Data Privacy Notice for Job and Academic Appointment Applicants

How we use your personal information

This privacy notice explains how Wolfson College (“we” “our” “the College” and “us”) handles and uses information we collect about applicants (“you” and “your”) for Jobs, College memberships and Academic appointments.  (Note:  There is a separate privacy notice for Research Fellowships and Referees.)

This statement forms part of the College’s compliance with data protection legislation in the UK.

The controller for your personal data is Wolfson College, Barton Road, Cambridge CB3 9BB.  Your primary contact for all data protection matters is the College Data Protection Lead: bursar@wolfson.cam.ac.uk This is the same address to contact if you wish to exercise any of your data protection rights, including requesting copies of personal data the College holds about you, or making a complaint about how the College has managed your personal data. 

The designated Data Protection Officer appointed by the College under UK GDPR is Intercollegiate Services Limited (ISL), 64 Bridge Street, Cambridge, CB2 1UR; 01223 768745; dpo@isl.colleges.cam.ac.uk.

What data are processed and why

In broad terms, we use data you provide on application forms and associated recruitment documents for the purposes of considering your suitability for employment, election, or appointment and for us to manage our recruitment processes, including our monitoring of equality and diversity within the College.

Unless otherwise stated below, the lawful basis for processing your personal data is that it is necessary in order for you to enter into an employment contract, or membership agreement with us where you will be subject to the College’s governing documents. 

The College may hold the following personal data relating to you, in line with the purposes above:

A. Personal details, including name, contact details (phone, email, postal)*.

B. Your application form and associated information submitted by you at that time*.

C. Other data relating to your recruitment (including references we take up as part of the recruitment process, any pre-employment assessment of you, and any assessment of you at an informal or formal interview).

D. Any occupational health assessments and/or any medical information you have provided * and other related work requirements.

E. Evidence of your right to work in the UK (e.g. a copy of your passport*).

F. Information relating to your age, gender reassignment, marriage and civil partnership, race (including colour, nationality, ethnic or national origin), religion or belief, sex, sexual orientation and disability*).

G. Any correspondence relating to the process and outcome of the recruitment process (either successful or unsuccessful).

Where does the data come from?

Those marked with an * relate to information provided by you. Other data and information are generated by us or, where self-evident, provided by a third party.

We will not access personal data about you from social media sites unless there is a legitimate interest for us to do so (e.g. the role you have applied for has a significant public-facing element to it or is involved with publicity and presenting us to the general public). Consequently, we do not routinely screen applicants' social media profiles but, if aspects of your social media profile are brought to our attention and give rise to concerns about your suitability for the role in question, we may need to consider them. 

We may use Disclosure and Barring Services (DBS) and Disclosure Scotland to help assess your suitability for certain “regulated activities” as defined in the Safeguarding Vulnerable Groups Act 2006.  If this is the case, we will make this clear to you in separate correspondence.  Certificate and status check information is only used for this specific purpose, and we comply fully with the DBS Code of Practice regarding the correct use, handling, storage, retention and destruction of certificates and certificate information.  We recognise that it is a criminal offence to pass this information on to anyone who is not entitled to receive it.  The College has a legal obligation to process criminal offence data to apply for DBS disclosures for roles identified as “regulated activities” The condition for processing criminal offence data is the ‘safeguarding of children and individuals at risk’.

We do not undertake automated decision-making or profiling.

Who we share your data with

Although we manage your data within the College, we use cloud-based storage systems for recruitment.  We have carried out a Data Protection Impact Assessment (DPIA) to assess the risks to your privacy in using these systems and have data sharing agreements in place to cover the data sharing. 

We do not share with other third parties without your written consent, except in an anonymised form where required by law (e.g. under the Freedom of Information Act). 

The College captures and records timed images of individuals moving through the College, using a number of fixed CCTV cameras. CCTV images are automatically deleted after 30 days, unless a copy is made for evidential or investigative purposes. Further details of the College’s CCTV system and procedures can be found in our CCTV Policy and Code of Practice.  

If you have concerns or queries about any of these purposes or how we share your data, please contact us at the address given above.

How long we keep information for

If you are successful in your application, the data is subsequently held as part of your employment, membership, or appointment record with us. 

If you are unsuccessful in your application, we retain personal data and information for no more than twelve months after the closing date of the application process.  The names of those who apply for College Fellowships and Senior Memberships are retained permanently. 

In either case, where a post has required a visa to work in the UK, the College will retain the application records of all shortlisted candidates for the duration of the sponsored post plus twelve months thereafter to comply with Home Office visa and immigration regulations.

Anonymised data is kept for equal opportunity monitoring. 

Your rights

You have the right: to ask us for access to, rectification or erasure of your data; to restrict processing (pending correction or deletion); and to ask for the transfer of your data electronically to a third party (data portability). Some of these rights are not automatic, and we reserve the right to discuss with you why we might not comply with a request from you to exercise them.

If you feel that the College has not met your expectations while handling your personal data, you have the right to make a complaint. Full details of the College’s data protection complaints procedure can be found at https://www.wolfson.cam.ac.uk/about/governance/data-protection

You retain the right at all times to lodge a complaint about our management of your personal data with the Information Commissioner’s Office. Details of how to make a complaint to the Information Commissioner’s Office are available at https://ico.org.uk/make-a-complaint/

This is a live document which will be updated periodically. The most recent version will always be available on our website.

College Data Protection Lead

Last updated: June 2026

 

Version Control 

DateVersionReview Reason

2018

 

DraftNew DPS for review by the Information & Records Management Working Party
2018              1.0Publication
06/20261.1Reviewed by Compliance Manager.  Senior Members, & Academic Visitors included.  New ISL contact details and complaints process to comply with DUAA legislation effective 19/6/2026.