GDPR & Data Protection Compliance
At Recruitment Choice UK, compliance is at the heart of our service. As a specialist UK recruitment agency connecting workers with immediate-start shifts in logistics, warehousing, construction, and healthcare, we handle highly sensitive Right to Work and identity documentation.
This page details the specific data processing workflows, encryption standards, and candidate rights we maintain to comply fully with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act.
1. The Legal Basis for Data Processing
Recruitment Choice UK collects and processes personal and compliance details under the following legal bases:
- Contractual Necessity: To register your profile, matching your credentials to employer shifts, and setting up payroll details.
- Legal Obligation: Under the UK Immigration Act, we are legally required to verify the Right to Work status of all candidates before placing them on assignments. Under HMRC payroll rules, we must gather Date of Birth and National Insurance parameters.
- Explicit Consent: For joining our active talent pool or saving custom shift alerts. You can withdraw your consent at any time.
2. Vetting Document Security & Storage
We recognize the critical nature of identity documents (passports, BRPs, selfies, and HMRC files). Our secure document vault infrastructure implements:
- End-to-End Encryption: All connection paths, inputs, and files are encrypted using 256-bit SSL protocols during transit.
- Obfuscated Buckets: Uploaded compliance files are kept in a secure database bucket using candidate UUID subfolders, making it impossible for unauthorized parties to guess or enumerate files.
- Restricted Access: Only vetted compliance officers and authorised client recruiters can view document links. We restrict Recruiter Dashboard access strictly to corporate domains (`@recruitment-choice.co.uk` and `@recruitment-choice.com`).
3. Powered by Sumsub Compliance Vetting
To verify passports and matching selfie photographs, we use verified compliance check pipelines modeled on Sumsub verification systems. This process performs:
- Automated structural auditing and OCR extraction of passport numbers and names.
- Biometric face geometry matching of your uploaded selfie vs your passport photo to prevent fraud.
- Instant background checking to allow immediate placement confirmation, bypassing long manual reviews.
4. Data Retention and Erasure
We do not store your identity papers indefinitely.
- If your registration is incomplete, your autosaved draft data is stored strictly to allow you to resume.
- Vetting files (passport scans, selfie checks, tax proofs) are automatically deleted after 12 months of inactivity, or immediately upon candidate erasure requests.
- Certain financial/payroll files must be retained longer to comply with HMRC tax auditing schedules.
5. How to Request Data Deletion
If you wish to remove your CV, contact details, and compliance papers from our system, you can do so easily:
- Send an email from your registered address to gdpr@recruitmentchoice.co.uk.
- Specify "Request for Account Deletion and Data Erasure" in the subject line.
- Our data compliance officer will review your record, verify identity, and purge all database entries and secure cloud storage files within 30 days. You will receive a final confirmation receipt.