PSA: If you want to know why a company rejected you, send them a GDPR request
old.reddit.com
old.reddit.com
The current lack of transparency is not fair to the candidates and is an artifact of people taking legal action (fairly or not) against companies when they didn’t get hired.
A "GDPR request" can be as simple as[1]:
> Dear...
>
> I wish to make an access request under Article 15 of the General Data Protection Regulation (GDPR) for a copy of any information you keep about me, on computer or in manual form in relation to...
GDPR does not apply to US citizens living in the US, but some federal and state-level (eg. CalOPPA or CCPA) privacy regulations might offer some similar rights (IANAL).[1] https://www.dataprotection.ie/en/individuals/know-your-right...
I'd love to see my interview feedback but abusing GDPR or CCPA to obtain it seems abusive.
A job applicant is a data subject of the company they apply to. The company produces data (interview evaluations) based on the expectation that their internal data is kept proprietary. However, GDPR permits the job applicant to act as a data subject and request the company's proprietary information (produced by employees who expected to remain semi-anonymous to provide candid feedback).
If that's the case, I think I have another in a long list of items to add to my list of "why GDPR is a crazy law and the implications weren't completely thought-through"
To phrase it bluntly, a company needs to consider what laws apply to it before it forms such expectations. I'm sure some company also compiled databases of addresses for advertising purposes to based on the expectation that their internal data is kept proprietary, also doesn't work like that. Also note that an obvious solution to having to disclose data is not having it. Plenty places will have you re-interview if you re-apply anyways, so justifying why they keep detailed interview notes around is an interesting question, assuming this request comes after the process has ended.
> (produced by employees who expected to remain semi-anonymous to provide candid feedback).
Employees don't just expect that, they have a legal right to it. "my personal data" does not include "who did interview me", and the company has to protect the personal details of its employees. (presumably why the reddit OP mentioned data being redacted)
So I do think that companies shouldn't really have anticipated this when they formed their expecftations, unless they were formed after GDPR was approved.
Just being able to read interview feedback is enough to recognize who wrote it.
GDPR was published 2016 and became active in 2018. Even if you only started to think about it at the second date you've had almost 4 years.
While that might be true internally, I think it's pretty unlikely that a candidate had enough of a sense of each person's writing style (especially if the interview was conducted via voice, as is typical)
> So I do think that companies shouldn't really have anticipated this when they formed their expecftations, unless they were formed after GDPR was approved.
The GDPR was passed in 2016. I feel like 5+ years is plenty of time to re-adjust expectations.
From I can tell a random throwaway made this post on reddit, it may have happened, but it doesn't mean that companies are required to do this. I would like to see more supporting data.
As I mentioned above, CA privacy laws exclude this information.
But that on the other hand that applicant data is personal data that falls under GDPR and that applicants can request their data is quite obvious, and that notes contain "personal data" about a person is also established, so you'd really need a specific argument why they don't fall under the access request requirement.
At least in the German case law I've seen, it's by now established that internal notes etc about a person also count specifically for the data access request - a prominent case was someone suing their insurance company for all internal records.
Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data
So before we're even talking about expectations of the availability of this data - e.g. detailed interview notes in some company HR system (personal notes of specific interviewing employees would not count if these notes are not used in the company processes) - the company must consider why do they think they are allowed to record and store that data in the first place, since the "default expectation" is that they are not. And if they have a valid reason, they are required to have their Data Protection Officer to know that they are processing this data and it's the duty of the DPO to inform these people about what exactly they are permitted and required to do with this data - so if the people recording this data have a misleading expectation, that's fully the fault of the company. Before "the company produces data (interview evaluations) based on the expectation that their internal data is kept proprietary" it's the duty of the company to ensure that this processing of private data is reviewed, verified whether that processing is lawful in the first place and ensure that the people recording this information are informed about what they can/can't/must do with it, as the law requires the company to either ensure "appropriate organizational measures" for that, or not process this data at all. If the company has their employees "simply" producing data that includes personal data of others without considering the GDPR impact, that by itself is a breach of their legal duty of Article 24 of GDPR.
In situations like these, most companies would assert that they have a specific legitimate interest (article 6.1.f) in processing the data for conducting the interview and application decision process, which is a perfectly valid justification - however, that would not necessarily grant them the right to process the data after the interview process ended with a rejection; there's no inherent right for the company to just continue storing the detailed interview notes just because, so it would be interesting to see what legal basis they assert for having that data in the first place, and IMHO in most EU companies the standard HR process now would require to discard the details after the interviews.
The ability to make subject access requests was in the Data Protection Directive which was passed in 1995.
If they are the wrong type of person they might come with a lawyer next.
A non-EU company could probably request at least some proof that you're in scope if they have reasonable doubts about if you are, but I suspect in practice many find it easier to just oblige a reasonable request they have a process for than getting into the weeds of scope and risk getting it wrong. (i.e. I suspect there's some fun legal nuance in scenarios like "I'm a US citizen living in the US that applied and got rejected 3 months ago, now I'm on holiday in Copenhagen and writing an access request" - I could see ways of arguing that either way depending on the circumstances, but also am not a lawyer). Although a request for interview information like this might be enough hassle to be restrictive.
You can't fly to Copenhagen and submit a request if the employer and application took place in eg the US. That's all part of the territorial applicability -- you don't necessarily need a presence in the EU, but you do need an establishment through eg stable arrangements. See Guidelines 3/2018 on the territorial scope of the GDPR (Article 3).
Good point on the lawsuit risk being a reason to be strict though.
And if your data is processed by "Google USA", then GDPR applies to that processing only if you are "a data subject in the Union".
I had a pretty nasty back and forth with a Grammarly alternative about retention of my data, where he insisted he needed my passport and a whole bunch of other stuff to fulfill the request, to verify I was requesting from Europe. I kindly reminded him that his privacy policy states the site collects IP information.
After about a month of legal threats, the GDPR request was fulfilled.
> natural person acting as a job applicant to, an employee of, owner of, director of, officer of, medical staff member of, or contractor of that business, as specified
Can I make requests for data generated during my time in the EU/California?
Article 3 (Territorial Scope) of the GDPR:
> 1. This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.
> 2. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:
> (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
> (b) the monitoring of their behaviour as far as their behaviour takes place within the Union.
> 3. This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.
So if either the data controller(s) or processor(s) are legally established in the EU or the data subject is physically in the EU then the GDPR applies.
Yes.
If a data controller (or processor) is based in the EU then they must comply with the GDPR regardless of where you are/were.
If a data controller (or processor) aren't based in the EU, then they must comply with the GDPR when they're processing personal data about you when you are physically in the EU.
This is set out in Article 3 of the GDPR
It does, actually. If the data controller is based in the EU then the GDPR applies regardless of where the data subject is.