Processing of (personal) data by the entity in charge of the online application process
TORAY GROUP (GENERAL) PRIVACY NOTICE
FOR EMPLOYEES AND APPLICANTS
(EU VERSION)
PLEASE READ THIS PRIVACY NOTICE CAREFULLY
OUR PRIVACY NOTICE
The protection of your personal data is of great importance to Toray International Europe GmbH (“OUR COMPANY” or “we” or “us”) and Toray Group worldwide (“TORAY Group”) and in particular the affiliates of TORAY Industries, Inc., Japan in the EU (such European entities jointly “TORAY EU Companies” or individually a “TORAY EU Company”). TORAY EU Companies are committed to protecting the personal data that you share with us. This Privacy Notice (the “Privacy Notice”) therefore intends to inform you in accordance with Articles 13 and 14 EU GDPR (as defined below) as Employee or prospective Employee of OUR COMPANY about how we, acting as data controller, collect, use and share your personal data. We also act as data controllers when we process your personal data received or obtained through third parties.
This Privacy Notice sets out how we collect and use your personal data before, during and after your working relationship with us. As part of any recruitment process, OUR COMPANY collects and otherwise processes personal data relating to job applicants. We are committed to being transparent about how we collect and use that data and to meeting our data protection obligations.
For the purposes of this Privacy Notice, the term "Employee" includes those who work on a permanent and non-permanent basis, including temporary and contract workers, independent contractors, consultants, professional advisors, trainers, work experience/placement students and secondees.
We process your personal data in accordance with the applicable EU and Member State regulations on data protection, the most notable of which is, the EU General Data Protection Regulation No 2016/679 (the “EU GDPR”).
We encourage you to read this Privacy Notice carefully.
WHAT TYPES OF PERSONAL DATA DO WE USE?
When you apply for an employment with OUR COMPANY or are an Employee of OUR COMPANY, we may collect, store, and use the following categories of personal data (“Personal Data”) about you in connection with your (prospective) employment with us:
- personal contact details such as name, title, addresses, telephone numbers, and personal email addresses;
- date and place of birth;
- gender;
- picture;
- information about your marital status, name, gender and date of birth of spouse and dependents (the “Family”);
- health insurance information about you and your Family;
- next of kin and emergency contact information;
- national tax and insurance number;
- bank account details, payroll records and tax status information;
- salary, annual leave, pension and benefits information;
- start date and location of employment/workplace;
- copy of licenses required in connection with your work such as driving license;
- copy of passport or other ID;
- recruitment information (including copies of right to work and VISA documentation, references and other information included in a CV or cover letter or as part of the application process);
- employment records (including job titles, work history, working hours, qualifications, training records and professional memberships);
- details of your existing and previous salary and fringe benefits;
- performance information (e.g., evaluation by supervisor as well as own assessment as part of the performance management process and/or performance review, employee development measures);
- disciplinary and grievance information;
- Video surveillance footage and other information obtained through electronic means;
- Data from the performance of employment, including work time, IT application and data usage (such as system and device passwords), system and device logs, and electronic content generated by you using our systems and devices (emails, documents, etc.), business trip information, customer relationship management and sales information (such as customer contacts, visit reports);
- photographs;
- employee number;
- absence records;
- health and safety records; and
- other documents arising during the course of employment including, without limitation, accident records and signed company rules and procedures.
We may also collect, store and use the following “special categories” of more sensitive Personal Data:
- information about trade union membership;
- information about your health, including any medical condition, health and sickness records;
- biometric data;
- information about criminal convictions and offences.
FOR WHAT PURPOSES DO WE PROCESS YOUR PERSONAL DATA?
We will process your Personal Data for the following purposes:
- Personnel planning and personnel management such as recruitment, transfer and promotion, accounting and payment of your remuneration and compensation, organization of your business trips and reimbursement of your business trip expenses as well as other company-related expenses, management of your sick leave and vacation, management of employee contributions and social security contributions, implementation of employment contracts (such as time recording, measurement, evaluation and remuneration of work performance), company care and safety and disaster prevention management, organization and implementation of employee events;
- Occupational health and safety such as contacting your family in emergency, inspecting workplaces or work sites for occupational health and safety to meet health requirements.
- General business management such as quality and regulatory management, financial management including compliance with capital market requirements, risk and claims management, company car management, conducting internal audits and investigations and press relation management;
- Provision of credit cards for processing company-related payments;
- Management of the work equipment provided to you, e.g. telephone, computer, cell phones, other IT equipment; maintenance of internal contact directories; management of access authorizations to systems and applications and authentication, such as when entering a building or parking garage using an access card; administration of user accounts and assignment of authorizations;
- Conduct of employee surveys;
- Video surveillance for the purpose of controlling access to office buildings;
- IT security (including logging of IT usage and defense against cyber-attacks).
FOR WHICH LEGAL BASES DO WE PROCESS YOUR PERSONAL DATA?
If you are a job applicant:
If you send us an application to become an Employee at OUR COMPANY, we will, in general, only consider your Personal Data for the post you applied for. In the course of the application process, we may also gather additional information about you from publicly available sources, former employers and instructors.
Legal basis for the data processing is to enter into an employment contract with you (Article 6(1)(b) EU GDPR). If the application process will not result in you becoming an Employee of a TORAY EU Company, we will delete all your Personal Data six months after the end of the application process.
Should you however provide us with an unsolicited application which is not aiming at a specific job or if you are not chosen for the post of your choice but you are still interested in other posts at OUR COMPANY, we may use your application for any relevant positions at one or more TORAY EU Companies (within any geographical or other limitations contained in your application) based on your consent (Article 6(1)(a) EU GDPR). In such case we may make available your application and Personal Data to selected responsible personnel within the relevant TORAY EU Company which decides on applications, so that such persons can inform themselves about your personal profile and your qualifications. We will in such case delete your data within six months after receipt of your application, however not before all application processes for which your application and Personal Data has been used have been terminated and an additional six-month period has lapsed thereafter.
If you are our Employee:
We process the categories of your Personal Data either on the basis of
- our overriding legitimate interest according to Article 6(1)(f) EU GDPR, which is to efficiently manage our human resources as well as our internal and external communication, or
- the performance of the contract we have concluded with you or the necessity to take steps at your request prior to entering into such an agreement, insofar as it is necessary (Article 6(1)(b) EU GDPR), or
- the necessity to comply with legal obligations to which we are subject (Article 6(1)(c) EU GDPR).
Insofar as sensitive Personal Data is concerned, processing takes place to comply with obligations under social or employment law to which we are subject (Article 9(2)(b) EU GDPR).
In certain special cases, when none of the above basis is applicable, we might ask for your consent to process your Personal Data in pursuant to Article 6(1)(a) and Article 7 EU GDPR.
We will hold your Personal Data for the duration of your employment and for any length after this to adhere to legal and statutory obligations, which usually is at least 10 years after the end of your employment relationship with the relevant TORAY EU Company.
HOW DO WE SHARE YOUR PERSONAL DATA?
If you are a job applicant:
If you are a job applicant, we don’t share applicant’s Personal Data with any other TORAY Group companies than OUR COMPANY unless you have made an unsolicited application or if we have your consent to share your Personal Data with other entities of TORAY Group, in which case we may share your Personal Data as further explained under Section 4 above.
If you are an Employee:
If you are an Employee of a TORAY EU Company, we may share your Personal Data internally, including with members of the legal team, the HR team, payroll, your line manager, managers in the business area in which you work, Directors and IT staff if access to the Personal Data is necessary for performance of their roles.
TORAY EU Companies may also share your Personal Data with third parties for certain purposes including:
- Providers of public benefits, such as health insurance funds and social security institutions;
- If it is necessary for the clarification or prosecution of illegal or abusive incidents, our legal advisors, the law enforcement authorities and, if applicable, to injured third parties. However, this will only be done if there are specific indications of illegal or abusive behavior;
- Public authorities to which we are obliged to provide information, such as law enforcement authorities, authorities that prosecute administrative offenses subject to fines and the tax authorities;
- Contractually affiliated third-party companies and external service providers to fulfill the purposes described in this Privacy Notice, such as logistics companies, IT service providers, business consultants, insurers, human resources service providers, training institutes, travel agencies, credit card companies and financial institutions. In such cases, Personal Data is passed on to these companies or individuals to enable them to continue processing. These external service providers are carefully selected by us and regularly checked to ensure that your Personal Data is used exclusively for the purposes specified by us and in accordance with applicable data protection laws.
As our business evolves, we may change the structure of our company by changing its legal form, establishing, buying or selling subsidiaries, divisions or components. In such transactions, the relevant employee information will be shared with the part of the company being transferred. For any transfer of Personal Data to third parties to the extent described above, we will ensure that this is done in accordance with this Privacy Notice and the relevant data protection laws.
The Personal Data which you give to us may be transferred to countries outside the European Economic Area (“EEA”). For example, some of our third-party providers may be located outside of the EEA. Also, we may share your Personal Data with other entities of TORAY Group (a list of the companies of the TORAY Group can be found here: https://www.toray.com/global/), if and to the extent necessary to allow for international cooperation.
Where your Personal Data is shared externally, we will take steps to make sure the right security measures are taken so that your privacy rights continue to be protected as outlined in this policy and as required under EU GDPR.
If we share your Personal Data with a data processor, we will put the appropriate legal framework in place in order to ensure that such transfer and processing are secure (Articles 26, 28 and 29 EU GDPR). Furthermore, if we share your Personal Data with any entity located in a non-EEA who does not provide an adequate level of data protection in pursuant to Article 45 EU GDPR, we will put appropriate legal frameworks in place, notably the Standard Contractual Clauses approved by the European Commission Implementing Decision (EU) 2021/914, in order to make sure that such transfers are sufficiently protected (Article 44 and Article 46(2)(c) EU GDPR). The transfer of your Personal Data within the TORAY Group is also safeguarded by our TORAY Group’s Standard Contractual Clauses, which can be made available upon request to the contact detail provided in this Privacy Notice.
Legal Compliance and Security
If we are compelled by law, legal process, litigation, and/or requests from public and governmental authorities within or outside your country of residence, it may be necessary for us to disclose your Personal Data. We may also disclose your Personal Data if we determine that, for the purposes of national security, law enforcement, or other issues of public importance, the disclosure is necessary or appropriate.
We may also disclose your Personal Data if we determine in good faith that disclosure is reasonably necessary to protect our rights and to pursue available remedies, enforce our terms and conditions, investigate fraud, or to protect our operations or users.
OUR RECORDS OF DATA PROCESSES
We handle records of all of our processing of Personal Data in accordance with the obligations established by the EU GDPR (Article 30), both where we might act as a controller or as a processor. In these records, we reflect all the information necessary in order to comply with the EU GDPR and cooperate with the supervisory authorities as required (Article 31 EU GDPR).
SECURITY MEASURES
We process your Personal Data in a manner that ensures their appropriate security, including protection against unauthorised or unlawful processing, accidental loss, destruction or damage. We use appropriate technical or organisational measures designed to implement data-protection principles in an effective manner, and we integrate the necessary safeguards into the processing to achieve this level of protection (Article 25(1) and 32 EU GDPR).
NOTIFICATION OF DATA BREACHES TO THE COMPETENT SUPERVISORY AUTHORITIES
In case of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed, we have the mechanisms and policies in place in order to identify it and assess it promptly. Depending on the outcome of our assessment, we will make the requisite notifications to the supervisory authorities and communications to the affected data subjects, which might include you (Articles 33 and 34 EU GDPR).
AUTOMATED DECISION MAKING
You will not be subject to decisions that will have a significant impact on you based solely on automated decision-making. There will always be human intervention into decisions based on automated processing, including automated analytics, testing, profiling. However, if this position changes, or there is a need and lawful base to do so, we will notify you in writing.
PROCESSING LIKELY TO RESULT IN HIGH RISK TO YOUR RIGHTS AND FREEDOMS
We have mechanisms and policies in place in order to identify data processing activities that may result in high risk to your rights and freedoms (Article 35 EU GDPR). If any such data processing activity is identified, we will assess it internally and either halt it or ensure that the processing is compliant with the EU GDPR or that appropriate technical and organizational safeguards are in place in order to proceed with it. We may from time to time conduct a data protection impact assessment, especially when we contemplate implementing a new data processing method utilizing new technologies.
In case of doubt, we will contact the competent Data Protection Supervisory Authority in order to obtain their advice and recommendations (Article 36 EU GDPR).
YOUR RIGHTS
You have the following rights regarding Personal Data collected and processed by us.
Information regarding your data processing: You have the right to obtain from us all the requisite information regarding our data processing activities that concern you (Articles 13 and 14 EU GDPR).
Access to Personal Data: You have the right to obtain from us written confirmation as to whether or not Personal Data concerning you are being processed, and, where that is the case, access to the Personal Data and certain related information such as the purpose of the processing and the categories of Personal Data concerned (Article 16 EU GDPR).
Rectification or erasure of Personal Data: You have the right to obtain from us the rectification of inaccurate Personal Data concerning you without undue delay, and to complete any incomplete Personal Data (Article 16 EU GDPR). You may also have the right to obtain from us the erasure of Personal Data concerning you without undue delay, when certain legal conditions apply (Article 17 EU GDPR).
Restriction on processing of Personal Data: You may have the right to obtain from us the restriction of processing of Personal Data, when certain legal conditions apply (Article 8 EU GDPR).
Object to processing of Personal Data: You may have the right to object, on grounds relating to your particular situation, at any time to processing of Personal Data concerning you, when certain legal conditions apply (Article 21 EU GDPR).
Data portability of Personal Data: You may have the right to receive your Personal Data in a structured, commonly used and machine-readable format, and have the right to transmit those data to another controller without our hindrance, when certain conditions apply (Article 20 EU GDPR).
Not to be subject to automated decision-making: You may have the right not to be subject to automated decision-making (including profiling) based on the processing of your Personal Data, insofar as this produces legal or similar effects on you, when certain conditions apply (Article 22 EU GDPR).
Withdraw given consent if any: You may have the right to withdraw your given consent at any time (Article 7(3) EU GDPR). Processing activities made prior to the withdrawal of your given consent shall be deemed legal and in some cases cannot be redone.
If you intend to exercise such rights, please refer to the contact section below.
If you are not satisfied with the way in which we have proceeded with any request, or if you have any complaint regarding the way in which we process your Personal Data, you may lodge a complaint with your local Data Protection Supervisory Authority. A list with the contact details of the respective Data Protection Supervisory Authorities can be found here:
https://edpb.europa.eu/about-edpb/board/members_en
You can submit your complaint to any data protection authority in the Federal Republic of Germany, in particular also to the competent lead data protection supervisory authority for the respective TORAY EU company in Germany, which for the Federal State of Hesse is as follows:
Landesbeauftragter für Datenschutz und Informationsfreiheit des Landes Hessen
P. O. box 3163
65021 Wiesbaden
Gustav-Stresemann-Ring 1
2nd floor
65189 Wiesbaden
phone: +49 611 1408 – 0
fax: +49 611 1408 – 611
e-mail: Poststelle@datenschutz.hessen.de
UPDATES TO PRIVACY NOTICE
We shall observe all applicable laws, regulations, guidelines and any other standards related to the handling of employees’ Personal Data and shall periodically review and improve this Privacy Notice as provided above. We may revise or update this Privacy Notice in our sole discretion from time to time. Any changes to this Privacy Notice will become effective upon circulating by email or the posting of, the revised Privacy Notice, via SharePoint as soon as it becomes available. Copy of this or revised Privacy Notice may also be obtained from the human resources department any time. If we make changes which we believe are significant, we will inform you through the Websites to the extent possible and seek your consent where applicable.
CONTACT
If you have any further queries and complaints regarding data protection in connection with our Websites or the services offered, please contact our internal data protection supervisor or our data protection officer.
You can contact our internal data protection supervisor by email:
dataprotection.teu.mb@mail.toray
The contact details of the Data Protection Officer of OUR COMPANY are as follows:
Frank Becker
Atsumi Sakai Europa GmbH – Rechtsanwälte- und Steuerberater
Bockenheimer Landstraße 2-4, 60306 Frankfurt am Main
Email:DPO_TORAY-Europe@aplaw.de