GDPR
The General Data Protection Regulation (GDPR) sets rules for handling personal data and protecting individuals’ privacy in the European Union. It has applied since 25 May 2018.
The GDPR replaced the Data Protection Directive (95/46/EC). It gives individuals rights over their personal data and sets responsibilities for organizations that collect, use and store it.
The GDPR applies to organizations established in the EU/EEA and can also apply to organizations outside it when they offer goods or services to individuals there or monitor their behaviour. Its scope is not determined by citizenship alone. In the UK, data protection is governed by the UK GDPR and the Data Protection Act 2018.
What is the Aim of GDPR?
The GDPR protects individuals’ personal data and governs how organizations process it. “Personal data” includes information relating to an identified or identifiable individual, also called a “data subject”.
The GDPR gives individuals a range of rights over their personal data. The conditions and exceptions that apply depend on the right and the circumstances.
Key GDPR rights and responsibilities include:
-
- Expanded rights for individuals The GDPR provides expanded rights for individuals in the European Union by granting them, among other things, the right to be forgotten and the right to request a copy of any personal data stored in their regard.
-
- Compliance obligations The GDPR requires organizations to implement appropriate policies and security protocols, conduct privacy impact assessments, keep detailed records of data activities and enter into written agreements with vendors.
-
- Data breach notification and security The GDPR requires organizations to report certain data breaches to data protection authorities, and under certain circumstances, to the affected data subjects. The GDPR also places additional security requirements on organizations.
-
- Requirements for profiling and monitoring The GDPR places additional obligations on organizations engaged in profiling or monitoring behavior of EU individuals.
-
- Increased enforcement Under the GDPR, authorities can fine organizations up to the greater of €20 million or 4% of a company’s annual global revenue, based on the seriousness of the breach and damages incurred. Also, the GDPR provides a central point of enforcement for organizations with operations in multiple EU member states by requiring companies to work with a lead supervisory authority for cross-border data protection issues.
How CVViZ Complies with GDPR?
CVViZ fully complies with GDPR in our role as a data processor. GDPR is a complex piece of legislation and we’ve been working with privacy experts and our attorneys to be sure we’re completely compliant with GDPR.
Our GDPR compliance work has included the following measures:
- Appointed a Data Protection Officer.
- Reviewed the areas of our product and business affected by GDPR.
- Updated our data protection documentation.
- Developed guidelines for addressing GDPR requirements in our product.
- Implemented product changes to support data subject rights, as described in the “Acknowledging Data Rights” section.
- Updated internal processes and procedures to support GDPR compliance.
- Tested the product and process changes made for GDPR.
- Published information about our data protection practices on our website.
Acknowledging Data Rights
Here’s a detailed log of the eight essential data subject rights and what we have done in order to facilitate the rights in accordance with GDPR, to ensure the privacy and security of our customers:
1. Right to be Informed
What does it mean?
Individuals have the right to receive clear and accurate information about how a business has acquired their data, who is processing the data and why, and how will it be stored and used.
How CVViZ complies?
When candidates use the job application page to apply to jobs, CVViZ gives candidates an opt-in button with a privacy document that tells candidates how data will be used. When you manually add candidates into the system it is your duty as a “Data Controller” to inform your candidates about how you will use their data.
2. Right to Access
What does it mean?
Individuals have the right to request access to the personal data an organization holds about them.
How CVViZ complies?
Our Update Resume functionality allows you to send your candidates a link they can use to access all the information you have stored about them.
3. Right to Rectification
What does it mean?
Individuals have the right to request correction of inaccurate personal data and completion of incomplete personal data.
How CVViZ complies?
With our Update Resume functionality you can send your candidates a link that they can use to update their information or resume/CV.
4. Right to Erase
What does it mean?
Individuals have the right to request erasure of their personal data where the applicable conditions are met. This right is subject to legal exceptions.
How CVViZ complies?
If a candidate or client requests that you delete their information, you can simply select their record in CVViZ and click on delete. We erase the record and all associated files immediately.
5. Right to Restrict Processing
What does it mean?
Individuals have the right to request a restriction on the processing of their personal data, pertaining to certain conditions or circumstances. When processing is restricted, data controllers are permitted to store the personal data, but not use it. An individual can make a request for restriction verbally or in writing. Organizations generally must respond within one month, subject to the applicable rules and permitted extensions.
How CVViZ complies?
CVViZ lets their customer change candidate status to inactive/suspended so that they are no longer send to companies for open job opportunities.
6. Right to Data Portability
What does it mean?
Where the right to data portability applies, individuals can request their personal data in a structured, commonly used and machine-readable format and transmit it to another controller. Organizations generally must respond within one month, subject to the applicable rules and permitted extensions.
How CVViZ complies?
To extract your data from CVViZ, User can select the candidate information and click on Export Data to export that data.
7. Right to Object
What does it mean?
Individuals, as data subjects, have the right to object to certain processing of their personal data. This includes the right to object to processing for direct marketing.
How CVViZ complies?
We let users attach an unsubscribe button with all the emails they send. This allows candidates and clients to opt-out from any communication from the recruiter.
8. Rights in Relation to Automated Decision Making and Profiling
What does it mean?
GDPR has provisions on making a decision based solely on automated means without any human involvement. And also automated processing of personal data to evaluate certain things about an individual i.e profiling. Profiling can be part of an automated decision-making process. GDPR applies to all automated individual decision-making and profiling.
How CVViZ complies?
CVViZ supports AI-assisted screening and recruiter-configured automation. Recruiters review recommendations and retain responsibility for hiring decisions.
Advanced Security
Under GDPR, a data processor must notify the data controller without undue delay after becoming aware of a personal data breach. The controller is responsible for assessing any notification obligations to the relevant authority and affected individuals.
As a software company, we take our customers data and its security very seriously. All your data is encrypted and stored in world class data centers managed by Amazon Web Services (AWS), Europe region. We also use many services provided by AWS to ensure that data is frequently backed-up and available.
The controls described above help customers manage candidate data and respond to data subject requests as part of their recruiting workflow.
Disclaimer:
This page provides background information about CVViZ’s data protection practices. Customers remain responsible for assessing the data protection requirements that apply to their processing. For guidance on the relevant legal framework, see the EDPB’s GDPR guidance and the UK government’s data protection overview.
If you have any queries, you may send them to he***@***iz.com
Last updated 10 September 2026