Applicant Privacy Notice
1. Introduction 1.1 This privacy notice describes how we CDP Europe (
CDP Worldwide (Europe) gGmbH & CDP Europe - Services GmbH) collect and use personal information we receive from you during the recruitment process and applies to all applicants.
1.2 CDP Europe is a “data controller”. This means that we are responsible for deciding how we hold and use your data. We are required under data protection legislation to notify you of this under this privacy notice.
1.3 As part of our recruitment process, we collect and process personal information from applicants.
1.4 Your privacy and the handling of your confidential information is important to us. This privacy notice describes how we will use your personal information when you apply for a role with us.
2. Personal Information 2.1 To manage your application, we need to process certain personal information about you. We only process your personal data necessary for the purposes of progressing your application or as required by law or regulatory requirements.
2.2 The personal information we collect may include:
2.2.1 your name, address and contact details, including email address and telephone number;
2.2.2 details of your qualifications, skills, experience and employment history; and
2.2.3 your entitlement to work in the country where the role is based.
2.3 We may collect this data in a variety of ways. For example, it might be contained in CVs, obtained from your passport or other identity documents, or collected through interviews or other forms of assessment.
2.4 We may also collect data about you in the form of references supplied by former employers. We will seek such data once a job offer has been made and your consent has been obtained.
2.5 Your data will be stored in your personnel file, the HR personal data system, and our secure IT systems.
3. Personal information 3.1 The personal information we obtain in relation to your application will be used by us to consider your suitability for employment.
3.2 We need to process your data to ensure we comply with our legal obligations. For example, we are required to check a successful applicant’s eligibility to work in the country where the job is based before employment starts.
3.3 We have a legitimate interest in processing your data during the recruitment process and for keeping records. Processing personal information from job applicants allows us to manage the recruitment process, assess and confirm a candidate’s suitability for employment and decide to whom to offer a job.
3.4 We will not use your data for any purpose other than the recruitment exercise for which you have applied.
4. Personal information disclosure 4.1 Your personal information may be shared internally for the recruitment exercise. This includes members of the HR team, interviewers involved in the recruitment process, managers in the business area with a vacancy and IT staff who manage user access.
4.2 We will not share your data with third parties unless your application for employment is successful and we make you an offer of employment.
4.3 Where appropriate, your data may be disclosed to law enforcement, regulatory or other government agencies, or third parties where necessary or desirable to comply with legal or regulatory obligations or requests.
5. Data security 5.1 We take the security of your personal information seriously. We have controls in place to ensure that your data is not lost, accidentally destroyed, misused or disclosed, and is not accessed except by our employees in the proper performance of their duties.
6. Data retention 6.1 If your application for employment is unsuccessful, your personal information will be retained for up to 6 months and will be securely deleted or destroyed once this date has passed.
6.2 If your application for employment is successful, your data gathered during the recruitment process will be transferred to your personnel file and retained during your employment.
7. Your rights 7.1 As the data subject, you can:
7.1.1 access and obtain a copy of your data on request;
7.1.2 require us to change incorrect or incomplete data;
7.1.3 require us to delete or stop processing your data, for example where the data is no longer necessary for the purposes of processing; and
7.1.4 object to the processing of your personal data where we are relying on legitimate interest as the legal ground for processing.
7.2 If you would like to exercise any of these rights, please email recruitment.cdpeuropeg@cdp.net.
7.3 If you believe that we have not complied with your data rights, you can raise your concerns with the Information Commissioner’s Office (ICO) or your national data protection supervisory authority.
7.4 You are under no statutory or contractual obligation to provide us with your personal information during the recruitment process. However, if you do not provide this data, we may not be able to process your application properly or at all.
7.5 Please note that we reserve the right to modify this privacy notice at any time. We will promptly reflect any such modifications so that you are always kept informed of how we collect and use your data.
Berlin, May 23rd, 2018Processing of (personal) data by the operator of the recruitment website
General information
This recruitment website is operated by Personio SE & Co. KG, which offers a human resource and candidate management software solution (
https://www.personio.com/legal-notice/).
Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. The sole controller of this data within the meaning of article 24 of the GDPR is the enterprise carrying out this online application process. Personio’s role is limited to operating the software and this recruitment website and, in this context, being a processor under article 28 of the GDPR. In this case, the processing by Personio is based on an agreement for the processing of orders between the controller and Personio.
In addition, Personio SE & Co. KG processes further data, some of which may be personal data, to provide its services, in particular for operating this recruitment website. We will refer to this in more detail below.
The controller
The controller under data protection law is:
Personio SE & Co. KG
Seidlstraße 3
80335 München
Tel.: +49 (89) 1250 1004
Entry in the commercial register
Commercial register entry number: HRA 115934
Registration Court: Amtsgericht München
Data Protection Officer contact:
privacy@personio.com
Access logs (“server logs”)
Each access to this recruitment website automatically causes general protocol data, so-called server logs, to be collected. As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual.
Without this data, it would, in some cases, be technically impossible to deliver or display the contents of the software. In addition, processing this data is absolutely necessary under security aspects, in particular for access, input, transfer, and storage control. Furthermore, this anonymous information can be used for statistical purposes and for optimizing services and technology. In addition, the log files can be checked and analyzed retrospectively when unlawful use of the software is suspected. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG.
Generally, data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp of the access to the software is collected. The scope of this log process does not exceed the common log scope of any other site on the web.
These access logs are stored for a period of up to 7 days. There is no right to object to this.
Error logs
So-called error logs are generated for the purpose of identifying and fixing bugs. This is absolutely necessary to ensure we can react as quickly as possible to possible problems with displaying and implementing content (legitimate interest). As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG.
When an error message occurs, general data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp upon occurrence of the respective error message and/or specification is collected.
These error logs are stored for a period of up to 7 days. There is no right to object to this.
Use of cookies
So-called cookies are used on parts of this recruitment website. They are small text files which are stored on the device with which you access this recruitment website. As a general rule, cookies serve the purpose of ensuring secure access to a website (“absolutely necessary”), implementing certain functionalities such as standard-language settings (“functional”), improving the user experience or the performance of the website (“performance”), or placing targeted advertisements (“marketing”).
On this recruitment website, we generally use only cookies that are absolutely necessary, functional or performance-related, in particular for implementing certain default settings such as language, for identifying the job advertising channel, or for analyzing the performance of a job advert via which a user accessed this recruitment website. The use of cookies is absolutely necessary for providing our services and thus for the performance of the contract (article 6 (1) b) of the GDPR).
Period of storage: up to 1 month or until the end of the browser session
Right to object: You can determine via your browser settings whether you allow or object to the use of cookies. Please note that deactivating cookies may result in limited or completely blocked functionalities of this recruitment website.
Rights of data subjects
If Personio SE & Co. KG as the controller processes personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular the right of access (article 15 of the GDPR) and the rights to rectification (article 16 of the GDPR), erasure (article 17 of the GDPR), restriction of processing (article 18 of the GDPR), and data portability (article 20 of the GDPR), as well as the right to object (article 21 of the GDPR). If the personal data is processed with your consent, you have the right to withdraw this consent under article 7 III of the GDPR.
To assert your rights as a data subject in relation to the data processed for the purpose of operating this recruitment website, please refer to Personio SE & Co. KG’s Data Protection Officer (see item B).
Concluding provisions
Personio reserves the right to adjust this data privacy statement at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the services offered, for example when new services are introduced. In this case, the new data privacy statement applies to any later visit of this recruitment website or any later job application.