Data Privacy Statement – How Rio Tinto Handles Your Personal Data

When you apply for a job or update your profile using CSOD (“Cornerstone”) we will collect personal data about you. Please take the time to read this Privacy Statement. We ask that you consent to the terms of this Privacy Statement before you provide any personal data to either SmashFly or Cornerstone, depending on the recruitment path you have followed

A Glossary has been included at the end which defines terms that are written in red.

1. Who am I sending my personal data to?

Rio Tinto plc is the data controller for the platform. It is responsible for ensuring that the personal data collected through the platform is protected and processed in accordance with this Privacy Statement and applicable data protection and privacy laws. The Rio Tinto Group company you have applied to work for will also be a data controller with respect to your personal data.

2. What personal data is processed?

When you apply for a job at Rio Tinto, or when you set up a profile so that you can receive job alerts, we will ask for personal data that identifies you (including your name and contact information) and for your Curriculum Vitae (CV or resume) (including information about your education, training, work experience and employment history). You can also choose to provide personal data relating to your achievements and languages spoken. As outlined at section 3 below, this is so we can consider you for the job you have applied for or for future job opportunities. It will also help us to plan future recruitment at Rio Tinto.

3. Why is personal data processed?

We collect and otherwise process personal data for the purpose of filling employment vacancies, to pursue Rio Tinto’s business interests in relation to recruitment planning and to meet legal, regulatory and compliance obligations.

As a job applicant, we will process your personal data to assess your suitability for a job you have applied for, and to match you with other job vacancies in the Rio Tinto Group. If you keep your profile up to date, this also helps us to ensure that your current skills can be considered for opportunities at Rio Tinto as they arise. Sometimes we need to collect certain types of personal data to comply with our legal obligations, and if that’s the case, that will be explained to you when it is requested.

We’ll collect personal data from you when you complete forms or upload documents to this platform, when you are applying for a job or updating your profile. Later in the recruitment process we may also request additional personal data (in compliance with applicable laws), including for the purposes of confirming your eligibility to work, and checking your qualifications and references.

4. Will my personal data be disclosed?

We will share your personal data within the Rio Tinto Group with staff involved in the recruitment process.

We will also share your personal data with external service providers who help us to carry out our recruitment and HR functions and other support functions (e.g. helping us to match profiles with job vacancies, or providing technical support, or conducting surveys). The Cornerstone platform (which is used by this platform) is operated by Cornerstone. Surveys will be conducted by Typeform SL, our external service provider.

Sometimes at the end of a recruitment process, and in compliance with applicable laws, we may seek your consent to disclose your personal data to third parties who assist us with our compliance obligations (in relation to the job you are being engaged to perform). We may also need to disclose your personal data if we are under a legal obligation to do so (e.g. responding to a court order).

5. Additional information about transfers of personal data and data retention

As the Rio Tinto Group operates globally, from time to time we need to disclose personal data across national borders (for the purposes described in this Privacy Statement). Where we do so, we take steps intended to ensure that such disclosures are adequately protected and comply with applicable laws. This includes disclosures:
• within the Rio Tinto Group (e.g. if you apply for a job in Australia, your application will be processed by Rio Tinto companies in both India and Australia); and
• to external service providers:

Cornerstone on Demand Limited
4 Colemanstreet, London, EC2R 5AR, United Kingdom
1601 Cloverfield Blvd, Suite 600 South, Santa Monica, CA 90404, United States

SmashFly Technologies Inc.
9 Pond Lane, Suite 3A3, Concord, MA 01742

TYPEFORM SL
c/ Bac de Roda, 163 (local), 08018 – Barcelona (Spain)

In each case, the data recipient may be in a country that does not have laws offering the same level of protection of personal data as the laws that apply in the country where you are located, or where your personal data may be accessible by government agencies. To address this, contractual protections have been put in place that are intended to ensure transfers national borders (or out of the European Economic Area) are adequately protected. More information about this (including the countries where Rio Tinto operates and the locations of its key external service providers) is contained in Rio Tinto’s Data Privacy Standard. By ticking the relevant consent box, you are understood to consent to any such transfers.

Personal data will only be processed for as long as this is required for the purposes it was collected for or for the time required or authorised by law. Also, as explained at section 7 below, you can choose to remove your profile.

6. What are my privacy rights?

You have rights to seek access to your personal data and to correct it, and in some cases to seek its erasure (see more under section 7 below). You also have the right to seek information about how your personal data is being processed and where, to object to its processing in some circumstances, and to make complaints about data processing. More information about how to exercise your rights is contained Rio Tinto Data Privacy Standard. You can also contact Rio Tinto’s global data privacy team, by emailing: aske&i@riotinto.com, using Data Privacy Request in the subject line, should you have any questions about the processing your personal data or about the exercise of your rights as a data subject.

You are encouraged to keep your profile up to date – and you don’t need to make a correction request to do that. You can simply log on and edit your profile yourself.

7. How do I unsubscribe or remove my profile?

With your consent, we also use your personal data to communicate with you and to provide you with information about opportunities within the Rio Tinto Group (see below). You can opt out from receiving information about Rio Tinto employment opportunities at any time by emailing recruitment.support@riotinto.com or by using the unsubscribe functions in emails that you receive. At any time, you can request for your profile to be removed and for you to no longer to be considered for employment. In some countries we may be required by law to hold personal data for a prescribed period, and in such circumstances we will delete your profile as soon as we are legally permitted to do so.

8. Profiling and data analytics

Where permitted by local law, Rio Tinto may use data analytics for the purposes of administering and managing its recruitment processes, including planning future recruitment.

This may involve the use of analytics or automated processing to identify potentially suitable job applicant profiles for recruitment processes.
However please be aware that Rio Tinto recruitment decisions are not made solely using data analytics or other automated processing; HR staff members and the line management for the relevant position review candidate profiles and make recruitment decisions.

9. Online privacy and cookies

When you use the platform, we collect your IP address and information about your operating system and browser type. We also collect information about traffic on the platform and other communication data. We do this to for system administration and statistical purposes (including so that we can continue to improve the platform by knowing which parts of the platform are of most interest to visitors).
We also use cookies on the platform, again to help us to understand the use of the platform. There is detailed information about the use of cookies on Rio Tinto platforms here.
The personal data you provide to this Platform will be transmitted over the internet and unfortunately, internet transmissions are not completely secure. Once received, we will take reasonable steps to protect your personal data, but we cannot guarantee the security of your data while it is being transmitted. Also, if you follow links from this platform to other platforms, please check the privacy policies of those platforms before you provide any personal data to them.

CONFIRMATION AND CONSENT

I confirm that the statements made by me in my profile and any job application (including supporting documents) are true and complete. I understand and agree that a false statement may disqualify me from employment, or after employment, may result in disciplinary action (to the extent permitted under applicable law).

I have read and understood this Privacy Statement and consent to the processing of my personal data in accordance with this Privacy Statement. In particular, I consent to the processing of my personal data for the purposes described in this Statement, the disclosure of my personal data within the Rio Tinto Group and to Rio Tinto’s external service providers in accordance with sections 4 and 5 (including where this involves disclosures across national borders or out of the EEA).[ ] Yes, I consent to the processing of my personal data in accordance with this Privacy Statement[ ] No, I do not consent to the processing of my personal data in accordance with this Privacy Statement.*

*Please note that if you do not consent, we cannot accept your job application or your profile. Also, if you decide to withdraw your consent later, we may need to remove you from the relevant recruitment process and also remove your profile in accordance with section 7.

GLOSSARY

Personal data means all information relating to an identifiable individual. It includes your name, contact details and the information that you include in your profile.
Processing includes anything that can be done with personal data, including its collection, use, disclosure, transfer, storage, retrieval, amendment and deletion.
Rio Tinto Limited is a company registered in Australia with company number ACN 004 458 404 and registered office at 360 Collins Street, Melbourne, Australia 3000.
Rio Tinto plc is a company registered in England and Wales with company number 00719885 and registered office at 2 Eastbourne Terrace, London, W2 6LG.
Rio Tinto Group means all businesses which are wholly or majority owned or managed by Rio Tinto plc or Rio Tinto Limited. See this link for the list of EEA/Swiss Employers (Data Controllers)

header shadow