Skip to main content

Privacy Notice for Deloitte’s Executive Search and Selection services

1. What is the purpose of this document?

Deloitte Greece is committed to protecting the privacy and security of your personal data. This privacy notice outlines the processing of your personal data in connection with our Executive Search and Selection services, in accordance with the General Data Protection Regulation (GDPR), national law 4624/2019, as in force, and all the applicable data protection laws and regulations. It provides information on the nature of the personal data - where personal data means any information relating to an identified or identifiable natural person (“Data Subject”) - collected by the Data Controller, the purposes of the processing and indicates your rights in relation to the data processed and who to contact for further information or to send any requests.  

2. What is the identity and contact details of the Data Controller?

The Data Controller (hereinafter referred to as “Data Controller” or “Deloitte” or “we” or “us”) is “Deloitte Business Solutions Societe Anonyme of Business Consultants” with the distinctive title “DELOITTE BUSINESS SOLUTIONS S.A.”, located in 3a Fragkokklisias & Granikou str., Marousi, Athens, P.O. 151 25.

3. What are the contact details of the Data Protection Officer?

The Data Protection Officer can always be contacted at the following e-mail address: DataPrivacyOfficer@deloitte.gr.

4. Which data do we collect about you, for which purposes and what are the sources of your data?

We process different types of personal data provided:

  • directly from you, as a Data Subject, during our communication with you in the context of our talent acquisition process, as part of the services we provide;
  • directly from you, when you voluntarily share it with us, for example, by submitting your CV or expressing interest in the services we offer;
  • by third parties (e.g. clients), who provide us with your CV or other relevant information;
  • through professional / networking platforms such as LinkedIn;

The personal data we process may be categorized as follows:

  • Basic identification information (such as name, surname);
  • Contact information (such as telephone number, email address);
  • Professional Data (such as data relating to your education, qualifications, certifications, work experience, etc.), as included in your CV or your LinkedIn profile;
  • Other personal data that may be provided to us during our communication;

Your personal information is processed for the purposes listed below:

a. We will use your personal information to contact you when your professional profile aligns with the job position requirements of our clients;

b. After confirming your interest, we will process your personal data to create a candidate profile for you in our Executive Search & Selection information system, contacting you for job opportunities, communicating with you during your candidacy for roles you may be interested in, sharing relevant announcements and requesting additional information when necessary;

c. We may process your data in case you choose to complete our services evaluation form.

d. We may process your data when this is necessary for the establishment, exercise and support of legal claims or the defense of our rights before courts, administrative or judicial authorities or in the context of an extrajudicial procedure;

We do not carry out any automated decision-making processes, including profiling, that produce legal effects concerning you or significantly affecting you.

5. What is the legal basis on which we process your personal data?

We will use your personal data for the purposes indicated above on the assumption of the following conditions of legitimacy (legal basis):

  • With reference to purpose (a) of par. 4, the legitimate interests pursued by the Data Controller to identify and contact potential candidates for a job opportunity, in the context of the provision of the Executive Search and Selection services (art. 6 par.1f GDPR);
  • With reference to purpose (b) of par. 4, your consent for the creation of a candidate profile and the retention of your information in the Executive Search & Selection information system, which is provided when you express interest in our services and submit your CV to us (article 6 par. 1a GDPR);
  • With reference to purpose (c) of par. 4, your consent that you provide to us by voluntarily participating and submitting your answers to our evaluation survey (article 6 par. 1a GDPR).
  • With reference to purpose (d) of par. 4, the legitimate interests pursued by us or by a third party, and in particular to safeguard our legal rights, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data (article 6 par. 1f GDPR);

6. Who has access to your personal data and to whom is it disclosed?

Your data may be communicated – for the purposes referred to in paragraph 4 of this privacy notice – to the following categories of recipients:

  • Companies belonging to the Deloitte Network;
  • Companies that provide services to us and/or the Deloitte Network;
  • Competent authorities, within the limits established by law and regulations;
  • Other entities within the Deloitte Network and other third parties, as part of a corporate transaction such as a sale, divestiture, reorganization, merger or acquisition, and only provided that the law permits such disclosure.

Your data will be communicated to these third parties after being appointed as Data Processors or recognized as autonomous Data Controllers and will be processed by collaborators and/or employees of Deloitte in the context of their respective functions and in accordance with the instructions given by Deloitte itself.

7. Are your data transferred abroad?

If necessary for the purposes stated above, the data collected may be transmitted or made accessible to other companies in the Deloitte network, to entities that provide services to us and/or the Deloitte network (e.g., vendors, suppliers), to competent authorities (e.g., courts, regulatory authorities) including those based in other countries, which may include countries outside the European Economic Area (EEA). Third parties to whom your personal data are transferred, are bound by specific agreement, and are required to keep your data securely.

In such cases, we guarantee that the transfer will take place in accordance with the provisions of Chapter V of the GDPR through the adoption of appropriate safeguards that ensure a level of data protection, as provided for in the applicable legal framework, such as Standard Contractual Clauses.

For further information about the third parties, how we work with them and their processing of your personal data, or for information about the adequate safeguards adopted by us in respect of data transfers please send an e-mail to DataPrivacyOfficer@deloitte.gr.

8. What is the data retention period, or if not possible, the criteria used to determine it?

The personal data that you provide to us will be processed and stored in our Executive Search & Selection information system for a period of two (2) years after the submission of your CV or until you revoke your consent, whichever occurs first. Before the end of this period, we may contact you to request your renewed consent for retaining your data for an additional two years, as well as to provide you with the opportunity to update the information we hold about you, should you wish to do so.

The above-mentioned data retention period may, however, be affected by other legal requirements which may extend minimum data retention requirements.

9. How do we protect and safeguard your personal data?

We will process your data with the utmost care and respect.

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, processed, or accessed in an unauthorized way, altered, or disclosed. These measures can include:

  • Education and training of our relevant staff to ensure they are aware of our privacy and data protection obligations when processing personal data;
  • Administrative and technical controls to restrict access to personal data on a “need to know” basis;
  • Technical security measures including, but not limited to: firewalls, encryption and anti-virus software;
  • Physical security measures.

In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any possible data breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so. Third parties will only process your personal data where they have agreed to treat the data confidentially and to keep it secure in compliance with the applicable law.

10. What are your rights and how can you exercise them?

In relation to the processing of your personal data, you have specific rights according to articles 12-22 of the GDPR:

  • Access: you can ask for confirmation as to whether or not a certain processing of data concerning you is in place, as well as further clarifications about the information referred to in this privacy notice;
  • Rectification: you can ask to rectify or supplement the data you have provided to us, if inaccurate;
  • Erasure: you can request that your data be deleted, if they are no longer necessary for our purposes, in case of withdrawal of consent or your opposition to the processing, in case of unlawful processing, or there is a legal obligation to erase them;
  • Restriction: you can request that your data be processed only for the purpose of storage, with the exclusion of other processing, for the period necessary for the correction of your data, in case of unlawful processing for which you oppose the erasure , if you have to exercise your rights in court and the data stored by us may be useful to you and,  finally, in the event of opposition to the processing and a review is in progress on the prevalence of our legitimate reasons over yours;
  • Object: you can object at any time to the processing of your data, unless there are our legitimate reasons to proceed with the processing that prevail over yours, for example for the exercise or defense of our legal claim in court;
  • Withdrawal of consent: you may withdraw your consent at any time, in all cases where consent is the legal basis for processing. Withdrawal of consent does not affect the lawfulness of processing based on consent prior to its withdrawal.
  • Portability: you can ask to receive your data, or to have them transmitted to another Data Controller indicated by you, in a structured format, commonly used and readable by automatic device.

To exercise these rights, you can contact our Data Protection Officer by sending an e-mail to DataPrivacyOfficer@deloitte.gr.

The time limit for the Deloitte to address your request is 1 month, which may be extended up to 2 further months in cases of particular complexity.

We also inform you that you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA), by following the instructions found on the HDPA’s website.

11. Changes to this Privacy Notice

We may modify or amend this Privacy Notice from time to time at our discretion and we will promptly inform you through traditional channels of communication. When we make changes to this notice, we will amend the revision date at the top of this page, and such modified or amended Privacy Notice will be effective from that revision date. We therefore invite you to regularly consult our Privacy Notice in order to stay up to date with any changes made since your last consultation.

This document has been prepared by Deloitte Business Solutions Societe Anonyme of Business Consultants, Deloitte Certified Public Accountants Societe Anonyme and Deloitte Alexander CompetenceCenter Single Member Societe Anonyme of Business Consultants.

Deloitte Business Solutions Societe Anonyme of Business Consultants, a Greek company, registered in Greece with registered number 000665201000 and its registered office at Marousi Attica, 3a Fragkokklisias & Granikou str., 151 25, Deloitte Certified Public Accountants Societe Anonyme, a Greek company, registered in Greece with registered number 001223601000 and its registered office at Marousi, Attica, 3a Fragkokklisias & Granikou str., 151 25 and Deloitte Alexander Competence Center Single Member Societe Anonyme of Business Consultants, a Greek company, registered in Greece with registered number 144724504000 and its registered office at Thessaloniki, Municipality of Pylaia - Chortiatis of Thessaloniki, Vepe Technopolis Thessaloniki (5th and 3rd street), 555 35, are all companies of the Deloitte Central Mediterranean S.r.l. (“DCM”) geography. DCM, a company limited by guarantee registered in Italy with registered number 09599600963 and its registered office at Via Santa Sofia no. 28, 20122, Milan, Italy is one of the Deloitte NSE LLP geographies. Deloitte NSE LLP is a UK limited liability partnership and member firm of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee.

Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited (“DTTL”), its global network of member firms and their related entities (collectively, the “Deloitte organization”). DTTL (also referred to as “Deloitte Global”) and each of its member firms and related entities are legally separate and independent entities, which cannot obligate or bind each other in respect of third parties. DTTL and each DTTL member firm and related entity is liable only for its own acts and omissions, and not those of any of each other. DTTL does not provide services to clients.

Please see www.deloitte.com/ about to learn more.

DTTL, Deloitte NSE LLP and Deloitte Central Mediterranean S.r.l. do not provide services to clients. Please see www.deloitte.com/about to learn more about our global network of member firms.

Deloitte is a leading global provider of audit and assurance, consulting, tax and related services. Our global network of member firms and related entities in more than 150 countries and territories serves four out of five Fortune Global 500® companies. Learn how Deloitte’s approximately 460,300 people make an impact that matters at www.deloitte.com.

This document and its contents are confidential and prepared solely for your use, and may not be reproduced, redistributed or passed on to any other person in whole or in part, unless otherwise expressly agreed with you. No other party is entitled to rely on this document for any purpose whatsoever and we accept no liability to any other party, who is provided with or obtains access or relies to this document.

© 2025 For more information contact Deloitte Central Mediterranean.