Last updated: May 2022
Quick links
Use the links below to go straight to the information you need.
- About this notice
- Eversheds Sutherland’s data protection responsibilities
- What types of personal data do we collect and where do we get it from?
- What do we do with your personal data, and why?
- Automated decision-making
- Anonymised and aggregated data
- Sensitive personal data (including criminal data)
- Who do we share your personal data with, and why?
- Where in the world is your personal data transferred to?
- How do we keep your personal data secure?
- How long do we keep your personal data for?
- What are your rights in relation to your personal data and how can you exercise them?
- Categories of personal data
- Purposes for processing personal data
- Purposes for processing sensitive personal data
- Individuals' rights
About this notice
This Privacy Notice applies to the Eversheds Sutherland network of law firms except for the ES entities in Austria, Czech Republic, Finland, Hungary, Italy, Slovakia, Sweden and Switzerland, which their own Privacy Notices that apply instead.
This notice explains how and why Eversheds Sutherland uses personal data about individuals who apply (or enquire about applying) to become our employees, partners, staff, contractors, trainees, officers, consultants, work experience students, vacation scheme students, apprentices and temporary or agency workers (referred to as “ applicants ” or “ you ”). You should read this notice, so you know what we are doing with your personal data. Please also read any other privacy notices that we give you, that might apply to our use of your personal data in specific circumstances in the future. For example, if you are successful in your application you should read our HR Privacy Notice when you join us.
For the purposes of this notice, the controller will be the Eversheds Sutherland entity that you are applying for a role with (the controller is also referred to in this notice as “ Eversheds Sutherland ”, “ ES ” “ we ”, “ our ” and “ us ”). View a list of the Eversheds Sutherland operating entities and their contact details.
This notice does not form part of any contract between us and you (including any contract of employment that may be offered or any other services contract).
Eversheds Sutherland’s data protection responsibilities
“ Personal data ” is any information that relates to an identifiable natural person. Your name, address, contact details, salary details and CV are all examples of your personal data, if they identify you.
The term “ process ” means any activity relating to personal data, including, by way of example, collection, storage, use, consultation and transmission.
Eversheds Sutherland is a “ controller ” of your personal data. This is a legal term – it means that we make decisions about how and why we process your personal data and, because of this, we are responsible for making sure it is used in accordance with data protection laws.
What types of personal data do we collect and where do we get it from?
We collect many different types of personal data about you for lots of reasons. We cannot administer your application without your personal data. Where we don’t need your personal data, we will make this clear, for instance we will explain if any data fields in our application forms are optional and can be left blank.
Further details of the personal data we collect and where we get it from are set out at Schedule 1.
As you can see from the table at Schedule 1, we collect your personal information from you directly and sometimes we obtain it from other people and organisations, including some public sources, such as publicly available directories and online resources, your emergency contacts, your use of Eversheds Sutherland provided assets, systems and platforms, your line manager and co-workers, your dependants and beneficiaries, third party benefits providers.
If any of the personal information you have given to us changes, such as your contact details, please inform us without delay by contacting recruitment@eversheds-sutherland.com.
What do we do with your personal data, and why?
We process your personal data for particular purposes in connection with your application or engagement with us, and in connection with the management and administration of recruitment activities and strategies.
We are required by law to always have a “lawful basis” (i.e. a reason or justification) for processing your personal data. There are six lawful bases for processing – they are set out in the law, and they are where:
- the individual has given his or her consent to the processing;
- the processing of the individual’s personal data is necessary to perform a contract with that individual or to take steps at the request of the individual before entering into a contract;
- the processing is necessary to comply with a legal obligation to which we are subject;
- the processing is necessary in order to protect the vital interests of an individual;
- the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us; and
- the processing is necessary for our legitimate interests, provided those interests are not overridden by the individual’s interests, rights or freedoms.
The table at Schedule 2 sets out the different purposes for which we process your personal data and the relevant lawful basis on which we rely for that processing.
If you would like more information on any of the purposes for which we process your personal data, please contact the Risk team at datagovernance@eversheds-sutherland.com for more information.
Please note that:
- where our processing is based on your consent, you can withdraw your consent at any time. If you do this, it won’t impact any processing we’ve done prior to that date.
- where we process your personal data because it is necessary for our legitimate interests, you can object to our processing at any time. If you object, we will stop processing unless we can show you a compelling reason why the processing overrides your privacy rights or where the processing is for the establishment, exercise or defence of legal claims.
In addition, where we have indicated in Schedule 2 that our processing of your personal data is either:
- necessary for us to comply with a legal obligation; or
- necessary for us to take steps, at your request, to potentially enter into an employment contract with you, or to perform it,
- and you choose not to provide the relevant personal data to us, we may not be able to enter into our contract of employment or engagement with you.
Automated decision-making
Sometimes, we may use your personal data for automated decision making (in other words, decision-making without any human involvement), for example when we set up automated alerts in our background checking processes.
If any of our automated decision-making has legal or other significant effects on you, we will only make those decisions if:
- it is necessary for us to enter into or perform a contract with you; or
- it is authorised by applicable law; or
- we have your explicit consent.
Anonymised and aggregated data
We may also convert your personal data into statistical or aggregated form to better protect your privacy, or so that you are not identified or identifiable from it. Anonymised data cannot be linked back to you. We may use it to conduct research and analysis, including to produce statistical research and reports. For example, to help us understand which of our practice groups attract the most applicants.
Sensitive personal data (including criminal data)
We are required by law to treat certain categories of personal data with even more care than usual. These are called special categories of personal data – and in this notice, we refer to them as “ sensitive personal data ”. For these categories of personal data, different lawful bases apply.
The table at Schedule 3 sets out the different purposes for which we process your sensitive personal data and the relevant lawful basis on which we rely for that processing. For some processing activities, we consider that more than one legal basis may be relevant – depending on the circumstances.
Who do we share your personal data with, and why?
Sometimes we need to disclose your personal data to other people.
Inside the Eversheds Sutherland network
We are part of the Eversheds Sutherland network of law firms. Therefore, we may share your personal data with other entities in the Eversheds Sutherland network for our general recruitment analysis and workforce management purposes.
Access rights between members of the Eversheds Sutherland network are limited and granted only on a need to know basis, depending – for example – jurisdictions, departments, job functions and roles.
Where any Eversheds Sutherland entities process your personal data on our behalf (as our processor), we will make sure that they have appropriate security standards in place to make sure your personal data is protected and we will enter into a written contract imposing appropriate security standards on them.
Outside the Eversheds Sutherland network
From time to time we may ask third parties to carry out certain business functions for us, such as the administration of our payroll and our IT support. These third parties will process your personal data on our behalf (as our processor). We will disclose your personal data to these parties so that they can perform those functions. Before we disclose your personal data to other people, we will make sure that they have appropriate security standards in place to make sure your personal data is protected and we will enter into a written contract imposing appropriate security standards on them. Examples of these third party service providers include service providers and/or sub-contractors, include our outsourced payroll, HR and marketing service providers, and our IT systems software and maintenance, back up, and server hosting providers.
In certain circumstances, we will also disclose your personal data to third parties who will receive it as controllers of your personal data in their own right for the purposes set out above, in particular:
- if we transfer, purchase, reorganise, merge or sell any part of our business or the business of a third party, and we disclose or transfer your personal data to the prospective seller, buyer or other third party involved in a business transfer, reorganisation or merger arrangement (and their advisors); and
- if we need to disclose your personal data in order to comply with a legal obligation, to enforce a contract or to protect the rights, property or safety of our employees, clients or others.
We have set out below a list of the categories of recipients with whom we are likely to share your personal data:
- consultants and professional advisors including legal advisors and accountants;
- recruitment agencies appointed by us or you;
- courts, court-appointed persons/entities, receivers and liquidators;
- business partners and joint ventures;
- trade associations and professional bodies;
- insurers; and
- governmental departments, statutory and regulatory bodies.
Where in the world is your personal data transferred to?
As we are an international network of law firms operating under a single brand, we may transfer your personal data to recipients that are established in jurisdictions other than your own. The data protection laws in these jurisdictions may not provide the same level of protection to your personal data as provided to it in your jurisdiction.
If you are employed or engaged by an Eversheds Sutherland entity in the United Kingdom or European Union and any disclosures of personal data referred to above require us to transfer your personal data from within the European Union to outside the European Economic Area, or from within the United Kingdom to outside the United Kingdom, we will only make that transfer if:
- the country to which the personal data is to be transferred ensures an adequate level of protection for personal data;
- we have put in place appropriate safeguards to protect your personal data, such as an appropriate contract with the recipient. Please contact our Data Protection Office at datagovernance@eversheds-sutherland.com if you wish to obtain a copy of these;
- the transfer is necessary for one of the reasons specified in data protection legislation, such as the performance of a contract between us and you; or
- you explicitly consent to the transfer.
How do we keep your personal data secure?
We will take specific steps (as required by applicable data protection laws) to protect your personal data from unlawful or unauthorised processing and accidental loss, destruction or damage.
How long do we keep your personal data for?
If you are our employee we will keep your personal data during the period of your employment and then, after your employment with us ends, for as long as is necessary in connection with both our and your legal rights and obligations. This may mean that we keep some types of personal data for longer than others.
We will only retain your personal data for a limited period of time. This will depend on a number of factors, including:
- any laws or regulations that we are required to follow;
- whether we are in a legal or other type of dispute with each other or any third party;
- the type of information that we hold about you; and
- whether we are asked by you or a regulatory authority to keep your personal data for a valid reason.
Please contact our Data Protection Office at datagovernance@eversheds-sutherland.com to request a copy of our Data Retention Policy.
What are your rights in relation to your personal data and how can you exercise them?
You may have certain legal rights in relation to your personal data, particularly where the Eversheds Sutherland entity you are applying to is based in the United Kingdom or European Union which are summarised at Schedule 4, in relation to any personal data about you which we hold.
Where our processing of your personal data is based on your consent (see Schedule 2), you have the right to withdraw your consent at any time. If you do decide to withdraw your consent we will stop processing your personal data for that purpose, unless there is another lawful basis we can rely on – in which case, we will let you know. Your withdrawal of your consent won’t impact any of our processing up to that point.
Where our processing of your personal data is necessary for our legitimate interests (see Schedule 2), you can object to this processing at any time. If you do this, we will need to show either a compelling reason why our processing should continue, which overrides your interests, rights and freedoms or that the processing is necessary for us to establish, exercise or defend a legal claim.
If you wish to exercise any of these rights please contact dataprotectionoffice@everhseds-sutherland.com in the first instance.
If you are based in the European Union or United Kingdom or you are applying for a position with an ES entity based in the European Union or United Kingdom, you also have the right to lodge a complaint with the relevant data protection supervisory authority – for contact details see here.
Updates to this notice
We may update this notice from time to time to reflect changes to the type of personal data that we process and/or the way in which it is processed. We will update you on material changes to this notice by email and we will publish revised versions of this notice on www.eversheds-sutherland.com.
Where can you find out more?
If you have any queries about how Eversheds Sutherland process your personal data, please contact the Risk team at datagovernance@eversheds-sutherland.com.
SCHEDULE 1
Categories of personal data
The table below sets out the different categories of personal data we collect and where we get it from (we’ve sorted them into groups, to make it more clear for you). As you can see, we collect your personal information from you directly and sometimes we obtain it from other people and organisations, including some public sources, such as publicly available directories and online resources, your emergency contacts, your use of Eversheds Sutherland provided assets, systems and platforms, your line manager and co-workers, your dependants and beneficiaries, third party benefits providers.
| Types of personal data | Collected from |
| a) Contact Information | |
|
|
| b) Personal Information | |
|
|
| c) Identity and Background Information | |
|
|
| d) Sensitive Personal Data (see section 5 for further information) | |
|
|
| e) Recruitment Administration, Performance and Grievance Information | |
|
|
| f) Asset, Systems and Platform Usage and Communications Information | |
|
|
| g) Security, Location and Access Information | |
|
|
SCHEDULE 2
Purposes for processing personal data
The table below sets out the different purposes for which we process your personal data and the relevant lawful basis on which we rely for that processing.
For some processing activities, we consider that more than one lawful basis may be relevant – depending on the circumstances.
| Lawful basis We are permitted to process your personal data because... |
|||||
| Purposes of processing | You have given your consent to the processing (Please also see section 10.2) | It is necessary to perform your employment contract | It is necessary for us to comply with a legal obligation | It is necessary for our legitimate interests or those of third parties (Please also see section 10.3) | It is necessary to protect your vital interests (or those of someone else) |
| New joiner activities | |||||
| Developing, operating and collecting feedback on recruitment activities and employee selection processes | Yes | ||||
| Administering your application for a job with us and considering your suitability for the relevant role | Yes |
||||
| Obtaining, considering and verifying your employment references and employment history |
Yes |
||||
| Reviewing and confirming your right to work |
Yes |
||||
| Conducting verification and vetting, including criminal background checks and credit checks where required by law (Note: Sensitive Personal Data, please also see Schedule 3) |
Yes |
||||
| Conducting background checks, credit checks, verification and vetting which are not required by law but needed by us to assess your suitability for your role (Note: May involve Sensitive Personal Data, please also see Schedule 3) |
Yes |
Yes |
|||
| Making a job offer to you and entering into a contract of employment with you |
Yes |
||||
| Identifying and assessing our strategic business direction, resourcing needs and areas for development |
Yes |
||||
| Analysing recruitment and retention objectives, processes and employee turnover rates |
Yes |
||||
| Communicating with you and providing you with information in connection with your application or engagement with us from time to time |
Yes | Yes | Yes | ||
| General staff administration, including workforce management and facilities operations |
Yes | ||||
| Managing our health and safety compliance obligations (Note: Sensitive Personal Data, please also see Schedule 3) |
Yes | ||||
| Determining whether any adjustments are necessary to enable you to carry out a role (Note: Sensitive Personal Data, please also see Schedule 3) |
Yes | Yes | |||
| Considering your suitability for existing and future vacancies |
Yes | ||||
| Handling grievances and complaints, including investigating issues, considering appropriate resolution and mitigating actions and reviewing outcomes |
Yes | ||||
| Responding to feedback from you or your recruitment agent |
|||||
| Security and governance | |||||
| Monitoring the security of Eversheds Sutherland’s physical premises and systems, networks and applications | Yes | Yes | |||
| Identifying and authenticating applicants and other individuals (Note: Sensitive Personal Data, please also see Schedule 3) |
Yes | ||||
| Identifying, investigating and mitigating suspected misuse of Eversheds Sutherland’s assets, systems and platforms (Note: Sensitive Personal Data, please also see Schedule 3) |
Yes | Yes |
|||
| Ensuring compliance with Eversheds Sutherland policies and procedures (Note: Sensitive Personal Data, please also see Schedule 3) |
Yes | ||||
| Legal and regulatory compliance and responsibilities |
|||||
| Managing and administering our equal opportunities reporting (Note: Sensitive Personal Data, please also see Schedule 3) |
Yes | ||||
| Responding to binding requests or search warrants or orders from courts, governmental, regulatory and/or enforcement bodies and authorities (Note: Sensitive Personal Data, please also see Schedule 3) |
Yes | ||||
| Responding to non-binding requests or search warrants or orders from courts, governmental, regulatory and/or enforcement bodies and authorities |
Yes | ||||
| Complying with disclosure orders arising in civil proceedings (Note: Sensitive Personal Data, please also see Schedule 3) |
Yes | ||||
| Investigating, evaluating, demonstrating, monitoring, improving, reporting on and meeting Eversheds Sutherland’s compliance with relevant legal and regulatory requirements (Note: Sensitive Personal Data, please also see Schedule 3) |
Yes | ||||
| Investigating, evaluating, demonstrating, monitoring, improving, reporting on and meeting Eversheds Sutherland’s compliance with best practice and good governance responsibilities |
Yes | ||||
| Eversheds Sutherland business operations |
|||||
| Implementing, adapting and enhancing systems and processes to develop or improve our business and/or our recruitment process |
Yes | ||||
| Managing, planning and delivering events, projects and initiatives in connection with our global business, Finance, Sales, HR, IT, Marketing and other strategies (for example arranging partner and practice group conferences) |
Yes | ||||
| Supporting our diversity programmes and targets (Note: Sensitive Personal Data, please also see Schedule 3) |
Yes | ||||
| Supporting, updating and maintaining our technology infrastructure |
Yes | Yes | |||
| Supporting the sale, transfer or merging of part or all of our business or assets, or in connection with the acquisition of another business |
Yes | Yes | |||
| Analysing recruitment-related objectives and results | Yes | ||||
| Collecting feedback in relation to our recruitment and HR activities and processes for continuous improvement purposes |
Yes | ||||
SCHEDULE 3
Purposes for processing sensitive personal data
The table below sets out the different purposes for which we process your sensitive personal data and the relevant lawful basis on which we rely for that processing. For some processing activities, we consider that more than one legal basis may be relevant – depending on the circumstances.
| Sensitive information - lawful basis We are permitted to process your personal data because... |
||||||
| Purposes of processing | You have given your explicit consent to the processing | It is necessary for your/our obligations and rights in the field of employment and social security and social protection law | It is necessary to protect the vital interests of the data subject or another person you or they are physically or legally incapable of giving consent | It is necessary for our establishment, exercise or defence of legal claims | It is necessary for reasons of substantial public interest | It is necessary for preventive or occupational medicine, for the assessment of the working capacity of the employee |
| Recruitment and workforce planning | ||||||
| Conducting verification and vetting, including criminal background checks and credit checks where required by law | Yes |
Yes |
||||
| Conducting background checks, verification and vetting which are not required by law but needed by us to assess your suitability for your role | Yes | Yes |
||||
| General application management and administration |
||||||
| Managing our health and safety compliance obligations |
Yes |
Yes |
||||
| Determining whether any adjustments are necessary to enable you to carry out a role |
Yes |
Yes |
||||
| Security and governance |
||||||
| Identifying and authenticating Applicants and other individuals |
Yes | Yes | ||||
| Identifying, investigating and mitigating suspected misuse of our assets, systems and platform |
Yes | |||||
| Legal and regulatory compliance and responsibilities |
||||||
| Managing and administering our equal opportunities reporting |
Yes | Yes | ||||
| Responding to binding requests or search warrants or orders from courts, governmental, regulatory and/or enforcement bodies and authorities or sharing information (on a voluntary basis) with the same |
Yes | |||||
| Responding to non-binding requests or search warrants or orders from courts, governmental, regulatory and/or enforcement bodies and authorities |
Yes | |||||
| Complying with disclosure orders arising in civil proceedings |
Yes | |||||
| Investigating, evaluating, demonstrating, monitoring, improving and reporting on our compliance with relevant legal and regulatory requirements |
Yes | |||||
| Investigating, evaluating, demonstrating, monitoring, improving, reporting on and meeting our compliance with best practice and good governance responsibilities |
Yes | Yes | ||||
| Day-to-day business operations |
||||||
| Supporting the sale, transfer or merging of part or all of our business or assets, or in connection with the acquisition of or by another business |
Yes | |||||
SCHEDULE 4
Individuals' rights
| Your right | What does it mean? | Limitations and conditions of your right |
|---|---|---|
| Right of access | Subject to certain conditions, you are entitled to have access to your personal data (this is more commonly known as submitting a “data subject access request”). | If possible, you should specify the type of information you would like to see to ensure that our disclosure is meeting your expectations. We must be able to verify your identity. Your request may not impact the rights and freedoms of other people, eg privacy and confidentiality rights of other staff. |
| Right to data portability | Subject to certain conditions, you are entitled to receive the personal data which you have provided to us and which is processed by us by automated means, in a structured, commonly-used machine readable format. | If you exercise this right, you should specify the type of information you would like to receive (and where we should send it) where possible to ensure that our disclosure is meeting your expectations. This right only applies if the processing is based on your consent or on our contract with you and when the processing is carried out by automated means (i.e. not for paper records). It covers only the personal data that has been provided to us by you. |
| Rights in relation to inaccurate personal or incomplete data | You may challenge the accuracy or completeness of your personal data and have it corrected or completed, as applicable. You have a responsibility to help us to keep your personal information accurate and up to date. We encourage you to notify us of any changes regarding your personal data as soon as they occur, including changes to your contact details, telephone number, immigration status. |
Please always check first whether there are any available self-help tools to correct the personal data we process about you. This right only applies to your own personal data. When exercising this right, please be as specific as possible. |
| Right to object to or restrict our data processing | Subject to certain conditions, you have the right to object to or ask us to restrict the processing of your personal data. | As stated above, this right applies where our processing of your personal data is necessary for our legitimate interests. You can also object to our processing of your personal data for direct marketing purposes. |
| Right to erasure | Subject to certain conditions, you are entitled to have your personal data erased (also known as the “right to be forgotten”), eg where your personal data is no longer needed for the purposes it was collected for, or where the relevant processing is unlawful. | We may not be in a position to erase your personal data, if for example, we need it to (i) comply with a legal obligation, or (ii) exercise or defend legal claims. |
| Right to withdrawal of consent | As stated above, where our processing of your personal data is based on your consent you have the right to withdraw your consent at any time. | If you withdraw your consent, this will only take effect for future processing. |