Processing of (personal) data by the entity in charge of the online application process
This template is provided for guidance purposes only and, therefore, may not fully reflect the specific characteristics of your organisation (industry, organisational structure, legal framework, etc.). We therefore recommend that you review it carefully and complete any missing information.
1. General Information
This data protection statement applies exclusively to data collected as part of the online recruitment process and includes information regarding the processing of applicants’ personal data collected throughout that process.
2. Data Controller
The data controller for the purposes of data protection law is:
[Company name and legal form]
[Company address]
Tel.: [Telephone number]
Commercial Register Registration
Registration Number: [Registration number]
Registering Court: [Name of the registering court]
Data Protection Officer: [Name and contact details of the Data Protection Officer, where applicable]
3. Processing of Personal Data During the Recruitment Process
Personal data means any information relating to an identified or identifiable natural person, such as name, address, telephone number and date of birth, as well as information relating to education, qualifications, or similar details that can reasonably be attributed to a specific individual. Any information that cannot be used to identify a person, either directly or indirectly, does not constitute personal data.
4. Principles and Purposes of the Processing of Personal Data in Relation to Applications and the Recruitment Process
When an application is submitted electronically, whether by email or via our online application form, the applicant’s personal data is collected and processed for the purpose of managing and administering the recruitment process and implementing any relevant pre-contractual measures.
By submitting an application through our recruitment page, the applicant explicitly expresses an interest in working with us. Any personal data provided in this context will be used and retained solely for recruitment and hiring purposes.
In particular, we may collect the following information:
- Full name
- Email address
- Telephone number
- LinkedIn profile (optional)
- The channel through which the applicant became aware of us
During the recruitment process, applicants may also upload relevant documents, such as a cover letter, CV, and qualifications, which may contain personal data including date of birth, address, and similar information.
Only authorised Human Resources employees or employees directly involved in the recruitment process will have access to the applicant’s data.
Personal data will be stored exclusively for the purpose of filling the vacancy for which the application has been submitted.
Applicant data will be retained for a period of [number] days following the conclusion of the recruitment process for compliance with legal obligations or the defence of potential claims. Thereafter, we are required to delete or anonymise such data. From that point onwards, data will only be retained in the form of metadata without any direct personal reference for statistical purposes (e.g., the percentage of male and female applicants, number of applications received during a given period, etc.).
In addition, we reserve the right to retain applicant data within our talent pool for [number] days following the conclusion of the recruitment process, in order to identify other opportunities that may be of interest to the applicant. This also applies, for example, to applications for internships or training placements. By accepting the privacy policy, the applicant expressly consents to the potential retention of their data for a longer period and inclusion within our talent pool.
Where an applicant receives and accepts an offer of employment during the recruitment process, the personal data collected as part of the recruitment process will be retained, at a minimum, for the duration of the employment relationship.
5. Disclosure of Data to Third Parties
Data submitted as part of an application is transmitted using TLS encryption and stored in a database. This database is operated by Personio, which provides recruitment and human resources management software (Personio Legal Notice).
In this context, Personio acts as our data processor in accordance with Article 28 of the UK GDPR / GDPR. The legal basis for such processing is the execution of the Data Processing Agreement (DPA) entered into between ourselves, as data controller, and Personio.
6. Data Subject Rights
Where we, as the data controller, process personal data, applicants, as data subjects, are entitled to certain rights under Chapter III of the GDPR, depending on the legal basis and purpose of the processing. These include, in particular, the right of access (Article 15 GDPR), right to rectification (Article 16 GDPR), right to erasure (Article 17 GDPR), right to restriction of processing (Article 18 GDPR), right to data portability (Article 20 GDPR), and right to object (Article 21 GDPR).
Where the processing of personal data is based on consent, pursuant to Article 7(3) GDPR, applicants have the right to withdraw their consent at any time.
To exercise any of their rights as data subjects in relation to the processing of data during the online recruitment process, applicants should contact the Data Protection Officer (see section 2).
7. Final Provisions
We reserve the right to amend this data protection statement at any time in order to comply with applicable legal requirements or to reflect changes made to the recruitment process or other comparable procedures. In such cases, should the applicant revisit this recruitment page or submit a new application, the updated data protection statement shall apply.
In addition to this data protection statement, applicants may consult our Privacy Policy at [link to your own privacy policy].