You are on page 1of 5

OROLFO-OLIVAR, Metha Dawn H.

06 December 2022
Certificate Course on Data Protection Officer

Privacy Impact Assessment Worksheet


Process Name:
Processing Applicant’s Data from Recruitment to Hiring
Data Subject:
All Applicants of the Company are the data subject
Data Fields:
The following are submitted to the Human Resource Department upon
application to the Company:
1. Resume or Curriculum Vitae
2. Application Form – general data
3. Mental Awareness Test
4. Sales and Personality Test

The following are filled out and submitted to the Human Resource Department
when the applicant passed the verification of the qualification and two (2) tests
taken above:
1. Information Sheet – personal data (family details and emergency contact)
2. Acknowledgment Form for Company Rules and Regulations
3. Bank Forms: Application for ATM Card
4. Transcript of Records
5. Diploma
6. NBI Clearance
7. 3pcs 2x2 and 1x1 ID
8. Government ID: SSS, Philhealth, PAG-IBIG
9. TIN ID
10.Medical Examination Results: Urinalysis, drugtest, chest x-ray, fecalysis
Purpose/s for Processing:
The processing of the personal data of the data subject is for recruitment
process of the Company. The process will entail gathering personal and/or
sensitive data of the data subject.
Security Measure/s:
The data will be first processed by recruiter, if the applicant passed and pre-
boarding requirements will be submitted the payroll will have access to the
Government ID and details of the newly hired personnel. For the immediate
supervisor and department head who interviewed the applicant – they will only
have access to the resume, application form, test results and the recruitment
OROLFO-OLIVAR, Metha Dawn H. 06 December 2022
Certificate Course on Data Protection Officer

processing slip strictly during the interview period.

The main keeper of the data is the HR Coordinator and HR Talent Acquisition
Coordinator.

For purposes of security a log book is maintained and kept for the borrowing of
201-Files of the applicant or the employee only for a specific and legitimate
purpose coupled with the Department Head’s approval.
Process Narrative:
The process of the application to the Company starts with the applicant’s intent
to apply in a position through submission of his or her Resume or Curriculum
Vitae either through an online job market platform or when the applicant
submits it physically.

The Human Resource Department trough the Talent Acquisition Coordinator will
Verify the qualifications specifically employment history of the applicant. Then,
the applicant will be invited for interview and on-site taking of Mental
Awareness Test and Sales and Personality Test.

On the same day, tests results will be released and if the applicant passed the
tests the Hiring Manager will interview the applicant. However, if the applicant
failed the tests and verification of qualifications he or she will not proceed to the
HR interview.

For the unsuccessful applicant, the HR department will keep the physical data
collected for one (1) month while if there will be a soft or scanned copy of the
data subject, these data will be kept for another month before the HR
department deletes the same.

For the applicants who passed the preliminary two-tiered test, the Hiring
Manager will interview the applicant.

A Recruitment processing slip will be filled out by the Hiring Manager – the slip
will contain the result of the interview and plan of action either to recommend
or not to recommend for next level interview.

If the applicant is recommended, the applicant will be interviewed by the


immediate supervisor before the final interview of the department head.
OROLFO-OLIVAR, Metha Dawn H. 06 December 2022
Certificate Course on Data Protection Officer

If the applicant passed his or her interview with the immediate supervisor and
department head a Notice or Personnel Action will be issued – it is a job offer of
the Company to its successful applicants.

Upon acceptance of the job offer the newly hired personnel will receive check list
of documents to be provided to the Company as his or her pre-boarding
requirements, the following are:
1. Transcript of Records
2. Diploma
3. NBI Clearance
4. 3pcs 2x2 and 1x1 ID
5. Government ID: SSS, Philhealth, PAG-IBIG
6. TIN ID
7. Medical Examination Results: Urinalysis, drugtest, chest x-ray, fecalysis

After submission of the pre-boarding requirement, he or she will fill out forms
provided by the company, these are:
1. Information Sheet – personal data (family details and emergency contact)
2. Acknowledgment Form for Company Rules and Regulations
3. Bank Forms: Application for ATM Card

The all the documents will be retained by the HR Department and kept in their
premises. For the application to request ATM Card for payroll purposes, the HR
Department will ask the newly hired personnel to fill out the forms and submit
to the corresponding bank.

Process-level Analysis: Data Lifecycle

Data Collection Data Use

Data Source: Data Subject Is the data being used as is, or does it
undergo further processing?
Collection Method: Submission of the For the Resume or CV it is used as it is.
required documents and filling out the However, the two pre-qualification
data subject’s details in the Company’s tests are being processed (checked and
pro-forma forms. rated).
OROLFO-OLIVAR, Metha Dawn H. 06 December 2022
Certificate Course on Data Protection Officer

Timing of Collection: Upon receipt of Is there automated decision-making?


the Resume or CV of the data subject. None, all decisions are manually
decided by the key personnel of the
Company.
Data Disclosure Data Storage or Disposal

Is data being transferred to third Retention period


parties? No data gathered by the
Company for its process will be Location of data/how stored?
transferred to third parties. Steel cabinet within the HR office
All the data subject has their own
The bank application form to request folders in the categorized file of HR
ATM Card for payroll purposes is not a Department.
data sharing mode. As the data subject
is filling out forms directly from the Is personal data being destroyed?
bank.  Failed Applicant – active file of
candidates are retained for one
Third-party recipients If data is being (1) month then files will be
disclosed to third parties, indicate the physically destroyed while
name and contact information of the scanned copy will be deleted one
third party. For the purposes of this (1) month after the physical
exercise, you can indicate fictional destruction of the files.
contact information.
 Passed Applicant but did not
Purpose/s of the transfer to the third accept the offer – job offer will
party? Not applicable. be shred upon refusal
immediately or within 24 hours,
Is the data transfer supported by a whichever is earlier, but the
data sharing agreement or a data profile will be kept and archived.
outsourcing agreement? Not As to when it will be destroyed,
applicable. deleted, or retain the Company
does not have any policy.
Is the personal data transferred
outside of the Philippines? If so,  Hired applicant –his or her
where? Not applicable. profile will be filed as 201-FILE
and will be kept within HR
premises.
OROLFO-OLIVAR, Metha Dawn H. 06 December 2022
Certificate Course on Data Protection Officer

You might also like