This page is provided for general company policy information. It should be read alongside Greystone Labour Ltd's Privacy Policy, Cookie Policy, Terms & Conditions and any worker/client agreements that apply.
Greystone Labour Information Security Policy
1. Purpose
The purpose of this policy is to ensure that information security requirements are integrated into the recruitment process to reduce the risk of employing individuals who may pose a security risk and to protect Greystone Labour Ltd's information assets.
2. Scope
This policy applies to:
All permanent, temporary, contract, and internship positions.
Human Resources (HR) personnel.
Hiring managers.
Recruitment agencies acting on behalf of Greystone Labour Ltd.
3. Policy Statement
Greystone Labour Ltd shall implement appropriate screening, confidentiality, and awareness measures during recruitment to ensure that employees and contractors understand their information security responsibilities before accessing Greystone Labour Ltdal information and systems.
4. Roles and Responsibilities
Human Resources
Conduct recruitment in accordance with this policy.
Coordinate background verification where legally permitted.
Ensure employment contracts include information security clauses.
Hiring Managers
Define security requirements for each role.
Ensure appropriate access levels are assigned based on job responsibilities.
Information Security Team
Advise HR on security requirements for sensitive positions.
Provide security awareness materials for new employees.
5. Recruitment Screening
Greystone Labour Ltd shall perform appropriate pre-employment screening based on:
Identity verification.
Employment history verification.
Education and professional qualification verification.
Reference checks.
Criminal record checks where permitted by law and appropriate for the role.
Right-to-work verification.
The extent of screening shall be proportionate to the role and associated information security risks.
6. Confidentiality Requirements
All successful candidates shall:
Sign a confidentiality or non-disclosure agreement (NDA), where applicable.
Agree to comply with Greystone Labour Ltd's Information Security Policy.
Understand their responsibilities regarding confidential information.
7. Employment Contracts
Employment contracts shall include:
Information security responsibilities.
Confidentiality obligations.
Acceptable use of Greystone Labour Ltdal systems.
Intellectual property requirements.
Consequences of policy violations.
Responsibilities upon termination of employment.
8. Security Awareness
Before being granted access to Greystone Labour Ltdal systems, new employees shall:
Complete mandatory information security awareness training.
Acknowledge relevant information security policies.
Understand reporting procedures for security incidents.
9. Access Control
Access to Greystone Labour Ltdal information and systems shall:
Be granted only after successful completion of recruitment and onboarding requirements.
Follow the principle of least privilege.
Be approved by the appropriate manager.
10. Third-Party Recruitment
When recruitment agencies are used, they shall:
Comply with applicable data protection regulations.
Protect candidate information.
Follow contractual confidentiality requirements.
Handle applicant data securely.
11. Protection of Candidate Information
Candidate personal information shall:
Be collected only for legitimate recruitment purposes.
Be stored securely.
Be accessible only to authorized personnel.
Be retained and disposed of according to legal and Greystone Labour Ltdal retention requirements.
12. Compliance
Failure to comply with this policy may result in:
Withdrawal of employment offers.
Disciplinary action.
Termination of employment or contracts.
Legal action where applicable.
13. Review
This policy shall be reviewed:
At least annually.
Following significant legal, regulatory, or Greystone Labour Ltdal changes.
After major information security incidents affecting recruitment processes.
