GDPR & Data Protection Policy
1. Introduction
Din BemanningsPartner AS (“DB Partner”, “we”, “our”, or “us”) is committed to safeguarding the privacy and data protection rights of our candidates, employees, clients, and partners.
We process personal data in compliance with the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act, under the supervision of Datatilsynet (the Norwegian Data Protection Authority).
2. Purpose of this Policy
This policy explains how DB Partner ensures that all processing of personal data is lawful, fair, and transparent.
It complements our Privacy Policy and applies to everyone whose personal information we collect and process in our business activities.
3. Roles and Responsibilities
Data Controller:
Din BemanningsPartner AS, Falkenborgvegen 9, 7044 Trondheim, Norway
Email: info@db-partner.no
For privacy, GDPR, AI transparency or compliance-related questions, you may contact us at:
compliance@db-partner.no
Supervisory Authority:
Datatilsynet – www.datatilsynet.no
DB Partner determines the purpose and means of processing personal data.
Our trusted technology partners, including RecMan AS and Recruitee B.V., act as data processors on our behalf under written data processing agreements (DPAs).
4. Our Commitment
We follow these core GDPR principles:
- Lawfulness, fairness & transparency – We process data on valid legal bases and explain clearly how it is used.
- Purpose limitation – Data is used only for the purposes collected.
- Data minimisation – We collect only data necessary for staffing, recruitment, or employment purposes.
- Accuracy – We keep data accurate and up to date.
- Storage limitation – We retain data only as long as required by law or contract.
- Integrity & confidentiality – We protect data with appropriate technical and organisational measures.
- Accountability – We can demonstrate compliance through internal controls and documentation.
5. Data Processing Activities
Our main processing operations include:
- Candidate registration, screening, and matching
- Employment administration and payroll
- HR, training, and performance management
- Client and supplier administration
- Marketing communication (only with consent)
- Accounting, compliance, and reporting obligations
All processing is documented in our internal Data Processing Register.
6. Legal Bases for Processing
We rely on one or more of the following GDPR legal bases:
- Contract performance – necessary to enter into or fulfil an employment or staffing contract.
- Legal obligation – to meet obligations under Norwegian labour, tax, or accounting laws.
- Legitimate interest – to operate and improve our recruitment services responsibly.
- Consent – for specific processing such as storing candidate data beyond 12 months or sending newsletters.
7. Data Sharing and Processors
We share data only when necessary and only with GDPR-compliant partners:
| Partner | Purpose | Location |
|---|---|---|
| Recruitee B.V. | Job application & talent management platform | Netherlands (EU) |
| RecMan AS | HR, payroll, recruitment & candidate management | Norway (EEA) |
| Accounting, IT & Cloud providers | Administration, secure communication | EU/EEA(Norway) |
Each partner operates under a written Data Processing Agreement and ensures EU/EEA data hosting.
DB Partner may and use trusted processors and service providers such as RecMan, Recruitee, Microsoft 365, payroll/accounting/IT providers, hosting/cloud providers and other approved suppliers where necessary for recruitment, staffing, employment administration, payroll preparation, communication, compliance and secure operations.
8. Data Protection by Design and Default
DB Partner implements privacy and security measures from the start of any new project or system, including:
- Limited data access (role-based permissions)
- Encryption and secure storage
- Regular backups and recovery procedures
- Two-factor authentication
- Regular audits and risk assessments
9. AI Governance and Automated Assistance
DB Partner may use approved AI-assisted tools to support recruitment, staffing, administration, communication, internal operations, document handling, payroll preparation and quality control.
AI-assisted tools may include, depending on the context, Microsoft 365/Copilot, RecMan, Recruitee, Aporetic/DB Partner Hub and other approved systems. DB Partner Hub is an internal system used only by authorised DB Partner personnel and is not a candidate-facing portal.
DB Partner applies the following controls for AI-assisted processing:
- AI is used to support employees, not to replace human responsibility.
- Final decisions that may significantly affect candidates, employees or workers are reviewed and made by people.
- DB Partner does not use AI to make fully automated final decisions about hiring, rejection, work assignment, pay, disciplinary matters, termination or other significant employment-related outcomes without human involvement.
- AI-assisted tools are documented in DB Partner’s internal AI System Inventory.
- Suppliers and systems are documented in DB Partner’s Vendor and Data Processor Register.
- Higher-risk AI use cases are assessed before deployment, including whether a Data Protection Impact Assessment or additional review is required.
- Access to systems and personal data is managed through role-based permissions and internal security controls.
- Employees and candidates are informed about relevant AI-assisted processing through DB Partner’s Privacy Policy and AI Transparency Notice.
- Employee-facing or candidate-facing AI tools are subject to review before launch and must have appropriate transparency, access control and human escalation safeguards.
More information is available in our AI Transparency Notice
10. Data Subject Rights
Every individual whose data we process has the right to:
- Request access to their personal data
- Request correction or deletion
- Restrict or object to processing
- Data portability (where applicable)
- Withdraw consent at any time
All requests can be sent to info@db-partner.no
.
We will respond within 30 days in accordance with GDPR Article 12.
11. Data Retention
We apply controlled retention periods:
| Category | Retention Period | Legal Basis |
|---|---|---|
| Candidate data | 12 months after last activity (or longer with consent) | Legitimate interest / consent |
| Employee records | As required by Norwegian law (typically up to 5 years after employment ends) | Legal obligation |
| Client & supplier data | Duration of contract + 5 years for bookkeeping purposes | Legal obligation |
| Marketing contacts | Until consent is withdrawn | Consent |
12. International Data Transfers
We store and process personal data within the EU/EEA.
If data must be transferred outside this area, we ensure appropriate safeguards, such as EU Standard Contractual Clauses or equivalent legal frameworks.
13. Data Breach Management
In the unlikely event of a data breach:
- The incident will be logged and assessed immediately.
- If the breach poses a risk to individuals, Datatilsynet will be notified within 72 hours.
- Affected individuals will be informed promptly when there is a significant risk.
DB Partner maintains an internal Incident Response Plan for such cases.
14. Training and Awareness
All employees receive onboarding and annual training on:
- GDPR principles and responsibilities
- Data handling and security
- Ethical and confidentiality standards
15. Monitoring and Review
This policy is reviewed annually or whenever there are major changes in legislation or business operations.
Updates are approved by management and communicated to all staff.
16. Contact us
Questions, concerns, or complaints about our data protection practices may be directed to:
DB Partner – Din BemanningsPartner AS
Falkenborgvegen 9, 7044 Trondheim, Norway
info@db-partner.no