Sensitive data in recruitment - can we process it at all?

28 October 2022

In the recruitment process, a wide range of data about candidates who submit their applications is processed. For this reason, it is extremely important that this process is conducted in accordance with the provisions of the General Data Protection Regulation (GDPR). Employees in HR departments face many practical issues, including the scope of data obtained from candidates. Particularly many doubts arise regarding whether the so-called sensitive data fall within the scope of data that can be lawfully collected during the recruitment process.

What scope of data can I process during the recruitment process?

The scope of personal data that an employer may collect during the recruitment process is directly derived from legal provisions, namely Article 22(1) § 1 of the Labour Code. This scope includes: first name(s) and surname, date of birth, contact details provided by the individual, education, professional qualifications, and the history of previous employment.

If the employer decides to collect other personal data, they must demonstrate that there is a legal basis for such a request. An example of such a situation may be the collection of data regarding criminal records. An employer may collect such data about a prospective employee only when there is a legal provision that imposes a requirement of no criminal record for employment in a specific position, e.g., a person wishing to work as a teacher must not have been convicted by a final judgment for an intentional crime or intentional fiscal crime (Article 10(5)(4) and (8), Article 91b(2b) of the Teacher's Charter). In such a case, the employer must obtain a certificate from the National Criminal Register from the individual before employing them in that position.

There is often also uncertainty regarding how to determine the permissible scope of data collected in connection with employing individuals based on civil law contracts, such as a mandate contract. The provisions of the Labour Code do not apply in this legal relationship. Nevertheless, it should be noted that they can provide valuable guidance for employers in this regard, as the scope of data that should be collected from candidates will be similar, regardless of the form of employment. Furthermore, it should be kept in mind that the fundamental principle that employers should adhere to in every recruitment process is the principle of data minimization, as explicitly stated in Article 5 of the GDPR. According to this principle, the data controller (in this case, the employer) may only collect such data that is necessary to achieve a specific purpose of processing.

What about sensitive data?

It happens that during the recruitment process there is a necessity to process special categories of data, commonly referred to as sensitive data. The catalog of sensitive data is specified in Article 9(1) of the GDPR and is a closed catalog. According to the cited provision, special categories of personal data include: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, membership in trade unions, as well as genetic data, biometric data processed for the purpose of uniquely identifying a natural person, or data concerning the health, sexuality, or sexual orientation of that person. 

FREE

GDPR in HR: Mistakes and Best Practices

Watch the webinar

During the recruitment process, data concerning health status most frequently arises. This is particularly related to job postings that are also open to candidates with disabilities. During such a recruitment process, a candidate may also present a certificate confirming their disability to a potential employer. According to Article 2b of the Act on Professional and Social Rehabilitation and Employment of Persons with Disabilities, the submission of documents confirming personal data regarding health status to the employer is voluntary. It should be noted that the recruiting employer is not obliged to obtain additional consent for the processing of sensitive data in connection with the submitted certificate, as the candidate provides it on their own initiative. This possibility arises directly from legal provisions. At the same time, as emphasized by the President of the Polish DPA, the presentation of the certificate is necessary for granting a person with a disability benefits and allowances in this regard, appropriate adjustments to the workplace, or granting them priority (provided that other requirements in the civil service recruitment process are also met).

It is also worth noting the provision of Article 22(1)(b) § 1 of the Labour Code, according to which the consent of the job applicant or employee may serve as the basis for the employer to process so-called sensitive data only if the provision of such personal data is initiated by the job applicant or employee. This provision clearly states that an employer publishing a job advertisement cannot in any way coerce the candidate into providing sensitive data, indicating that by submitting their application, the candidate agrees to their processing by the potential employer. The initiative to provide such data must come from the candidate. It is also important to emphasize that even if during the recruitment process the candidate voluntarily provides the data controller with personal data, for example, regarding their health status, they should express a separate consent for the processing of such personal data, unless the possibility of processing such data by the employer arises from legal provisions, as in the case of employing individuals with disabilities.

GDPR in HR

The requirement for the employer to obtain a separate statement arises from the content of Article 9(2) of the GDPR, according to which consent for the processing of special categories of data should be explicit, for example, in the form of a separate statement. In the absence of explicit consent for the processing of sensitive data, the employer should not process such data, and if they have received it from the candidate, they should promptly delete it.

There are also situations in which the statutory provision does not leave any discretion to the candidate and directly imposes an obligation on the future employer to obtain sensitive data, such as Article 25(2) of the Police Act, which states that the acceptance of a candidate into police service occurs after conducting a qualification procedure aimed at determining whether the candidate meets the conditions for acceptance into police service and assessing their suitability for performing this service. The qualification procedure consists, among other things, of a physical fitness test, a psychological test, and an assessment of the physical and mental ability to serve in the police. Throughout the entire process, there will therefore be processing of data regarding the candidate's health status.

Authorization for Processing Sensitive Data

An important issue in the context of processing sensitive data is the necessity for the data controller to grant written authorization to individuals permitted to process such data.

This obligation arises directly from Article 22(1)(b) § 3 of the Labour Code, according to which only individuals who possess a written authorization to process such data, issued by the employer, may be permitted to process sensitive data. Individuals authorized to process such data are obliged to keep it confidential.

Summary

The answer to the question of whether the processing of special categories of data is permissible in the recruitment process is affirmative, with the caveat that the employer must always have a valid legal basis for processing such data. This may be the explicit consent of the candidate or a legal provision that imposes an obligation on the employer to process sensitive data.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.