Information for job seekers regarding the processing of personal data
1. Data Controller Information
EOS KSI, Upravljanje terjatev d.o.o.
Letališka cesta 33
SI - 1000 Ljubljana
2. Contact Details of the Data Protection Officer:
MIKROCOP informacijski inženiring in storitve d.o.o., Ulica Ambrožiča Novljana 7, 1000 Ljubljana
Grega Vozel, [email protected]
Phone: +386 (0)1 5874 280
3. Scope of Application
This privacy policy governs the processing of personal data of job seekers for permanent employment as well as for student and pupil work (hereinafter: job candidate or candidate) within the scope of human resources activities.
4. Personal Data Processing Activities
4.1. Job Application, Candidate Selection, and Notification
In the process of searching for and selecting candidates for employment, you provide us with the following personal data when applying for a vacant position:
- Name and surname
- Address of permanent/temporary residence
- Date of birth
- Email address
- Telephone number
- Education
- CV/Résumé
- Motivation letter
- Certificate from ZPIZ (Pension and Disability Insurance Institute)
The specified data is processed for the purpose of selection, for sending a notification to the selected candidate, and for sending notifications to unsuccessful candidates. We do not use this data for profiling.
The legal basis for data processing is Article 6(1)(a) of the GDPR (consent).
We will store the personal data of unsuccessful candidates for 30 days from the day the unsuccessful candidate receives the notification.
We will store the personal data of selected candidates until the purpose is fulfilled (general limitation period of 5 years).
4.2. Candidate Check
The controller performs a check on the candidate to determine if they are listed in its debtor database, due to a potential conflict of interest. The controller processes the following personal data for this purpose:
- Name and surname
- Address of permanent/temporary residence
- Date of birth
The legal basis for data processing is Article 6(1)(f) of the GDPR (legitimate interest that overrides the rights, freedoms, and interests of the candidate).
The personal data is not stored; only a check in the debtor database is performed.
4.3. Conclusion of an Employment Contract
For the purpose of concluding an employment contract or a contract for student or pupil work, we process the following personal data:
- Name and surname
- Address of permanent/temporary residence
- Date of birth
- Personal Identification Number (EMŠO)
- Tax number
- Bank account number
- Education
- Place of birth
- Country of birth, if born abroad
- Citizenship
- Disability status
- Partial retirement status of the employee
- Performance of any supplementary activities with another employer
- Date of birth of children
- Length of service
- Dependent family members
The legal basis for data processing is Article 6(1)(c) of the GDPR (fulfillment of a legal obligation under the Employment Relationships Act and the Act on Records in the Field of Labour and Social Security).
The above personal data will be stored permanently.
5. Recipients of Personal Data
In addition to the controller EOS KSI d.o.o., the recipients of personal data are contractual partners and data processors who are bound by labor law and data processing agreements to respect and protect employee personal data. Detailed information about contractual partners and processors can be obtained upon request from the Data Protection Officer at [email protected].
Personal data will not be transferred outside the EU.
The controller may also transfer your personal data to the following legal or natural persons to fulfill the purpose for which it is processed:
- State bodies and courts
- Auditors, inspectors, and lawyers
- Providers of technical support and security maintenance
- Affiliated companies within the EOS KSI Group
The legal basis for transferring your personal data is either a legal obligation or point (b) of Article 6(1) of the GDPR (performance of a contract).
6. Your Rights as a Data Subject
As an individual, you have the following rights concerning your personal data. You can submit a request in writing to the controller's address or to the Data Protection Officer. The controller will fulfill justified requests within one month. In case of complex or numerous requests, this deadline may be extended by an additional two months.
- a. Withdrawal of Consent: You have the right to withdraw your consent at any time where processing is based on consent, without affecting the lawfulness of processing based on consent before its withdrawal.
- b. Right of Access: Upon your request, we will inform you whether personal data concerning you is being processed and, if so, provide you with a copy of the data and the following information: the types of personal data; the categories of recipients to whom the data has been or will be disclosed; the retention periods; the existence of the right to request rectification, erasure, or restriction of processing, or to object to such processing; the right to lodge a complaint with the Information Commissioner; the source of the data if not collected from you; the existence of automated decision-making, including profiling, and meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for you.
- c. Right to Rectification: You can request at any time that the controller corrects inaccurate data or completes incomplete data relating to you.
- d. Right to Erasure ('Right to be Forgotten'): You can request the erasure of your personal data if: the data is no longer necessary for the purposes for which it was collected; you withdraw consent and there is no other legal ground for the processing; you object to the processing and there are no overriding legitimate grounds; the data has been unlawfully processed; the data must be erased for compliance with a legal obligation in EU or Slovenian law.
- e. Right to Restriction of Processing: You can request that the processing of your data be restricted if: you contest the accuracy of the data; the processing is unlawful and you oppose erasure; you have objected to processing pending the verification of legitimate grounds.
- f. Right to Data Portability: You can request a copy of the data you have provided to the controller in a machine-readable format, where the processing is based on consent and carried out by automated means.
- g. Right to Lodge a Complaint: If you believe that your personal data is being processed unlawfully or that your data protection rights have been violated, you can lodge a complaint with the Information Commissioner or turn to the competent court.
7. Protection of Personal Data
All data will be strictly protected in accordance with personal data protection regulations and the internal acts of EOS KSI and will not be used for other purposes. The company implements appropriate technical and organizational measures to ensure a high level of security for personal data in its information systems and to guarantee the rights of data subjects.
8. Right to Lodge a Complaint with a Supervisory Authority
If you believe that the processing of your personal data violates the provisions of the GDPR or other applicable data protection regulations, you have the right under Article 77 of the GDPR to lodge a complaint with the supervisory authority at the following address:
Republic of Slovenia
Information Commissioner
Dunajska cesta 22
1000 Ljubljana
T: 01 230 97 30
F: 01 230 97 78
E-mail: [email protected]
How to exercise your rights
You can send a request to exercise your rights from point 6:
- By mail to the company’s address
- Electronically to the email address [email protected].
The request should include:
- Your identification details
- The right you wish to exercise
- Any additional information or documentation.