Recruitment Privacy Notice

Last Updated: 14th May 2018

Summary

This Recruitment Privacy Notice explains what information we gather about you, what we use that information for and who we give that information to, throughout the recruitment process.  It also sets out your rights concerning your information and who you can contact for more information.

Who does this Recruitment Privacy Notice apply to and what does it cover? 

This Recruitment Privacy Notice is to let you know how companies within MeDirect (including MeDirect Bank (Malta) plc and MeDirect SA/NV (hereinafter collectively referred to as the “Bank”) collect, process and store personal information about you, as part of the recruitment process. Such information is processed for a number of reasons as detailed herein, such as your application, assessment, pre-employment screening, and your work permit requirements (if any).

This Recruitment Privacy Notice aims to help you understand:

  • What information is collected and from where
  • Why we collect your personal information
  • How it is processed throughout the recruitment process

  • Throughout this notice the term “processing” is used to cover all activities concerning your personal information, and can include any of the following:

    • Collecting
    • Recording
    • Organising
    • Structuring
    • Storing
    • Adapting or altering
    • Retrieving
    • Consulting
    • Using
    • Disclosing by transmission
    • Disseminating or otherwise making available
    • Aligning or combining
    • Restricting
    • Erasing or destroying

What information do we collect?

As part of the recruitment process, we need to process certain personal information about you. We only process your information as necessary for the purposes of progressing your application or as required by law or regulatory requirements.
Here are some examples of the type of personal information (‘personal data’) we may process.

  • Personal details such as name, address, date and place of birth
  • Work history/job data; previous employers, positions, dates, etc.
  • Compensation; basic salary, benefits, bonuses, etc.
  • Education and work history including professional qualifications and skills
  • Employer feedback/references to include regulated references where necessary
  • Nationality/Visa/work permit information (e.g. copies of identity card and/or passport, National Insurance number, etc.)
  • Photographs and images from recorded assessments or from onsite CCTV
  • Results of pre-employment screening checks (e.g. credit history, criminal records checks where permitted under local law)
  • Assessment results (e.g. interview assessment, psychometric assessment results, pre-screening calls, technical test results)

During the recruitment process we may also capture some sensitive personal data about you (e.g. personal health). We do this in order to make reasonable adjustments to enable our candidates to apply for jobs with us and to ensure that we comply with regulatory obligations placed on us with regard to our recruitment process.

From where do we collect information?

We collect personal data in the following ways:

Careers Websites

We collect your personal data when you submit a job application via email or through our HR portal.

Social Network Sites

We collect personal data about you from other sources, including LinkedIn, Facebook and other social network sites when you choose to provide us with a link to your profile on any social network site as part of your job. We will collect the following personal data from social network sites:

  • Linkedin: personal data contained in the following fields: name, headline and summary, job title, current employer, employment history, recommendations and contact details made publicly available (such as phone number and email address). Your LinkedIn connections are not collected.
  • Facebook: personal data contained in the following fields: first name, last name, email, employer and job title. Your “likes”, “comments”, “friends lists/details” and “wall posts” are not collected.
  • Other social network sites: personal data contained in the following fields: first name, last name and public website.

We will not collect your photographs or videos from any social network site unless you submit a photograph or video voluntarily as part of your recruitment application.

We may also obtain your contact details from publicly available sources, including content that you have made public on other social network sites or similar sites for professional purposes, to make initial contact with you for recruitment purposes. If we contact you in this way you will be given the opportunity to object at any point in time, to receiving any further information about career opportunities by contacting us on careers@medirect.com.mt.

Recruitment Agencies

Your personal data may be provided to the Bank by recruitment agencies with which you have registered an interest in working for the Bank. Where a recruitment agency refers you to us, a copy of your personal details shall be processed in our recruitment database based on the information provided, and in accordance with this Recruitment Privacy Notice.

Other sources

Whilst in most cases you will provide your personal data, it may also be collected about you from third parties during the recruitment process such as references from previous employers, subject to receiving your prior consent.

How we use information about you?

We collect and use your personal data for legitimate human resource and business management reasons including:

  • Identifying and evaluating candidates for potential employment, as well as for future roles that may become available
  • Record keeping in relation to recruiting and hiring
  • Ensuring compliance with legal requirements, including diversity and inclusion requirements and practices
  • Conducting criminal history checks as permitted by applicable law
  • Protecting our legal rights to the extent authorized or permitted by law
  • Emergency situations where the health or safety of one or more individuals may be endangered


We may also analyse your personal data or aggregated/anonymized data to improve our recruitment and hiring process and augment our ability to attract successful candidates.

Following the recruitment process, we shall retain your personal data (including the CV) for a period of twelve (12) months based on legitimate grounds for the purpose of defending and/or responding to any legal claims that may arise. Moreover, subject to obtaining your prior consent, we may decide to process your personal data retained during the said twelve (12) month period for the purpose of considering you for potential future roles with the Bank. Should you decide that you no longer wish to be contacted by the Bank for potential future roles, please contact us at careers@medirect.com.mt

 

Who we disclose your information to?

The Bank will need to share your personal information internally (both in the country where you may work and in other countries in which we have operations) and may require to share it with some external parties or associates of the Bank. Some of these third parties and associates will be located outside the European Economic Area (“EEA”). Your information will only be shared if it is necessary or required (for example in order to carry out pre-employment screening or apply for a work permit).

The recruitment process will involve:

  • Assessing and processing your application
  • Assessing your suitability (skills, strengths, behaviours for the role)
  • Activities needed to complete the on-boarding and screening process should your application be successful

Your personal data may be disclosed to any of the following for any of the purposes outlined above:

  • Internally, limiting access to what is required by each individual to perform their role in the recruitment process
  • Professional advisers, third party service providers, agents or independent contractors providing services to the Bank
  • Any person to whom disclosure is allowed or required by law and/or regulation
  • Any court, tribunal, Regulatory Authority or Governmental Entity
  • Any criminal records bureau , credit bureau or credit reference agency when conducting background checks
  • Third parties to whom we may transfer our rights and/or obligations under any agreement

How do we protect your personal information?

We use a range of physical, electronic and managerial measures to ensure that we keep your personal data secure, accurate and up to date. These measures include:

  • Educating and training relevant staff to ensure they are aware of our privacy obligations when handling personal data
  • Administrative and technical controls to restrict access to personal data on a ‘need to know’ basis
  • Information security controls, including audit logging technologies, firewall and intrusion prevention systems, content filtering technologies, encryption and anti-virus software
  • Physical security measures, such as staff security passes to access our premises


Although we use appropriate security measures once we have received your personal data, the transmission of data over the internet (including by e-mail) is never completely secure. We endeavour to protect personal data, but we cannot guarantee the security of data transmitted to us or by us.

How long do we retain your information for?

 

If you accept an offer of employment with us, any relevant personal data collected during your pre-employment period will become part of your personnel records and will be retained in accordance with specific country requirements and subject to our employee Privacy Notice. 

If you are not selected for the position for any reason, we shall retain your personal data (including your CV) for a maximum period of twelve (12) months based on legitimate grounds for the purpose of defending and/or responding to any legal claims that may arise and, subject to receiving your consent, will process the retained personal data to contact you for future potential roles with the Bank. 

Personal data collected is retained by the Bank in accordance with the Bank’s applicable policies. 

 

What are your rights?

You have various rights in relation to your personal data. In particular, you have a right to:

  • Obtain confirmation that we are processing your personal data and request a copy of the personal data we hold about you
  • Ask that we update the personal data we hold about you, or correct such personal data that you think is incorrect or incomplete
  • Ask that we delete personal data that we hold about you, or restrict the way in which we use such personal data
  • Withdraw consent to our processing of your personal data (to the extent that such processing is based on consent)
  • Receive a copy of the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and to transmit such personal data to another party (to the extent the processing is based on consent or a contract)
  • Object to our processing of your personal data

Withdrawing your consent or asking that we delete your personal data during the recruitment process would mean that we will be unable to continue processing your application to work with the Bank.

To exercise any of your rights, file a complaint relating to your privacy or if you have any other questions about our use of your personal data, please email the Data Protection Officer at the e-mail address: dataprotection@medirect.com.mt.

How can you avail of your right to complain?

If you are unhappy with the way we have handled your personal data or any privacy query or request that you have raised with us, you have a right to complain to the Office of the Information and Data Protection Commissioner. Find out on the IDPC website how to send a complaint.

Changes to this Recruitment Privacy Notice

We reserve the right to modify or amend this Recruitment Privacy Notice from time to time without giving any prior notice.

To let you know when we make changes to this Recruitment Privacy Notice, we will amend the revision date at the top of this page. The new modified or amended notice will apply from that revision date.

Therefore, we encourage you to periodically review this notice to be informed about how we are protecting your information.

Cookie Policy

To find out more about how we use cookies, please see our Cookie Policy.

Contact Us

Give us a call

(+356) 2557 4400

Mon – Fri 8.00am to 6.00pm
Sat 9.00am to 1.00pm

Send us an email

info@medirect.com.mt

Write to us

MeDirect Bank (Malta) plc
The Centre, Tigné Point
Sliema, TPO 0001, Malta