Introduction
We are RAW RESOURCING LTD (Registered in England & Wales No. 15132024 ) of 63-66 Hatton Garden, London, EC1N 8LE
This Privacy Notice sets out the basis on which we use personal data in the course of our business activities.
As a business which relies upon having access to information about Candidates to meet our Clients’ requirements, data is essential to our business. Our systems and processes are designed to ensure that we can provide the best possible service to our clients while operating within the law at all times and protecting individuals’ data privacy rights.
We reserve the right to update this Privacy Notice from time to time. Where appropriate, we shall contact you to notify you of any material changes to the Privacy Notice. You should also refer to our website periodically so that you may access and view our updated Privacy Notice. This will ensure that you understand (i) how we are using your personal data and (ii) your legal rights around our usage of such personal data.
Who Should Read This Privacy Notice?
This Privacy Notice applies to any living, identifiable individuals about whom we may process personal data in the course of our business activities. You should read this Privacy Notice if you are a:
Please note that, in some cases, you will fall into more than one of the above categories.
If you are an employee, applicant for employment or in-house temporary worker, you should refer to our internal Privacy Notice instead.
Definitions
This Privacy Notice uses the following defined terms:
Candidate means a person who is recorded in RAW RESOURCING LTD’s records as seeking or potentially suitable for an engagement with a Client. This includes individuals who are not actively seeking a new role but who are in contact with RAW RESOURCING LTD about potential opportunities which may be of interest from time to time.
Client means a business which has engaged RAW RESOURCING LTD to provide services or which RAW RESOURCING LTD has identified as a business for which RAW RESOURCING LTD wishes to perform services.
Client Contact means a person who is employed or engaged by a Client and with whom RAW RESOURCING LTD may liaise in respect of any services which RAW RESOURCING LTD is providing or wishes to provide to the Client. In some cases, the Client Contact and the Client may be the same person e.g. where a Client is a sole trader.
Data Protection Legislation means (i) the General Data Protection Regulation ((EU) 2016/679) and any national implementing laws, regulations and secondary legislation, as amended or updated from time to time, in the UK and then (ii) any successor legislation to the GDPR or the Data Protection Act 1998.
Referee means a person who has provided to RAW RESOURCING LTD a written or verbal opinion in respect of the work history, skills, competency and/or experience of a Candidate;
Supplier means a business which provides services to RAW RESOURCING LTD and which may process personal data relating to any Candidate, Client Contact or Supplier Representative in the course of performing such services.
Supplier Representative means a person who is employed or engaged by a Supplier and with whom RAW RESOURCING LTD may liaise from time to time in respect of the services which are provided by that Supplier.
Third-Party Services Provider means any relevant third-party business which provides services to RAW RESOURCING LTD, including our:
How We Obtain Personal Data
We obtain personal data from a number of different sources, depending on the capacity in which you are dealing with us.
If you are a Candidate, we may obtain personal data relating to you:
If you are a Client Contact or Supplier Representative, we may obtain personal data relating to you:
If you are a Referee, we may obtain personal data relating to you:
Types of Information We Hold
If you are a Candidate, we may collect, store and process the following types of personal information about you:
We may also collect, store and use the following “special categories” of more sensitive personal information:
If you are a Client Contact, we will collect, store, and use the following categories of personal information about you:
We do not collect, store or use any “special categories” of sensitive personal information if you are a Client Contact.
If you are a Referee, we will collect, store, and use the following categories of personal information about you:
We do not collect, store or use any “special categories” of sensitive personal information if you are a Referee.
If you are a Supplier Representative, we will collect, store, and use the following categories of personal information about you:
We do not collect, store or use any “special categories” of sensitive personal information if you are a Supplier Representative.
How We Use Personal Data
If you are a Candidate, we may use your personal data to:
If you are a Client Contact, we may use your personal data to:
If you are a Referee, we may use your personal data to:
If you are a Supplier Representative, we may use your personal data to:
Our Lawful Basis for Processing Data
We have determined that we have a legitimate interest to process your personal data where you are:
Our Lawful Basis for Processing Sensitive Personal Data
[If you are a Candidate, we may also need to process sensitive personal data relating to you. In this event, we will ask for your consent to process this type of data. You are free to decline such consent but it may affect the scope of the services which we can provide to you and the roles for which you may be submitted.]
OR
[If you are a Candidate, we may also need to process sensitive (special) personal data relating to you. The type of sensitive personal data which we might process includes (i) information about any medical conditions or disability insofar as they are relevant to the type of work which you are proposing to carry out (ii) information about any unspent criminal convictions and, where relevant to the type of role which you are carrying out, spent convictions, police warnings etc and (iii) information about any trade union of which you are a member (but only insofar as it relates to an employment claim or pay and working conditions on a client site).
[We are acting as an employment agency and/or an employment business in our dealings with you. In accordance with Article 9 (2)(b) of the GDPR, this sensitive personal data is necessary in the field of employment. i.e. it is required for performing our obligations as an employment agency or employment business and is used solely for this purpose. Any sensitive personal data shall be held strictly in accordance with our policies on data retention and sensitive personal data.
We may also process equal opportunities information relating to you. This shall be anonymised and it is not therefore personal data within the meaning of the Data Protection Legislation.]
Where We Process Personal Data
Your personal data is held and processed by us in the United Kingdom.
We have put in place appropriate safeguards to ensure that your data is only transferred to jurisdictions with enforceable data subject rights and effective legal remedies in respect of data privacy breaches. We will therefore only transfer your personal data to jurisdictions outside of the EEA where:
Parties with Whom We May Share Data
If you are a Candidate, we may share your personal data for legitimate purposes with:
We may also share your personal data with Clients on an anonymised basis where we have agreed to provide general statistical information to such Clients.
If you are a Client Contact, we may share very limited data relating to you with a Candidate where such sharing is strictly required for the recruitment process e.g. so that the Candidate may contact you directly. We will also share your personal data with Third-Party Services Providers for legitimate business purposes.
If you are a Referee, we will share with our Clients the details of any reference which you may give. We will usually provide your name, job title and employer name when doing so. In some circumstances and only when you have agreed to such disclosure, we will provide your contact details so that our Client may verify the reference or ask for further information. We will also share your personal data with Third-Party Services Providers for legitimate business purposes.
If you are a Supplier Representative, we will share your personal data with other Third-Party Services Providers for legitimate business purposes.
Our Website
If you interact with our website at www.rawresourcing.com, we may process information relating to your usage of the website. However, unless you are submitting information through our website as a Candidate or Client Contact, the information which we process is anonymised and not therefore personal data within the meaning of the Data Protection Legislation.
Automated Decision Making
Automated decision-making takes place when an electronic system uses personal information to make a decision without human intervention.
All decisions which are made in the course of our business processes involve human intervention. We do not therefore expect to make any decisions about you using automated means, whether you are a Candidate, Client Contact, Referee or Supplier Representative.
Data Security
We have put in place appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal information to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal information on our instructions and they are subject to a duty of confidentiality. Details of these measures may be obtained from the Data Protection Manager.
We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.
Data Retention
We will only retain your personal information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
Our standard data retention period is two years from the last date on which we are in actual contact with you i.e. where we actually speak with you or exchange correspondence. After this time, we will usually delete your personal data from our records.
Where we are required to keep any information (i) for auditing or compliance purposes (ii) to comply with our contractual obligations to third parties or (iii) in respect of any potential or actual legal proceedings, we shall keep your data for as long as is strictly necessary for these purposes, which is typically for seven years in total. This usually applies in particular to Candidates who we have placed with Clients.
In some circumstances we may completely anonymise your personal information so that it can no longer be associated with you, in which case we may use such information without further notice to you.
Rights of access, correction, erasure, and restriction
Your duty to inform us of changes. It is important that the personal information we hold about you is accurate and current. Please keep us informed if your personal information changes during your working relationship with us.
Your rights in connection with personal information. Under certain circumstances, you have the right to:
If you want to exercise any of the above rights, please contact the Data Protection Manager in writing. We will consider your request and confirm the actions which we have taken in response to such request.
We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is an appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.
In the limited circumstances where you may have provided your consent to the collection, processing and transfer of your personal information for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. To withdraw your consent, please contact the Data Protection Manager. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law. We will confirm the actions which we have taken in respect of any such request.
If you are unhappy with any aspect of the manner in which we have processed your personal data or dealt with your decision to exercise any of the rights set out in this section, you have the right to complain to the Information Commissioners Office in the United Kingdom. Their details are:
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Tel: 0303 123 1113 (local rate) or 01625 545 745
Email: casework@ico.org.uk
Contacting Us
If you have any questions about this Privacy Notice, you can write to the Data Protection Managerat RAW RESOURCING LTD, ADDRESS. Alternatively, you may telephone us on 07 946 390 098 or email us at info@rawresourcing.com.
You should be specific about the job boards which you use, if any.
This is a possible justification. The company could also choose to use consent or performance of a contract, depending upon their preferences. This point requires advice.
Assumes no international data transfers as standard.
If applicable
You should also have a cookie policy on your website. This has been a requirement for several years so is not a new GDPR-related issue. However, you should check that there is one present.
Do you capture the IP address of all visitors? If so, this would be personal data and this will need to be amended
This is open to discussion. 1-3 years are all common.
Where I have referred to a Data Protection Manager, this could be amended to any other suitable job title.
SUBJECT ACCESS REQUEST PROCEDURE
About This Procedure
This Subject Access Request Procedure sets out RAW RESOURCING LTD . ’s procedures in relation to any Subject Access Request which RAW RESOURCING LTD may receive from a Data Subject.
The Data Protection Manager (DPM) is responsible for overseeing this procedure. Any questions about the operation of this procedure should be submitted to the DPM.
Receiving A Request
Data Subjects have the right to request access to their personal data processed by RAW RESOURCING LTD. Such requests are called subject access requests (SARs).
When a Data Subject makes an SAR, RAW RESOURCING LTD shall take the following steps:
(a) log the date on which the request was received (to ensure that the relevant timeframe of one month for responding to the request is met);
(b) confirm the identity of the Data Subject who is the subject of the personal data. For example, RAW RESOURCING LTD may request additional information from the Data Subject to confirm their identity;
(c) search databases, systems, applications and other places where the personal data which are the subject of the request may be held; and
(d) confirm to the Data Subject whether or not personal data of the Data Subject making the SAR are being processed.
Charges
RAW RESOURCING LTD shall not usually charge a fee to the Data Subject for carrying out a SAR (i.e. as the previous statutory £10 fee is no longer in force.)
If the SAR is manifestly unfounded or excessive, for example, because of its repetitive character, RAW RESOURCING LTD may charge a reasonable fee, taking into account the administrative costs of providing the personal data.
Provision of Information
If personal data of the Data Subject are being processed, RAW RESOURCING LTD shall provide the Data Subject with the following information in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in writing or by other (including electronic) means:
(a) the purposes of the processing;
(b) the categories of personal data concerned (for example, contact details, bank account information and details of sales activity);
(c) the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients overseas (for example, US-based service providers);
(d) where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
(e) the existence of the right to request rectification or erasure of personal data or restriction of processing of personal data or to object to such processing;
(f) the right to lodge a complaint with the Information Commissioner’s Office (ICO);
(g) where the personal data are not collected from the Data Subject, any available information as to their source;
(h) the existence of automated decision-making and meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the Data Subject; and
(i) where personal data are transferred outside the EU, details of the appropriate safeguards to protect the personal data.
RAW RESOURCING LTD shall also, unless there is an exemption, provide the Data Subject with a copy of the personal data processed by RAW RESOURCING LTD . in a commonly used electronic form e.g. PDF documents, unless the Data Subject either did not make the request by electronic means or has specifically requested not to be provided with the copy in electronic form. RAW RESOURCING LTD . shall usually submit the data to the Data Subject within one monthof receipt of the request.
Before providing the personal data to the Data Subject making the SAR, RAW RESOURCING LTD shall review the personal data requested to see if they contain the personal data of other Data Subjects. If they do, RAW RESOURCING LTD . may redact the personal data of those other Data Subjects prior to providing the Data Subject with their personal data, unless those other Data Subjects have consented to the disclosure of their personal data.
Extending the Time to Respond
If the request is complex, or there are a number of requests, RAW RESOURCING LTD may extend the period for responding by a further two months. If RAW RESOURCING LTD extend the period for responding RAW RESOURCING LTD shall inform the Data Subject within one month of receipt of the request and explain the reason(s) for the delay.
Refusing A Request
If the SAR is manifestly unfounded or excessive, for example, because of its repetitive character, RAW RESOURCING LTD may refuse to act on the request.
If RAW RESOURCING LTD is not going to respond to the SAR, RAW RESOURCING LTD . shall inform the Data Subject of the reason(s) for not taking action and of the possibility of lodging a complaint with the ICO.
Find and replace Company with the actual business name
Amend as appropriate
Data Retention & Erasure Policy (External)
About This Policy
This Data Retention & Erasure Policy (External) relates specifically to Candidates, Referees, Client Contacts and Supplier Representatives (Data Subjects).
For information about data retention relating to Applicants and Employees, you should refer to our Data Retention Policy (Internal) which may be viewed at URL.
The policy is intended to ensure that RAW RESOURCING LTD processes its business records in accordance with the personal data protection principles, in particular that:
The Data Protection Manager (DPM) is responsible for overseeing this policy. Any questions about the operation of this policy should be submitted to the DPM.
Location of Business Records
Our business records are mainly stored within our CRM/database, NAME. We may also store relevant information:
– On our internal network in shared folders;
– In cloud-based storage services such as OneDrive and Dropbox.
Keeping Information Up To Date
RAW RESOURCING LTD needs to ensure that our business records are kept up to date and accurate. Our employees are trained to update Data Subjects’ records whenever appropriate to ensure that (i) the data is up to date and (ii) all relevant employees are able to access and use such data for legitimate business purposes.
General Principles on Retention & Erasure
RAW RESOURCING LTD’s approach to retaining business records is to ensure that it complies with the data protection principles referred to in this policy and, in particular, to ensure that:
Standard Retention & Erasure of Business Records
Erasure/Right To Be Forgotten Requests
A Data Subject may submit a request for erasure of their details from time to time (Erasure Request) i.e. the right to be forgotten.
Upon receipt of an Erasure Request, RAW RESOURCING LTD shall first verify the identity of the Data Subject and then establish whether the Data Subject wishes (1) to be entirely deleted from RAW RESOURCING LTD’s business records or (2) to remain within the RAW RESOURCING LTD’s business records but marked as Non-Active or Do Not Contact.
(1) Erasure. If the Data Subject wishes to have their personal data erased:
(2) Do Not Contact. If the Data Subject wishes to have their record marked as Do Not Contact:
User should find and replace all instances of Company with the actual business name.
Or as appropriate. This should mirror the Job Title specified in the Internal Privacy Notice
These are typical examples. Business should consider where and how data is stored as part of the usual GDPR data mapping process.
This is relatively uncommon but the business should be aware of this and potentially retain any relevant data for this longer limitation period where applicable.
Unless it is possible for data to be stored away from the main database in a secure manner e.g. in an encrypted data backup. In that event, it may be possible to delete from the CRM, provided that this does not corrupt any other records which are dependent upon the Data Subject’s data record.
Or as appropriate, depending on the terminology used
Or as appropriate, depending on the business terminology
Subject to any technical process which the Agency may have to prevent this happening.
In most circumstances, there will not be a joint data controller. The Data Subject would need to make the erasure request to each independent Data Controller separately. i.e. the agency does not have the power to instruct clients/MSPs to delete the data unless they are processing on behalf of the agency. Usually, any such third party will be a controller in their own right.
WHAT ARE COOKIES?
Cookies are small text files containing a string of characters that can be placed on your computer or mobile device that uniquely identify your browser or device. What are cookies used for?
Cookies allow a site or services to know if your computer or device has visited that site or service before. Cookies can then be used to help understand how the site or service is being used, help you navigate between pages efficiently, help remember your preferences, and generally improve your browsing experience. Cookies can also help ensure marketing you see online is more relevant to you and your interests.
WHAT TYPES OF COOKIES DOES RAW RESOURCING USE?
There are generally four categories of cookies: “Strictly Necessary,” “Performance,” “Functionality,” and “Targeting.” RAW RESOURCING routinely uses all four categories of cookies on the Service. You can find out more about each cookie category below.
Copyright © 2024 RAW Resourcing - All Rights Reserved.
Powered by GoDaddy