Privacy Policy & GDPR Notice

Paul Mitchell Associates and its employees (“PMA”, “we” or “us”) take the privacy of our Clients and Candidates (“you” or “your”) very seriously.

PMA acknowledge and agree that all data processed is done so in accordance with the Data Protection Act 1998 and from 25th May 2018, the General Data Protection Regulations (GDPR).


The purpose of this GDPR Notice is to inform you of the following:

  • What data we hold
  • Why we hold your data
  • How we may use or disclose your data
  • How long we hold data for
  • Data storage
  • Your rights
  • Data breaches


What Data We Hold:

We will hold some or all of the data below upon agreeing to engage our services.


If you do NOT consent to PMA storing your personal data or setting up a personal registration for you, please do NOT submit your CV for any roles advertised by us on our website or third party job board. We are unable to process your application without your consent.



  • Your Name
  • Your Address
  • Your Email Address
  • Your Telephone Number(s)
  • D.O.B.
  • CV / Employment History
  • ** Identification Documentation: (including but not limited to: Passport, VISA, Proof of Address, Proof of National Insurance and Driving Licence)
  • Registration Documentation: References, **Referees, **Proof of Qualifications, **Health / Emergency Contact Information
  • ** Financial Information: (including but not limited to: bank details, payroll data and HMRC data)
  • ** Criminal Record Checks and Security Clearance for certain roles
  • A log of our communications with you (email, face to face and telephone)
  • CV Submissions, Interviews, Placements and Job Offers
  • Job Preferences: (including but not limited to: Salary, Role and Locations)
  • Photograph

NB: If you provide PMA with information for third parties (Referees / Emergency Contact Details), PMA will assume that the third party in question has given you permission to do so and for PMA to collect, process and store their Personal Data to the same extent as yours.

** Sensitive Personal Data


Prospective Clients & Clients:

  • Your Name
  • Your company email address
  • Your company telephone number(s)
  • A log of our communications with you (letter, email, face to face and telephone).


Why We Hold Your Data & How We Will Use or Disclose Your Data:

Paul Mitchell Associates may hold personal data on individuals for the following reasons:



  • To match your skill sets with specific job vacancies
  • To submit your CV / details to our clients and your prospective employers
  • To place you in temporary / contract / permanent employment
  • To keep you informed of job opportunities
  • To keep you informed of our services
  • To comply with recruitment / employment / HMRC law and legislation
  • To provide contractual arrangements and documentation relating to a job offer
  • To pay you if placed in a temporary job via PMA
  • To establish that you have the right to work
  • To deal with any medical / health and safety issues in the workplace
  • To undertake relevant security / criminal record checks if required by our Client
  • We may share your data with trusted third parties as follows: HMRC, Pension Scheme Providers, Legal Advisors, Barclays Bank and other companies for the purpose of undertaking pre-employment checks for the job or for paying you.


Prospective Clients & Clients:

  • To contact you via phone, email, text and letter relating to recruitment services
  • For Advertising, Marketing and PR
  • To supply you with recruitment services
  • To submit work-seekers CV’s / details for specific job vacancies
  • To supply or introduce temporary / contract / permanent work-seekers
  • To invoice your company for recruitment services on successful placements
  • To comply with recruitment / employment / HMRC law and legislation


How Long We Hold Your Data For:

All businesses must keep personnel and financial records in order to run their business efficiently and to comply with statutory requirements. The type of record will determine the length of time the record must be kept for. (Record Keeping Time Scales)


Candidate Records:

As a recruitment agency our relationship with candidates can span years with multiple job placements throughout a candidates career. Under legitimate interest, your consent will allow us to store your Personal Data until such a time you wish to be removed from our records. This does not affect your right to be “Forgotten” at any time.


PMA will be in touch with you periodically to ascertain how to mark your record. You will have the following options: 

  • LIVE – Seeking employment and open to contact
  • INACTIVE – Not seeking employment but keep me on file with periodical contact
  • STOP – Keep me on file but do not contact me
  • FORGET – Erase all of my data*

NB: *Where we have placed / employed a candidate in a job, we are required to retain evidence of that placement for administrative, accounting and contractual purposes. PMA will however take the required steps to ensure minimal personal data is retained and will not make any further contact unless legally required to do so. (Record Keeping Time Scales)

If we have had no contact with you within 12 months we will make your file “INACTIVE” and delete all Sensitive Personal Data**. Should you become a “LIVE” job-seeker in the future you will be required to provide this information / proof again.


Prospective Clients & Clients:

Due to the nature of recruitment Paul Mitchell Associates will hold Clients and Prospective Clients data indefinitely for administrative purposes under legitimate interest. This will not affect your right as a contact to be “Forgotten”. In order to be “Forgotten” and receive no further contact from PMA please email


Data storage:

We take the security of your data seriously. We have internal policies and controls in place to ensure that your data is not lost, accidentally destroyed and is not accessed by unauthorised third parties.

If you require further information on how your data is stored and managed you can request a copy of our Data Storage & Management Policy from


Your Rights:

As a data subject you have the following rights:

  • Access to obtain a copy of the data we hold for you.
  • Ability to request updates / alterations of your data.
  • Alter how we contact you.
  • Request to be “Forgotten” (deleted) from our database.*
  • Object to the processing of your data where PMA is relying on legitimate interest as the legal ground for processing.

If you would like to exercise any of these rights, please contact Once PMA have verified your identity we will provide / amend / delete the information you have requested within 30 days.

If you believe that PMA has not complied with your data protection rights, you can complain to the Information Commissioner.


Data Breaches:

PMA will treat any data breach as a serious incident and will conduct a thorough internal investigation and will notify the affected parties and the Information Commissioners office within 72 hours.

Paul Mitchell Associates ICO Reference: Z9844382


Complaints or Queries

If you wish to complain about this privacy notice or any of the procedures set out in it please contact:

Data Protection Officer: Paul Mitchell

Data Protection Administrator: Charlotte Mitchell

You also have the right to raise concerns with Information Commissioner’s Office on 0303 123 1113 or at, or any other relevant supervisory authority should your personal data be processed outside of the UK, if you believe that your data protection rights have not been adhered to.