Privacy Policy Statement for employment applications
Last updated 7 November 2024
The protection of your personal data is important to the BNP Paribas Group, which has adopted strong principles in that respect for the entire Group.
This Personal Data Protection Notice has been issued in accordance with Law No. 27 of 2022 concerning Personal Data Protection and its implementing regulations, as may be amended or replaced from time to time (“Indonesian PDP Laws”). It provides you with transparent and detailed information relating to the protection of your personal data processed by PT Bank BNP Paribas Indonesia as a recruiter (“us”) in the context of our application and recruitment procedures.
This Personal Data Protection Notice applies to all candidates who have applied directly or indirectly for a job offer (permanent, fixed term contract, trainee/internship, international volunteer program, summer job, apprenticeship, graduate program, holiday job) from PT Bank BNP Paribas Indonesia (“you”).
As a controller, we are responsible for th e collection and processing of your personal data in relation to our activities, in accordance with the applicable regulations.
This Data Protection Notice lets you know which personal data we collect about you, the reasons why we use and share such data, how long we keep it, what your rights are and how you can exercise them.
This Personal Data Protection Notice may be supplemented, where appropriate, by other local statements, in order to specify certain processing or as it is required to comply with Indonesian local.
1. WHICH PERSONAL DATA DO WE COLLECT AND USE ABOUT YOU?
We collect the following categories of personal data (i.e., any information that identifies or allows identifying you) directly from you when applying for a job offer from PT Bank BNP Paribas Indonesia or from third parties such as recruitment firms, job sites or social networks, to the extent necessary for the purposes detailed in section 3.
Depending on the nature of our intended employment relationship, the targeted position and the stage of recruitment, we may process various types of personal data, including:
- identification and personal information about you (e.g.: full name, identity (such as ID card and passport information), nationality, place and date of birth, gender, family status (e.g. marital status, dependents and date of birth), photograph, video);
- private and professional contact details (e.g.: postal and e-mail addresses, phone number, emergency contact details);
- social insurance number/national insurance number/identification number;
- information about your training and career path (e.g.: education, CV’s, professional qualifications, cover letter, interview);
- information you provide in support of your application (e.g.: declarative data, questionnaire replies, satisfaction survey, interviews, online conversation exchange);
- information from your answers to the various tools used in the recruitment process (e.g.: personality tests or inventories);
- employment information and data related to previous work experience;
- economic and financial information (e.g.: salary expectations, other information necessary to administer payroll and, depending on the situation, details of bank accounts, taxes, pensions, and benefits);
- information about your work permit (e.g.: residence and immigration status);
- recording of data image and sound (e.g.: CCTV (Closed Circuit TeleVision) video surveillance, professional videos and photos, telephone and video calls, conversations and electronic communications); and
- social networks data when it is public and authorized by terms and conditions of social networks.
We may collect and use the following sensitive data only when required by law or when you have given your consent:
- biometric and genetic information (e.g.: the fingerprint, voice pattern, face pattern which can be used for identification and security purposes);
- health data in relation to workplace adaptation needs;
- information on criminal convictions and offences data (e.g.: for investigation or background checks);
- data of children (e.g.: information in family cards); and
- other specific data as stipulated by applicable laws and regulations.
We do not collect nor process personal data related to your ethnic origins, political opinions, religious or philosophical beliefs, or data concerning your sexual orientation unless it is required by law or made public by you and necessary for the purposes for which it is intended.
2. WHO IS CONCERNED BY THIS NOTICE AND FROM WHOM DO WE COLLECT PERSONAL DATA?
This notice is addressed to all candidates as defined above and to your references (former employer, professor, etc.) for whom you have provided us with the contact details.
We may sometimes also collect additional data from other third parties, for example:
- other BNP Paribas Group entities;
- recruitment firms;
- schools and administrations;
- background check providers;
- former employers; and
- social media and other public sources.
When you are providing us personal data about these third parties like the examples listed above, please remember to inform them that we process their personal data and direct them to the present Data Protection Notice.
3. WHY AND ON WHICH BASIS DO WE USE YOUR PERSONAL DATA?
3.1 To comply with our regulatory obligation
As a financial institution and a recruiter, we use your personal data to comply with various regulatory obligations:
- to verify the elements necessary for identity control and conduct identity checks;
- to perform background checks on candidates;
- to implement a system for handling professional alerts;
- to comply with regulation relating to sanctions and embargoes;
- to prevent market abuses by monitoring and recording transactions, phone calls (including VoIP and videoconferences), electronic communications (such as emails, instant messaging (chat) and SMS) in order to identify those which deviate from normal activities and habits such as personal account dealing;
- to ensure transparency of transactions on the financial markets by monitoring and recording transactions, phone calls (including VoIP and videoconferences), electronic communications (such as emails, instant messaging (chat) and SMS) when required;
- to exchange and report different information or reply to official requests from a duly authorized local or foreign financial, tax, administrative, criminal or judicial authorities, arbitrators or mediators, law enforcement, state agencies or public bodies; and
- to maintain security e.g., to ensure network and information security, including protecting BNP Paribas Group against malicious and inadvertent data security breaches.
3.2 To take step at your request prior to entering into a possible contract with you
We use your personal data to conduct the recruitment process to enter into and perform your possible employment contract, including:
- to select and to analyze applications and professional skills (pre-selection of applications);
- to assess and to verify of your abilities, skills, professional skills and interest for the target job (conducting interviews, face-to-face or remote; conducting tests and evaluation);
- to communicate with you about the current recruitment process and your application; and
- to use data collected during the recruitment phase for human resources management purposes for selected candidates.
3.3 To fulfil our legitimate interest
We also collect and use your personal data where we have a legitimate reason:
- to offer you employment opportunities related to your career and skills;
- to inform you of actions or events of interest (such as forums or fairs, conferences or thematic meetings);
- to establish CV-bank for the purpose of researching and identifying candidate profiles;
- to manage recruitment and mobility through the performance and communication of personality tests, matching of personality, comparison of your test result to standard test result to teams involved in the recruitment process;
- to manage our platform for job applications;
- to check professional references;
- to perform background checks when it is required by applicable law;
- to implement a system for handling professional alerts;
- to manage inquiries and surveys;
- to access information from your social network profile (when it is public and is authorized by terms and conditions of the social network);
- to establish aggregated statistics, tests and models (e.g. implementation of chatbots), to improve our processes;
- to conduct data analytics studies to review, better understand and monitor our recruitment procedures;
- to ensure physical security of our buildings, in particular video protection, and managing access to buildings;
- to prevent, detect and manage fraud, bribery andmoney laundering and financing terrorism whenit is required by applicable law;
- to comply with regulation relating to sanctions and embargoes when it is required by applicable laws;
- to monitor compliance with our internal policies and procedures including but not limited to our code of conduct. This may include monitoring and recording of phone calls and voice communications (including VoIP and videoconferences), emails and instant messaging (chat) communications when you interact with our employees subject to specific legal and regulatory obligations; and
- to manage our defense of legal claims and litigation.
In any case, our legitimate interests remain proportionate, and we verify according to a balancing test, that your interests and fundamental rights are preserved. Should you wish to obtain more information about such balancing test, please contact us using the contact details in section 9 “How to contact us” below.
3.4 To respect your choice if we requiested your consent for a specific processing
For certain personal data processing operations, we will communicate additional information and invite you to consent to such processing (note that you may be able to withdraw your consent at any time) notably:
- where the above purposes lead to automated decision-making, which produces legal effects or which significantly, concern and affects you. In this case, we will inform you separately about the logic involved, as well as the significance and the envisaged consequences of such processing;
- if we need to carry out further processing for purposes other than those above, we will inform you and, where necessary, obtain your consent.
4. WHO DO WE SHARE YOUR PERSONAL DATA WITH?
4.1 Sharing of information within the BNP Paribas Group
To fulfil the purposes set out above, we may share your personal data with the following category of recipients:
- Recruitment operational teams including HR people and hiring managers;
- Recruitment tool support teams including system administration teams.
If applicable, to benefit from other job opportunities, your consent will be required for additional data sharing to other BNP Paribas entities (out of PT Bank BNP Paribas Indonesia).
4.2 Disclosing information outside the BNP Paribas Group
In order to fulfil some of the purposes described in the Notice, we may disclose from time to time your personal data with third parties, including:
- service providers and subcontractors performing services on our behalf;
- partners and associations with whom we are partnering or, when you choose to participate in any of their events;
- local or foreign financial, tax, administrative, criminal or judicial authorities, regulators, arbitrators or mediators, law enforcement, state agencies or public bodies, where we are required to disclose data pursuant to:
- their request;
- defending or responding to a matter, action or proceeding;
- complying with regulation or guidance from an authority applying to us.
- certain regulated professionals such as lawyers, notaries, rating agencies or auditors under specific circumstances (e.g. litigation, audit, etc.) or insolvency administrators in case of private bankruptcy.
5. INTERNATIONAL TRANSFERS OF PERSONAL DATA
For any international transfers of personal data outside Indonesia, your personal data will be transferred with an adequate level of data protection pursuant to a mechanism permitted by the Indonesian PDP Laws.
6. HOW LONG DO WE KEEP YOUR PERSONAL DATA?
We will retain your personal data for the period required to comply with the applicable laws and regulations or another period to achieve the purpose for which it was collected and until the applicable limitation periods have expired.
The main retention period applied within our HR systems for Indonesia is 10 years after last contact with you.
7. WHAT ARE YOUR RIGHTS AND HOW CAN YOU EXERCISE THEM?
In accordance with applicable regulations and where applicable, you have the following rights:
- to access: you can obtain information relating to the processing of your personal data and a copy of such personal data;
- to rectify: where you consider your personal data to be inaccurate or incomplete, you may request that your personal data be amended accordingly;
- to erasure: you can require the deletion of your personal data, to the extent permitted by law;
- to restrict: you can request the restriction of the processing of your personal data;
- to object: you can object at any time, on grounds relating to your particular situation, to the processing of your personal data. In such case, we will no longer process your personal data unless we demonstrate compelling legitimate grounds for the processing, which override your interests, rights and freedoms, or for the establishment, exercise or defense of legal claims. You also have the absolute right to object to the processing of your personal data for direct marketing purposes, which includes profiling related to such direct marketing;
- to withdraw your consent: where you have given your consent for the processing of your personal data, you have the right to withdraw your consent at any time;
- to data portability: where legally applicable, you have the right to have the personal data you have provided to us be returned to you or, where technically feasible, transferred to a third party; and
- other rights as stipulated in the Indonesian PDP Laws.
If you wish to exercise any of these rights, you can send your application by mail or by email via the recruitment service to which you have applied and for which an acknowledgement of receipt has been sent.
8. HOW CAN YOU KEEP UP WITH CHANGES TO THIS DATA PROTECTION NOTICE?
In a world of constant regulatory and technological changes, we may need to regularly update this Notice. We invite you to review the latest version of this Notice online.
9. HOW TO CONTACT US?
If you have any questions relating to our use of your personal data under this Notice, you can contact the recruitment service to which you have applied and for which an acknowledgement of receipt has been sent to you.
For the Privacy Policy Statement for employment applications in Bahasa Indonesia, please click here.