Privacy notice:
Job applicants
Last updated: 2 December 2024
TABLE OF CONTENTS
Who you are
This information is relevant to you if you’ve applied for a job with us.
Who we are
For the purposes of data protection law, the ‘controller’ of your personal data will be Shieldpay Operations Limited, a company registered in England and Wales under number 14318564 and registered as a controller with the ICO under number ZB476223.
What personal data we collect about you
Application process data includes information contained in a CV such as employment history, educational background, copies of qualification certificates and other information offered by candidates such as hobbies and interests; references; correspondence between candidates and Shieldpay by email; interview and shortlisting notes/review scores (including the reasons for selection or rejection) and any selection test paperwork
Biographical and contact data includes full name, date of birth, home postal address, personal phone number, personal email address, work email address and other contact information, marital status, parental status and gender (in each case, if offered by the applicant)
Compliance data includes identity verification documents and check results, visa document and right to work check results, the results of any politically exposed persons, sanctions and adverse media checks
Criminal records data includes details of spent and unspent convictions and cautions (other than protected convictions or cautions)
Health data includes information relating to physical or mental disabilities, preferences for communication based on cognitive abilities, and dietary requirements
Survey data includes responses to any recruitment process surveys provided after conclusion of the recruitment process
Where we get your personal data from
We will generally get your personal data directly from you (via email, LinkedIn or our recruitment platform, Teamtailor). However, we may be provided with personal data about you from recruitment agencies and referees.
What we use your personal data for
We'll use your personal data for the purposes listed below. Against each of these purposes, we've identified which categories of personal data listed above are required and the legal ground relied on by us in line with data protection law.
Purpose | Categories of personal data | Legal ground |
---|---|---|
Administering and undertaking the recruitment process | Our legitimate interests in conducting an accessible, fair and efficient recruitment process. Where we process health data to make any adjustments to our application process, we will do so based on our legal obligations under equalities law. | |
Considering an applicant’s suitability for the role applied for |
|
Our legitimate interests in evaluating the suitability of an applicant for a role |
Verifying the identity of successful applicants and running right to work and sanctions screening checks |
|
Complying with our legal obligations under immigration, anti-money laundering, terrorist financing, sanctions and other financial crime law |
Undertaking criminal records checks on successful applicants |
|
If the applicant will be a director, officer or senior managers, complying with our legal obligations under financial services regulation and, for all other roles, our legitimate interests in mitigating the risk of criminal activity whether or not involving business or client funds and the associated legal and reputational consequences |
Obtaining feedback on our recruitment process | Our legitimate interests in improving our recruitment process for future job applicants |
We may also use your personal data for purposes that are compatible with the above purposes. In doing so, we'll take into account various factors including the link between the original purpose and the purposes of the intended further processing, the nature of our relationship, the nature of the personal data, the potential consequences for you and any additional safeguards that we can put in place.
Who we share your personal data with
Depending on which of the purposes listed above applies, we may share your personal data with:
- Data service providers such as identify verification, right to work, politically exposed persons, sanctions and adverse media screening providers
- Internal and external auditors for the purpose of ensuring that our recruitment practices comply with legal and regulatory requirements
- Technical service providers as necessary for us to administer the recruitment process and conduct our business
- Previous employers and educational institutions for the purpose of obtaining references
- Regulatory bodies such as the Financial Conduct Authority where information about our recruitment practices is requested by them (although we will take steps to aggregate and anonymise personal data where possible)
How long we keep your personal data for
We’ll only keep your personal data for as long as necessary in connection with the purposes for which we collected it. We maintain a data retention schedule for each category of personal data we hold.
If you’ve been successful in applying for a role, application process data will be retained for the duration of your employment plus 12 months. If you’ve been unsuccessful, application process data will be retained for 12 months from the end of the recruitment process.
As compliance data is only obtained for successful candidates, this will be retained for 12 months from the date of each check (such checks to be renewed annually during the course of employment). Criminal records checks are retained for 12 months from the date of the check, for both unsuccessful and successful candidates (also renewed annually during the course of employment).