Fair processing notice for job applicants on handling of personal data

Data protection legislation regulates how certain data about you (received as part of applying for employment with the Royal Society of Medicine), both in paper and electronic form, is used and held. The Royal Society of Medicine (RSM) is registered with the Information Commissioner’s Office and fully complies with the requirements placed on it as a ‘data processor’.

The following statement describes the type of data that the RSM keeps about job applicants and the purpose for which it is kept and your rights under the GDPR related to data processed about you, should you apply to work for the RSM. This applies whether your application is received directly by the RSM or via an agency.

Processing job applications

From the point at which we receive your application for employment with the RSM, the RSM will need to maintain and process data about you for the purposes of reaching and communicating a recruitment decision and production of an offer of employment if appropriate.

Such data is normally retained for six months following completion of our recruitment processes in the event of an offer of employment not being made.

Should an offer be made a further fair processing notice will be provided alongside any offer covering how such data is used and stored during the processing of offers and subsequent employment.

Processing at the recruitment stage includes the collection, storage, retrieval, alteration, disclosure or destruction of data. The kind of data that the RSM will process includes:

  • Interview details including notes of interviewers, dates and times
  • Candidate’s work history
  • Qualifications and experience relevant to the role
  • Ethnic origin (for monitoring purposes only)
  • Disabilities (for monitoring and adjustments only)
  • Date of birth (for post-employment health checks and adjustments advice only)
  • Contact details, including addresses, phone numbers and other contact details including historical address records for staff vetting and ID verification
  • Criminal records (only where relevant to the role and where legally permitted)
  • Court judgements and directorships (only where relevant to the role and where legally permitted)
  • References provided by previous employers and personal or educational referees
  • National Insurance number
  • Rights to work information for example copies of passports, ID cards, residence permits
  • Documents to confirm identity and address, for example, the above and utility bills, bank statements
  • Details of when you have entered and left the building for safety evacuation purposes

The RSM believes that those records are consistent with the recruiter, candidate and in the event of an offer being made, employer relationship between the RSM and yourself and with our requirements under data protection legislation.

Applicant and employee data

The data the RSM holds may be held and processed to meet the RSM’s legal responsibilities and also for the purposes of management and administration of an offer of employment, ascertaining suitability for employment, to comply with equal opportunity, immigration and money laundering legislation and, from time to time, the need to disclose data it holds about you to relevant third parties (for example where legally obliged to do so by HM Revenue and Customs, UK Border or other public authority, or where requested to do so by you for the purpose of giving a reference).

The RSM may also share this data with selected third parties, under agreements which strictly govern the use the third party may make of the data, to facilitate the above uses including our nominated occupational health advice provider and our nominated staff vetting provider.

In some cases, the RSM will use automated profiling methods to analyse the above data, including against standard industry benchmarks, but will not use such methods as the sole basis for any related decision making.

In some cases, the RSM may also hold sensitive data, as defined by the legislation, about you. This could be information about health, criminal convictions and financial debts and directorships.

Accessing your personal information

If you wish to view the information held about you, you must make a written request to the Chief Digital Officer at John.Foster-Hill@rsm.ac.uk. You may, within a period of thirty days of your written request, inspect and/or have a copy (subject to the requirements of the legislation) of the information held about you and, if necessary, require corrections should such records be faulty.

Your rights under the GDPR also include the following:

  • The right to rectification
  • Right to erasure (sometimes known as the right to be forgotten)
  • Right to restrict processing
  • Right to data portability
  • Right to object
  • Rights concerning automated decision making and profiling

Should you have any complaints regarding the handling of your data you have the right to lodge a complaint with John Foster-Hill, the RSM’s Data Protection Officer.

You can contact him at:

John Foster-Hill
Chief Digital Officer
Royal Society of Medicine
1 Wimpole Street

E: John.Foster-Hill@rsm.ac.uk