The Gentleman With One Red Shoe
MZIZI Africa works with organizations to set up compliance systems rooted in ethics.
Our Data Privacy Library is 1 of 16 law libraries containing easy to deploy employee Learning & Communication resources and through which we help set up Data Protection Act, 2019 (DPA,19) compliant processes.
This requires that we document our client's data processing inventory to include HR processes.
75% of the respondents to our DPA,19 Self Assessment Survey admit to not having an employee Privacy policy.
Data Privacy & Recruitment
When we hold training or consultancy sessions we define personal data simply: Any data
that allows you to identify a person is personal data. This includes
names, photos, vehicle registration numbers, addresses, company names of sole traders or in the
context of a venue “the gentleman with one red shoe” if there is only one
male person wearing a red shoe.
CV Applicant data is personal data. An applicant’s CV, whether randomly mailed or part of a process that leads to a review, interview or employed is personal data and it must therefore be handled in a compliant manner.
So what should hiring managers look out for when handling applicant data:
1. Review information sought.
Is all the data sought from candidates relevant and necessary? The information required during recruitment may not be needed to complete the hiring process. While the the jury is out on psychometric tests (and I look forward to reviewing this area in future), there is value in critically reviewing this area for compliance.
2. Check devices for CVs
You will probably find CVs in multiple devices having been sent and circulated previously.
Do search your firms devices (laptop, mobile, tablet, etc) for any CVs and consolidate them in one location / folder.
This will also help when you are dealing with Data Subject Access Requests.
3. Delete CVs that are currently not in a hiring process
There is no reason to continue to hold on to CVs of applicants that are not currently in a hiring process. Therefore delete any CVs you are not currently working on. You may be required to do this even for those employees that you did hire.
TIP - Just because you press delete does not mean a file is fully erased from your device - consult your IT
How many recruitment
agencies actually go over old applications to see if there is a suitable
past candidate for a new role? Review your practices in this area
honestly and delete CVs that you no longer need. However, if your
company is the exception, you can certainly hold the data.
4. Develop a compliant recruitment process.
Managers / employees sometimes request for and receive CVs directly on email.
If applicants send CVs directly, do develop a compliant process to handle the data - Forward the CV to HR and inform the candidate about it and then delete the CV from your device. Regularly communicate with your employees on this area to ensure continued compliance through top of mind awareness - there are tools that simplify this process.
If you don’t have a suitable role for the applicant, inform them of the same and that you will be deleting their details in accordance with the DPA,19.
5. Develop a secure process of sharing CVs
Email is not the safest way of sharing personal data. Emails bounce through a couple of servers and may not be secure.
Consider secure data sharing and storage programs instead.
6. Update your privacy policy
Update your employee privacy policy to include how you handle applicant data under the DPA,19.
Policies are a bedrock of compliance systems and this should be handled early on. Your privacy policy should include why you need the data, the specific data required, how you store data,
how long, whether you are sharing details with third parties and why
you do it etc. In addition, you should inform the candidates of this
process and give them the opportunity to object and have their data
removed.
6. Accountability
Document your processes to be audit ready.
Finally...
If you are in any doubt whether the DPA,19 applies to data you hold or you would like to learn more about how to set up or strengthen your compliance system, get in touch with Mzizi Africa and we will be delighted to have a conversation with you.
In the meantime, do take our DPA,19 Self Assessment Survey to establish your organisations' state of compliance to the DPA, 2019.
Comments
Post a Comment