Avoiding Privacy Issues When Recruiting Staff: 10 Practical Tips
When a potential hire sends you their CV, you will likely collect their personal information. For organisations covered by the Australian Privacy Act (or GDPR or CPRA), this triggers certain legal obligations. For other organisations, it’s still a good practice to have processes and procedures for managing personal information – especially if you want to harness privacy as a competitive advantage.
Australian Privacy Laws: What Employers Should Know
Australia’s Privacy Act, and the Australian Privacy Principles apply to businesses with an annual turnover of $3 million or more, as well as all private health services providers, certain small businesses, and all Australian Government agencies. These employers must comply with the law – even in the context of collecting personal information from candidates.
Organisations that aren’t covered by Australia’s federal privacy law may be covered by state or territory surveillance laws.
It’s also important to be aware of the federal Fair Work Act, which requires all employers to collect and keep certain personal information about their employees.
Protect Your Reputation by Implementing Good Privacy Practices
In 2019, Shell made headlines when it forced job applicants to submit to blood testing and waive privacy rights to be considered. The ABC’s coverage of the story noted that the third-party recruiter required applicants to sign a waiver that allowed them to send their data, medical records, and blood samples overseas – to countries with fewer privacy protections than Australia.
The ABC itself also faced scrutiny and backlash when it required applicants to disclose their gender, age, ethnicity, and disability status in a job advertisement. This sensitive information was not relevant to the position.
This kind of coverage is never good for any organisation. Good privacy practices, including training for your team, can go a long way towards avoiding these situations – and the reputational damage that comes with it.
10 (Quick) Practical Tips for Better Privacy When Hiring Employees
- Let potential employees know about what data will be collected as part of the hiring process at the earliest possible stage – and what happens to that data.
- Don’t collect information you don’t need to make your hiring decision.
- Do not collect sensitive information about your applicants, such as biometrics, unless absolutely necessary.
- Implement appropriate security and processes for managing the data of candidates while you make your hiring decisions. And make sure your processes include deleting the data when you no longer need it.
- Consider your privacy obligations, commitments, or preferences before outsourcing hiring to a third party.
- Provide information in advance about any workplace surveillance.
- Assign ‘applicant privacy’ as an accountability to a team member or department to ensure someone takes ownership of it.
- Train your team so they understand privacy risks that arise during the hiring process (and can respond accordingly if any issues crop up in practice).
Better Data Management with Privacy 108
Wherever you are on your data management maturity path, we can provide the advice, support and implementation assistance you need.
Our data management services include:
- Creating a data management strategy for your organisation.
- Identifying data management visions and objectives.
- Establishing data governance programs including defined roles and responsibilities for ensuring accountability and ownership of data assets.
- Creating data inventories and data flow maps.
- Developing of data management policies and procedures.
- Training and awareness programs.