Professional Documents
Culture Documents
Candidate Privacy Notice
Candidate Privacy Notice
Owen Mumford Limited (we or us) are committed to protecting the privacy and security of your personal
information. This privacy notice describes how we collect and use personal information about candidates during
our recruitment processes, in accordance with the General Data Protection Regulation (GDPR).1
We are a data controller. This means that we are responsible for deciding how we hold and use personal information
about you. You are provided with a copy of this privacy notice because you are applying for work with us (whether as
an employee, worker or contractor) and because we are required by GDPR to provide to you the information contained
in this notice. It makes you aware of how and why your personal data will be used by us for the purposes of our
recruitment exercise, and how long it will usually be retained for.
In connection with your application, we will hold and use the following categories of personal information about you:
the information you have provided to us in your curriculum vitae and covering letter, and in any application
form. This would usually include name, title, address, telephone number, personal email address, date of
birth, employment history, and qualifications; and
any information you provide to us during an interview or during the recruitment process. In some cases we
may conduct and record interviews remotely, in which case we may retain a video or audio recording of the
interview; and
depending on your role, and at a later stage in the application process, we may receive information connected
with relevant checks, such as ID and right-to-work checks or vehicle licensing checks.
We may also hold and use "special categories" of more sensitive personal information relating to your health.
However, we will not ask you any questions about your health unless they are necessary to determine whether we
should make reasonable adjustments to the assessment process or are necessary to determine whether you can carry
out an intrinsic function of the role (for example, heavy lifting). We may ask you questions relating to your health after
your application is successful (i.e. if we offer you the role or if we place you in a limited pool of successful applicants
from whom we intend to fill the role).
1
GDPR is European law but was translated into UK law under the UK’s Data Protection Act and European Union
Withdrawal Act, as modified by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU
Exit) Regulations 2019, creating the “UK GDPR”. For simplicity’s sake, we just refer to GDPR.
Under GDPR we are required to identify the lawful basis on which we process your personal data. We process the
personal data described above primarily on three lawful bases: in anticipation of entering into a contract with you; to
enable us to comply with legal obligations; and to pursue legitimate interests. For example, it is in our legitimate
interests to decide whether to appoint you to a given role since it benefits our business to fill that role.
We will use your CV and any information provided before interview to decide whether your application is strong
enough to invite you for an interview. If we decide to call you for an interview, we will use the information you provide
to us at the interview, as well as the information provided before interview, to decide whether to offer you the role. If
we decide to offer you the role, we will then take up references, conduct other checks and, depending on the role, ask
you for health-related information, before confirming your appointment.
If you fail to provide information when requested, which is necessary for us to consider your application (such as
evidence of right-to-work, qualifications or work history), we will not be able to process your application successfully.
We will use your health information to consider whether we need to provide appropriate adjustments during the
recruitment process, and to ensure you meet any physical requirements which are intrinsic to the role.
Automated decision-making
You will not be subject to decisions that will have a significant impact on you based solely on automated decision-
making.
Data sharing
We will only share your personal information with limited third parties for the purposes of processing your application
(such as providers of hosted services on which we store recruitment information). All our data processors are required
to take appropriate security measures to protect your personal information. We do not allow our data processors to
use your personal data for their own purposes. We only permit them to process your personal data for specified
purposes and in accordance with our instructions. We may also report back to whichever recruiter referred you to us in
order to provide them with feedback.
Data security
We have put in place appropriate security measures to prevent your personal information from being accidentally lost,
used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal information
to those employees, agents, contractors and other third parties who have a business need-to-know. They will only
process your personal information on our instructions, and they are subject to a duty of confidentiality. We have put in
place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a
suspected breach where we are legally required to do so.
If your application is unsuccessful, we will retain your personal information for the retention period confirmed by you
(or otherwise up to a maximum of six (6) months after recruitment has ended). We retain your personal information for
that period so that we can show, in the event of a legal claim, that we have not discriminated against candidates on
prohibited grounds and that we have conducted the recruitment exercise in a fair and transparent way. After this
period, we will securely destroy your personal information in accordance with our data retention policy.
If we wish to retain your personal information on file, on the basis that a further opportunity may arise in future and we
may wish to consider you for that, please let us know.
If your application is successful, then your personal information will be stored in your personnel file. We will provide
you with a further privacy notice setting out the ongoing uses of, and period of retention of, your personal data in
relation to your employment.
If you have any questions about this privacy notice or how we handle your personal information, or which to exercise
any of the rights set out above, please contact us at info@owenmumford.com. You have the right to make a
complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data
protection issues.