Privacy Policy
Recruitment - Privacy Notice
SANS Institute (“we”, “us”) are committed to protecting and respecting your privacy. This Privacy Notice sets out the basis on which the personal data collected from you, or that you provide to us, will be processed by us in connection with our recruitment processes.
For the purpose of the General Data Protection Regulation (“GDPR”) and other data protection legislation the Data Controller is SANS Institute.
We use Pinpoint, an online software product provided by The Infuse Group Ltd (t/a Pinpoint Software), to assist with our recruitment process. We use Pinpoint to process personal information as a data processor on our behalf. Pinpoint is only entitled to process your personal data in accordance with our instructions. We only use processors which have adequate information security processes in place.
When you apply for an opportunity posted by us, these provisions will apply to our processing of your personal information, in association with our main Privacy Notice which is available on our website.
Your Personal Information
Information we collect from you
We collect and process some or all of the following types of information from you:
- Information that you provide when you apply for a role. This includes information provided through an online application, via email, in person at interviews and/or by any other method.
- In particular, we process personal details such as name, email address, address, date of birth, qualifications, experience and any information relating to your employment history, skills and experience that you provide to us.
- If you contact us, we may keep a record of that correspondence.
- Details of your visits to our careers website including, but not limited to, traffic data, location data and other communication data, the site that referred you to our careers website and the resources that you access.
Information we collect from other sources
Pinpoint provides us with the facility to link the data you provide to us with other publicly available information about you that you have published on the Internet – this may include sources such as LinkedIn and other social media profiles.
Pinpoint’s technology enables us to search various databases, which may include your personal data, to find possible candidates to fill our job openings. Where we find you in this way we will obtain your personal data from these sources in accordance with the privacy policies of the sources we use.
Diversity and Inclusion Information
As part of the application process you may be asked to provide equality and inclusion information. You do not have to answer these questions and if you choose not to this will have no effect on the recruitment process. We collect this information to help us ensure that we are acting fairly and to ensure we comply with our own Diversity and Inclusion policies. If you provide this information it will be held securely and we will only access aggregated/anonymised results to monitor our compliance.
Uses made of your information
Lawful basis for processing
Where you provide your personal data, including equality monitoring data directly as part of the application process through Pinpoint, we rely on your explicit consent to process this data.
We rely on legitimate interests to process your personal data provided from Pinpoint or recruiters for the purposes detailed below. Our legitimate interests are the recruitment of staff for our business in the following ways:
- To consider your application in respect of a role for which you have applied.
- To consider your application in respect of other roles.
- To communicate with you in respect of the recruitment process.
- To enhance any information that we receive from you with information obtained from third party data providers such as LinkedIn
- To find appropriate candidates to fill our job openings.
- To help Pinpoint improve their services through analytics
Automated decision making / profiling
We may use Pinpoint’s technology to help us select appropriate candidates for us to consider based on criteria we have identified. The process of finding suitable candidates is automatic, however, any decision as to who we will engage to fill the job opening will be made by our team.
How we store your personal data
Security
We take appropriate measures to ensure that all personal data is kept safe including security measures to prevent personal data from being accidentally lost, or used or accessed in any unauthorised way. We limit access to your personal data to those who have a genuine business need to view it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted through any online means, therefore any transmission remains at your own risk.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted through any online means, therefore any transmission remains at your own risk.
Where we store your personal data
The data that we collect and process from you using Pinpoint’s Services will be transferred to and stored at one of several data centre locations in Amsterdam (Netherlands) and may be synchronised to one of several data centre locations in London (United Kingdom) for backup and redundancy purposes. By submitting your personal data, you agree to this transfer, storing or processing.
The data that we collect and process from you using Pinpoint’s Services will be transferred to and stored at one of several data centre locations in Amsterdam (Netherlands) and may be synchronised to one of several data centre locations in London (United Kingdom) for backup and redundancy purposes. By submitting your personal data, you agree to this transfer, storing or processing.
How long we keep your personal data
We retain all candidate data for a period of 12 months from the time of application, or as long as is indicated in accordance with local data protection laws of your country of residence. In addition you may request that your personal information is deleted in via:
- Deletion of your personal information by you via the Manage Your Data tool or
- Receipt of a written request by you to us.
Your rights
Under the General Data Protection Regulation or as a general right you have a number of important rights. In summary, those include rights to:
- access to your personal data and to certain other supplementary information that this Privacy Notice is already designed to address
- require us to correct any mistakes in your information which we hold
- request the erasure of personal data concerning you in certain situations
- request access to the personal data concerning you which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to a third party in certain situations
- object at any time to processing of personal data concerning you for direct marketing
- object to decisions being taken by automated means which produce legal effects concerning you or similarly significantly affect you
- object in certain other situations to our continued processing of your personal data
- otherwise restrict our processing of your personal data in certain circumstances
- claim compensation for damages caused by our breach of any data protection laws.
If you would like to exercise any of these rights, please either:
- utilise the Manage Your Data tool provided or
- contact us using our contact details below, ensuring we have enough information to identify you, proving your identity and address and confirming which information to which your request relates
How to complain
We hope that we can resolve any query or concern you raise about our use of your information. If you have a complaint or a concern you can contact SANS Data Protection at sheys@sans.org. We will do our best to resolve your complaint internally. If you are not satisfied then you also have the right to lodge a complaint with your local data protection supervisory authority, in particular in the European Union (or European Economic Area) state where you work, normally live or where any alleged infringement of data protection laws occurred.