We process your personal information provided in the course of applying for a role with us either as an employee or a contractor in order to carry out our recruitment process and for no other purpose.
We share your information with suppliers who act on our behalf to carry out elements of our recruitment process such as psychometric tests and ID checks.
When we have a high volume of applications for a role, we use automated software to review applications to check that applicants meet our minimum criteria. You have the right to ask us to review any automated decision that has been made.
This notice explains what data we process, why, how it is legal and your rights.
Please familiarise yourself with the following words and phrases (used in bold) as they have particular meanings in the Data Protection Laws and are used throughout this Privacy Notice:
This means any person who determines the purposes for which, and the manner in which, any personal data is processed.
criminal offence data
This means any information relating to criminal convictions and offences committed or allegedly committed.
Data Protection Laws
This means the laws which govern the handling of personal data. This includes the General Data Protection Regulation (EU) 2016/679 and any other national laws implementing that Regulation or related to data protection.
The person to whom the personal data relates.
This means the UK Information Commissioner's Office which is responsible for implementing, overseeing and enforcing the Data Protection Laws.
This means any information from which a living individual can be identified.
This will include information such as telephone numbers, names, addresses, e-mail addresses, photographs and voice recordings. It will also include expressions of opinion and indications of intentions about data subjects (and their own expressions of opinion/intentions).
It will also cover information which on its own does not identify someone but which would identify them if put together with other information which we have or are likely to have in the future.
This covers virtually anything anyone can do with personal data, including:
obtaining, recording, retrieving, consulting or holding it;
organising, adapting or altering it;
disclosing, disseminating or otherwise making it available; and
aligning, blocking, erasing or destroying it.
This means any person who processes the personal data on behalf of the controller.
special categories of data
This means any information relating to:
racial or ethnic origin;
religious beliefs or beliefs of a similar nature;
trade union membership;
physical or mental health or condition;
sexual life; or
genetic data or biometric data for the purpose of uniquely identifying you.
The sections below set out the categories of personal data we may ask for at each stage of your application for a role with us. Some data may not be required depending on the type of role you are applying for. The reasons as to why we need each category of data are set out in the section 'Why do we need your personal data'.
If you choose not to provide us with any of these categories of data, your application may be rejected or it could affect our ability to process your application.
If you contact us with any questions prior to submitting an application for a role, we will keep a record of your name and contact details, as well as details of any question you have asked.
If you submit an application or send us a CV
If you submit an application for a role with us, we will ask you for:
Your contact details, including your name, address, e-mail address and telephone number
Details of your relevant education and employment history
Details of referees
Date of birth
Professional and academic qualifications
Information for the purposes of Equal Opportunities Monitoring (optional)
(Northern Ireland only) Religious Beliefs
Information about a disability for the purposes of making reasonable adjustments to our application process
If you submit a CV to us and it contains additional information, we will process whatever information you provide in your CV.
When we have a high volume of applications for a role, we use automated software to review applications to check that applicants meet our minimum criteria for that role. The criteria have been identified as mandatory for the particular role. They require simple yes/no responses. The software will automatically reject applications which do not meet the mandatory criteria. You have the right to ask us to review any automated decision that has been made, which is explained in more detail in the section headed "Your Rights".
If you are successful in our initial shortlisting stage, we may invite you for an interview, assessment day, or to complete online tests. Information will be generated by you and by us during this process. For example, you might complete written tests, undertake group exercises, take psychometric tests or we might take interview notes.
If we make you a conditional offer
If we make you a conditional offer of employment, we may gather further personal data before deciding whether to make you a final offer, to check:
Proof of your identity (including passport information)
Proof of your qualifications
Pre-employment health questionnaire
Right to work
We may also look at your professional background on relevant platform and network sites such as LinkedIn.
If we make and you accept a final offer
We will require further information from you in order to meet our obligations as an employer/contractor, such as your bank details so that we can pay your salary and your emergency contact details so that we know who to contact in case of emergency. How we process your information as an employee/contractor is set out in our Staff Privacy Notice which you will have access to when you start your employment.
Personal information provided by third parties
Most of the personal data we process about you when you apply for a role is information that you give us directly, or is generated through the recruitment exercise. However, some information we gather from the third parties below:
Yourformer employer and other referees: When we make you a conditional offer, we will contact your referees directly, using the details you provide in your application, to request a reference;
Psychometric test agency: You will be required to take psychometric tests during the assessment stage. The test provider, SHL Group Limited, will send us your responses, score and any other analysis that they carry out based on your responses.
Recruitment Agencies:We fill some of our roles through recruitment agencies. If you apply for a role through them, they will pass us details of your name, contact details, CV, notes of interview with the agency
We use your personal datafor the purposes listed in the table below. We are allowed to do so on certain legal grounds which are also set out in the table below (and which are explained further in the section 'Legal grounds for processing personal data').
Type of data
Why do we need it?
Legal grounds for processing
Contact details (name, email address, telephone number, home address)
So that we can contact you about your application for a role with us
Education and employment history, and proof of qualifications
So that we can assess your relevant experience and suitability for a role with us, and assess what your training needs would be if you started working for us
Information provided by professional and personal referees
So that we can assess your relevant experience and suitability for a role with us
Information generated during the recruitment process itself (such as interview notes, psychometric test results and your answers to assessment questions)
So that we can assess your relevant experience and suitability for a role with us Psychometric tests help us understand your characteristics and working-style preferences
Information about your regulatory or other professional memberships
So that we can comply with our legal obligation (and obligation to our professional insurers) to make sure that individuals carrying out certain regulated roles are appropriately registered.
So that we can assess your relevant experience and suitability for a role with us (where this is relevant for certain senior roles where there is no legal requirement to be registered with a regulator).
Compliance with a legal obligation
Special categories of personal data and criminal offences data
Type of data
Why do we need it?
Legal grounds for processing
Identity documents such as a copy of your passport (including information about your national origin) or other right to work documentation
So that we can comply with our obligation to check that our employees have the right to work in the UK
Necessary for complying with our legal obligations as an employer
Information provided in our Equal Opportunities Monitoring form (such as information about your sexual orientation, racial origin and religion or belief). Optional except for Northern Ireland where religious beliefs are mandatory
In order to promote and monitor diversity in our recruitment process.
Information gathered for these purposes will be used anonymously for the purposes of assessing diversity statistics across the organisation, and will not be used as a basis for making any decisions about you. If you choose not to provide this information (or later decide you would like us to delete information you have already provided for this purpose), this will have no bearing on your application or employment with us.
In Northern Ireland it is a legal obligation to know the religious beliefs of employees in certain roles and we have to report on this annually to the Equality Commission for Northern Ireland.
Necessary for reasons of substantial public interest (Northern Ireland only – legal obligation)
Information about a disability which may affect the application process
To make reasonable adjustments to our application process for your disability
Necessary for complying with our legal obligations as an employer
Pre-employment health data
To determine whether you are medically able to carry out the work you have been offered, and to assess whether any adjustments are needed to the work environment to enable you to carry out that work
Necessary for complying with our legal obligations as an employer
Necessary for assessing your working capacity as an employee
We have set out below a description about each of the legal grounds on which we process your personal data.
Reasons for processing your personal data
Necessary for our legitimate interests:We process some personal data if doing so is in our legitimate interests as an employer. In order to do so, we have considered the impact on your interests and rights, and have put in place appropriate safeguards to ensure that the intrusion on your privacy is reduced as much as possible. You have the right to object to the processing of your personal data on this ground. See section headed'Your Rights' to found out how.
Necessary for the compliance of a legal obligation:We have to process some of your personal data in order to comply with certain of our legal obligations.
Additional conditions for processing special categories of data
Necessary for compliance with our obligations under employment law:We have to process some of your special categories ofdata in order to comply with certain legal obligations.
Necessary for substantial public interest:The law allows us to process certain special categories of data where there is a substantial public interest. You have the right to object to the processing of your personal data on this ground. See section headed'Your Rights' to found out how.
Necessary for the purposes of occupational medicine, including the assessment of your working capacity as an employee:We will process information about your health in order to assess your medical capacity to perform the role you have applied for.
Necessary to establish, exercise or defend legal claims: we may need to process special categories of data in order to exercise our legal rights and bring or defend claims.
The table below lists some of our key service providers that act as our processors who will have access to your personal data. If you would like to know the names of our other service providers who provide typical services required by all companies to support our business (e.g. website hosting, IT support, hard copy mailing providers), please contact us using the details at the start of this Privacy Notice.
SAP UK Limited - Success Factors (Hovis HR system)
Google LLC (formerly known as Google Inc.), Google Ireland Limited, Google Commerce Limited, Google Asia Pacific Pte. Ltd or Google Australia Pty Ltd (as applicable) – General corporate email, document storage, corporate directory and messaging service provider
In addition, we share your personal data with the following entities who act as separate controllers of your personal data. You should review their privacy notices to find out how they process your personal data. If you have any queries or complaints about how they process your personal data by them, please contact them separately using the contact information provided on their website.
We will also share your personal data with the police, other law enforcements or regulators where we are required by law to do so.
SHL Group Limited – Psychometric test provider
Staffline Group Plc – Recruitment Agency. We also use other recruitment agencies from time to time. You can ask us for a full list.
Transfers of your personal data outside the EEA
We need to transfer your personal data to Google LLC, for the provision of its services (such as corporate email service) to Hovis. As Google LLC is located in a country outside the European Economic Area, any transfer of your data will be carried out in accordance with the Data Protection Laws to safeguard your privacy rights and give you remedies in the unlikely event of a security breach or to any other similar approved mechanisms. If you want to know more about how personal data is transferred, please contact us using the details in the section headed "How to Contact Us”
How we keep your personal data secure
We strive to implement appropriate technical and organisational measures in order to protect your personal data against accidental or unlawful destruction, accidental loss or alteration, unauthorised disclosure or access and any other unlawful forms of processing. We aim to ensure that the level of security and the measures adopted to protect your personal data are appropriate for the risks presented by the nature and use of your personal data. We follow recognised industry practices for protecting our IT environment and physical facilities.
If your application for a role with us is unsuccessful or you do not accept our offer of employment, then we will delete all of the personal data gathered during the recruitment exercise1 year after the relevant recruitment exercise has ended.
If your application for a role with us is successful and you start work as our employee/contractor, please see the Staff Privacy Notice for details of how long we will retain the data gathered during the recruitment exercise. If you apply for a new role with us when you are already our employee/contractor, this Privacy Notice applies in respect of any new information gathered during that application process, and the Staff Privacy Notice continues to apply in respect of any information we already hold by virtue of you being a current employee/contractor.
As a data subject, you have the following rights under the Data Protection Laws:
Right to object to processing of your personal data;
Right of access to personal data relating to you (known as data subject access request);
Right to correct any mistakes in your personal data;
Right to prevent your personal data being processed;
Right to erasure;
Rights in relation to automated decision-making; and
Right to have your personal dataported to another controller (note not relevant).
These rights are explained in more detail below. If you want to exercise any of your rights, please contact us (please see "How to contact us").
We will respond to any rights that you exercise within a month of receiving your request, unless the request is particularly complex, in which case we will respond within three months.
Please be aware that there are exceptions and exemptions that apply to some of the rights which we will apply in accordance with the Data Protection Laws.
Right to object to processing of your personal data
You may object to us processing your personal data where we rely on a legitimate interest as our legal grounds for processing.
If you object to us processing your personal data we must demonstrate compelling grounds for continuing to do so. We believe we have demonstrated compelling grounds in the section headed "Why do we need your personal data". The key point to note is that without processing your data, we will not know as much about you which could affect our assessment of your suitability for a job with us.
Right to access personal data relating to you
You may ask to see what personal data we hold about you and be provided with:
a copy of the personal data;
details of the purpose for which the personal data is being or is to be processed;
details of the recipients or classes of recipients to whom the personal data is or may be disclosed, including if they are overseas and what protections are used for those oversea transfers;
the period for which the personal data is held (or the criteria we use to determine how long it is held);
any information available about the source of that data; and
whether we carry out an automated decision-making, or profiling, and where we do information about the logic involved and the envisaged outcome or consequences of that decision or profiling.
To help us find the information easily, please provide us as much information as possible about the type of information you would like to see.
Right to correct any mistakes in your information
You can require us to correct any mistakes in your information which we hold. If you would like to do this, please let us know what information is incorrect and what it should be replaced with.
Right to restrict processing of personal data
You may request that we stop processing your personal data temporarily if:
you do not think that your data is accurate. We will start processing again once we have checked whether or not it is accurate;
the processing is unlawful but you do not want us to erase your data;
we no longer need the personal data for our processing, but you need the data to establish, exercise or defend legal claims; or
you have objected to processing because you believe that your interests should override our legitimate interests.
Right to erasure
You can ask us to erase your personal data where:
you do not believe that we need your data in order to process it for the purposes set out in this Privacy Notice;
if you had given us consent to process your data, you withdraw that consent and we cannot otherwise legally process your data;
you object to our processing and we do not have any legitimate interests that mean we can continue to process your data; or
your data has been processed unlawfully or have not been erased when it should have been.
Rights in relation to automated decision making
In relation to the automated decision making that we carry out, you have the right to obtain human intervention from us, to express your views on the decision made and to contest the decision.
Right to data portability (note not relevant)
In some scenarios, you may ask for an electronic copy of your personal data which we hold electronically or you can ask us to provide this directly to another party. This right does not apply as we do not process your personal data based on your consent or on a contract with us.
It is important that you ensure you have read this Privacy Notice - and if you do not think that we have processed your data in accordance with this notice - you should let us know as soon as possible. You may also complain to the ICO. Information about how to do this is available on his website at www.ico.org.uk.