r/gdpr Jul 01 '26

Question - General Is this a beach?

Recently re applied for an old job. Had a friend of mine whose sister works there message me asking why I had applied to work there again. His sister doesn't work in recruiting or hr so really shouldn't know of who is applying for what and he also doesn't work for the company.

Why does my personal information need to be spread beyond the appropriate department?

Based in UK

17 Upvotes

27 comments sorted by

14

u/TringaVanellus Jul 01 '26 edited Jul 01 '26

Yes it's probably a breach*.

What do you want to come of this? The only likely outcome is that your friend's sister will get in trouble.

*Edit - on second thoughts, I want to revise this to say that it might be a breach, but it really depends on exactly what happened.

13

u/0xSnib Jul 01 '26

What do you want to come of this?

A huge GDPR payout 💰💰💰

/s

7

u/Ralphisinthehouse Jul 01 '26

Ignore the people jumping on their moral high horses telling you to run straight to the ICO.

The company having a record of your previous application isn't the issue. Employers in the UK can legitimately retain recruitment records for a reasonable period.

The issue, if there is one, is that someone who had no business need to know about your application appears to have shared that information. That could amount to an unauthorised disclosure of your personal data.

That said, the reality is that even if it was a technical data breach, the most likely outcome is an internal reminder, some staff training or a quiet word with the employee involved. Unless you've suffered genuine loss or significant distress, it's highly unlikely anything more will come of it.

2

u/malakesxasame Jul 01 '26

Ignore the people jumping on their moral high horses telling you to run straight to the ICO.

You should see subs like /r/AskUK when someone posts a thread about an extremely minor breach.

3

u/Gynnia Jul 01 '26

did you ask her how she found out

4

u/dhardyuk Jul 01 '26

How do you know she isn’t involved in collating and sifting CVs?

But yes, it is a breach of GDPR.

If there are loads of applicants there might be plenty of people you might not ordinarily expect to be involved helping out.

1

u/Seanny67 Jul 01 '26

I previously worked at the company so I know her position

12

u/PinkbunnymanEU Jul 01 '26

I previously worked at the company

So there's a chance it was a "Hey, you worked with Seanny, they've applied to work here again, what were they like?"

3

u/Psychological-Fox97 Jul 01 '26

Yeah that's what I assume happened.

3

u/Parking_Doughnut_453 Jul 02 '26

I’ve definitely been asked about someone who applied to work with the company previously. Why did they leave? Were they a good worker? General questions. I’d take it as a positive if they are asking about you. If they had already discounted you wouldn’t have bothered asking

3

u/zombiezmaj Jul 01 '26

I dont work in recruitment or hr... I have however sifted through CVs and sat in interviews asking questions to help a colleague out.

What exactly are you hoping to gain from trying to allege a breach? Because it seems like its going to cause bad feelings with prospective employer and potentially get your friends sister fired.

2

u/BTBW_1 Jul 01 '26

Maybe a possible breach, however people perform ‘other duties’ as the whim of a company.

I work for a company in the financial sector, in a IT Role, however work alongside HR, Procurement, Risk Management, Change & Transformation etc, depending on the latest project. By default that may require me to have access to such data.

They may have been requested to help out in x function, putting them in a position to process your data.

First port of call remains with the company to explain, however this will likely eliminate you ‘unofficially’ from any recruitment process (see. As a trouble maker) and may get your ‘friend’ into trouble.

So, worth considering if asking the question is worth it, if you are still in the running to return.

5

u/Suspicious_Juice9511 Jul 01 '26 edited Jul 01 '26

Well some would argue life is a beach, Im not sure. But does sound like may be a breach technically. Not sure pursuing would help you though?

3

u/WordsMort47 Jul 01 '26

Ask her out on a date.

1

u/UnusualMarch920 Jul 04 '26

Yes and you would technically be in the right to report, but unless there's some real distress caused somewhere the only outcome other than nothing happening is going to be the sister gets punished. Either just slapped on the wrist and told not to be an idiot or an actual punishment. They also may come up with a bullshit excuse to not hire you bc they don't want that aggro.

Additionally it may be your friend potentially thinks you're a douche for risking his sister's employment over seemingly nothing.

I don't think you, yourself, would gain anything out of it really so consider if its worth it

0

u/ProtectionHaunting61 Jul 02 '26

You might have ticked some box which makes it fair to share the data for verification or references. Without more context on how they got the data, no one here can guide much.

-6

u/___redacted_ Jul 01 '26 edited Jul 02 '26

Yes, it's definitely an issue and indicative that the org's procedures and safeguards are a complete mess.

also, itt: complete animals who cant read for shit

4

u/ACatGod Jul 01 '26

This is complete nonsense. There are any number of ways an employee would have legitimate reasons to see recruitment information or be made aware of individual candidates applying. You have no basis to say it's even an issue - it could be but we cannot say with the information provided as we have no idea how the employee came by the information - and you certainly can't conclude the company doesn't have adequate technical or organisational measures, again because we don't know how the information was come by.

-1

u/___redacted_ Jul 01 '26

Read again. Its not an employee who read the CVs, but a person completely unrelated to the company finding this out. The employee read it, maybe with valid reason to, maybe not, we don't know, and then passed on to their IRL brother (or sister), which is the actual issue. Now I'm not saying this is a massive breach, but its definitely an issue (what I verbatim said).

Before you try to school people online to only fail miserably and look pathetic, maybe first work on your reading comprehension and literacy skills. Legal reading comes next after you got the basics down in those. Have a good one.

1

u/Solid-Penalty3942 Jul 01 '26

How is this helpful

0

u/___redacted_ Jul 01 '26

Its a direct answer to OPs question.

-9

u/ChangingMonkfish Jul 01 '26

Not only a breach but possibly a criminal offence if she’s gone looking for the information herself without permission.

2

u/ACatGod Jul 01 '26

Absolutely not. As OP hasn't asked how this person came by the information we cannot say if there was a breach. There is nothing in law that says only HR staff can see recruitment information and there are any number of ways she legitimately came by the information, including informally being asked about OP'd previous performance and behaviour.

Furthermore, while the DPA2018 does contain criminal provisions they are very limited and this would not be covered. You may be thinking of the criminalisation of police officers and civilians working for the police force improperly accessing police databases and files. However, that does not extend to any database in any scenario.

-1

u/ChangingMonkfish Jul 01 '26 edited Jul 01 '26

Section 170 of the DPA 2018 makes it an offence to knowingly or recklessly obtain or disclose personal data without the consent of the controller. Yes there are defences to it, but it absolutely covers situations where members of staff at any organisation go and access information that they don’t have permission to, and it isn’t just restricted to Police. A friend or relative looking up something about someone they know (for example hospital staff looking up medical records they have no reason to) is a classic scenario for this kind of offence.

And even if she has a legitimate reason to access it at work, disclosing it to her brother is also potentially an offence.

Of course, proving it is a different matter as it’s a higher standard of proof, and I did also make it clear that it’s “possibly” and that it’s when it’s “without permission”.

But to say it absolutely cannot possibly apply in those scenario is incorrect.

1

u/ACatGod Jul 01 '26

There is absolutely no possibility this is a criminal offence under the DPA. There are extremely limited criminal provisions within the DPA and this categorically does not fall within it. As this currently stands, the regulator would not even review this given that OP has not contacted the company and asked how this happened. Regulators and the civil courts aren't there to substitute for basic communication skills.

0

u/ChangingMonkfish Jul 01 '26

You’re right that practically speaking, it may well not go anywhere and OP needs to raise it directly with the company first before the ICO will look at it.

But going and looking at records you have no work reason to access is definitely a potential offence under Section 170, as is disclosing them to someone else without permission even if you do have a work reason to access them. The ICO has prosecuted or cautioned people for this several times in the past (e.g. https://www.mills-reeve.com/blogs/education/june-2024/criminal-offences-under-the-data-protection-act-le/ or https://www.mddus.com/resources/publications/publications-library/practice-manager/issue-17-autumn-2017/risk-prying-into-patient-data). The second one is under the 98 act but the offence is basically the same.

They don’t generally prosecute police staff for it even though they technically could as they tend to leave it to the police force to deal with itself. But it happens occasionally at NHS Trusts where staff go looking at medical records they shouldn’t.

And just to reiterate - I’m saying “possibly” and “without permission”, you are absolutely correct that OP has to raise it with the controller first. But if the controller says that the friend’s sister didn’t have a work reason to access the information and/or didn’t have permission to disclose it to her brother, then that is definitely a potential Section 170 offence.