Who are we?

We are an affiliate member of Philip Morris International, a collective group of businesses. All affiliate members of the group are listed here along with data protection officer contact points where relevant. Please use these details if you wish to contact us. Our details (name, address, etc.) will have been given to you separately at the time of (or to confirm) the collection of information about you, for example, in a notice on an app or a website or in an e-mail, containing a link to this notice.

  • Philip Morris International or PMI means Philip Morris International, a leading international tobacco group. It is made up of a number of companies or “affiliates”.
  • PMI affiliates: Each member of the Philip Morris International group of companies is a “PMI affiliate”. “We” (or “us” or “our”) refers to the relevant PMI affiliate that is recruiting for a position: when you set up a candidate profile or apply for a job, you provide information about yourself to that PMI affiliate, and that PMI affiliate may process information about you for its own recruitment purposes as a data controller. PMI affiliates may share information about you within the Philip Morris International group of companies to assist with the recruitment process. These entities will process your personal data on behalf of the PMI affiliate that is recruiting for a position. 

Where you agree to be contacted about future opportunities, information about you may be shared with other PMI affiliates for recruitment purposes as a data controller.  

How do we collect information about you?

In order to ensure an effective recruitment process, we collect various types of personal data about you in various ways as follows.

  • You may provide us with information directly (e.g., when creating an account, creating a candidate profile, applying for a job, attending an interview, completing a test/assessment, sending an e-mail, or making a call to us).
  • We may collect information automatically when you interact with our systems or we communicate with you (e.g., when you use a PMI app or website or, where we use technologies to observe when you receive or open e-mails or receive SMS messages).
  • We may also acquire information from third parties (e.g., from recruitment agencies, referrals, reference providers, test/assessment providers, (where permitted by law) background screening providers and publicly available sources, such as a company website, internet searches or social media platforms such as LinkedIn).

In this notice, we refer to all the methods by which you are in contact with us as “PMI touchpoints”. PMI touchpoints include both physical (for example, offices and events) and digital (for example, apps and websites).

We may collect information that you provide directly. Typically, this will happen when you:

  • sign up to be a member of our databases (this could be, for example, in person, via an app, or online when you create an account and a candidate profile);
  • submit a job application and supporting information to us;
  • participate in an interview;
  • complete a test/assessment;
  • provide job acceptance, background screening and on-boarding information (where applicable);
  • download, or use, a digital touchpoint (e.g., an app or a website);
  • contact us through a PMI touchpoint, or by e-mail, social media or telephone;
  • register to receive press releases, e-mail alerts, or job updates;
  • participate in surveys or (where permitted by law) competitions or promotions; or
  • attend an event that a PMI affiliate has organized.

We may collect information from an electronic device, if you choose to send the information to us. This may be shared with us through a direct connection to the internet, or via one of our apps that you may download.

We may collect information about you automatically. Typically, this will happen when you:

  • visit our offices (e.g., through video (CCTV) recording and building access logs);
  • complete online skills and aptitude tests (including online and via video recording);
  • attend an event that a PMI affiliate has organized (e.g., through sensors at the event that connect with mobile technology);
  • use PMI’s systems or PMI-issued devices such as a laptop;
  • communicate with us (for example, through a PMI touchpoint; or by e-mail, or social media platforms);
  • use PMI touchpoints (e.g., such as cookies and web beacons/pixels); or
  • make public posts on social media platforms that we follow (for example, so that we can understand public opinion).

As mentioned above, we may collect information about you automatically through the use of cookies and similar tracking technologies (such as web beacons/pixels) that you receive when you visit digital PMI touchpoints or get an e-mail electronic message from us. The specific cookies and other mechanisms used will depend on the PMI touchpoint in question. To learn about these mechanisms used on a PMI touchpoint, including how you can accept or refuse cookies, please see the information made available on or through that touchpoint. These mechanisms may include Google analytics cookies (see www.google.com/policies/privacy/partners/.)

Where permitted by law, we may acquire information about you from third parties. This may include:

  • information from recruitment agencies;
  • information provided by employees making referrals;
  • information shared between PMI affiliates;
  • information from third party social media sites (for example, if you want to upload information to the platform (for example, from LinkedIn or Indeed) instead of manually completing an application); and
  • publicly available profile information (such as your experience, skills and interests) on third party social media sites (such as LinkedIn).

We may also collect information in other contexts made apparent to you at the time.

What information about you do we collect?

We may collect various types of information about you (always within the scope permitted by law):

  • information necessary to manage and administer our relationship with you (including, where we agree, to reimburse certain expenses to attend an interview) and to run our business, including to meet our legal and regulatory obligations (e.g., verifying your identity, your right to work, application details and, where permitted by law, your suitability for a job using background checks)
  • information you give us in your candidate profile, job application, forms, or surveys
  • information necessary to assess your eligibility for a role, shortlist and select candidates
  • information about your visits to our offices and attendance at events
  • where applicable, information necessary to offer you a job and on-board you (such as issuing an offer, drafting an employment contract, providing benefits information or to ensure benefits are in place when you join, and arranging access to systems)
  • information gathered as part of our monitoring and continuous improvement of the recruitment process
  • information you give us in calls you make to us or e-mails you send to us
  • information about your preferences, interests, and career aspirations (including information that we infer from other information, for example from statistical information)
  • information gathered as part of business analytics and improvements
  • statistical information about you (for example, statistical information about people in certain geographical areas)

Information that we collect from you directly will be apparent from the context in which you provide it. For example:

  • during the application and recruitment process, you provide your name, contact details, skills, qualifications, experience information, and, where we agree, information (such as your bank account details) to allow us to reimburse certain expenses to attend interview);
  • during any interview or assessment you provide answers to questions;
  • you may provide information on your career aspirations and interests so that we can send you relevant opportunities; and
  • we may collect information that enables us to verify your identity and right to work, for example, a copy of an identity document or your facial image.

Information that we collect automatically will generally concern:

  • details of your visits to our offices, attendance at interviews, assessments, and events (such as time and duration);
  • details of your use of PMI touchpoints (such as applications/information accessed, time and duration, information searched); 
  • your devices (such as IP address or other unique device identifier, location data, details of any cookies that we may have stored on your device);
  • your use of PMI digital touchpoints (such as the pages you have visited, the page from which you came, and the page that you move to, search terms entered, links clicked within the touchpoint, when you first open the touchpoint, for how long you use it, and how you interact with messages we send you or advertisements we show you). We may use cookies and similar tracking technologies (such as pixels/web beacons) to do this; and
  • your use of third-party websites, where the information collected will be similar to that described in the bullet above. We may use cookies and similar tracking technologies (such as pixels/web beacons) to do this;

Information that we collect from third parties will generally consist of:

  • your basic contact information where you are referred for an opportunity by an employee;
  • job application information from recruitment agencies (where you apply for a role via a recruitment agency);
  • references and work certificates from your previous employers or your other reference providers;
  • where permitted by law, background screening information as appropriate for the role (such as identity document validation, address verification, confirmation of qualifications and employment history, searches against sanctions and politically exposed persons lists, and details of any convictions);
  • profile information from third party social media sites (for example, if you want to upload information to the platform (for example, from LinkedIn or Indeed) instead of manually completing an application); and
  • publicly-available profile information (such as your role, skills, qualifications, experience and interests, for example from a company website, internet searches or on social media platforms such as LinkedIn).

Information we collect and process about you may include your:

  • full name including preferred name
  • password
  • address including home and correspondence
  • contact details including personal e-mail address and home/personal mobile phone number where these details are provided as part of your application
  • gender
  • date and place of birth
  • cover letter
  • preferred language and/or language proficiency
  • resume/job application, including personal and professional information
  • how you heard about the job
  • eligibility to work, including passport or other official identification document
  • nationality
  • residence status
  • references
  • qualification transcripts and certificates
  • education and employment history
  • information about military service
  • jobs applied for
  • current, expected and offered employment terms and conditions (e.g., pay, hours of work, holidays, benefits, notice period)
  • any current or previous PMI affiliation
  • interview notes and assessment results
  • application outcome and reason
  • reason for withdrawing your job submission (where applicable)
  • social insurance and personal income tax data
  • tax code
  • family status, family members and situation
  • bank account information (if we agree to reimburse you certain expenses to attend interview, or if you are offered a job and accept it)
  • photographs and video recordings
  • automated records of your use of PMI information systems
  • information submitted to us when using information systems that PMI affiliates operate
  • information about your visits to our offices and events

We may also collect and process special categories of information about you such as your:

  • racial or ethnic origin (e.g., for equal opportunities monitoring)
  • political opinions (only if you voluntarily share this information)
  • religious or philosophical beliefs (e.g., for reasonable accommodation)
  • sexual orientation (e.g., for equal opportunities monitoring or if you voluntarily share this information)
  • trade union membership (only if you voluntarily share this information)
  • data concerning your health, including any disability (e.g., for reasonable accommodation)

We will process these types of data if you voluntarily share them with us, if we have a legal obligation to process the information and, in relation to the recruitment process, to provide reasonable accommodation.

The purposes for which we use information about you, with corresponding methods of collection and legal basis for use, are:

Purpose

Method of collection and legal basis for Processing

Comply with regulatory obligations

·    identity and right to work checks

·    assessing the demographic makeup of our workforce, such as equal opportunities monitoring

This information is generally provided to us by you directly.

We use it because it is necessary for us to comply with a legal obligation to employ only people with a right to work in the country where the job is located and to monitor the demographics of our workforce, or, in countries where there is no such legal obligation, because we have a legitimate business interest to run our business in accordance with good practice requirements that is not overridden by your interests, rights and freedoms to protect information about you.

Application verification and candidate vetting (where permitted by law)

·    verifying employment history, qualifications, experience, and references

·    where permitted by law, candidate vetting and background screening

This will typically be a combination of information that you provide directly (as part of your application) and, during the later stages of our recruitment process, information that we collect from third parties such as references and (where permitted by law) criminal record checks.

We use it because it is necessary for us to comply with a legal obligation to employ only eligible and suitable people, or, in countries where there is no such legal obligation, we use it because we have a legitimate business interest in ensuring your suitability and eligibility for a role with us that is not overridden by your interests, rights and freedoms to restrict use of information about you.

Recruitment and selection

·   candidate recruitment and selection, including interviews, recorded videos, assessments, psychometric testing

·    review of application forms and online assessment tools and skills tests

·    shortlisting

·    where applicable, administering reimbursement of certain expenses to attend interview

·    where applicable, making an offer and agreeing benefits

·    group, panel, and individual interview

·    informing you of the outcome of applications and of other opportunities that may be of interest, advertising positions, and monitoring interest

·    record keeping

This will typically be a combination of information that you provide directly (at various stages during the recruitment process) and, information that we collect from third parties such as any recruiter or social media platform you use to share information about you with us.

We use it because we have a legitimate business interest in recruiting and selecting candidates for roles with us (including carrying out interviews and assessments), administering the process, and keeping records of the recruitment process, that is not overridden by your interests, rights, and freedoms to restrict use of information about you.

Pre-employment workforce management

·    hiring activities such as preparing, issuing, and signing employment contract

·    establishing electronic personal record and personal files

·    creating payroll records

·    enrolling new employee benefits

·    reporting employment commencement to legal authorities

This information is collected during the later stages of our recruitment process and during the processing of job offer and/or acceptance.

We use it because we have a legitimate business interest in preparing necessary employment documents and completing necessary internal records not overridden by your interests, rights and freedoms to restrict use of information about you.

Monitoring of the recruitment process

·    quality control and checks to monitor compliance with our recruitment process

This information is collected throughout our recruitment process.

We use it because we have a legitimate business interest in checking compliance with our recruitment process that is not overridden by your interests, rights, and freedoms to restrict use of information about you.

Support for all the above purposes

·    administering your accounts

·    enabling you to use PMI touchpoints (for example, allowing you to remain logged in to sections of a touchpoint that are reserved for authorized users only, and administering your language preference)

·    corresponding with you

·    managing your appointments with us (for example, regarding an interview or assessment)

·    enhancing your experiences

·    administration and troubleshooting

This will typically be a combination of information that you provide to us (name, password (or equivalent)) and information that we collect automatically (for example, information about your device, and cookies and similar tracking technologies).

We use it on the grounds that correspond to the purpose for using the information that we are supporting. For example, where we administer your account to support a job search or application, we use the information on the grounds that we have a legitimate business interest to run our business and recruit staff that is not overridden by your interests, rights, and freedoms to protect information about you.

Business analytics and improvements

·    assessing the effectiveness of our recruitment process

·    business analytics and improvements (including for our recruitment process, events, digital PMI touchpoints and the information that we (or our affiliates) provide to job candidates)

This will typically be a combination of information that you provide to us; information that we collect automatically; and (where permitted by law) information that we acquire from third parties.

We use it on the grounds that we have a legitimate business interest to analyze, assess the effectiveness of and improve our recruitment efforts, processes, PMI touchpoints, and events that is not overridden by interests, rights, and freedoms to protect information about you.

 

Where we do not base our use of information about you on one of the above legal bases, or where law requires it, we will ask for your consent before we process the information (these cases will be clear from the context). We may from time to time ask for your explicit consent to process special categories of information about you.

In some instances, we may use information about you in ways that are not described above. Where this is the case, we will provide a supplemental privacy notice that explains such use. You should read any supplemental notice in conjunction with this notice.

Do we use Artificial Intelligence or make automated decisions?

We may use the following Artificial Intelligence (AI) features during the recruitment process.

Our candidate portal has built in AI that contains a number of features, including making personalized job recommendations to you based on your location, experience, and preferences.

The candidate portal also has a chatbot feature that will answer frequently asked questions and help you navigate through the portal by assisting you to search for jobs, apply for jobs more easily and build a profile when you provide your information (such as current job title, preferred location, or your resume) directly through the chatbot.  

In addition, the candidate portal has a feature which ranks every candidate’s application, much like the way in which a recruiter reviews written materials provided as part of the recruitment process and ranks candidates’ application for a job advertisement based on relevant skills and experience. This feature uses advanced language processing to analyse our written job description and compares this with the written information that you have provided as part of your application to us. This feature calculates a grade based on several criteria such as: job title, years of experience, skills, and location. The grading (e.g., A, B, C, or No Fit (with A indicating the highest match)), helps recruiters to understand how well-suited you are for the position. The ranking is determined using AI that is powered by explicit and implicit data. Explicit data encompasses all information you have shared with us, including skills, work experience, current job title, and location information. The candidate portal extracts keywords from this data and stores it in your profile, with these keywords.  The candidate portal can also infer similar or related keywords that can further augment our understanding of your skills based on pre-existing data regarding job titles and experience. By combining these data sources, the candidate portal provides a measure of how likely you may fit the requirements of the role that you are applying for.

The actual ranking and matching process depends on the specific criteria and the relative weight assigned to each criterion based on the role. For example, the highest score is given to exact matches (a “sales representative” candidate matches to a “sales representative” job), and a partial score is given to similar matches (a “business development” candidate matches to a “sales representative” job). Contextual information can guide the relative weight of each score component. For example, for a job such as “truck driver,” more weight may be given to the title match score, because a candidate who already has that title is more likely to meet the minimum requirements of the role. By contrast, for a job such as “software engineer,” the skills match score would also have high weight, because the overall fit score should reflect skills such as specific programming languages.

Criteria, such as skills and experience, of current employees who hold the same position may also be considered, to provide examples of ideal candidates for a role and improve the accuracy of the ranking and matching process.

Additionally, we may use AI features during the digital interview for our internship roles. In particular, digital interviews use a natural language processing feature to transpose your responses from audio (what you say) to text and then to compare it with job-related competencies critical for success in these internship roles.  Your response is scored and used to assist recruiters in identifying candidates most likely to have the job-related competencies needed for success.  

In this way, an AI model initially assists recruiters in identifying candidates for interview but does not make hiring decisions on its own. PMI recruiters will always review applications from all grades, including incomplete profiles that may not have loaded correctly into our system.

No automated decision-making is used to make any final hiring decisions and the information that you provide will always ultimately be assessed in person by a recruiter or hiring manager when making a hiring decision.

If we use any automated decision making, we will draw this to your attention at the time, together with information about the logic involved in the decision, as well as the significance and the envisaged consequences for you of such use of your information.

Additionally, we may use third party technology providers that embed AI in their technology products (such as Microsoft). For example, translating data from your emails or documents that you provide to us in the context of your application. Such technology products may include AI features such as speech-to-text and text-to-speech capabilities. 

Who do we share your information with, and for what purposes?

We may share information about you with:

  • PMI affiliates;
  • third parties who provide PMI affiliates or you with products or services (such as recruitment agencies, background screening, online assessment providers and vendors that support PMI’s endeavors to improve the candidate experience); and
  • other third parties, where required or permitted by law (such as regulatory authorities; government departments; past, potential, or future employers; and in the context of organisational restructuring).

We share information about you with others only in accordance with applicable laws. Thus, where law requires your consent, we will first ask for it.

Sharing data with other PMI affiliates

Information about you will be shared with Philip Morris Products S.A. (based in Lausanne Switzerland), which is the place of central administration of personal data processing for PMI affiliates. Information about you may also be shared with Philip Morris International IT Service Centre Sàrl (based in Lausanne, Switzerland) as technology provider for PMI affiliates. Philip Morris Products S.A. and (to the extent it has access) Philip Morris International IT Service Centre Sàrl process the information about you for all the purposes described in this notice.

Information about you will be shared with other PMI affiliates to assist with the recruitment process. Where you agree to be contacted about future opportunities, information about you may be shared with other PMI affiliates for recruitment purposes. Accordingly, information about you may be transferred globally (if your information is collected within the European Economic Area, this means that your information may be transferred outside of the European Economic Area subject to the protections set out below in the section entitled “Where might information about you be sent?”).

Details of PMI affiliates and the countries in which they are established are available here.

Sharing data with third parties

We may share information about you with third parties who provide PMI affiliates or you with products or services (such as recruitment agencies, background screening providers, online assessment providers, information services providers and identity verification providers).

We may share information about you with other third parties, where required or permitted by law, for example: regulatory authorities; government departments; in response to a request from law enforcement authorities or other government officials; when we consider disclosure to be necessary or appropriate to prevent physical harm or financial loss or in connection with an investigation of suspected or actual illegal activity; and in the context of organizational restructuring.

If we arrange travel or accommodation for you (e.g., if you need to travel to attend an interview), information about you may be shared with third parties who arrange travel and accommodation, provide transport or travel-related services, such as travel agents, online booking providers, ticketing agents, airlines, car hire companies, rail providers and hotels. These third parties will use information about you for their own purposes (for example, to discharge their obligations to provide transport or accommodation to you) and you should check their privacy notices for further details about their use of information about you. Note also that you may have rights, exercisable against such third parties, in respect of their processing of information about you.

 

Where might information about you be sent?

As with any multinational organization, we transfer information globally to our affiliates and service providers.  Your data may therefore be transferred to other countries as part of our standard operations.  Whenever we transfer your data abroad, we will limit access to your data only to those who need to see it, process your data in accordance with our internal data protection standards, protect it appropriately and only transfer information in compliance with applicable data privacy laws.  When data is transferred, we will require the receiving party to keep your data confidential, delete it when it is no longer required and act in accordance with this privacy notice.  Accordingly, information about you may be transferred outside of your jurisdiction. For example, if you are in the European Economic Area (“EEA”), UK, Switzerland, Australia or Japan, your data may be processed in another country.

When using information as described in this notice, information about you may be transferred either within or outside the country or territory where it was collected, including to a country or territory that may not have equivalent data protection standards.

For example, we and other PMI affiliates within the EEA may transfer personal information to PMI affiliates, or to their service providers, outside the EEA. In all such cases, the transfer will be:

  • on the basis of a European Commission adequacy decision;
  • subject to appropriate safeguards, for example the EU Standard Contractual Clauses or binding corporate rules: or
  • with your consent or as necessary to discharge obligations under a contract between you and us (or the implementation of pre-contractual measures taken at your request) or for the conclusion or performance of a contract concluded in your interest between us and a third party, such as in relation to travel arrangements.

For transfers from Switzerland and the UK, in accordance with the Federal Act on Data Protection UK GDPR and guidance of the Information Commissioner’s Office. 

In all cases, appropriate security measures for the protection of personal information will be applied in those countries or territories, in accordance with applicable data protection laws.

Our service providers are located in many countries throughout the world, including in particular the EEA, Switzerland, the USA, Canada, India, Turkey, the Philippines, Indonesia, and Australia.

How do we protect information about you?

We implement appropriate technical and organizational measures to protect personal information that we hold from unauthorized disclosure, use, alteration or destruction. Where appropriate, we use encryption and other technologies that can assist in securing the information you provide. However, no method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, while we strive to use reasonable acceptable means to protect your information, we cannot guarantee its absolute security or confidentiality. We also require our service providers to comply with equivalent data privacy and security requirements.

How long will information about you be kept?

We will retain information about you for the period necessary to fulfil the purposes for which the information was collected in accordance with our internal data retention standards. After that, we will delete it. The period will vary depending on the purposes for which the information was collected. Note that in some circumstances, you have the right to request us to delete the information. Also, we are sometimes legally obliged to retain the information, for example, for tax and accounting purposes.

Typically, we retain data based on the criteria described in the table below. Where these periods conflict with legal obligations, for example, for tax and accounting purposes, to either retain the information for a set minimum period of time, or to delete it after a set maximum period of time, we apply those set periods instead.

Type

Explanation/typical retention criteria

·    recruitment process data

If you apply for a job with us, we will keep a record of your application and retain it while it remains relevant to our relationship, for example during the recruitment process, to tell you about other opportunities that may be of interest and, if your application is successful, during your employment with us.

Typically, information about you is kept for up to 24 months after the date on which you last logged into the recruitment platform. As a minimum, we keep records of the recruitment process for the statutory period in which a claim arising from the recruitment process may be brought. We may keep information about you for longer if you apply for certain types of jobs and this is allowed or required in the country where that job is based.

Other records relevant to the recruitment process (for example, assessment results and background checks) are retained for a short period until more permanent records are made (for example, a record of the result of the assessment or background check).

·    visitor records

If you visit our buildings, visitor records are retained typically for a period of only a few months.

·    CCTV

If you visit our buildings, CCTV records are retained typically for a period of only a few days.

·    system audit and fraud prevention

System audit logs are retained typically for a period of up to 6 months for system recovery and for up to 10 years for fraud prevention.

·    business analytics

Business analytics data is typically collected automatically when you use PMI touchpoints and anonymized/aggregated shortly afterwards.

What rights and options do you have?

You may have some or all of the following rights in respect of information about you that we hold:

  • request us to give you access to it;
  • request us to rectify it, update it, or erase it;
  • request us to restrict our using it, in certain circumstances;
  • object to our using it, in certain circumstances;
  • withdraw your consent to our using it;
  • data portability, in certain circumstances; and
  • lodge a complaint with the supervisory authority in your country (if there is one).

We offer you easy ways to exercise these rights, such as “unsubscribe” links, by logging in to your account and using the self-service function, by contacting people.culture@pmi.com or by using the contacts in the paragraph “who should you contact with questions?” at the end of this notice.

The rights you have depend on the laws of your country. If you are in the EEA, UK or Switzerland, you will have the rights set out in the table below. If you are elsewhere, you can contact us to find out what rights apply to you (see the paragraph “who should you contact with questions?” at the end of this notice) or look at the specific section for your country below.

Right in respect of the information about you that we hold

Further detail (note: certain legal limits to all these rights apply)

·    to request us to give you access to it

This is confirmation of:

·    whether or not we process information about you;

·    our name and contact details;

·    the purpose of the processing;

·    the categories of information concerned;

·   the categories of persons with whom we share the information and, where any person is outside the UK/ EEA/Switzerland and does not benefit from a European Commission adequacy decision, the appropriate safeguards for protecting the information;

·   (if we have it) the source of the information, if we did not collect it from you;

·    (to the extent we do any, which will have been brought to your attention) the existence of automated decision-making, including profiling, that produces legal effects concerning you, or significantly affects you in a similar way, and information about the logic involved, as well as the significance and the envisaged consequences for you of such use of information about you; and

·    the criteria for determining the period for which we will store the information.

On your request we will provide you with a copy of the information about you that we use (provided this does not affect the rights and freedoms of others).

·    to request us to rectify or update it

This applies if the information we hold is inaccurate or incomplete.

·    to request us to erase it and in some cases an extension of this right, the right to be forgotten

This applies if:

·    the information we hold is no longer necessary in relation to the purposes for which we use it;

·    we use the information on the basis of your consent and you withdraw your consent (in this case, we will remember not to contact you again, unless you tell us you want us to delete all information about you in which case we will respect your wishes);

·    we use the information on the basis of legitimate interest and we find that, following your objection, we do not have an overriding interest in continuing to use it;

·    the information was unlawfully obtained or used; or

·    to comply with a legal obligation.

·    to request us to restrict our processing of it

This right applies, temporarily while we look into your case, if you:

·    contest the accuracy of the information we use; or

·   have objected to our use of the information on the basis of legitimate interest

(if you make use of your right in these cases, we will tell you before we use the information again).

This right applies also if:

·    our use is unlawful and you oppose the erasure of the data; or

·    we no longer need the data, but you require it to establish a legal case.

·    to object to our processing it

If we use the information about you on the basis of legitimate interest, you can object to our using it for those purposes, giving an explanation of your particular situation, and we will consider your objection.

·    to withdraw your consent to our using it

This applies if the legal basis on which we use the information about you is consent. These cases will be clear from the context.

·    to challenge certain automated decisions

If, as part of our recruitment process, we make a decision based solely on automated processing, and that decision produces legal effects concerning you or similarly significantly affects you (for example, you are not invited to interview on the basis of the decision), you have a right to contest the decision, to request us to have a human review of that decision, and to express your point of view.

This right does not apply if:

(i)    you gave your consent to the decision beforehand;

(ii)   that use of information about you is necessary for entering into; or the performance of, a contract between you and us; or

(iii)  it is authorized by law.

As mentioned above, these decisions will be drawn to your attention at the time, together with information about the logic involved in the decision, as well as the significance and the envisaged consequences for you of such use of information about you.

·    to data portability

If:

(i)  you have provided data to us; and

(ii) we use that data, by automated means, and on the basis either of your consent, or on the basis of discharging our contractual obligations to you,

then you have the right to receive the data back from us in a commonly used format, and the right to require us to transmit the data to someone else if it is technically feasible for us to do so.

·    to lodge a complaint with the supervisory authority in your country

If you have any complaint, we welcome the opportunity to resolve it for you directly.  Please consider contacting us using the contact details linked at the start of this notice before contacting a supervisory authority.

If you do wish to contact a supervisory authority, details are as follows:

·     For the European Economic Area, you can contact your local authority as listed on the Europa website via this link. If you are unsure who your jurisdiction’s supervisory authority is, please contact us using the details linked to at the top of this page.

·     For the UK, you can contact the Information Commissioner’s Office via this link.

·       For Switzerland, you can contact the Federal Data Protection and Information Commissioner via this link.  

·     For other countries please consult the website of your country’s authority.

If you are unsure who your jurisdiction’s supervisory authority is, please contact us using the details linked to at the top of this page.

 

Country-specific additional points

According to which country you are in, we want you to be aware of some further points. In particular you may have some additional rights.

If you are in Australia, find out more...

If you are in Australia, the following additional information applies to you:

(A)  if you do not provide your personal information to us, we may not be able to (as applicable) provide you with the information, products or services that you request, or manage or administer our employment with you; and

(B)  our Privacy Policy (available at https://www.pmiprivacy.com/en-au/homepage) explains: (i) how you may access and correct the personal information that we hold about you; (ii) how you can lodge a complaint regarding our handling of your personal information; and (iii) how we will handle any complaint.

If you are in China, find out more…

If you are in China, the following additional information applies to you:

  1. you have the right to request us to erase your personal information if our processing of your personal information violates the laws, administrative rules, or the agreements between you and us.
  2. in the event you request us to erase your personal information while the storage period provided by any local law or administrative regulations has not expired, or it is difficult to erase personal information technically, then we will cease the processing of your personal information other than storing and taking necessary security protection measures for such information.
  3. you have the right to request us to interpret the personal information processing rules if you have any questions. 
  4. in the event of your death, your closed relatives may, for their own legal and legitimate interests, exercise the rights to handle your personal information as provided by local laws and administrative regulations or in this notice. You can also make alternative arrangements before your death.

If you are in Colombia, find out more...

The data controller is Coltabaco S.A.S. located in Carrera 52 No. 4-96, Medellín, Colombia, phone number: +57 4 356 90 00, email: people.culture@pmi.com. We are an affiliate of Philip Morris International. For all activities that involve the processing of personal data we will abide by the provisions of Law 1581 of 2012, Decree 1377 of 2017 and other regulations that modify or add them. Where required, we will always obtain your consent for the processing of personal data in advance, including any international transfers, unless a legal exception applies. You have the right to access, update and rectify your personal data free of charge by contacting us using the contact details set out above, or by getting in touch with the data processor. This right may be exercised, among others, against partial, inaccurate, incomplete, fragmented, misleading data, or where processing is prohibited or has not been authorized. Your data will be processed through automated systems that do not involve automated decision. You may: (i) optionally answer the questions about sensitive data or the data of children and adolescents; (ii) request to be informed by us, upon request, regarding the use we have given to your personal data; (iii) ask us for proof of your consent; (iv) withdraw your consent, provided there is no conflicting legal or contractual duty to remain in a database; (v) revoke your consent and/or request the deletion of the data when the processing does not respect constitutional and legal principles, rights and guarantees. The Privacy team is responsible for all requests, complaints and claims relating to the processing of personal data. If you wish to contact the Privacy team, you can find the contact information above. This notice is effective for Colombia on September 2nd, 2024.

If you are in France, find out more…

If you are in France, you have the right to give us instructions regarding information we hold about you in the event of your death (specifically, whether we should store or delete it, and whether others should have the right to see it). You may:

  • issue general instructions to a digital service provider registered with the French data protection supervisory authority (called “CNIL”) (these instructions apply to all use of information about you); or
  • give us specific instructions that apply only to our use of information about you.

Your instructions may require us to transfer information about you to a third party (but where the information contains information about others, our obligation to respect also their privacy rights might mean that we can’t follow your instructions to the letter). You may appoint a third party to be responsible for ensuring your instructions are followed. If you do not appoint a third party in that way, your successors will (unless you specify otherwise in your instructions) be entitled to exercise your rights over information about you after your death:

  • in order to administer your estate (in which case your successors will be able to access information about you to identify and obtain information that could be useful to administer your estate, including any digital goods or data that could be considered a family memory that is transferable to your successors); and
  • to ensure that parties using information about you take into account your death (such as closing your account, and restricting the use of, or updating, information about you).

You may amend or revoke your instructions at any time. For further information on the processing of information about you in the event of your death, see Articles 84 to 86 of the law 78-17 dated 6 January 1978 as amended. When you die, by default, you will stop using your account and we will delete information about you in accordance with our retention policies (see the paragraph “How long will information about you be kept?” for details).

If you are in Greece, find out more... 

If we use artificial intelligence and conduct candidate profiling in the recruitment process then the following will apply:

We create a profile for each candidate, but it is important to note that no decision is solely based on this profile. The direct involvement and screening by human recruiters throughout the whole procedure ensures that no automated decision-making processes are used in the recruitment process. In our assessment of your application, we consider the following criteria. However, there might be situations where we need additional information and consultation beforehand:

  • Current Job Title
  • Years of experience (calculated as a sum from work history)
  • Skills (extracted from resume and/or manually entered by you)
  • Location (based on City)

Technical and organizational measures have been taken to ensure the implementation of the principle of equal treatment and to combat discrimination in employment on grounds of sex, race, color, national or ethnic origin, birth, religion or belief, disability or chronic illness, age, marital or social status, sexual orientation, identity or gender identity.

The use of AI that performs profiling is subject to additional guarantees to safeguard your rights. You have the right to request human intervention, the right to express your opinion, the right to receive justification of the decision taken in the context of profiling and the right to challenge the decision.

You may, at any time, exercise the right not to be subject to the profiling of your application in the recruitment process, by submitting a relevant request to us to people.culture@pmi.com

If you are in Israel, find out more...

We may rely on your consent to such processing of the information. For clarity, approval of this privacy notice shall be deemed as your consent to our use and processing of your information as set forth in this privacy notice.

If you are in Japan, find out more......

If you are in Japan, note that we share information about you, for the purposes described in this notice, with other PMI affiliates on the basis of “joint use” under Japanese data protection laws. When we do this, Philip Morris Japan Limited (PMJ) continues to manage your personal information responsibly, and we require those with whom we share the data to do the same. Further, if they are located outside Japan, we take reasonable measures in accordance with the relevant laws and regulations.

If you are in Poland, find out more...

If you are in Poland, the following additional information applies to you:

1.     The controller of your personal data, within the meaning of the GDPR, is the respective Polish legal entity to which you apply for a job, namely Philip Morris Polska S.A., Philip Morris Polska Distribution Sp. z o.o., Philip Morris Polska Tobacco Sp. z o.o.- based in Kraków, Al. Jana Pawła II No. 196, 31-982 Kraków. In order to exercise your rights in Poland you can contact our agents through +48 800 331 1351; +48 126464111. To lodge a complaint to the supervisory authority (President of the Office for Personal Data Protection, 2 Stawki Street, 00-193 Warsaw; www.uodo.gov.pl)

If you are applying in South Korea

Please refer to Philip Morris Korea’s candidate privacy notice.

If you are in Switzerland, find out more…

If you are in Switzerland, information about you may be transferred outside of Switzerland, including to a country or territory that may not have equivalent data protection standards. In such cases, the transfer will be subject to appropriate safeguards such as the Standard Contractual Clauses in accordance with the new Data Protection Act and guidance from the Federal Data Protection and Information Commissioner.

If you are in Taiwan, find out more…

If you are in Taiwan, the following additional information applies to you:  Your personal data will be collected, processed, and used by Philip Morris Taiwan S.A., Taiwan branch/ Taipei branch. If you do not provide your personal information to us, we may not be able to (as applicable) provide you with the information, products or services that you request.

If you are in Turkey, find out more...

If you are in Turkey, the data controller is one of the following entities of PMI:

·       Philip Morris Pazarlama ve Satış A.Ş.

·       Philip Morris Tütün Mamulleri Sanayi ve Ticaret A.Ş.

·       Philip Morris Seyahat Perakende Satış A.Ş.

·       Philip Morris Yönetim Hizmetleri A.Ş.

According to Law on the Protection of Personal Data No. 6698 Article 11, in addition to the rights listed in ‘What rights and options do you have?’ section, you have the following rights:

·       To request reporting of the operations carried out by third parties to which your personal data have been transferred if incomplete or inaccurate processing has been corrected, or if deletion, destruction, or anonymization has been carried out

·       To claim compensation for the damage arising from the unlawful processing of your personal data

If you are in the UAE, find out more...

Please check any supplementary notices or information provided on a case-by-case basis with further details on safeguards and certifications, if applicable. For our Applicant Tracking System (ATS) and Digital Interviews please click on the corresponding hyperlinks for further information.

If you are in the United States, find out more...

Your rights if you are a resident of California:

In accordance with the CPRA, residents of the State of California are entitled to the following rights with respect to their personal information. Please note that these rights are subject to certain exceptions and certain of these rights are subject to verification mechanisms under the CPRA.

Rights to Know, Correct and Delete Personal Information Collected About You.

You have the right to know: (1) the categories of personal information we have collected about you; (2) the categories of sources from which the personal information is collected; (2) the business or commercial purpose for collecting personal information; (3) the categories of third parties to whom we disclose personal information; and (4) the specific pieces of personal information we have collected about you.

Right to Know Personal Information Disclosed and to Whom.

Since we may disclose your personal information, as described above, you have the right to request that we disclose to you: (1) the categories of personal information that we collected about you; and (2) the categories of personal information that we disclosed about you for a business purpose and the categories of persons to whom it was disclosed for a business purpose.

Right to Correct Inaccurate Information.

If you believe that any of the personal information we maintain about you is inaccurate, you have the right to submit a request for us to correct that information.  Upon receipt of a request, we will use commercially reasonable efforts to correct the information as you direct.

Right to Request Deletion of Your Personal Information.

You have the right to request that we delete your personal information.  Following receipt of a request, we will let you know what, if any, personal information we can delete from our records.  If we cannot delete all of your personal information, we will let you know the reason.

Exercising Rights to Know, Correct and Delete, and Related Verification Measures

You may submit a request regarding your rights to know, correct and/or delete by emailing us at people.culture@pmi.com

Upon submission of a request to know, correct or delete, we will take reasonable steps to confirm that the person submitting the request to know or request to delete is the person to whom the information relates (or his or her authorized agent), and to prevent unauthorized access or deletion of information.  The specific steps taken to verify the identity of the requesting person may vary based on the nature of the request, including the type, sensitivity, and value of the information requested, the risk of harm posed by unauthorized access or deletion, the likelihood that fraudulent or malicious actors may seek the information, the robustness of personal information provided to verify your identity, the nature of our relationship with you, and available technology for verification. 

We will generally try to avoid requesting additional information from you for the purpose of verification, but we may need to do so if we cannot verify your identity based on the information already maintained by us.  If we request additional information to verify your identity, it will be for that purpose only and will be deleted as soon as practical after processing the request, except as otherwise provided by law. 

The following generally describes the verification processes we use:

  • Password Protected Accounts.  If you have a password-protected account with us, we may use existing authentication practices to verify your identity but will require re-authentication before disclosing, correcting or deleting data.  If we suspect fraudulent or malicious activity relating to your account, we will require further verification (as described below) before complying with a request to know or delete.
  • Verification for Non-Accountholders.  If you do not have, or cannot access, a password-protected account with us, we will generally verify your identity as follows:
    • For requests to know categories of personal information, we will verify your identity to a reasonable degree of certainty by matching at least two data points provided by you with reliable data points maintained by us.
    • For requests to know specific pieces of personal information, we will verify your identity to a reasonably high degree of certainty by matching at least three data points provided by you with reliable data points maintained by us.  We will also require a declaration, signed under penalty of perjury, that the person requesting the information is the person whose information is the subject of the request or that person’s authorized representative.  We will maintain all signed declarations as part of our records.
    • For requests to correct or delete personal information, we will verify your identity to a reasonable degree or a reasonably high degree of certainty depending on the sensitivity of the personal information and the risk of harm posed by unauthorized deletion.  We will act in good faith when determining the appropriate standard to apply.

If there is no reasonable method by which we can verify your identity, we will state so in response to a request to know or delete personal information, including an explanation of why we have no reasonable method to verify your identity.

If you use an authorized agent to submit a request to know, delete or correct, we may require the authorized agent to provide proof that you gave the agent signed permission to submit the request. We may also require you to do either of the following: (a) verify your own identity directly with us; or (b) directly confirm with us that you provided the authorized agent permission to submit the request.  This requirement does not apply if you have provided the authorized agent with power of attorney pursuant to Probate Code sections 4121 to 4130.

We will respond to requests to know, requests to delete and / or delete no later than 45 calendar days.  If we cannot verify your request within 45 days, we may deny your request.  If necessary, we may take up to an additional 45 days to respond to your request but in such an event will provide you a notice and an explanation of the reason that we will take more than 45 days to respond to your request. 

Right to Opt-Out of the Sale and Sharing of Your Personal Information.  We do not sell or share your personal information.  As such, you do not have this right. 

Right to Limit the Use of Your Sensitive Personal Information.  We only use your sensitive personal information for the following purposes:  (i) to that use which is necessary to perform the services reasonably expected by you; (ii) to help to ensure security and integrity; (iii) to perform services on our behalf; (iv) to undertake activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by us; and (v) to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by us.  Given the nature of our use of your sensitive personal information, you do not have the right to request that we limit the use of your sensitive personal information. 

Right to Non-Discrimination for Exercising Your Rights.  If you choose to exercise any of your rights, you have the right to not receive discriminatory treatment by us. This includes the right not to be retaliated against for the exercise of your rights

Who should you contact with questions?

If you have any questions, or wish to exercise any of your rights, you can 

  • contact us at people.culture@pmi.com, or
  • contact the relevant PMI affiliate’s data protection officer (if it has one), whose contact details you can find here .

Contact details will also be given in any communications that a PMI affiliate sends you.

If your country has a data protection authority, you have a right to contact it with any questions or concerns. If the relevant PMI affiliate cannot resolve your questions or concerns, you also have the right to seek judicial remedy before a national court.

Changes to this notice

We may update this notice (and any supplemental privacy notice), from time to time. Where the law requires it, we will notify you of the changes; further, where the law requires it, we will also obtain your consent to the changes.

Last modified 31st August 2024. You can find previous versions of this notice here.