How to prepare for the FCA's new Consumer Duty regulations for positive, compliant outcomes
Practical and preparatory steps to Duty compliance
TCC (“we”), as Data Controllers, are committed to safeguarding the security, privacy and integrity of the personal information that we process concerning our Associate or prospective Associate personnel (“you” or “your”). This includes the disclosure of data for employment related purposes.
This Privacy Notice applies to all current Associate and prospective Associate personnel and sets out how we handle your personal data, and how we use the personal data in compliance with the EU General Data Protection Regulation (GDPR), and any subsequent legislation that enacts this; hereafter referred to as the data protection regulation.
We ask you to read this privacy statement very carefully as it contains important information on the way in which we will process your personal data, in particular:
We reserve the right to change our privacy statement from time to time.
Personal data includes any information that directly or indirectly identifies an individual.
We may collect your personal data directly or passively from you, or indirectly from other sources, when we are assessing your candidacy for relevant job opportunities, or when entering into, or arranging to enter into a contract with you. This will depend upon our historical interactions with you where you have previously completed assignments on behalf of TCC.
Personal data we may gain directly from you may include:
We will only process special category data (sensitive data) in line with employment legislation and other legal obligations to which we are subject, and for the purposes of managing your employment contract. Otherwise we will obtain your prior informed and explicit consent to process this information.
We may also process your personal data which we obtain indirectly from other sources, such as:
We will only process your personal data where we have a legal basis for doing so (see section below). We will only use your personal data for the purposes described in this Privacy Notice, and in particular to assess your candidacy for and to offer you Associate opportunities with TCC; either working directly for TCC or via TCC on behalf of one (or more) of our clients.
We will never share your data with any other third party, other than those stated in this policy, nor use your data for any other purpose, unless we firstly gain your explicit consent to do so.
We may rely on a number of legal bases for collecting and further processing your personal data, including:
We collect personal information about you to enable us to enter into and manage the employment contract with you.
We will always gain your freely given, specific, unambiguous explicit and informed consent prior sharing your personal data with any third-party clients, for the purposes of exploring or assessing your candidacy for any relevant job opportunity.
We may also process your personal information to allow us, or our clients, to comply with certain legal obligations to which we are subject. For example, in compliance with FCA regulation, as well as compliance with employment, social security or social protection law. We may also rely on our legal obligation where processing is necessary for the establishment, exercise or defence of legal claims.
We may use your personal data for our legitimate business interests, whilst carefully considering and balancing any potential impact on you and your rights as a data subject under the relevant data protection regulation.
As an example, we may rely on our legitimate interest to process your personal data for the following purposes:
Please note, you have the right to object to the processing for which we rely on legitimate interest as the legal basis. You can do so by emailing firstname.lastname@example.org.
As a data subject, you can exercise rights in relation to the processing of your personal data, under the data protection regulation, as detailed below:
Right to request access: you can request a copy of the personal information that we hold about you.
This privacy notice complies with your right to confirmation on whether or not we are processing your personal data and provides you with the following information:
Right to request rectification of your personal information: you shall have the right to obtain from us without undue delay the rectification of inaccurate personal data concerning you. Taking into account the purposes of the processing, you shall also have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
Right to request erasure (“to be forgotten”) of your personal information: in some circumstances you have the right to have your personal data erased and no longer processed where:
Right to restrict processing: you have the right to obtain the restriction of processing where one of the following applies:
Where you have obtained restriction of processing you have the right to be informed by us before the restriction processing is lifted.
Right to object to processing: you have the right to object, on grounds relating to your particular situation, at any time, to processing of personal data concerning you which is based on our legitimate interest.
Right to data portability: you have the right to receive the personal data concerning you, which you have provided to us and have the right to transmit this data to another controller without hindrance from us to which the personal data has been provided. Where feasibly possible, you also have the right to have the personal data transmitted directly to another controller.
Right to complain: we will be more than happy to discuss any complaint you may have about the processing of your personal data. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO). The contact details of the ICO are:
Helpline: 03030123 1113
Right to understand the source of data gained indirectly: This Privacy Notice complies with your right to be informed of the source of any personal data that is not collected directly from you.
Should you wish to obtain a copy (free of charge) of the personal data being processed, TCC is required to respond to your request within one month from receipt of the request. For added security, we may ask you to provide proof of your identity before releasing any data. All requests must be sent to the following address:
6th Floor10 Lower Thames Street
Telephone: 0203 772 7230
If you do not provide, or object to certain data processing activities, we may not be able to assess your candidacy or suitability for a role. This will result in you being removed from any candidate shortlist.
You have certain obligations under your employment contract to provide TCC, or our client firm, with personal data. For example, if you do not provide, or object to certain data processing activities, we would not be able to perform our obligations that exist in the contract of employment that is in place between us. For example, if you withhold your bank details, then we would not be able to pay you.
We may also not be able to comply with our legal or regulatory obligations which may make it difficult for us to continue to employ you in a particular role. For example, if you are employed in a position that requires certification from the FCA and you objected to us conducting screening searches using personal data that you had previously provided, we may not be able to obtain (or maintain) the certification, which means you could not legally continue in that role.
We use the following third-party providers who may process or have access to your personal data. This is necessary for the Associate recruitment process, to obtain references from other employers and providers, and to obtain necessary criminal records checks from the Disclosure and Barring Service:
TCC will only keep your personal data for as long as necessary for the purposes for which it was collected.
Personal data will be retained for the purposes of keeping you informed of relevant job opportunities within both TCC and our client firms, or where we have another legal basis for processing.
If the personal data is no longer necessary, or where we no longer have the legal basis for processing, we will delete or fully anonymise the data we hold about you, in line with our Data Control Policy. If your data has become inaccurate or out of date, we will update it accordingly.
Your data will be erased when it is no longer necessary for the purpose it was originally processed, or after four years from our last contact with you.
We take the security of your data seriously. We are committed to ensuring we have appropriate technical and organisational controls in place to keep your information secure. This includes internal policies and controls in place to protect against accidental or unlawful destruction, loss, alteration, disclosure or access to your personal data.
Your personal data will only be accessed by authorised employees of TCC, in the performance of their duties or where you have otherwise given your explicit consent. In order to prevent unauthorised access or disclosure, TCC has put in place suitable physical, electronic and managerial procedures to safeguard and secure the information TCC collects.
TCC will not process your data outside of the EEA and all personal data is stored in servers in the EEA.
This privacy statement details the standards that we will apply when processing your personal information. In return, it is important that you help keep your information accurate, reliable and up-to-date. Any changes to your personal data, such as a new address or change of name can be updated by contacting email@example.com.
We will be more than happy to help you should you have any complaints about the processing of your personal data. If you have any queries about this privacy notice, or should you wish to make a complaint, please contact TCC at firstname.lastname@example.org as detailed in the section below.
You have the right to lodge a complaint with the Information Commissioner’s Office (ICO), which is the national authority responsible for the protection of personal data. A complaint can be made to the ICO via its website: ico.org.uk or through its helpline: 0303 123 1113.
If you have any queries or requests concerning this privacy statement, your personal information or how we process it, please contact TCC at email@example.com.
If so, you should read our standard Privacy Statement, which sets out how we will process your data in order to effectively communicate with you and enable you to use our website.
We reserve the right to change this Privacy Notice. The up-to-date version will be on Sharepoint and TCC’s website. Previous versions will continue to be available here. We recommend that you check this notice regularly so that you are informed of any changes.
Version 6.0 | September 2022