Compliance built into every hire
RecruitCommis is designed to meet the employment, data protection, and right-to-work requirements of every region we operate in. This hub provides detailed, trust-building documentation for employers, candidates, and compliance teams.
RecruitCommis Ltd
- Company Number
- 17458604
- ICO Registration
- ZC248642
- Data Protection Officer
- privacy@recruitcommis.com
- Support
- support@recruitcommis.com
Registered in England and Wales. Registered office: 82A James Carter Road, Mildenhall, Bury St. Edmunds, IP28 7DE.
Submit a data protection requestDocuments stored privately, every view logged
AES-256 encrypted document storage with full access logging
ICO reg. ZC248642
Registered with the Information Commissioner's Office
Multi-Region
5 compliance regions supported
Regional compliance overview
A summary of the regulations, right-to-work requirements, and retention rules in each operating region.
| Region | Regulation | Right-to-Work | Retention |
|---|---|---|---|
| UKUnited Kingdom | UK GDPR & Data Protection Act 2018 | Right-to-Work checks per Home Office guidance | RTW documents retained 2 years post-employment |
| EUEurope (EU/EEA) | EU GDPR | Explicit GDPR consent before processing | Data retained per member state requirements |
| USUnited States | CCPA/CPRA & state privacy laws | I-9 verification within 3 business days | I-9 forms retained 3 years after hire or 1 year after termination |
| CACanada | PIPEDA | Social Insurance Number verification | Per provincial requirements |
| GCCGCC | Saudi PDPL, UAE Data Protection Law, Qatar PDPPL, Bahrain | Visa and labour card verification | Per local labour law requirements |
| APACAustralia & New Zealand | Privacy Act 1988 (AU) APPs & Privacy Act 2020 (NZ) IPPs | VEVO (AU) / VisaView (NZ) Right-to-Work alignment | Per Fair Work and MOM guidelines |
Detailed regional compliance
Expand each region for a full breakdown of data subject rights, consent models, and right-to-work alignment.
How we protect right-to-work documents
Uploaded passports, hygiene certificates, and IDs are stored in private, AES-256 encrypted Supabase Storage buckets with strict role-based access controls and full audit logging. Here is the technical breakdown.
AES-256 Encryption at Rest
All uploaded documents are encrypted with AES-256-GCM before being written to storage. Encryption keys are managed via Supabase Vault and rotated quarterly.
Role-Based Access Control with Step-Up
Documents are only accessible to designated individuals at the venue that received the application — not to every team member, and not to RecruitCommis staff. Access requires passkey or authentication-code step-up authentication, creating a short-lived vault session. No RecruitCommis employee can view document contents. Every access grant and revocation is logged.
Full Access Logging
Every read, download, and metadata query on the vault is logged with timestamp, user ID, IP address, and document reference. Logs are retained for 12 months and are available for audit.
Private Storage Buckets
Documents are stored in private Supabase Storage buckets that are not publicly accessible. Access is mediated through signed, time-limited URLs generated server-side - never direct public links. Right-to-work document URLs expire after 120 seconds and are single-use.
Regional Data Residency
In regions with data sovereignty requirements (e.g., GCC), documents are stored in-region and are not replicated to other jurisdictions. Cross-border transfers require explicit legal safeguards.
Automated Retention & Deletion
Documents are automatically deleted after the legally required retention period expires. Deletion is irreversible and logged. Candidates can also request early deletion at any time.
Document lifecycle
Upload with consent
Candidate uploads document after accepting a dedicated consent prompt. Document is encrypted client-side before transmission.
AES-256 encryption at rest
Document is stored in a private Supabase Storage bucket with AES-256-GCM encryption. Keys are managed via Supabase Vault with quarterly rotation.
Role-based access with step-up
Only designated individuals can access right-to-work documents, and only after passkey or authentication code step-up. Signed URLs expire after 120 seconds and are single-use.
Full access logging
Every read, download, and metadata query is logged with timestamp, user ID, purpose, and document reference. Logs retained for 12 months. Candidates can see who accessed their documents, self-serve.
Automated retention & deletion
Document is automatically deleted after the legally required retention period. Deletion is irreversible and logged. Candidates can request early deletion.