Return to the Legal & Compliance Centre to view all policies, procedures, terms, and compliance documents.
Privacy & Data Protection

Data Protection Policy

Review our approach to data protection, information security, privacy safeguards, and responsible handling of personal data.

   
Clause I

Purpose

Virtual Recruitment Solutions ("VRS", "we", "us", or "our") is committed to protecting personal information, confidential information, customer data, candidate information, business records, and other information entrusted to us.

The purpose of this Data Protection Policy is to establish the principles, standards, responsibilities, controls, and safeguards applied by VRS when collecting, accessing, processing, storing, transferring, disclosing, managing, retaining, and protecting information in connection with our business activities.

This Policy supports VRS's commitment to responsible information management, confidentiality, information security, privacy protection, customer trust, legal compliance, and operational integrity.

VRS recognises that effective data protection is essential to maintaining confidence in our services and supporting the secure delivery of recruitment-focused support solutions.

   
Clause II

Scope

This Policy applies to all information handled by or on behalf of VRS in connection with its business operations and service delivery activities.

This includes information accessed, processed, stored, managed, transferred, reviewed, or otherwise handled by directors, officers, contractors, consultants, support professionals, authorised representatives, service providers, and other individuals acting on behalf of VRS.

The Policy applies to customer information, candidate information, contractor information, supplier information, business records, website information, marketing information, recruitment records, commercial information, operational information, system information, and confidential information regardless of format or storage location.

   
Clause III

Data Protection Principles

VRS seeks to manage information in accordance with recognised privacy, confidentiality, information security, and data protection principles.

Information should be collected lawfully, processed fairly, used only for legitimate business purposes, retained only where necessary, protected against unauthorised access, maintained accurately, handled responsibly, and managed in a manner that respects applicable legal obligations and individual rights.

VRS also seeks to ensure that information handling practices remain proportionate, secure, transparent, accountable, and aligned with recognised international privacy and data protection standards.

   
Clause IV

Data Protection Roles and Responsibilities

Depending on the circumstances, VRS may act either as a controller of information or as a processor/service provider acting on behalf of a customer.

Where VRS determines the purpose and means of processing personal information, VRS acts as the controller and is responsible for ensuring that such processing is conducted lawfully and appropriately.

Where VRS personnel access customer-controlled systems, databases, applicant tracking systems, customer relationship management systems, communication platforms, recruitment systems, reporting systems, or related technologies, VRS generally processes information in accordance with customer instructions and contractual arrangements.

Customers remain responsible for the lawful collection, use, disclosure, storage, retention, and transfer of information within their own systems.

All individuals providing services through VRS share responsibility for protecting information and complying with applicable security, confidentiality, and data protection requirements.

   
Clause V

Information Covered by this Policy

This Policy applies to information including personal information, candidate information, resumes, employment history, qualifications, reference information, interview records, recruitment records, customer information, contractor information, supplier information, financial information, commercial information, contractual information, operational records, communications, system information, access credentials, website information, analytics information, marketing information, reporting information, compliance information, and confidential business information.

The Policy applies regardless of whether information is stored electronically, physically, verbally communicated, or maintained within third-party systems.

    
Clause VI

Information Classification

VRS encourages information to be handled according to its sensitivity and business importance.

Information may be classified as Public, Internal, Confidential, or Restricted. Public information includes information intended for unrestricted distribution. Internal information includes operational information intended for authorised business use.

Confidential information includes customer information, recruitment information, commercial information, and business records that should only be accessed by authorised individuals.

Restricted information includes highly sensitive information where unauthorised disclosure could result in significant legal, operational, financial, privacy, reputational, or commercial harm.

Appropriate safeguards should be applied according to the classification of the information.

   
Clause VII

Lawful and Responsible Processing

Information should only be collected, accessed, processed, used, disclosed, transferred, or retained where there is a legitimate business purpose, contractual requirement, legal obligation, customer instruction, consent, or other lawful basis for doing so.

VRS seeks to avoid excessive collection, unnecessary processing, unauthorised disclosure, or inappropriate use of information.

Information should be handled only to the extent reasonably necessary for the purpose for which it was obtained.

   
Clause VIII

Data Minimisation

VRS promotes data minimisation principles throughout its operations.

Only information reasonably necessary for service delivery, recruitment support activities, operational requirements, compliance obligations, customer instructions, legitimate business purposes, or legal requirements should be collected or processed.

Individuals providing services through VRS should avoid creating unnecessary copies of information, downloading information without authorisation, storing excessive information, or retaining information beyond legitimate business requirements.

   
Clause IX

Data Accuracy

VRS seeks to maintain accurate, complete, relevant, and current information.

Reasonable steps should be taken to correct inaccuracies, update outdated information, remove duplicate records, and maintain data quality where practical and appropriate.

Customers, candidates, contractors, suppliers, and other individuals are encouraged to notify VRS where information requires correction or updating.

   
Clause X

Access Management and Permissions

Access to information should be limited to authorised individuals with a legitimate business need.

VRS encourages the use of role-based access controls, least-privilege principles, individual user accounts, authentication controls, periodic access reviews, and access removal processes when access is no longer required.

Shared credentials should be avoided wherever practical. Administrative privileges should be granted only where necessary and should be reviewed regularly.

Access to sensitive information should be restricted according to operational requirements and information classification levels.

   
Clause XI

Client Systems and Customer Data

VRS personnel may be granted access to customer-controlled systems including applicant tracking systems, customer relationship management platforms, communication systems, recruitment databases, reporting systems, document management systems, sourcing tools, email platforms, compliance systems, and related technologies.

Customers are encouraged to provide only the minimum access necessary to perform agreed services and to maintain appropriate internal controls over user permissions, account creation, account ownership, system administration, and access reviews.

VRS seeks to process customer data only to the extent necessary to deliver agreed services and in accordance with applicable contractual obligations, confidentiality requirements, customer instructions, and legal obligations.

VRS does not claim ownership of customer data.

   
Clause XII

Confidentiality Obligations

All individuals providing services through VRS are expected to maintain appropriate confidentiality regarding information obtained through their activities.

Confidential information should not be disclosed, copied, transferred, discussed, distributed, or otherwise made available to unauthorised persons.

Confidentiality obligations apply during and after the relevant business relationship and continue unless information becomes publicly available through lawful means.

Appropriate contractual, operational, and technical measures may be used to support confidentiality obligations.

   
Clause XIII

Information Security Controls

VRS seeks to maintain appropriate administrative, technical, organisational, and physical safeguards designed to protect information against unauthorised access, disclosure, misuse, loss, alteration, corruption, destruction, or compromise.

Such safeguards may include authentication controls, access restrictions, confidentiality obligations, security awareness activities, role-based permissions, monitoring controls, endpoint protection, secure communication methods, cloud security measures, data minimisation practices, password management standards, encryption technologies where appropriate, and secure disposal procedures.

Security controls should be proportionate to the sensitivity of the information being protected.

   
Clause XIV

Remote Working and Device Security

As VRS operates within a distributed and remote service delivery environment, individuals providing services through VRS are expected to maintain appropriate security practices when accessing information remotely.

Devices should be protected through authentication controls, operating systems should be maintained and updated, confidential information should be protected from unauthorised viewing, and reasonable care should be taken when working from shared or public environments.

Where practical, information should remain within authorised systems rather than being stored locally on personal devices.

Lost, stolen, compromised, or suspected compromised devices should be reported promptly.

   
Clause XV

Third-Party Providers and Vendors

VRS may utilise third-party providers to support business operations, communication, recruitment support activities, customer relationship management, cloud infrastructure, analytics, accounting, scheduling, marketing, document management, and related activities.

Where practical, VRS seeks to engage reputable providers that maintain appropriate privacy, confidentiality, security, and compliance standards.

VRS may assess providers based on factors including security practices, operational reliability, confidentiality commitments, legal compliance, and suitability for the intended purpose.

   
Clause XVI

Data Subject Rights and Requests

Where applicable, individuals may have rights relating to their personal information, including rights of access, correction, deletion, restriction, objection, portability, withdrawal of consent, and complaint.

Requests relating to personal information should be directed to VRS using the contact details provided within this Policy.

Before responding to a request, VRS may require information necessary to verify identity and authority.

VRS may decline requests where permitted by law or where legal, contractual, operational, security, or regulatory obligations require continued retention or processing of information.

   
Clause XVII

Data Breach Management

A data breach may involve unauthorised access, disclosure, misuse, corruption, alteration, loss, theft, destruction, compromise, or unavailability of information.

Suspected or actual incidents should be reported promptly through appropriate channels.

VRS may investigate incidents, assess affected information, identify potential risks, implement containment measures, undertake remediation activities, determine notification requirements, cooperate with affected customers where relevant, and take reasonable steps to reduce the likelihood of recurrence.

Where required by law, VRS may notify customers, individuals, regulators, authorities, or other affected parties.

Following significant incidents, VRS may review controls, procedures, and practices to identify opportunities for improvement.

   
Clause XVIII

International Data Access and Transfers

VRS operates internationally and may utilise personnel, customers, contractors, technology providers, cloud infrastructure providers, communication platforms, and business systems located across multiple jurisdictions.

As a result, information may be accessed, processed, stored, transferred, reviewed, or managed across international borders.

VRS seeks to implement reasonable safeguards including confidentiality obligations, contractual protections, access controls, security measures, and operational controls designed to protect information involved in cross-border activities.

Customers remain responsible for assessing their own legal obligations relating to international access, transfers, and processing within their environments.


   
Clause XIX

Monitoring, Auditing and Review

VRS may monitor compliance with this Policy through operational reviews, access reviews, security reviews, compliance assessments, incident reviews, customer feedback, process evaluations, training activities, and other governance mechanisms.

This Policy may be reviewed, updated, amended, or replaced periodically to reflect changes in legal requirements, operational practices, technology, security threats, business activities, industry standards, or customer expectations.

Corrective actions, process improvements, and additional safeguards may be implemented where appropriate.

   
Clause XX

Contact Information

Questions, concerns, incidents, complaints, requests, or enquiries relating to data protection, confidentiality, information security, or this Policy may be directed to:

Virtual Recruitment Solutions

VRS will seek to review and respond to data protection enquiries within a reasonable timeframe and in accordance with applicable legal obligations and internal procedures.