Established in 2007, with offices in Cambridge, Milton Keynes, Leeds, and Bristol, Aaron Wallis is a committed independent sales recruiter focusing on permanent, contract and interim sales recruitment.
Our dedicated and friendly sales team are always on hand to deliver a tailored service to guarantee results.
Data Protection and GDPR
Aaron Wallis has taken a lot of time to ensure that all of our processes comply with the General Data Protection Regulation (GDPR). We have always taken data privacy very seriously but as a business that is passionate about continuous improvement, we saw GDPR as an opportunity to revisit our whole process from start to end. We aim to not only ensure that our data is secure, but in revisiting our methods, we hope to provide our clients and candidates with the best possible, and consistent, service.
So What Has Aaron Wallis Done?
Aaron Wallis Recruitment and Training Limited can confirm that we are compliant with the General Data Protection Regulations by the 25th May 2018 implementation date. So, here’s an overview of what we have done:
- Firstly, we have made many behind-the-scenes adjustments to this website:
- Removing email marketing signups
- Making our cookies visible to visitors
- Making the whole site secure with SSL
- Upgrading to an HTTP2 server
- Introduced secure upload facilities for sensitive documents
- Encrypted many web forms (all that require sensitive information, such as the Online Registration Form)
- For clients that require it, we have also introduced a password-locked secure information transfer process.
As a recruiter, we have to store candidate (job seeker) information to provide work-finding services and to match them with suitable roles and employers. We use the industry-leading software, JobAdder, to store data. JobAdder undertakes an independent third party annual SOC 1, Type 2 audit that reviews certain of its internal controls and processes https://www.bullhorn.com/uk/gdpr-commitment-statement
Our sensitive client information, such as mobile contact numbers, are also stored on the same JobAdder ATS and CRM System.
As a business, Aaron Wallis has:
- GDPR Policy adopted
- Conducted a personal Data Audit
- Introduced for ID documents, client data, etc.
- Updated Candidate Registration Form and introduced encrypted security for forms containing sensitive data
- Introduced a range of forms for candidates to consent to allow us to store their CVs and to send their Personal Data to an Employer Client
- Introduced a withdrawal of Consent Form
- Introduced a Subject Access Request Form (SAR) and process
- Amended our website Terms of Use
- Amended our Privacy Policy
- Introduced a transparent cookie policy
- Updated Disclaimers
- Updated Complaint Procedure and Policy
- Updated Equal Opportunities and Diversity Policy
- Introduced a Data Retention Policy
- Introduced a Data Breach Policy with a formal 72-hour breach process documented for reporting incidents, with and Data Breach Register Log
- Introduced a Candidate Privacy Notice
- Appointed a DPO with Job Description
- Updated Candidate Terms of Business
- Updated Employer Client Terms of Business with data protection, liability and indemnity provisions
- Audited all third-party suppliers and ensured that their data protection policies and privacy notices clear and easy to read
- Introduced a Clear Desk Policy
- Amended the IT security policy that includes provisions to never hold sensitive data locally
- All paper records containing sensitive data have been securely destroyed together with HDD back up servers and obsolete equipment
- Introduced Candidate consent on all applications with a withdrawal of consent process
- Introduced Candidate Consent for candidates sourced from third-parties, such as LinkedIn, Job Boards and headhunting
- ‘Right to be forgotten’ process created and implemented with full SAR and data erasure procedure
- Designed a Business Critical dataflow diagram and IAO structure
- Staff training on GDPR completed including two formal courses completed by operational staff - ‘The Essentials of GDPR’ and ‘Cyber Security Awareness’. All staff aware of Internal IT security Policy which is confirmed in the Employee Handbook alongside contracts
- Offered new employee contracts for staff and updated staff handbook
- Internal IT and Social Media Policy updated
- Post–Brexit Aaron Wallis do not intend to have representation based from the EEA
What Are the New and Updated Forms
Candidate Consent to Send Personal Data to Employer Client
Candidate Consent Declaration and to Send Personal Data to Employer Client
Complaint Procedure and Policy
Search jobs
With hundreds of jobs available, now is the time to look for your perfect position
by Rob Scott
Managing Director
About the author
Rob Scott