Privacy Policy

CSM Baltija
GDPR/Privacy Policy

Important Notice: If you are on this page (www.csmlv.com) because you wish to access our current and valid GDPR/GDPR/Privacy Policy.

Introduction

How to Use This GDPR/Privacy Policy

Context-Specific Privacy Information

This section of the GDPR/Privacy Policy applies to Candidates.

Candidates include individuals with whom CSM Baltija has not had prior contact, but whom CSM Baltija reasonably considers would be interested in, or might benefit from, CSM Baltija services and being considered for any roles advertised or promoted by CSM Baltija including permanent, part-time and Temporary positions and freelance roles with CSM Baltija Clients (including those individuals who want to become Temporary Workers). Candidates also include applicants for such roles as well as people who have supplied a speculative CVs to CSM Baltija not in relation to a specific job and/or who have engaged with CSM Baltija about CSM Baltija services and/or any roles advertised or promoted by CSM Baltija . Individual contractors, freelance workers and employees of suppliers or other third parties put forward for roles with CSM Baltija Clients as part of a Managed Service Provider offering or otherwise will be treated as Candidates for the purposes of this GDPR/Privacy Policy.

What kind of personal information do we collect?

So, you're looking for a bit more insight into what data we collect about you? Here's a more detailed look at the sorts of information that we will collect. The information described below is, of course, in addition to any personal data we are required by law to process in any given situation.

Depending on the relevant circumstances and applicable local laws and requirements, we will collect some or all of the information listed below to enable us to assess how we can assist you if we reasonably believe you might be interested in, or might benefit from our services, and to offer you employment opportunities which are tailored to your circumstances and your interests.

In some jurisdictions, we are restricted from processing some of the data outlined below. In such cases, we will only process the data in those jurisdictions to the extent and under the circumstances permitted by law:

Please note that the above list of categories of personal data we collect is not exhaustive.

To the extent that you access our website or click through any links in an email from us, we will also collect certain data from you. If you would like more information about this, please refer to the context-specific section of this GDPR/Privacy Policy that applies to Website Users.

How do we collect your personal data?

We collect Candidate personal data in the following ways:

Personal data you give to us

as described in the section entitled “What Kind of Personal Information Do We Collect?” above.

Personal data we receive from other sources

Personal data we collect automatically

How do we use your personal data?

We generally use Candidate data in five ways:

Pre-recruitment Activities

Why and how we process your information

Types of personal data used

Legal basis relied upon

Collecting and processing data in the course of and to the extent necessary to work out whether you might be interested in or benefit from recruitment services, including by:

  • collecting data from Candidates and other sources, such as LinkedIn
  • storing Candidates’ details on databases
  • assessing data against vacancies
  • Key identification and contact information
  • Education and employment information
  • Additional information that you choose to tell us
  • Information that others provide about you
  • Automatically collected information

Legitimate interests, namely it is in our interests and your interests for us to assess whether you may be interested in or benefit from our recruitment services

Collecting and processing your data in the course of reviewing your information to ascertain how CSM Baltija recruitment services may assist

  • Key identification and contact information
  • Additional information that you choose to tell us

Legitimate interests, namely it is in our interests and your interests for us to identify how we can help you with your job search

Collecting and processing your data in the course of communicating with you in relation to CSM Baltija recruitment services

  • Key identification and contact information
  • Additional information that you choose to tell us

Legitimate interests, namely it is in our interests and your interests to contact and correspond with you as part of providing you with our recruitment services

Recruitment Activities

Why and how we process your information

Types of personal data used

Legal basis relied upon

Collecting and processing data in the course of and to the extent necessary to provide recruitment services to Candidates and facilitating the recruitment process including by:

  • Collecting data from Candidates and other sources, such as LinkedIn
  • Storing Candidates' details on database
  • Assessing data against vacancies
  • Sending Candidates' information to Clients, in order to apply for jobs or to assess eligibility for jobs
  • Enabling Candidates to submit CVs, apply online for jobs or to subscribe to alerts about jobs
  • Recording Candidates' question and answer sessions and/or video interviews to support our recruitment services (with the recordings being analyzed for training/monitoring purposes and/or shared with Clients and viewed via a secure third-party platform)
  • Making video recordings of Candidates' participation in training sessions or meetings for internal training/monitoring purposes and/or monitoring internal compliance standards
  • Key identification and contact information
  • Education and employment information
  • Additional information that you choose to tell us (e.g. information that you tell us in a recording)
  • Information that others provide about you
  • Video recording footage

We will rely on legitimate interests, namely it is in our interests and your interests for us to provide you with our recruitment services and for you to receive them in order for us to function as a profit-making business, and to help you and other Candidates to find employment

If you have entered or are about to enter into a contract with us or if you are making a request in the course of doing so, we may rely on the performance of a contract legal basis to the extent that the processing activity that we are seeking to conduct is necessary for the purposes of the contract or your request

To the extent that we record a video of you, we will ask for your consent before we start recording but will rely on legitimate interests in relation to our use of the data for training/monitoring and for monitoring compliance standards

Processing Candidates' data to facilitate payroll and invoicing processes

  • Key identification and contact information
  • Education and employment information
  • Financial information

Legitimate interests, namely it is in our interests and your interests to:

  • ensure that our business runs smoothly, so that we can carry on providing services to Candidates like you
  • ensure that you are appropriately remunerated

If you have entered or are about to enter into a contract with us or if you are making a request in the course of doing so, we may rely on the performance of a contract legal basis

Collecting and processing Candidates' data in the course of carrying out:

  • customer satisfaction surveys
  • CSM Baltija market research which we will use to inform our marketing materials and other informational materials such as whitepapers, reports and articles (e.g. our salary guides)

To the extent that any data is published, this will be in aggregated/anonymised form only

  • Key identification and contact information
  • Additional information that you choose to tell us

Legitimate interests, namely it is in our interests to:

  • improve and develop the recruitment services that we provide to you by considering your feedback and feeding this into our processes where we deem necessary
  • gain an insight into the careers, goals and aspirations of the Candidates to whom we provide services in order to market our service offering to help differentiate us in a competitive marketplace

Collecting and processing Candidates' data in the course of communicating with Candidates in relation to services-related issues and providing customer support by processing requests for support

  • Key identification and contact information
  • Additional information that you choose to tell us

We will rely on legitimate interests, namely it is in our interests and your interests to:

  • address any issues that you have been experiencing
  • improve and develop the recruitment services that we provide to you by considering your feedback and feeding this into our processes where we deem necessary

If you have entered or are about to enter into a contract with us or if you are making a request in the course of doing so, we may rely on the performance of a contract legal basis in relation to using your data in the course conducting communications relating to our services with you

Processing Candidates' data to enable them to receive services ancillary to recruitment services, such as participation in:

  • specialist online training
  • interactive features of services
  • recruitment-related services via the CSM Baltija/Columbia Shipmanagement applications and web-sites.
  • Key identification and contact information
  • Additional information that you choose to tell us
  • Information that others provide about you
  • Certain automatically collected information e.g. User choices and information about your use of these services

We will rely on legitimate interests, namely it is in our interests and your interests to:

  • recommend and grant you with access to our specialist online training or some of our more interactive services as this might help with your job search
  • provide you with the best possible end-to-end service and enhance our service offering to you and to help differentiate us in a competitive marketplace

If you have signed up to receive these ancillary services (either separately or because they form part of the recruitment services to which you have already signed up) or if you are making a request in the course of doing so, we may rely on the performance of a contract legal basis to the extent that the processing activity that we are seeking to conduct is necessary for the purposes of the contract or your request

Processing Candidates' data in the course of carrying out CSM Baltija obligations arising from any contracts entered into between CSM Baltija and third parties in relation to Candidates' recruitment, such as potential employers to whom we are committed to identifying the most suitable Candidates for roles in their organizations

  • Key identification and contact information
  • Education and employment information
  • Financial information
  • Information that others provide about you
  • Additional information that you choose to tell us

We will rely on legitimate interests, namely it is in our interests and your interests to fulfil our obligations under agreements with third parties such as potential employers so that we can help you find employment

If you have entered or are about to enter into a contract with us or if you are making a request in the course of doing so, we may rely on the performance of a contract legal basis to the extent that the processing activity that we are seeking to conduct is also necessary for the purposes of our contract with you (as well of the third party)

Verifying details that a Candidate has provided or to request information (such as references, qualifications and potentially any criminal convictions, to the extent that this is appropriate and in accordance with local laws)

  • Key identification and contact information
  • Education and employment information
  • Criminal conviction data
  • Information that others provide about you
  • Additional information that you choose to tell us

For criminal conviction data, we will obtain your explicit consent.

For all other types of data:

  • we will rely on the legitimate interests legal basis, namely it is in our interests and your interests to verify that all of the information that you have provided to us is true and accurate and to obtain references about your prior conduct as part of the process of finding you employment
  • if you have entered or are about to enter into a contract with us or if you are making a request in the course of doing so, we may rely on the performance of a contract legal basis to the extent that verifying details that you have provided or the requests that we need to make are necessary for the purposes of our contract with you.

In certain jurisdictions, using a web-based video identity verification process to verify a Candidate's identity if we do not meet them in person and document this process

  • Key identification and contact information (including a copy of driving license and/or passport/identity card)
  • Additional information that you choose to tell us
  • Video recording footage

To the extent that this is carried out in your jurisdiction, we will ask for your consent before we start recording but rely on the legitimate interests condition (it is in our legitimate interests to maintain internal compliance standards) in relation to our use of the data that we capture to verify your identity.

For more information in relation to your jurisdiction, please do your research on the internet.

Collecting and processing Candidate data in the course of carrying out assessment and development activities such as psychometric evaluations or skills tests - for more information in relation to your jurisdiction, please make your own research on internet.

  • Key identification and contact information
  • Additional information that you provide or choose to tell us during the evaluation/skills test (including in relation to your performance)

Legitimate interests, namely it is in our interests and your interests for us to provide you with the services of our Assessment and Development departments, namely in relation to psychological assessment and research, assessment centers, competency management, reorganization issues, management development, career development, mobility, outplacement, career transition and coaching.

Marketing Activities

Why and how we process your information

Types of personal data used

Legal basis relied upon

Using Candidates' data to carry out marketing activities to promote our services through digital channels including in relation to:

  • marketing our full range of recruitment services (permanent, Temporary, contract, outplacement, other programmes and services to you
  • sending Candidates details of reports, promotions, offers, networking and client events, and general information about the industry sectors which we think might be of interest to them
  • providing Candidates with information about certain discounts and offers that they are eligible for by virtue of their relationship with CSM Baltija
  • Key identification and contact information
  • Automatically collected information

If we have obtained your contact details from an occasion when you previously engaged with us and we are e-marketing other recruitment-related services of our own, we will rely on soft opt-in consent if we consider that the legitimate interests legal basis applies, namely if we wish to reach out to you to tell you about our services and we consider that it would be in your interests to hear about similar services to those that you have already expressed an interest in

In all other circumstances, we will obtain your opt-in consent

Collection of data via cookies or tracking pixels and use of data to show users CSM Baltija adverts and other content on other websites, for example, Facebook, LinkedIn, etc.

  • Key identification and contact information
  • Automatically collected information

We will obtain your consent via the Cookie Preferences link on our website

If you do not want us to use your data in this way, please turn off the “Advertising Cookies” option (please refer to our Cookies Policy)

Even where you have turned off advertising cookies, it is still possible that you may see a CSM Baltija advert, but in this case, it won’t have been targeted at you personally, but rather at an anonymous audience

Please note that if you access CSM Baltija services across multiple devices, you may need to adjust your settings (e.g. if you want to turn off advertising cookies) via the Cookie Preferences link on each of your devices

Lookalike targeting and other data driven marketing: providing lists of certain Candidates' data to Facebook and Google to enable them to find an audience of people with similar characteristics or demographics to these Candidates (which will not include these Candidates) for CSM Baltija marketing purposes.

Facebook's policy is to irreversibly hash such lists prior to use, match the hashed data against their own customers, generate the lookalike audience, then delete the original list and use it for no other purpose. We will not have access to the identity of anyone in the lookalike audience, unless they choose to click on the advertisements.

  • Key identification and contact information
  • Automatically collected information (advertising identifiers)

We will obtain your opt-in consent for the collection of advertising identifiers via the Cookie Preferences link on our website

We will share these advertising identifiers with Facebook and Google in reliance on the legitimate interests legal basis, namely it is in our interests to identify and target advertisements to potential customers who share characteristics or demographics with our existing customers, unless we are required by local law to obtain your consent in which case we will obtain such consent via our consent management tool

Displaying excerpts from Candidates' profiles for promotional purposes on CSM Baltija website(s) to provide examples of success stories

  • Key identification and contact information
  • Education and employment information
  • Additional information that choose to tell us (we may ask you for additional details for the purposes of the story that we tell about you)

We will always ask for your explicit consent before featuring you in this way on the website

Use of Candidates' data in the course of making service and marketing communications via WhatsApp

  • Key identification and contact information
  • Automatically collected information

We will ensure that you have opted-in (and therefore provided your consent) through one of a number of channels:

  • when you signing up to WhatsApp job alerts on the website
  • submitting an opt-in message direct to one of our WhatsApp channels
  • clicking through on a sign-up button on an invite email.

Special category data

Why and how we process your information

Types of personal data used

Legal basis relied upon

Collecting and analyzing Candidates' data in order to assess and ensure our compliance with equal opportunities obligations

Details of racial or ethnic origin, sexual orientation, religious or other similar beliefs, and physical or mental health, including chronic deceases and disability-related information

We will process your personal data in this way if our processing is necessary for the purposes of (and we have a legitimate interest in) keeping under review the existence or absence of equality of opportunity or treatment between groups of people and local laws allow us to process your data in this way without obtaining your consent

If local law requires us to obtain your consent, we will do so

Sharing Candidates' data (that has been collected to assess and ensure our compliance with equal opportunities obligations) with Clients (including to their internal or external auditors) where this is contractually required or the Client specifically requests such information to enable them to comply with their own employment processes

Details of racial or ethnic origin, sexual orientation, religious or other similar beliefs, and physical or mental health, including disability-related information

We will obtain your explicit consent before we share your data in this way

Processing medical history/health-related data to make reasonable adjustments during the recruitment process

Medical history/physical or mental health-related data

We will process your personal data in this way if we have a legitimate interest in and it is necessary for us to process your data for health and social care purposes (e.g. to assess the working capacity of an employee or potential employee for an employer) and local laws allow us to process your data in this way without obtaining your consent

If local law requires us to obtain your consent, we will do so

Processing health-related data to when we need to use or offer occupational health to Candidates in the context of certain types of roles (e.g. teaching, nursing or night work)

Medical history/physical or mental health-related data

We will process your personal data in this way if we have a legitimate interest in and it is necessary for us to process your data for health and social care purposes (e.g. the provision of health care or treatment) and local laws allow us to process your data in this way without obtaining your consent

If local law requires us to obtain your consent, we will do so

Processing health-related information arising from or in connection with the COVID-19 or other pandemics where this is required for a role that you are interested in applying for or where volunteered by you

Test results (whether positive or negative), or vaccination history (including medical conditions relating to or affecting vaccination) where appropriate

We rely on legitimate interests, namely it is in our and your interests for us to collect and share your health-related information if this is required for a role that you are interested in applying for

We may also rely on the vital interests and the public interest lawful bases, namely to protect against serious cross-border threats to health

We may process your health and travel-related information pursuant to Article 9(2)(i) of the GDPR to enable us to process health-related information arising from or in connection with the COVID-19 pandemic to prevent the spread of and assess the risk of COVID-19 and other infectious viruses and diseases

If local law requires us to obtain your consent, we will do so

Processing criminal convictions data when carrying out background checks

Details of any criminal convictions disclosed by Candidate on the Candidate Application Form

Details of any criminal convictions obtained via background checks that we are required to carry out where this is necessary for us to comply with our legal obligations in connection with a Candidate's search for work (e.g. if we put a Candidate forward for certain roles which require a certain type of background check to be carried out)

We will obtain your explicit consent in the Candidate Application Form though where local laws allow us to do so, we may need to request a Disclosure and Barring Service Check (or equivalent applicable check in your jurisdiction) without your consent where this is necessary for us to comply with our legal obligations in connection with your search for work

Processing certain types of Candidate data in order to calculate entitlement to annual leave

Medical history/health-related data

Religious affiliation

We will process your personal data in this way if our processing is necessary for the purposes of (and we have a legitimate interest in) carrying out the obligations and exercising CSM Baltija specific rights in the field of employment and social security and social protection law and local laws allow us to process your data in this way without obtaining your consent

If local law requires us to obtain your consent, we will do so

Processing the sensitive/special category personal data of individuals connected with Candidates, for example:

  • where a Candidate discloses this to us in the course of providing next-of-kin details
  • to allow the relevant Candidate to access certain benefits

Details of sexual orientation, and physical or mental health, including disability-related information

We will process your personal data in this way if our processing is necessary for the purposes of (and we have a legitimate interest in) carrying out the obligations and exercising CSM Baltija specific rights in the field of employment and social security and social protection law and local laws allow us to process your data in this way without obtaining your consent

If local law requires us to obtain your consent, we will do so

To help us to establish, exercise or defend legal claims

Why and how we process your information

Types of personal data used

Legal basis relied upon

Preserving, sharing and otherwise processing Candidate data to establish, exercise or defend legal claims

The actual information used depends on the factual circumstances, but could include any of the following:

  • Key identification and contact information
  • Education and employment information
  • Special category information
  • Criminal conviction data
  • Automatically collected information
  • Information that others provide about you
  • Additional information that you choose to tell us

Legitimate interests, namely it is in our interests to seek and receive legal advice should we need it and to protect ourselves in the context of litigation and other disputes

In the unlikely event that we need to process any special category information or criminal conviction data for this purpose, we will only do so where local law allows us to process such data to establish, exercise or defend legal claims

Profiling, Algorithms and Automated Decision Making

Why and how we process your information

Types of personal data used

Legal basis relied upon

Collection of data via personalization cookies/pixels and use of this data for profiling purposes so that we can show Candidates both targeted and personalized content. This will include:

  • personalizing Candidates' website experience, including in relation to the roles that are brought to their attention when visiting the website
  • making recommendations for editorial content that we think may be of interest to Candidates (e.g. reports about developments in their industry)
  • personalizing the marketing content that Candidates receive via the website, email and other marketing channels (where they have consented to that marketing)

These personalization cookies/pixels are used to understand how Candidates engage with the website by recording their visit to the website, the pages they have visited, the interactions they have made and the links they have followed

We will use this information to understand what they may be interested in and tailor what we show and send to them accordingly

  • Key identification and contact information
  • Education and employment information
  • Automatically collected information
  • Additional information that you choose to tell us

More specifically, this will include:

  • Personal information and information about the Candidate's job search (i.e. as submitted via form or pulled through from our Systems)
  • Details of Candidates' interactions with the website (e.g. applications, web page visits), and other information pulled through from the Systems (e.g. job title, past applications)
  • Location data - either inferred from jobs, IP, or application history, or system stored data
  • Digital identifiers - IP address, personalization cookies
  • Website browsing data, form submission data and email engagement data
  • Marketing preferences

We will obtain your consent via the Cookie Preferences link on our website before we place personalization cookies/pixels on your device and enable this functionality

If you do not wish to provide your consent to us placing a personalization cookie on your device, please turn off the “Functionality Cookies” and “Advertising Cookies” options (please refer to our Cookies Policy)

Please note that if you access CSM Baltija services across multiple devices, you may need to adjust your settings via the Cookie Preferences link on each of your devices.

Notwithstanding our collection of consent prior to placing personalization cookies/pixels onto your device, we will rely on the legitimate interests condition in relation to the personalization activities that we subsequently carry out

We consider that it is in our interests (and sometimes your interests) to:

  • increase engagement with and improve the experience of using our services by increasing the relevance of the content that you see across the CSM Baltija websites and email campaigns
  • increase application numbers, conversion rates and application usefulness through providing tailored job recommendations to you
  • encourage you to come back to our website by making this most helpful experience possible
  • reduce website bounce rate
  • increase email engagement rate (i.e. the frequency with which users click through)

We may capture and analyze Candidates' web-based behaviours using various items of data e.g. number of job ads read/applied for online, number and type of articles read, number of web visits made, membership of “talent pools”/segments – see below) in order to award a Candidate a weighted “approachability score” with a view to providing insights into Candidates' needs and to allow CSM Baltija to follow up where needed

Consultants will use these scores as part of the shortlisting and ranking activities described in more detail below and as a factor in determining whether to approach/show roles to a Candidate, which will serve to supplement other data that CSM Baltija holds about the Candidate

Our collection of web-based data will rely on the personalization cookies/pixels that we place on your device as part of the personalization activities as described above

  • Key identification and contact information
  • Education and employment information
  • Automatically collected information
  • Information that others provide about you
  • Additional information that you choose to tell us

We will obtain your consent via the Cookie Preferences link on our website before we place personalization cookies/pixels on your device

If you do not wish to provide your consent to us placing a personalization cookie on your device, please turn off the “Functionality Cookies” and “Advertising Cookies” options (please refer to our Cookies Policy)

Please note that if you access CSM Baltija services across multiple devices, you may need to adjust your settings via the Cookie Preferences link on each of your devices

However, please note that we may still carry out engagement scoring activities even if a personalization cookie is not placed on your device (e.g. we may consider the information that we already hold about you on our Systems with a view to allocating you an engagement score even if you have opted out of the personalization cookie)

Notwithstanding our collection of consent prior to placing personalization cookies/pixels onto your device, we will rely on the legitimate interests condition in relation to allocating you an engagement score and our subsequent use of this score

We consider that it is in our legitimate interests to allocate you with an engagement score in order to help our consultants to make decisions in relation to suggesting relevant roles and sending relevant communications to you

We may use the data that we collect via personalization cookies/pixels e.g. web-based behaviours such as details of Candidates' interactions with the website (e.g. applications, web page visits), to enrich the Candidate data and existing profiles about them that we already hold on our Systems

  • Key identification and contact information
  • Education and employment information
  • Automatically collected information

We will obtain your consent via the Cookie Preferences link on our website before we place personalization cookies/pixels on your device

If you do not wish to provide your consent to us placing a personalization cookie on your device, please turn off the “Functionality Cookies” and “Advertising Cookies” options (please refer to our Cookies Policy)

Please note that if you access CSM Baltija services across multiple devices, you may need to adjust your settings via the Cookie Preferences link on each of your devices

Notwithstanding our collection of consent prior to placing personalization cookies/pixels onto your device, we will rely on the legitimate interests condition in relation to using data that we collect about you to enrich your existing profile on our Systems

We consider that it is in our legitimate interests to enrich the data that we hold about you to help our consultants to make decisions in relation to suggesting relevant roles and sending relevant communications to you

Analyzing Candidates' data by continuously tracking and monitoring their experience and account activity in order to profile them and allocate them to “talent pools” based on their attributes and behaviours (e.g. previous roles, skills, industry experience, location, when a Candidate is willing to work)

Talent pools are used as a means of managing the Candidate database, placing Candidates in roles and marketing to Candidates

The assignment of Candidates to talent pools is a fully automated process and can involve the use of bots

  • Key identification and contact information
  • Education and employment information
  • Automatically collected information
  • Information that others provide about you
  • Additional information that you choose to tell us

Legitimate interests, namely it is in our interests to use profiling methods to place you and your Candidate profile into groups or segments with other Candidates, based on your interests, habits, attributes and/or preferences in order to:

  • help us to optimize the matching of Candidate profiles to roles and improve the effectiveness and efficiency of the recruitment cycle
  • allow us to keep track of whether we have enough suitable Candidates to fulfil our business needs and those of our Clients at all times
  • help our consultants to make decisions in relation to suggesting relevant roles and sending relevant communications to you

We may use profiling methods in relation to Candidates' data so that we can:

  • place them and other suitable Candidates on shortlists for particular roles based on prescribed criteria, which will allow our consultants to identify the most appropriate Candidates for roles in the most efficient manner efficiently; and
  • recommend roles based on how a Candidate's interests, habits, attributes and/or preferences, rank in comparison to other Candidates

Our intention is for any such activities (which might involve using automated processes to profile, select, screen, rank, grade, shortlist and/or put forward Candidates for roles) to complement rather than completely replace the activity of our consultants

  • Key identification and contact information
  • Education and employment information
  • Automatically collected information
  • Information that others provide about you
  • Additional information that you choose to tell us

Legitimate interests, namely it is in our interests to use profiling methods to place you and your Candidate profile into groups or segments with other Candidates, based on your interests, habits, attributes and/or preferences in order to:

  • help us to optimize the matching of Candidate profiles to roles and improve the effectiveness and efficiency of the recruitment cycle
  • help our consultants to make decisions in relation to suggesting relevant roles to you

If these shortlisting and ranking activities amount to Automated Decision Making for the purposes of Article 22 of the GDPR, we will only conduct these activities where we deem this to be necessary for the completion of pre-contractual steps taken at your request. We think it is reasonable to assume that, as a Candidate, you are hoping to enter into an employment contract, and that by using our services you are asking us to take the necessary steps for this purpose. Such steps might include, for example, checking you meet certain requirements for a particular role. If the role is very popular, we may have to check the eligibility of a large number of potential Candidates – we may therefore use automated decision making to filter this pool of Candidates down to a more manageable number.

Compliance with a legal obligation

Why and how we process your information

Types of personal data used

Legal basis relied upon

Accessing, preserving and disclosing Candidates' data if there is a valid legal request from a regulator, law enforcement, authority or if we otherwise have a legal duty to do so

The actual information used depends on the factual circumstances, but could include any of the following:

  • Key identification and contact information
  • Financial information
  • Automatically collected information
  • Education and employment information
  • Information that others provide about you

Compliance with a legal obligation including where:

  • we are in receipt of a court order to disclose information for the purposes of court proceedings in the context of civil and commercial matters
  • we are compelled by law enforcement agencies to provide data in relation to a criminal investigation
  • we need to comply with our obligations under consumer law, for example competition legislation
  • we need to comply with our obligations under companies’ legislation and tax law, for example, to provide details of your remuneration and tax paid
  • we need to comply with our obligations under data protection laws
  • we need to comply with our obligations under employment laws (e.g. those which require us to track the number of hours you have worked)

Preserving and sharing Candidates' data with others including law enforcement agencies and to respond to legal requests when we are not compelled by applicable law but have a good faith belief it is required by law in the relevant jurisdiction

The actual information used depends on the factual circumstances, but could include any of the following:

  • Key identification and contact information
  • Financial information
  • Automatically collected information
  • Information that others provide about you

Even where we are not under a legal obligation to process your data, we will, under certain circumstances, have a legitimate interest in cooperating with law enforcement agencies and other bodies in order to assist, for example, with the prevention and detection of crime

Processing Candidates' data when verifying documents and information requested from and provided by Candidates to prove that they have the right to work in a particular jurisdiction

  • Key identification and contact information (e.g. a copy of your passport and proof of address)
  • Education and employment information (e.g. immigration status and work permit if applicable)
  • Financial information (e.g. social security number or equivalent in your country)

We will process your data where this is necessary for us to comply with our legal obligations in relation to ensuring that you have the right to work in a particular jurisdiction

Sharing of data

Why and how we process your information

Types of personal data used

Legal basis relied upon

Disclosing Candidates' data to the recipients listed in the section entitled “Who do we share your personal data with”, including the transfer, storage and processing of such data outside of the UK/European Economic Area for the purposes listed in the preceding tables

The actual information used depends on the factual circumstances, but could include any of the following:

  • Key identification and contact information
  • Financial information
  • Education and employment information
  • Special category data
  • Criminal conviction data
  • Automatically collected information
  • Information that others provide about you
  • Additional information that you choose to tell us
  • The disclosure is necessary (e.g. to potential employers) to conclude and perform any contracts that we have entered into with you (see section entitled Recruitment Activities above)
  • The disclosure (e.g. to tax, audit, or other authorities) is necessary for the compliance with a legal obligation to which we are subject (see section entitled Compliance with a legal obligation above)
  • The disclosure (e.g. to our professional advisers) is necessary to help us to establish, exercise or defend legal claims
  • We have obtained your consent (e.g. when we share your special category data with Clients (including to their internal or external auditors) where this is contractually required or the Client specifically requests such information to enable them to comply with their own employment processes
  • The disclosure is necessary for health and social care purposes (e.g. to an occupational health specialist to enable the provision of support during the recruitment process if a Candidate suffers from a health condition or disability)
  • The disclosure is necessary for carrying out the obligations and exercising CSM Baltija specific rights in the field of employment and social security and social protection law (e.g. on an intragroup basis when assessing and effecting your entitlement to annual leave/certain benefits)
  • The disclosure is necessary for the purposes of ‘legitimate interests’ pursued by us (as detailed in the tables above)

This section of the GDPR/Privacy Policy applies to Temporary Workers.

Temporary Workers include someone who becomes employed or engaged by CSM Baltija for the purposes of undertaking Temporary work for a Client or other CSM Baltija group company. If you are a Temporary Worker, we will also continue to process your personal data as a Candidate throughout the duration of your Temporary work assignment and thereafter, in accordance with the terms of this GDPR/Privacy Policy. The question of whether and the extent to which the Recruits GDPR/Privacy Policy and the CSM Baltija Staff GDPR/Privacy Policy apply to you as a Temporary Worker depends on local law requirements. For more information in relation to your jurisdiction, please do your own research on the internet. Temporary Relationship means our contractual relationship with Temporary Workers while they are employed or engaged directly by us.

What kind of personal information do we collect?

If we employ or engage you as a Temporary Worker directly, we will, depending on the relevant circumstances and applicable local laws and requirements, collect some or all of the information listed below (in addition to the data collected about Candidates) in order to ensure that our Temporary Relationship runs smoothly and that we are able to comply with our contractual and other duties to each other, and to our Clients, as part of our Temporary Relationship and our duties to third parties such as tax authorities and government agencies. In some jurisdictions, we are restricted from processing some of the data outlined below. In such cases, we will only process the data in those jurisdictions to the extent and under the circumstances permitted by law:

Please note that the above list of categories of personal data we collect is not exhaustive.

A number of elements of the items listed above are required to enable us to fulfil our contractual duties to you or to others. Some, for example your social security number (or equivalent) are required by statute or other laws. Other items may simply be needed to ensure that our Temporary Relationship can run smoothly, or to run our business.

Depending on the type of personal data in question and the grounds on which we may be processing it, should you decline to provide us with such data, we may not be able to fulfil our contractual requirements or, in extreme cases, may not be able to continue with our Temporary Relationship.

How do we collect your personal data?

If we employ or engage you as a Temporary Worker directly, we collect your data (in addition to the data already collected about Candidates) in the following ways:

Below are some more details about each of these methods.

Personal data you give to us

CSM Baltija needs to know certain information about you in order to fulfil our obligations to you, to ensure that you are properly fulfilling your obligations to us, and to ensure that we are both fulfilling our obligations to others. This information will enable us to operate a usual Temporary Relationship, along with all that entails.

There are numerous ways that you can share your information with us in addition to the information you share as a Candidate. Where appropriate and in accordance with any local laws and requirements, these may include:

The types of information that we receive from you in this way include:

as described in the section entitled “What Kind of Personal Information Do We Collect?” above.

Personal data we receive from other sources

We also receive personal data about you from other sources. Depending on the relevant circumstances and applicable local laws and requirements, these may include personal data received in the following situations:

The types of information that we receive about you in this way include:

as described in the section entitled “What Kind of Personal Information Do We Collect?” above.

HOw do we use your personal data?

If we employ or engage you as a Temporary Worker directly, we use your data for the following purposes:

Some more detailed information about the way in which your data is processed can be found in the Recruits GDPR/Privacy Policy. For example, during the on-boarding process with CSM Baltija , Temporary Workers will be treated in a similar way as recruits for CSM Baltija roles and their personal data during the recruitment process for such roles will be processed in the ways described in the Recruits GDPR/Privacy Policy. Depending on the applicable local laws, we appreciate that you are not a 'Recruit' in the sense of that Policy but given that we use the data in a similar way, for the same purposes, we thought you wouldn’t mind having a quick look at that policy if you were interested in a greater level of detail.

The question of whether and the extent to which the Recruits GDPR/Privacy Policy and the Staff GDPR/Privacy Policy apply to you as a Temporary Worker depends on local law requirements. For more information in relation to your jurisdiction, please do your own research on the internet.

Temporary Relationship Activities

Please note that in certain of the jurisdictions in which we operate, we comply with additional local law requirements. For more information in relation to your jurisdiction, please do your own research on the internet.

Why and how we process your information

Types of personal data used

Legal basis relied upon

Collecting and processing data in the course of and to the extent necessary to facilitate the Temporary Relationship, including by:

  • Facilitating payroll and invoicing processes
  • Determining the terms on which Temporary Workers work during the Temporary Relationship
  • Storing Temporary Worker details on database (including start dates and duration of the length of assignment, hours worked during assignments, and (in some jurisdictions) records of any promotions, salary rises or bonuses awarded)
  • Assessing Temporary Workers' performance
  • Giving Temporary Workers feedback in relation to assignments
  • Managing absences
  • Temporary worker information
  • Special category information

If you have entered into a Temporary Relationship with us, we will rely on the performance of a contract legal basis to the extent that the processing activity that we are seeking to conduct is necessary for the purposes of the contract that we have entered into with you

We will otherwise rely on legitimate interests, namely it is in our interests and your interests for us to facilitate the Temporary Relationship

If we need to process your special category data (e.g. details of any sickness absence including health-related information), we will process your personal data in this way if we have a legitimate interest in and it is necessary for us to process your data for health and social care purposes and local laws allow us to process your data in this way without obtaining your consent. If local law requires us to obtain your consent, we will do so.

Sharing of data

Please note that in certain of the jurisdictions in which we operate, we comply with additional local law requirements. For more information in relation to your jurisdiction, please do your own research on the internet.

This section of the GDPR/Privacy Policy applies to Clients.

Clients include our customers, clients, and others to whom CSM Baltija provides services in the course of its business or whom CSM Baltija reasonably considers would be interested in our services. In certain circumstances, CSM Baltija provides services to individual employees who work for Client organizations, such as training courses to teaching staff who work for Clients in the education sector. Please note that in this context, CSM Baltija requires Clients to communicate the relevant parts of this GDPR/Privacy Policy (namely the sections directed at Clients, Visitors and Website Users) to their employees.

What kind of personal information do we collect?

So, you're looking for a bit more insight into what data we collect about you? Here's a more detailed look at the sorts of information that we will collect. The information described below is, of course, in addition to any personal data we are required by law to process in any given situation.

The data we collect about Clients is actually very limited. We generally only need to have your contact details or the details of individual contacts at your organization to enable us to ensure that we can reach out to you about our services, ensure our relationship runs smoothly and in certain circumstances, provide services to your employees. We also hold information relating to your online engagement with Candidate profiles and other material published by CSM Baltija , which we use to ensure that our marketing communications to you are relevant and timely. We may also hold extra information that someone in your organization has chosen to tell us. In certain circumstances, such as when you engage with our Finance and Debt Recovery teams, our calls with you may be recorded, depending on the applicable local laws and requirements. If we need any additional personal data for any reason, we will let you know:

About yourself or individual contacts at your organization, including:

Please note that the above list of categories of personal data we collect is not exhaustive.

To the extent that you access our website or click through any links in an email or text message from us, we will also collect certain data from you. If you would like more information about this, please refer to the Context-Specific section of this GDPR/Privacy Policy that applies to Website Users.

How do we collect your personal data?

We collect Client personal data in the following ways:

Personal data that we receive directly from you

as described in the section entitled “What Kind of Personal Information Do We Collect?” above.

Personal data we receive from other sources

Personal data we collect via our website or through links and emails

How do we use your personal data?

We use Client information for:

Providing our services

Please note that in certain jurisdictions in which we operate, we comply with additional local law requirements. For more information in relation to your jurisdiction, please do your own research on the internet.

Why and how we process your information

Types of personal data used

Legal basis relied upon

Collecting and processing data in the course of and to the extent necessary to reach out to Clients about our services, including by:

  • Storing Client details (and updating them when necessary) on CSM Baltija database, so that CSM Baltija can contact Clients in relation to our services;
  • Keeping records of CSM Baltija conversations and meetings with Clients, so that CSM Baltija can provide targeted services to Clients
  • Key identification and contact information
  • Information that others provide about you
  • Additional information that you choose to tell us

Legitimate interests, namely it is in our interests and your interests:

  • for us to reach out to you about our services in order to provide you or your organization with suitable Candidates, and/or consultancy and advisory services

Collecting and processing data in the course of and to the extent necessary to:

  • provide services to colleagues/employees of CSM Baltija Clients
  • make video recordings of Clients' (and colleagues/employees of Clients) participation in training sessions or meetings for internal training/monitoring purposes and/or maintaining internal compliance standards
  • Key identification and contact information
  • Additional information that you choose to tell us
  • Video recording footage

Legitimate interests, namely it is in our interests and your interests:

  • for us to, in certain circumstances, reach out to your colleagues/employees about our services, such as training courses

To the extent that we record a video of you, we will ask for your consent before we start recording, but will rely on legitimate interests in relation to our use of the data for training/monitoring and for maintaining compliance standards

Collecting and processing Client data in the course of carrying out:

  • customer satisfaction surveys
  • CSM Baltija market research which CSM Baltija will use to inform its marketing materials and other informational materials, such as whitepapers, reports and articles (e.g. CSM Baltija salary guides)

To the extent that any data is published, this will be in aggregated/anonymized form only

  • Key identification and contact information
  • Automatically collected information
  • Additional information that you choose to tell us

Legitimate interests, namely it is in our interests and your interests to:

  • improve and develop the recruitment services that we provide to you by considering your feedback and feeding this into our processes where we deem necessary

Processing Client data in the course of carrying out CSM Baltija obligations arising from any contracts entered into between CSM Baltija and third parties in relation to recruitment, such as potential Candidates who CSM Baltija identifies as suitable for a role in a Client organization

  • Key identification and contact information
  • Information that others provide about you
  • Additional information that you choose to tell us

Legitimate interests, namely it is in our interests and your interests to fulfil our obligations under agreements with third parties such as potential Candidates, so that we can help you find suitable employees

In certain jurisdictions, using a web-based video identity verification process to verify a Client's identity and document this process

  • Key identification and contact information (including a copy of driving license and/or passport/identity card)
  • Additional information that you choose to tell us
  • Video recording footage

To the extent that this is carried out in your jurisdiction, we will ask for your consent before we start recording but rely on compliance with a legal obligation to the extent that we are compelled by applicable law to verify your identity (e.g. in the context of payments services)

For more information in relation to your jurisdiction, please do your own research on the internet.

Collecting and processing Client data in the course of obtaining Candidate references from Clients, and sharing this data with third parties who require these references where appropriate

  • Key identification and contact information
  • Additional information that you choose to tell us
  • Reference about a Candidate

Legitimate interests, namely it is in our interests to obtain Candidate references in the course of carrying out our services, and to verify details they have provided

Marketing Activities

Please note that in certain of the jurisdictions in which we operate, we comply with additional local law requirements regarding marketing activities. For more information in relation to your jurisdiction, please do your own research on the internet.

Why and how we process your information

Types of personal data used

Legal basis relied upon

Processing Client data for the purpose of targeting appropriate marketing campaigns for CSM Baltija services

  • Key identification and contact information
  • Automatically collected information

Legitimate interests, namely if we wish to reach out to you to tell you about our services, and we consider that it would be in your interests to hear about similar services to those that you have already expressed an interest in.

Profiling, Algorithms and Automated Decision Making

Please note that in certain of the jurisdictions in which we operate, we comply with additional local law requirements. For more information in relation to your jurisdiction, please do your own research on the internet.

Why and how we process your information

Types of personal data used

Legal basis relied upon

Collection of data via personalization cookies/pixels and use of this data for profiling purposes so that CSM Baltija can show Clients both targeted and personalized content

This will include:

  • personalizing Clients' website experience, including in relation to the roles that are brought to their attention when visiting the website
  • making recommendations for editorial content that we think may be of interest to Clients (e.g. reports about developments in the relevant industry)
  • personalizing the marketing content that Clients receive via the website, email and other marketing channels (where they have consented to that marketing)

These personalization cookies/pixels are used to understand how Clients engage with the website by recording their visit to the website, the pages they have visited, the interactions they have made and the links they have followed. CSM Baltija will use this information to understand what they may be interested in and tailor what it shows and sends to them accordingly

  • Key identification and contact information
  • Automatically collected information

More specifically, this will include:

  • Personal information and information about the Client's job search (i.e. as submitted via form or pulled through from our Systems)
  • Details of Clients' interactions with the website (e.g. applications, web page visits), and other information pulled through from the Systems (e.g. job title, past applications)
  • Location data - either inferred from jobs, IP, or application history, or system stored data
  • Digital identifiers - IP address, personalization cookies
  • Website browsing data, form submission data and email engagement data
  • Marketing preferences

We will obtain your consent via the Cookie Preferences link on our website before we place personalization cookies/pixels on your device and enable this functionality.

If you do not wish to provide your consent to us placing a personalization cookie on your device, please turn off the “Functionality Cookies” and “Advertising Cookies” options (please refer to our Cookies Policy)

Please note that if you access CSM Baltija services across multiple devices, you may need to adjust your settings via the Cookie Preferences link on each of your devices

Notwithstanding our collection of consent prior to placing personalization cookies/pixels onto your device, we will rely on the legitimate interests condition in relation to the personalization activities that we subsequently carry out

We consider that it is in our interests (and sometimes your interests) to:

  • increase engagement with and improve the experience of using our services by increasing the relevance of the content that you see across the CSM Baltija websites and email campaigns
  • increase application numbers, conversion rates and application usefulness through providing tailored job recommendations to you
  • encourage you to come back to our website by making this most helpful experience possible
  • reduce website bounce rate
  • increase email engagement rate (i.e. the frequency with which users click through)

CSM Baltija may capture and analyze Clients' web-based behaviours using various items of data e.g. number of web visits made, number of candidates searched) in order to award a client a weighted “approachability score” with a view to providing insights into Clients' needs and to allow CSM Baltija to follow up where needed

Consultants will use these scores as part of the shortlisting and ranking activities described in more detail below and as a factor in determining whether to approach/show roles to a client (and what to show them), which will serve to supplement other data that CSM Baltija holds about the Client

CSM Baltija collection of web-based data will rely on the personalization cookies/pixels that it places on Clients' devices as part of the personalization activities described above

  • Key identification and contact information
  • Automatically collected information
  • Information that others provide about you
  • Additional information that you choose to tell us

We will obtain your consent via the Cookie Preferences link on our website before we place personalization cookies/pixels on your device

If you do not wish to provide your consent to us placing a personalization cookie on your device, please turn off the “Functionality Cookies” and “Advertising Cookies” options (please refer to our Cookies Policy)

Please note that if you access CSM Baltija services across multiple devices, you may need to adjust your settings via the Cookie Preferences link on each of your devices

However, please note that we may still carry out engagement scoring activities even if a personalization cookie is not placed on your device (e.g. we may consider the data that we already hold on our systems about you with a view to allocating you an engagement score even if you have opted out of the personalization cookie)

Notwithstanding our collection of consent prior to placing personalization cookies/pixels onto your device, we will rely on the legitimate interests condition in relation to allocating you an engagement score and our subsequent use of this score

We consider that it is in our legitimate interests to allocate you with an engagement score in order to help our consultants to make decisions in relation to suggesting relevant services and sending relevant communications to you

CSM Baltija may use the data that it collects via personalization cookies/pixels e.g. web-based behaviors such as details of Clients' interactions with the website (e.g. applications, web page visits), to enrich the Client data and existing profiles about them that CSM Baltija already holds on its Systems

  • Key identification and contact information
  • Automatically collected information

We will obtain your consent via the Cookie Preferences link on our website before we place personalization cookies/pixels on your device

If you do not wish to provide your consent to us placing a personalization cookie on your device, please turn off the “Functionality Cookies” and “Advertising Cookies” options (please refer to our Cookies Policy)

Please note that if you access CSM Baltija services across multiple devices, you may need to adjust your settings via the Cookie Preferences link on each of your devices

Notwithstanding our collection of consent prior to placing personalization cookies/pixels onto your device, we will rely on the legitimate interests condition in relation to using data that we collect about you to enrich your existing profile on our Systems

We consider that it is in our legitimate interests to enrich the data that we hold about you to help our consultants to make decisions in relation to suggesting relevant services and sending relevant communications to you

Sharing of data

If you would like to see a more detailed list of who we will share your personal data with, please refer to the section entitled “Who do we share your personal data with” in the General Privacy Information section of this GDPR/Privacy Policy. Please note that in certain of the jurisdictions in which we operate, we comply with additional local law requirements. For more information in relation to your jurisdiction, please do your own research on the internet.

Why and how we process your information

Types of personal data used

Legal basis relied upon

Disclosing Clients' data to the recipients listed in the section entitled “Who do we share your personal data with”, including the transfer, storage and processing of such data outside of the UK/European Economic Area for the purposes listed in the preceding tables

The actual information used depends on the factual circumstances, but could include any of the following:

  • Key identification and contact information
  • Automatically collected information
  • Information that others provide about you
  • Additional information that you choose to tell us
  • The disclosure (e.g. to our professional advisers) is necessary to help us to establish, exercise or defend legal claims
  • The disclosure is necessary for the purposes of ‘legitimate interests’ pursued by us (as detailed in the tables above)

To help us to establish, exercise or defend legal claims

Why and how we process your information

Types of personal data used

Legal basis relied upon

Preserving, sharing and otherwise processing Client data to establish, exercise or defend legal claims

The actual information used depends on the factual circumstances, but could include any of the following:

  • Key identification and contact information
  • Automatically collected information
  • Information that others provide about you
  • Additional information that you choose to tell us

Legitimate interests, namely it is in our interests to seek and receive legal advice should we need it and to protect ourselves in the context of litigation and other disputes

This section of the GDPR/Privacy Policy applies to Suppliers.

Suppliers include partnerships and companies (including sole traders), and atypical workers such as independent contractors and freelance workers, who provide services to CSM Baltija . In certain circumstances CSM Baltija will sub-contract the services it provides to Clients to third party suppliers who perform services on CSM Baltija behalf. In this context, suppliers that are individual contractors, freelance workers, or employees of suppliers will be treated as Candidates for data protection purposes. Please note that in this context, CSM Baltija requires Suppliers to communicate the relevant parts of this GDPR/Privacy Policy (namely the sections directed at Candidates) to their employees.

This section of the GDPR/Privacy Policy also applies to other parties with which we have a business or other type of relationship (ranging from investors to charitable organizations).

What kind of personal information do we collect?

We don't collect much data about Suppliers and other third parties with which we conduct a business relationship (e.g. investors) – we simply need to make sure that our relationship runs smoothly. We'll collect the details of contacts within your organization, such as names, telephone numbers and email addresses. In the case of Suppliers, we'll also collect bank details, so that we can pay you. We may also hold extra information that someone in your organization has chosen to tell us. In certain circumstances, such as when a Supplier engages with our Accounting Team, our calls with you may be recorded, depending on the applicable local laws and requirements:

About yourself or individual contacts at your organization, including:

Please note that the above list of categories of personal data we collect is not exhaustive.

To the extent that you access our website or click through any links in an email or text message from us, we will also collect certain data from you. If you would like more information about this, please refer to the Context-Specific section of this GDPR/Privacy Policy that applies to Website Users.

How do we collect your personal data?

We collect Supplier and other third-party personal data in the following ways:

Personal data that we receive directly from you

as described in the section entitled “What Kind of Personal Information Do We Collect?” above.

Personal data we receive from other sources

How do we use your personal data?

Please note that in certain of the jurisdictions in which we operate, we comply with additional local law requirements. For more information in relation to your jurisdiction, please do your own research on the internet.

Why and how we process your information

Types of personal data used

Legal basis relied upon

Storing Supplier and other third-party details (and updating them where necessary) on CSM Baltija database, so that CSM Baltija can contact Suppliers and third parties in relation to CSM Baltija agreements and business relationships with these parties

  • Key identification and contact information
  • Information that others provide about you
  • Additional information that you choose to tell us

Legitimate interests, namely it is in our interests and your interests:

  • for us to reach out to you about the arrangements that we have in place

Collecting and processing data in the course of and to the extent necessary to receive support and services from Suppliers and maintain business relationships with other third parties

  • Key identification and contact information
  • Additional information that you choose to tell us

Legitimate interests, namely it is in our interests and your interests to:

  • for us to, in certain circumstances, receive information from you about your services
  • conduct our business relationship with you

If you are an individual (e.g. a Supplier that operates as a sole trader) or you have entered or are about to enter into a contract with us or if you are making a request in the course of doing so, we may rely on the performance of a contract legal basis

In limited circumstances, we may need to rely on the compliance with a legal obligation legal basis to the extent that we are compelled by applicable law to conduct various checks in relation to our Suppliers and other third parties e.g. in relation to verifying that social contributions are being paid and obtaining lists of overseas employees)

Preserving, sharing and otherwise processing Supplier and third-party data to establish, exercise or defend legal claims

The actual information used depends on the factual circumstances, but could include:

  • Key identification and contact information
  • Information that others provide about you
  • Additional information that you choose to tell us

Legitimate interests, namely it is in our interests to seek and receive legal advice should we need it and to protect ourselves in the context of litigation and other disputes

In certain jurisdictions, using a web-based video identity verification process to verify a Supplier or third party's identity and document this process

  • Key identification and contact information (including a copy of driving license and/or passport/identity card)
  • Additional information that you choose to tell us
  • Video recording footage

To the extent that this is carried out in your jurisdiction, we will ask for your consent before we start recording but rely on:

  • compliance with a legal obligation to the extent that we are compelled by applicable law to verify your identity (e.g. in the context of payments services)
  • the legitimate interests condition to the extent that we are not legally required to verify your identity but it is in our legitimate interests to do so in order to maintain internal compliance standards

For more information in relation to your jurisdiction, please do your own research on the internet.

Sharing of data

Please note that in certain of the jurisdictions in which we operate, we comply with additional local law requirements. For more information in relation to your jurisdiction, please do your own research on the internet.

.

This section of the GDPR/Privacy Policy applies to People Whose Data we receive from Candidates and CSM Baltija Staff. These may include emergency contacts and referees. We will only contact them in appropriate circumstances.

What kind of personal information do we collect and how do we collect it?

All we need from referees is confirmation of what you already know about our Candidate or prospective member of Staff, so that they can secure that job they really want. Emergency contact details give us somebody to call on in an emergency. To ask for a reference, we'll obviously need the referee's contact details (such as name, email address and telephone number). We'll also need these details if our Candidate or a member of our Staff has put you down as their emergency contact so that we can contact you in the event of an accident or an emergency.

We will collect your date of birth, contact details and potentially some health information if a member of our Staff has put you down as a defendant or any other kind of beneficiary for a benefit connected with their employment or if a member of our Staff exercises certain employment rights. We may also be provided (by inference) with some limited information about your sexual orientation if a member of our Staff identifies you as a spouse or partner when putting you down as a defendant, next of kin or emergency contact:

Please note that the above list of categories of personal data we collect is not exhaustive. To the extent that you access our website or click through any links in an email from us, we will also collect certain data from you. If you would like more information about this, please refer to the Context-Specific section of this GDPR/Privacy Policy that applies to Website Users.

How do we use your personal data?

We will only use the information that our Candidates or Staff give us about you for the following purposes:

We will use your personal data for these purposes if we deem this to be necessary for our legitimate interests or in accordance with applicable employment law.

If you are not happy about this, you have the right to object and can find out more about how to do so by referring to the section entitled “How can you access, amend or take back the personal data that you have given to us” in the General Privacy Information section of this GDPR/Privacy Policy.

Please note that in certain of the jurisdictions in which we operate, we comply with additional local law requirements. For more information in relation to your jurisdiction, please click do your own research on the internet.

Why and how we process your information

Types of personal data used

Legal basis relied upon

Collecting and processing data in the course of and to the extent necessary to:

  • respond to accidents and emergencies, including by storing data of people whose data CSM Baltija receives from Candidates and Staff, such emergency contacts and defendants, on database
  • provide employee benefits and pay remuneration, including by storing data of people whose data CSM Baltija receives from Staff and Temporary Workers, such defendants, on database, and sharing these with benefits providers where appropriate
  • Key identification and contact information
  • Additional information that you choose to tell us (e.g. information that you tell us in a recording)
  • Information that others provide about you

Legitimate interests, namely it is in our interests and your interests for us to:

  • have the means to contact you in the event of an accident or emergency;
  • provide any pay or remuneration due to you as part of Staff or Temporary worker benefits

Collecting and processing data of people whose data CSM Baltija receives from Candidates and Staff, such as referees, in the course of communicating with referees in order to obtain Candidate or Staff references, and sharing this data with third parties who require references where appropriate

  • Key identification and contact information;
  • Additional information that you choose to tell us
  • Reference about a Candidate

Legitimate interests, namely it is in our interests to obtain Staff and Candidate references in the course of carrying out our services, and to verify details they have provided

Using the data of people whose data CSM Baltija receives from Candidates and Staff, such as referees, emergency contacts and defendants, to carry out marketing activities to promote CSM Baltija services where CSM Baltija thinks the individual may be interested in becoming a Client (subject to any local laws and requirements)

  • Key identification and contact information

We will obtain your opt-in consent

Sharing of data

Please note that in certain of the jurisdictions in which we operate, we comply with additional local law requirements. For more information in relation to your jurisdiction, please do your own research on the internet.

This section of the GDPR/Privacy Policy applies to Website Users.

Website Users include any individual who accesses any of the CSM Baltija websites or any of the CSM Baltija mobile applications (apps).

What kind of personal information do we collect?

We collect a limited amount of data from our Website Users which we use to help us to improve your experience when using our website or mobile apps and to help us manage the services we provide. This comprises information such as how you use our website or our mobile apps, the frequency with which you access our website or mobile apps, your browser type, your type of device, the location you view our website from, the language you choose to view it in and the times that our website is most popular. If you contact us via the website or the mobile apps, for example by using the chat function, or when you register for one of our newsletters, webinars or participate in any further offer of our website or mobile apps, we will collect any information that you provide to us, for example your name and contact details:

Please note that the above list of categories of personal data we collect is not exhaustive.

How do we collect your personal data?

When you visit our website or mobile apps there is certain information that we will automatically collect, whether or not you decide to use our services namely your IP address, the date and the times and frequency with which you access the website or the mobile apps, the way you browse its content and other technical information. We will also collect data from you when you contact us via the website or the mobile apps, for example by using the chat function or when you register for one of our newsletters, webinars or participate in any further offer of our website or mobile apps.

We collect your data automatically via cookies or similar technology such as tracking pixels and HTML5 Local Storage in line with the cookie settings that you specify via the “Cookie Preferences” link at either the top or bottom of the website, or the settings in your browser. If you are also a Candidate or a Client of CSM Baltija , we will use data from your use of our websites to enhance other aspects of our communications with or service to you. If you would like to find out more about cookies or similar technology, including how we use them and what choices are available to you, please refer to the section entitled “Cookies” in the General Privacy Information section of this GDPR/Privacy Policy.

The types of information that we collect about you in this way include:

as described in the section entitled “What Kind of Personal Information Do We Collect?” above.

How do we use your personal data?

We use your data to:

We will use your personal data for these purposes if we deem this to be necessary for our legitimate interests. If you are not happy about this, you have the right to object and can find out more about how to do so by referring to the section entitled “How can you access, amend or take back the personal data that you have given to us” in the General Privacy Information section of this GDPR/Privacy Policy.

If you would like to find out more about cookies or similar technology, including how we use them and what choices are available to you, please refer to the section entitled “Cookies” in the General Privacy Information section of this GDPR/Privacy Policy.

Please note that in certain of the jurisdictions in which we operate, we comply with additional local law requirements. For more information in relation to your jurisdiction, please do your own research on the internet.

Why and how we process your information

Types of personal data used

Legal basis relied upon

Collecting and processing data in the course of and to the extent necessary to provide Website Users with services they register for, including newsletters and online surveys

  • Key identification and contact information
  • Automatically collected information
  • Additional information that you choose to tell us

We will rely on legitimate interests, namely it is in our interests and your interests for us to provide you with these services and for you to receive them in support of our core business activities relating to recruitment

If you have entered or are about to enter into a contract with us or if you are making a request in the course of doing so, we may rely on the performance of a contract legal basis to the extent that the processing activity that we are seeking to conduct is necessary for the purposes of the contract or your request

We will obtain opt-in consent before sending you any marketing materials

Collection of data via personalization cookies/pixels and use of this data for profiling purposes so that CSM Baltija can show Website Users both targeted and personalized content. This will include:

  • personalizing Website Users' website experience, including in relation to the roles that are brought to their attention when visiting the website
  • making recommendations for editorial content that CSM Baltija thinks may be of interest to Website Users
  • personalizing the marketing content that Website Users receive via the website, email and other marketing channels (where they have consented to that marketing)

These personalization cookies/pixels are used to understand how Website Users engage with the website by recording their visit to the website, the pages they have visited, the interactions they have made and the links they have followed. CSM Baltija will use this information to understand what Website Users may be interested in and tailor what they are shown and sent accordingly.

  • Key identification and contact information
  • Automatically collected information

More specifically, this will include:

  • Personal information and information about the Website Users search (i.e. as submitted via form or pulled through from our Systems)
  • Details of the Website Users' interactions with the website (e.g. applications, web page visits), and other information pulled through from the Systems (e.g. job title, past applications)
  • Location data - either inferred from jobs, IP, or application history, or system stored data
  • Digital identifiers - IP address, personalization cookies
  • Website browsing data, form submission data and email engagement data
  • Marketing preferences

We will obtain your consent via the Cookie Preferences link on our website before we place personalization cookies/pixels on your device and enable this functionality

If you do not wish to provide your consent to us placing a personalization cookie on your device, please turn off the “Functionality Cookies” and “Advertising Cookies” options (please refer to our Cookies Policy)

Please note that if you access our services across multiple devices, you may need to adjust your settings via the Cookie Preferences link on each of your devices

Notwithstanding our collection of consent prior to placing personalization cookies/pixels onto your device, we will rely on the legitimate interests condition in relation to the personalization activities that we subsequently carry out

We consider that it is in our interests (and sometimes your interests) to:

  • increase engagement with and improve the experience of using our services by increasing the relevance of the content that you see across the CSM Baltija websites and email campaigns
  • increase application numbers, conversion rates and application usefulness
  • encourage you to come back to our website by making the most helpful experience possible
  • reduce website bounce rate
  • increase email engagement rate (i.e. the frequency with which users click through)

To prevent and take measures against fraud, illegal activities, infringement of CSM Baltija rights or interests, or other attacks to CSM Baltija Systems

  • Key identification and contact information
  • Additional information that you choose to tell us
  • Automatically collected information

Legitimate interests, namely:

  • it is in our interests and your interests for us to prevent and take measures against fraud, unauthorized use of our System and other illegal or harmful activity
  • it is in our interests to protect ourselves, you. and others
  • even if we are not under a legal obligation to share or otherwise process your data, we will, under certain circumstances, have a legitimate interest in cooperating with law enforcement agencies, regulators and other bodies

If we are under a legal obligation to share or otherwise process your data, compliance with a legal obligation, for example if we receive a valid legal request from a law enforcement agency, regulator or other body

Sharing of data

If you would like to see a full list of who we will share your personal data with, please refer to the section entitled “Who do we share your personal data with” in the General Privacy Information section of this GDPR/Privacy Policy. Please note that in certain of the jurisdictions in which we operate, we comply with additional local law requirements. For more information in relation to your jurisdiction, please do your own research on the internet.

This section of the GDPR/Privacy Policy applies to Staff Alumni.

Staff Alumni include former members of Staff who have expressed their wish to remain part of CSM Baltija alumni network.

What kind of personal information do we collect?

If you are a former member of Staff and you want to be part of our alumni network, we will collect your name, the contact details that you would like us to use and any other information you would like to provide to us for staying in touch with you. We may also retain certain types of data that we held about you relating to your time with us as a member of Staff:

How do we collect your personal data?

If you are a former member of Staff, we will ask you if you wish to remain part of our alumni network just before your departure. If you are interested, we will ask you to provide your name and contact details to us and give you the option to opt into receiving marketing communications that we think will be of interest to you as one of our alumni.

How do we use your personal data?

If you are a former member of Staff and you want to be part of our alumni network and use our alumni portal, we will use your data to engage and stay in touch with you in order to maintain our relationship with you, including by:

In most cases, we will use your personal data for the purposes below if we deem it necessary to do so for our legitimate interests.

Article 6(1)(f) of the GDPR says that we can process your data where it “is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by the interests or fundamental rights or freedoms of you which require protection of personal data.” If you are not happy about this, you have the right to object and you can find out more about how to do so by referring to the section entitled “How can you access, amend or take back the personal data that you have given to us” in the General Privacy Information section of this GDPR/Privacy Policy.

Please note that in certain of the jurisdictions in which we operate, we comply with additional local law requirements. For more information in relation to your jurisdiction, please do your own research on the internet.

Why and how we process your information

Types of personal data used

Legal basis relied upon

Collecting and processing data in the course of and to the extent necessary to provide Staff Alumni with access to CSM Baltija alumni network, including by storing Staff Alumni details on database

  • Key identification and contact information
  • Education and employment information
  • Additional information that you choose to tell us

Legitimate interests, namely it is in our interests and your interests for us to provide you with access to the alumni network, and relevant resources

Collecting and processing Staff Alumni data in the course of carrying out CSM Baltija opinion polls

To the extent that any data is published, this will be in aggregated/anonymized form only

  • Key identification and contact information
  • Additional information that you choose to tell us

Legitimate interests, namely it is in our interests to:

  • improve and develop the experience that we provide to you considering your feedback and feeding this into our processes where we deem necessary

Collecting and processing Staff Alumni data in the course of communicating with Staff Alumni, including by:

  • Sending Staff Alumni newsletters and reports
  • Inviting Staff Alumni to events
  • Informing Staff Alumni of special vacancies
  • Sending Staff Alumni messages on special occasions
  • Key identification and contact information
  • Additional information that you choose to tell us

We will obtain your consent before using your data for marketing purposes. If you provide consent, you will be entitled to withdraw consent at any time

We will otherwise rely on legitimate interests, namely it is in our interests and your interests to:

  • recommend and grant you with access to our alumni resources and events

Sharing of data

Please note that in certain of the jurisdictions in which we operate, we comply with additional local law requirements. For more information in relation to your jurisdiction, please do your own research on the internet.

This section of the GDPR/Privacy Policy applies to Visitors.

Visitors include individuals who visit our premises but who are not members of our Staff.

What kind of personal information do we collect?

So, you're looking for a bit more insight into what data we collect about you? Here's a more detailed look at the sorts of information that we will collect. The information described below is, of course, in addition to any personal data we are required by law to process in any given situation.

Depending on the relevant circumstances and applicable local laws and requirements, we will collect some or all of the information listed below. In some jurisdictions, we are restricted from processing some of the data outlined below. In such cases, we will only process the data in those jurisdictions to the extent and under the circumstances permitted by law:

Please note that the above list of categories of personal data we collect is not exhaustive.

To the extent that you are visiting our premises as a Candidate, Client, Supplier/other third party or Temporary Worker, please also refer to the relevant Context-Specific section of this GDPR/Privacy Policy which contains information about how we process your data in each of these scenarios in addition to the processing activities set out in this section.

How do we collect your personal data?

We collect Visitor personal data in the following ways:

Personal data you give to us

CSM Baltija needs to know certain information about you in order to provide you with access to its premises.

CSM Baltija will usually collect this information from you upon your arrival at our premises.

The types of information that receive from you in this way include:

as described in the section entitled “What Kind of Personal Information Do We Collect?” above.

Personal data we collect automatically

To the extent that you connect to our Wi-Fi services, or are captured on our CCTV systems, where appropriate and in accordance with any local laws and requirements, we will also collect your data automatically (e.g. via website tracking scripts such as cookies or pixels) or through you providing it to us.

The types of information that collect about you in this way includes the Automatically collected information described in the section entitled “What Kind of Personal Information Do We Collect?” above.

How do we use your personal data?

We generally use Visitor data for Visitor Management purposes.

Visitor Management

Please note that in certain of the jurisdictions in which we operate, we comply with additional local law requirements. For more information in relation to your jurisdiction, please do your own research on the internet.

.

Why and how we process your information

Types of personal data used

Legal basis relied upon

Collecting and processing personal data to the extent necessary to keep a record of Visitors to our premises, including by:

  • Collecting data from Visitors upon arrival
  • Storing Visitor details on our Systems
  • Key identification and contact information
  • Education and employment information
  • Additional information that you choose to tell us

We will rely on legitimate interests, namely it is in our interests to keep a record of all visitors to our premises for visitor management purposes, and to ensure the protection and security of our premises

Collecting health and travel-related special category information to maintain the health and safety of Staff and other Visitors and to prevent the spread of and assess the risk of COVID-19 and other infectious viruses and diseases

  • Special category information

We rely on legitimate interests, namely it is in our interests to protect our business from COVID-19 and other infectious viruses and diseases by monitoring the health and travel background of our visitors. We have to make sure our business runs smoothly and our Staff and other Visitors may be put at risk if we do not implement appropriate measures to ensure that our Visitors pass the appropriate checks.

We may also rely on the vital interests and the public interest lawful bases, namely to protect against serious cross-border threats to health

We may process your health and travel-related information pursuant to Article 9(2)(i) of the GDPR to enable us to process health-related information arising from or in connection with the COVID-19 pandemic or as otherwise applicable to enable us to take steps, where appropriate, to ensure the health and safety of Staff and other Visitors and to prevent the spread of and assess the risk of COVID-19 and other infectious viruses and diseases

Recording and processing images and videos of Visitors captured by CSM Baltija CCTV systems

  • Automatically collected information

We will rely on legitimate interests, namely it is in our interests and your interests to maintain and protect the security of our premises and our Staff and other by preventing and detecting security threats or other criminal or harmful activities

Retaining and processing electronic identification data collected from Visitors and their electronic devices to enable them to access IT services e.g. guest Wi-Fi

  • Key identification and contact information
  • Automatically collected information

We will rely on legitimate interests, namely it is in our interests and your interests for us to provide IT related services on our premises, such as guest Wi-Fi services

Sharing of data

Please note that in certain of the jurisdictions in which we operate, we comply with additional local law requirements. For more information in relation to your jurisdiction, please do your own research on the internet.

Where appropriate and in accordance with local laws and requirements, we generally share your personal data with the following categories of people:

There are also certain categories of people that we share your personal data with if you are a Candidate, Temporary Worker, Person whose data we receive (e.g. a referee) or Staff Alumni.

Candidates:

If you are a Candidate, we may also share your personal data with the following categories of people:

Temporary Workers:

If you are a Temporary Worker, we may also share your personal data with the following categories of people:

People whose data we receive:

If you are a referee of one of our Candidates, we may also share your personal data with the following categories of people:

Staff Alumni:

Candidates:

Temporary Workers:

If you are a Temporary Worker, we will also continue to process your personal data as a Candidate through the duration of your Temporary Relationship and thereafter. The question of whether and the extent to which we will continue to process your personal data as Staff data through the duration of your Temporary Relationship and thereafter depends on local law requirements. For more information in relation to your jurisdiction, please do your own research on the internet.

Website Users:

Other Categories of people:

Please note that in certain of the jurisdictions in which we operate, we comply with additional local law requirements regarding data subject access requests and may refuse your request in accordance with such laws. For more information in relation to your jurisdiction, please do your own research on the internet.

Please note that in certain of the jurisdictions in which we operate, we comply with additional local law requirements regarding data subject right to erasure and may refuse your request in accordance with local laws. For more information in relation to your jurisdiction, please do your own research on the internet.

What's a cookie?

How do we use Cookies?

Hopefully this means less time for you trawling through endless pages and will get you into the employment you want more quickly.

The Cookie Preferences link on our website provides a list of the Cookies we use in your jurisdiction, why we use them and what types of Cookies they are.

How to manage or reject Cookies

Annex 1


How to contact us

Country in which you use CSM Baltija services or supply CSM Baltija with services

CSM Baltija entity responsible for processing the personal data of Website Users

The CSM Baltija entity responsible for processing the personal data of Candidates, Temporary Workers, Clients, Suppliers and Third Parties, People Whose Data We Receive, Website Users, Staff Alumni and Visitors will depend on which of the below companies is the counterparty associated with the relevant arrangement

How you can get in touch with us:

  • to access, amend or take back the personal data that you have given to us;
  • if you suspect any misuse or loss of or unauthorized access to your personal information;
  • to withdraw your consent to the processing of your personal data (where consent is the legal basis on which we process your personal data);

with any comments or suggestions concerning this GDPR/Privacy Policy

How you can get in touch with us to update your marketing preferences

Latvia

CSM Baltija Specialist in marine manning/recruitment and placement

CSM Baltija Specialist in marine manning/recruitment and placement

You can write to us at the following address: Katrinas dambis 20, Business Centre “Katrinas Osta”

5th floor, Riga, 1045 LV, Latvia and//or Data Protection Officer Deniss Vinogradovs

Alternatively, you can contact our Data Protection Officer and data protection team by email at: dataprotection@csmlv.com

You can do it by sending an email to us at: dataprotection@csmlv.com


In the event that more than one of the CSM Baltija entities listed above jointly determines the means and purposes of processing personal data of the types of individuals listed above, the CSM Baltija entities will process such personal data as joint controllers for the purpose of Article 26(1) of the GDPR.

We adhere to the requirements imposed by the GDPR in relation to the establishment of joint controller relationships between CSM Baltija entities.

If you wish to exercise your rights under the GDPR in relation to the processing of your personal data by CSM Baltija entities operating on a joint controller basis, please contact us using the channels set out above.

Annex 2


How to Contact OUR Local LATVIAN Supervisory Authority

Country in which you use CSM Baltija services or supply CSM Baltija with services

Details of your local supervisory authority

LATVIA

Contacts of DVI Authority in Latvia:

pasts@dvi.gov.lv

+371 67223131

Web Site: https://www.dvi.gov.lv/en/contacts-authority

Location

Elijas 17, Riga, LV- 1050

Media

ginta.gailuma@dvi.gov.lv

+371 67686086

Working Hours:e open today 8.00-12.00, 12.30-16.30

  • Monday 8.00-12.00, 12.30-17.00
  • Tuesday 8.00-12.00, 12.30-17.30
  • Wednesday 8.00-12.00, 12.30-16.30
  • Thursday 8.00-12.00, 12.30-16.30
  • Friday 8.00-12.00, 12.30-15.00
  • Saturday Closed
  • Sunday Closed

Annex 3


Country-Specific Variations to our GDPR/Privacy Policy

GDPR/PRIVACY POLICY TOPIC

JURISDICTION

COUNTRY-SPECIFIC LEGAL REQUIREMENT

CSM BALTIJA PROCESSING OF YOUR SENSITIVE PERSONAL DATA

Latvia

Where your personal data are processed in accordance with the fair processing condition relating to our rights and obligations under employment and social security law, this relates to our processing of your personal data which is necessary for compliance with legal obligations (such as ensuring that we pay you statutory sick pay, comply with the statutory employment protections that you enjoy, comply with health and safety laws, and ensure that appropriate National Insurance contributions are made).

CSM BALTIJA PROCESSING OF VIDEO RECORDINGS

Latvia

We may from time-to-time record question and answer sessions and/or video interviews of Candidates to support our recruitment services for you and our work in finding opportunities for Clients. The video recordings shall be shared with Clients and viewed via a secure third-party platform. We may also, at the request of Clients, record presentations by Clients to share with Candidates using the same secure platform. Video recordings will be removed from the third-party platform once they are no longer needed or if a Candidate or Client requests deletion. Video recordings will be retained by CSM Baltija in line with normal CSM Baltija retention policy.

CSM BALTIJA PROCESSING AND SHARING OF REFERENCES

Latvia

We adopt a policy of openness, where possible, in relation to references that referees provide about Candidates.

This means that if a Candidate wishes to see a reference that a referee has provided about them, we will endeavor to comply with the Candidate's request unless the referee objects to us doing so (and we will give the referee the opportunity to object).

As well as sharing references provided by a referee with the Candidate, we will also share references with third parties, such as Clients (e.g. those seeking to employ the Candidate) and third-party providers (e.g. if they request references while conducting an audit of the participants in a crew supply programme) unless the referee objects to us doing so (and we will give the referee the opportunity to object).

ANNEX IV

TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

Description of the technical and organisational measures implemented by the data importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural persons.

  1. Confidentiality
    1. Entrance Control

Measures which are adequate to prevent that unauthorized persons may have access to data processing equipment being used for the handling with personal data:

Alarm System

Protection of Building Funnels

Automatic Access Controllsystem

Chip Cards / Transponder Locksystem

Locking System with Codelockout

Manual Locksystem

Biometric Accesslockout

Video Surveillance of Entries

Photo Sensor/ Motion Sensor

Security Locks

Key regulation (Issuance of keys etc.)

Identity Check at the Reception

Logging of Visitors

Careful Choice of Cleaning Staff

Careful Choice of Guards

Wearing Policy of Entrance Card

  1. Entry Control

Measures which are adequate to prevent that data processing equipment can be used by unauthorized persons:

Classification of User Rights

Creation of User Profiles

Password Assignment

Authentication with biometric Procedures

Authentication with User Name/

Password

Appropriation of User Profiles to IT-Systems

Computer Case Locking

Use of VPI-Technology

Locking of external Interfaces (USB etc.)

Security Locks

Use of Instrusion-Detection-Systems

Encryption of Mobile Data Carriers

Encryption of Smartphone Contents

Use of central Smartphone-Administration Software (e.g. for the external deletion of data)

Use of Anti-Virus-Software

Encryption of Data Carrier in Laptops/ Notebooks

Use of Hardware-Firewall

Use of Software-Firewall

  1. Access Control

Measures which are adequate, that authorized persons having access to the data processing equipment have only access to data to which they are authorized and that personal data cannot be read without authorization, being copies, changed or delete in the course of their handling, use and after their storage.

Creation of an authorization concept

Administration of rights by the system administrator

Reduction of system administrators to a number being necessary

Guideline for pass words, including length of pass words and change of pass words

Logging of access, in particular regarding the entry, change and deletion of data

Safe storage of data carrier

Physical deletion of data carrier before re-use

Proper destruction of data carrier

Use of document shredders or service providers (if possible, with a data protection certification)

Logging of destruction

Encryption of data carrier

  1. Separation Order and Pseudonymisation

Measures which are adequate to ensure that personal data being used for different reasons are handled separately.

Physically separate storage in different systems for data carriers

Logical separation of clients (regarding software)

Creation of an authorization scheme

Codification of data sets which are used for the same reason

Adding of data fields to data sets

For pseudonymous data: separation of the assignment file and storage on a separate, secured IT-system

Determination of rights for database

Separation of test- and production system

The processing of personal data in such a method/way, that the data cannot be associated with a specific Data Subject without the assistance of additional Information, provided that this additional information is stored separately, and is subject to appropriate technical and organizational measures.

  1. Integrity
    1. Control of Transmission

Measures which are adequate, that personal data cannot be read unauthorized, be copied, changed or deleted during the electronic transfer or during the transport of their storage on data carrier, and measures which are adequate to control and determine the transfer of personal data.

Installation of permanent line or VPN-channels

Transfer of personal data in an anonymized or pseudonymized form

e-Mail encryption

Creation of an overview of regular access and transfer actions

Documentation of the recipients of personal data and the time frame of the intended transfer or deletion deadline

In case of physical transport: safe transport packaging

In case of physical transport: careful chose of transport personnel and transport vehicles

  1. Input Control

Measures which are adequate to control and determine retroactively from whom and when personal data have been inserted, changed or deleted:

Logging of entry, change and deletion of data

Creation of an overview showing on which applications personal data have been inserted, changed and deleted

Confirmability of the insertion, change and deletion of personal data by individual user names (not user groups)

Storage of form from which personal data have been taken over by way of automated processing

Granting of rights for the data input, change and deletion on basis of an authorization scheme

  1. Availability and Resilience plus Recovery

Measures which are adequate to ensure that personal data are protected against accidental or willful destruction or loss.

Uninterruptible electrical power supply

Air Conditioning in the server rooms

Control devices for the temperature and the humidity in the server rooms

Protected plug sockets in the server rooms

Fire and smoke alarm

Fire extinguisher in the sever rooms

Alarm system for unauthorized entry in the server rooms

Creation of a backup and recovery concept

Testing of data recovery

Creation of an emergency plan

Storage of data backup at a secure, outsourced place

Server rooms are not located under washrooms

In flood areas: Server rooms are above the waterside border

  1. Procedures for regular testing

Measures which are adequate to ensure a regular testing, assessment and evaluation.

Data Protection Management

Incident Response Management

Data Protection by Design and Default

For transfers to (sub-) processors, also describe the specific technical and organisational measures to be taken by the (sub-) processor to be able to provide assistance to the controller and, for transfers from a processor to a sub-processor, to the data exporter

The data importer shall conduct reasonable due diligence and security assessments of sub-processors, and enter into agreements with sub-processors that contain provisions similar to or more stringent than those detailed above, taking into account the Processing activity carried out by the sub-processor.

Glossary