Job Application Privacy Notice

Last Revised 14/08/2023

Download a copy of this notice

Data controller: Moatfield Surgery

Data protection officer: Laura Taw | Email:

The practice gathers and processes personal data relating to its employees to enable us to run the business and manage our relationship with you. We are committed to being open and transparent about how we gather and use that data and to meeting our data protection obligations.

Collecting information

We will collect and use the following types of personal data about you:

  • Recruitment Information such as your application form and CV, references, qualifications ad membership of any professional bodies and details of any pre-employment assessments.
  • Your contact details and date of birth
  • Information about your current level of remuneration, including benefit entitlements
  • Whether or not you have a disability for which the practice needs to make reasonable adjustments during the recruitment process
  • Information in relation to your right to work in the UK
  • Information from the Disclosure and Barring Service (DBS) in order to administer relevant checks and procedures;

The practice may collect this information in a variety of ways, for example from application forms, CVs or resumes, obtained from your passport or other identity documents such as your driving licence, from forms completed by you or through interviews, meetings or other assessments, including on-line tests.

This personal data might be provided to us by you, or someone else (such as a former employer’s reference, information from background check providers including criminal records checks permitted by law) or it could be created by us.

The practice will seek information from third parties only once a job offer has been made to you and we will inform you that we are doing so.

Your personal data will be stored in a range of different places, including in your application record, in the practice's HR management systems and in other IT systems (including the practice's email system).


Processing your Personal Data

The practice will process your personal data (including special categories of personal data) in accordance with our obligations under the 2018 Act.

The practice will process your personal data (including special categories of personal data) in accordance with our obligations under the 2018 Data Protection Act.

We will use your personal data:

  • To take steps at your request prior to entering into a contract with you to enter into a contract with you
  • To comply with any legal obligations
  • If it is necessary for our legitimate interests (or for the legitimate interests of someone else). However, we can only do this if your interests and rights do not override ours (or theirs). You have the right to challenge our legitimate interests and request that we stop this data processing.

We will process employee data for the purpose of:

  • Assisting in decision making in recruitment and promotion procedures
  • Assessing and confirming a candidate’s suitability for employment
  • Maintaining accurate and up-to-date recruitment records
  • Obtaining occupational health advice, to ensure that it complies with duties in relation to individuals with disabilities and meets its obligations under health and safety laws
  • Ensuring effective general HR and business administration
  • Obtaining references from third parties
  • Responding to and defending legal claims


Special categories of personal data

Some special categories of personal data, such as information about health or medical conditions, is processed to carry out employment law obligations (such as those in relation to job applicants with disabilities).

For some roles, the practice is obliged to seek information about criminal convictions and offences. Where we seek this information, we do so because it is necessary for us to carry out our obligations and exercise specific rights in relation to employment.

Where the practice processes other special categories of personal data, such as information about ethnic origin, sexual orientation or religion or belief, this is done for the purposes of equal opportunities monitoring. Data that the practice uses for these purposes is anonymised or is collected with the express consent of job applicants, which can be withdrawn at any time. Job applicants are entirely free to decide whether or not to provide such data and there are no consequences of failing to do so.

If your application is unsuccessful, the practice may keep your personal data on file in case there are future job opportunities for which you may be considered. We will seek your consent to do this and you are free to withdraw your consent at any time.


Automated Decision-Making

Employment decisions are not based solely on automated decision-making.


Sharing your personal data

Your information may be shared internally for the purpose of the recruitment exercise, including with members of the HR and recruitment team, interviewers in the recruitment process, managers in the business area with the vacancy and IT staff if access to the data is necessary for performance of their roles.

The practice will not share your personal data with third parties, except those engaged for the purposes of the recruitment process, or unless your application for employment is successful and we make you an offer of employment. We will then share your data with former employers to obtain references for you, employment background check providers to obtain necessary background checks and the Disclosure and Barring Service to obtain necessary criminal record checks.


Protection of personal data

The practice has internal policies and controls in place to ensure that your personal data is not lost, accidentally destroyed, misused or disclosed and is not accessed except by its employees in the performance of their duties.

St Michaels Road, East Grinstead, RH19 3GW 4 Where the practice engages third parties to process personal data on its behalf, they do so on the basis of written instructions, are under a duty of confidentiality and are obliged to implement appropriate technical and practical measures to ensure the security of data.


Retention of data

If your application is unsuccessful, the practice will hold your personal data for a period of six months following the recruitment process. If you agree to allow the practice to keep your personal data on file, for consideration for future job opportunities, we will hold your data for a further six months. At the end of that period (or once you withdraw consent), your data will be deleted or destroyed.

If your application for employment is successful, personal data gathered during the recruitment process will be transferred to your personnel file and retained during your employment. The periods for which your data will be held will be provided to you in a new privacy notice.


Storing DBS Certificates

The correct storage of DBS certificate information is important. The code of practice requires that the information revealed is considered only for the purpose for which it was obtained and should be destroyed after six months.


Your data subject rights:
  • You have the right to information about what personal data we process, how and on what basis as set out in this document
  • You have the right to access your own personal data by way of a subject access request
  • You can correct any inaccuracies in your personal data
  • You have the right to request that we erase your personal data where we were not entitled under the law to process it or it is no longer necessary to process it for the purpose it was collected
  • While you are requesting that your personal data is corrected or erased or are contesting the lawfulness of our processing, you can apply for its use to be restricted while the application is made
  • You have the right to object to data processing where we are relying on a legitimate interest to do so and you think that your rights and interests outweigh our own and you wish us to stop
  • You have the right to object if we process your personal data for the purposes of direct marketing
  • You have the right to receive a copy of your personal data and to transfer your personal data to another data controller. We will not charge for this and will, in most cases, aim to do this within one month
  • You have the right to be notified of a data security breach concerning your personal data
  • With some exceptions, you have the right not to be subjected to automated decision making
  • In most situations we will not rely on your consent as a lawful ground to process your data. If we do however request your consent to the processing of your personal data for a specific purpose, you have the right not to consent or to withdraw your consent later.

If you would like to exercise any of these rights, or withdraw your consent, please contact Michael Bebbington, Operations Manager.


Accessing your data

The practice is legally required to act on requests and provide information free of charge with the exception of requests that are manifestly unfounded, excessive or repetitive.

If the practice determines this to be the case we may charge a reasonable fee or refuse to act on the request. We will acknowledge your request and provide the information within one month of receiving your request.

Please send your request to Michael Bebbington, Operations Manager.


Lodging a complaint

If you are not satisfied with our response or believe we are processing your personal information in a way that is not in accordance with the law, you have the right to lodge a complaint with the supervisory authority in the UK responsible for the implementation and enforcement data protection law: the ICO.

You can contact the ICO via the following:


Telephone: 0303 123 1113


Reviews of and Changes to our Privacy Notice

We keep our Job Applicant Privacy notice under regular review. This notice was last reviewed on 14th August 2023



Page Last Updated 16/08/2023