Handling of personal data
People are at the heart of the labour-intensive services provided by Vebego. With more than 100 companies forming part of Vebego and thousands of employees across Europe, personal data is processed on a large scale. In addition, Vebego and its staff spend a great deal of time visiting clients and suppliers, and the company works with many external partners to deliver its services. To protect all employees, the company and its partners, Vebego takes privacy very seriously.
With regard to privacy and the protection of personal data, Vebego adopts a ‘risk-based approach’ in its business operations. This means that it does not focus solely on compliance with laws and regulations, but concentrates on the most extensive and high-risk processing activities and their security. Vebego recognises that protecting personal data and ensuring its organisation remains privacy-compliant is a dynamic process involving many challenges. The processing of personal data relating to its many employees is the most extensive and high-risk activity. This is where Vebego’s focus lies. Great importance is also attached to raising awareness in the workplace regarding the careful handling of all data.
Vebego is constantly seeking to strike the right balance between compliance – adhering to laws and regulations – and maintaining a workable environment for everyone involved, with sufficient scope for entrepreneurship and a passion for service.
Purposes of processing
Vebego collects and processes personal data for the following purposes:
• To fulfil its role as an employer for its many employees, both permanent and flexible, which includes, but is not limited to, the following processing activities: building and managing personnel files and absence records, payroll administration, complying with obligations relating to reintegration, assessing employees’ suitability for assignments, and the temporary placement of employees. Vebego also processes data relating to job applicants in recruitment and selection procedures;
• Fulfilling its role as a contractor or supplier in many areas within the wide range of services in which Vebego operates, which includes, but is not limited to, the following processing activities: managing data relating to prospects, customers and clients in CRM and maintaining these business relationships;
• The provision of data relating to permanent and flexible staff to clients and contractors, which is necessary for the performance of a contract. Many Vebego employees are always out and about, working at clients’ or contractors’ premises. The law requires Vebego to provide certain data relating to its employees to those clients/contractors where the employees are working. These clients/contractors need to be able to verify the identity of the employees and record the data in their records. Where the basis for disclosure is not laid down by law, but the client/contracting party nevertheless requires Vebego to do so, an assessment is carried out at all times to determine whether the disclosure of data complies with the General Data Protection Regulation (hereinafter: ‘GDPR’);
• The processing of data concerning patients’ health by Vebego subsidiaries operating in the healthcare sector. This processing is justified by the exception in the GDPR to the prohibition on processing such data, where this is carried out by healthcare institutions. The processing takes place for the performance of the agreement on medical treatment or on another legitimate basis;
the exchange of data within Vebego Holding, with and between subsidiaries, for the purpose of optimising service provision;
• The provision of employee data to the central government, where this is requested or required, for example, to obtain a certificate of good conduct for staff;
the monitoring or supervision of employees, for example, using an employee tracking system. This will only take place where there is a specific reason for doing so and where it is necessary to investigate incidents. In such cases, an assessment will always be carried out, and the first step will be to determine whether the problem or incident can be resolved using less intrusive means;
• CCTV may be used to ensure the security of Vebego’s personnel, buildings, premises and property. The cameras film only the entrances to the buildings and any other areas surrounding the buildings and premises. The CCTV footage is not used for any purpose other than security, and the recordings are not retained for longer than is permitted. CCTV surveillance may also take place at the premises of Vebego’s clients or contractors where employees are deployed. Vebego has no oversight of this and is not responsible for it. The client or contractor in question must inform all employees (both their own and hired staff) of this.
• The provision of data to Vebego’s processors, which is necessary for the performance of a contract between Vebego and that processor. A Vebego processor must always sign a data processing agreement in which the rights of data subjects are sufficiently safeguarded and the processor is obliged to secure the data appropriately.
Where personal data is processed without falling under one of the above purposes, an assessment is carried out at all times to determine whether one of the lawful purposes applies and whether there is a lawful basis for processing.
Processing of personal data: employees and business contacts
The processing of personal data within Vebego mainly takes place in the HR department. Vebego processes only those data relating to its employees that are necessary for the creation and maintenance of personnel files and, where applicable, absence records. During the employment relationship and for a period following its termination, Vebego retains, in addition to the necessary basic employee data, a copy of the ID document, references and certificates, and, where necessary or applicable, pre-screening documentation, A1 certificates, residence permits, work permits, notifications or VAR declarations.
In addition, data relating to business contacts is processed, namely that of (potential) customers, suppliers and (other) business partners. The data that Vebego processes relating to its business contacts is mostly company data and does not fall under the GDPR. However, the details of contact persons (name, contact details, job title) for all business contacts do fall under the GDPR. Vebego handles all data with the utmost care. Company data is also treated as strictly confidential.