EU-U.S. and Swiss-U.S. Privacy Shield Policy
Employment Background Investigations, Inc. (EBI) is committed to protecting your privacy and developing technology that gives you a powerful and safe online experience.
EBI® is a consumer reporting agency that collects personal data solely for the purposes of providing our clients with essential information required to make Fair Credit Reporting Act (FCRA) compliant screening decisions, and is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC).
Information provided by an individual may include name, date of birth, Social Security Number, Motor Vehicle Operator’s License Number, Professional License information, employment history, education and other subject information.
All data is collected, stored and delivered in compliance with applicable laws, including the Fair Credit Reporting Act (FCRA), European Union’s General Data Protection Regulation (GDPR), and other local, state and federal laws, as well as the EU-U.S. and Swiss-U.S. Privacy Shield Framework (“Privacy Shield Framework”). EBI does not process personal information in a manner incompatible with the purposes for which it has been collected, however it may be required to disclose personal information in response to lawful requests by public authorities, including meeting national security or law enforcement requirements. All individuals that are the subject of a consumer report procured by EBI have the right to access their personal data.
Consumers may elect not to submit personal information to EBI if they do not want their personal data disclosed to our client, a third party, or to be used for a purpose that is materially different from the purpose for which it was originally collected or authorized. Consent forms either from EBI or the consumer’s employer or potential employer indicate the consumer agrees to provide personally-identifying information (PII), and consent to EBI’s use of that information. With regard to sensitive information, EU or Swiss residents are given an affirmative choice whether to disclose the information to a third party or if the information will be used in a manner inconsistent with the purposes for which it has been collected or subsequently authorized by the consumer through the exercise of opt-in choice. EBI will treat as sensitive any personal information received from a third party where the party has identified it and treated it as sensitive. In addition, under the US-Swiss Privacy Shield framework sensitive data also includes ideological views or activities, information on Social Security measures or administrative or criminal proceedings and sanctions, which are treated outside pending proceedings.
Accountability for Onward Transfer
When transferring personal data to a third party acting as an agent, EBI will only (i) transfer data for limited and specified purposes consistent with the consent provided by the consumer, (ii) ascertain that the agent is obligated to provide at least the same level of privacy protection required by the Privacy Shield Framework, (iii) take reasonable and appropriate steps to ensure that the agent effectively processes the personal information transferred in a manner consistent with EBI’s obligations under the Privacy Shield Framework, (iv) require the agent to notify EBI if it makes a determination that it can no longer meet its obligation to provide the level of protection required and will take reasonable and appropriate steps to stop and remediate unauthorized processing at that time, and (v) will provide a summary or a representative copy of the relevant privacy provisions of its contract with that agent to the Department upon request.
EBI takes reasonable and appropriate precautions to protect personal information from loss, misuse and unauthorized access, disclosure, alteration and destruction. EBI takes into due account the risks involved in the processing and the nature of the personal data.
Data Integrity and Purpose Limitation
Personal information obtained by EBI is relevant for the purposes of providing our clients with information required to make employment screening decisions. EBI takes reasonable steps to ensure that data is reliable for its intended use, accurate, complete, and current. The data obtained will be retained only for as long as it serves its relevant purpose for processing of the background screening report and correlated compliance and legal considerations. If any consumer believes any information in EBI's possession is inaccurate, they should contact EBI directly to discuss correcting, amending or deleting the incorrect information.
United States residents have the right to obtain a consumer report produced or maintained by EBI once every twelve months. Information will be mailed via the United States Postal Service within seven days of the consumer’s request. European Union or Switzerland residents may also contact EBI to request a copy of their consumer report. A fee no greater than $12.50 USD may be charged to cover delivery expenses, information will be forwarded within 30 days via standard delivery methods. Consumers may contact EBI to dispute any information that they believe is inaccurate or incomplete, and EBI will conduct a reinvestigation which may result in the information being corrected, amended or deleted when found to be inaccurate or processed in violation of the Privacy Shield Framework. There is an exception to the aforementioned reinvestigation when the burden or expense of providing access would be disproportionate to the consumer’s privacy in the case in question, or where the rights of persons other than the consumer would be violated.
Recourse, Enforcement, and Liability
EU or Swiss consumers who feel that their privacy rights may have been violated should first contact the controller of their data, typically the employer or organization providing EBI with personal data. If you have any questions about who the controller may be, please contact EBI. In the event that EBI is required to and is not able to resolve the matter, EBI has committed to refer any unresolved privacy complaints under the US-EU and US-Swiss Privacy Shield Framework to an independent recourse mechanism by which consumer complaints and disputes can be investigated and resolved at no cost to the individual. The independent recourse mechanism chosen will include verification that EBI’s assertions regarding privacy practices are accurate, and remedying failure to comply with the principles.
EBI has designated the EU Data Protection Authorities (DPAs) and the Swiss Federal Data Protection and Information Commissioner (SFDPIC) as its independent recourse mechanism for dispute resolution. EBI will cooperate with the DPAs and the SFDPIC in the investigation and resolution of complaints brought under US-EU or US-Swiss Privacy Shield. EBI will comply with any direction given by the DPAs and the SFDPIC, including any specific actions to ensure compliance with the Privacy Shield Framework. It is possible, under certain conditions, for the individual to invoke binding arbitration.
EBI will respond promptly to inquiries for information relating to the Privacy Shield, and to complaints regarding compliance with the Principles referred by EU Member State authorities. If EBI was subject to a Federal Trade Commission (FTC) or court order due to non-compliance, we will make public any relevant Privacy Shield related issues.
The contact information for the EU Data Protection Authorities is available at: http://ec.europa.eu/justice/data-protection/bodies/authorities/third-countries/index_en.htm
The contact information for the Swiss Federal Data Protection and Information Commissioner (SFDPIC) is available at: http://www.edoeb.admin.ch/
To learn more about the Privacy Shield program, and to view our certification, please visit: https://www.privacyshield.gov
Contact InformationAttn: Compliance Employment Background Investigations (EBI), Inc.
700 Red Brook Blvd.
Owings Mills, MD 21117
Telephone: (800) 324-7700