Privacy Policy for Job Applicants

In accordance with the provisions of the GDPR, we hereby inform you about the processing of your personal data by the data controller:

PRIF – Peace Research Institute Frankfurt

Darmstädter Landstraße 110-114, 60598 Frankfurt am Main/Germany

You can contact our Data Protection Officer at: gds – Gesellschaft für Datenschutz Mittelhessen mbH, Auf der Appeling 8, 35043 Marburg-Cappel, E-Mail: daten-schutz@gdsm.de, Tel.: 06421 804 1310 (Please mention PRIF when contact them).

How can you apply? 
You can apply by emailing application@prif.org and specifying 'Application for position XY'. If you would like to send your application materials encrypted via email, you can send them in a password-protected file, for example. Please provide us with the password over the phone on +49 69 9591040.

Data processed
When you apply for a position with us, we process the infor­mation you provide as part of the application process. This includes the follow­ing personal data:

  • Personal information (name, address, contact details),
  • application materials,
  • information regarding education, qualifications, and work experience,
  • communication records,
  • notes from job interviews,
  • where applicable, information regarding severe disability or equal opportunity.

Please do not send us any information that is not required for your application. For example, we do not require a photo with your application. If we process any special categories of personal data as defined in Article 9 of the GDPR, this will be done only if permitted by law. This applies in particular to the follow­ing information:

  • regarding severe disability,
  • regarding medical fitness,
  • and other circum­stances relevant under social welfare law.

The processing is carried out solely to ful­fill legal obligations and rights under labor, social security, or dis­ability laws.

Purpose of Data Processing
We process your data to conduct the application process and decide whether to establish an employment relation­ship with you. This includes the follow­ing purposes, in particular:

  • Assessment of your professional and personal qualifications,
  • communi­cation during the application process,
  • conducting interviews,
  • compliance with legal obligations,
  • exercising the partici­pation rights of bodies designated by law.

Legal Basis for Processing
We process your data based on the following legal grounds:

  • § 26(1), first sentence 1 BDSG,
  • Art. 6(1)(b) GDPR,
  • Art. 6(1)(c) GDPR,
  • § 23 HDSIG,
  • or, where consent has been given, Article 6(1)(a) of the GDPR.

Processing special categories of personal data (e.g., health data) is generally not required for your application. However, if necessary, we will process special categories of personal data based on the follow­ing legal grounds:

  • Art. 9(2)(b) of the GDPR,
  • § 26(3) of the BDSG,
  • §§ 164 et seq. of SGB IX,
  • and, where applicable, other provisions of labor, social security, or civil service law.

The legal basis for temporarily storing data after an unsuccessful application process is Article 6(1)(f) of the GDPR. We have a legitimate interest in protecting ourselves against potential legal claims, especially those under the General Equal Treatment Act (AGG).

Source of the Data
We generally receive your data directly from you as part of your application through:

  • application materials,
  • correspondence,
  • telephone or in-person interviews,
  • digital communication channels.

Recipients of Data
Within the institute, access to your data is limited to those departments that require it to carry out the application process. These include, in particular:

  • Human Resources,
  • the relevant department,
  • selection committees,
  • institutional leadership,
  • staff representatives,
  • representatives for persons with severe disabilities,
  • equality officers.

Employee representatives, equal opportunity officers, and representatives for persons with severe disabilities are only involved to the extent provided for by law.

Technical service providers or IT processors are granted access to personal data only to the extent necessary. These providers process data only on the basis of a data processing agreement in accordance with Article 28 of the GDPR and our instructions. Data will only be disclosed to other third parties if legally required or with your consent.

Retention Period
We only store your personal data for as long as is necessary to complete the application process.

  • If you are hired, your data will be included in your personnel file and the applicable retention periods for an employment relationship will apply.
  • If your application is unsuccessful, we typically store your data for six months after the application process ends or after the rejection notice is sent.

If there are any applicable statutory retention obligations, such as those related to travel expense reimbursements, budgetary matters, or taxes, we will store your data in accordance with the applicable statutory retention periods.

Automated Decision-Making/Profiling
We do not engage in automated decision-making or profiling.

Transfer to Third Countries
Personal data is generally not transferred to countries outside the European Union or the European Economic Area. However, if service providers with a connection to a third country are used in individual cases, this is done exclusively in compliance with the legal requirements of Articles 44 et seq. of the GDPR.

Note on Providing Data
Providing your personal data is required to complete the application process. Otherwise, your application cannot be considered.

Note on Video Conferencing Tools
If job interviews are conducted via video conference, technical connection data will be processed as well. No recording will be made. The privacy policy of the video conferencing provider also applies.

As a data subject, you have the following rights:

  • The right of access (Art. 15 GDPR or § 52 HDSIG).
  • The right to rectification (Art. 16 GDPR or § 53 HDSIG).
  • The right to erasure (Art. 17 GDPR and §§ 34 and 53 HDSIG), or the right to restrict processing (Art. 18 GDPR or § 53 HDSIG).
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)
  • The right to lodge a complaint with the supervisory authority (Art. 77 GDPR and § 55 HDSIG).

If a data subject believes that their personal data is being processed in violation of the GDPR, they may file a complaint with a supervisory authority.

The contact information for the supervisory authority responsible for the state of Hesse is as follows:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit

Postfach 3163

65021 Wiesbaden