Global Privacy Policy for Job Applicants
Introduction
This Privacy Notice explains how the ComplyMAP Group and each ComplyMAP Group Entity (as defined below) collects, uses, stores, shares and otherwise processes personal data relating to individuals who apply for employment with us through our website, recruitment portals, recruitment agencies or any other recruitment channel.
This Privacy Policy applies globally and is intended to comply with applicable data protection and privacy laws, including where applicable:
- the EU General Data Protection Regulation (EU) 2016/679 (“GDPR”);
- Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data of 2018 (Law 125(I)/2018);
- the laws of Member States of the European Economic Area;
- the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data;
- India’s Digital Personal Data Protection Act, 2023;
- Mauritius Data Protection Act, 2017;
and any other applicable legislation.
Where local legislation grants additional rights or imposes additional obligations, those provisions will apply in addition to this Privacy Policy.
Definitions
“ComplyMAP Group” means ComplyMAP Group and its relevant affiliated entities, business divisions and operating companies, including, as applicable, Complyport (EU) Ltd, Complyport Tech (EU) Ltd, Complyport Limited, Complyport Tech (UK) Ltd, Complyport Gentium UK Limited, Complyport Information Technology CO. LLC, Complyport (MAU) Ltd, Complyport (IND) Private Limited, Spinebiz FZCO, ComplyportCyprus Limited (each a “ComplyMAP Entity” and together the “ComplyMAP Group Entities”).
“DPO” means the Data Protection Officer appointed by ComplyMAP Group, where required by applicable law, responsible for monitoring compliance with applicable data protection laws, advising on data protection obligations, cooperating with supervisory authorities, and acting as a contact point for data subjects and competent authorities on data protection matters.
“Personal Data” means any information relating to an identified or identifiable natural person. For the avoidance of doubt, information relating solely to a corporate entity, such as the corporate name of a client company, is not Personal Data unless it identifies a natural person.
“Privacy Policy” means this Privacy Policy, as amended from time to time.
Who we are
The ComplyMAP Group and each ComplyMAP Group Entity (as defined below) are committed to protecting individuals’ personal data in line with the requirements of applicable law. ComplyMAP Group’s commitment applies to all individuals whose personal data it may process.
Each ComplyMAP Entity, as controller, maintains records of processing activities under its responsibility in accordance with Article 30 of the GDPR, where applicable.
ComplyMAP Group is a UK-headquartered group operating across multiple jurisdictions, including the United Kingdom, the European Union and the United Arab Emirates, and also has operations in Mauritius and India.
From time to time, the composition of the ComplyMAP Group may change, including through reorganisation, merger, rebranding, acquisition, disposal or internal restructuring. Any reference in this Privacy Policy to a ComplyMAP Entity shall include its successors, permitted assigns and any entity forming part of the ComplyMAP Group at the relevant time.
References in this Privacy Policy to “we”, “us”, “our”, or the “ComplyMAP Group” shall be construed as references to the relevant ComplyMAP Entity acting as controller or processor, as the case may be, and/or to more than one ComplyMAP Entity where the context so requires.
The ComplyMAP Group, operating globally under the Complyport brand, provides integrated governance, risk, compliance and technology-enabled services. These include regulatory and financial services advisory, compliance and risk management consultancy, internal audit and assurance services, RegTech and transaction reporting solutions, operational resilience and cyber risk support, IT and digital transformation services, technology‑enabled managed services (including client lifecycle and financial crime support), as well as broader business and regulatory consultancy services across multiple jurisdictions
As the controller, each ComplyMAP Entity determines the purpose and means of processing individuals’ personal data.
Personal data that we collect
Each ComplyMAP Entity processes different personal data for a variety of reasons. These may include:
- Personal data for applicantsand other purposes:
These may include name and surname, position, residential address, identification details (e.g. passport or ID), postal or residential address, business address, mobile number, email address, , signature, employment status, company of employment.
- Publicly available information:
ComplyMAP Entities may also process personal data from public sources, including databases used for compliance checks.
- Compliance with statutory obligation:
ComplyMAP Entities may process personal data where obliged to do so under the law (e.g. employment records, company records, tax reporting obligations, personnel recruitment laws, and contractual duties).
- Children’s data:
ComplyMAP services are not directed at children under the age of 16 (or the applicable age of digital consent in the relevant jurisdiction). We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us using the details in Section 15.
- Employee, worker, consultant and applicant data:
ComplyMAP Entities may process personal data relating to employees, workers, consultants, directors, officers, candidates and other individuals engaged by, or applying to work with, a ComplyMAP Entity. This may include identification and contact details, recruitment and application information, contact information, curriculum vitae (CV), employment history, educational qualifications, professional licences and certifications, references, skills and experience, interview notes, recruitment assessment results, right-to-work or eligibility information, contract and role details, salary expectations, payroll, tax, social security and benefits information, bank account details, performance, training and development records, notice period, absence and leave records, disciplinary and grievance records, IT and system access information, health and safety information, and any other communication with you or information reasonably required for the establishment, administration, management or termination of the employment or engagement relationship.
Where permitted by law and necessary for the role, we may also collect criminal record information, background verification results, immigration status and information necessary to provide workplace accommodations.
Please avoid including unnecessary sensitive personal information unless specifically requested.
Such personal data may be processed for recruitment and selection, onboarding, workforce administration, payroll and benefits management, training and development, performance and talent management, compliance with employment, tax, social security, immigration, health and safety and other legal obligations, internal governance and reporting, IT and security administration, investigation of complaints or concerns, business continuity, and the management or termination of employment or engagement with the relevant ComplyMAP Entity.
Where special categories of personal data are processed, such as health-related information or information required for equality, absence, workplace accommodation, legal or regulatory purposes, this will be done only where permitted or required by applicable law and subject to appropriate safeguards.
How we collect your information
We collect personal data directly from you, through our website, through recruitment agencies, during interviews, from referees identified by you or from publicly available sources including client entities, government agencies and risk intelligence service providers (e.g. World-Check, Lexis-Nexis).
Why we process your personal data
We process your personal data to evaluate your application and communicate with you, arrange interviews, assess qualifications, verify the information provided, conduct recruitment assessments, comply with employment and legal obligations, protect our legitimate business interests, defend or uphold legal rights, comply with any order of a competent court or other authority, maintain recruitment, employment, payroll and other related records or consider you for future employment opportunities where permitted.
Legal ground for personal data processing
ComplyMAP Entities may process the personal data set out above on one or more of the following grounds:
- You have provided your consent to a ComplyMAP Entity for the specific purpose of processing;
- The processing is necessary for the performance of a contract to which you are party, such as an employment contract, or in order to take steps at your request prior to entering into a contract with a ComplyMAP Entity;
- The processing is necessary for compliance with a legal obligation to which a ComplyMAP Entity, as controller, is subject;
- The processing is necessary in order to protect the vital interests of you or of another natural person;
- The processing is necessary for the purposes of the legitimate interests pursued by a ComplyMAP Entity as controller or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of personal data, in particular where the data subject is a child.
Examples where a ComplyMAP Entity may process personal data on the basis of legitimate interests include fraud detection and prevention, credit and KYC checks, inquiries in relation to politically exposed persons, product development, communications and marketing, insurance purposes, employment and recruitment purposes, IT purposes (e.g. data loss prevention, information security, system security, network security and cyber-security), employment data processing, general operations and due diligence (e.g. internal customer analysis, reporting and management information).
Where your consent is relied upon, you may withdraw it at any time, subject to applicable law.
Provision of your personal data
ComplyMAP Entities may share your information with other ComplyMAP Entities within the ComplyMAP Group. In particular, ComplyMAP Entities may share your personal data with their Human Resources personnel, the DPO, legal and compliance functions, hiring managers, affiliated companies, internal audit, risk management personnel, recruitments agencies, IT security team, payroll team, professional advisers or government authorities where required by applicable law.
ComplyMAP Entities may also share your information where obliged to do so by an applicable court order and/or where required to do so by applicable law.
The safety of your personal data
ComplyMAP Entities take appropriate physical, organisational and technical measures to ensure the safety of your personal data against accidental or unlawful destruction, loss, alteration, unauthorised access or disclosure. Your personal data may be stored electronically or in paper form.
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with applicable data protection law, unless certain exceptions apply.
Personal data that you provide to us in relation to other individuals
Where you provide to a ComplyMAP Entity personal data of other individuals (e.g. previous employers, referees), you represent that you are duly entitled to do so.
You also represent that the individual in question is aware of the relevant ComplyMAP Entity’s data protection practices as stated in this Policy, where relevant to that individual, how such ComplyMAP Entity may be contacted, as well as any information that you are obliged to provide to such individual under applicable laws in relation to the relevant ComplyMAP Entity.
How long we store your personal data for
ComplyMAP Entities store personal data for no longer than is reasonably necessary for the purposes for which it is processed. Where a ComplyMAP Entity stores personal data based on your consent, it will delete such personal data when you withdraw your consent, provided that it is not obliged under law to retain such data. In the case of recruitment activities, ComplyMAP Entities will delete your personal data if you are not employed unless you expressly consent to the storage of your personal data for potential future roles and/or other purposes. Consent will be updated on an annual basis. If you accept an offer of employment by a ComplyMAP Entity, any relevant personal data collected during your pre-employment period will become part of personnel records and will be retained during your employment and for as long as required by applicable laws after the end of employment. ComplyMAP Entities may, in any case, keep personal data for as long as necessary for the defence or bringing of legal claims as provided by applicable limitation laws in the relevant jurisdiction.
Transfers of personal data
ComplyMAP Entities may transfer personal data internationally where required for any of the purposes stated above, including for storage purposes. In such a case international data transfers are carried out in compliance with the data protection laws of the jurisdiction in which the relevant ComplyMAP Entity is established:
ComplyMAP Entities in the United Kingdom will ensure that transfers of personal data to countries outside the UK comply with the UK General Data Protection Regulation, using adequacy regulations, the UK International Data Transfer Agreement (IDTA), the UK Addendum to EU Standard Contractual Clauses, or other appropriate safeguards under UK GDPR.
ComplyMAP Entities in the European Union will ensure that transfers of personal data to third countries outside the EU/EEA comply with the General Data Protection Regulation (Regulation (EU) 2016/679), based on a Commission adequacy decision, appropriate safeguards (e.g. standard contractual clauses), or other grounds provided by the GDPR.
ComplyMAP Entities in the United Arab Emirates will ensure that transfers of personal data internationally comply with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and will implement appropriate contractual or other safeguards as required under UAE law.
For ComplyMAP Entities established outside the UK and EU/EEA, international transfers of personal data will be carried out in accordance with the data protection laws applicable to that entity. Appropriate safeguards will be implemented where required by the applicable legal framework governing such transfers.
You may contact the relevant ComplyMAP Entity or the DPO in order to be informed of the appropriate or suitable safeguards, as the case may be.
Automated Decision-Making
Unless specifically notified otherwise, we do not make hiring decisions based solely on automated decision-making.
Your rights as a data subject
- Right of access – you have the right to request from a ComplyMAP Entity acting as your controller a copy of the personal data held about you.
- Right of rectification – you have the right to request from a ComplyMAP Entity acting as your controller the correction of personal data that is inaccurate or incomplete.
- Right to erasure – you have the right to request from a ComplyMAP Entity the erasure of your personal data from its records, where the applicable legal conditions are met and no exception applies.
- Right to restriction of processing – you have the right to request from a ComplyMAP Entity acting as your controller, where certain conditions apply, restriction of the processing of your personal data.
- Right to portability – you have the right to request from a ComplyMAP Entity acting as your controller, where certain conditions apply, to have the data it holds about you transferred to another organisation.
- Right to object – you have the right to object, on grounds relating to your particular situation, to certain types of processing such as direct marketing.
- Right to withdraw consent– where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
- Right regarding automated decision-making and profiling– you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, except where such processing is necessary for entering into or performance of a contract, authorised by law, or based on your explicit consent.
- Right to lodge a complaint– you have the right to lodge a complaint with the competent supervisory authority (see Section 16 below).
- Right to judicial remedy – in the event that a ComplyMAP Entity refuses your request in relation to any of the above rights, it will provide you with reasons, subject to applicable law.
You can make a request or exercise these rights by completing the Data Subject Access Request Form and sending it by e-mail to the following e-mail address: dpo@complyport.com
We may request you to provide information for the purpose of verifying your identity and residency in order to comply with our security obligations and to prevent unauthorised disclosure of data.
We will answer your request, or request additional information from you, within 1 (one) month. Occasionally, it may take longer than 1 (one) month if your request is particularly complex or you have made a number of requests. In this case, we will notify you within 1 (one) month of receipt of your request about the extension and keep you updated.
Each ComplyMAP Entity may charge a reasonable fee where a request is manifestly unfounded, excessive or repetitive, or where we receive a request to provide further copies of the same data. In this case, we will send you a fee request which you will have to accept prior to us processing your request. Alternatively, we may refuse to comply with your request in these circumstances.
Failure to provide personal information
If a ComplyMAP Entity requests that you provide personal data and you fail to do so, such ComplyMAP Entity may not be in a position to enter into an agreement with you, in which case it will inform you accordingly.
Your right to make a complaint
The DPO and/or the relevant ComplyMAP Entity will endeavour to respond promptly to your requests and complaints. In the event that you are unsatisfied with the way your personal data has been handled, or with any privacy query or request that you have raised, you may submit a complaint in writing to: dpo@complyport.com
We will try to respond to all requests within 1 (one) month. Occasionally, it may take longer than 1 (one) month if your request is particularly complex or you have made a number of requests. In this case, we will notify you within 1 (one) month of receipt of your request and keep you updated.
If you are not satisfied with our response to your complaint, you have the right to lodge a complaint with the competent supervisory authority in the jurisdiction of the relevant ComplyMAP Entity or where otherwise available under applicable law. For ease of reference, the principal supervisory authorities relevant to ComplyMAP Group Entities include:
Cyprus:
For entities established in Cyprus, details of the Office of the Commissioner for Personal Data Protection are available at this link
Address: kypranoros 15, Nicosia 1061 , Cyprus, Postal address, P.O.Box 23378, 1682 Nicosia, Cyprus
Telephone: +357 22818456
Fax: +357 22304565
Email: commissionerdataprotection.gov.cy
United Kingdom:
Information Commissioner’s Office (ICO)
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Email: icocasework@ico.org.uk
Website: https://ico.org.uk
United Arab Emirates (UAE):
UAE Mainland (Federal):
UAE Data Office (Data Protection under Federal Decree-Law No. 45 of 2021)
Website: https://u.ae/en/about-the-uae/digital-uae/data/data-protection
Dubai International Financial Centre (DIFC):
Commissioner of Data Protection – Dubai International Financial Centre (DIFC)
Address: Level 14, The Gate, P.O. Box 74777, Dubai, United Arab Emirates
Email: commissioner@dp.difc.ae
Telephone: +971 4 362 2222
Website: https://www.difc.ae/business/registrar/data-protection
India:
Data Protection Board of India
Head office: National Capital Region (New Delhi), India
Website: https://dpdpaedu.org
Mauritius:
Data Protection Office
Address: Level 5, SICOM Tower, Wall Street, Ebene Cyber City, Republic of Mauritius
Email: dpo@govmu.org
Telephone: +230 460 0251
Website: https://dataprotection.govmu.org
Cookies
ComplyMAP Entities use cookies in order to deliver a better user experience on their websites. For further information regarding cookies please see the ComplyMAP Group Cookie Policy at Cookie Policy.
Changes to this Privacy Policy
This Privacy Policy is subject to change to reflect changes in data protection practices or the legal framework. In the event that this Policy is amended, the revised document will be posted on the ComplyMAP Group website and such change will apply from the date it is posted unless otherwise stated in the revised Privacy Policy.