DATA PROTECTION POLICY FOR EMPLOYERS/CUSTOMERS
An Employer who engaged WeLinkTalent Pte Ltd to conduct job matching or candidate (job application) search for their job vacancies is known as “Customer”. Customer who received personal data from WeLinkTalent Pte Ltd will likely be considered data intermediaries.
WeLinkTalent Pte Ltd (“we”, “us”, or “our”) imposes this Data Protection policy with obligations on the Customer so as to ensure the WeLinkTalent Pte Ltd‘s own compliance with the Personal Data Protection Act (“PDPA”).
DEFINITION
1) In this Agreement, unless the context otherwise requires, the following terms shall have the meanings assigned to them below:
-
“Customer” means the company name of the Customer;
-
“Candidate Personal Data” means Personal Data which the WeLinkTalent Pte Ltd discloses to the customer.
-
“PDPA” means the Personal Data Protection Act 2012; and
-
“Personal Data” means data, whether true or not, about an individual who can be identified:
-
from that data alone; or
-
from that data and other information to which the customer has or is likely to have access.
HANDLING AND PROTECTION OF PERSONAL DATA
-
Compliance with PDPA. The customer shall comply with all its obligations under the PDPA at its own cost. Customers are subjected to audit by us against the PDPA requirements and contractual agreements when:
-
There is a compliant lodge relating to the customer or
-
There is a personal data breach incident or
-
There is a suspected case of breach of the PDPA requirements and contractual agreements
-
-
The customer shall only process and/or use candidate Personal Data:
-
Strictly for the purposes of fulfilling its obligations and evaluating the suitability of the candidate for the job offer.
-
-
Transfer of personal data
-
The customer is not allowed to transfer or share any of the candidate's personal data from us to any organisation or any unauthorised person without our consent from us
-
-
Security Measures.
-
The customer shall protect the candidate’s Personal Data in the customer’s control or possession by making reasonable security arrangements (including, where appropriate, physical, administrative, procedural and information & communications technology measures) to prevent unauthorised or accidental access, collection, use, disclosure, copying, modification, disposal or destruction of Customer Personal Data, or other similar risks. For the purposes of this Agreement, “reasonable security arrangements” include arrangements set out below:
-
Physical records containing Candidate’s Personal Data which are mailed or sent by courier must be secured in transit (e.g. in a sealed envelope etc.)
-
Physical duplicating (e.g. photocopying, etc.) of the candidate’s Personal Data is discouraged.
-
Physical or electronic documents containing a Candidate’s Personal Data should never be left unattended
-
Customer’s employees are to be bound by confidentiality obligations
-
Candidate’s Personal Data should be stored in locked file cabinets
-
candidate’s Personal Data should be classified as a confidential document
-
Candidate personal data are not allowed to be disclosed to any organisation or any unauthorised person without our consent
-
Implements robust policies and procedures to protect the candidate’s Personal Data
-
Conducts regular training sessions to impart good practices in handling and protecting personal data
-
Limit access to candidates’ Personal Data to only authorized personnel based upon their assigned roles and responsibilities.
-
Encryption of portable storage device used for the transfer/storage of personal data.
-
Enforce boundary protection (e.g. installing a firewall and virus-checking software)
-
Download and install the applicable patches or security updates which should cover vulnerabilities in applications, systems and databases.
-
Perform regular back-ups of the information on computer systems.
-
Work station, computer, and laptop should be password protected.
-
Disposal of the candidate’s Personal Data when no longer any legal or business purpose behind retaining such data by:
-
-
Shredding off all physical copies of candidate’s Personal Data
-
Deleting all electronic copies of the candidate’s Personal Data from your system and storage ensures that such data are securely deleted and unable to recover.
6. Accuracy and Correction of Personal Data.
-
When we provide the Candidate’s Personal Data to the Customer, we shall make a reasonable effort to ensure that the Candidate’s Personal Data is accurate and complete before providing the same to the customer. The customer shall put in place adequate measures to ensure that the Customer Personal Data in its possession or control remain or is otherwise accurate and complete. In any case, the customer shall take steps to correct any errors in the Customer Personal Data, as soon as practicable upon the notification received from u
7. Retention of Personal Data.
-
The customer shall not retain the candidate’s personal data (physical or electronic form) for any period of time longer than is necessary to serve the purposes of this Agreement.
-
The customer shall, upon the request from us to:
-
return to the physical copy of the candidate’s personal data; and/or
-
delete the electronic copy of the candidate’s personal data in its possession,
Where applicable, the customer shall also instruct all third parties to whom it has disclosed the candidate’s personal data for the purposes of this Agreement to return the candidate’s personal data or delete such candidate’s personal data.
8. Notification of Breach.
-
The customer shall immediately notify the Customer when the customer becomes aware of a breach of any of its obligations in Clauses [2.1 to 2.7].
-
The customer report to the customer’s Data Protection Officer by the below channel:
-
DPO: Nathalie White
-
Email: dpo@welinktalent.com
-
Contact Number: +65 81574380
9. Indemnity
The customer shall indemnify us and its officers, employees and agents, against all actions, claims, demands, losses, damages, statutory penalties, expenses and costs (including legal costs on an indemnity basis), in respect of:
-
any breach of Clauses [2.1 to 2.7]; or
-
any act, omission or negligence of the customer that causes or results in a breach of the PDPA.
Effective date: 18 October 2019
Last updated: 20 May 2022
