Processing of (personal) data by the entity in charge of the online application process
Reading aid
Data protection information for applicants
Information on data protection regarding our processing of applicant data in accordance with Articles 13, 14 and 21 of the General Data Protection Regulation (GDPR)
1. Controller responsible for data processing and contact detailsResponsible body within the meaning of data protection law
GESIS – Leibniz-Institut für Sozialwissenschaften e.V.
Team Personal
B6, 4-5
68159 Mannheim
Telefon: 0621 1246 0
E-Mail: info@gesis.org
HEC Harald Eul Consulting GmbH
Datenschutzbeauftragter GESIS
Auf der Höhe 34
50321 Brühl
HEC-DSB-E-Mail: GESIS-Datenschutz@he-c.de
2. Purposes and legal basis on which we process your data
We process personal data in accordance with the provisions of the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and other applicable data protection regulations. Details in the following. Further details or additions to the purposes of data processing can be found in the respective contract documents, forms and other information provided to you.
2.1 Purposes for the fulfillment of a contract or pre-contractual measures (Art. 6 para. 1 b GDPR)
Your personal data is processed for the purpose of handling your application for a specific job advertisement or as an unsolicited application, and in this context in particular for the following purposes: examination and assessment of your suitability for the vacancy, performance and behavior assessment to the extent permitted by law, if necessary for registration and authentication for application via our website, if necessary, for the creation of the employment contract, verifiability of transactions, orders and other agreements, as well as for quality control through appropriate documentation, measures to fulfill general due diligence obligations, statistical evaluations for corporate and personnel recruitment management, travel and event management, travel booking and travel expense accounting, Administration of authorizations and ID cards, cost recording and controlling, reporting, internal and external communication, billing and tax assessment of company services (e.g. canteen meals), billing via company credit card, occupational health and safety, contract-related communication (including appointments) with you, assertion of legal claims and defense in legal disputes; ensuring IT security (including system and plausibility tests) and general security, including building and facility security, safeguarding and exercising domiciliary rights by means of appropriate measures such as video surveillance to protect third parties and our employees and to prevent and secure evidence in the event of criminal offences; ensuring the integrity, prevention and investigation of criminal offences; authenticity and availability of data, control by supervisory bodies or control instances (e.g. internal audit).
2.2 Purposes in the context of a legitimate interest of us or third parties (Art. 6 para. 1 f GDPR)
Beyond the actual fulfillment of the (preliminary) contract, we may process your data if it is necessary to protect our legitimate interests or those of third parties. Your data will only be processed if and to the extent that no overriding interests on your part speak against such processing, in particular for the following purposes: measures for the further development of existing systems, processes and services; comparisons with European and international anti-terrorism lists as well as further fraud or abuse prevention measures, insofar as these go beyond legal obligations; enrichment of our data, including by using or researching publicly available data as far as necessary; benchmarking; development of scoring systems or automated decision-making processes; building and facility security (e.g. through access controls and video surveillance), insofar as this goes beyond general due diligence; internal and external investigations, security checks.
2.3 Purposes within the scope of your consent (Art. 6 para. 1 a GDPR)
Your personal data may also be processed for certain purposes (e.g. obtaining references from previous employers or using your data for future vacancies) on the basis of your consent. As a rule, you can revoke this at any time. You will be informed separately about the purposes and the consequences of revoking or refusing consent in the corresponding text of the consent.
As a general rule, the revocation of consent is only effective for the future. Processing that took place before the revocation is not affected and remains lawful.
2.4 Purposes for the fulfillment of legal requirements (Art. 6 para. 1 c GDPR) or in the public interest (Art. 6 para. 1 e GDPR)
Like everyone who participates in economic life, we are also subject to a variety of legal obligations. Primarily, these are legal requirements (e.g. the German Works Constitution Act, the German Social Security Code, commercial and tax laws), but also, where applicable, regulatory or other official requirements (e.g. employers' liability insurance association). The purposes of processing may include the verification of identity and age, fraud and money laundering prevention (e.g. comparisons with European and international anti-terrorism lists), company health management, ensuring occupational safety, fulfilling tax control and reporting obligations, and archiving data for the purposes of data protection and data security, as well as for the purposes of audits by tax consultants/auditors, tax and other authorities. Furthermore, the disclosure of personal data may be required as part of official/judicial measures for the purpose of gathering evidence, criminal prosecution or the enforcement of civil claims.
Insofar as it is necessary for the contractual relationship with you and for the application you have submitted, we may process data that we have legitimately received from other sources or from other third parties. In addition, we process personal data that we have legitimately obtained, received or acquired from publicly accessible sources (such as commercial and association registers, civil registers, the press, the internet and other media), insofar as this is necessary and we are permitted to process this data in accordance with legal requirements.
Relevant personal data categories may include, in particular,
- Address and contact data (registration and comparable data, such as email address and telephone number)
- Information about you on the internet or in social networks
- Video data
4. Recipients or categories of recipients of your data
Within our company, your data is received by those internal departments or organizational units that require it to fulfill our contractual and legal obligations (such as managers and line managers who are looking for a new employee or are involved in the decision on filling a position, accounting, company doctor, occupational safety, employee representatives, if applicable, etc.) or in the context of processing and implementing our legitimate interest. Your data will be passed on to external parties only
- to process your application for a specific job vacancy or as an unsolicited application to employees of affiliated companies, insofar as they are involved in or support the decision to fill the position (see section 2.1).
- for purposes for which we are obliged or entitled to provide information, report or pass on data in order to comply with legal requirements (e.g. tax authorities) or where the disclosure of data is in the public interest (see section 2.4);
- to the extent that external service providers process data on our behalf as processors or function providers (e.g. credit institutions, external data centers, travel agencies/travel management, printing companies or data disposal companies, courier services, postal services, logistics);
- due to our legitimate interest or the legitimate interest of the third party for the purposes mentioned in section 2.2 (e.g. to authorities, credit agencies, lawyers, courts, experts, affiliated companies and committees and control bodies);
- if you have given us permission to transfer the data to third parties.
5. Duration of the storage of your data
We process and store your data in principle for the duration of your application. This also includes the initiation of a contract (pre-contractual legal relationship).
In addition, we are subject to various retention and documentation obligations, which arise, among other things, from the German Commercial Code (HGB) and the German Fiscal Code (AO). The periods for retention and documentation specified there are up to ten years beyond the end of the contractual relationship or the pre-contractual legal relationship. Your application documents will be destroyed after 180 days if you are not hired. Electronic data will be anonymized accordingly after 180 days. If we wish to store your data for a longer period for future vacancies or you have placed your data in an applicant pool, the data will be deleted at a later date; you will be informed of the details in connection with the respective process.
If the data is no longer required for the fulfillment of contractual or legal obligations and rights, it will be deleted on a regular basis, unless its further processing – for a limited period of time – is necessary to fulfill the purposes listed under point 2.2 due to an overriding legitimate interest of our company. Such an overriding legitimate interest exists, for example, if deletion is not possible or only possible with disproportionately high effort due to the special type of storage. In these cases, we may also store your data for a period compatible with the purposes agreed, and use it to a limited extent if necessary, even after our contractual relationship has ended. In principle, in these cases, deletion is replaced by a restriction of processing. In other words, the data is blocked from the usual use by appropriate measures.
6. Talent pool
If we are unable to consider you for the position for which you have applied, we may contact you to ask whether we can include you in our talent pool.
We will contact you by email for this purpose. If you agree, we will include your data in the talent pool and consider you for new, suitable job postings. This does not happen automatically; we will contact you and inform you each time you are considered. You can object to being considered. Your data will remain in our pool for 180 days after the application process has ended. The data will then be anonymized.
7. Processing of your data in a third country or by an international organization Data will be transferred to recipients in countries outside the European Economic Area EU/EEA (so-called third countries) if it should be necessary for the performance of a contractual obligation towards you (e.g. applying for a job abroad), or if it is in the legitimate interest of us or a third party, or if you have given us your consent.
In this case, your data may also be processed in a third country in connection with the involvement of service providers for the purpose of order processing. If the EU Commission has not issued a decision regarding an adequate level of data protection in the country concerned or for specific sectors in a third country, appropriate contracts (such as EU standard contracts) and additional measures may be used as a basis for the transfer. Information on the appropriate or suitable guarantees and on how to obtain a copy of them can be requested from the company data protection officer.
Under certain conditions, you can assert your data protection rights against us.
Every data subject has the right of access under Article 15 of the GDPR, the right to rectification under Article 16 of the GDPR, the right to erasure under Article 17 of the GDPR, the right to restriction of processing under Article 18 of the GDPR and the right to data portability under Article 20 of the GDPR. The restrictions according to §§ 34 and 35 BDSG apply to the right of access and the right of deletion. In addition, there is a right of appeal to a data protection supervisory authority (Art. 77 DS-GVO in conjunction with § 19 BDSG).
Your requests to exercise your rights should, if possible, be addressed in writing to the above address or directly to our data protection officer.
9. Scope of your obligations to provide us with your data
You are only required to provide the data that is necessary for the processing of your application or for a pre-contractual relationship with us or that we are legally obliged to collect. Without this data, we will generally not be able to continue the application and selection process. If we request additional data from you, you will be informed separately about the voluntary nature of the information.
10. Existence of automated decision-making in individual cases (including profiling)
We do not use any purely automated decision-making processes in accordance with Article 22 of the GDPR. If we do use such a process in individual cases in the future, we will inform you of this separately, provided that this is required by law.
Information about your right to object Art. 21 GDPR 1. You have the right to object at any time to the processing of your data based on Art. 6 (1) f GDPR (data processing based on a balancing of interests) or Art. 6 (1) e GDPR (data processing in the public interest). However, this requires that there are reasons for your objection that arise from your particular personal situation. This also applies to profiling based on this provision within the meaning of Art. 4 No. 4 GDPR. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that outweigh your interests, rights and freedoms, or the processing is for the purpose of enforcing, pursuing or defending legal claims. You can, of course, withdraw your application at any time. 2. We do not plan to use your personal data for direct marketing purposes. Nevertheless, we must inform you that you have the right to object to advertising at any time; this also applies to profiling insofar as it is associated with such direct marketing. We will take this objection into account for the future. The objection can be made informally and should preferably be addressed to GESIS – Leibniz-Institut für Sozialwissenschaften e.V. Team Personal B6, 4-5 68159 Mannheim |