1 Introduction
1.1 MauBank Ltd (hereafter referred to as “MauBank”, “we”, “us”, “our”) is committed to protecting the privacy of its job candidates and processes personal data in accordance with the Mauritius Data Protection Act 2017 (hereafter referred to as the “MDPA”). This Recruitment Privacy Notice (“Notice”) outlines how we process your personal data during the recruitment process. While the Notice describes the broadest possible use of such data, we may make less use of your personal data than is described here.
2 Types of Personal Data We Collect
2.1 The type of personal data we process will depend on the purpose for which it is collected. We will only collect and process data that we need for that purpose.
2.2 We may collect your personal data in the following ways:
· Directly from you, for example, when you give us your CV, information you provide to us via emails, interviews; and
· From third parties, for example, professional recruiting agencies such as myjob.mu and references and/or testimonials supplied by your previous employers.
2.3 We may collect, process and maintain your personal data including:
· Contact Details: Name, Residential Address, Phone Number, Email Address, Contact details of references (names, email addresses and phone numbers)
· Individual Details: Gender, Nationality, Date of Birth, Age, Language
· Identification Details: National Identity Card Number
· Educational and professional background: CV/ resumé, Academic and professional qualifications, Employment history and past employers’ testimonials, Reference letters
· Other: Information you choose to share with us such as your hobbies and social preferences, interview notes
3 Purpose for using your personal data
3.1 MauBank will only use your personal data for the purpose for which it was collected or agreed with you. If you are hired by MauBank, we may collect other necessary personal data in connection with your employment as described in our Employee Privacy Notice.
3.2 We will not use your personal data for any automated individual decision making which will have a significant impact on you.
3.3 We have set out below the legal basis of processing for each purpose. Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your personal data.
|
Purpose of Processing |
Legal Basis for Processing |
|
As required for the recruitment process at MauBank: - For communicating with you, - To analyse your qualifications and and assess your suitability for the job, - To set out your job conditions, - To conduct candidate screening and assess candidate credibility
|
The processing is necessary to perform a contract or to take steps at your request, before entering a contract, namely your contract of employment. For our legitimate interests, namely for the proper administration of our business and to ensure appropriate job candidates are being recruited.
|
|
To contact your previous employers for references |
Consent |
|
To store your CV and contact details for the purpose of contacting you in the event there are future job opportunities |
Consent |
4 Mandatory and Voluntary Information
4.1 Some of the information we request from you may be mandatory for us to effectively assess your application. We will clearly indicate which data falls into this category during the information collection process, for example in our forms, job advertisements, amongst others. Failure to provide this obligatory information could impact the progress of your application, potentially resulting in the inability to process your application further.
4.2 If you choose to provide more information beyond what is required, we will evaluate its necessity for our purposes. If it is determined to be unnecessary, we will promptly delete it to protect your privacy.
5 Who has access to your personal data?
5.1 Access to your personal data within MauBank
5.1.1 Employees who may have access to the personal data within the Human Resources Department or other relevant departments are required to keep that data confidential.
5.2 Access to your personal data by third parties
5.2.1 Except as otherwise stated in this Notice or as required for legal or regulatory purposes, we treat your personal data as confidential and will only share your personal data with third party service providers which assist us in fulfilling our responsibilities regarding the purposes listed above.
5.2.2 We may also share your personal data with public and government authorities, as required by applicable laws and regulations, for national security and/or law enforcement purposes.
5.2.3 For more details, please contact the Data Protection Officer (hereafter referred to as the “DPO”), as per Section 12 of this Notice.
6 Personal Data Security
6.1 We prioritise the security of your personal data and have adopted several IT Policies to protect all information by safeguarding its confidentiality, integrity and availability and to ensure business continuity and minimise operational damage by reducing the impact of security incidents.
6.2 We have also put in place procedures to deal with any suspected data security breach and will promptly notify you and the Data Protection Office of any suspected breach where we are legally required to do so.
7 Data Retention
7.1 MauBank adheres to data retention practices that are in accordance with our business requirements and provisions stipulated in the MDPA.
7.2 If your employment application is unsuccessful, all personal data collected during the recruitment process may be retained on file for three (3) years after the end of the relevant recruitment process in order to consider you for other job opportunities. If you wish to have your CV deleted earlier, please notify us and we will process your request accordingly; otherwise, at the end of that period, your CV will be properly destroyed.
7.3 If your employment application is successful, personal data gathered during the recruitment process will be transferred to your personnel file and retained during your employment. The periods for which your personal data will be held will be provided to you in an Employee Privacy Notice.
8 Transfer of Personal Data Outside Mauritius
8.1 In certain circumstances, your personal data may be transferred to and processed outside Mauritius. We will ensure that any such transfer is compliant with provisions stipulated in the MDPA. If your personal data is transferred to a country that does not provide an adequate level of data protection, we will implement appropriate safeguards, such as contractual clauses, to protect your personal data.
9 Your responsibilities
9.1 You are responsible for the data you provide or make available to us, and you must ensure it is honest, truthful, accurate and not misleading in any way. You must ensure that the data provided does not contain material that is obscene, defamatory, or infringing on any rights of any third party, does not contain malicious code and is not otherwise legally actionable.
9.2 Further, if you provide any data concerning any other person, such as individuals you provide as references, you are responsible for providing any notices and obtaining any consents necessary for us to collect and use that data as described in this Notice.
10 Your Rights
10.1 Under the MDPA, you have rights that we need to make you aware of. The rights available to you depend on our reason for processing your information.
· Right of Access: You have the right to request access to the personal data we hold about you. This includes the right to obtain confirmation of whether we process your personal data and to receive a copy of that information.
· Right to Rectification: If you believe that the personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or update it.
· Right to Erasure: In certain circumstances, you may have the right to request the erasure of your personal data. This includes situations where your personal information is no longer necessary for the purposes for which it was collected, or you withdraw your consent and there is no other legal basis for processing.
· Right to Restriction of Processing: You have the right to request the restriction of processing of your personal data under certain conditions. This means we will temporarily suspend the processing of your personal data, such as when you contest its accuracy or when you object to the processing.
· Right to Object: You have the right to object to the processing of your personal data for certain reasons, such as direct marketing or legitimate interests. If you exercise this right, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
· Right to Data Portability: You have the right to request a copy of your personal information in a structured, commonly used and machine-readable format. You also have the right to transmit this data to another data controller.
· Right to Withdraw Consent: If we rely on your consent as the legal basis for processing your personal data, you have the right to withdraw your consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
10.2 To exercise your right as a data subject, you are requested to send an email to the Human Resources Department at [recruitment@maubank.mu] by copying the DPO in the email.
10.3 You are asked to send your request with all required information, including:
· The request type – For example, are you requesting a copy of your information, the deletion or modification of your personal data; and
· All relevant information which can help to successfully respond to your request.
11 Queries and Complaints
11.1 If you have any questions, concerns or complaints about the processing of your personal data, you should contact the DPO. We will investigate and attempt to resolve complaints and disputes regarding the use and disclosure of your personal data in accordance with this Notice and provide you with a timely an appropriate response typically within thirty days. If additional time is required, we will inform you accordingly.
11.2 When contacting the DPO, you are requested to provide a clear and detailed description of your concerns. This will help us understand the issue and take appropriate action.
11.3 If you believe that we have not handled your request appropriately, you may submit a complaint to the Data Protection Office of Mauritius.
12 Contact Us
12.1 For inquiries or to exercise your data protection rights, contact our DPO as follows:
Email: dpo@maubank.mu
Phone Number: (+230) 4059400
Address: 25 Bank Street, Ebene Cyber City, Mauritius.
13 Changes to this Notice
13.1 We may update this Notice from time to time to reflect best practices in data management, security and control and to ensure compliance with any changes or amendments made to the MDPA and any laws or regulations thereof.