Disclose GDPR information on prospect form in Greenhouse Events

Permissions: Job Admin and above who have access to CRM

Product tier: Available for all subscription tiers

Companies are required to provide a variety of details at the time data is requested (for example, when a prospect submits their information at a career fair), including why they are requesting certain information, how long it will be stored, where it will be sent, and the safeguards in place relating to the transfer.

Using Greenhouse's Events app, you can provide the required GDPR notification on the prospect form as a custom question.

Add GDPR information on a prospect form

To add GDPR Information to an Open or Planned Event, click CRM on your navigation bar.

Screenshot-of-CRM.png

Scroll to the Events section, and click the Ellipsis icon beside an event. Click Edit Event from the dropdown.

Note: If you don't see the event you're looking for, click See All and choose the event from the subsequent list.

Scroll to the Prospect Info Form section and click Add a Question.

Use the Edit a Custom Question box to input your organization's GDPR information in the What is your question? field.

Select Single-select from the Answer type dropdown and input a statement of acknowledgment in the Options field.

Select Required.

When finished, click Add Custom Question.

Click Update Event to confirm the change. Your organization's GDPR information will be added to the prospect form.

Greenhouse GDPR notice example text

Note: You should seek the advice of your legal counsel to prepare your GDPR notice text as it applies to your business. What follows is an example of an Article 13 notification. Greenhouse cannot guarantee that this text will ensure GDPR compliance for your company.

Example: When you apply to a job on this site, the personal data contained in your application will be collected by [CONTROLLER] (“Controller”), which is located at [ADDRESS] and can be contacted by emailing [EMAIL]. Controller’s data protection officer is [DPO NAME], who can be contacted at [CONTACT INFORMATION]. Your personal data will be processed for the purposes of managing Controller’s recruitment related activities, which include setting up and conducting interviews and tests for applicants, evaluating and assessing the results thereto, and as is otherwise needed in the recruitment and hiring processes. Such processing is legally permissible under Art. 6(1)(f) of Regulation (EU) 2016/679 (General Data Protection Regulation) as necessary for the purposes of the legitimate interests pursued by the Controller, which are the solicitation, evaluation, and selection of applicants for employment.

Your personal data will be shared with Greenhouse Software, Inc., a cloud services provider located in the United States of America and engaged by Controller to help manage its recruitment and hiring process on Controller’s behalf. Accordingly, if you are located outside of the United States, your personal data will be transferred to the United States once you submit it through this site. Because the European Union Commission has determined that United States data privacy laws do not ensure an adequate level of protection for personal data collected from EU data subjects, the transfer will be subject to appropriate additional safeguards under [either the standard contractual clauses or the Privacy Shield]. You can obtain a copy of the standard contractual clauses by contacting us at example@yourcompany.com.

Your personal data will be retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have to right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.