How does Timing handle personal data?
Timing is legally required as an employer to correctly establish the identity of employees and handle their personal data appropriately. As a client of Timing, you will also encounter this.
Timing acts according to the rules and guidelines of:
1. The verification obligation
According to the NEN 4400-1 standard, the Wage Tax Act, and the agreements made by you and Timing, you as a client are required* at the commencement of employment to establish the identity of the employee using the original identity document (passport, identity card, or alien document) and to check these documents for authenticity and validity. This check may not be conducted based on a copy of an identity document.
2. The SNA quality mark
The quality mark for all temporary employment and payroll companies and (sub)contractors of work, the SNA quality mark, is based, among other things, on the NEN 4400-1 standard; prevention of fraud and illegality. Timing complies with the standards of requirements for identity verification, validity of the ID document, avoidance of identity confusion, and documentation of the performed check.
3. The GDPR
For handling personal data, Timing is required to adhere to the provisions laid down in the General Data Protection Regulation (GDPR). We do everything possible to prevent data breaches.
What are data breaches?
A data breach can occur when personal data falls into the hands of someone who should not have it. The likelihood of this is significantly increased by the way information from ID documents is often exchanged today. Consider:
- photographing ID documents on a smartphone: these photos remain on the phone and are often not (promptly) deleted and then automatically copied to personal cloud storage;
- saving the photo on a PC to then email or upload via a website: these photos are often not (promptly) removed from the PC;
- copying an ID document on a copier: most copiers have memories that are not regularly erased;
- sending and receiving copies of ID documents via WhatsApp: these often remain both in the app and are also copied to the photo gallery on the phone and backed up to personal cloud storage;
- sending copies of ID documents via email: these often remain in the mailbox and are not (promptly) deleted.
In the context of the GDPR, these are undesirable situations.
*Justification by Legal Affairs
The reason that Timing adheres closely to these rules is explained by our Legal Advisor: For example, by scanning copies of an ID document, the risk is very high of employing a person who is not allowed to reside in the Netherlands and/or a person who is not allowed to work in the Netherlands. When that happens, illegal employment, even if only for a few hours, can cost the client €10,000.
That is the first offense. If more offenses occur, the fines increase (doubling and even tripling!). Now, this will not quickly concern the same client, but the fine imposed on Timing will increase if illegal employment occurs with another client. This is then taken very seriously (money).
In addition to the monetary fine, the offense is made public (naming and shaming). Both Timing and the client therefore run a significant risk regarding reputational damage.
Furthermore, Timing receives an investigation by the SZW Inspectorate for each illegal employment, which costs a lot of time and therefore money. The SZW Inspectorate reports each incident in this area to SNA/VRO, and Timing will also receive additional investigations from them. This way, Timing gets 'crosses behind the name', with the ultimate consequence being the loss of our certification.
Want to know more?
Contact your Timing contact person.