Candidates' Privacy Notice 

Our commitment to your personal data

We take your personal security and privacy seriously. Our Candidates' Privacy Notice outlines how we responsibly collect, use, share and protect your data throughout the recruitment process.

Prima Global Recruitment - Candidates’ Privacy Notice

This Privacy Notice applies to anyone wishing to pursue a career at Prima, either by applying directly through our official channels or through a personal referral. It describes how subsidiaries that are part of Prima Group (“we”, “us” or “Prima Group”) jointly collect and process your personal data (“Data”) in connection with your application including how we use and protect your information and what your rights are,pursuant the Regulation EU 2016/679 (“GDPR”) and the UK Data Protection Act 2018 (“DPA’18”).

For any requests for information, please send an email to our designated contact point: privacy@prima.it. Should you prefer, please use the below contact details to email the relevant subsidiary for your country.

The Joint Controllers (each one the “Controller”) and Data Protection Officer (“DPO”) are:

  • Prima Assicurazioni S.p.A., with registered office at Piazzale Loreto 17, 20131 Milano, Italy - VAT No. 08879250960;
    DPO: dpo@prima.it
    DSR: privacy@prima.it
  • Prima Assicurazioni S.p.A., Sucursal en España, with registered office at Nanclares de Oca 1B, 28022 Madrid, Spain - VAT No. W0233473H;
    DPO and DSR: es-dpo@helloprima.com
  • Prima Assicurazioni S.p.A., German Branch, with registered office at Kurfürstendamm 21/Regus-Berlin KuDamm 21, 10719 Berlin, Germany - VAT No. HRB242956B
    DPO: dpo@prima.it
    DSR: privacy@prima.it
  • Prima, Hello Prima, with registered office at Paul van Vlissingenstraat 24, 1096BK Amsterdam, Netherlands - VAT No. NL863920287B01
    DPO: dpo@prima.it
    DSR: privacy@prima.it
  • Prima Subsidiary Ltd, with registered office at 71-73 Carter Lane, EC4V 5EQ London, United Kingdom - VAT. No. 432254130
    DPO: admin@digitallawuk.com
    DSR: help@helloprima.co.uk

Data processed by Prima Group

The Data that we may collect directly from you are:

  1. identifying data (e.g. full name, date of birth,address, marital status and tax code);
  2. contact details (e.g. phone number, e-mail address, postal address or mobile number);
  3. information contained in your resume or CV and other documents related to the application or recruitment process (e.g. questionnaire, cover letter, transcripts, certifications);
  4. educational details (e.g. educational history, qualifications, certifications, skills);
  5. citizenship or immigration information;
  6. information related to professional social media profile you may want to share with us;
  7. other information you may choose to submit to us in connection with your application;
  8. Data belonging to “special categories” (pursuant to Article 9 GDPR), where specific job positions require their processing (for example, in Italy, some job openings are specific to individuals who have a disability). For more information on special category data, please see below;
  9. Data relating to your IP address, operating system and web browser type.

We can also collect some of the above-mentioned Data from other sources, such as:

  1. head-hunters or recruitment and temp agencies;
  2. Prima employees, in case of referral;
  3. information about your relationship with Prima, including prior work experience or association you may have with any current or former Prima employees.

Special Category Data

During the course of the application process, Prima may process your health-related Data if the job position falls under the requirements of specific regulations (e.g. law regarding legally protected status).

Any other Data belonging to “special categories” will not be requested by Prima and may only be processed if voluntarily provided by the candidate.

Where special category personal data is processed, we will ensure that the necessary additional safeguards are in place to protect such data, acknowledging that by definition special category data should be treated with additional care due to the sensitive nature of the data collected.

Purposes and legal basis of the processing

We use your Data to:

  1. assess your skills, qualifications and interests in the job position applied for;
  2. manage and assess a candidate’s suitability for other roles within Prima Group;
  3. communicate with you in relation to your application, the recruitment process and to arrange interviews;
  4. manage your enquiries and requests;
  5. where applicable, onboard you as an employee and manage your employment within Prima Group.

The legal basis for the above-mentioned purposes is the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (Article 6, lett. b), GDPR).

  1. store your Data for a period of 12 months following the end of the initial selection process, in order to facilitate subsequent open job selections.

The legal basis for the above-mentioned purpose is the legitimate interest of Prima Group to prevent a repetition in future selection processes. This allows for balances between the need to maintain an efficient and effective recruitment process on the one hand with the rights and the expectations of the candidates on the other (Article 6, lett. f), GDPR).

  1. retain your Data for an additional period of 12 months to allow us to contact you in relation to other job opportunities in line with your profile and qualifications.

The legal basis for the above-mentioned purpose is yourconsent (Article 6, lett. a) GDPR).

  1. comply with our legal obligations to which we are subject, including cooperating with all relevant regulators and enforcement bodies.

The legal basis for the above-mentioned purpose is compliance with a legal obligation to which the Joint Controllers or each Controller are subject (Article 6, lett. c), GDPR).

  1. detect, prevent and respond to fraud or potentially illegal activities, misuse of the recruitment system, intellectual property infringement or other violations of law or Prima Group policies;
  2. if necessary, to ascertain, exercise and/or defend the Joint Controllers’ or each Controller’s rights in court.

The legal basis for the above-mentioned purposes is the legitimate interest pursued by the Joint Controllers or each Controller (Article 6, lett. f), GDPR).

  1. carry out the obligations and exercising specific rights of the Joint Controllers or each Controller or of the data subject in the field of employment and social security and social protection law or a collective agreement pursuant to EU Member State law.

The legal basis for the above-mentioned purpose is fulfil legal obligations to which Joint Controllers or each Controller are subject in respect of special categories of personal data (Article 9, par. 2, lett. b), GDPR).

Any failure to provide the Data may prevent or delay the fulfilment of these purposes.

How we keep your data secure:

We use technical and organisational measures to safeguard your personal data. For example:

  1. access to your account is controlled by a password and a username that’s unique to you; and
  2. we store your Data on secure cloud servers.

Technical and organisational measures include ways of dealing with any suspected personal data breach. If you suspect any misuse, loss or unauthorised access to your Data, please let us know immediately by emailing us using the details at the top of this policy.

Data Retention

We store your Data for a period of 12 months following the end of the initial selection process. We will only store your Data after this time to:

  1. comply with our legal obligations; or
  2. if you have given us specific, informed consent to do so (for example, so that we can consider you for another role in the future).

If your application is successful, your personal data will be stored throughout our working relationship with you and retained in line with our legal and regulatory obligations.

A candidate may contact us at any time to be removed from the recruitment database by contacting us at privacy@prima.it or alternatively contacting the relevant DPO for your country of residence.

Recipients of Data

Your Data may be shared with:

  1. third parties, including service providers and business partners that Prima Group as Data Processor appoint, pursuant to Article 28 GDPR (for example, platforms used throughout the candidate application process);
  2. Prima Group’s staff authorised for processing, pursuant to Article 29 GDPR;
  3. industry bodies, courts, regulators, government authorities, credit reference agencies or other third parties to which Prima Group is required to share your Data by law.

For further information about the service providers and business partners who may have access to your personal data please contact Prima Group using the contact details at the start of this policy.

International Data Transfers

Prima Group may, from time to time, transfer data between different subsidiaries of Prima Group. Where applicable such transfers are made under an Intra Group Agreement and Data Processing Agreement that is in place within Prima Group. Alongside this, any transfer between Prima Group is limited to within the European Economic Area (“EEA”).

In order to provide services to you, Prima Group may transfer your personally identifiable information to third parties, affiliates, and service providers, some of which may process and/or store your personally identifiable information outside of the EEA. However, in such an instance all reasonable steps will be taken to ensure that your personal data is processed securely and in accordance with this Privacy Policy (where possible). Any data transfers that take place outside of the EEA will be covered by the necessary Data Transfer Agreement (“DTA”) and Standard Contractual Clauses (“SCCs”).

Data Subject Rights

Under Articles 15-22 of GDPR and DPA’18 Candidates may have the following rights:

  1. Right to access – You have the right under GDPR and DPA’18 to access the information that we hold about you. This will be provided to you within one calendar month of the request date;
  2. Right to rectification – You have the right under GDPR and DPA’18 to request the amendment or updating of all the personal data that we hold about you;
  3. Right to erasure – This includes the right to request that we delete or remove your personal data from our systems. Should you make such a request, your personal data will be deleted in line with our statutory and legal responsibilities;
  4. Right to restrict our use of your personal data – In line with Article 18 (1) (a) to (d) of GDPR you have the right under DPA’18 to obtain from the controller a restriction of processing;
  5. Right to data portability – You may have the right under GDPR and DPA’18 to receive personal data we hold on you in a structured, commonly used and machine readable format. This right will only apply where the lawful basis of processing is consent or the performance of a contract and the processing is by automated means;
  6. Right to object – This includes the right to object to our use of your personal data;
  7. Right to complain to us or the relevant data protection authority (for more information on data protection authorities, please see below).

Where applicable, in accordance with the provisions of Articles 15-22 GDPR and DPA’18, the data subject may contact our designated contact point by sending an e-mail to privacy@prima.it.

Enforcement:

We cooperate with the appropriate regulatory authorities, including local data protection authorities to resolve any complaints regarding the collection, processing and disclosure of personally identifiable information that cannot be resolved between Prima and the individual.

If you have a concern about your privacy or would like to know more about how your personally identifiable information is collected or used, please contact us. We ask that when you contact us with a complaint, please include contact information and clearly describe your complaint.

We will respond to your request or complaint within a reasonable time and will let you know the next steps in resolving your complaint. If you are not satisfied with our response, you may also contact your local and federal data protection authorities to lodge a complaint.

Should you not be satisfied with the process, conduct or response to a request you may have made you have the right to complain to the relevant supervisory authority for your country of origin. For more information on this, please contact us directly.

Processing the personal data of those below the age of 13

Our application process is not intended for use by anyone under the age of 13 nor does Prima Group knowingly collect or solicit personally identifiable information from anyone under the age of 13. If you are under the age of 13, you may not attempt to send any information about yourself to us, including your name, address, telephone number, or email address.

In the event that we confirm that we have collected personally identifiable information from someone under the age of 13 without verification of parental consent, we will delete/destroy that information promptly. If you are a parent or legal guardian of a child under the age of 13 and believe that we might have any information from or about such a child, please contact us at the email or mailing address provided at the end of this Privacy Policy.

Changes to this Privacy Notice

We reserve the right to change this privacy notice as we may deem necessary from time to time. we will give you sufficient advance notice prior to starting the personal data processing, so that you are aware of it.

Last update: v.3 published on 10/02/2025