Please click here if you would like to read this page in German.

Global Data Privacy Notice 
Contingent Workforce Management in Fieldglass

1. Purpose

This Global Data Privacy Notice provides information about the processing of Personal Data  with respect to Contingent Workforce Management via the Vendor Management System (VMS),  Fieldglass.  

2. Scope  

Subject to the sections below, this Global Data Privacy Notice applies to Data Subjects whose data are processed in the VMS, Fieldglass.  

The Notice applies if Personal Data of Data Subjects are processed by any legal entities within the Roche Group that are located in the European Economic Area(EEA) and Switzerland as well as legal entities that are not in the EEA or Switzerland but process personal data of Data Subjects in the EEA and Switzerland. 


3. Identity and contact details of the data controller

FF. Hoffmann-La Roche Ltd, Grenzacherstrasse 124, CH-4070 Basel, Switzerland, email: global.privacy@roche.com (“Roche”) is data controller. 

In the event that your personal data is covered by the EU General Data Protection Regulation (EU) 2016/679 (“GDPR”): EU representative of F. Hoffmann-La Roche Ltd is Roche Privacy GmbH, Emil-Barell-Str. 1, D-79639 Grenzach-Wyhlen.

In addition, personal data will be forwarded to the specific company offering the vacancy. Details of the arrangement can be requested from the controllers. The identity and contact details of said company will be provided by or can be obtained from the supplier.

Please direct any questions and requests related to this information to F. Hoffmann-La Roche Ltd, Global Privacy Office, Grenzacherstrasse 124, CH-4070 Basel, Switzerland, email: 

global.privacy@roche.com.

4. Legal Basis  

For the Management of Contingent Workforce (Contractors) via the VMS, Fieldglass, Roche has a legitimate interest for processing Personal Data that enables identifying the most  suitable candidates for the performance of an engagement, in an effective and efficient manner. Being able to access data in a timely manner improves the overall experience for Job Candidates wishing to be engaged as Contingent Workers at Roche, minimizing processing times and improving efficiencies along the process.  

Once the Job Candidate is engaged and becomes a Contractor, Personal Data will be  processed for the fulfillment of contract obligations and to comply with legal requirements.


5. Personal Data in relation to Contingent Workforce Management in Fieldglass 
  
5.1. Types of Personal Data collected 

  • Job Candidate data (Job Seeker): In order to assess suitability to Roche’s engagement opportunities candidate’s personal data is collected. This collection is done via  the corresponding Staffing Agency and/or Employer of the candidate in a lawful and legitimate way, such as in accordance with appropriate consent. Further, the corresponding Staffing Agency and/or Employer of the candidate shall ensure that all information required by applicable Data Protection Laws is provided to Data Subjects. 
     
    The details collected are:
    • Full Name
    • Contact information (including address)
    • Birth of date
    • Educational background
    • Employment History
    • Qualifications
    • Interests 
    • Photograph
   
  • Contractors data: In order to manage the engagement with contingent workers, Roche collects and processes the following additional information to the candidate’s personal data:    
    • Job Title
    • Salary information 
    • Work address 
    • Time management data 
    • Engagement feedback
    • Emergency contact

  • Supplier Data: Basic supplier information is required to carry out contractual  obligations. While every supplier can control the information they store and share  in Fieldglass, the details requested and processed by Roche are details of a delegated contact person: Name, job title, work email and work telephone.  

5.2. How is Personal Data collected?

  • Job Candidate data (Job Seeker): All details are provided by the corresponding Staffing Agency and/or Employer of the candidate, who must hold written consent from the candidate for sharing the data with Roche, and for uploading the Data into SAP Fieldglass. 
  • Contractors data: Data is generated by Roche or suppliers as per contractual agreement. Time management data is obtained via time keeping system where available, or entered directly in Fieldglass by the contractors.  
  • Supplier Data: Data is entered directly and managed by the supplier in their instance of the Fieldglass application.  


5.3. How is Personal Data used?  

  • Job Candidate data: The collected information is processed as part of the  recruitment process of the contingent worker. It is reviewed by the relevant  individuals in the organization to assess suitability of candidates to the roles  Roche requires fulfilling with contractors.  
  • Contractors data: The collected information is processed to manage the  engagement with contingent workers, enabling time management and  corresponding payment of the relevant fees. This information is processed in  accordance with the relevant labor laws.  
  • Supplier Data: The collected information is processed to fulfill our contractual  obligations, and to interact with suppliers by designated contact person.  

5.4. Who is Data Shared with?  

Data is shared within the Roche group and with third party vendors, consultants and other  service providers that help us in the management of Contingent Workforce and operating our  IT systems. These companies provide work and services such as information technology and  related infrastructure provision, data analysis and insight, auditing and other similar services.  In some cases, these companies need access to some of your Personal Data in order to carry  out their work for us. They are not permitted to use your Personal Data for their own purposes.

Roche’s Data Processors are: 
  • Fieldglass Inc
    • Types of service: Access Management, Business Continuity, Collection, Customer Services, Deletion, Hosting, Late Stage IT System Development, Maintenance, Quality Assurance, Reporting, Service, Support, Surveys & Testing
    • Location: main location Germany, support may be provided from countries outside the European Union
  • Hays Talent Solutions (Switzerland) LTD
    • Types of Service: Collection, Statistics, Surveys & Testing
    • Location: Switzerland
  • Germany: Hays Talent Solutions GmbH
    • Types of Service: Collection, Statistics, Surveys & Testing
    • Location: Germany
  • US & Kanada: PRO Unlimited Inc.
    • Types of Service: Collection, Statistics, Surveys & Testing
    • Location: USA

Data of Contingent Workforce in contact with European Roche Affiliates is stored in Fieldglass  Data Centers located in the European Union. Your Personal Data may be transferred to, used, processed or stored in other countries where Roche operates, including jurisdictions that may not have data privacy laws that provide an equivalent data protection as those provided in your home country. 

If your Personal Data is covered by the GDPR: for transfers of Personal Data to a third country outside the European Union (EU), European Economic Area (EEA) or in absence of an adequacy decision, within the Roche Group, business partners and service providers, we establish the contracts containing the EU Standard Contractual Clauses, which according to the EU Commission decisions of 27 December 2004 (2004/915/EC) and 05 February 2010 (C(2010)593) or according to EU Commission decision of 04 June 2021 (EU 2021/914), whichever is applicable, constitute appropriate and suitable safeguards to ensure compliance with GDPR. For more information and a copy of the EU Standard Contractual Clauses, please contact us using the contact details above. 


5.5. Data Safeguarding

Measures for protecting and limiting access to and misuse of Personal Data are in place in the  Fieldglass system, including but not limited to secured servers, passwords, role settings and back-ups.  

5.6. Data Retention 

Job Candidates data will be retained for 3 years following the last update of data.  

In case a Job Candidate is hired (Contractor), data will be retained in accordance with tax, and other laws retention rules, which vary from country to country. 


6. Data Subjects Rights 
 
6.1. Legal background

Under the GDPR and other applicable Data Protection laws, you may place requests with Roche to execute the following rights: 
  • You have the right to learn about the processing of your personal data and obtain  a copy of the personal data (“right of access”); 
  • You have the right to have inaccuracies or incompleteness in your personal data rectified (“right of rectification”); 
  • You have the right to have your personal data erased  (“right of erasure”) if and to the extent the processing of personal data is based on consent or legitimate interest;
  • You have the right to restrict or object to how the personal data is collected, used, disclosed, retained, analyzed, profiled, or otherwise  processed (“right of restriction of processing”), if and to the extent the processing of personal data is based on consent or legitimate interest;
  • In certain circumstances, you have the right to receive personal data you originally provided in a structured format (“right of data portability”); 
  • You have the right to object to your personal data being used for direct marketing purposes (“right to object”)

Data Subjects have the right to lodge a complaint: In case that you have the  impression that Roche violates EU data protection laws, if and to the extent applicable, you have the right to lodge a complaint with the responsible data protection authority. A  list of the data protection authorities of the EU member states can be found here:    http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm 

Please note the above listed rights are not absolute and may be restricted by a range of legal  exemptions.  

Please note further that in cases where GDPR does not apply, applicable local law may  entitle Data Subject to similar, if not the same, rights.  

 
6.2. Exercise of Rights

To exercise the rights mentioned in 6.1 above, Data Subjects may contact the privacy officer of the data controller at global.privacy@roche.com .