Data Protection Policy – GDPR
Marine Science Recruitment Agency Ltd. (MSRA) is committed to protecting the privacy and security of personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy outlines how we handle personal data collected from candidates, clients, and employees in the course of our recruitment activities.
1. Introduction
MSRA is committed to protecting the privacy and security of personal data as outlined above.
2. Scope
This policy applies to all employees, contractors, and third parties who process personal data on behalf of MSRA. It covers the collection, storage, processing, and sharing of personal data related to candidates, clients, and employees.
3. Definitions
- Personal Data: Any information relating to an identified or identifiable individual.
- Processing: Any operation performed on personal data (e.g., collection, storage, alteration, deletion).
- Data Subject: The individual whose personal data is being processed.
- Data Controller: MSRA, responsible for how and why personal data is processed.
- Data Processor: Third parties processing data on behalf of MSRA.
4. Principles
- Lawfulness, Fairness, and Transparency: Personal data is processed lawfully and transparently.
- Limitation: Data is collected for specific, legitimate purposes only.
- Data Minimisation: Only data necessary for the intended purpose is collected.
- Accuracy: Data is accurate and kept up to date.
- Storage Limitation: Data is not kept longer than necessary.
- Integrity and Confidentiality: Data is processed securely to prevent unauthorised access or loss.
5. Lawful Bases for Processing
- Consent: Clear permission from the data subject.
- Contractual Necessity: Processing needed to fulfill a contract.
- Legal Obligation: Processing required by law.
- Legitimate Interests: Processing necessary for business interests not overridden by individual rights.
6. Personal Data We Collect
- Candidates: Contact details, employment history, qualifications, references, criminal records, health data, NI numbers, bank details, tax codes.
- Clients: Business contact information and job requirements.
- Employees: Contact details, employment and payroll records, and other relevant data.
7. How We Use Personal Data
- Candidates: To manage job applications and communications.
- Clients: To match candidates with vacancies and support recruitment efforts.
- Employees: For HR, payroll, performance, and legal compliance.
8. Data Retention
Candidate data is kept for 12 months post-recruitment unless extended by consent. Client and employee data is retained per legal and contractual requirements.
9. Data Sharing
Data is shared only as needed with:
- Clients (for recruitment)
- Service providers (e.g., payroll, background checks)
- Legal authorities (as required by law)
10. International Transfers
Data is primarily stored within the UK and EEA. Any transfer outside the EEA includes appropriate safeguards.
11. Data Security
- Data encryption
- Access control measures
- Regular audits
- Employee training
12. Data Subject Rights
Data subjects may exercise the following rights:
- Access
- Rectification
- Erasure
- Restriction of processing
- Data portability
- Objection to processing
Contact: contact@marinesciencerecruitment.com
13. Data Breaches
In the event of a breach, we will notify the ICO and affected individuals as legally required.
14. Data Protection Officer (DPO)
Name: MSRA Data Protection Officer
Email: contact@marinesciencerecruitment.com
15. Review and Updates
This policy is reviewed regularly. Last reviewed on 17/10/2024.
