GDPR Guidline and responsibilities
GDPR-managers in Team tailor are:
GDPR- Manager responsibilities
GDPR Manager shall:
- Understand and act on the internal deletion routines in Teamtailor;
- Oversee how many missing permissions, deletion requests, upcoming outdated permissions and upcoming deletions are on the account in Teamtailor. Check and make sure that the that the candidates are deleted correctly and accordingly to this Guideline
- Take action when candidates send in deletion requests - See this Guideline to know when you shall delete candidate data according to country specific standard;
- Take action when there are expired permissions – see this Guideline to know when candidates shall be deleted according to country specific standard;
- Inform other recruiters in your country about their responsibilities, make sure new team members know about our GDPR principles and routines. Re-inform recruiters once a year about GDPR routines and their responsibilities working with candidates’ personal data;
- Support, advise and help to other recruiters in your country when they face questions or situations with candidates’ personal data in Teamtailor;
- Escalate Privacy issues/questions to Group HR & Infrastructure Privacy Manager. Inform other GDPR Managers about risks and/or questions.
- If other countries GDPR Manager informs you about risks, situation and/or questions they face, take action and check if the situation impacts local account. If needed, inform your local Privacy Manager about the situation;
- If something is not correct in this Guideline, escalate this issue to Group HR & Infrastructure Privacy Manager;
- Apart from the responsibilities as GDPR Manager, remember to follow the Recruiter responsibilities on next part as well.
Recruiter responsibilities
Recruiter shall:
- Understand internal deletion routines in Teamtailor;
- Minimize the use of personal data outside Teamtailor, e.g. do not send CV via email, link to candidate card in Teamtailor instead
- Before starting to process added or referred candidates, make sure that candidate has confirmed permission;
- Not delete candidate in Teamtailor - only GDPR Manager may do that;
- Always involve GDPR Manager if you want to send multiple candidates vacancies or other e-mails of activities;
- When candidate have not given consent for future job opportunity, do not process that candidate in other recruitment processes;
- Inform Hiring Managers you work with about their responsibilities in Teamtailor and working with candidates’ personal data Inform or remind Hiring manager about their GDPR responsibilities in a recruitment process;
- If you receive candidate application via e-mail (either directly or through Hiring Manager), before application deadline, contact the candidate and kindly ask them to use Teamtailor to apply. Delete CV you received via e-mail and ask Hiring Manager to do the same;
- If you receive candidate application via e-mail (either directly or through Hiring Manager), after application deadline, add the candidate to the system yourself and inform candidate to give consent to processing his personal data. (as they might miss this info). Delete CV you received and ask Hiring Manager to do the same. Delete CV from your computer if it is been saved there; Before you continue to process added candidate in the recruitment process, check if the consent by the candidate is received;
- Escalate Privacy issues/questions to local Teamtailor GDPR Manager.
Hiring Manager responsibilities
Hiring Manager shall:
- Understand GDPR Guidelines in Teamtailor;
- Minimize the use of personal data outside Teamtailor, e.g. do not send CV through e-mail, link to candidate card in Teamtailor instead;
- Keep notes about candidate in Teamtailor using Notes section in Candidate card. Be professional when you leave comments about candidates;
- If CV is received in your e-mail, if recruitment project is active, ask the candidate to apply through Teamtailor, send candidate the link for the project and delete received CV in your e-mail afterwards. If recruitment project has expired and you decide to accept the candidate’s application, add the candidate in Teamtailor and delete CV from e-mail and computer afterwards;
- Do not start processing added or referred candidates’ personal data without confirmed permission from them;
- Keep your candidates’ data confidential - we respect the privacy of the applicants. This means that we don’t discuss or send data concerning the applicant to others, especially the current manager of the applicant, unless this has been agreed with the applicant.
Guideline for GDPR manager and recruiter document is here.