SlideShare a Scribd company logo
1 of 30
Download to read offline
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Candidate Data Compliance
1
Are you prepared for the risks?
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved 2
Sultan runs product, technology and customer experience at
Beamery, partnering with customers to find and apply best
recruiting practices, including on compliance and data
management. He is a frequent speaker on all things product,
recruiting, data, talent operations and compliance.
Your speaker today
Sultan Saidov
President and Co-founder, Beamery
Icon
Placeholder
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Charity giveaway!
Please submit questions during the Q&A session, and get an e-charity card from Beamery to
donate to your favorite charity
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Disclaimer:
This discussion should not be
construed as legal advice , and you
should take your own legal opinion
on this subject matter
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Agenda ■ Why are we here?
■ Data compliance in recruiting
● Recruiter experience
● Candidate experience
● Infrastructure
■ Compliance Q&A
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Why are we here?
6
Today’s regulatory environment presents many risks to talent teams
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
GDPR (2018)
Why are we here?
Schrems ii - EU-US privacy shield invalidated (2020)
China Cybersecurity Law (2017)
CCPA (2020)
Russian data localization law (2015)
Global regulation is getting more complex
Schrems i - Safe Harbor invalidated(2015)
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Why are we here?
Fines, brand image, and other risks
Russia
Fines up to $ 100,000 for an initial violation, up to $280,000 after that
GDPR
160,921 personal data breaches within the EEA, from May 25, 2018, up until now. However only ~350 fines
so far totalling 176m euros (most of this in 2020). Largest fine was for Google (50m euros in 2019), and in
2020 TIM telecoms 27.8m euros.
CSL
Fines and criminal prosecution for illegal collection of private data
Data Breaches
Fines can take place outside of GDPR including - British Airways (EUR 204M), Marriott Alliance (EUR 110M)
8
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Impact of Schrems ii
9
Considerations for Talent Acquisition
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Why are we here?
Schrems ii - privacy shield invalidated
SCC
Make sure your suppliers have ensured that not only they but their suppliers will replace any privacy shield
reliant mechanisms , with another valid method of data transfer - either through SCC with safeguards built in,
and/or binding corporate rules within their organisational entities. Note, that for 11 countries (e.g. Israel,
Switzerland) SCCs are not required (e.g. for your vendors and/or their sub processors that are based there)
Privacy policies
Companies (e.g. your vendors) will likely need to have updated their privacy policies (eg to remove references to
privacy shield), and the Privacy compliance statement
EU Servers
Some businesses - particularly those who have activities located solely with the EU - are choosing to work only
with vendors who can host their data solely in the EU (e.g. in Beamery we offer EU hosting, in countries such as
in the Netherlands or Germany). However, this is not required by the GDPR regulations and is a business choice
10
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Data compliance in recruiting
11
What areas of recruiting operations are affected by global data regulation?
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
How can talent teams be compliant, while
still staying agile and offering competitive
candidates experiences?
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Data compliance in recruiting
How are daily recruiting activities
affected?
What constraints should recruiters
be aware of?
What are the right of candidates
throughout the hiring process?
Is the recruiting experience
hindered by compliance
requirements?
What technical support is needed
to be compliant?
Recruiter experience Candidate experience Infrastructure
3 main areas of impact to take in consideration
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Data compliance in recruiting
Recruiting workflows need to adapt
14
Considerations
Consent Management Needs to be explicit under GDPR (EU) - or specifically the PECR rules
Data retention and deletion
Only opted-in data should be stored under GDPR. Data on citizens
from Russia or China might need to be stored in those territories.
Sourcing
Recruiters might need to send a consent link when first reaching out
to candidates in order to record consent
Diversity data visibility Certain data fields must be restricted access under EEO
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Data compliance in recruiting
Candidates understand their data rights
Candidates want to…
★ Easily opt out of communications or ask for their data to
be deleted (GDPR, CCPA)
★ Know what private data the company is collecting about
them (GDPR, CCPA)
★ Be reassured that they won’t be discriminated against
based on data shared in the application process (EEO)
15
Recruiters have to...
Where applicable, ensure their candidates have
been asked to opt-in (or equivalent).
Provide opt-out links, understand how to
delete/anonymize data
Be able to access and share candidate data
Restrict access to sensitive data
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Data compliance in recruiting
Consent capture in applications
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Data compliance in recruiting
Consent capture - include messaging channels
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Data compliance in recruiting
Consent capture - include messaging channels
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved 19
Give candidates control
Talent Portals
● Give candidates granular control of
communication preferences, including for
types of message, and for medium (e.g.
email, sms, notification)
● Enable more granular data capture for opt
out reasons
● Give candidates control of accessing their
Data, and requesting it to be forgotten /
deleted.
Provide a control center to manage
communication and compliance (e.g.
GDPR preferences)
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Recipe: Data Privacy
Anonymize
profile
Consent is
opted in
(364 days)
Contact
Checked
(24hrs)When…
Then...
Trigger
Filter
Action
If…
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
What are the infrastructure and technology considerations?
21
Hosting requirements Automation and AI
Sub-processing and
integrations
Where the data is stored and processed, who can access it and from where, how long it is stored and if a record of all processing
is kept, how recruiting teams can manage their workflows in a compliant way at scale… all of the above are influenced by the
infrastructure in place.
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Data infrastructure considerations:
“Critical information operators
[and Network operators] that
gather or produce personal
information...within the mainland
territory of the People’s Republic
of China, shall store it within
mainland China.”
Example: China
Cybersecurity Law
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Data infrastructure considerations
“Personal data of Russian citizens
must be recorded, systematized,
accumulated, stored, refined (i.e.
updated, modified), and retrieved
only using databases located
within Russia. [However],
trans-border transfer of personal
data to foreign jurisdictions is not
prohibited...”
Example: Russia data
localization requirements
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Ask me about global data compliance
24
A guided Q&A… More questions welcome!
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Compliance Q&A
What are some common misunderstanding around data compliance
regulation that you see in TA teams?
25
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Compliance Q&A
Any low-hanging fruits around data compliance that talent teams can
easily address?
26
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Compliance Q&A
What are the some of the most confusing requirements you’ve seen, and
how do companies deal with them?
27
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Compliance Q&A
What is the first thing to start with when trying to assess the state of your
candidate data?
28
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Compliance Q&A
What should you ask your talent team to understand how compliant you
are with applicable data regulation?
Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved
Thank you!

More Related Content

What's hot

Talent Attraction Insights from the Fortune 500
Talent Attraction Insights from the Fortune 500Talent Attraction Insights from the Fortune 500
Talent Attraction Insights from the Fortune 500Beamery
 
Building Talent Teams at Scale with Twitter
Building Talent Teams at Scale with TwitterBuilding Talent Teams at Scale with Twitter
Building Talent Teams at Scale with TwitterBeamery
 
Beamery + Workday: Better Together for your Talent Team
Beamery + Workday: Better Together for your Talent TeamBeamery + Workday: Better Together for your Talent Team
Beamery + Workday: Better Together for your Talent TeamBeamery
 
3 Ways to Drive Talent Goals with AI
3 Ways to Drive Talent Goals with AI3 Ways to Drive Talent Goals with AI
3 Ways to Drive Talent Goals with AIBeamery
 
Mercer_Building_Talent_Acquisition_Excellence
Mercer_Building_Talent_Acquisition_ExcellenceMercer_Building_Talent_Acquisition_Excellence
Mercer_Building_Talent_Acquisition_ExcellenceShufang Yeo
 
Learn How Organizations Are Maximizing Their Reach Using Social Media For Rec...
Learn How Organizations Are Maximizing Their Reach Using Social Media For Rec...Learn How Organizations Are Maximizing Their Reach Using Social Media For Rec...
Learn How Organizations Are Maximizing Their Reach Using Social Media For Rec...Talemetry
 
70% of Candidates Use Mobile Devices to Search for Jobs… Will They Find Yours?
70% of Candidates Use Mobile Devices to Search for Jobs… Will They Find Yours?70% of Candidates Use Mobile Devices to Search for Jobs… Will They Find Yours?
70% of Candidates Use Mobile Devices to Search for Jobs… Will They Find Yours?Talemetry
 
Fill Current Jobs Faster By Building Talent Pipelines
Fill Current Jobs Faster By Building Talent PipelinesFill Current Jobs Faster By Building Talent Pipelines
Fill Current Jobs Faster By Building Talent PipelinesTalemetry
 
Cultivating Resilience with Talent Teams
Cultivating Resilience with Talent TeamsCultivating Resilience with Talent Teams
Cultivating Resilience with Talent TeamsBeamery
 
Reduce your hiring cost by using LinkedIn Solutions
Reduce your hiring cost by using LinkedIn SolutionsReduce your hiring cost by using LinkedIn Solutions
Reduce your hiring cost by using LinkedIn SolutionsFrancesco Costanzo
 
Treating Candidates like Customers - Beamery Innovation Spotlight
 Treating Candidates like Customers - Beamery Innovation Spotlight Treating Candidates like Customers - Beamery Innovation Spotlight
Treating Candidates like Customers - Beamery Innovation SpotlightTALiNT Partners
 
Phil Mogilev. Linkedin Social Media and Recruitment in Russia
Phil Mogilev. Linkedin Social Media and Recruitment in RussiaPhil Mogilev. Linkedin Social Media and Recruitment in Russia
Phil Mogilev. Linkedin Social Media and Recruitment in RussiaAwara Direct Search
 
Social Media Moscow Event
Social Media Moscow EventSocial Media Moscow Event
Social Media Moscow EventPhil Mogilev
 
Allen Recruitment LinkedIn Webcast
Allen Recruitment LinkedIn WebcastAllen Recruitment LinkedIn Webcast
Allen Recruitment LinkedIn WebcastKevin Cassidy
 
Hiring Solutions Presentation
Hiring Solutions PresentationHiring Solutions Presentation
Hiring Solutions Presentationjchristensen08
 
Webinar aug 2018 unlock career potential with digital credentials (1)
Webinar aug 2018   unlock career potential with digital credentials (1)Webinar aug 2018   unlock career potential with digital credentials (1)
Webinar aug 2018 unlock career potential with digital credentials (1)Patricia Diaz, SMS
 
Fortune 1000 HR Leader Survey Results
Fortune 1000 HR Leader Survey ResultsFortune 1000 HR Leader Survey Results
Fortune 1000 HR Leader Survey ResultsChuck Solomon
 

What's hot (20)

Talent Attraction Insights from the Fortune 500
Talent Attraction Insights from the Fortune 500Talent Attraction Insights from the Fortune 500
Talent Attraction Insights from the Fortune 500
 
Building Talent Teams at Scale with Twitter
Building Talent Teams at Scale with TwitterBuilding Talent Teams at Scale with Twitter
Building Talent Teams at Scale with Twitter
 
Beamery + Workday: Better Together for your Talent Team
Beamery + Workday: Better Together for your Talent TeamBeamery + Workday: Better Together for your Talent Team
Beamery + Workday: Better Together for your Talent Team
 
3 Ways to Drive Talent Goals with AI
3 Ways to Drive Talent Goals with AI3 Ways to Drive Talent Goals with AI
3 Ways to Drive Talent Goals with AI
 
5 Steps to Sourcing Like a Pro on LinkedIn
5 Steps to Sourcing Like a Pro on LinkedIn5 Steps to Sourcing Like a Pro on LinkedIn
5 Steps to Sourcing Like a Pro on LinkedIn
 
Mercer_Building_Talent_Acquisition_Excellence
Mercer_Building_Talent_Acquisition_ExcellenceMercer_Building_Talent_Acquisition_Excellence
Mercer_Building_Talent_Acquisition_Excellence
 
Learn How Organizations Are Maximizing Their Reach Using Social Media For Rec...
Learn How Organizations Are Maximizing Their Reach Using Social Media For Rec...Learn How Organizations Are Maximizing Their Reach Using Social Media For Rec...
Learn How Organizations Are Maximizing Their Reach Using Social Media For Rec...
 
70% of Candidates Use Mobile Devices to Search for Jobs… Will They Find Yours?
70% of Candidates Use Mobile Devices to Search for Jobs… Will They Find Yours?70% of Candidates Use Mobile Devices to Search for Jobs… Will They Find Yours?
70% of Candidates Use Mobile Devices to Search for Jobs… Will They Find Yours?
 
Fill Current Jobs Faster By Building Talent Pipelines
Fill Current Jobs Faster By Building Talent PipelinesFill Current Jobs Faster By Building Talent Pipelines
Fill Current Jobs Faster By Building Talent Pipelines
 
Cultivating Resilience with Talent Teams
Cultivating Resilience with Talent TeamsCultivating Resilience with Talent Teams
Cultivating Resilience with Talent Teams
 
Reduce your hiring cost by using LinkedIn Solutions
Reduce your hiring cost by using LinkedIn SolutionsReduce your hiring cost by using LinkedIn Solutions
Reduce your hiring cost by using LinkedIn Solutions
 
Treating Candidates like Customers - Beamery Innovation Spotlight
 Treating Candidates like Customers - Beamery Innovation Spotlight Treating Candidates like Customers - Beamery Innovation Spotlight
Treating Candidates like Customers - Beamery Innovation Spotlight
 
Phil Mogilev. Linkedin Social Media and Recruitment in Russia
Phil Mogilev. Linkedin Social Media and Recruitment in RussiaPhil Mogilev. Linkedin Social Media and Recruitment in Russia
Phil Mogilev. Linkedin Social Media and Recruitment in Russia
 
Social Media Moscow Event
Social Media Moscow EventSocial Media Moscow Event
Social Media Moscow Event
 
Forwed24
Forwed24Forwed24
Forwed24
 
Allen Recruitment LinkedIn Webcast
Allen Recruitment LinkedIn WebcastAllen Recruitment LinkedIn Webcast
Allen Recruitment LinkedIn Webcast
 
Hiring Solutions Presentation
Hiring Solutions PresentationHiring Solutions Presentation
Hiring Solutions Presentation
 
Webinar aug 2018 unlock career potential with digital credentials (1)
Webinar aug 2018   unlock career potential with digital credentials (1)Webinar aug 2018   unlock career potential with digital credentials (1)
Webinar aug 2018 unlock career potential with digital credentials (1)
 
Agency Benelux presentation
Agency Benelux presentationAgency Benelux presentation
Agency Benelux presentation
 
Fortune 1000 HR Leader Survey Results
Fortune 1000 HR Leader Survey ResultsFortune 1000 HR Leader Survey Results
Fortune 1000 HR Leader Survey Results
 

Similar to Candidate Data Compliance - Are you prepared for the risks?

Symantec Webinar Part 4 of 6 GDPR Compliance, What NAM Organizations Need to...
Symantec Webinar Part 4 of 6  GDPR Compliance, What NAM Organizations Need to...Symantec Webinar Part 4 of 6  GDPR Compliance, What NAM Organizations Need to...
Symantec Webinar Part 4 of 6 GDPR Compliance, What NAM Organizations Need to...Symantec
 
CyberSource MRC Survey - Top 9 Fraud Attacks and Winning Mitigating Strategie...
CyberSource MRC Survey - Top 9 Fraud Attacks and Winning Mitigating Strategie...CyberSource MRC Survey - Top 9 Fraud Attacks and Winning Mitigating Strategie...
CyberSource MRC Survey - Top 9 Fraud Attacks and Winning Mitigating Strategie...Visa
 
Rethinking Trust in Data
Rethinking Trust in Data Rethinking Trust in Data
Rethinking Trust in Data DATAVERSITY
 
Findability Day 2016 - What is GDPR?
Findability Day 2016 - What is GDPR?Findability Day 2016 - What is GDPR?
Findability Day 2016 - What is GDPR?Findwise
 
Fundamentals of Information Systems Security Chapter 2
Fundamentals of Information Systems Security Chapter 2 Fundamentals of Information Systems Security Chapter 2
Fundamentals of Information Systems Security Chapter 2 Dr. Ahmed Al Zaidy
 
Security and Privacy: What Nonprofits Need to Know
Security and Privacy: What Nonprofits Need to KnowSecurity and Privacy: What Nonprofits Need to Know
Security and Privacy: What Nonprofits Need to KnowTechSoup
 
How to determine a proper scope selection based on ISO 27001?
How to determine a proper scope selection based on ISO 27001?How to determine a proper scope selection based on ISO 27001?
How to determine a proper scope selection based on ISO 27001?PECB
 
Implementing and Auditing General Data Protection Regulation
Implementing and Auditing General Data Protection Regulation Implementing and Auditing General Data Protection Regulation
Implementing and Auditing General Data Protection Regulation Jim Kaplan CIA CFE
 
Cloud data security and GDPR compliance
Cloud data security and GDPR complianceCloud data security and GDPR compliance
Cloud data security and GDPR complianceSalim Benadel
 
Implementing and Auditing GDPR Series (3 of 10)
Implementing and Auditing GDPR Series (3 of 10) Implementing and Auditing GDPR Series (3 of 10)
Implementing and Auditing GDPR Series (3 of 10) Jim Kaplan CIA CFE
 
Symantec Webinar Part 1 of 6 The Four Stages of GDPR Readiness
Symantec Webinar Part 1 of 6 The Four Stages of GDPR ReadinessSymantec Webinar Part 1 of 6 The Four Stages of GDPR Readiness
Symantec Webinar Part 1 of 6 The Four Stages of GDPR ReadinessSymantec
 
Explain your algorithmic decisions for gdpr
Explain your algorithmic decisions for gdprExplain your algorithmic decisions for gdpr
Explain your algorithmic decisions for gdprPierre Feillet
 
2019 08-21 Automating Privacy Management
2019 08-21 Automating Privacy Management2019 08-21 Automating Privacy Management
2019 08-21 Automating Privacy ManagementTrustArc
 
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
1 -2-6 kista watson summit-gdpr ibm pov hogg-smIBM Sverige
 
info-sys-security.pptx
info-sys-security.pptxinfo-sys-security.pptx
info-sys-security.pptxMhndHTaani
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
GDPR Complaince: Don't Let SIEM BE Your Downfall
GDPR Complaince: Don't Let SIEM BE Your DownfallGDPR Complaince: Don't Let SIEM BE Your Downfall
GDPR Complaince: Don't Let SIEM BE Your DownfallSplunk
 

Similar to Candidate Data Compliance - Are you prepared for the risks? (20)

Symantec Webinar Part 4 of 6 GDPR Compliance, What NAM Organizations Need to...
Symantec Webinar Part 4 of 6  GDPR Compliance, What NAM Organizations Need to...Symantec Webinar Part 4 of 6  GDPR Compliance, What NAM Organizations Need to...
Symantec Webinar Part 4 of 6 GDPR Compliance, What NAM Organizations Need to...
 
CyberSource MRC Survey - Top 9 Fraud Attacks and Winning Mitigating Strategie...
CyberSource MRC Survey - Top 9 Fraud Attacks and Winning Mitigating Strategie...CyberSource MRC Survey - Top 9 Fraud Attacks and Winning Mitigating Strategie...
CyberSource MRC Survey - Top 9 Fraud Attacks and Winning Mitigating Strategie...
 
Rethinking Trust in Data
Rethinking Trust in Data Rethinking Trust in Data
Rethinking Trust in Data
 
Findability Day 2016 - What is GDPR?
Findability Day 2016 - What is GDPR?Findability Day 2016 - What is GDPR?
Findability Day 2016 - What is GDPR?
 
Fundamentals of Information Systems Security Chapter 2
Fundamentals of Information Systems Security Chapter 2 Fundamentals of Information Systems Security Chapter 2
Fundamentals of Information Systems Security Chapter 2
 
20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here
 
2016 11-17-gdpr-integro-webinar
2016 11-17-gdpr-integro-webinar2016 11-17-gdpr-integro-webinar
2016 11-17-gdpr-integro-webinar
 
Security and Privacy: What Nonprofits Need to Know
Security and Privacy: What Nonprofits Need to KnowSecurity and Privacy: What Nonprofits Need to Know
Security and Privacy: What Nonprofits Need to Know
 
How to determine a proper scope selection based on ISO 27001?
How to determine a proper scope selection based on ISO 27001?How to determine a proper scope selection based on ISO 27001?
How to determine a proper scope selection based on ISO 27001?
 
Implementing and Auditing General Data Protection Regulation
Implementing and Auditing General Data Protection Regulation Implementing and Auditing General Data Protection Regulation
Implementing and Auditing General Data Protection Regulation
 
Cloud data security and GDPR compliance
Cloud data security and GDPR complianceCloud data security and GDPR compliance
Cloud data security and GDPR compliance
 
Implementing and Auditing GDPR Series (3 of 10)
Implementing and Auditing GDPR Series (3 of 10) Implementing and Auditing GDPR Series (3 of 10)
Implementing and Auditing GDPR Series (3 of 10)
 
Webinar: Introduction to GDPR - What It Is and How It Will Affect Your Business
Webinar: Introduction to GDPR - What It Is and How It Will Affect Your BusinessWebinar: Introduction to GDPR - What It Is and How It Will Affect Your Business
Webinar: Introduction to GDPR - What It Is and How It Will Affect Your Business
 
Symantec Webinar Part 1 of 6 The Four Stages of GDPR Readiness
Symantec Webinar Part 1 of 6 The Four Stages of GDPR ReadinessSymantec Webinar Part 1 of 6 The Four Stages of GDPR Readiness
Symantec Webinar Part 1 of 6 The Four Stages of GDPR Readiness
 
Explain your algorithmic decisions for gdpr
Explain your algorithmic decisions for gdprExplain your algorithmic decisions for gdpr
Explain your algorithmic decisions for gdpr
 
2019 08-21 Automating Privacy Management
2019 08-21 Automating Privacy Management2019 08-21 Automating Privacy Management
2019 08-21 Automating Privacy Management
 
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
 
info-sys-security.pptx
info-sys-security.pptxinfo-sys-security.pptx
info-sys-security.pptx
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
GDPR Complaince: Don't Let SIEM BE Your Downfall
GDPR Complaince: Don't Let SIEM BE Your DownfallGDPR Complaince: Don't Let SIEM BE Your Downfall
GDPR Complaince: Don't Let SIEM BE Your Downfall
 

More from Beamery

AI in Talent Acquisition: The Fundamentals
AI in Talent Acquisition: The FundamentalsAI in Talent Acquisition: The Fundamentals
AI in Talent Acquisition: The FundamentalsBeamery
 
Rise of Talent Operations - What Good Looks Like
Rise of Talent Operations - What Good Looks LikeRise of Talent Operations - What Good Looks Like
Rise of Talent Operations - What Good Looks LikeBeamery
 
Rise of Talent Operations- The Fundamentals
Rise of Talent Operations- The FundamentalsRise of Talent Operations- The Fundamentals
Rise of Talent Operations- The FundamentalsBeamery
 
Rise of Talent Operations—The Career Path
Rise of Talent Operations—The Career PathRise of Talent Operations—The Career Path
Rise of Talent Operations—The Career PathBeamery
 
Building an effective employer brand in 2020
Building an effective employer brand in 2020  Building an effective employer brand in 2020
Building an effective employer brand in 2020 Beamery
 
The recruiting skills of 2020 with Kevin Blair - Beamery
The recruiting skills of 2020 with Kevin Blair - BeameryThe recruiting skills of 2020 with Kevin Blair - Beamery
The recruiting skills of 2020 with Kevin Blair - BeameryBeamery
 
Talent Engagement Summit 2019 - Bryan Lick
Talent Engagement Summit 2019 - Bryan LickTalent Engagement Summit 2019 - Bryan Lick
Talent Engagement Summit 2019 - Bryan LickBeamery
 
Talent Engagement Summit 2019 - Kelsea Gibson
Talent Engagement Summit 2019 - Kelsea GibsonTalent Engagement Summit 2019 - Kelsea Gibson
Talent Engagement Summit 2019 - Kelsea GibsonBeamery
 
Talent Engagement Summit - Amy Miller - 2019
Talent Engagement Summit - Amy Miller - 2019Talent Engagement Summit - Amy Miller - 2019
Talent Engagement Summit - Amy Miller - 2019Beamery
 
Talent Engagement Summit 2019 - Craig Pyke
Talent Engagement Summit 2019 - Craig PykeTalent Engagement Summit 2019 - Craig Pyke
Talent Engagement Summit 2019 - Craig PykeBeamery
 
Talent Engagement Summit 2019 - Tricia Goose
Talent Engagement Summit 2019 - Tricia GooseTalent Engagement Summit 2019 - Tricia Goose
Talent Engagement Summit 2019 - Tricia GooseBeamery
 
Talent Engagement Summit 2019- Essie Russell Butler
Talent Engagement Summit 2019- Essie Russell ButlerTalent Engagement Summit 2019- Essie Russell Butler
Talent Engagement Summit 2019- Essie Russell ButlerBeamery
 
Know your Talent Tech Stakeholders: Understanding Needs, Managing Expectations
Know your Talent Tech Stakeholders: Understanding Needs, Managing ExpectationsKnow your Talent Tech Stakeholders: Understanding Needs, Managing Expectations
Know your Talent Tech Stakeholders: Understanding Needs, Managing ExpectationsBeamery
 
Beamery + Workday: Better Together for your Talent Team
Beamery + Workday: Better Together for your Talent TeamBeamery + Workday: Better Together for your Talent Team
Beamery + Workday: Better Together for your Talent TeamBeamery
 
Beamery and Workday Better Together
Beamery and Workday Better TogetherBeamery and Workday Better Together
Beamery and Workday Better TogetherBeamery
 
Change Management in Talent Acquisition
Change Management in Talent AcquisitionChange Management in Talent Acquisition
Change Management in Talent AcquisitionBeamery
 
Talent Engagement - The New Frontier
Talent Engagement - The New Frontier Talent Engagement - The New Frontier
Talent Engagement - The New Frontier Beamery
 

More from Beamery (17)

AI in Talent Acquisition: The Fundamentals
AI in Talent Acquisition: The FundamentalsAI in Talent Acquisition: The Fundamentals
AI in Talent Acquisition: The Fundamentals
 
Rise of Talent Operations - What Good Looks Like
Rise of Talent Operations - What Good Looks LikeRise of Talent Operations - What Good Looks Like
Rise of Talent Operations - What Good Looks Like
 
Rise of Talent Operations- The Fundamentals
Rise of Talent Operations- The FundamentalsRise of Talent Operations- The Fundamentals
Rise of Talent Operations- The Fundamentals
 
Rise of Talent Operations—The Career Path
Rise of Talent Operations—The Career PathRise of Talent Operations—The Career Path
Rise of Talent Operations—The Career Path
 
Building an effective employer brand in 2020
Building an effective employer brand in 2020  Building an effective employer brand in 2020
Building an effective employer brand in 2020
 
The recruiting skills of 2020 with Kevin Blair - Beamery
The recruiting skills of 2020 with Kevin Blair - BeameryThe recruiting skills of 2020 with Kevin Blair - Beamery
The recruiting skills of 2020 with Kevin Blair - Beamery
 
Talent Engagement Summit 2019 - Bryan Lick
Talent Engagement Summit 2019 - Bryan LickTalent Engagement Summit 2019 - Bryan Lick
Talent Engagement Summit 2019 - Bryan Lick
 
Talent Engagement Summit 2019 - Kelsea Gibson
Talent Engagement Summit 2019 - Kelsea GibsonTalent Engagement Summit 2019 - Kelsea Gibson
Talent Engagement Summit 2019 - Kelsea Gibson
 
Talent Engagement Summit - Amy Miller - 2019
Talent Engagement Summit - Amy Miller - 2019Talent Engagement Summit - Amy Miller - 2019
Talent Engagement Summit - Amy Miller - 2019
 
Talent Engagement Summit 2019 - Craig Pyke
Talent Engagement Summit 2019 - Craig PykeTalent Engagement Summit 2019 - Craig Pyke
Talent Engagement Summit 2019 - Craig Pyke
 
Talent Engagement Summit 2019 - Tricia Goose
Talent Engagement Summit 2019 - Tricia GooseTalent Engagement Summit 2019 - Tricia Goose
Talent Engagement Summit 2019 - Tricia Goose
 
Talent Engagement Summit 2019- Essie Russell Butler
Talent Engagement Summit 2019- Essie Russell ButlerTalent Engagement Summit 2019- Essie Russell Butler
Talent Engagement Summit 2019- Essie Russell Butler
 
Know your Talent Tech Stakeholders: Understanding Needs, Managing Expectations
Know your Talent Tech Stakeholders: Understanding Needs, Managing ExpectationsKnow your Talent Tech Stakeholders: Understanding Needs, Managing Expectations
Know your Talent Tech Stakeholders: Understanding Needs, Managing Expectations
 
Beamery + Workday: Better Together for your Talent Team
Beamery + Workday: Better Together for your Talent TeamBeamery + Workday: Better Together for your Talent Team
Beamery + Workday: Better Together for your Talent Team
 
Beamery and Workday Better Together
Beamery and Workday Better TogetherBeamery and Workday Better Together
Beamery and Workday Better Together
 
Change Management in Talent Acquisition
Change Management in Talent AcquisitionChange Management in Talent Acquisition
Change Management in Talent Acquisition
 
Talent Engagement - The New Frontier
Talent Engagement - The New Frontier Talent Engagement - The New Frontier
Talent Engagement - The New Frontier
 

Candidate Data Compliance - Are you prepared for the risks?

  • 1. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Candidate Data Compliance 1 Are you prepared for the risks?
  • 2. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved 2 Sultan runs product, technology and customer experience at Beamery, partnering with customers to find and apply best recruiting practices, including on compliance and data management. He is a frequent speaker on all things product, recruiting, data, talent operations and compliance. Your speaker today Sultan Saidov President and Co-founder, Beamery Icon Placeholder
  • 3. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Charity giveaway! Please submit questions during the Q&A session, and get an e-charity card from Beamery to donate to your favorite charity
  • 4. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Disclaimer: This discussion should not be construed as legal advice , and you should take your own legal opinion on this subject matter
  • 5. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Agenda ■ Why are we here? ■ Data compliance in recruiting ● Recruiter experience ● Candidate experience ● Infrastructure ■ Compliance Q&A
  • 6. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Why are we here? 6 Today’s regulatory environment presents many risks to talent teams
  • 7. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved GDPR (2018) Why are we here? Schrems ii - EU-US privacy shield invalidated (2020) China Cybersecurity Law (2017) CCPA (2020) Russian data localization law (2015) Global regulation is getting more complex Schrems i - Safe Harbor invalidated(2015)
  • 8. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Why are we here? Fines, brand image, and other risks Russia Fines up to $ 100,000 for an initial violation, up to $280,000 after that GDPR 160,921 personal data breaches within the EEA, from May 25, 2018, up until now. However only ~350 fines so far totalling 176m euros (most of this in 2020). Largest fine was for Google (50m euros in 2019), and in 2020 TIM telecoms 27.8m euros. CSL Fines and criminal prosecution for illegal collection of private data Data Breaches Fines can take place outside of GDPR including - British Airways (EUR 204M), Marriott Alliance (EUR 110M) 8
  • 9. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Impact of Schrems ii 9 Considerations for Talent Acquisition
  • 10. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Why are we here? Schrems ii - privacy shield invalidated SCC Make sure your suppliers have ensured that not only they but their suppliers will replace any privacy shield reliant mechanisms , with another valid method of data transfer - either through SCC with safeguards built in, and/or binding corporate rules within their organisational entities. Note, that for 11 countries (e.g. Israel, Switzerland) SCCs are not required (e.g. for your vendors and/or their sub processors that are based there) Privacy policies Companies (e.g. your vendors) will likely need to have updated their privacy policies (eg to remove references to privacy shield), and the Privacy compliance statement EU Servers Some businesses - particularly those who have activities located solely with the EU - are choosing to work only with vendors who can host their data solely in the EU (e.g. in Beamery we offer EU hosting, in countries such as in the Netherlands or Germany). However, this is not required by the GDPR regulations and is a business choice 10
  • 11. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Data compliance in recruiting 11 What areas of recruiting operations are affected by global data regulation?
  • 12. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved How can talent teams be compliant, while still staying agile and offering competitive candidates experiences?
  • 13. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Data compliance in recruiting How are daily recruiting activities affected? What constraints should recruiters be aware of? What are the right of candidates throughout the hiring process? Is the recruiting experience hindered by compliance requirements? What technical support is needed to be compliant? Recruiter experience Candidate experience Infrastructure 3 main areas of impact to take in consideration
  • 14. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Data compliance in recruiting Recruiting workflows need to adapt 14 Considerations Consent Management Needs to be explicit under GDPR (EU) - or specifically the PECR rules Data retention and deletion Only opted-in data should be stored under GDPR. Data on citizens from Russia or China might need to be stored in those territories. Sourcing Recruiters might need to send a consent link when first reaching out to candidates in order to record consent Diversity data visibility Certain data fields must be restricted access under EEO
  • 15. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Data compliance in recruiting Candidates understand their data rights Candidates want to… ★ Easily opt out of communications or ask for their data to be deleted (GDPR, CCPA) ★ Know what private data the company is collecting about them (GDPR, CCPA) ★ Be reassured that they won’t be discriminated against based on data shared in the application process (EEO) 15 Recruiters have to... Where applicable, ensure their candidates have been asked to opt-in (or equivalent). Provide opt-out links, understand how to delete/anonymize data Be able to access and share candidate data Restrict access to sensitive data
  • 16. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Data compliance in recruiting Consent capture in applications
  • 17. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Data compliance in recruiting Consent capture - include messaging channels
  • 18. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Data compliance in recruiting Consent capture - include messaging channels
  • 19. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved 19 Give candidates control Talent Portals ● Give candidates granular control of communication preferences, including for types of message, and for medium (e.g. email, sms, notification) ● Enable more granular data capture for opt out reasons ● Give candidates control of accessing their Data, and requesting it to be forgotten / deleted. Provide a control center to manage communication and compliance (e.g. GDPR preferences)
  • 20. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Recipe: Data Privacy Anonymize profile Consent is opted in (364 days) Contact Checked (24hrs)When… Then... Trigger Filter Action If…
  • 21. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved What are the infrastructure and technology considerations? 21 Hosting requirements Automation and AI Sub-processing and integrations Where the data is stored and processed, who can access it and from where, how long it is stored and if a record of all processing is kept, how recruiting teams can manage their workflows in a compliant way at scale… all of the above are influenced by the infrastructure in place.
  • 22. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Data infrastructure considerations: “Critical information operators [and Network operators] that gather or produce personal information...within the mainland territory of the People’s Republic of China, shall store it within mainland China.” Example: China Cybersecurity Law
  • 23. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Data infrastructure considerations “Personal data of Russian citizens must be recorded, systematized, accumulated, stored, refined (i.e. updated, modified), and retrieved only using databases located within Russia. [However], trans-border transfer of personal data to foreign jurisdictions is not prohibited...” Example: Russia data localization requirements
  • 24. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Ask me about global data compliance 24 A guided Q&A… More questions welcome!
  • 25. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Compliance Q&A What are some common misunderstanding around data compliance regulation that you see in TA teams? 25
  • 26. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Compliance Q&A Any low-hanging fruits around data compliance that talent teams can easily address? 26
  • 27. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Compliance Q&A What are the some of the most confusing requirements you’ve seen, and how do companies deal with them? 27
  • 28. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Compliance Q&A What is the first thing to start with when trying to assess the state of your candidate data? 28
  • 29. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Compliance Q&A What should you ask your talent team to understand how compliant you are with applicable data regulation?
  • 30. Beamery.com Private & Confidential - Do Not Share © Beamery Inc. All rights reserved Thank you!