Policy Classification: Public
Document Type: Corporate Data Privacy and Protection Policy
Applicability: Candidates, Data Subjects, Clients, Authorized Users, Employees, Contractors, Service Providers, Verification Partners, and Business Partners
Policy Owner: Data Privacy, Protection, and Security Office
Approving Authority: Circa Logica Group Management
Version: 3.2
Effective Date: 1 October 2019
Last Review Date: 6 January 2026
1. POLICY STATEMENT
Talentprobe Due Diligence (“Talentprobe”) is a background screening, verification, and due diligence service operated by Circa Logica Group (“CLG” or the “Group”).
The nature of Talentprobe’s services requires the responsible processing of personal information concerning candidates, applicants, employees, former employees, professionals, client representatives, references, and other individuals. Talentprobe recognizes that the information entrusted to it may be private, confidential, sensitive, or capable of materially affecting an individual if handled inaccurately or inappropriately.
Privacy and data protection are therefore fundamental components of Talentprobe’s operating standards.
Talentprobe is committed to processing personal data lawfully, fairly, transparently, proportionately, accurately, securely, and only for legitimate and authorized purposes. Talentprobe shall implement reasonable and appropriate organizational, physical, and technical measures designed to protect personal data throughout its lifecycle.
Talentprobe further recognizes that responsible background screening requires more than compliance with minimum legal requirements. It requires appropriate controls over what information is collected, why it is collected, who may access it, how it is verified, how it is protected, how long it is retained, to whom it may be disclosed, and how individuals may exercise their rights concerning their information.
This Policy establishes the overarching privacy and personal data protection framework of Talentprobe.
PART I
GENERAL PRIVACY FRAMEWORK
2. PURPOSE
The purpose of this Policy is to establish and communicate Talentprobe’s standards for the responsible processing and protection of personal data.
Specifically, this Policy is intended to:
a. establish the principles governing Talentprobe’s processing of personal data;
b. explain the nature and categories of personal data Talentprobe may process;
c. describe the purposes for which personal data may be collected, accessed, used, verified, stored, disclosed, transferred, or otherwise processed;
d. identify the principal sources from which information may be obtained;
e. establish the circumstances under which information may be disclosed to clients, service providers, verification sources, regulators, government authorities, and other authorized recipients;
f. explain the rights available to data subjects and the mechanisms through which such rights may be exercised;
g. establish standards concerning consent, authorization, confidentiality, security, data minimization, accuracy, retention, and accountability;
h. describe Talentprobe’s approach to third-party processing and cross-border data processing;
i. establish the relationship between Talentprobe, Circa Logica Group, its clients, candidates, and authorized third parties with respect to privacy responsibilities;
j. provide clients, candidates, procurement teams, compliance teams, auditors, regulators, and other stakeholders with a clear statement of Talentprobe’s privacy commitments; and
k. establish the foundation upon which Talentprobe’s more specific privacy, information security, retention, quality assurance, and candidate rights policies operate.
3. REGULATORY FRAMEWORK
Talentprobe shall process personal data in accordance with applicable privacy and data protection requirements.
For processing activities subject to Philippine law, this includes, without limitation:
a. Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012;
b. the Implementing Rules and Regulations of the Data Privacy Act of 2012;
c. applicable circulars, advisories, orders, decisions, and other issuances of the National Privacy Commission;
d. other Philippine laws and regulations applicable to the collection, use, disclosure, security, retention, and processing of information; and
e. applicable contractual privacy and data protection obligations.
Talentprobe may provide services to clients or process information involving individuals located outside the Philippines. Where a processing activity is subject to the privacy or data protection requirements of another jurisdiction, Talentprobe shall take reasonable measures to comply with requirements applicable to its role and processing activities.
Talentprobe does not represent that every privacy or data protection law in every jurisdiction automatically applies to all Talentprobe services. Applicability shall depend upon the relevant processing activity, jurisdiction, contractual arrangement, data subject, client relationship, and other relevant circumstances.
4. RELATIONSHIP WITH CIRCA LOGICA GROUP
Talentprobe operates under Circa Logica Group and follows the Group’s broader commitment to privacy, confidentiality, responsible information management, and appropriate data protection.
The Group and Talentprobe may maintain common or coordinated privacy governance functions, including the Data Privacy, Protection, and Security Office, compliance oversight, information security controls, technology infrastructure, administrative systems, legal and regulatory compliance, and shared corporate services.
Where Group systems or shared services process personal data relating to Talentprobe operations, access shall remain subject to appropriate authorization, confidentiality, security, and legitimate business requirements.
Talentprobe may establish privacy standards that are more specific or restrictive than general Group policies because of the nature and sensitivity of background screening and due diligence activities.
Where a Talentprobe-specific privacy requirement conflicts with a general Group practice, the requirement providing the appropriate level of protection for the relevant processing activity shall be applied, subject to applicable law and contractual obligations.
5. SCOPE
This Policy applies to personal data processed by Talentprobe in connection with its services and operations, whether such information is:
a. collected directly from an individual;
b. supplied by a client;
c. obtained from an authorized third party;
d. received from an employer, educational institution, reference, professional organization, government agency, court, regulator, or verification source;
e. obtained from a lawfully accessible public record or database;
f. generated during Talentprobe’s verification activities;
g. submitted through Talentprobe’s websites, platforms, portals, forms, applications, or communication channels;
h. maintained in electronic or physical form; or
i. otherwise processed in connection with Talentprobe’s legitimate operations.
This Policy applies to Talentprobe personnel, authorized representatives, contractors, and other persons acting under Talentprobe’s authority who process personal data.
6. PERSONS COVERED
Depending upon the relevant service or processing activity, this Policy may apply to personal data relating to:
a. employment candidates and applicants;
b. employees and former employees undergoing authorized screening;
c. contractors, consultants, freelancers, and other workers;
d. directors, officers, beneficial owners, vendors, suppliers, or business persons subject to authorized due diligence;
e. client representatives and authorized users;
f. professional and employment references;
g. character references;
h. representatives of current or former employers;
i. representatives of educational institutions;
j. representatives of professional, licensing, or regulatory organizations;
k. suppliers, contractors, verification partners, and service providers;
l. visitors to Talentprobe websites and online services;
m. individuals communicating with Talentprobe; and
n. other individuals whose personal data is lawfully and legitimately processed in connection with Talentprobe’s services.
PART II
DATA PROTECTION PRINCIPLES
7. TRANSPARENCY
Talentprobe shall take reasonable measures to ensure that individuals are appropriately informed about relevant processing of their personal data.
Information concerning processing should be communicated in reasonably accessible and understandable language and should provide sufficient information for the individual to understand the nature, purpose, and extent of relevant processing.
Where appropriate, Talentprobe may provide privacy information through this Policy, candidate consent and authorization forms, specific privacy notices, client documentation, platform notices, website notices, or other appropriate means.
8. LEGITIMATE PURPOSE
Talentprobe shall collect and process personal data only for specified, legitimate, lawful, and authorized purposes.
Information obtained for background screening shall not knowingly be used by Talentprobe for unrelated purposes incompatible with the purpose for which it was obtained unless another lawful basis exists.
Talentprobe shall not knowingly conduct a screening activity for an unlawful purpose.
9. PROPORTIONALITY AND DATA MINIMIZATION
Talentprobe shall seek to ensure that personal data processed is adequate, relevant, suitable, and not excessive in relation to the purpose of the processing.
The availability of a particular screening capability does not mean that the check should be performed on every candidate.
The scope of screening should reflect the service requested, authorized purpose, applicable legal requirements, contractual arrangement, and where appropriate, the relevance of the information to the position, engagement, transaction, or risk being evaluated.
Talentprobe reserves the right to decline a requested processing activity that it reasonably believes is unlawful, disproportionate, unauthorized, or inconsistent with applicable privacy requirements.
10. FAIRNESS
Personal data shall be processed in a manner that respects applicable rights and reasonable expectations of data subjects.
Talentprobe shall seek to avoid processing practices that are deceptive, misleading, discriminatory, unnecessarily intrusive, or inconsistent with the authorized purpose of the screening.
Information shall not knowingly be presented in a manner that materially misrepresents the underlying verified findings.
11. ACCURACY AND DATA QUALITY
Talentprobe recognizes that data accuracy is particularly important in background screening.
Reasonable measures shall be maintained to support the accuracy, completeness, relevance, and appropriate attribution of information contained in screening reports.
Where information is materially inaccurate, incomplete, outdated, or attributed to the wrong individual, Talentprobe shall take appropriate corrective action in accordance with applicable policies and procedures.
Talentprobe’s detailed standards concerning source verification, quality assurance, report accuracy, corrections, and amendments are governed by its Background Screening Quality and Accuracy Policy.
12. CONFIDENTIALITY
Personal data obtained through Talentprobe’s services shall be treated as confidential except where disclosure is authorized, necessary for the relevant service, permitted or required by law, or otherwise supported by an appropriate legal basis.
Personnel and authorized representatives who access personal data shall be subject to confidentiality requirements appropriate to their functions.
Confidentiality obligations may continue after termination of employment, engagement, assignment, or contractual relationship.
13. ACCOUNTABILITY
Talentprobe recognizes that accountability for privacy requires documented governance rather than reliance solely on individual discretion.
Talentprobe shall maintain appropriate policies, responsibilities, records, controls, training, contractual safeguards, risk management practices, and oversight mechanisms proportionate to its processing activities.
PART III
TALENTPROBE’S ROLE IN DATA PROCESSING
14. PERSONAL INFORMATION PROCESSOR
In many client engagements, Talentprobe performs background screening on behalf of a client based on the client’s authorized instructions.
In such circumstances, Talentprobe may act as a Personal Information Processor, while the client acts as the Personal Information Controller.
When acting as a processor, Talentprobe shall process personal data in accordance with applicable law, documented client instructions, contractual requirements, and applicable Data Processing Agreements.
15. PERSONAL INFORMATION CONTROLLER
Talentprobe or Circa Logica Group may act as a Personal Information Controller where it independently determines the purpose and means of a processing activity.
This may include, where applicable, processing undertaken for:
a. Talentprobe account administration;
b. regulatory compliance;
c. corporate recordkeeping;
d. information security;
e. fraud prevention;
f. legal claims and dispute management;
g. compliance monitoring;
h. service improvement;
i. internal quality assurance;
j. website administration;
k. business communications; or
l. other legitimate corporate purposes.
The precise role of Talentprobe shall be determined by the nature of the relevant processing activity rather than solely by the description of the overall commercial relationship.
16. CLIENT AND TALENTPROBE RESPONSIBILITIES
Where a client determines the purpose and scope of screening, the client remains responsible for ensuring that its instructions to Talentprobe are lawful.
Clients are expected to:
a. have an appropriate lawful basis for requesting screening;
b. provide required notices;
c. obtain consent or authorization where required;
d. request only appropriate and lawful checks;
e. protect reports received from Talentprobe;
f. limit report access to authorized personnel;
g. use screening information only for legitimate purposes;
h. comply with applicable employment, labor, privacy, anti-discrimination, and other laws; and
i. make their own employment or business decisions.
Talentprobe shall not assume responsibility for a client’s independent use of information after lawful delivery of the report except to the extent otherwise required by law or binding contract.
PART IV
INFORMATION TALENTPROBE MAY PROCESS
17. IDENTITY INFORMATION
Talentprobe may process information necessary to establish, distinguish, or verify identity, including:
a. full legal name;
b. former names or aliases where relevant;
c. date of birth;
d. nationality or citizenship information where relevant and legally permissible;
e. photograph;
f. signature;
g. current or previous address;
h. contact information;
i. government-issued identification information; and
j. other identity attributes reasonably required to prevent mistaken identity or properly conduct an authorized verification.
18. EMPLOYMENT INFORMATION
Talentprobe may process information concerning:
a. current and previous employers;
b. positions and job titles;
c. dates of employment;
d. employment status;
e. responsibilities;
f. employment history;
g. reason for separation where lawfully obtainable and relevant;
h. eligibility for rehire where appropriately provided;
i. employment references; and
j. other information necessary to perform an authorized employment verification.
19. EDUCATIONAL AND PROFESSIONAL INFORMATION
Talentprobe may process information including:
a. schools and educational institutions attended;
b. dates of attendance;
c. qualifications;
d. degrees;
e. diplomas;
f. academic credentials;
g. professional certifications;
h. professional licenses;
i. regulatory registrations;
j. memberships; and
k. other credentials relevant to the authorized verification.
20. REFERENCE INFORMATION
Where included within the authorized scope, Talentprobe may contact professional, employment, character, or other references.
Information may include the identity and contact details of the reference, relationship to the candidate, observations relevant to the authorized inquiry, and information reasonably necessary to document the verification.
Talentprobe shall seek to limit reference inquiries to legitimate screening purposes.
21. COURT, REGULATORY, SANCTIONS, AND PUBLIC RECORD INFORMATION
Where authorized and legally permissible, Talentprobe may process information obtained from:
a. courts and tribunals;
b. government agencies;
c. regulatory authorities;
d. professional registries;
e. sanctions databases;
f. watchlists;
g. procurement or compliance databases;
h. other official records; and
i. lawfully accessible public sources.
The existence of information in a source shall not automatically constitute a finding of wrongdoing.
Talentprobe shall seek to report information according to the nature and status of the underlying source and shall avoid knowingly representing an allegation, pending matter, unresolved record, or identity match as a final adverse determination where such characterization would be inaccurate.
22. FINANCIAL AND CREDIT-RELATED INFORMATION
Where relevant to an authorized screening purpose and permitted by applicable law, Talentprobe may process financial or credit-related information.
Such checks should be requested only where appropriate to the legitimate purpose of the screening and supported by an appropriate legal basis or authorization.
23. TECHNICAL AND PLATFORM INFORMATION
When individuals access Talentprobe websites, platforms, portals, forms, or other digital services, Talentprobe may process technical information including:
a. IP address;
b. browser type;
c. operating system;
d. device information;
e. date and time of access;
f. login and authentication information;
g. platform activity;
h. upload and download activity;
i. security events;
j. system logs; and
k. other technical information necessary for operation, security, fraud prevention, troubleshooting, analytics, and service improvement.
This reflects the broader Circa Logica Group practice of collecting limited technical and usage information necessary to operate, secure, understand, and improve its digital services.
24. SENSITIVE PERSONAL INFORMATION
Certain Talentprobe services may require the processing of sensitive personal information.
Talentprobe shall process sensitive personal information only where such processing is lawful, relevant, necessary, appropriately authorized, and supported by an applicable legal basis.
Access to sensitive personal information shall be restricted according to business need and appropriate access controls.
Talentprobe shall not intentionally collect sensitive personal information merely because it is available.
25. INFORMATION TALENTPROBE DOES NOT REQUIRE
Talentprobe seeks to avoid collecting information that is unnecessary for the authorized service.
Candidates should not submit passwords, authentication credentials, financial account passwords, or other information that Talentprobe has not specifically requested.
Talentprobe does not require candidates to disclose account passwords for personal social media, email, or similar private services as a general condition of background screening.
Payment card information, where applicable to a transaction, may be processed through authorized payment service providers rather than directly stored by Talentprobe, subject to the applicable payment arrangement.
PART V
SOURCES OF INFORMATION
26. DIRECT COLLECTION
Talentprobe may obtain information directly from the data subject through:
a. candidate forms;
b. authorization documents;
c. platform submissions;
d. uploaded supporting documents;
e. email communications;
f. telephone or video communications;
g. dispute or correction submissions; and
h. other authorized interactions.
27. CLIENT-PROVIDED INFORMATION
Clients may provide Talentprobe with information necessary to initiate, identify, administer, or complete a screening request.
Clients are responsible for ensuring that information provided to Talentprobe has been lawfully collected and may lawfully be disclosed for the intended purpose.
28. THIRD-PARTY VERIFICATION SOURCES
Talentprobe may obtain information from appropriate third-party sources including:
a. employers;
b. educational institutions;
c. professional organizations;
d. licensing bodies;
e. references;
f. government agencies;
g. courts;
h. regulators;
i. authorized databases;
j. verification providers; and
k. other legitimate sources.
29. PUBLICLY AVAILABLE INFORMATION
Where relevant, lawful, proportionate, and within the authorized scope of a service, Talentprobe may review information lawfully available to the public.
The fact that information is publicly accessible does not automatically mean that Talentprobe will collect, retain, or report it.
Talentprobe shall consider the authorized purpose, relevance, applicable law, source reliability, and potential for mistaken identity or misinterpretation.
PART VI
PURPOSES AND LEGAL BASIS
30. BACKGROUND SCREENING AND VERIFICATION
Personal data may be processed to:
a. establish identity;
b. verify information supplied by a candidate;
c. verify employment;
d. verify education;
e. verify professional credentials;
f. conduct reference checks;
g. conduct authorized court or public record searches;
h. perform compliance-related checks;
i. conduct other authorized due diligence; and
j. prepare and deliver screening findings to authorized recipients.
31. SERVICE ADMINISTRATION
Personal data may also be processed to:
a. establish and administer client accounts;
b. authenticate users;
c. manage screening requests;
d. communicate case status;
e. provide customer support;
f. manage billing and commercial relationships;
g. maintain transaction and audit records;
h. respond to inquiries; and
i. administer contractual relationships.
32. COMPLIANCE, SECURITY, AND RISK MANAGEMENT
Talentprobe may process information where necessary to:
a. comply with legal obligations;
b. respond to lawful regulatory requests;
c. prevent or investigate fraud;
d. protect Talentprobe systems;
e. investigate suspected misuse;
f. maintain security logs;
g. manage disputes;
h. establish or defend legal claims;
i. conduct audits;
j. conduct quality assurance; and
k. manage operational and compliance risk.
33. LAWFUL BASIS
Talentprobe shall process personal data only where an appropriate lawful basis exists.
Depending upon the circumstances, such basis may include:
a. consent;
b. performance of a contract;
c. steps necessary prior to entering into a contract;
d. compliance with a legal obligation;
e. protection of lawful rights and interests;
f. legitimate interests recognized by applicable law;
g. establishment, exercise, or defense of legal claims;
h. processing expressly authorized by law; or
i. another basis permitted under applicable law.
Talentprobe shall not assume that consent is the only possible legal basis for every processing activity.
PART VII
CONSENT AND AUTHORIZATION
34. CANDIDATE AUTHORIZATION
Where consent or authorization is required, Talentprobe shall obtain or require evidence of appropriate authorization before performing the relevant screening activity.
Authorization may be obtained electronically, digitally, physically, or through another legally recognized mechanism.
The authorization process should provide sufficient information for the candidate to understand the nature and purpose of the screening.
35. WITHDRAWAL OF CONSENT
Where processing relies upon consent, a data subject may withdraw that consent subject to applicable law.
Withdrawal shall not necessarily affect processing that:
a. occurred lawfully before withdrawal;
b. is required by law;
c. is necessary for legal claims;
d. is supported by another lawful basis; or
e. must be retained in accordance with applicable legal or contractual requirements.
Where withdrawal prevents Talentprobe from completing an authorized service, Talentprobe may inform the relevant client that the verification could not be completed, without unnecessarily disclosing the reason where such disclosure would be inappropriate.
PART VIII
WEBSITE, COOKIES, ANALYTICS, AND COMMUNICATIONS
36. WEBSITE INFORMATION
When an individual visits a Talentprobe or applicable Circa Logica Group website, certain technical information may be collected automatically.
This may include IP address, browser information, device information, referring page, pages accessed, duration of visits, navigation activity, and other information concerning use of the website.
Such information may be used for:
a. website operation;
b. security;
c. performance monitoring;
d. analytics;
e. troubleshooting;
f. service improvement;
g. fraud or abuse prevention; and
h. understanding how users interact with Talentprobe services.
37. COOKIES AND SIMILAR TECHNOLOGIES
Talentprobe websites may use cookies and similar technologies.
Cookies may support:
a. session management;
b. authentication;
c. security;
d. user preferences;
e. website functionality;
f. analytics; and
g. other legitimate website purposes.
Where required by applicable law, users shall be provided with appropriate notice or choices regarding non-essential cookies.
Users may also be able to manage cookies through their browser settings. Restricting certain cookies may affect the availability or functionality of portions of the website or platform.
38. ANALYTICS
Talentprobe or Circa Logica Group may use reputable analytics services to understand website and platform usage.
Analytics information may include technical and interaction data such as device type, browser, approximate location derived from technical information, pages visited, navigation activity, and other usage metrics.
Analytics shall be used for legitimate operational, security, service improvement, and measurement purposes subject to applicable privacy requirements.
39. BUSINESS COMMUNICATIONS
Talentprobe may use contact information to communicate regarding:
a. screening cases;
b. account administration;
c. contractual matters;
d. customer support;
e. billing;
f. system notices;
g. privacy or security matters;
h. service changes; and
i. other operational communications.
Certain operational communications may be necessary to provide the service and therefore may continue even where an individual has opted out of promotional communications.
40. MARKETING COMMUNICATIONS
Where legally permissible, Talentprobe or Circa Logica Group may communicate information concerning relevant products, services, programs, or business developments.
Where consent is required for such communications, Talentprobe shall seek the appropriate consent.
Recipients may opt out of promotional electronic communications through the mechanism provided in the communication or through the appropriate contact channel.
Opting out of marketing communications does not necessarily prevent necessary transactional, legal, security, billing, service, or account communications.
PART IX
DISCLOSURE AND DATA SHARING
41. CLIENT DISCLOSURE
Screening information may be disclosed to the client or authorized organization that commissioned or is otherwise entitled to receive the screening service.
Access should be limited to authorized client personnel with a legitimate business purpose.
42. SERVICE PROVIDERS
Talentprobe and Circa Logica Group may use trusted third-party providers to support services including:
a. cloud infrastructure;
b. data storage;
c. communications;
d. customer support;
e. verification services;
f. analytics;
g. cybersecurity;
h. payment processing;
i. business administration; and
j. other supporting functions.
Such providers may receive access to personal data only to the extent reasonably necessary for their authorized function and shall be subject to applicable privacy, security, confidentiality, and contractual requirements.
43. VERIFICATION PARTNERS
Certain verification activities may require interaction with third-party partners, researchers, institutions, databases, or local verification sources.
Talentprobe shall seek to disclose only information reasonably necessary to perform the relevant verification.
Verification partners are expected to process information consistently with applicable law and contractual or confidentiality requirements where applicable.
44. PROFESSIONAL ADVISERS
Personal data may be disclosed where reasonably necessary to Talentprobe’s or Circa Logica Group’s legal counsel, auditors, insurers, accountants, compliance advisers, or other professional advisers subject to appropriate confidentiality requirements.
45. LEGAL AND REGULATORY DISCLOSURE
Talentprobe may disclose personal data where required or permitted by law, including in response to:
a. court orders;
b. subpoenas;
c. lawful regulatory requests;
d. government investigations;
e. legally authorized law enforcement requests; or
f. other compulsory legal processes.
Talentprobe shall seek to limit such disclosure to information reasonably required by the applicable legal process.
46. BUSINESS TRANSFERS
If Talentprobe or relevant Circa Logica Group operations undergo a merger, acquisition, restructuring, financing, sale, transfer of assets, or similar corporate transaction, personal data may form part of the relevant transferred business records where legally permissible.
Talentprobe shall take reasonable steps to ensure that applicable privacy obligations continue to be considered in connection with such a transaction.
47. NO SALE OF CANDIDATE DATA
Talentprobe does not sell candidate background screening information as a commercial data product.
Information obtained for a screening engagement shall not be sold to unrelated third parties for their independent marketing purposes.
PART X
THIRD PARTIES AND CROSS-BORDER PROCESSING
48. THIRD-PARTY DUE DILIGENCE
Talentprobe shall take reasonable measures appropriate to the nature and risk of the processing when selecting third parties that may process personal data.
Assessment may consider, as appropriate:
a. nature of services;
b. categories of information processed;
c. confidentiality;
d. security capabilities;
e. privacy commitments;
f. location of processing;
g. incident management;
h. contractual safeguards; and
i. other relevant risk factors.
49. CONTRACTUAL SAFEGUARDS
Where appropriate, contracts with service providers or processors shall establish relevant requirements concerning:
a. authorized processing;
b. confidentiality;
c. information security;
d. incident notification;
e. subcontracting;
f. return or deletion of information;
g. assistance with data subject rights;
h. audit or compliance information; and
i. applicable legal requirements.
50. CROSS-BORDER PROCESSING
Personal data may be processed, accessed, or stored in jurisdictions outside the location where it was originally collected where necessary for legitimate service delivery and legally permissible.
Cross-border processing may occur because of:
a. cloud infrastructure;
b. international clients;
c. verification sources;
d. authorized service providers;
e. regional operations; or
f. other legitimate business requirements.
Talentprobe shall maintain appropriate safeguards applicable to its role and the relevant processing arrangement.
51. CONTINUING ACCOUNTABILITY
The transfer of information to an authorized service provider or another jurisdiction does not, by itself, eliminate applicable privacy responsibilities.
Talentprobe shall maintain reasonable oversight and contractual protections appropriate to the circumstances.
PART XI
INFORMATION SECURITY AND CONFIDENTIALITY
52. SECURITY COMMITMENT
Talentprobe shall maintain reasonable and appropriate organizational, physical, and technical measures designed to preserve the confidentiality, integrity, and availability of personal data.
Controls shall be proportionate to the nature of the information, processing risks, technology environment, operational requirements, and applicable legal obligations.
53. ORGANIZATIONAL SAFEGUARDS
Organizational safeguards may include:
a. privacy and security policies;
b. assigned privacy responsibilities;
c. confidentiality obligations;
d. employee training;
e. role-based responsibilities;
f. access management;
g. incident reporting requirements;
h. risk assessments;
i. vendor management;
j. business continuity planning; and
k. periodic review of controls.
54. TECHNICAL SAFEGUARDS
Technical safeguards may include, as appropriate:
a. encryption;
b. authentication;
c. access controls;
d. network protection;
e. system monitoring;
f. logging;
g. vulnerability management;
h. malware protection;
i. backup and recovery mechanisms;
j. secure system configuration; and
k. other measures appropriate to the relevant environment.
Detailed technical controls are governed by Talentprobe’s Information Security and Data Breach Management Policy and related internal standards.
55. PHYSICAL SAFEGUARDS
Talentprobe shall implement reasonable safeguards intended to restrict unauthorized physical access to facilities, equipment, records, and work areas in which personal data is processed.
Physical records containing personal data shall be protected according to their sensitivity and legitimate business requirements.
56. ACCESS CONTROL
Access to personal data shall be based upon legitimate business need.
Personnel should receive only the level of access appropriate to their responsibilities.
Access may be modified, suspended, or terminated where:
a. job responsibilities change;
b. employment or engagement ends;
c. access is no longer required;
d. a security concern exists; or
e. Talentprobe otherwise determines that access should be restricted.
57. SECURITY LIMITATIONS
Talentprobe maintains safeguards designed to protect personal data but recognizes that no information system, network, transmission method, or storage environment can reasonably be represented as entirely free from security risk.
Talentprobe therefore applies a risk-based approach that includes prevention, detection, response, recovery, review, and continuous improvement.
PART XII
RETENTION AND DISPOSAL
58. RETENTION PRINCIPLE
Talentprobe shall retain personal data only for as long as reasonably necessary for the purpose for which it was collected or subsequently lawfully processed.
Retention shall take into consideration:
a. the original purpose;
b. contractual obligations;
c. legal and regulatory requirements;
d. potential disputes;
e. establishment, exercise, or defense of legal claims;
f. audit requirements;
g. security requirements;
h. legitimate business requirements; and
i. applicable industry standards.
59. DIFFERENT RETENTION PERIODS
Talentprobe recognizes that different records may require different retention periods.
Accordingly, retention periods may differ for:
a. candidate-provided documents;
b. identity documentation;
c. consent and authorization records;
d. verification evidence;
e. correspondence;
f. final reports;
g. dispute records;
h. quality assurance records;
i. security logs;
j. client account information;
k. billing records; and
l. contractual records.
Detailed retention periods shall be established under Talentprobe’s Data Retention and Secure Disposal Policy and applicable retention schedules.
60. LEGAL HOLDS
Information otherwise scheduled for deletion may be preserved where reasonably necessary in connection with:
a. litigation;
b. regulatory inquiry;
c. investigation;
d. dispute;
e. audit;
f. legal claim; or
g. other lawful preservation requirement.
Information subject to a valid hold shall be retained until the hold is appropriately released.
61. SECURE DISPOSAL
When personal data is no longer required and no lawful basis exists for continued retention, Talentprobe shall take reasonable measures to securely delete, destroy, anonymize, or otherwise dispose of the information in a manner intended to prevent unauthorized recovery or further processing.
PART XIII
DATA SUBJECT RIGHTS
62. RIGHT TO BE INFORMED
Data subjects have the right to receive appropriate information regarding the processing of their personal data in accordance with applicable law.
63. RIGHT OF ACCESS
Subject to applicable limitations, data subjects may request reasonable access to personal data concerning them and information regarding its processing.
Talentprobe may require appropriate verification of identity before providing access.
64. RIGHT TO RECTIFICATION
A data subject may challenge information believed to be inaccurate or incomplete and may request appropriate correction.
Background screening disputes involving substantive findings shall be handled in accordance with the Candidate Rights, Dispute and Resolution Policy.
65. RIGHT TO OBJECT
Where recognized by applicable law, a data subject may object to particular processing activities.
The effect of an objection shall depend upon the nature of the processing and the lawful basis supporting it.
66. RIGHT TO ERASURE OR BLOCKING
Where the requirements of applicable law are satisfied, a data subject may request erasure, deletion, blocking, or restriction of personal data.
This right may be limited where continued processing or retention is required or permitted by law, contract, legal claim, legitimate business requirement, or another applicable basis.
67. DATA PORTABILITY
Where applicable legal requirements are satisfied, data subjects may exercise applicable rights concerning portability of personal data maintained in an electronic and structured format.
68. WITHDRAWAL OF CONSENT
Where processing is based upon consent, the data subject may withdraw consent subject to applicable legal limitations and the consequences of withdrawal.
69. RIGHT TO COMPLAIN
Individuals may raise privacy concerns directly with Talentprobe or Circa Logica Group.
Nothing in this Policy prevents an individual from exercising any right to lodge a complaint with the National Privacy Commission or another competent authority where such right exists.
70. IDENTITY VERIFICATION FOR RIGHTS REQUESTS
Talentprobe has an obligation to protect information against unauthorized disclosure.
Accordingly, Talentprobe may require reasonable verification of identity or authority before fulfilling a data subject request.
Where a representative submits a request on behalf of another individual, Talentprobe may require evidence of the representative’s authority.
71. REQUESTS RELATING TO CLIENT-CONTROLLED INFORMATION
Where Talentprobe processes information solely on behalf of a client, Talentprobe may refer a request to the relevant client or coordinate with the client as appropriate.
Talentprobe shall provide reasonable assistance where required by applicable law or contractual obligations.
PART XIV
BACKGROUND SCREENING-SPECIFIC PRIVACY PROTECTIONS
72. PURPOSE LIMITATION IN SCREENING
Information collected for an authorized screening shall be used only for the relevant screening, associated compliance, quality, security, legal, or other compatible lawful purposes.
73. IDENTITY MATCHING
Talentprobe recognizes the risk of incorrect attribution where individuals have identical or similar names.
Where appropriate, multiple identifiers may be considered to establish reasonable confidence that a record relates to the relevant individual.
A name similarity alone should not automatically be treated as conclusive identification where additional verification is reasonably necessary.
74. CONTEXTUAL REPORTING
Where information has different possible legal or factual meanings, Talentprobe shall seek to describe the verified status of the information rather than unnecessarily characterize the individual.
Where appropriate, Talentprobe may distinguish between allegations, pending matters, final judgments, confirmed records, unresolved information, discrepancies, and information that could not be independently verified.
75. EMPLOYMENT DECISIONS
Talentprobe provides screening information and related findings.
Talentprobe does not make the client’s final hiring, employment, promotion, retention, termination, or other employment decision.
The client remains responsible for determining whether and how screening information may lawfully and appropriately be considered in its decision-making.
A Talentprobe report should not be interpreted as an instruction to hire or reject an individual unless Talentprobe has expressly agreed to provide a separate service that is lawful and specifically designed for such purpose.
76. DISPUTED INFORMATION
Candidates may raise concerns regarding potentially inaccurate, incomplete, or misattributed information.
Talentprobe shall maintain procedures for reviewing such concerns and, where warranted, conducting appropriate reinvestigation or correction.
Detailed requirements are governed by the Candidate Rights, Dispute and Resolution Policy.
PART XV
AUTOMATION, AI, AND TECHNOLOGY
77. USE OF TECHNOLOGY
Talentprobe may use technology, automation, artificial intelligence-assisted systems, data matching, workflow automation, analytics, or similar tools to support appropriate aspects of its operations.
Such technologies may support activities including:
a. document processing;
b. identity matching;
c. workflow administration;
d. quality control;
e. security monitoring;
f. fraud detection;
g. data organization;
h. research assistance; and
i. other legitimate operational functions.
78. HUMAN ACCOUNTABILITY
Use of automated or AI-assisted technology does not eliminate Talentprobe’s responsibility for appropriate privacy, accuracy, security, and accountability.
Where human review is appropriate to the nature and consequences of a finding, Talentprobe shall maintain reasonable mechanisms for such review.
79. AUTOMATED DECISION-MAKING
Talentprobe does not position its ordinary background screening reports as autonomous final employment decisions.
Where applicable law imposes specific obligations relating to automated decision-making or profiling, Talentprobe shall take reasonable measures to comply with those requirements.
PART XVI
DATA BREACHES AND INCIDENTS
80. INCIDENT MANAGEMENT
Talentprobe shall maintain processes for identifying, escalating, containing, investigating, assessing, documenting, remediating, and recovering from suspected or confirmed information security incidents.
81. PERSONAL DATA BREACH ASSESSMENT
Where an incident involves personal data, Talentprobe shall assess the circumstances to determine:
a. the nature of the information involved;
b. the individuals potentially affected;
c. the nature and extent of unauthorized access, disclosure, alteration, loss, or destruction;
d. potential consequences;
e. containment measures;
f. notification obligations; and
g. appropriate corrective measures.
82. NOTIFICATION
Where applicable law or contract requires notification of a personal data breach, Talentprobe shall undertake the required notification in accordance with applicable requirements.
Depending upon the circumstances, this may include notification to:
a. affected clients;
b. data subjects;
c. the National Privacy Commission;
d. another competent regulator; or
e. other parties required by law or contract.
Detailed requirements are governed by the Information Security and Data Breach Management Policy.
PART XVII
PRIVACY GOVERNANCE
83. DATA PRIVACY, PROTECTION, AND SECURITY OFFICE
Talentprobe operates within Circa Logica Group’s privacy governance framework.
The Data Privacy, Protection, and Security Office provides oversight and coordination for relevant privacy, data protection, and security matters.
Its responsibilities may include:
a. privacy compliance oversight;
b. policy development;
c. regulatory coordination;
d. privacy risk management;
e. data subject request oversight;
f. incident and breach coordination;
g. privacy awareness;
h. review of processing activities;
i. support for privacy assessments;
j. monitoring relevant regulatory developments; and
k. coordination with management, technology, legal, risk, and operational functions.
84. DATA PROTECTION OFFICER
Circa Logica Group shall designate a Data Protection Officer or other responsible privacy personnel as required by applicable law.
The Data Protection Officer shall have authority and responsibilities appropriate to the role and shall serve as an appropriate point of contact concerning privacy and data protection matters.
85. RECORDS OF PROCESSING ACTIVITIES
Talentprobe shall maintain appropriate documentation concerning relevant personal data processing activities where required.
Such documentation may include information concerning:
a. purposes of processing;
b. categories of data subjects;
c. categories of personal data;
d. recipients;
e. data flows;
f. retention;
g. security measures;
h. processors or subprocessors;
i. cross-border processing; and
j. responsible functions.
86. PRIVACY IMPACT AND RISK ASSESSMENTS
Talentprobe shall consider privacy and data protection risks when introducing or materially changing systems, services, technologies, processing activities, or third-party arrangements involving personal data.
Where appropriate or required, a privacy impact assessment or similar risk assessment shall be conducted.
87. PRIVACY BY DESIGN AND DEFAULT
Privacy shall be considered throughout the lifecycle of systems and processes involving personal data.
Where reasonably practicable, Talentprobe shall design processes so that only information necessary for the authorized purpose is collected, accessed, used, retained, and disclosed.
88. TRAINING AND AWARENESS
Personnel who process personal data shall receive appropriate privacy, confidentiality, information security, and responsible information-handling guidance or training appropriate to their responsibilities.
Training may be reinforced periodically and following material changes in policy, law, systems, risk, or personnel responsibilities.
89. CONFIDENTIALITY OF PERSONNEL
Personnel, contractors, and other authorized persons with access to personal data shall be subject to appropriate confidentiality obligations.
Unauthorized access, disclosure, copying, extraction, modification, use, or distribution of personal data may result in disciplinary action, termination of access, contractual remedies, or other appropriate action.
PART XVIII
COMPLAINTS, QUESTIONS, AND REQUESTS
90. PRIVACY COMPLAINTS
Talentprobe takes complaints concerning personal data seriously.
A complaint may concern, among other matters:
a. unauthorized processing;
b. inappropriate disclosure;
c. inaccurate personal data;
d. inability to exercise a privacy right;
e. suspected misuse;
f. excessive collection;
g. security concerns; or
h. other alleged failures to comply with applicable privacy requirements.
Talentprobe shall acknowledge, assess, investigate, and address complaints in accordance with applicable procedures and legal requirements.
91. CORRECTION AND UPDATE REQUESTS
Individuals who believe personal data maintained by Talentprobe is inaccurate or incomplete may request correction through Talentprobe’s designated channels.
Talentprobe may request supporting documentation where reasonably necessary to evaluate the requested correction.
Corrections affecting a background screening finding may require reinvestigation or verification before an amended report is issued.
92. MARKETING OPT-OUT
Individuals may opt out of promotional communications through the unsubscribe mechanism provided or through the applicable contact channel.
Talentprobe may continue to send communications necessary for:
a. active screening cases;
b. contractual relationships;
c. billing;
d. security;
e. legal notices;
f. privacy matters;
g. system administration; and
h. other non-promotional service communications.
93. CONTACT INFORMATION
Privacy questions, requests, complaints, and concerns may be directed to:
Data Privacy, Protection, and Security Office
Circa Logica Group / Talentprobe Due Diligence
Email: privacy@circalogicagroup.com
Talentprobe may maintain additional candidate support, client support, and operational contact channels for matters not requiring direct attention of the privacy office.
PART XIX
CHILDREN AND MINORS
94. SERVICES INVOLVING MINORS
Talentprobe’s services are primarily designed for employment, professional, commercial, compliance, and other legitimate due diligence purposes and are generally not directed toward children.
Talentprobe shall not intentionally conduct background screening involving a minor unless:
a. the processing is lawful;
b. the screening serves a legitimate purpose;
c. the information requested is appropriate and proportionate;
d. any required parental, guardian, or other authorization has been obtained; and
e. appropriate safeguards are implemented.
95. WEBSITE USE BY CHILDREN
Talentprobe’s business services and platforms are not designed primarily for children.
Where Talentprobe becomes aware that personal data concerning a child has been collected in circumstances inconsistent with applicable requirements, Talentprobe shall take reasonable steps appropriate to the circumstances.
PART XX
INTERNATIONAL PROCESSING
96. MULTI-JURISDICTIONAL SERVICES
Talentprobe recognizes that clients may operate internationally and that candidates, verification sources, and technology providers may be located in different jurisdictions.
Talentprobe shall evaluate applicable privacy obligations based on the circumstances of the processing.
97. CONTRACTUAL REQUIREMENTS
A client may impose privacy and data protection requirements through a Data Processing Agreement, master services agreement, security addendum, or other written instrument.
Where such requirements are lawful and accepted by Talentprobe, they shall apply in accordance with the relevant agreement.
98. CONFLICT OF REQUIREMENTS
Where privacy requirements from different jurisdictions or contractual arrangements appear to conflict, Talentprobe shall seek appropriate legal, compliance, or privacy guidance.
Talentprobe shall not knowingly disregard a mandatory legal obligation solely because another jurisdiction applies a different standard.
PART XXI
RELATED POLICIES AND DOCUMENTS
99. RELATED TALENTPROBE POLICIES
This Policy should be read together with the following:
- Information Security and Data Breach Management Policy
- Data Retention and Secure Disposal Policy
- Background Screening Quality and Accuracy Policy
- Candidate Rights, Dispute and Resolution Policy
- Data Processing Agreement
- applicable Candidate Consent and Authorization documentation
- applicable privacy notices
- applicable client agreements
- applicable internal information security and privacy standards
These documents collectively form part of Talentprobe’s privacy, security, and responsible screening governance framework.
PART XXII
POLICY ADMINISTRATION
100. POLICY REVIEW
This Policy shall be reviewed periodically and may be revised in response to:
a. changes in applicable law;
b. National Privacy Commission guidance or issuances;
c. regulatory developments;
d. changes to Talentprobe services;
e. changes in processing activities;
f. changes in technology;
g. material security or privacy risks;
h. findings from audits or assessments;
i. lessons from incidents or disputes;
j. changes to Circa Logica Group policies; or
k. developments in recognized privacy and data protection practices.
101. MATERIAL CHANGES
Where material changes are made to this Policy, Talentprobe may provide notice through its website, platform, client communications, candidate communications, or other appropriate means.
The effective date or version information shall be updated accordingly.
Continued processing shall remain subject to applicable legal requirements concerning notice, consent, or other lawful basis.
102. AVAILABILITY
The current public version of this Policy shall be made available through Talentprobe’s official website or upon reasonable request.
Clients may include this Policy as part of vendor accreditation, procurement, privacy assessment, risk assessment, or due diligence documentation.
103. INTERPRETATION
This Policy describes Talentprobe’s general privacy governance principles and commitments.
It does not create contractual rights beyond those established by applicable law or binding written agreement and does not restrict rights that cannot lawfully be waived or limited.
Where a provision of this Policy conflicts with a mandatory requirement of applicable law, the mandatory legal requirement shall prevail.
Questions regarding interpretation shall be referred to the Data Privacy, Protection, and Security Office or another appropriately authorized representative.
104. CONTINUOUS IMPROVEMENT
Privacy and data protection are continuing responsibilities.
Talentprobe shall periodically evaluate its privacy governance framework and make reasonable improvements in response to changes in risk, technology, regulation, industry practice, service delivery, and organizational requirements.
The existence of a policy or control shall not prevent Talentprobe from adopting stronger safeguards where appropriate.
105. TALENTPROBE PRIVACY COMMITMENT
Background screening depends upon trust.
Candidates entrust Talentprobe with information concerning their identity, education, employment, professional history, credentials, and other aspects of their personal and professional lives. Clients rely upon Talentprobe to obtain and handle that information responsibly. Institutions, references, verification partners, and other sources similarly expect information exchanged during the verification process to be treated appropriately.
Talentprobe accepts that responsibility.
Our commitment is to collect only what is appropriate, process information for legitimate purposes, protect it throughout its lifecycle, verify information responsibly, restrict access to authorized persons, maintain reasonable safeguards, respect applicable data subject rights, correct substantiated inaccuracies, retain information only for justified periods, and securely dispose of information when it is no longer required.
Privacy is therefore not treated solely as a regulatory requirement. It forms part of Talentprobe’s standard for responsible due diligence.
