CONTINENTAL HR PROCESSING NOTICE
1. PURPOSE OF THIS NOTICE AND TERMS
1.1 We, Continental Tyre SA Pty Ltd, Registration no: 1998/005020/07, Contitech Africa Pty Ltd, Registration no: 2006/036140/07, Contitech ServicesPty Ltd, Registration no: 1976/002089/07, Contitech South Africa Pty Ltd, Registration no: 2005/026683/07, Contitrade Africa Pty Ltd, Registration no: 2013/059163/07, referred to as “we”, ”us”,“Continental” or “the company”) in our capacity as a Responsible Party, in order to engage with you, will have to process your Personal Information, and in doing so, will have to comply with a law known as the Protection of Personal Information Act, 4 of 2013 (hereinafter referred to as “POPIA”), which regulates and controls the processing of a legal entity’s and / or an individual’s Personal Information in South Africa, (hereinafter referred to as a “Data Subject”), which processing includes the collection, use, and transfer of a Data Subject’s Personal Information.
1.2 For the purpose of this Processing Notice, please take note of the following words and phrases which will be used throughout this Processing Notice:
· "consent", means the consentwhich you, in your capacity as a Data Subject, may have to give to us,under certain circumstances, to process your Personal Information, which consent must be voluntary, specific and informed. Following this, once we have explained to you why we need your Personal Information and what we will be doing with it, you are then, in relation to certain uses of the information, required to give us your permission to use it, which permission or consent can be express or implied; implied meaning that your consent can be demonstrated by way of your actions;
· "Data Subject", means you, the person who owns and who will provide us with your Personal Information for processing;
· "Operator" is any person who processes your Personal Information on our behalf as a contractor, in terms of a contract or mandate, without coming under the direct authority of us. These persons for illustration purposes may include verification agencies, advertising and public relations agencies, call centres, service providers, auditors, legal practitioners,and / or organs of state, including government, provincial and municipal entities and bodies;
· "Personal Information", means Personal Information relating to any identifiable, living, natural person, and an identifiable, existing legal entity, namely the Data Subject, including, but not limited to —
· in the case of an individual:
o name, address, contact details, date of birth, place of birth, identity number, passport number, bank details, details about your employment, tax number and financial information;
o vehicle registration;
o dietary preferences;
o financial history;
o information about your next of kin and or dependants;
o information relating to your education or employment history; and
o Special Personal Information including race, gender, national, ethnic or social origin, colour, disability, criminal history, including offences committed or alleged to have been committed, and biometric information, such as images and fingerprints;
· in the case of a legal entity:
o name, address, contact details, registration details, financials and related history, B-BBEE score card, registered address, description of operations, bank details, details about your employees, business partners, customers, tax number, VAT number and other financial information.
· "processing" / “process”or “processed”, means in relation to Personal Information, the collection, receipt, recording, organisation, collation, storage, updating or modification, retrieval, alteration, consultation or use; dissemination by means of transmission, distribution or making available in any other form; merging, linking, as well as restriction, degradation, erasure or destruction of information; or sharing with, transfer and further processing, including physical, manual and automatic means. This is a wide definition and therefore includes all types of usage of your Personal Information by us including the initial processing when we first collect your Personal Information and any further and ongoing processing until destruction of such information when no longer required;
· “Purpose” means the reason why your Personal Information needs to be processed by us;
· "Responsible Party”means us, the person who is processing your Personal Information;
· “you” means you, the person or organization who will be providing us, the Responsible Party, with your Personal Information, for processing, who is known as the Data Subject under POPIA.
1.3 In terms of POPIA, where a person processes another’s Personal Information, such processing must be done in a lawful, legitimate and responsible manner and in accordance with the provisions, principles and conditions set out under POPIA.
1.4 In order to comply with POPIA, a Responsible Party processing a Data Subject’sPersonal Information must:
1.4.1 provide the Data Subject with a number of details pertaining to the processing of the Data Subject’sPersonal Information, before such information is processed; and
1.4.2 get permission or consent, explicitly or implied, from the Data Subject, to process his / her / its Personal Information, unless such processing:
§ is necessary to carry out actions for the conclusion or performance of a contract to which the Data Subject of the Personal Information is a party;
§ is required in order to comply with an obligation imposed by law; or
§ is for a legitimate purpose or is necessary to protect the legitimate interest (s) and / or for pursuing the legitimate interests of i) the Data Subject; ii) the Responsible Party; or iii) that of a third party to whom the Personal Information is supplied; or
· is necessary for the proper performance of a public law duty.
1.5 In accordance with the requirements of POPIA, and because your privacy and trust is important to us, we set out below how we, Continental collect, use, and share your Personal Information and the reasons why we need to use and process your Personal Information.
2.1 This Processing Notice applies to the following persons:
2.1.1 Applicants: persons who wish to apply for an employment position withinContinental, or who wish to apply for a learnership or bursary, scholarship,or study assistance;
2.1.2 learnership or bursary recipients:persons who have been granted a bursary, learnership, scholarship,or study assistanceby Continental;
2.1.2 Employees: persons who are employed by Continental.
3. PURPOSE FOR PROCESSING YOUR PERSONAL INFORMATION
3.1 Your Personal Information will be processed by us for the following purposes:
SUMMARY OF THE PURPOSE OF COLLECTION
Due diligence purposes – legitimate purpose: To carry out a due diligence before we decide to engage or interact with you, including obtaining and verifying your credentials, including your personal details, medical status, health history and related records, education and employment history and qualifications, credit and financial status and history, tax status, B-BBEE status, and or any performance or employee related history.
Employment- potential –legitimate purpose: To conduct and communicate with you regarding recruiting, potential employment and human resources administration.
Employment- actual-to contract with you: To conclude an employment contract with you, and to manage the employment relationship including managing you, communicating with you regarding your employment, performing human resources administration, operational, financial, and organizational matters, providing you with training and skills development, providing you with employee benefits such as pension and medical aid benefits, and conducting performance assessments and disciplinary matters.
Potential scholarships, bursaries, study assistance, learnerships recipients –legitimate purpose: To investigate whether we are able or willing to conclude a contract with you based on the findings of any due diligence, and if in order to conclude a scholarship, bursary, study assistance, or CSI contract.
Scholarships, bursaries, study assistance, and learnership recipients –to contract with you: To conclude acontract with you, and to manage the relationship.
Attending to financial matterspertaining to your employment- contract and legitimate purpose: To administer payroll including payment of statutory levies, deductions, fees owed to Organization, registrations, subscriptions, or payment of refunds.
Communications- legitimate purpose: To make contact with you and to communicate with you generally or specifically, i.e. in respect of our or your requirements, or instructions, or to respond to you in order to comply with your specified or general instructions.
Risk assessment and anti- bribery and corruption matters- legitimate purpose: To carry out organizational and enterprise wide risk assessments, in order todetect and prevent bribery, corruption, fraud and abuse, to comply with Anti Bribery and Corruption laws,as well as to identify and authenticate your access to our assets, systems, goods, services or premises and generally to ensure the security and protection of all persons including employees, and persons when entering or leaving our sites and / or to exercise our rights and to protect our and others’ rights and / or property, including to take action against those that seek to violate or abuse our assets, systems, services, customers or employees and / or other third parties where applicable.
Legal rights, duties and obligations and insurance matters- comply with law and protect legitimate interests: To comply with the law and our legal obligations, exercise legal rights and duties, including to register with Regulators, obtain and hold permits and certificates, ensure a safe and healthy work environment, register for VAT, Tax, PAYE, SDL, COIDA and UIF etc, provide medical care and facilities, to submit reports or provide various notices or returns, to litigate,to proceed to protect the company’s legal rights, collect debts or enforce contractual or employment rights, and / or to respond to a request or order from a SAP official, investigator or court official, regulator, or public authority and / or to manage and attend to insurance matters.
Security purposes: legitimate purpose and to comply with laws: Topermit you access to our offices, facilities, manufacturing or parking areas, as well as to controlled areas, for the purposes of monitoring via CCTV, your interaction and access in and from our facilities described above, and for general risk management, security and emergency incident control purposes as well as for data and cybersecurity purposes.
Operational issues - compliance with law and manage the contract: To communicate, enforce and ensure youcomply with policies, including in relation to claims, disciplinary actions or legal requirements and conducting investigations and incident response, including reviewing your communications in these situations in accordance with relevant internal policies and applicable law.
Occupational health - compliance with laws: To manage occupational health and absence and fitness for work and notifying family members in emergencies.
Travel - contractual: To facilitate business travel, travel-related support including conference attendance, bookings, and emergency support services.
B-BBEE - compliance with laws: To monitor equal employment opportunities, in respect of diversity categories including but not limited to age, gender, ethnicity, nationality, religion, disability, sexual orientation, and marital or family status.
IR and Labour relations - compliance with laws: To manage membership to trade unions and collective agreements for administering collective employee arrangements where these are in place
For internal research and development purposes- Legitimate purpose:To conduct internal research and development.
Effectuate the sale, merger, acquisition, or other disposition of our business (including in connection with any bankruptcy or similar proceedings) - Legitimate interest: to comply with our legal obligations and to change our business structure we may disclose your Personal Information in connection with proceedings or investigations anywhere in the world to third parties, such as public authorities, law enforcement agencies, regulators and third-party litigants. We may also provide relevant parts of your Personal Information to any potential acquirer of or investor in any part of the Group’s business for the purpose of that acquisition or investment.
4. WHAT PERSONAL DATA OR INFORMATION DO WE COLLECT FROM YOU?
4.1 In order to engage and / or interact with you, for the purposes described above, we will have to process certain types of your Personal Information, as described below:
· Your contact information, such as name, alias, address, identity number, passport number, security number, phone number, cell phone number, vehicle make and registration number, social media user ID, email address, and similar contact data, and other contact information including details of your previous employers serial numbers of equipment, details regards the possession of dangerous weapons, , memberships or affiliations, including professional bodies and trade unions, and similar data, which are required for various legitimate interest, contractual and / or lawful reasons pertaining to your application for employment or actual employment with the Organization or pertaining to your application for a scholarship, bursary, learnership or study assistance or where you are granted ascholarship, bursary, learnership or study assistance.
· Career, Education, and Employment Related Information, such as job preferences or interests, work performance and history, salary history, nationality and immigration status, demographic data, professional licensure information and related compliance activities, accreditations and other accolades, education history (including schools attended, academic degrees or areas of study, academic performance, and rankings), and similar data, which are required for contractual or employment related matters or which are required to comply with laws and public duties.
· Specific identifiers, known as Special Personal Information, which are required in order to protect legitimate interests, comply with legal obligations or public legal duties, or in order to accommodate you in our workplaces, such as your race, disability-related information (B-BBEE related), religion (correct and fair treatment related), sexual and medical history including any medical conditions (to comply with laws and related to correct and fair treatment issues), trade union matters (to comply with laws and related to correct and fair treatment issues), and financial, credit, deviant and criminal history, (to protect our legitimate interests and to perform risk assessments), as well as children’s details (benefits related) and Biometrics such as finger prints, which are required in order to provide you with access to our facilities, give you access to our IT infrastructure, for security monitoring purposes and in order to comply with health and safety requirements in the workplace.
· Demographic Information, such as country, preferred language, age and date of birth, marriage status, gender, physical characteristics, personal or household / familial financial status and metrics, and similar data, which are required for various legitimate interests, as well as contractual and / or other legal reasons.
· Your Image, still pictures, video, voice, and other similar data, which are required in order to provide you with access to our facilities, give you access to our IT infrastructure, for security monitoring purposes as well for various public relations and corporate affairs purposes.
· Public issued Identity Information, such as government-issued identification information, tax identifiers, social security numbers, other government-issued identifiers, and similar data, which are required to comply with laws and public duties.
· Tax and Financial Information, banking details, and tax registration number and status, which are required to perform contractual matters and / to comply with tax laws and public duties.
· IT Information, including IT security-related information (including IT user names and passwords, authentication methods, and roles), and similar data, which are required for various legitimate and legal purposes.
· Health history and records, which is classified as Special Personal Information, such as medical status and history, examinations, blood type, medical aid history, disability-related information, biometrics, medicals, psychometrics and similar data, which are required for contractual or employment related matters or which are required to comply with laws and public duties.
· Social Media and Online activities and presence, such as information placed or posted in social media and online profiles, online posts, and similar data, which are required for contractual or employment related matters or which are required to comply with laws and public duties.
5. SOURCES OF INFORMATION - HOW AND WHERE DO WE COLLECT YOUR PERSONAL INFORMATION
5.1 Depending on your requirements, we will collect and obtain Personal Information about you either directly from you, from certain third parties or from other sources which are described below:
5.1.1. Direct collection: You provide Personal Information to us when you:
· interact with us;
· enquire about, or apply for a position withinContinental, including requesting or signing up for information;
· express an interest in working with us or apply for a job or position or bursary,learnership or scholarship with us;
· take up a job or position with us;
· conclude a contract with us;
· communicate with us by phone, email, chat, in person, or otherwise;
· complete a questionnaire, or other information request form.
5.1.2 Automatic collection: We collect Personal Information automatically from you when you:
· search for, visit, interact with, or use our websites, applications, mobile applications, or social media portals or platforms;
· access, use, or download content from us;
· open emails or click on links in emails or advertisements from us;
· Otherwise interact or communicate with us.
5.1.3 Collection from third parties: We collect Personal Information about you from third parties, such as:
· recruitment or employment agencies, previous employees and colleagues;
· your previous employer;
· regulators, professional or industry organizations and certification / licensure agencies that provide or publish Personal Information related to you;
· third parties and affiliates who deal with or interact with us or you;
· service providers and business partners who work with us and that we may utilize to deliver services;
· SAP, Home Affairs, Credit bureaus and other similar agencies;
· Government agencies, regulators and others who release or publish public records;
· Other publicly or generally available sources, such as social media sites, public and online websites, open databases, and data in the public domain.
6. HOW WE SHARE INFORMATION
6.1 We share Personal Information for the purposes set out in this Processing Notice with the following categories of recipients:
· Our employees, and our affiliates. We may share your Personal Information amongst our employees, affiliates and the companies within Continentalfor employment, HR, IR, business and operational purposes.
· Your Contacts and other employees. We may share your Personal Information with other Continentalemployees, with others with whom you or we have a relationship with, in order to fulfil or perform a contract or other legal obligation, including with third parties that arrange or provide us or you with goods or services.
· Business Partners and Third Party Service Providers, as well as Operators. We may share your Personal Information with our third party service providers to perform tasks on our behalf and which are related to our relationship with you, including financial, benefits, health and medical, and wellness benefits etc and to assist us in offering, providing, delivering, analyzing, administering, improving, and personalizing such services or products.
· Third Party Service Providers. We may share your Personal Information with our third party service providers to perform tasks on our behalf and to assist us in providing, delivering, analyzing, administering, improving, and personalizing services or content related to our relationship with you, including financial, benefits, health and medical, and wellness benefits etc and may to this end pass certain requests from you to these providers.
· Cyber and IT Third Party Service Providers. We may share your Personal Information with our third party cyber service and IT providers to perform tasks on our behalf and which are related to our relationship with you, including those who provide technical and/or customer support on our behalf, who provide application or software development and quality assurance, who provide tracking and reporting functions, research on user demographics, interests, and behavior, and other products or services. These third party service providers may also collect Personal Information about or from you in performing their services and/or functions. We may also pass certain requests from you to these third party service providers.
· Advertisers and PR Agencies. We may share your Personal Information with PR Agencies, advertisers, advertising exchanges, and marketing agencies that we engage for PR services and advertising services, to deliver PR services or advertising, and to assist us in promoting and advertising our brand, products and services.
· Regulators and law enforcement agencies. We may disclose your Personal Information to regulators and other bodies in order to comply with any applicable law or regulation, to comply with or respond to a legal process or law enforcement or governmental requests.We may also disclose your Personal Information in connection with proceedings or investigations anywhere in the world to third parties, such as public authorities, law enforcement agencies, regulators and third-party litigants.
· Potential sale transactors: We may provide relevant parts of your Personal Information to any potential acquirer of or investor in any part of Continental’s business for the purpose of that acquisition or investment.
· Other Disclosures. We may disclose your Personal Information to third parties if we reasonably believe that disclosure of such information is helpful or reasonably necessary to enforce our terms and conditions or other rights (including investigations of potential violations of our rights), to detect, prevent, or address fraud or security issues, or to protect against harm to the rights, property, or safety of the group, our employees, any users, or the public.
7. SECURITY OF INFORMATION
7.1 The security of your Personal Information is important to us. Taking into account the nature, scope, context, and purposes of processing Personal Information, as well as the risks to individuals of varying likelihood and severity, we have implemented technical and organizational measures designed to protect the security of Personal Information. In this regard we will conduct regular audits regarding the safety and the security of your Personal Information.
7.2 Your Personal Information will be stored electronically and in some cases in hard copy in files and records, which information, for operational reasons, will be accessible to and or provided to persons employed or contracted by us on a need to know basis.
7.3 Once your Personal Information is no longer required due to the fact that the purpose for which the Personal Information was held has come to an end, such Personal Information will be retained in accordance with our Continentalrecords retention schedule, which varies depending on the type of processing, the purpose for such processing, the business function, record classes, and record types.We calculate retention periods based upon and reserve the right to retain Personal Information for the periods that the Personal Information is needed to: (a) fulfil the purposes described in this Processing Notice, (b) meet the timelines determined or recommended by regulators, professional bodies, or associations, (c) comply with applicable laws, legal holds, and other legal obligations (including contractual obligations), and (d) comply with your requests.
7.4 Notwithstanding the contents housed under clauses 7 and 8, please note that no method of transmission over the Internet or method of electronic storage is 100% secure. Therefore, while we strive to use commercially acceptable measures designed to protect Personal Information, we cannot guarantee its absolute security.
8. ACCESS BY OTHERS AND CROSS BORDER TRANSFER
8.1 Continentalmay from time to time have to disclose your Personal Information to other parties, including Continentalsubsidiaries, trading partners, agents, auditors, organs of state, regulatory bodies and / or national governmental, provincial, or local government municipal officials, or overseas trading parties or agents, but such disclosure will always be subject to an agreement which will be concluded as between ourselves and the party to whom we are disclosing your Personal Information to, which contractually obliges the recipient of your Personal Information to comply with strict confidentiality and data security conditions.
8.2 Where Personal Information and related data is transferred to a country which is situated outside South Africa, your Personal Information will only be transferred to those countries which have similar data privacy laws in place or where the recipient of the Personal Information concludes an agreement which contractually obliges the recipient to comply with strict confidentiality and data security conditions and which in particular will be to a no lesser set of standards than those imposed by POPIA.
9. YOUR RIGHTS
9.1 You as a Data Subject you have certain rights, which are detailed below and which may be exercise by using the relevant forms housed on the CONTINENTAL Website www.continental.co.za / www.bestdrive.co.za-see Data Privacy and Access To Information page:
· The right of access - You may ask CONTINENTAL (free of charge) to confirm that we hold your Personal Information, or ask us to provide you with details, (at a fee) on how we have processed your Personal Information, which request must be done by following the process set out under the CONTINENTAL PAIA Manual.
· The right to rectification - You have the right to ask us to update or rectify any inaccurate Personal Information which we hold of yours, which can be done by accessing the update / rectification request.
· The right to erasure (the ‘right to be forgotten’) -Where any overriding legal basis or legitimate reason to process your Personal Information no longer exists, and the legal retention period in relation to the archiving of the information has expired, you may request that we delete the Personal Information, which can be done by accessing the request for erasure form.
· The right to object to and restrict further processing - Where we do not need your consent to process your Personal Information, but you are not in agreement with such processing, you may lodge an objection to such processing by accessing the objection request.
· The right to withdraw consent - Where you have provided us with consent to process your Personal Information, you have to right to subsequently withdraw your consent, which can be done by accessing the withdrawal of consent request.
· The right to data portability- Where you want your Personal Information to be transferred to another party, which can be done under certain circumstances, by accessing completing the required transfer form.
10. CHANGES TO THIS PRIVACY STATEMENT
10.1 As Continentalchanges over time, this Processing Notice is expected to change as well.
10.2 Continental reserves the right to amend the Processing Notice at any time, for any reason, and without notice to you other than the posting of the updated Processing Notice on the Continental Website.
10.3 We therefore request that you to visit our Continental website https://www.continental-tyres.co.za/car frequently in order to keep abreast with any changes.
11. COMPLIANTS OR QUERIES - CONTACT US
11.1 Any comments, questions or suggestions about this Processing Notice or our handling of your Personal Information should be emailed to firstname.lastname@example.org.
11.2 Alternatively, you can contact us at the following telephone numbers:
Information Officer details:
(1) Chifundo Ncube (Continental Tyres SA Pty Ltd)
T|041 406 5580
(2) Ms Lizelle Els (Contitech Africa Pty Ltd) (Contitech Services Pty Ltd) (Contitech South Africa Pty Ltd)
T|041 996 2041
11.3 Our telephone switchboard is open 8:00 am – 4:30 pm GMT, Monday to Friday. Our switchboard team will take a message and ensure the appropriate person responds as soon as possible.
11.4 Should you wish to discuss a complaint, please feel free to contact us using the details provided above. All complaints will be treated in a confidential manner.
11.5 Should you feel unsatisfied with our handling of your Personal Information, or about any complaint that you have made to us, you are entitled to escalate your complaint to the South African, Information Regulator who can be contacted at < https://www.justice.gov.za/inforeg/>.
12. PROCESSING OTHER PERSONS PERSONAL INFORMATION
12.1 If you process another’s Personal Information on Continental’s behalf, or which we provide to you in order to perform your contractual or legal obligations or to protect any legitimate interest, you will keep such information confidential and will not, unless authorized to do so, process, publish, make accessible, or use in any other way such Personal Informationunless in the course and scope of your duties, and only for the purpose for which the information has been received and granted to you, and related to the duties assigned to you.
13. ACCEPTANCE AND BINDING NATURE OF THIS DOCUMENT
13.1 By providing Continental with the Personal Information which we require from you as listed under this Processing Notice:
· you acknowledge that you understand why your Personal Information needs to be processed;
· you accept the terms which will apply to such processing, including the terms applicable to the transfer of such Personal Information cross border;
· where consent is required for any processing as reflected in this Processing notice, you agree that we may process this particular Personal Information.
13.2 Where you provide us with another person’s Personal Information for processing,you confirm that that you have obtained the required permission from such person (s) to provide us with their Personal Information for processing.
13.3 The rights and obligations of the parties under this Processing Notice will be binding on, and will be of benefit to, each of the parties’ successors in title and / or assigns where applicable.
13.4 Should any of the Personal Information concern or pertain to a legal entity whom you represent, you confirm that you have the necessary authority to act on behalf of such legal entity and that you have the right to provide the Personal Information and / or the required permissions in respect of the processing of that Organization or entities’ Personal Information.