Introduction

This Candidates Privacy Notice (this "Notice") governs the collection and use of personal data by Dubai Holding Corporate LLC, specifically in relation to all candidates applying to become employees, staff, interns, consultants, contractors or officers at Dubai Holding Corporate LLC.

This Notice explains the types of personal data we collect, how we use that personal data, who we share it with, transfers to other countries, how we protect that information, and your legal rights in relation to your personal data. We are committed to abiding by this Notice as well as the requirements of applicable laws in the entire recruitment/engagement process.

Candidates who are successful in their application and are formally offered employment (or selected for an engagement) with Dubai Holding Corporate LLC, will be provided with a different Privacy Notice as part of the on-boarding/engagement process, which will supersede this Notice.

References to "our", "us" or "we" within this Notice are to Dubai Holding Corporate LLC.

Who we are

We are the data controller of your personal data. We decide how and why your personal data is processed, either alone or jointly with others.

You can access a ‘Data Controller List’ here, which sets out all of our different entities and their contact details. This will enable you to identify the relevant entity that holds, processes, and secures your personal data and is the data controller in relation to your personal data.

Information covered by this notice

In this Notice we refer to "processing your personal data".

Processing means anything that is done to or with personal data (including simply collecting, storing or deleting that data).

Personal data is any information relating to an identified or identifiable living person (for example, name, address, telephone number). When "you" or "your" are used in this Notice, we are referring to the relevant individual who is the subject of the personal data.

Our use of cookies

When you visit our website, we may use cookies and other technologies to automatically collect the following personal data:

  • Technical information, including the Internet Protocol (IP) address used to connect your computer to the internet, your login activity, browser type and version, device identifier, location and time zone setting, browser plug-in types and versions, operating system and platform, page response times, and download errors;
  • Information about your visit, including the full Uniform Resource Locators (URL) clickstreams to, on and from our websites; and
  • Length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouseovers) and methods used to browse away from the page.

IP addresses and other online identifiers (i.e. those listed above) are your personal data. This means that you have the same rights under data protection laws in relation to these as you do with other personal data. For information about the rights see our Cookies Notice.

What personal data do we collect from you and how?

We may collect personal data at every touch point and interaction we have with you during the recruitment/engagement journey. We collect personal data about you as a candidate from different sources whilst adhering to the data minimization and purpose limitation principles in accordance with the applicable data protection law. As detailed below (some of these may not be relevant to you specifically):

We cannot process your application for employment or engagement without your personal data. Where we do not need your personal data, we will make this clear. For instance, we will explain if any part of an application form you are required to complete is optional or can be left blank.

Information you give us:

  • You provide your personal data to us when you respond to a communication from us, when filling in forms on our careers website, over the telephone or through written correspondence with us (e.g. any follow-up queries in relation to your application).|

Information we collect about you:

  • We collect and create personal data about you ourselves during your application process, for example, our notes of your progress throughout the application process will contain personal data about you. The data we collect, and the scenarios of collection are specified in the section titled “How we use your personal data” below.

Information we receive and collect from other sources

  • Where permitted by data protection laws, we collect personal data about candidates from publicly available sources, including publicly available content on social media depending what your privacy settings are on such services and the platforms which you use.
  • We also collect personal data about candidates for recruitment purposes from government agencies, and third parties who provide services to candidates or to us in connection with an application, for example, recruitment consultants/agencies, previous employer, or your through employment and character references.
  • To the extent necessary, we will also receive your personal data from other entities that form part of the Dubai Holding Corporate LLC group of companies, including subsidiaries.
How do we use your personal data?

Data protection laws require us to clearly explain the purpose to justify our processing of your personal data.

You should be aware that our purposes for processing your personal data may be impacted by the legal requirements in the country you work in and by what data protection law(s) apply.

Personal data usage
We will use your personal data when: We process the following personal data for these purposes: What is the legal basis for us processing your information in this way? Storage Period
Purpose: Perform consultant engagement activities
We obtain the required starting documentation to initiate the process to engage the consultant. As appropriate this will include: Place of Birth, Date of Birth, Compensation and Benefits, Telephone Number, Name, Email Address, Passport, National ID, Nationality, Address, Curriculum Vitae / Application Information, Visa Information (Including Sponsor / Cancellation Information), Gender, Employment Information (Including Performance , Signature and E-Signature, Criminal Information) Legal Obligations 12 months after completion of the application process relating to the role.
To obtain appropriate Government approval and issuance of entry. Legal Obligations 12 months after completion of the application process relating to the role.
Conduct background checks (including criminal, right to work and, reference checks and identification of applicants), that are required either by law, or are necessary to assess consultant's suitability for a role. Legitimate Interest and Legal Obligations 12 months after completion of the application process relating to the role.
Interact with applicants, including interviewing, providing information on the application, providing feedback and responding to queries or complaints. Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
Assess the DH Group strategic direction and resourcing needs through feedback and monitoring to improve the recruitment process. Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
Determining whether any adjustments required by law are necessary during the interview process to enable you to carry out a role offered to you (which may include disabilities or dietary requirements) Such adjustments specifically concern personal data relating to: Health Legal Obligations Where we process sensitive data we do so because it is necessary to meet obligations and rights in the field of employment and social security and social protection law 12 months after completion of the application process relating to the role.
Determining whether any adjustments not required by law are necessary during the interview process to enable you to carry out a role offered to you (which may include disabilities or dietary requirements) Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
Maintaining the Groups' security including people identification and authentication, premises, assets, systems, website and platforms. As appropriate this will include: Place of Birth, Date of Birth, Compensation and Benefits, Telephone Number, Name, Email Address, Passport, National ID, Nationality, Address, Curriculum Vitae / Application Information, Visa Information (Including Sponsor / Cancellation Information), Gender, Employment Information (Including Performance , Signature, E-Signature and Criminal Information). Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
Registering the candidate in relevant systems and creating a 'Pending Worker' status to initiate the collection of joiner documentation. Legal Obligations 12 months after completion of the application process relating to the role.
Description of Processing Personal Data Legal Basis Storage Period
Purpose: Recruitment and recruitment planning
Evaluating your application for a position with us and considering your suitability for the relevant role. As appropriate this will include: Place of Birth, Date of Birth, Compensation and Benefits, Telephone Number, Name, Email Address, Passport, National ID, Nationality, Address, Curriculum Vitae / Application Information, Visa Information (Including Sponsor / Cancellation Information), Gender, Employment Information (Including Performance), Criminal Information Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
Obtaining, considering and verifying your employment references and employment history, as well as otherwise confirming your identity. We carry out a reference check by emailing the references stated in a candidate's application or as provided to us later in the process. Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
Reviewing and confirming your legal right to work in a particular country or geographic region. Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
Conducting verification and vetting, including criminal background checks where required by law. Legal Obligations Where we process sensitive data as part of these checks, we do so only because it is necessary to meet obligations and rights in the field of employment and social security and social protection law. 12 months after completion of the application process relating to the role.
We undertake security clearance checks for successful candidates for some roles. This is in addition to the background checks stated above. Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
Conducting background checks, testing, verification and vetting which are not required by law but needed by us to assess your suitability for the role applied. For those candidates applying for senior roles, and prior to making a formal offer, we also undertake background checks. These checks may include engaging a third-party to undertake checks against a candidate's criminal history, financial history and any gaps in their CV. We also carry out a reference check by emailing the references stated in a candidate's application. Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
We undertake psychometric and ability tests (including assessment centres, technical or trade evaluations, ability testing regarding verbal, numerical and logical reasoning that may be required) to align candidates against our core competencies and technical requirements of a job. Name, Email Address, Report of Performance in Tests Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
We use artificial intelligence and machine learning to conduct profiling activities. This helps us make more informed decisions during the recruitment process. Name, Address and Date of Birth, Video Recording, Curriculum Vitae / Application Information, Tone of Voice, Micro Facial Expressions and Body Language Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
Making an initial offer of employment or engagement to you and entering a contract of employment or internship agreement with you. This may include making reasonable adjustments to enable you to carry out a role offered to you. Such reasonable adjustments will be to your duties, responsibilities, and physical work location as appropriate. As appropriate this will include: Religion, Health, Compensation and Benefits, Employment History, Medical Information Forms and Notes, Bank Details, Health, Name, Reference Information, Photograph, Marital Status, Family, Passport, National ID, Address, Personal Certificates (e.g. Birth, Marriage), Qualifications / Grades, Visa Information (Including Sponsor / Cancellation Information), Title, Emergency Contact Details, Beneficiaries, Employment Information (Including Performance) Performance of a Contract Where we process sensitive data we do so only because it is necessary to meet obligations and rights in the field of employment and social security and social protection law. 12 months after completion of the application process relating to the role.
Purpose: General candidate management and administration
Communicating with you and providing you with information in connection with your application or engagement with us from time to time. Telephone Number, Name, Email Address, Interview Responses / Notes, Curriculum Vitae / Application Information Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
Determining whether any adjustments required by law are necessary during the interview process to enable you to carry out a role offered to you (which may include disabilities or dietary requirements). Such adjustments specifically concern personal data relating to Disability Records. Legal Obligations Where we process sensitive data we do so because it is necessary to meet obligations and rights in the field of employment and social security and social protection law. 12 months after completion of the application process relating to the role.
Determining whether any adjustments not required by law are necessary during the interview process to enable you to carry out a role offered to you (which may include disabilities or dietary requirements). Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
Keeping your candidate information and resume on file to consider your suitability for existing and future vacancies. Employment History, Telephone Number, Reference Information, Email Address, Address, Gender, Curriculum Vitae / Application Information Consent 12 months after completion of the application process relating to the role.
Responding to feedback requests from you. Telephone Number, Name, Email Address, Interview Responses / Notes Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
Developing, operating and collecting feedback on recruitment activities and employee/intern selection processes. Name, Email Address, Title, Contact Number Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
Purpose: IT Security
Identifying, investigating, and mitigating incidents, such as where a personal data breach occurs. As appropriate this will include: Email Address, Signature, E-Signature, Employment History, Telephone Number, Name, Reference Information, Email Address, Family, Passport, Address, Qualifications / Grades, Emergency Contact Details, Beneficiaries, Dietary Requirements, Date of Birth, Curriculum Vitae / Application Information, Gender Consent and Legitimate Interest Where we process sensitive data we do so only for the establishment, exercise or defence of legal claims. 12 months after completion of the application process relating to the role.
Supporting disaster recovery procedures such as data recovery and backups. This will include all personal data referenced in the processing activities in this Notice. Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
Purpose: Legal and regulatory compliance and responsibilities
Managing and administering our equal opportunities As necessary this will include: Place of Birth, Date of Birth, Religion, Signature, E-Signature, Compensation and Benefits, Employment History, Telephone Number, Bank Details, Health, Name, Reference Information, Marital Status, Email Address, Family, Passport, National ID, Nationality, Address, Curriculum Vitae / Application Information, Languages Spoken, Qualifications / Grades, Age, Visa Information (Including Sponsor / Cancellation Information), Gender, Travel History, Beneficiaries Legal Obligations and Legitimate Interest Where we process sensitive data we do so where this is in the substantial public interest. 12 months after completion of the application process relating to the role.
Comply with our legal requirements and to the extent necessary to exercise or defend legal claims should they arise. Medical Information Forms and Notes, Name, National ID, Address, Age Consent and Legitimate Interest Where we process sensitive data we do so only for the establishment, exercise or defence of legal claims. 12 months after completion of the application process relating to the role.
Establishing and potentially contacting an emergency contact for individuals in case of emergency. Name, Emergency Contacts' Name, Email Address, Telephone Number, Address, Health Consent and Legitimate Interest It is necessary to protect the vital interests of a candidate. 12 months after completion of the application process relating to the role.
Responding to binding requests or search warrants or orders from courts, governmental, other regulatory and/or enforcement bodies and authorities. As appropriate this will include: Place of Birth, Date of Birth, Religion, Compensation and Benefits, Telephone Number, Photograph, Marital Status, Passport, National ID, Nationality, Qualifications / Grades, Visa Information (Including Sponsor / Cancellation Information), Gender, Title, Employment Information (Including Performance) Legal Obligations Depending upon the nature of the request, we process sensitive data either in the substantial public interest or for the establishment, exercise or defence of legal claims. 12 months after completion of the application process relating to the role.
Responding to non-binding requests or search warrants or orders from courts, governmental, other regulatory and/or enforcement bodies and authorities. Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
Purpose: Day-to-day business operations / other purposes
Implementing, adapting and enhancing systems and processes to develop or improve our business and/or make the application process easier or more enjoyable. Name, Email Address, Curriculum Vitae / Application Information Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
Supporting the sale, transfer or merging of part or all of our business or assets, or in connection with the acquisition of or by another business. In the scenario where part of our business is sold or transferred to another business, we may need to transfer any and all personal data listed in this table to that new business, or provide certain personal data (on a confidential basis) prior to a sale to support the transaction. Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
We process your personal data to improve your user experience when you are on our website. This includes 'remembering you' when you sign in each time (if you select that option). This also includes seeing the ways in which you navigate our website and seeing which pages are of interest to you. IP Address, Information about your visit, including the full Uniform Resource Locators (URL) clickstreams to, on and from our websites, Length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouseovers), methods used to browse away from the page Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
For management and audit of our business operations including accounting. As appropriate this will include: Compensation and Benefits, Telephone Number, Name, Email Address, Languages Spoken, Visa Information (Including Sponsor / Cancellation Information), Gender, Title, Employment Information (Including Performance) Consent and Legitimate Interest 12 months after completion of the application process relating to the role.
To deal with complaints or questions from you. Telephone Number, Name, Email Address, Interview Responses / Notes Consent and Legitimate Interest 12 months after completion of the application process relating to the role.

Some of the processing described above, will include the processing of sensitive data which we are required to process based on your consent and with more care, in accordance with applicable data protection laws. Where this is the case, we make explicit reference to it.

Your personal data will also sometimes be converted into statistical or aggregated data which cannot be used to re-identify you. This is used to produce statistical research and reports amongst other things. This aggregated data may be shared by us.

How long do we keep your personal data?

Your personal data is stored by us and/or our Third-Party Service Providers strictly for the time necessary to achieve the purposes for which the information is collected, in accordance with applicable data protection laws. The storage period is outlined in section titled "How do we use your personal data?" below. We will only retain your personal data after that if you are the successful candidate and the information will be used to on-board/engage you and form part of your employment/engagement records.

When we no longer need to use your information, we will remove it from our systems and records and/or take steps to properly anonymise it so that you can no longer be identified from it (unless we need to keep your information to comply with legal or regulatory obligations to which we are subject).

Who do we share your personal data with?

To the extent necessary, we will also share your personal data with other entities within the Dubai Holding Corporate LLC group of companies. Where we do disclose your personal data within the group or to third parties, we will ensure that appropriate safeguards are in place - for example our Intra Group Transfer Agreement, or Controller to Processor Data Processing Agreements.

We also use companies, agents or contractors ("Third-Party Service Providers") to perform services on our behalf or to assist us with the provision of services to support the recruitment process. For example, we engage Third-Party Service Providers to provide psychometric testing, online competency assessment, background checks, security checks, IT services including suppliers of website hosting services and to provide legal, accounting, insurance, audit and other professional services, to host personal data in data storage facilities. We also use recruitment agencies to assist us with the provision of services to support the recruitment/engagement process.

Third parties permitted by law:

In certain circumstances, we will be required to disclose or share your personal data in order to comply with a legal or regulatory obligation (for example, we could be required to disclose personal data to the police, counter-terrorist government authorities, or to judicial or administrative authorities).

We will also disclose your personal data to third parties in order to enforce our terms and conditions or other agreements, or to protect the rights, property or safety of Dubai Holding or the public, where that is necessary and where data protection laws permit this.

Third parties connected with business transfers:

We will sometimes transfer your personal data to third parties in connection with a re-organization, restructuring, merger, acquisition, or transfer of assets, provided that the receiving party agrees to treat your personal data in a manner consistent with this Notice.

Our legal counsel and other professional advisers:

We will sometimes share your personal data with firms and companies who provide legal, tax, accountancy and audit related services to us.

Recruitment agencies that are appointed by you or us:

We will sometimes use recruitment agencies to find prospective candidates for us, this will also include providing feedback on the application process to recruitment agencies in order to assist them with sourcing us other appropriate candidates in the future. The agency will also provide a candidate with feedback on their performance in the recruitment process directly.

Government agencies:

We will share your personal data with government agencies that provide us with candidate security checks and related services.

Please be aware that, we may share or disclose your personal data without your consent in situations such as in respond to requests from law enforcement and government agencies, for personal data security audits, and to protect individuals from fraud and severe personal injuries.

How do we protect your personal data?
Artificial Intelligence and Machine Learning

For selected roles we use data processors who use artificial intelligence and machine learning during the recruitment process. Our processors incorporate artificial intelligence, machine learning and psychology into their platforms, providing us with an automated candidate view or profile. This allows us to predict areas such as natural abilities, cultural values, cultural needs, competencies, behaviour, thinking styles, working styles, motivators, and integrity.

Profiling

These processors, as well as those who provide online recruitment questionnaires rely on profiling. This means any form of automated processing of your personal data to evaluate certain personal aspects about you, such as to analyse or predict aspects concerning your economic situation, personal preferences, etc. This type of profiling does not have a legal or other significant effect on you. We will seek your consent before the start of this type of personal data processing.

Profiling
Specific details about profiling and automated decisions involving candidates

We sometimes use a questionnaire that automatically ranks candidates, however, no candidates are automatically accepted or rejected, instead they are ranked according to their responses. This is profiling. The answers to the questionnaire do amount to a profile of you. We will seek your consent before the start of this type of Personal Data processing.

Where we store/transfer your personal data?

The majority of personal data processed by us and our recruitment system provider is stored in the United Arab Emirates, where the appropriate data protection measures are in place.

We may transfer this to third parties based in other countries, to the extent necessary to fulfil the purposes described in this Notice. Your personal data may also be transferred within this Dubai Holding Corporate LLC group of companies, as well as it's subsidiaries.

Where data transfers take place, such transfers shall always be done in compliance with relevant data protection laws.

Security of your personal data

We have implemented technology and operational security measures in order to protect personal data from loss, misuse, alteration or destruction. Only authorised persons are provided access to personal data; such individuals have agreed to maintain the confidentiality of this personal data.

Third party websites and apps

Our websites may contain links to and from third party websites. Please note that if you follow a link to any of these websites, these websites will have their own terms of use and privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.

Your rights

You may have certain rights relating to your personal data. However, these rights can differ depending upon the country in which you are located. That country’s law will determine which rights apply and in what instances.

Right to withdraw consent

Where you have provided your consent to us, you will always have the right to withdraw this at any time. You can do this by either by following the information provided at the time you provided your consent, or by contacting us using the following email address privacyoffice@dubaiholding.com. The withdrawal of consent will not affect any processing that was based on consent before its withdrawal.

Right to request correction of your personal data

You will always have the right to request that we correct and update any personal data that we process about you that is inaccurate or incomplete. You can do this by contacting us at privacyoffice@dubaiholding.com.

Additional Data Protection Rights

Certain Data Protection Regulation also provide you with additional rights which may allow you to:

- upon request, be provided access to, or copies of, your personal data that we process;

- upon request, restrict the processing of your personal data;

- upon request, delete your personal data which we process;

- object to our processing of your personal data; or

- upon request, obtain a copy of your personal data which we process in a commonly used and machine-readable format.

- lodge a complaint with the supervisory authority in your country of residence, place of work or the country in which an alleged infringement of data protection law has occurred

It is important to understand that these rights are not absolute (e.g. their application may depend upon the lawful basis we rely upon to process your personal data) and that we may require further information from you (e.g. to confirm your identity) to action your request. You can enquire whether these rights apply to you by contacting us using the following email address at privacyoffice@dubaiholding.com.

AI Implications
Contact us

If you want to exercise any of the rights set out above or have any questions or concerns about how we treat your personal data, please contact us at privacyoffice@dubaiholding.com or by writing to us at: Umm Suqeim Road, PO Box 66000, Dubai, United Arab Emirates. Please include your reply address when you write to us.

Changes to this Notice

We will update this Notice if we need to do that in response to changing legal, regulatory, or operational requirements. We will notify you of any such changes (including when they will take effect) if we are required to do so by data protection laws.