1. Data Retention Policy
Purpose
This Data Retention Policy outlines how DriverJobs.co.uk manages, stores, and disposes of personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018.
Scope
This policy applies to all personal data collected, processed, and stored by DriverJobs.co.uk in relation to both job applicants (candidates) and employers using our recruitment services
Legal Basis for Retention
We retain personal data only as long as necessary for the purposes for which it was collected, including:
- Recruitment and placement activities
- Legal and compliance obligations
- Audit and business continuity purposes
Retention Periods
The following table outlines the retention periods for key data types:
Data Retention Schedule:
Data Type | Retention Period | Reason / Notes |
---|---|---|
Candidate application data (CV, contact details, licence info) | 12 months from last activity | To support ongoing job-matching and re-engagement |
Placed candidate records | Up to 6 years | For legal and audit purposes |
Employer contact and transaction data | Up to 6 years | Accounting, tax and regulatory obligations |
Right to work and eligibility documents | 12 months after role application closes | Comply with employment regulations |
SAR requests and data breach logs | 6 years | ICO guidance and accountability requirements |
Marketing consent records | Until withdrawal of consent | To maintain audit trail of consent |
Deletion and Disposal
Once data reaches the end of its retention period, it will be securely deleted or anonymised using industry-standard methods. Physical records (if any) will be securely shredded.
Data Subject Rights
Individuals have the right to request deletion of their data earlier under their UK GDPR rights. Requests will be assessed on a case-by-case basis and actioned in line with legal obligations.
Policy Review
This policy will be reviewed annually or when significant legal or operational changes occur. Updated versions will be made available on our website.
Contact Us
If you have questions about this policy, please contact our Data Protection Officer:
Email: info@driverjobs.co.uk
Address: 18 Longwood Road, Trafford Park, Manchester M17 1PZ
2. Data Breach Policy
Effective Date: 01st August2025
Reviewed By: Data Protection Officer
Review Frequency: Annually or upon material change
Purpose
This policy outlines how DriverJobs.co.uk identifies, manages, reports, and mitigates data breaches involving personal data. Our objective is to comply with our legal obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and to ensure the trust of our users is maintained through swift and transparent action.
Scope
This policy applies to all personal data held or processed by DriverJobs.co.uk relating to:
- Candidates and job applicants using our platform
- Employers and recruiters advertising vacancies or accessing candidate profiles
- Employees, contractors, and third-party service providers
What Is a Data Breach?
A personal data breach is a security incident that results in:
- Unauthorised access to personal data
- Loss, theft, or destruction of data (accidental or deliberate)
- Alteration or corruption of data
- Disclosure to an unauthorised party
- Unavailability of data that affects the rights or freedoms of individuals
Examples include: lost devices, email sent to the wrong recipient, hacking, ransomware attacks, or accidental deletion of records.
Roles and Responsibilities
Role | Responsibility |
---|---|
Data Protection Officer (DPO) | Coordinates the breach response, assessment, reporting, and communication with the ICO and affected individuals |
All Staff & Contractors | Must report any suspected data breach immediately to the DPO |
IT & Security Team (if applicable) | Investigates, contains, and remediates the breach, and supports forensic assessment |
Breach Response Procedure
Identify & Report
Any employee, user, or contractor who discovers or suspects a breach must report it immediately to the DPO via email or post.
DriverJobs.co.uk
18 Longwood Road, Trafford Park, Manchester M17 1PZ
Email: info@driverjobs.co.uk
Contain the Breach
- Isolate affected systems or services
- Suspend compromised accounts or access
- Preserve evidence for forensic analysis
Assess the Risk
The DPO will evaluate:
- What data is involved (e.g., driving licence details, contact information, CVs)
- Who is affected (e.g., candidates, employers)
- Volume of data exposed
- Risk to individuals’ rights and freedoms
- Whether the data was encrypted or pseudonymised
Notify Authorities (If Required)
If the breach is likely to result in a risk to individuals’ rights and freedoms, the DPO will notify the Information Commissioner’s Office (ICO):
- Deadline: Within 72 hours
- Method: ICO’s data breach notification portal
Notify Affected Individuals (If Required)
We will inform individuals if the breach is likely to result in serious harm or distress, explaining:
- What happened
- What data was affected
- What we are doing to reduce harm
- How they can protect themselves
- Contact details for the DPO
Record Keeping
All data breaches—regardless of whether they are reported to the ICO—will be logged in our Data Breach Register, including:
- Date/time of discovery and report
- Summary of the breach
- Risk assessment results
- Actions taken
- Whether it was reported to the ICO and/or affected individuals
- Lessons learned and prevention measures implemented
Prevention Measures
We maintain appropriate technical and organisational measures to prevent data breaches, including:
- Secure servers and encrypted storage
- HTTPS transmission
- Access control and permission levels
- Regular vulnerability assessments
- Employee training on data protection and breach response
Training & Awareness
All employees and relevant third parties are trained on:
- What constitutes a data breach
- How to report a breach
- Their responsibilities under this policy
Training is repeated annually and upon significant system or policy updates.
Policy Review
This policy will be reviewed annually or after any serious data breach to ensure continued compliance with legal and operational standards.
Contact Us
DriverJobs.co.uk
18 Longwood Road, Trafford Park, Manchester M17 1PZ
Email: info@driverjobs.co.uk