Recruitment Privacy Notice
Contents
- Introduction
- Link with other Privacy Notices.
- Who we are.
- The data we collect about you.
- Legal basis for processing your personal data.
- Disclosures of your personal data.
- International cross-border data transfers.
- Data security.
- Data retention.
- Your legal rights.
- Changes to the Notice.
- Your duty to inform us of changes.
- Consequences of not providing Personal information to us.
- Providing Mereo with other people’s data.
- Questions.
- Glossary.
- REVISION HISTORY.
1. Introduction
This Privacy Notice (this “Notice”) is made available by Mereo Biopharma Group plc and its affiliated entities (referred to as “Mereo”, “we”, “us” or “our”), and is intended to assist you in understanding how we collect, process, secure, and transfer personal data. We also describe how you can contact us to learn more information about our privacy practices. The terms “you”, “your” or “user” refer to the person applying for a job role with Merio either directly, via a recruitment agency or through a third-party source.
2. Link with other Privacy Notices
If your application become an employee, worker or contractor of Mereo is successful, your personal information will be handled in accordance with Mereo’s Employee Privacy Notice which will be notified to you and is found on Mereo’s intranet.
It is important that you read this Notice together with any other privacy notice that we may provide you with so that you are fully aware of how and why we are using your data. This Notice supplements any other privacy notices and privacy policies that we may provide to you and is not intended to supersede them.
3. Who we are
Mereo Biopharma Group Plc is the Data Controller and is responsible for the processing of your personal data.
4. The data we collect about you
Mereo will collect and may utilize your personal data for the purposes described below:
Category of Data |
Purpose for Data Processing |
Contact details (Example, your name, nationality, postal address, telephone number, e-mail address) |
|
Current and former job titles and positions |
|
Identification information such as passport ID, date of birth, other paper copies of identity |
|
Academic Qualifications Such as copies of certificates |
|
Previous employment references |
|
Right to live/work data |
|
Current/Historic compensation data |
|
Assessment information such as the results of psychometric |
|
Special categories of Personal Data such as detials about your health. |
|
We may use criminal data to verify your suitability for a role with Mereo. If we would like to offer you the role, we will request a basic disclosure of unspent criminal convictions. This information is collected on the basis of our legitimate business interest to satisfy ourselves that there is nothing in your criminal convictions history that makes you unsuitable to work for us. Once the recruitment decision has been made the information collected is destroyed in line with our retention periods.
We will only use any information relating to criminal convictions and offences where the law allows us to. And we have an appropriate policy and safeguards in place when processing such data.
5. Legal basis for processing your personal data
Processing for any of the above purposes is necessary to enable us to pursue our legitimate business interest (or the legitimate interests of one or more of our affiliates) in –
a) personnel recruitment and HR forecasting;
b) the prevention or detection of fraud or abuses in our job application process; and
c) the maintenance of records of business activities around recruitment.
Mereo may also process your personal data for other reasons, as outlined below:
• to comply with legal and regulatory obligations;
• to decide whether to enter into a contract of employment with you.
• to establish, exercise or defend our legal rights and/or for the purpose of (or in connection with) legal proceedings (including for the prevention of fraud); and
• with your consent.
At all times, Mereo will only use your personal data when the law allows us to.
Generally, we do not rely on consent as a legal basis for processing your personal data in circumstances where: (i) the law specifies that we have to process your personal data; (ii) we need to process your data to perform a contract with you; (iii) we have a public interest to do so; or (iv) we have a legitimate business reason for doing so.
Where we do rely on your consent, you have the right to withdraw it any time in the manner indicated when your consent was provided.
6. Disclosures of your personal data
Where necessary to fulfil the purposes described in this Notice, Mereo may disclose your personal data to certain third-parties, vendors and service providers or affiliated employees, contractors and entities as described below.
Whenever Mereo shares your personal data with companies acting as our authorized agents and service providers, these companies agree to use your personal data only for specified purposes. Furthermore, the recipient will implement and maintain reasonable security procedures and practices appropriate to the nature of your information to protect your personal data from unauthorized access, destruction, use, modification or disclosure.
We will transfer and disclose your personal data to the following categories of recipients where it is lawful to do so, and subject to the implementation of appropriate protections:
Category of third party |
Purpose for Disclosure |
Subsidaries and affiliated entities |
|
Recruitment or Human Resource service providers |
|
Background check vendors |
|
Law enforcement, govornment, courts or regulators, or fraud prevention agencies |
|
7. International cross-border data transfers
Mereo operates globally and your data may be transferred outside of the country in which you interact with Mereo, including to countries whose data protection laws substantially differ from the country in which you work or reside. To accomplish the purposes described in this Notice, we may also disclose and transfer personal data to personnel and other departments throughout Mereo. For example, your personal data may be transferred or accessed by Mereo and its affiliate entities in the United States of America.
Whenever we transfer your personal data out of the UK or EEA, we ensure a similar degree of protection is afforded to it by ensuring that at least one of the following safeguards is implemented:
• We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. For further details, see here.
• Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe. For further details, see here or here, for transfers from the United Kingdom.
Please contact us here if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.
8. Data security
Mereo will implement appropriate technical and organizational security measures necessary to adequately safeguard your personal data. These safeguards will include, for example:
Security Measures
- Access to Personal Data is limited and provided only where necessary, to those employees, agents, contractors and other third parties who have a business need to know.
- All employees handling Personal Data receive security and privacy awareness training, will only process your personal data on our instructions and are subject to a duty of confidentiality.
- Employees with access to Personal Data are given the least privilege necessary
- We have robust procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
- A disciplinary policy is enforced to prevent unauthorized access
- Where technically feasible, data is encrypted in transit and at rest
9. Data retention
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements. By law, we have to keep basic information about our clients (including contact, identity, financial and transaction data) for six years after they cease being clients for tax purposes.
In some circumstances you can ask us to delete your data: see your legal rights below for further information.
In some circumstances we will anonymise your personal data (so that it is no longer your personal information as it cannot be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
10. Your legal rights
You may have rights relating to your Personal Data. Depending on the applicable data privacy law, you may have the right to direct Mereo to take certain actions related to your personal data. You may have the right to request confirmation as to whether Mereo is processing your personal data, and if so:
- You may have the right to request information relating to the categories of data involved, purposes of processing, recipients of your data, retention periods/criteria, and your rights as a Data Subject.
- You may have the right to access any of your personal data that Mereo is processing.
- You may have the right to rectify any inaccurate or incomplete personal data that Mereo is processing.
- You may have the right to request erasure or restriction of any personal data that Mereo is processing, subject to certain exceptions.
- You may have the right to obtain a copy of your personal data in a commonly-used and machine-readable format.
- You may have the right to request your information not be sold or otherwise disclosed to a third-party.
- You may have the right to lodge a complaint with your local Data Protection Authority or Supervisory Authority.
To exercise the rights described above, please email [email protected] with a description of your request.
You will not be subject to decisions that will have a significant impact on you based solely on automated decision-making, unless we have a lawful basis for doing so and we have notified you.
11. Changes to the notice
We keep our privacy notices under regular review. This version was last published in March 2023.
We reserve the right, at our discretion, to change, modify, add or remove sections of this Notice at any time. You are encouraged to review this Notice from time to time for updates, or to contact Mereo for more information.
12. Your duty to inform us of changes
It is important that the personal data we hold about you is accurate and current. You are responsible for making sure the information you give us is accurate and up to date. You must tell us if anything changes, as soon as possible.
13. Consequences of not providing personal information to us
Providing your personal data to Mereo is voluntary for you. Should you choose not to provide your personal information to us, your interaction with us may be adversely impacted. Also, the provision of your personal information may be necessary to allow us to perform a contract with you and/or to provide services to you.
14. Providing Mereo with other people's data
If you give us any personal information that does not relate to you (e.g., information about another candidate), you must ensure that you have the required legal basis to collect and share such personal information. You must also tell them what information you have given to us, and make sure they agree we can use it as set out in this privacy notice. You must also tell them how they can see what information we have about them and correct any mistakes.
15. Questions
If you have any questions about this Notice, the use of your data, or if you would like to make a request to exercise your data protection rights, please contact the Data Protection Officer using the details set out below.
Email: [email protected] and mark your query “For the urgent attention of the Data Protection Officer”.
Post: Data Protection Officer, Mereo Biopharma Group Plc, 1 Cavendish Place, London, W1G 0QF, United Kingdom.
You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.
16. Glossary
“Data Controller” means the person or organisation that determines how and why your data is being collected and used.
“Personal data” refers to any information relating to an identified or identifiable natural person, whether that information can be used alone or in conjunction with other information to identify a natural person.
“Aggregated Data” means summarised data derived from your personal data. Examples are statistical or demographic data. It is not considered personal data in law as this data will not directly or indirectly reveal your identity.
“Process” (or “Processing”) means any operation or set of operations which is performed on personal data or sets of personal data, whether by automated means, such as collection, use, and erasure.
Revision History
Effective Version |
Description of changes |
Effective date |
1.0 |
First Version |
07-Mar-2023 |