Organizations may receive personal data from job applicants who provide it voluntarily through a job application, either in response to a recruitment
advertisement or otherwise. Data protection employee rights helps you to understand your employment rights.
When an individual voluntarily provides his personal data to an organization in the form of a job application, he may be deemed to consent to the organization collecting, using and disclosing the personal data for the purpose of assessing his job application. If the individual is subsequently employed, it would be reasonable for the organization to continue to use the personal data provided by the individual in the job application form for the purpose of managing the employment relationship with the individual, if required.
After an organization has decided which job applicant to hire, the personal data that the organization had collected from the other job applicants should only be kept for as long as it is necessary for business or legal purposes. Organizations should note that job applicants have the right to obtain access and request corrections to their personal data held by the organization.
Under the PDPA, individuals have the right to obtain access and request corrections to their personal data held by organizations. Upon request, the organization must also inform the individual of the ways in which the personal data had been used for the past year. Thus, organizations must reveal to the job applicant who requests so, the personal data the organization has on them. There are however exceptions to this obligation to provide access to personal data, including several mandatory exceptions.
Section 25 of the PDPA requires an organization to cease to retain its documents containing personal data, or remove the means by which the personal data can be associated with particular individuals, as soon as the purpose for which that personal data was collected is no longer being served by retention of the personal data, and retention is no longer necessary for legal or business purposes.
Also Read: 7 Key Principles of Privacy by Design that Businesses should adopt
Employee rights under GDPR have increased, and now employers based out of or doing some business in the EU must follow these guidelines in addition to existing privacy regulations in order to keep employees’ data secure at all times:
The exception relating to “managing or terminating an employment relationship” only apply when there is an employment relationship. Where an organization is collecting the personal data of individuals that are not its employees for a specific purpose, this specific exception would not apply. However, other exceptions may apply, for example where the organization is required under written law to collect personal data of such individuals in order to assess whether the qualifications of such individuals comply with regulatory requirements.
Also read: https://globaldatahub.taylorwessing.com/article/changes-to-employee-data-management-under-the-gdpr