Introduction
This Candidate Privacy Policy (together with our Terms and Conditions and any other documents referred to in it) describes how Bank Albilad (hereinafter referred to as "Bank Albilad," "we," "us," or "our") collects, uses, discloses, and protects the Personal Data of candidates who apply for employment with us (herein referred to as "you" or "your". We are committed to ensuring the privacy and security of your Personal Data and comply with the applicable data protection laws in Saudi Arabia, including but not limited to the Saudi Arabia Personal Data Protection Law (KSA PDPL), the Data Management & Personal Data Protection Standards of the National Data Management Office (NDMO), and the Saudi Arabian Monetary Authority (Saudi Central Bank or SAMA) regulations.
Purpose
The purpose of this Candidate Privacy Policy is to inform you about how we handle your Personal Data during the recruitment process. It explains the types of data we collect, the purposes for which we use it, how we protect it, and your rights regarding your Personal Data. Our goal is to provide transparency about our data processing practices and ensure you are fully informed about how your Personal Data is managed when you apply for a job with us.
We process your data in an appropriate and lawful manner, in accordance with the applicable laws and regulations to which Bank is subject, including the Saudi Personal Data Protection Law, Royal Decree No. M/148 dated 5/9/1444H, herein referred to as "PDPL".
Objective
The objective of this policy is to ensure that your Personal Data is processed in a lawful, fair, and transparent manner throughout the recruitment process. We aim to provide clear and concise information about our data handling practices to build trust and confidence in our recruitment procedures. This policy outlines our commitment to privacy and compliance with relevant data protection regulations and informs you of your rights and how you can exercise them.
Scope
This Candidate Privacy Policy applies to all Personal Data collected and processed by Bank Albilad Group during the recruitment process. This includes data collected through our websites, job application portals, recruitment agencies, and any other channels or touch points where we interact with job applicants. The policy covers the entire recruitment process, from the initial collection of your data to the final decision regarding your application. It applies to all candidates, including those who are ultimately hired and those who are not, ensuring that all Personal Data is handled with the same level of care and compliance with data protection laws.
Acronyms, and Abbreviations
Term | Definition |
Personal Data | Any data, regardless of its source or form, that may lead to identifying an individual specifically, or that may directly or indirectly make it possible to identify an individual, including name, personal identification number, addresses, contact numbers, license numbers, records, personal assets, bank and credit card numbers, photos and videos of an individual, and any other data of personal nature. |
Sensitive Personal Data | Personal Data revealing racial or ethnic origin, or religious, intellectual, or political belief, data relating to security criminal convictions and offenses, biometric or Genetic Data for the purpose of identifying the person, Health Data, and data that indicates that one or both of the individual's parents are unknown. |
Data Processing | Any operation carried out on Personal Data by any means, whether manual or automated, including collecting, recording, saving, indexing, organizing, formatting, storing, modifying, updating, consolidating, retrieving, using, disclosing, transmitting, publishing, sharing, linking, blocking, erasing and destroying data. |
Data Subject Consent | Consent of the data subject refers to any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of their Personal Data. |
Consent Management | Refers to the act or process of managing consents from your users and customers for Processing their Personal Data. |
Data Protection Officer, "DPO" | A DPO is an appointed expert on data protection that informs and advises on applicable data protection laws and regulations, monitors compliance with applicable laws and regulations, and acts as a point of contact with relevant regulatory authorities. |
Candidate | Refers to any person who applies for a job or is nominated for election. |
Policy Statement
Types of Personal Data We May Collect
- Personal details and identification information (e.g., date of birth, nationalities, picture, gender, ID card, passport numbers and other national ID numbers as required, immigration status).
- Relatives and emergency contact details.
- Physical and electronic address details (e.g., private telephone number, email and addresses).
- Education and employment information (e.g., remuneration at your current employer, employment dates with your current employer, interview performance evaluation and scores in any online testing, position information such as position title, and language skills).
- Information submitted as part of your application (e.g., any interviews in which you participate, and anything you choose to submit by choice in support of your application)
- Electronic and physical communication information, including but not limited to emails including attachments, phone conversations, chat or other instant messaging and other communication data.
- Where relevant, behavioral information and information about personality traits such as data collected to assess a candidate's suitability.
- Profile Data includes your username and password, your interests, preferences, feedback.
- Marketing and communications information includes your preferences in receiving marketing from us and any third-party companies on our behalf and your communication preferences.
- Technical information includes your internet protocol (IP) address, login data to our website/ application, browser type and version, time zone setting and location, operating system, platform, and other technology on the devices you use to access this website. We use this information for system administration or our commercial purposes.
In some cases, the Personal Data we collect from you is needed to meet our legal or regulatory obligations. If so, we will indicate to you that the provision of this information, and the consequences if we cannot collect this information. The above-mentioned Personal Data are collected from information that you directly provide (through the completion and submission of online application forms and profiles, through resumes or curriculum vitae, or through interviews or other communications). In some cases, Bank Albilad will also collect Personal Data indirectly from third parties, such as recruitment agencies that you used to apply to Bank Albilad, background check providers and other administration services providers (for instance who provide candidate shortlisting services), or from publicly available sources such as business and employment orientated employment networking services and job boards.
Use of Personal Data
- We will only use your Personal Data when you have provided your consent by applying or when Bank Albilad is required by the applicable laws to do so.
- Information about criminal convictions and offences.
- Information related to credit history to comply with SAMA's hiring requirement.
- Non-personal data may be derived from your Personal Data but is not considered Personal Data for the purposes of law as such does not directly or indirectly reveal your identity.
- However, if we combine or connect aggregated data with your personal data in a way that, either directly or indirectly, identify you we treat the combined data as personal data which will be used in accordance with this Candidate Privacy Policy.
Purpose of Collecting and Processing Personal Data
We always process your Personal Data for a specific purpose and only process the Personal Data which is relevant to achieve that purpose. In particular, we process Personal Data of candidates for the purposes of:
Recruiting and application handling:
- to undertake recruitment activities, such as determining the suitability of a candidate's qualifications, maintaining information on the status of your application.
- to assist us in managing external providers (e.g., recruitment agencies).
- to prepare for and enter into a precontractual employment relationship, such as offer approvals.
Staff Administration:
- to manage our HR records and update the Bank Albilad database (e.g., keeping your application data on file).
- to communicate with you about any actual or potential job vacancy.
Compliance & Risk Management and / or Crime Prevention:
- to carry out background checks as part of the screening process, including checking for any existing or potential conflicts of interest or any other restrictions which may otherwise restrict or prevent a candidate's engagement with Bank Albilad as well as to prevent crime, including fraud, criminal activity and credit history.
- to receive and handle complaints, requests or reports made to a compliance function, HR function, or other designated units within Bank Albilad.
- to comply with any legal or regulatory obligations imposed on Bank Albilad, including responding to actual or potential proceedings, requests, or inquiries from public or judicial authorities, and adhering to requirements related to recruitment practices such as governmental reporting.
Other purposes:
- to provide information to third parties to enable a transfer, merger or disposal to a potential buyer, transferee, merger partner or seller and their advisers in connection with an actual or potential transfer, merger or disposal of part or all of Bank Albilad's business or assets, or any associated rights or interests, or to acquire a business or enter into a merger with it.
Legal Basis for Processing
Our processing of your Personal Data for the purposes mentioned above is based in one or more of the following legal grounds:
- in part, on our legitimate business interests in evaluating your application to manage our relationship with you, to ensure that we recruit appropriate employees, and to evaluate and maintain the efficacy of our recruiting process more generally and in operating our business and protecting Bank and its employees, clients, and third parties. When we rely on this legal ground, Bank Albilad will only process your Personal Data after assessing the adequacy, proportionality, and legitimacy of the data processing activity.
- in part, on our performing contractual and precontractual measures relating to our potential employment relationship with you.
- in part, on our complying with applicable law with regard to Personal Data necessary to satisfy our legal and regulatory obligations, including with regard to public health and workplace safety.
- in part, on your consent, where you choose to participate in our recruiting programs or if we collect sensitive personal data as defined in the PDPL, for legally permitted purposes other than compliance with our legal obligations regarding public health and workplace safety.
- Additionally, you are under no obligation to provide data to us during the recruitment process. However, if you do not provide the information, we may not be able to process your application properly or at all.
Retention
We will retain your Personal Data solely for the duration necessary to complete the recruitment process or to comply with legal, regulatory or internal policy requirements. Should you provide consent, we may retain your Personal Data beyond the recruitment period to consider you for future job opportunities within Bank Albilad. This extended retention will comply with the requirements and provisions outlined in the PDPL and its implementing regulations. You have the right to withdraw your consent at any time, upon which your Personal Data will be securely deleted. If your data is no longer necessary for the purposes for which it was collected, it will be destroyed. Data relating to successful candidates is dealt with by the employee privacy policy that will be provided to you upon joining Bank AlBilad. If your application is successful, your application will be retained as part of your personnel record.
Security
We use a variety of methods, such as firewalls, intrusion detection software and manual security procedures, to secure your data against loss or damage and to help protect the accuracy and security of Personal Data and to prevent unauthorized access or improper use.
If you think that the website or any Personal Data is not secure or that there has been unauthorized access to the website or your Personal Data, please contact DPO@bankalbilad.com immediately.
Who has access to your Personal Data and with whom might it be shared?
Within Bank Albilad:
We make available Personal Data to personnel within Bank Albilad for the purposes indicated in this policy.
Outside Bank Albilad:
For the purposes listed above, and to the extent permitted under applicable law, we may also transfer Personal Data to third parties outside Bank Albilad, such as:
- Third party service providers, who are contractually bound to confidentiality, such as our IT system or hosting providers, cloud service providers, database providers, consultants (including the recruitment agency whom you used to apply to Bank Albilad and others) and third parties who carry out pre-employment checks on prospective employees.
- Authorities, e.g., regulators, enforcement or exchange body or courts or party to proceedings where we are required to disclose information by applicable law or regulation or at their request, or to safeguard our legitimate interests.
- The referees provided on your application form to Bank Albilad.
- Any government department and other statutory or public bodies.
- Any legitimate recipient of communications required by laws or regulations.
Where Bank Albilad transfer your data to third party service providers processing data on Bank Albilad behalf, we take steps to ensure they meet our data security standards, so that your Personal Data remains secure. Third party service providers are thereby mandated to comply with a list of technical and organizational security measures, irrespective of their location, including measures relating to:
- information security management;
- information security risk assessment;
- information security measures (e.g., physical controls; logical access controls; malware and hacking protection; data encryption measures; backup and recovery management measures).
- No method of transmission of data is one hundred percent (100%) secure and absolute security cannot be guaranteed.
Candidate Subject Rights, and how you can exercise them
Your rights:
You have a right to access and to obtain information regarding your Personal Data that we may process. If you believe that any information we hold about you is incorrect or incomplete, you may also request the correction of your Personal Data.
You also have the right to:
- Where applicable, request the erasure of your Personal Data.
- Withdraw your consent where Bank Albilad obtained your consent to process Personal Data (without this withdrawal affecting the lawfulness of any processing that took place prior to the withdrawal), unless statutory or judicial requirements require otherwise.
- Where applicable, request restriction of processing.
- Request a copy of your data in a structured, commonly used format.
- Object to processing based on legitimate interests.
Exercising your rights:
To exercise the above rights, please send an email to DPO@bankalbilad.com.
Changes to your Personal Data
We are committed to keeping your Personal Data accurate and up to date. Therefore, if your Personal Data changes, please inform us of the change as soon as possible.
Updates to this Policy
Any changes to this Privacy Policy will be promptly communicated on this page and you should check back to see whether there are any changes.
Contact Us and Our Data Protection Officer
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
Bank Albilad
Head Office Address: 8229 Al Mutamarat, Unit 2, RIYADH 3952- 12711, Kingdom of Saudi Arabia
Phone: 011-4798888
Worldwide Phone: 00966-14798888
Email: DPO@BankAlbilad.com
Any enquiries with regards to the use of your personal data should be sent to the above email address.
Bank Albilad is committed to protecting your privacy, addressing any concerns, and resolving any issues related to the processing of your Personal Data and will oversee your Personal Data with utmost care and respect.
Periodic Review of this Policy
The bank can review and update this policy at any time and the updates will be reflected for both parties.