a) Contract- To enter into and perform an employment or services contract with you. (b) Legitimate Interest- To know who our candidate is and where they can be contacted in relation to the application. (c) To inform our relevant managers of your application.

Recruitment Agents

(1) PURPOSE | (a) To recruitment agents who introduced you, to let them know the outcome and pay them any commission due. (b) To verify the applicability of any restriction periods preventing us engaging you directly.

(2) LAWFUL BASIS | Legitimate Interest- To be able to use recruitment agents to find staff.

References

(1) PURPOSE | To capture reference details Assessing your suitability for the role you applied for.

(2) EXAMPLES | (a) Obtaining references from your referees. (b) Sharing those references with managers responsible for interviewing you and making decisions. (c) Reviewing those references to assess your suitability and prepare for interviews with you

(3) LAWFUL BASIS | (a) Contract- To prepare for entering into a contract with you. (b) Legitimate Interest- To be able to fairly judge your suitability for the role, and against other candidates.

 

8. WHO DO WE SHARE YOUR DATA WITH?

This section details who we may share your information with. We will normally share in confidence unless the law requires otherwise

Auditors

(1) PURPOSE | (a) We may share your personal data with any third party that is auditing our business and controls, including our security measures and operational controls, for the purposes of evidence, but only to the extent reasonably required for such evidence. (b) It will be shared securely, and under a non-disclosure agreement; and is shared normally to the auditors secure evidence repository.

(2) RECEIVED AS | They use it as our sub-processor, to provide audit services to us.

Other Staff

(1) PURPOSE | (a) We may share your information where relevant with other staff who are to be involved in interviewing you or making decisions on your employment. (b) If you are successful we may share your information with our HR staff to commence your joining process with us.

(2) RECEIVED AS | They will receive it in their capacity as our staff.

Recruitment Agents

(1) PURPOSE | To recruitment agents who introduced you, to let them know the outcome and pay them any commission due.

(2) RECEIVED AS | They will receive it as data controller, and will let you have a privacy notice if legally required.

Referees

(1) PURPOSE | To your referees as needed to provide us with a reference.

(2) RECEIVED AS | They will receive it as data controller, and will let you have a privacy notice if legally required.

Background Check Providers

(1) PURPOSE | We will share your information with background check providers (currently Experian) to the extend necessary for them to carry out background checks such as: (a) criminal records; (b) credit; (c) electoral roll, world watch list, and address and employment history.

(2) RECEIVED AS | (a) They use it as our sub-processor, or provide the background check information to ourselves. (b) A credit search may also go on your credit record and they will do this as controller.

 

9. WHERE DO WE KEEP YOUR DATA?

Your data is kept in the systems referred to below. We no longer keep any paper records and all of your data is created, stored, and retained electronically.

Recruitment System : Cezanne

(1) We use the recruitment cloud service provided by Cezanne to store your CV and application details and track your application.

(2) Your CV is shared securely by link from Cezanne to staff who will be involved in your recruitment only.

Microsoft 365 and SharePoint

(1) ENSEK uses Microsoft 365, Exchange, and SharePoint for its general email, messaging, document creation, document storage and document sharing.

(2) Your personal data may appear there in an ad-hoc form where you are referenced in any emails or meetings in connection with your recruitment, including emails and contacts from you about placements and recruitment which may be stored in Microsoft systems.

 

10. HOW LONG DO WE KEEP YOUR DATA FOR?

This section covers our retention policy.

General Principle

We will only use your data for as long as it is required for the purposes for which it is processed.

Archiving Period | Unsuccessful

(1) If you are not successful, then we will retain a copy of your data for 18 months after the end of the recruitment process, and we will not use it except: (a) if you re-apply for the same role, or apply for a different role; (b) to check whether we are outside any restrictions preventing us from recruiting you directly and not through a recruitment agency; (c) to maintain evidence in case of claims.

(2) You can ask us to keep your CV on file longer than this, but we reserve the right to delete it at any time.

Archiving Period | Successful

If you are successful, then our full employee privacy notice will apply and you will be informed of that separately, which has a 7 year retention period from the end of your employment.

 

11. HOW DO WE KEEP YOUR DATA SECURE?

This section covers our security measures.

General Principle

(1) We have appropriate security measures in place to prevent personal information from being accidentally lost, or used or accessed in an unauthorised way.

(2) In particular we have the following measures to keep your data secure.

ISO 27001

We are certified to and aim to keep certified to ISO 27001, which requires us to have a security management system, and to maintain a wide range of security controls. See ISO 27001

ISO 27701

We are also certified to and aim to keep certified to ISO 277001, which is an extension to ISO 27701 for privacy information management. See ISO 27701

SOC

We have our security controls audited independently by an auditor under the ISAE 3402 audit standard. See ISAE 3402

Data Breach

(1) We have procedures in place to deal with any suspected data security breach affecting your data.

(2) We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.

Other Measures and Controls

(1) The above standards and audits require and examine all our security and privacy measures and controls, which we have in place to protect against unauthorised use, access to, change to, or disclosure of your data, against viruses and other malicious software, and against unauthorised access to our equipment, offices, networks, cloud systems, and databases.

(2) These measures and controls cover areas such as office access controls, equipment log-in, cloud system log-in and associated roles and permissions, network and access monitoring, staff training, management, staff background checks, usage monitoring, anti-virus and other protective software and devices, and data segregation and encryption.

System Providers

Individual system providers listed in this document have their own separate security and controls with respect to your data in their systems, and we consider these prior to using those systems.

Cloud First

We operate on a "cloud first" basis, which means that your data is stored in secure and reputable cloud systems, rather than at any offices of ours.

Access Controls

We limit access to your personal information to those who have a genuine business need to know it.

Proportionate and Confidentially

Those processing your information will do so only in an authorised and proportionate manner and are subject to a duty of confidentiality.

 

12. WHAT ARE YOUR RIGHTS?

This section covers your rights in relation to our processing of your data.

Introduction

(1) You have the following rights in relation to our processing of your personal data, but please note that these rights may be subject to conditions and exceptions set out in the law.

(2) If you would like to exercise these rights, please contact the head of human resources or our data protection officer.

Our Service Providers

If you ask for the following, we are obliged to pass this request down to the providers of the systems we use and anyone else we use to process your data, as needed. See Article 19 of the UK GDPR.

Right to be informed

(1) You have the right to be informed if your data is being used.

(2) This document is how we are informing you.

(3) See Article 13 and Article 14 of the UK GDPR.

Right to withdraw consent

If any processing is based on your consent, you have the right to withdraw it at any time. Just email using our contact details in this document.

Right to stop direct marketing

You have the right to stop direct marketing at any time.

Right to a copy

(1) You have a right to an update of the information in this document.

(2) You also have a right to a copy of the personal data we hold about you.

(3) See Article 15 - Paragraph 3 of the UK GDPR.

(4) You have the right to ask for your data in a computer readable for, so that you can use it elsewhere.

(5) See Article 20 of the UK GDPR.

Right to a correction

(1) You have the right to request correction of your data (a right to rectification).

(2) See Article 16 of the UK GDPR.

Right to erasure

(1) You have the right to request erasure of your data (also known as the right to be forgotten).

(2) However, there are a range of exceptions to this, which mean that we do not have to erase your data if there are good reasons for retaining a copy of it.

(3) See Article 17 of the UK GDPR.

Right to restriction

(1) You have the right to request that we stop using your data for some purposes.

(2) There are conditions that apply.

(3) This means that we might still hold your data, but we would be stopped from using it for certain purposes.

(4) See Article 18 of the UK GDPR.

Right to object to legitimate interests

(1) If the legal basis for our using your personal data is a "legitimate interest", or we are using your data to market to you, then you can object to the processing.

(2) See Article 21 of the UK GDPR.

(3) We must stop the processing, unless we can show that our interests should take precedence over yours.

Automated Decision Making

(1) If we are making important decisions about using a compute, without any human involvement, then you can ask us to stop, subject to conditions.

(2) See Article 22 of the UK GDPR.

Right to complain

(1) We hope that our head of human resources and data protection officer can resolve any quey or concern you have about our use of your personal data or your rights.

(2) In any case, you have the right to complain to the Information Commissioner at any time.

(3) Their details are: (a) Address - Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF; (b) Helpline number - 0303 123 1113; (c) ICO website - https://ico.org.uk/make-a-complaint/

 

13. USEFUL LINKS

Air Table

An online database system we use to manage staff system access rights records.

https://www.airtable.com/product

Cezanne HR

Our employee management system.

https://cezannehr.com/

Cezanne HR Hosting

Hosting information.

https://cezannehr.com/hr-systems/hosting-updates/

Cezanne Recruitment

Our recruitment system.

https://cezannehr.com/hr-systems/recruitment/

Data Protection Act 2018

Contains additional rules to support the UK GDPR.

https://www.legislation.gov.uk/ukpga/2018/12/contents/enacted

ENSEK Ltd

The processor of your data.

https://ensek.com/

Expensify

Our staff expenses management system.

https://www.expensify.com/

Expensify | Hosting

Expensify hosting information.

https://community.expensify.com/discussion/4066/hosting-country-for-expensify-software-and-data

Expensify | Privacy

Expensify privacy information.

https://use.expensify.com/privacy

Expensify | Processors

Sub-processors used by expensify.

https://use.expensify.com/subprocessors

ICO | Complaints Page

Page for making a complaint to the ICO.

https://ico.org.uk/make-a-complaint/

ICO | Your Rights

ICO page on your rights.

https://ico.org.uk/your-data-matters/

Information Commissioners Office (ICO)

The UK regulator of privacy laws.

https://ico.org.uk/for-organisations/sme-web-hub/make-your-own-privacy-notice/

ISO 27001

International security controls standard.

https://www.iso.org/isoiec-27001-information-security.html

ISO 27701

International personal data management controls standard.

https://www.iso.org/isoiec-27001-information-security.html

Limitation Act 1980

Legal limitation periods for bringing a claim in court.

https://www.legislation.gov.uk/ukpga/1980/58/contents

Microsoft 365

Our back office business tools for email, messaging, calling, and file creation, storage and editing.

https://docs.microsoft.com/en-us/microsoft-365/enterprise/o365-data-locations?view=o365-worldwide

Omniplex Learning

A training system of the Lloyds group for security and any other training that our investors require our employees to take.

https://omniplexlearning.docebosaas.com/learn

Sage

Our new finance system, from March 2023.

https://www.sage.com/en-gb/

SOC (Service Organisation Controls)

Auditing standard for auditing of security and operational controls.

https://en.wikipedia.org/wiki/ISAE_3402

Thrive Learning

Providers of our employee training system from 1st January 2023.

https://www.thrivelearning.com/

UK GDPR

The UK's copy of the GDPR following BREXIT.

https://www.legislation.gov.uk/eur/2016/679/contents

UK GDPR | Article 13

The provision of the GDPR requiring this notice.

https://www.legislation.gov.uk/eur/2016/679/article/13

UK GDPR | Article 14

The provision of the GDPR requiring this notice.

https://www.legislation.gov.uk/eur/2016/679/article/14

UK GDPR | Data Protection Principles

The fundamental rules we have to follow when processing your data.

https://www.legislation.gov.uk/eur/2016/679/article/5

UK GDPR | Lawful Basis

We must satisfy one of the grounds in this article to be able to process your data.

https://www.legislation.gov.uk/eur/2016/679/article/6

XERO

Our old finance system, replaced in March 2023.

https://www.xero.com/uk/

 

END OF NOTICE