When you submit your application, the following privacy notice applies:
Your data is being collected by The Dudley Group NHS Foundation Trust, whose privacy notice can be found here.
The data controller for this information is The Dudley Group NHS Foundation Trust. This application tracking system is provided by Civica UK Ltd (https://www.civica.com/en-gb/product-pages/trac/) as a data processor.
To make an enquiry, a request for your personal information held as part of this process, or to arrange for any mistakes to be corrected, you may contact either the team who are handling your application or the Data Protection Officer ([email protected]).
The Dudley Group NHS Foundation Trust - TRAC’s Privacy Notice
This privacy notice is issued in accordance with UK Data Protection Legislation, including the Data Protection Act 2018, the UK General Data Protection Regulation (UK GDPR) and the Data (Use and Access) Act 2025 (DUAA). It explains how the Trust uses (“processes”) personal data collected from job applicants and employees through the TRAC recruitment system.
This notice is for transparency purposes. It does not form part of your employment contract and may be updated periodically.
Personal data means any information relating to an identified or identifiable person.
Special Category data (“sensitive information”) includes information about:
- the racial or ethnic origin
- political opinions,
- religious or philosophical beliefs,
- trade union membership,
- physical or mental health,
- sexual orientation,
- genetic data; and
- biometric data used for identification,
- any criminal offence e.g. the commission or alleged commission of any offence,
- any proceedings for any offence committed or alleged to have been committed by them, the disposal of such proceedings or the sentence of any court in such proceedings.
Data Controller and Data Processor:
The Dudley Group NHS Foundation Trust (“the Trust”) is the Data Controller for personal data processed through the TRAC recruitment system.
Civica UK Ltd. (TRAC owners) act as the Data Processor on behalf of the Trust and processes data only under the Trusts instructions.
For any concerns regarding how Trust handles your personal data, you can contact Trusts Data Protection Officer at: [email protected]
The kind of information we hold about you.
We will collect, store and use a range of personal data about applicants and employees which may include:
· contact details (e.g. name, title, addresses, telephone numbers and personal email addresses)
· Date of birth and gender
· National Insurance number
· Marital status and dependant’s details
· Next of kin and emergency contact information
· Recruitment information (including copies of formal identification documents including right to work documentation, references and other information included in a CV or cover letter or as part of the application process)
· Employment records (including job titles, work history, working hours, training records and professional memberships)
· Location of employment or workplace
· Performance information
· Disciplinary and grievance information
· Bank account details, payroll, pension records and tax status information (for appointed staff)
· Photographs (where provided)
· CCTV footage and other information obtained through electronic means such as swipe card records
· Salary, annual leave, pension and benefits information
We may also process special category data such as:
· ethnicity, religion, sexual orientation (for monitoring purposes)
· health information, including occupational health assessments
· biometric or genetic data (where applicable only)
· criminal conviction or DBS information
Some administrative processes may be supported by AI‑enabled features and digital tools to assist us with the recruitment activity. However, these tools are always subject to human review and do not make any decisions about applicants or applications.
Legal basis for purpose of processing the data
It is necessary for us to process your personal data for both recruitment and employment purposes including:
1. We will need the information in order to identify the individual for the purposes of recruitment.
2. We will need to maintain that information for the general purposes of the ongoing employment relationship including performing the employment contract and maintaining the health and safety of individuals on our premises.
There are some specific situations in which we will use your personal data to make decisions about your recruitment or appointment determining the terms on which you work for us; Examples include –
· checking you are legally entitled to work in the UK;
· salary information;
· business management and planning, assessing qualifications for a particular job or task, including decisions about promotions;
· gathering evidence of possible grievance or disciplinary hearings;
· making decisions about your continued employment or engagement;
· making arrangements for the termination of our working relationship; education, training and development requirements;
· dealing with legal disputes involving you, or other employees, workers and contractors, including accidents at work; ascertaining your fitness to work;
· managing sickness absence; complying with health and safety obligations;
· to prevent fraud and equal opportunities monitoring.
The Dudley Group gained Foundation Trust status in 2008, and all staff employed directly by the Trust will automatically become a member of the Trust. Any staff who prefer not to be members have the right to opt-out and should contact the Foundation Trust office by calling 01384 321124 or emailing [email protected]. Consent can be withdrawn at any time.
Personal information, including your name, address and staff group will NOT be shared with anyone else outside of The Trust, other than those with legitimate statutory function e.g. The Returning Officer for Council of Governors elections, the following condition for lawful processing will apply for the performance of a task carried out in the public interest or in the exercise of official authority.
Our legal basis for processing personal data of applicants and staff is that:
1. Processing the personal data is necessary for the purpose of carrying out the employment contract or to take steps to enter into an employment contract.
2. Processing is necessary to comply with a legal obligation (for example we are obliged under employment law to include in a written statement of employment terms the identity of the parties to the employment contract; and to ensure your health and safety); and/or
3. Processing the data is necessary for the purposes of our “legitimate interests” as the data controller (except where such interests are overridden by the interests, rights or freedoms of the individual).
Our “legitimate interests” for these purposes are:
1. the need to process data on applicants and staff for the purposes of assessing suitability for employment and then carrying out the employment contract.
2. the need to gather data for the purposes of safeguarding the health and safety of job applicants and employees.
3. the need to transfer employee data intra-group for administrative purposes; and
There is no strict statutory or contractual requirement for you to provide data to us but if you do not provide at least that data that is necessary for us to assess suitability for employment and then to conduct the employment relationship then it will not practically be possible for us to employ you.
Some administrative processes may be supported by AI enabled features and use of digital tools to support recruitment activity. However, these tools are subject to human review and do not make an decisions about applicants or applications.
Recipients of personal data
Your personal data may be received by the following categories of people:
1. Our HR and relevant internal departments.
2. In the case of job applicants, the interviewer and prospective manager.
3. Any individual authorised by us to maintain personnel files.
4. Our professional advisers
5. Insurance companies and any other third party necessary to comply with any legal disclosure; and
6. Appropriate external regulators and authorities (such as NMC, HMRC, DHSC, HSE etc.)
We will not:
· share your identifiable data with third parties for marketing purposes
· sell your identifiable data
Where we are required to transfer identifiable information about you internationally outside the UK/EU, we will make sure that an adequate level of protection is to be satisfied before the transfer.
Duration of storage of personal data
We will retain your personal data for no longer than is strictly necessary having regard to the original purpose for which the data was processed in line with NHS Records Management Code of Practice.
Your rights in relation to your personal data
- The Right to Be Informed
You have the right to be informed about how and why your personal data is collected and used. This includes the purposes of processing, the lawful basis, who data is shared with and how long it is kept. This information is provided through the privacy notices such as this one.
2. The Right of Access
You have the right to request access to the personal data we hold about you. This is known as a “Subject Access Request”. The Trust must respond within one month and may need to verify your identity before releasing information.
3. The right to rectification
You have the right to request correction of inaccurate or incomplete personal data. We may need to verify the accuracy of new information before making changes.
4. The Right to Erasure (“Right to be Forgotten”)
You have the right to request that your personal data is deleted if:
· it is no longer necessary for us to store that data having regard to the purposes for which it was originally collected; or
· in circumstances where we rely solely on your consent to process the data (and have no other legal basis for processing the data), you withdraw your consent to the data being processed; or
· you object to the processing of the data for good reasons which are not overridden by another compelling reason for us to retain the data; or
· the data was unlawfully processed; or
· the data needs to be deleted to comply with a legal obligation.
However, we can refuse to comply with a request to delete your personal data where we process that data:
· to exercise the right of freedom of expression and information;
· to comply with a legal obligation or the performance of a public interest task or exercise of official authority;
· for public health purposes in the public interest;
· for archiving purposes in the public interest, scientific research, historical research or statistical purposes; or to exercise or defence of legal claims.
5. The right to restrict processing
You can request that we limit the way your personal data is used in certain circumstances for e.g. if you contest its accuracy or object to processing. Restriction is usually temporary while issues are investigated.
6. The right to data portability
You have the right to receive the personal data which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided (us) where:
· the processing is based on consent or on a contract; and
· the processing is carried out by automated means.
Note that this right only applies if the processing is carried out by “automated means” which means it will not apply to most paper-based data.
7. The Right to Object
You may object to processing carried out under the lawful basis of public task or legitimate interests. We may stop processing unless we can demonstrate compelling legitimate grounds that override your interests or the processing is required for legal claims.
8. Rights related to automated decision making and profiling
You have the right not to be subject to a decision based solely on automated processing that has legal or significant effects on you.
This right does not apply where the decision is necessary for a contract, authorised by law or based on your explicit consent. The Trust does not make recruitment or employment decisions based solely on automated processing within TRAC.
The Right to withdraw your consent:
Where we rely on consent as the lawful basis for processing, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing already carried out.
You can refer to the Trusts detailed privacy notice for staff here.
Complaints
If you have any questions or concerns regarding how your data is being processed, please contact Trusts Data Protection Officer.
Data Protection Officer
Information Governance Team
South Block, 2nd Floor,
Russells Hall Hospital,
Pensnett Road,
Dudley, West Midlands
DY1 2HQ
Telephone: 01384 456 111 Ext: 1208
Email: [email protected]
If you are dissatisfied the way the Trust handles your personal information you can complaint to the UK’s Supervisory authority (ICO) - Information Commissioner’s office using the details below:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire, SK9 5AF
Telephone: 0303 123 1113 (local rate)
Telephone: 01625 545 745 (national rate)
Fax: 01625 524 510
Email: [email protected]
This privacy notice may change from time to time. It was last updated in December 2025.