Data Protection & RTW Vault Compliance Hub

Compliance built into every hire

RecruitCommis is designed to meet the employment, data protection, and right-to-work requirements of every region we operate in. This hub provides detailed, trust-building documentation for employers, candidates, and compliance teams.

RecruitCommis Ltd

Company Number
17458604
ICO Registration
ZC248642
Data Protection Officer
privacy@recruitcommis.com

Registered in England and Wales. Registered office: 82A James Carter Road, Mildenhall, Bury St. Edmunds, IP28 7DE.

Submit a data protection request

Documents stored privately, every view logged

AES-256 encrypted document storage with full access logging

ICO reg. ZC248642

Registered with the Information Commissioner's Office

Multi-Region

5 compliance regions supported

Regional compliance overview

A summary of the regulations, right-to-work requirements, and retention rules in each operating region.

RegionRegulationRight-to-WorkRetention
UKUnited KingdomUK GDPR & Data Protection Act 2018Right-to-Work checks per Home Office guidanceRTW documents retained 2 years post-employment
EUEurope (EU/EEA)EU GDPRExplicit GDPR consent before processingData retained per member state requirements
USUnited StatesCCPA/CPRA & state privacy lawsI-9 verification within 3 business daysI-9 forms retained 3 years after hire or 1 year after termination
CACanadaPIPEDASocial Insurance Number verificationPer provincial requirements
GCCGCCSaudi PDPL, UAE Data Protection Law, Qatar PDPPL, BahrainVisa and labour card verificationPer local labour law requirements
APACAustralia & New ZealandPrivacy Act 1988 (AU) APPs & Privacy Act 2020 (NZ) IPPsVEVO (AU) / VisaView (NZ) Right-to-Work alignmentPer Fair Work and MOM guidelines

Detailed regional compliance

Expand each region for a full breakdown of data subject rights, consent models, and right-to-work alignment.

RTW Document Security Vault

How we protect right-to-work documents

Uploaded passports, hygiene certificates, and IDs are stored in private, AES-256 encrypted Supabase Storage buckets with strict role-based access controls and full audit logging. Here is the technical breakdown.

AES-256 Encryption at Rest

All uploaded documents are encrypted with AES-256-GCM before being written to storage. Encryption keys are managed via Supabase Vault and rotated quarterly.

Role-Based Access Control with Step-Up

Documents are only accessible to designated individuals at the venue that received the application — not to every team member, and not to RecruitCommis staff. Access requires passkey or authentication-code step-up authentication, creating a short-lived vault session. No RecruitCommis employee can view document contents. Every access grant and revocation is logged.

Full Access Logging

Every read, download, and metadata query on the vault is logged with timestamp, user ID, IP address, and document reference. Logs are retained for 12 months and are available for audit.

Private Storage Buckets

Documents are stored in private Supabase Storage buckets that are not publicly accessible. Access is mediated through signed, time-limited URLs generated server-side - never direct public links. Right-to-work document URLs expire after 120 seconds and are single-use.

Regional Data Residency

In regions with data sovereignty requirements (e.g., GCC), documents are stored in-region and are not replicated to other jurisdictions. Cross-border transfers require explicit legal safeguards.

Automated Retention & Deletion

Documents are automatically deleted after the legally required retention period expires. Deletion is irreversible and logged. Candidates can also request early deletion at any time.

Document lifecycle

1

Upload with consent

Candidate uploads document after accepting a dedicated consent prompt. Document is encrypted client-side before transmission.

2

AES-256 encryption at rest

Document is stored in a private Supabase Storage bucket with AES-256-GCM encryption. Keys are managed via Supabase Vault with quarterly rotation.

3

Role-based access with step-up

Only designated individuals can access right-to-work documents, and only after passkey or authentication code step-up. Signed URLs expire after 120 seconds and are single-use.

4

Full access logging

Every read, download, and metadata query is logged with timestamp, user ID, purpose, and document reference. Logs retained for 12 months. Candidates can see who accessed their documents, self-serve.

5

Automated retention & deletion

Document is automatically deleted after the legally required retention period. Deletion is irreversible and logged. Candidates can request early deletion.

Need a compliance question answered?

Our compliance team can help with region-specific requirements, DPAs, and audit documentation.

    How can we serve you?