CM Consulting is committed to protecting your privacy
Introduction
This privacy notice will inform you as to how we look after your personal data when you interact with us directly, you visit our website (regardless of where you visit it from), or any of our promotional web pages.
As part of any recruitment activity undertaken (client assignment or speculative), the Company collects and processes personal information, and/or personal data, relating to candidates. This information may be held by the Company on paper or in electronic format.
The Company is committed to being transparent about how it handles your personal information, to protecting the privacy and security of your personal information and to meeting its data protection obligations under the General Data Protection Regulation (“GDPR”) and the Data Protection Act 2018. The purpose of this privacy notice is to make you aware of how and why we will collect and use your personal information during the recruitment process. We are required under the GDPR to notify you of the information contained in this privacy notice.
This privacy notice applies to all candidates. It is non-contractual.
The Company has appointed a Data Compliance Contact to oversee compliance with this privacy notice. If you have any questions about this privacy notice or about how we handle your personal information, please contact us at
Data Protection Principals
Under the GDPR, there are six data protection principles that the Company must comply with. These provide that the personal information we hold about you must be:
- Processed lawfully, fairly and in a transparent manner.
- Collected only for legitimate purposes that have been clearly explained to you and not further processed in a way that is incompatible with those purposes.
- Adequate, relevant and limited to what is necessary in relation to those purposes.
- Accurate and, where necessary, kept up to date.
- Kept in a form which permits your identification for no longer than is necessary for those purposes.
- Processed in a way that ensures appropriate security of the data.
- The Company is responsible for, and must be able to demonstrate compliance with, these principles. This is called accountability.
What types of personal information do we collect about you?
Personal information is any information about an individual from which that person can be directly or indirectly identified. It doesn’t include anonymised data, i.e. where all identifying particulars have been removed. There are also “special categories” of personal information, and personal information on criminal convictions and offences, which requires a higher level of protection because it is of a more sensitive nature. The special categories of personal information comprise information about an individual’s racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation and genetic and biometric data.
The Company collects, uses and processes a range of personal information about you during a recruitment process. This includes (as applicable):
- Your contact details, including your name, address, telephone number and personal e-mail address
- Personal information included in a CV, any application form, cover letter or interview notes references
- Information about your right to work in the UK and copies of proof of right to work documentation
- Copies of qualification certificates
- Copy of driving licence
- Other background check documentation
- Details of your skills, qualifications, experience and work history with previous employers
- Information about your current salary level, including benefits and pension entitlements
- Your professional memberships
The Company may also collect, use and process the following special categories of your personal information during the recruitment process (as applicable):
- Whether or not you have a disability for which the Company needs to make reasonable adjustments during the recruitment process
- Information about your racial or ethnic origin, religious or philosophical beliefs and sexual orientation
- Information about criminal convictions and offences.
How do we collect your personal information?
The Company collects personal information about you during a recruitment process. We may also collect personal information from other external third parties, such as job boards, CV websites references from current and/or former employers, information from background check providers, information from credit reference agencies and criminal record checks from the Disclosure and Barring Service (DBS).
We may also collect data through Third parties or public available sources.
You are under no statutory or contractual obligation to provide personal information to the Company during the recruitment process.
Your personal information may be stored in the Company’s IT systems, such as our candidate managements system and e-mail system.
Cookies
As you interact with our website or other web-based company pages, we may automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, and other similar technologies. You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly. For more information about the cookies we use, please see our cookie policy.
Why and how do we use your personal information?
We will only use your personal information when the law allows us to. These are known as the legal bases for processing. We will use your personal information in one or more of the following circumstances:
- Where we need to take steps at your request in connection with a recruitment activity
- To advise you of any recruitment opportunities, resources or stay in touch, which may include, telephone, email and SMS.
- Where we need to comply with a legal obligation
- Where it is necessary for our legitimate interests (or those of a third party), and your interests or your fundamental rights and freedoms do not override our interests.
- We need all the types of personal information listed under “What types of personal information do we collect about you?” primarily to enable us to take steps at your request to manage a recruitment process, and to enable us to comply with our legal obligations. In some cases, we may also use your personal information where it is necessary to pursue our legitimate interests (or those of a third party), provided that your interests or your fundamental rights and freedoms do not override our interests. Our legitimate interests include: pursuing our business of providing employees, workers and contractors; managing the recruitment process; conducting due diligence on prospective candidates and performing effective internal administration.
The purposes for which we are processing, or will process, your personal information are to:
- Manage the recruitment process and assess your suitability for employment or engagement
- Decide to who to put forward to our clients
- Comply with statutory and/or regulatory requirements and obligations, e.g. checking your right to work in the UK
- Comply with the duty to make reasonable adjustments for disabled job applicants and with other disability discrimination obligations
- Ensure compliance with your statutory rights
- Ensure effective HR, management and business administration
- monitor equal opportunities
- Enable us to establish, exercise or defend possible legal claims
- Please note that we may process your personal information without your consent, in compliance with these rules, where this is required or permitted by law.
What if you fail to provide personal information?
If you fail to provide certain personal information when requested, we may not be able to include you in a recruitment process, we may not be able to arrange a contract for you, or we may be prevented from complying with our legal obligations. You may also be unable to exercise your statutory rights.
Why and how do we use your sensitive personal information?
We will only collect and use your sensitive personal information, which includes special categories of personal information and information about criminal convictions and offences, when the law allows us to.
Some special categories of personal information, i.e. information about your health, and information about criminal convictions and offences, is processed so that we can perform or exercise our obligations or rights under employment law and in line with our data protection policy.
We may also process information about your health and information about any criminal convictions and offences where we have your explicit written consent. In this case, we will first provide you with full details of the personal information we would like and the reason we need it, so that you can properly consider whether you wish to consent or not. It is entirely your choice whether to consent. Your consent can be withdrawn at any time.
The purposes for which we are processing, or will process, health information and information about any criminal convictions and offences, are to:
- Assess your suitability for employment or engagement
- Comply with statutory and/or regulatory requirements and obligations, e.g. carrying out criminal record checks
- Comply with the duty to make reasonable adjustments for disabled job applicants and with other disability discrimination
- obligations
- Ensure compliance with your statutory rights
- Ascertain your fitness to work
- Ensure effective HR, management and business administration
- Monitor equal opportunities
- Where the Company processes other special categories of personal information, i.e. information about your racial or ethnic origin, religious or philosophical beliefs and sexual orientation, this is done only for the purpose of equal opportunities monitoring in recruitment and in line with our data protection policy. Personal information that the Company uses for these purposes is either anonymised or is collected with your explicit written consent, which can be withdrawn at any time. It is entirely your choice whether to provide such personal information.
We may also occasionally use your special categories of personal information, and information about any criminal convictions and offences, where it is needed for the establishment, exercise or defence of legal claims.
Change of purpose
We will only use your personal information for the purposes for which we collected it and in line with this privacy notice.
Who has access to your personal information?
Your personal information may be shared internally within the Company and its consultants for the purposes of recruitment activity, where access to your personal information is necessary for the performance of their roles.
The Company will only share your personal information with third parties should you be successful in connection with a recruitment process.
These may include:
- Your new employer for the purposes of making you a job offer
- External organisations for the purposes of conducting pre-employment reference and employment background checks
- The DBS, to obtain a criminal record check
- Former employers, to obtain references
- Professional advisors, such as lawyers
- We may also need to share your personal information with a regulator or to otherwise comply with the law.
How does the Company protect your personal information?
The Company has put in place measures to protect the security of your personal information. It has internal policies, procedures and controls in place to try and prevent your personal information from being accidentally lost or destroyed, altered, disclosed or used or accessed in an unauthorised way. In addition, we limit access to your personal information to those who have a business need to know in order to perform their job duties and responsibilities.
Where your personal information is shared with third parties, we require all third parties to take appropriate technical and organisational security measures to protect your personal information and to treat it subject to a duty of confidentiality and in accordance with data protection law. We only allow them to process your personal information for specified purposes and in accordance with our written instructions and we do not allow them to use your personal information for their own purposes.
The Company also has in place procedures to deal with a suspected data security breach and we will notify the Information Commissioner’s Office (or any other applicable supervisory authority or regulator) and you of a suspected breach where we are legally required to do so.
For how long does the Company keep your personal information?
The Company will only retain your personal information for as long as is necessary to fulfil the purposes for which it was collected and processed.The Company will only retain your personal information for as long as is necessary to fulfil the purposes for which it was collected and processed.If your initial application for employment or engagement is unsuccessful, the Company will generally seek consent to hold your personal information for future consideration in connection with employment opportunities. You can withdraw your consent at any time.Holing your data is also subject to: (a) any minimum statutory or other legal, tax, health and safety, reporting or accounting requirements for particular data or records, and (b) the retention of some types of personal information to protect against legal risk, e.g. if they could be relevant to a possible legal claim in a tribunal, County Court or High Court. If your application for employment or engagement is successful, personal information gathered during the recruitment process will be retained for as long as is necessary to comply with any statutory and legal obligations as previously set out above.The company undertakes regular reviews of the data it holds and as such personal information which is no longer to be retained will be securely and effectively destroyed or permanently erased from our systems and we will also require any third parties to destroy or erase such personal information where applicable.
Your rights in connection with your personal information
As a data subject, you have a number of statutory rights. Subject to certain conditions, and in certain circumstances, you have the right to:
- Request access to your personal information - this is usually known as making a data subject access request and it enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it
- Request rectification of your personal information - this enables you to have any inaccurate or incomplete personal information we hold about you corrected
- Request the erasure of your personal information - this enables you to ask us to delete or remove your personal information where there’s no compelling reason for its continued processing, e.g. it’s no longer necessary in relation to the purpose for which it was originally collected
- Restrict the processing of your personal information - this enables you to ask us to suspend the processing of your personal information, e.g. if you contest its accuracy and so want us to verify its accuracy
- Object to the processing of your personal information - this enables you to ask us to stop processing your personal information where we are relying on the legitimate interests of the business as our legal basis for processing and there is something relating to your particular situation which makes you decide to object to processing on this ground
- Data portability - this gives you the right to request the transfer of your personal information to another party so that you can reuse it across different services for your own purposes.
- If you wish to exercise any of these rights, please contact our Data Compliance Contact at
This email address is being protected from spambots. You need JavaScript enabled to view it. or on 020 8287 0760. We may need to request specific information from you in order to verify your identity and check your right to access the personal information or to exercise any of your other rights. This is a security measure to ensure that your personal information is not disclosed to any person who has no right to receive it.
In the circumstances where you have provided your consent to the processing of your personal information for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. This will not, however, affect the lawfulness of processing based on your consent before its withdrawal. If you wish to withdraw your consent, please contact our Data Compliance Contact. Once we have received notification that you have withdrawn your consent, we will no longer process your personal information for the purpose you originally agreed to, unless we have another legal basis for processing.
If you believe that the Company has not complied with your data protection rights, you have the right to make a complaint to the Information Commissioner’s Office (ICO) at any time. The ICO is the UK supervisory authority for data protection issues.
Transferring personal information outside the European Economic Area
The Company will not transfer your personal information to countries outside the European Economic Area.
Changes to this privacy notice
The Company reserves the right to update or amend this privacy notice at any time. We will issue you with a new privacy notice when we make significant updates or amendments. We may also notify you about the processing of your personal information in other ways.
Contact
If you have any questions about this privacy notice or how we handle your personal information, please contact our Data Compliance Contact at
Carys Mills Consulting Ltd trading as CM Consulting
Registered in England and Wales no.8220935
Registered office: 167-169 Great Portland Street, 5th Floor, London, W1W 5PF