1. Scope and responsibility
This statement covers personal information processed through Yorkshire Legal Recruitment, including candidate, employer, locum, supplier and website information. It supports compliance with the UK GDPR, the Data Protection Act 2018 and, where electronic communications or device storage are involved, the Privacy and Electronic Communications Regulations. Ten-Percent.co.uk Limited is responsible for governance and for ensuring that staff and providers handle information appropriately.
2. Data protection principles
We aim to process information lawfully, fairly and transparently; collect it for specified purposes; limit collection to what is relevant; keep it accurate; retain it only as long as needed; protect it appropriately; and maintain evidence of compliance.
New or materially changed processing is assessed for purpose, lawful basis, necessity, risk, transparency, security and retention. A data protection impact assessment is used where processing is likely to create a high risk to individuals.
3. Recruitment information through its lifecycle
Collection
We explain the recruitment purpose and avoid requesting information that is not relevant. Special category and criminal-offence information is only requested where there is a genuine requirement and an appropriate legal condition.
Use and disclosure
Access is limited to people who need the information. Candidate identities and CVs are shared through an agreed introduction process, not circulated indiscriminately.
Accuracy
Candidates and employers are encouraged to correct changes to contact details, availability, qualifications, vacancies and preferences.
Deletion
Records are deleted, anonymised or securely disposed of at the end of the applicable retention period, subject to legal holds and backup-management processes.
4. Security measures
Measures are selected according to risk and may include access controls, strong authentication, encrypted connections, device and account management, secure backups, malware protection, logging, staff confidentiality, supplier due diligence and procedures for joiners, movers and leavers.
Users should send CVs through the secure Ten Percent registration route or approved email addresses and should not send client files or case papers.
5. Service providers and international transfers
Providers processing information on our behalf are selected and instructed for defined purposes. Contracts address confidentiality, security, assistance with rights and incidents, deletion or return, and audit information where required.
Where information is transferred outside the UK, we assess the destination and use an applicable adequacy regulation, UK International Data Transfer Agreement, UK Addendum or another lawful safeguard.
6. Retention and individual rights
Retention follows the schedule summarised in our privacy policy. Requests for access, correction, erasure, restriction, objection or portability are logged, verified and handled within the applicable legal timescale. Staff are expected to recognise a rights request even when it does not use formal legal wording.
7. Personal data incidents
Suspected loss, unauthorised access, disclosure, alteration or destruction should be reported immediately. Incidents are contained, investigated and documented. Where required, the ICO is notified without undue delay and, where feasible, within 72 hours; affected individuals are informed when the legal threshold is met.
8. Training and review
People handling recruitment information receive proportionate guidance on confidentiality, security, rights requests and incident reporting. This statement is reviewed when services, law, technology or risk materially change.
Questions may be sent to cv@ten-percent.co.uk.