Hacker News new | ask | show | jobs
by Insimwytim 40 days ago
There's also issue with EU companies forcing candidates to agree to their anti-privacy policies (confusingly named "privacy policies") as a requirement before the job interview.

Those anti-privacy policies will state, that you grant the company and third-parties (so, anyone) permissions to use your data (including voice and image) for any purpose. (Of course, it is stated in a slightly obscure fashion, so a layman may not comprehend it.)

I wonder if there has been any similar action taken against those.

2 comments

I haven't personally encountered that, but you are free to lodge complaint with your local DPA about it.

That exact language is unlikely to be compliant. If you want to maximize your effect you could make Article 15 request to the company in question, get the list of actual recipients of data (make sure to be ask for this specifically) and then make another request to all of those companies. That will then allow you to possibly make further complaints (e.g. why exactly they didn't send Article 14 information to you, are the legal basis they use actually proper in your case especially if the original one was consent and it was not freely given).

Wouldn't you have to "consent" first?

What if you didn't and did not proceed with the process? Can you complain still?

As in - if you didn't give your consent there's no violation has occurred and they don't have your data, so nothing to ask for?

That's a bit more complex.

Everyone is free to make a tip to DPA. However DPA is free to decide if they want to start their own investigation based on that unlike when you make Article 77 complaint.

There isn't a lot of case law around the threshold of Article 77. The text says "if the data subject considers that the processing of personal data relating to him or her infringes this Regulation". If read completely alone one could make argument that since you didn't consent no processing occurred -> you do not have right to make an Article 77 complaint.

However when taking the in account the goals and purpose of GDPR as well as recital 141 I would argue otherwise. To be specific recital 141 says "if the data subject considers that his or her rights under this Regulation". CJEU also often refers to GDPR's objective of ensuring high level of protection of fundamental rights and freedoms of natural persons. I feel that ex post requirement would be quite contrary to that.

Due to this my personal stance would be that just offering invalid consent choice where refusal has negative consequences is something that violates data subject's rights even if processing didn't occur and would be eligible for actual Article 77 complaint rather than just tip to DPA.

[EDIT] Also, there is Article 82 path via damages. In your case you could potentially argue that you suffered damages (like lost wages) due to company's invalid consent requirement. This, however, is generally a lot harder and more expensive path. Depending on how legal costs are allocated in your jurisdiction you could also end up with judgement where you need to pay your opponent's legal costs if you lose.

For Article 82 claim you almost definitely will need a lawyer.

Can i withdraw consent later? So, attend the interview (to maximise my chances of being offered the job), and then after the application process withdraw consent?
You can withdraw consent later, but I don't see how that would affect data processed before the withdrawal (except that storage is processing and the data would have to be deleted). I don't imagine a reputable employer would have any other use for the data, so the withdrawal of your consent might not bother them much. If your application were successful and you took the job, I expect that would establish contract, rather than consent, as a legal basis for them to process your data.

In general, I'm not sure a company processing my data on the basis of consent would stop all processing of my data just because I withdraw my consent. Some processing of some of my data might have a different legal basis. Judging by some websites' privacy options, there's a distinction between consent (opt-in), legitimate interest (opt-out) and other legal bases (maybe neither). I'm confused about website forms that have separate reject and object options for each category of data processing and a reject-all button that closes the form. Does clicking "reject all" mean I have or haven't objected?

Thanks. Appreciate the thought trail. For an employer, if they delete the data later (if I don't get the job) then I'm ok with that since I'm expecting it to be accessed and used by humans.

Interesting about the website forms that have separate options for each category, I'd always believed this was to wear me down so I click "agree" once instead of changing 98 separate sliders to no.

Our local DPA, who will then proceed to ignore it for years or tell us to take them to court ourselves. [0] As European privacy law including GDPR is a symbolic tool meant to placate and selectively enforce when politically expedient, not to seriously enforce. Understandable, given that near all EU politicians work for corporate interests, as in the US.

[0] https://noyb.eu/en/project/dpa/dpc-ireland - 80% of complaints pending a reply for more than 1.5 years

I grated a bit at an EU company's use of https://www.crosschq.com/ recently.