PRIVACY POLICY

Privacy Policy & GDPR Compliance Statement | AllAboutLaw Recruitment Services on behalf of Crowell & Moring

AllAboutLaw have been instructed to conduct recruitment services on behalf of Crowell & Moring for the law firm’s 2021 training contract in London. AllAboutLaw is a brand of AllAboutGroup Holdings Ltd.

This privacy policy sets out how AllAboutGroup Holdings Ltd uses and protects any information that you give to AllAboutGroup Holdings Ltd when participating in Crowell & Moring’s application process for their 2021 London training contract. This includes: when you use the CrowellTrainees.co.uk website, register to attend a Crowell & Moring webinar, participate in a Crowell & Moring webinar, submit an application to Crowell & Moring’s 2021 Training Contract via the firm’s online applicant tracking system, complete a video interview or attend a virtual/in-person assessment centre.

AllAboutGroup Holdings Ltd is committed to ensuring that your privacy is protected.

Should we ask you to provide personal data by which you can be identified when participating in Crowell & Moring’s application process for their 2021 London training contract, then you can be assured that it will only be used in accordance with this privacy statement.

AllAboutGroup Holdings Ltd may change this policy from time-to-time by updating this page. We will notify you of any changes or updates we make to this policy. You should also check this page occasionally to ensure that you are happy with any changes. This policy was last updated on 21.07.2020.

If you have any questions, please email AllAboutGroup Holdings Ltd at: mydata@allaboutgroup.org

About GDPR

As of 25 May 2018, all organisations that process personal data on citizens of the EU are required to comply with the EU General Data Protection Regulation (GDPR).

The GDPR replaced the Data Protection Directive 95/46/EC and was designed to harmonise data privacy laws across Europe, to protect and empower all EU citizens’ data privacy and to reshape the way that organisations, which operate within the region, approach data privacy.

The GDPR applies to ‘personal data’ meaning any information relating to an identifiable person who can be directly or indirectly identified in particular reference to an identifier. A broad range of personal identifiers constitute personal data, including: name, location data and IP address.

Our commitment to GDPR

AllAboutGroup Holdings Ltd is committed to data protection. Everybody at AllAboutGroup Holdings Ltd, at the highest management level and throughout the organisation, understands the need for stringent data protection policies and procedures, and we all take responsibility for complying with the GDPR.

We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect online.

We take a data protection by design and default approach, and put appropriate data protection measures in place throughout the entire lifecycle of our processing operations.

We are also committed to ensuring that all third-party data processors that process personal data on our behalf fully comply with the GDPR. We do not enter into contracts with other data processors unless they can demonstrate the steps they have taken towards compliance.

As an organisation we are dedicated to continually reviewing and improving our data protection procedures and accountability measures. 

If you have any questions relating to data protection and/or our privacy policy, please send us an email at mydata@allaboutgroup.org

What personal data do we collect?

When you submit an application via our online applicant tracking system, we collect and store the following data:

- Your first name;

- Your last name;

- Your email address;

- Your phone number;

- Your preferred name;

- Your country of residence;

- If you have any personal links with Crowell & Moring;

- Visa status (if applicable);

- A copy of your visa (if applicable);

- Availability for starting a training contract in January 2021;

- Completion of the Legal Practice Course (LPC);

- Your CV - including academic achievements, work experience and extracurricular activities;

- Grades for each of your degree modules;

- Grades for each of your GDL modules;

- Grades for each of your LPC modules;

- A statement of how you obtained your work experience;

- Any extenuating circumstances for your academic performance;

- Details of any exam resits;

- Criminal convictions;

- Details of any proceedings and/or complaints initiated by membership bodies;

- Details of any professional memberships;

- Employment referees;

- Attendance at a Crowell & Moring webinar;

- How you heard about this job opportunity;

When you register to attend a Crowell & Moring webinar, we collect and store the following data:

- Your first name;

- Your last name;

- Your email address;

When you submit a video interview, we collect and store the following data:

- First name;

- Last name;

- Email address;

- Video recording of your video interview answers;

When you complete a voluntary Equal Opportunities Questionnaire, we collect and store the following data:

- Age;

- Gender;

- Gender identity;

- Sexual orientation;

- Ethnicity;

- Disability status;

- If you consider yourself to be from a disadvantaged socio-economic background;

- The reasons why you consider yourself to be from a disadvantaged socio-economic background;

- Your parents or guardians’ highest level of academic attainment.

When you use CrowellTrainees.co.uk, we may process data on your use of the website, including:

- Which pages you visit;

- The time of your visit;

- How long you spend on each page;

- How long you remain on the website;

- The method/ by which you were referred to our website, e.g. via Google or social media channel;

- Your general site browsing habits;

- The type of device you used to access the website;

- The type of web browser you used to access the website;

- The type of operating system you used to access the website;

- Your network location and IP address.

Please see below for details of why and how we process this personal data.

Our lawful basis for collecting this data

Before we process any of your personal data, we obtain active, clear consent from you. According to the GDPR, this should be explicit and requires a very clear and specific statement of consent.

When we ask you to opt in or opt out of our Privacy Policy, we provide you with all of the information you need on how and why we process this data.

This is hugely important, as we want to offer all individuals real choice and control.

How do we obtain your consent to process your personal data?

We always obtain active consent, explicitly asking you to allow us to process your data.

These data processing consent requests are communicated in a clear and concise way. They require you to provide a positive opt-in and we don’t use pre-ticked boxes or any other methods of default consent.

Please note: there are no third-party controllers who rely on this consent. All of the information you share with us is solely controlled by AllAboutGroup Holdings Ltd. We do, however, use third-party data processors to help us process some of your personal data. A list of these can be found below.

We are committed to ensuring that all of the third-party data processors that process personal data on our behalf fully comply with the GDPR. Indeed, we do not enter into contracts with other data processors unless they can demonstrate the steps they have taken towards compliance.

Please note: even if you provide us with consent initially, you can remove your consent at a later date. Just send us an email to make your request at: mydata@allaboutgroup.org

We will act on these withdrawals of consent as soon as we can and will not penalise any individuals who wish to withdraw their consent.

In order to liaise with you throughout the Crowell & Moring application process, we do require you to agree to our Privacy Policy in order to submit an application. Indeed, it is impossible for us to contact you about your progression through the application process or assess your suitability without being able to process your personal data. 

When you use the CrowellTrainees.co.uk website, we may place cookies on your browser to log your session or record user traffic via Google Analytics.

Why do we collect this personal data and what do we do with it?

We require your personal data to understand and assess your suitability for a training contract with Crowell & Moring. 

This data will be accessible by the following people: 

- Selected employees of Crowell & Moring;

- Selected employees of AllAboutGroup Holdings Ltd, all of whom are required to sign a GDPR compliance agreement, receive GDPR ‘refresher training’ every 6 months and are required to complete online cyber security training each year. 

- Selected recruitment associates of AllAboutGroup Holdings Ltd, all of whom are required to sign a GDPR compliance form as part of their contract with us.

Please note: we do not process personal data for the purposes of automated individual decision making or profiling.

Reasons for processing - breakdown by data category

We collect and store the following data for specific reasons. Here’s a breakdown for you:

- Your first name - This helps us to personalise our communications with you throughout the assessment process and identify you as a candidate;

- Your last name - This helps us to personalise our communications with you throughout the assessment process and identify you as a candidate;

- Your email address - This helps us to communicate with you throughout the assessment process and notify you of your progression through the various stages of assessment;

- Your phone number - This helps us to communicate with you throughout the assessment process and notify you of your progression through the various stages of assessment;

- Your preferred name - This helps us to address you using your preferred name when communicating with you throughout the application process;

- Country of residence - This helps us to assess your eligibility to work for Crowell & Moring in the UK;

- Visa status (if applicable) - This helps us to assess your eligibility to work for Crowell & Moring in the UK;

- A copy of your visa (if applicable) - This helps us to assess your eligibility to work for Crowell & Moring in the UK;

- If you have any personal links with Crowell & Moring - This helps us to assess your eligibility to work for Crowell & Moring in the UK;

- Availability for starting a training contract in January 2021 - This helps us to assess your eligibility to start work for Crowell & Moring when required;

- Completion of the Legal Practice Course - This helps us to assess your eligibility to start work for Crowell & Moring when required;

- Your CV - This helps us to assess your suitability for a training contract with Crowell & Moring;

- Grades for each of your degree modules - This helps us to assess your suitability for a training contract with Crowell & Moring;

- Grades for each of your LPC modules - This helps us to assess your suitability for a training contract with Crowell & Moring;

- A statement of how you obtained your work experience - This helps us to assess your suitability for a training contract with Crowell & Moring;

- Any extenuating circumstances for your academic performance - While academic performance is an important consideration for us when assessing your suitability for a training contract with Crowell & Moring, it is important that we understand the context around any circumstances which may have affected your performance to help us consider all applicants fairly;

- Details of any exam resits - While academic performance is an important consideration for us when assessing your suitability for a training contract with Crowell & Moring, it is important that we understand the context around any circumstances which may have affected your performance to help us consider all applicants fairly;

- Criminal convictions - This helps us to assess your eligibility to work for Crowell & Moring in the UK;

- Details of any proceedings and/or complaints initiated by membership bodies - This helps us to assess your eligibility to work for Crowell & Moring in the UK;

- Details of any professional memberships - This helps us to assess your eligibility to work for Crowell & Moring in the UK;

- Employment referees - This helps us to assess your suitability for a training contract with Crowell & Moring;

- Attendance at a Crowell & Moring webinar - This helps us to evaluate the efficacy of our recruitment marketing activities;

- How you heard about this job opportunity - This helps us to evaluate the efficacy of our recruitment marketing activities;

- Video recording of your video interview answers - This helps us to assess your suitability for a training contract with Crowell & Moring.

- Equal Opportunities data (optional) - Crowell & Moring is an equal opportunities employer, committed to a policy of treating all employees and job applicants equally.

It is Crowell & Moring’s policy not to discriminate against applicants on the basis of their age, disability, gender reassignment, marital or civil partner status, pregnancy or maternity, race, colour, nationality, ethnic or national origin, religion or belief, sex or sexual orientation.

With this in mind, each applicant is asked to complete a voluntary Equal Opportunities Questionnaire, which requests the following data:

- Age;

- Gender;

- Gender identity;

- Sexual orientation;

- Ethnicity;

- Disability status;

- If you consider yourself to be from a disadvantaged socio-economic background;

- The reasons why you consider yourself to be from a disadvantaged socio-economic background;

- Your parents or guardians’ highest level of academic attainment.

The reason we process the data listed above is that Crowell & Moring is dedicated to widening access to the legal profession, particularly for people from under-represented backgrounds. Once you have submitted your application, you will receive an email with a separate Equal Opportunities Questionnaire. This monitoring form is voluntary but the information collected here is very useful as it helps us to understand the diversity of those candidates who apply to Crowell & Moring. Your answers are strictly confidential and will be anonymised. It will NOT be a factor in any recruitment decisions. 

We may also use the following information to improve our products and services, or customise the CrowellTrainees.co.uk website according to your interests:

- Which pages you visit;

- The time of your visit;

- How long you spend on each page;

- How long you remain on the website;

- The method/ by which you were referred to our website, e.g. via Google or social media channel;

- Your general site browsing habits;

- The type of device you used to access the website;

- The type of web browser you used to access the website;

- The type of operating system you used to access the website;

- Your network location and IP address.

Where is this personal data stored?

Any of the data that we processed internally by AllAboutGroupHoldings Ltd is securely stored on our dedicated server which is managed by our server provider at their privately owned UK Data Centre.

It is a Tier 3+ 2N UK Data Centre which uses the latest technology to deliver the highest reliability, security and performance.

Security is a top priority at the Data Centre. 3m perimeter fencing, 25+ CCTV cameras, 24x7 personnel and electronic access control systems safeguard the data hall from unauthorised access.

For security reasons, the name of the server provider will only be named on receipt of legitimate requests.

All of the data you give us consent to use by opting into cookies on your browser is processed by Google Analytics.

Some of your data will be processed by our 3rd party data processors. You can view how they store and process your data below. 

3rd party data processors we use to help process your data

Here is a list of the 3rd party data processors we use to store or process your personal data during the application process for the Crowell & Moring training contract. Click on their names to read their own Privacy Policies:

- Leadpages - CrowellTrainees.co.uk website

- Google GSuite - via Google Forms - webinar registration

- Jazz HR - applicant tracking system

- Spark Hire - video interviews

We are committed to ensuring that all of the above third-party data processors that process personal data on our behalf are fully compliant with the GDPR.

We do not enter into contracts with other data processors unless they can demonstrate the steps they have taken towards compliance.

Security measures and procedures

We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, we have analysed the risks presented by our processing and have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect online.

All of the platforms we use have an SSL Certificate installed. This means when you are browsing on any of these platforms a secure connection will be established, and the connection between your browser and our server will be secure. You can see that the SSL Certificate is working correctly because a padlock or green bar will show in the address bar in your browser, depending on which one you use.

This is a method of cryptography and encrypts the data that is sent from your browser to our servers. This means that if a hacker was to intercept that message, they will only be able to see a cryptographic code that it is impossible for them to break. Only the intended recipient of this data (i.e. our secure server) will be able to understand and process it.

Furthermore, we use the following measures to ensure the protection of your personal data:

  • Enforced strong passwords and password change lockouts;
  • Regular auditing of internal computers and laptops;
  • Password or user permissions protected documents and folders;
  • Industry leading antivirus and firewall software.

We regularly review our information security policies and measures and improve them where necessary. We also conduct regular testing and reviews of our measures to ensure they remain effective. We also make sure that any data processors we use implement appropriate technical measures.

How long do we retain your data?

The GDPR states that personal data should be stored for no longer than is necessary for the purposes for which the personal data is processed. With that in mind, we will only store personal data on Crowell & Moring applicants for a maximum of one year from the date on which you provide consent for us to process your data, unless you request otherwise.

Data breach policy and procedure

We are fully committed to securing your personal data. We make sure that we constantly review and update our security practices where necessary.

In the event that the data we store and process is subject to a data breach, however, we have a data breach policy and procedure in place to help mitigate against impact this may have on your personal security.

We have prepared a response plan for addressing any personal data breaches and have put a data breach procedure in place. All members of our staff are educated about this procedure and are given access to the guidance and resources required to notify our Head of Operations if they suspect that a data breach has occurred.

If it is ascertained that a data breach has, in fact, taken place, we have outlined a process to assess the likely risk to individuals as a result of the breach.

We will then notify the ICO of a breach within 72 hours and the individuals affected without undue delay. We will also provide any affected individuals with advice on how to protect themselves from its effects.

Links to other websites

Our website may contain links to other websites. However, once you have used these links to leave our site, you should note that we do not have any control over that other website. Therefore, we cannot be responsible for the protection and privacy of any information, which you provide whilst visiting such sites and such sites are not governed by this privacy statement. You should exercise caution and look at the privacy statement applicable to the website in question.

Your rights as a data subject & controlling your personal data

Once you have given us consent to process your personal data, you are entitled to:

- Access the data we hold on you;

- Rectify the data we hold on you if you believe it to be incorrect;

- Request that the data we hold on you be erased;

- Request that we restrict the processing of the data we hold on you;

- Obtain and reuse the data we hold on you for different services;

- Object to the use of your data for direct marketing.

To exercise your rights and request any of the above, please email: mydata@allaboutgroup.org

We will not charge you to request any of the above, unless the request is deemed to be excessive. In the unlikely event of this happening, we may charge you a small fee to cover the costs of this excessive request.

If you have any concerns about this Privacy Policy or how we handle your personal data, you have the right to lodge a complaint to the GDPR’s supervisory authority in the UK.