Data Processing Agreement
(“Agreement”)
1. Scope
1.1. For the purpose of clauses 1.1.1 and 1.1.2, Stepstone Group UK Ltd (“Stepstone Group UK”) shall process personal data on behalf of the Customer in accordance with the UK General Data Protection Regulation (“UK GDPR”) and the UK Data Protection Act 2018 (“UK DPA”) (together the “Data Protection Legislation”). The Customer shall be the data controller, and The Stepstone Group UK shall be the data processor in the following circumstances:
1.1.1. Direct Search Database. Stepstone Group UK processes personal data on behalf of the Customer to the extent that the Customer uses the comment function (“Comment Function”) within the Stepstone Group UK Direct Search Database (“Direct Search”). When using the Direct Search function, it is possible for the Customer to view profiles of Jobseekers and, in particular may save comments on the respective profiles. Stepstone Group UK only processes personal data on behalf of the Customer in the event that the Comment Function is used (storage of the respective comments on a Candidate’s profile).
1.1.2. Applicant Application Manager. Stepstone Group UK processes personal data on behalf of the Customer to the extent that the Customer uses the Comment Function within Applicant Manager. When using the Applicant Manager, it is possible for the Customer to add comments on the Candidates’ application. Stepstone Group UK only processes personal data on behalf of the Customer in the event that the Comment Function is used.
1.2. Stepstone Group UK shall only process the personal data within the UK or the European Economic Area (“EEA”), unless instructions to the contrary have been issued by the Customer and any data transfer complies with the Data Protection Legislation.
1.3. The processing of personal data will terminate once the use of the respective services has ended. The subject-matter, nature and purpose of the processing is as set out under clause 1.1.1, 1.1.2 and 2.1. The duration of the processing corresponds to the duration of the application process, with the data being deleted by the system twelve (12) months after receipt of an application. The categories of data subjects are Jobseekers, and the types of personal data are the comments added by the Customer to profiles of Candidates within the scope of the Comment Function pursuant to clause 1.1.1 of this Agreement.
1.4. Within this frame of reference, the data subjects are individuals who apply for specific job roles through Customers’ job adverts or those who have profiles which allow Customers to add their own comments.
2. Stepstone Group UK’s obligations
2.1. Stepstone Group UK will only process the personal data derived from the (i) Comment Function and (ii) application status to the extent, and in such a manner, as is necessary for the purpose of the contract in effect between the parties to provide services, which include the Comment Function (“Contract”) and in accordance with the Customer’s written instructions from the agreed authorised persons. Stepstone Group UK will not process the Personal Data for any other purpose or in a way that does not comply with this Agreement or the UK GDPR. Stepstone Group UK will promptly notify the Customer if, in its opinion, the Customer’s instructions do not comply with the UK GDPR, unless required to do so by applicable law to which Stepstone Group UK is subject. In such case, Stepstone Group UK will notify the Customer of the legal requirement before processing, unless, that law prohibits such information on important grounds of public interest.
Security
2.2. Where processing is to be carried out on behalf of a Customer, Stepstone Group UK shall take appropriate organisational and technical measures in accordance with Data Protection Legislation and in particular Article 32 UK GDPR thereof, to protect the personal data of the data subjects and their rights and freedoms, taking into account implementation costs, the state of the art, nature, scope and purpose of processing as well as the likelihood of occurrence and severity of the risk. These protective measures are recorded in the overview of technical and organisational measures, specified in Annex 1. Alternative protective measures are permitted as long as they do not fall below the protective level of the measures in Annex 1.
Data subject requests
2.3. Taking into account the nature of the processing, Stepstone Group UK will provide reasonable assistance to Customer, to enable Customer (i) to comply with its obligations pursuant to Articles 32 to 36 of the UK GDPR and (ii) to respond to requests for exercising the data subjects rights under applicable Data Protection Legislation. Notwithstanding clause 2.3 (ii) Stepstone Group UK shall not on its own authority rectify, erase or restrict the processing of data that is being processed on behalf of the Customer, but only on documented instructions from the Customer. Insofar as a data subject contacts Stepstone Group UK directly concerning a rectification, erasure, or restriction of processing, Stepstone Group UK will inform the data subject’s request to the Customer.
Cross-Border Transfer of Personal Data
2.4. Stepstone Group UK (and any subprocessors) must not transfer or otherwise process the personal data outside of the UK or the EEA without obtaining the Customer’s prior written consent.
Subprocessors
2.5. Stepstone Group UK shall be entitled to engage subprocessors identified in the Recruiter Privacy Policy or as otherwise agreed to process personal data, and Customer hereby authorises such appointments provided that:
2.5.1 Stepstone Group UK shall ensure that a written contract exists between Stepstone Group UK and the subprocessor containing clauses reasonably equivalent to those imposed on Stepstone Group UK in this Agreement.
2.5.2 Stepstone Group UK shall inform Customer if it intends to replace or engage additional subprocessors.
Term and Termination
2.6. The Agreement will remain in full force and effect so long as the Contract remains in effect.
2.7. Any provision of this Agreement that expressly or by implication should come into or continue in force on or after termination of the Contract in order to protect the personal data will remain in full force and effect.
Data Return and Destruction
2.9 On termination of the Contract for any reason or expiry of its term, Stepstone Group UK will securely delete or destroy or, if directed in writing by the Customer, return and not retain, all or any of the personal data related to this Agreement in its possession or control unless applicable law requires storage of the personal data.
Audit
2.10 Stepstone Group UK will permit the Customer and Customer’s representatives to audit Stepstone Group UK’s compliance with its Agreement obligations, on at least sixty (60) days’ notice during the Term defined in the Order Form. Stepstone Group UK will give the Customer and Customer’s representatives all reasonable assistance to conduct such audits (including inspections).
2.11 Both parties shall warrant and represent that:
2.11.1. its employees, agents, and any other person or persons accessing the Personal Data on its behalf have committed themselves to confidentiality obligations are reliable and trustworthy and have received the required training on the Data Protection Legislation;
2.11.2. it and anyone operating on its behalf will process the Personal Data in compliance with the Data Protection Legislation and other laws, enactments, regulations, orders, standards, and other similar instruments;
2.11.3. it has no reason to believe that the Data Protection Legislation prevents it from providing any of the Contract and/or services; and
2.11.4. considering the current technology environment and implementation costs, it will take appropriate technical and organisational measures to prevent the accidental, unauthorised or unlawful processing of Personal Data and the loss or damage to the Personal Data, and ensure a level of security appropriate to:
(a) the harm that might result from such accidental, unauthorised, or unlawful processing and loss or damage;
(b) the nature of the Personal Data protected; and
(c) comply with all applicable Data Protection Legislation and its information and security policies, including the security measures required in Annex 1.
Annex 1
SECURITY MEASURES
Processor to insert description of its technical and organisational data security measures such as:
During the past decade, Stepstone Group UK has enforced the security of its websites and databases with the help of technical and organizational measures.
Regarding UK GDPR, these security measures can be considered as appropriate for the protection of Stepstone Group UK’s customers, candidates and employees’ personal data.
Physical Access Controls
- All Stepstone Group UK buildings are equipped with an alarm system, activated when the building is not occupied (nights & weekends), with motion detectors placed all around.
- Each Stepstone Group UK employee must have a badge to be able to enter the building.
- Stepstone Group UK uses ISO27001 certified datacenters for the hosting of some applications. These datacenters are compliant with ISO27001 regarding physical security.
Perimeter Security
- For its websites, Stepstone Group UK uses Akamai as Content Delivery Network, which acts as a proxy between the clients and the servers, caches the websites’ static content, and protects them behind a Web Application Firewall (WAF). The WAF inspects each request sent to the website and blocks or monitors it if it is not compliant with the WAF policy.
- Stepstone Group UK uses a Next Generation Firewall that not only does packet filtering (like a traditional firewall), but also has an Intrusion Prevention System (IPS), antivirus, antibot and is identity access based.
- Akamai offers also a DDOS Protection for Stepstone Group UK’ websites. DDOS, or Distributed Denial Of Services, is a type of attack where an attacker floods a website with an enormous amount of traffic, rendering the website unusable for the rest of the users.
- Stepstone Group UK services are also protected with a bot detection device. A bot is a software application that runs automated tasks, faster than a human. Some of these bots may conduct malicious activities, like sending SPAM emails, viruses or DDOS attacks.
Network Security
- Access to the network is identity based. It means that for each access to the network, Stepstone Group UK can identify the human behind it.
- At Stepstone Group UK also uses a Security Incident and Event Management (SIEM) solution. It helps Stepstone Group UK to identify anything that happens on its information systems, reports it in a readable format, and understand if it is legitimate or not.
- Log correlation helps Stepstone Group UK to identify and regroup events that have a common source (a hacker entering the network, then some folders were deleted…), and report alerts if necessary.
- In Stepstone Group UK, IT Environments are segregated (Development, Test, Q&A, Production). New functionalities are thoroughly tested before being pushed to production, to reduce the risks of compromising the production environment’s integrity or availability.
Host Security
- Operating systems of Stepstone Group UK’ employees’ laptops are automatically patched with critical updates once a week.
- Each laptop is equipped with anti-virus/malware.
- Laptop’s hard drives are fully encrypted. USB key must be encrypted before use.
Data Access Controls
- Stepstone Group UK uses an Identity and Access Management system (IAM), ensuring that the right individual accesses the right resource, at the right time and for the right reasons.
- Private data, like personal data (sensitive or not) are always encrypted.
- Stepstone Group UK relies on the need-to-know principle, meaning that restricted access is the norm. No one has access to everything but rather access to only what he/she needs to have access to, to perform his/her job duties.
- Access to any of Stepstone Group UK’ systems are logged and monitored.
Application Security
- Communications between the client and the application server are mandatorily encrypted with Secure Sockets Layer (SSL), it ensures that the server is authenticated, as well as the confidentiality and integrity of exchanged data between the server and its client.
- Stepstone Group UK’ applications are hardened, meaning that vulnerabilities are regularly being scanned and fixed, data are encrypted in transit and at rest, unused server ports are closed, access to the systems are restricted through authentication and authorization processes.
- Penetration tests are regularly being conducted on Stepstone Group UK’ application, to simulate a hacker attack on the system, and find application flaws that are fixed afterwards.
Policies, Procedures & Awareness
- Although Stepstone Group UK is not ISO 27001 certified and does not currently intend to be, we have established a set of security policies, guidelines, and procedures inspired by ISO 27002 security domains and controls: information security policy, access control policy, backup policy, incident management policy and procedure, etc. These policies are approved by the management, communicated to the appropriate audiences and reviewed regularly.
- Based on these policies, Stepstone Group UK assesses regularly the level of compliance of each entity within the group.
- Regular awareness e-learning sessions are sent to all personnel with mandatory attendance.
Personally Identifiable Information
- Stepstone Group UK implemented necessary controls around Identity and Access Management (IAM), ensuring that the right individual accesses the right resource, at the right time and for the right reasons.
- Private data, like personal data (sensitive or not) is always encrypted.
- The Stepstone Group relies on the need-to-know principle, meaning that restricted access is the norm. No one has access to everything but rather access to only what he/she needs to have access to, to perform his/her job duties.
- Every access to any of The Stepstone Group’s system is logged and monitored.