Thursday 13 August 2009

Data protection

Data protection


My security

I've put a lot of personal information on public display, particularly on this blog and the associated blogs Career, Certificates and The nineties job quest, but I've stopped short of displaying some sensitive details. People can find out even more about me by looking up my other blogs as well as Facebook, MySpace, Shelfari and Amazon and by doing a Google search on my full name. I want as much information about me as possible to be available publicly for a variety of reasons. This makes me particularly vulnerable to leakage of the information that I want to remain available on a restricted basis, so that I am especially concerned about protecting those details that I do regard as sensitive.

Job applications

I sometimes register with recruitment agencies and normally accept this without fuss, but I looked at one privacy statement that I was required to agree to and decided to delay registering while I investigated further, as it seemed very intrusive. (In the end, I didn't register with that agency, but there are many other agencies who I've registered with.) I post it here, modified to remove the name, address, website links and e-mail address of the recruiter, who I now call Recruiter (because I respect Recruiter's privacy rights). The only people who should be able to identify the source are those who have read the original agreement. I suspect that many people who registered with Recruiter didn't read the agreement properly and that some of those who did read it properly have long forgotten what was in it.

Does it comply with the data protection act? If it does, I'm not impressed with the law. I'm concerned in particular about the so-called non-personal information, which appears to be far too wide-ranging. I particularly object to the definition of my IP address as non-personal, since it is unique to my computer, but it's not my only concern. For example, why does Recruiter need to use my cookies and why would I be prevented from registering if I block cookies? If I register via Leicester public library, the cookies are destroyed between sessions, so if the purpose of the cookies is to remember the results of previous tests (information that should be on Recruiter's own database), that information will not be preserved. It would certainly explain why Recruiter is adamant that applicants allow cookies, but it's bad software design.

I also don't like the inclusion of personal information that has been de-identified. Given the amount of stuff I've posted publicly, I can see that it would really be quite easy for somebody to figure out that it's me. The more I look at this privacy statement, the more I feel that it blatantly violates my privacy, potentially endangering my personal security. Here's the killer clause.

We do not restrict the ways that we use or disclose non-personal information. We will or may use non-personal information collected from you to help us make this Web Site more useful to users and for other business purposes.

For instance, we may use non-personal information that we collect from you through this Web Site to:

  • create reports to develop programs, products, services or content,
  • customize the Web Site, and/or the information or services that are of interest to you, or
  • share it with or sell it to third parties.

Look, all I want to do is to register for job vacancies. As a former computer programmer, I realise that data collected in this way may sometimes be used as test data and I can live with that; I'd be a hypocrite if I couldn't, since I frequently accessed live data in my programming days. However, I don't see why this same information should be sold to third parties. Recruitment agencies are supposed to earn their money by placing people in jobs, not by selling information about applicants.

Skip to the next page titled Poor ideas for change if you don't want to read the whole privacy statement.

I have used bold, italics and underline effects as used in the original statement, to make its appearance here reflect the original as closely as possible. Apart from suppression of sensitive information identifying Recruiter, my only deviation is to include a few links to external websites, but the wording remains exactly the same. Copy and paste it into a word processing document, then replace the links with normal text, to make it look more like the original, if you wish.

PRIVACY STATEMENT

This Privacy Statement explains what information Recruiter ("Recruiter" or "we") collects on (website link) and internet tools accessible from this web site ("Web Site"), how Recruiter uses that information, your choices and this Web Site's other privacy practices. This Privacy Statement only covers information collected at this Web Site, and does not cover any information collected at any other web site or offline by Recruiter, our affiliates or any other company (unless specifically stated). Please read this Privacy Statement carefully.

IDENTIFICATION

Our contact details are as follows: (not telling you)

The identity of the organisation responsible for operating this Web Site is Recruiter, the address of whose corporate headquarters is: (not telling you)

All personal information collected from you by means of this Web Site will be controlled primarily by us, and secondarily by Recruiter.

Recruiter operates a privacy policy in connection with information by it from this Web Site. To read the details of this privacy policy please click here.

INFORMATION COLLECTED

We may collect either or both of two kinds of information from you: non-personal information and personal information.

We collect personal information from you through the Web Site only when you voluntarily share it with us, such as when you fill out a registration or job application form, an online test or survey, or send us an e-mail; if you choose to purchase a product or apply for a job with us; or when you use one of our online forms. The type of personal information that Recruiter asks you to voluntarily provide depends on the specific purpose for which you are using the Web Site. For example, you may be asked to provide credit card information if you are purchasing product. In other situations you may only be asked to provide your name and e-mail address.

Non-personal information is information that we collect through this Web Site that does not identify you by name or as an individual person. It may include information like:

  • the type of web browser software that your computer uses;
  • pages that your computer visited and the date and the time your computer accessed our pages;
  • personal information that has been de-identified;
  • the IP (internet protocol) address associated with your computer; and
  • cookies: unless you chose to disable cookies, we may collect non-personal information from your computer's web browser. A cookie is an information file that the Web Site causes to be placed on your computer for record keeping and site navigation purposes. The cookie caused to be placed on your computer by the Web Site does not store your name, e-mail address or any other personal information about you. Your browser software can be set to reject cookies and you may delete any cookie placed on your computer prior to setting your browser software to reject cookies. However, please note that if you refuse or reject our cookies, you will not be able to use this Web Site.

Personal information is information that we collect through this Web Site that we can use to specifically identify you, and may include the following types of information:

  • name, telephone number, social security number and e-mail address
  • credit card or similar information
  • past employment history
  • information that you provide in online tests and surveys, including responses to test questions and surveys

Please understand that all of the information listed above will not be collected in all cases, and will depend on the specific purpose of your use of the Web Site. You have the right to request the modification or deletion of any personal information retained by Recruiter that is inaccurate, except that information relating to your test scores and performance, as set forth below. You understand that Recruiter, in its sole discretion, will determine whether personal information should be modified or deleted.

USE AND DISCLOSURE OF INFORMATION

We do not restrict the ways that we use or disclose non-personal information. We will or may use non-personal information collected from you to help us make this Web Site more useful to users and for other business purposes.

For instance, we may use non-personal information that we collect from you through this Web Site to:

  • create reports to develop programs, products, services or content,
  • customize the Web Site, and/or the information or services that are of interest to you, or
  • share it with or sell it to third parties.

We may use personal information that we collect from you through this Web Site:

  • to respond to your requests, including your request to be evaluated for possible employment opportunities;
  • to provide you with products or services that you request;
  • (if you have ticked the consent box in our registration form) to provide you with access to the products or services of Recruiter;
  • to prepare, process and develop records, including records of your personal information;
  • for analytical purposes and to research, develop and improve programs, products, services and content;
  • to remove your personal identifiers (your name, e-mail address etc). In this case, you would no longer be identified as a single unique individual. Once we have de-identified information, it is non-personal information and we may use and treat it like other non-personal information;
  • to contact you regarding any problems or questions that we have relating to your use of the Web Site, or, in our discretion, notify you of changes to our Privacy Statement, Terms of Use or other policy or terms that affect you or your use of the Web Site;
  • to enforce this Privacy Statement or the Terms of Use;
  • to protect our rights or property;
  • to protect someone's health, safety or welfare; or
  • to comply with any applicable law or regulation, court order or other legal process.

SHARING PERSONAL INFORMATION WITH THIRD PARTIES

Unless otherwise disclosed in this Privacy Statement or at the time that you provide your information, Recruiter will only share your personal information with third parties under the following limited circumstances:

  • We may share the personal information that you provide with the organisation to which you are applying for a job, and with any of its suppliers or contractors who are involved in the application process.
  • We may also share your personal information with our parent, subsidiary, and/or affiliated companies for our or their internal business purposes; but we do not share this information for their independent marketing purposes.
  • If you are applying for employment with Recruiter we may ask you to provide us with self-identifying information (such as gender and ethnicity). If you choose to provide us with this self-identifying information, which is voluntary, we will ask you to click an "opt-in" box to confirm that you explicitly agree to our processing this information in accordance with this Privacy Statement.
  • In the ordinary course of business, we also will share some personal information with companies that we hire to perform services or functions on our behalf. For example, we may use different vendors or suppliers to process your credit card information or to deliver to you products that you order from the Web Site. In such cases those third parties may have access to your personal information in order to provide the services on our behalf.
  • We may cooperate with law enforcement authorities in investigating and prosecuting Web Site users who violate our rules or engage in behaviour which is harmful (or illegal) to other users. Recruiter may transfer and disclose information about our users, including personally identifiable information, to enforce this Privacy Statement and the other rules about your use of this Web Site, protect our rights or property, protect someone else's safety or welfare, or comply with a law or regulation, court order or other legal process.
  • Recruiter reserves the right to disclose and transfer user information, including personal information, in connection with a corporate sale, merger, dissolution, or acquisition, or similar transaction.

RETENTION AND YOUR CHOICES AND ABILITY TO ACCESS PERSONAL INFORMATION

Even if you are no longer registered with us, we may maintain copies of your information in our internal records, systems, and databases, in which case we will continue to treat your personal information in accordance with this Privacy Statement.

Recruiter provides individuals with a reasonable opportunity to access and update their personal information, subject to the qualifications noted below. You have the right to obtain confirmation from Recruiter that we have retained personal data about you, as well as a written description of the nature of that personal data, the purposes for which it is being used, the sources of the personal data and a list of the recipients with whom we have shared your personal data. You also have the right to request the modification or deletion of any personal information retained by Recruiter that is inaccurate. Please contact us at the Recruiter address appearing on the first page to inquire about your personal information. Recruiter reserves the right to charge a modest fee for providing you with access to your personal information that we collect from you through this Web Site.

Test Takers: Please note that test scores reflect a Test Taker's performance at a particular time, and neither your responses nor your score can be changed after the fact. Similarly, certain information that you provide in preliminary question forms completed prior to or following a test session are immediately disclosed to the Test Administrator. Upon reasonable request, Recruiter will provide you with an opportunity to access and update your personal information that we have on file. We recommend, however, that you follow up as well with your Test Administrator to update the personal information held on file by that entity. Please check the Test Administrator's privacy policy for details on its information collection and use practices.

Employees: Recruiter permits each of its employees to access and update his or her personal information as permitted by law. Please contact your local Human Resources Representative for details on accessing and updating your personal information.

LINKS TO OTHER ONLINE RESOURCES

This Web Site may contain links to other online resources. We provide the links for your convenience, but we do not review, control, or monitor the privacy practices of online resources operated by others. This Privacy Statement does not apply to any other online resources where a link to this Privacy Statement does not appear. We are not responsible for the performance of sites operated by third parties or for your business dealings with them. Therefore, whenever you leave this Web Site and move to another site we recommend that you review the latter's privacy practices and make your own conclusions regarding the adequacy of these practices.

CONSENT TO TRANSFER

This Web Site is operated in the United States. If you are located in the European Union, Canada or elsewhere outside of the United States, please be aware that any information that you provide to us may be transferred to the United States. By providing us with your information through this Web Site, you expressly consent to this transfer.

SECURITY

We have implemented commercially reasonable electronic, physical and procedural safeguards designed to help protect against the loss, unauthorised access or disclosure, alteration or destruction of the information under our control. Certain features of our Web Sites may require you to use an access code, password or similar unique identifier. You are responsible for protecting the secrecy of your account information. Recruiter recommends that you use the latest browsers so as to take advantage of advances in security technology. While on a secure page, such as when you initially access (web addresses) for an online test session, the lock icon on the bottom of certain browsers, such as Microsoft Internet Explorer, appears in "locked" mode, as opposed to un-locked, or open, as when you are just "surfing." Your access to the homepage of (web addresses) is encrypted with a 128-bit encryption protocol known as SSL ("Secure Sockets Layer"). Although we strive to protect your encrypted information, no data transmission over the Internet is completely secure. There is some risk associated with any data transmission, including the risk that personal information may be intercepted in transit.

ACCEPTANCE & PRIVACY POLICY CHANGES

By using this Web Site, you accept our privacy practices, as outlined in this Privacy Statement. Recruiter reserves the right to modify, alter or otherwise update this Privacy Statement at any time. We will post any new or revised policies on the Web Site. However, Recruiter will use your personal information in a manner consistent with the Privacy Statement in effect at the time that you submitted the information, unless you consent to the new or revised policy.

The EFFECTIVE DATE of this Privacy Policy is: (date).

No comments: