Welcome

This notice is also available in Arabic, Hindi and Japanese language versions: 

عربي हिंदी 日本語

BAE Systems is committed to protecting the privacy and security of your personal information. This Notice describes how BAE Systems Plc and its subsidiaries, affiliates, and related entities (the “Company”, "we", “our”, or "us") collect and process personal information about you throughout our recruitment and onboarding process, and during and after your engagement with the Company. This Notice applies to prospective, current and former staff members only. This Notice applies to staff members located in the following countries working for the associated companies (including branches): 

Bahrain BAE Systems (International) Limited – Bahrain
Brazil BAE SYSTEMS do Brasil Ltda
Egypt BAE Systems Technology LLC
India BAE Systems India (Homeland Security) Private Limited
BAE Systems India (Services) Private Limited
Indonesia PT BAE Systems Services
BAE Systems (International) Limited - Indonesia
Iraq BAE Systems (International) Ltd - Iraq
Japan BAE Systems Japan GK
BAE Systems Air Japan KK
Kuwait BAE Systems Applied Intelligence Integrated Computer Solutions (Kuwait) SPC
Malaysia BAE Systems Applied Intelligence Malaysia Sdn Bhd
BAE Systems (International) Limited – Malaysia
Oman BAE Systems (Oman) Limited
BAE Systems Oman LLC
Qatar BAE Systems (International) Limited – Qatar
BAE Systems Operations Limited QA
BAE Systems QFC Branch
Singapore BAE Systems (International) Limited – Singapore
BAE Systems Applied Intelligence (Asia Pacific) Pte Ltd
South Africa BAE Systems (Military Air) Overseas Limited
South Korea BAE Systems (International) Limited - South Korea
Taiwan BAE Systems Holdings International LLC - Taiwan
Thailand BAE Systems (International) Limited - Thailand
Ukraine BAE Systems Ukraine LLC
United Arab Emirates BAE Systems plc - Abu Dhabi
BAE Systems Applied Intelligence (International) Ltd

This Notice describes the categories of personal information that we collect, how we use your personal information, how we secure your personal information, when we may disclose your personal information to third parties, and when we may transfer your personal information outside of your home location. This Notice also describes how you can access, correct, and request erasure of your personal information, where those rights apply under your Data Protection Laws. You can find the definitions for capitalised terms in the Glossary at the foot of this Notice.

Not all of the parts of this Notice will be relevant to everyone. The Notice is intended to provide details of the processing activities that we undertake and the listing of an activity in this Notice does not mean that we are processing your personal information in this manner and for these purposes. If you have any questions about how the information presented relates to you, please do contact us using the relevant contact details appearing in the contact us section.

We are a company with a global presence. We may be subject to different Data Protection Laws in the countries where we operate. Our approach to data protection across our business aims to be as consistent as possible and to satisfy all applicable Data Protection Laws, although the specific requirements, rights and obligations relating to personal information and/or our data processing activities in your country may be different. Nothing in this Notice may be interpreted to establish rights or obligations that go beyond what is mandated by the applicable Data Protection Laws.

Who is the data controller of my personal information?

The BAE Systems group company you apply to, or identified in your contract (whether issued by us or a third party), will typically be the data controller of your personal information. In addition, processing of personal information may be carried out by another group company, for related purposes or for its own purposes, in which case that other group company will be the data controller of your personal information.

How do you use my personal information?

The Annex to this Notice will help you understand how we use your personal information in our relationship or interactions with you.

We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason If we need to use it for a different reason, we will only do so if it is related to the original purpose. If we need to use your information in a way that is not covered in this Notice or is not related to the original purpose, we will give you additional information about that new use.

We may amend the content of the Notice from time to time to keep it up to date with current legal requirements and the way we operate our business.

What is the basis on which you justify processing my personal information? 

To carry out any processing of your personal information, we need to ensure that we have a particular reason to do so. The reasons that we have for processing your personal information relate to the legal grounds for processing set out in your Data Protection Laws (if any). The general reasons for processing all types of your personal information and what they mean are described further below:

Reason Description
Entering into or performing a contract with you. We can process your personal information where the processing is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into such a contract. This means that we can carry out the actions needed to conclude or execute our contract with you.
Complying with our legal obligations. We can process your personal information comply with a legal or regulatory obligation to which we are subject. Therefore, we can carry out any actions we need to take to comply with applicable laws.
The processing is needed for our or a third party’s (including your own) legitimate interests. We can process your personal information where the processing is necessary for our or a third party’s (including your own) legitimate interests, provided that those interests are not overridden by your interests or rights.
You have given your consent to the processing. We can process your personal information where you have given consent for us to process such personal information for a specific purpose. You can withdraw this consent, typically by contacting us. When applying for a role with us, if you choose to provide us with your personal information as part of the application or selection process, we may treat this as your implied consent to use that information where consent is required under your local Data Protection Laws. This is because you are voluntarily giving us the information so we can consider your application.
The processing is needed for vital interests. We can process your personal information where the processing is necessary to protect your life or someone else’s life or to keep you/them safe.
Sensitive personal information

To process your Sensitive Personal Information, we ensure that we have a particular reason to do so. This may be in addition to the general reasons for processing set out above. The reasons that we have for processing your Sensitive Personal Information relate to the legal grounds for processing set out in your Data Protection Laws (if any). The general reasons for processing Sensitive Personal Information and what they mean are described further below:

Legal ground Description
Carrying out our employment law obligations. We process Sensitive Personal Information where the processing is necessary for us to carry out any actions we need to undertake in order to comply with our obligations under employment, tax and health and safety law.
The processing is needed for occupational medicine. Our external and internal occupational health service providers process Sensitive Personal Information where the processing is necessary for the purposes of preventive or occupational medicine, for the assessment of your working capacity, or to provide a medical diagnosis.
The processing is necessary for substantial public interests. We process Sensitive Personal Information where the processing is necessary for reasons of substantial public interest, as set out in the applicable Data Protection Laws.
The processing is needed to protect your life or the life of another. We process Sensitive Personal Information where the processing is necessary to protect your vital interests or those of another person where you are physically or legally incapable of giving consent. This means that we can process your special categories of personal information in exceptional emergency situations, such as a medical emergency, for example.
The processing is needed for legal claims. We process Sensitive Personal Information if the processing is necessary for the establishment, exercise or defence of legal claims.

 

Data Protection Law in your jurisdiction may provide additional protections for certain other types of personal information. We will respect the requirements of applicable Data Protection Laws for these types of personal information

What if I don’t provide you with my personal information? 

In some cases, if you do withhold specific information we may not be able to continue with your application or maintain our relationship with you. This may happen where we require the relevant information to support the effective and efficient administration and management of that relationship.

For example, we require your identity information, contact and payroll information in order to pay you. If this is not provided, we may be unable to manage our contractual relationship.

How do you keep my information secure?

The Company is committed to securing the personal information we process. In support of this commitment, we have implemented appropriate technical, physical and organisational measures to ensure a level of security appropriate to the risks associated with our processing of your personal information.

Where do you get my personal information from?

In most cases, we receive the personal information directly from you. You either provide this to us at the outset of our relationship or do so at another time during your interactions with us. This will include personal information that you input into a form or through any self-service function, as well as information that you give to the HR team, your People Manager and to any member of our workforce.

We may create personal information about you during your relationship with us – see internal sources below.
In some cases, we get personal information about you from third party sources – see external sources below.

Internal sources

In addition to the personal information that you provide to us, we may generate some further personal information internally. This will usually be generated by HR or your line management as appropriate.

In some circumstances, data may be collected indirectly from monitoring devices or by other means (for example, building and location access control and monitoring systems, CCTV, telephone logs and recordings, IT network and application use logs and reports, and email and Internet access logs and reports), if and to the extent permitted by applicable laws. In these circumstances, the data may be collected by us or a third-party provider of the relevant service on our behalf.

External sources

We may also obtain some personal information from third parties.

We may obtain references from a previous employer, medical reports from your doctor (subject to the requirements of applicable law) or other external professionals (e.g. our occupational health service providers, share scheme and/or pension scheme administrators) information from tax authorities, benefit providers or from a third party that we engage to carry out security vetting or a background check (where permitted by applicable law). We may also receive results from recruitment‑related assessments, such as psychometric or aptitude tests carried out by trusted external providers. In some instances, we may obtain some personal information from public information sources.

When do you share my personal information with others?

Within the Company, your personal information can be accessed by or may be disclosed internally on a need-to-know basis – see internal recipients below.

Your personal information may also be shared with or accessed by third parties, including suppliers, advisers, national authorities and government bodies – see external recipients below.

In addition, there are circumstances where we may need to disclose your personal information to third parties, to help manage and secure our business, and to deliver our services. We may disclose your personal information to third parties if:

  • We sell or buy any business, in which case we may disclose your personal information to the prospective seller or buyer of such business;
  • BAE Systems plc or substantially all of its assets are acquired by a third party, in which case personal information held by it about you will be transferred to that third party;
  • We are under a duty to disclose or share your personal information in order to comply with any legal or regulatory obligation, to comply with national security requirements set by the government of the jurisdiction in which we operate, or in order to enforce or apply our legal rights, in which case we may share your personal information with our regulators and law enforcement agencies around the world, or to our legal advisers;
  • It is necessary to protect the rights, property, or safety of BAE Systems plc or any member of the BAE Systems group of companies, our customers, suppliers or others, in which case we may disclose your personal information to our legal advisers and other professional services firms; and
  • They provide services to us connected with your relationship with us.

Where these third parties (or any others) act as a Data Processor (for example, a payroll provider), they carry out their tasks on our behalf and upon our instructions to support business activities. In this case your personal information will only be disclosed to these parties to the extent necessary to provide the required services. 

Internal recipients

Internal recipients of your personal information may include:

  • local, and global departments, including line management and team members;
  • local management and global executive management responsible for managing or making decisions in connection with your relationship with the Company or when involved in a process concerning your relationship with the Company (including, without limitation, staff from Compliance, Legal, Audit and Security);
  • system administrators; and
  • where necessary for the performance of specific tasks or system maintenance by staff in teams such as the Finance and IT departments.

Personal information may also be shared inside of the Company between certain interconnecting IT systems.

In addition, where relevant, certain basic personal information (which may include your name, location, job title, contact information and any published skills and experience) may also be accessible to the Company's employees for the purposes set out in this Notice.

External recipients

External recipients of your personal information may include:

  • service providers;
  • joint ventures;
  • tax authorities;
  • regulatory authorities;
  • law enforcement;
  • our insurers;
  • our banks and other financial advisers;
  • IT administrators; lawyers;
  • auditors;
  • investors;
  • consultants and other professional advisors;
  • training bodies, education providers, vocational and professional membership and/or organisations;
  • payroll providers;
  • benefits providers;
  • administrators of our benefits programs; and
  • our customers.  

Personal information contained in our IT systems may be accessible by providers of those systems, their associated companies and sub-contractors (such as those involved with hosting, supporting and maintaining the framework of our HR information systems).

We expect these third parties to process any data disclosed to them in accordance with the contractual relationship we have with them and applicable law, including with respect to data confidentiality and security.

In addition, we may share personal information with national authorities in order to comply with a legal obligation to which we are subject. This is for example the case in the framework of imminent or pending legal proceedings or a statutory audit. 

Is any of my personal information transferred overseas?

We share your personal information within the BAE Systems group of companies as set out in this Notice (see “When do you share my information with others?” above).
Any transfers of personal information within the BAE Systems group will be covered by an intra-group agreement which gives specific contractual protections to ensure that your personal information receives an adequate and consistent level of protection wherever it is transferred within the group.

In addition, some of the external organisations (see “When do you share my personal information with others?” above) we share your personal information with may be located outside of the country in which you are based. We take steps to ensure that any transfer of personal information between jurisdictions is carefully managed to protect your privacy rights, such as by relying on approved standard contractual clauses for the transfer of personal information to third countries, other legally acceptable safeguards that ensure an adequate level of protection, or derogations available under Data Protection Law.

Any requests for information we receive from law enforcement or regulators will be carefully checked before personal information is disclosed.

How long do you retain my personal information?

We will retain your personal information for as long as is reasonably necessary for the purposes explained in this Notice. 

In some circumstances we may need to retain your personal information for longer periods of time than is needed for those purposes .For instance: where we are required to do so in accordance with legal, regulatory, tax or accounting requirements; to ensure that we have an accurate record of your dealings with us in the event of any complaints or challenges; or if we reasonably believe there is a prospect of litigation relating to your relationship with us.

We maintain policies governing the creation, retention and disposal of records in our care. These policies set out our requirements for the management of records, including guidance on keeping personal information as current as possible, securely deleting records and irrelevant or excessive data, and storing information in a manner which no longer identifies you.

How do you manage personal information about other individuals provided by me?

Apart from personal information relating to you, you may also provide us with personal information of third parties, for instance, your family or dependants, or your colleagues. Where this may be the case, we have set this out in this Notice.

Before you provide information about others to us, you must first inform these individuals that you intend to provide their details to us and of the processing to be carried out by us, as detailed in this Notice.

What are my rights?

Depending on your location, you may have certain rights under Data Protection Law, including the right to access, correct, restrict, port or delete your personal information. Where we make automated decisions with a legal effect or a similarly significant effect, you may have the right to request human review of such decisions.

If you wish to exercise your rights, you should contact us using the details below or contact your usual BAE Systems contact or manager. We will endeavour to respond to any request to exercise rights under Data Protection Law within the timescales set out in the applicable law. However, in some cases we will ask you to confirm your identity before we proceed.
 

What if I want more information?

If you are not satisfied with the level of information provided in this Notice, you can contact us using the following details:

The primary point of contact for all issues arising from this Notice, including requests to exercise data subject rights or to contact a relevant data controller, is external.dataprotection@baesystems.com. You can also submit your request verbally or in writing to your hiring manager or line manager.

How do you manage changes to this Notice?

We amend this Notice from time to time, for example, to keep it up to date or to comply with legal requirement.

Glossary of terms
General terms relating to personal information

Data controller means the company that determines the means and purposes of processing of personal information. For example, the BAE Systems entity which contracts with you will be your data controller as it determines how it will collect personal information from you, the scope of data which will be collected, and the purposes for which it will be used. 

Data processor means a natural or legal person (such as a company) that is responsible for processing personal information on behalf of a controller.

Data Protection Law or Data Protection Laws means the laws concerning the processing of data protection that apply in your local jurisdiction.

Personal information is information that relates to a living individual. It includes information that may identify a person by name and contact details, or refer to associated information such as account activity, or personal preferences that can directly or indirectly identify an individual.

Sensitive Personal Information includes any personal information relating to your health, genetic or biometric data, criminal convictions, sex life, sexual orientation, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership.

Categories of personal information

The following definitions are not exhaustive and are intended to illustrate the types of personal information that we process with reference to the categories described below.

  • Business information: your business contact details (e.g. address, telephone number, e-mail); your job title; your employer; any other information relevant to conducting business on behalf of the Company.
  • Contact information: home address; email address; and telephone number/s.
  • Data related to your engagement with the Company: work contact details (e.g. address, telephone number, e-mail); work location default hours; default language, time zone and currency for location; your worker ID and various system IDs; your performance review information; your work biography; your reporting line; your employee/contingent worker type; your hire/contract begin and end dates; your cost centre; your job title and job description; your working hours and patterns; whether you are full or part time; your termination/contract end date; the reason for termination; your last day of work; exit interviews, references, status (active/inactive/terminated); position title; the reason for any change in job and date of change; your benefit coverage start date.
  • Employment claims, complaints and disclosures information: termination arrangements and payments; subject matter of employment-based litigation and complaints; employee involvement in incident reporting and disclosures.
  • Financial information: credit card information; bank account details; other relevant information about your payment information.
  • HR processes information: allegations, investigations and proceeding records and outcomes; colleague and line management feedback; appraisals; talent programmes; formal and informal performance management processes; flexible working processes; restructure and redundancy plans; consultation records; selection and redeployment data; health and safety audits; other business audits; risk assessments; incident reports; data relating to training and development needs or training received.
  • Identity information: your title; forename and surname; preferred name; photographic images; any additional names
  • Immigration information: gender; nationality; second nationality; civil/marital status; date of birth; age; national ID number; immigration data; languages spoken; next-of-kin/dependent contact information.
  • Leave information: absence records (including dates and categories of leave/time-off); holiday dates; information related to family leave.
  • Monitoring information (to the extent permitted by applicable laws): Closed Circuit television footage; system and building login and access records; keystroke, download and print records; internet browsing records; call recordings; data caught by IT security programmes and filters such as firewalls, threat hunting software and data loss prevention tools.
  • Share information: number of shares held; date joined the register; date left the share register; dividends paid/not cashed; bank mandate details; share transactions; nationality and AGM / Proxy voting.
  • Staff related information: your title, forename, middle name(s) and surname; birth name; preferred name; any additional names; gender; nationality; second nationality; residency details; civil/marital status; date of birth; age; home contact details (e.g. address, telephone number, e-mail); national ID number; immigration and eligibility to work data; languages spoken; next-of-kin/dependent contact information; passport details; driving licence; car registration details.
  • Recruitment information: Professional and educational qualifications; references, CV and application; employment history; digital and in person interview and assessment data.
  • Regulatory information: records of your registration with any applicable regulatory authority, your regulated status and any regulatory references
  • Remuneration and benefits information: your remuneration information (including salary/hourly plan/contract pay information as applicable, allowance, bonus and merit plans), bank account details, grade, social security number, tax information, third party benefit recipient information
  • Vetting information: The results of any security- and employment-related vetting and verification checks, which include checking qualifications, financial and tax information, identity and right to work data, results of required criminality checks, nationality, directorships and sanctions and publicly available social media check results; details of certain personal or business travel plans.
Annex – Purposes of Processing
Recruitment and Selection

We use your personal information to communicate with you, assess your suitability for roles and make hiring decisions. We may also retain your details for future vacancies and analyse recruitment processes for improvement.

Categories of personal information: Staff Related Information; Recruitment Information.

Medical Screening

Where required by law, we assess health information during pre employment checks to confirm role suitability and make adjustments.

Categories of personal information: Staff Related Information; Recruitment Information; Sensitive Personal Information.

Ethics Reporting and Case Management

We operate reporting channels for raising concerns about unethical or unlawful conduct and process this information to investigate and act appropriately. In support of these processes and our compliance obligations, we operate a third party provided Ethics Reporting line.

Categories of personal information: Identity Information; Staff Related Information; Data Related to Your Engagement with the Company; Recruitment Information; Regulatory Information; Vetting Information; Remuneration and Benefits Information; Leave Information; HR Processes Information; Monitoring Information; Employment Claims, Complaints and Disclosures Information; Sensitive Personal Information.

Compensation and Benefits

We administer remuneration, benefits, pensions, share plans, tax/social security, expenses and budgets using your personal information.

Categories of personal information: Staff Related Information; Data Related to Your Engagement with the Company; Leave Information; Remuneration and Benefits Information; Financial Information; Vehicle Information.

HR Administration

We manage your employment relationship, including training, business planning, communications, reporting, surveying, equipment allocation and record keeping.

Categories of personal information: Staff Related Information; Data Related to Your Engagement with the Company; Recruitment Information; Regulatory Information; Remuneration and Benefits Information; Leave Information; Financial Information; HR Processes Information; Vehicle Information; images/photographs.

Health and Safety

We process information to meet health and safety requirements, conduct risk assessments and occupational health assessments and processes, and make workplace adjustments.

Categories of personal information: Staff Related Information; Data Related to Your Engagement with the Company; Recruitment Information; Employment Claims, Complaints and Disclosures Information; Sensitive Personal Information.

Business Travel and Immigration

We process personal information to arrange business travel, immigration formalities and, where applicable, relocation.

Categories of personal information: Staff Related Information; Data Related to Your Engagement with the Company; Financial Information; Sensitive Personal Information.

HR Processes

We manage appraisals, conduct, performance, capability, grievances, safeguarding, investigations and related HR decisions. We process information about absences, which can include health information, to administer absences and return to work processes.

Categories of personal information: Staff Related Information; Data Related to Your Engagement with the Company; Recruitment Information; Vetting Information; Regulatory Information; Leave Information; HR Processes Information; Monitoring Information; Employment Claims, Complaints and Disclosures Information; Sensitive Personal Information.

Vetting

We conduct vetting before and during employment, including identity (yours and your next of kin), qualifications, credit, driving, criminal record, employment history, travel and regulatory checks.

Categories of personal information: Staff Related Information; Data Related to Your Engagement with the Company; Recruitment Information; Regulatory Information; Vetting Information; Monitoring Information; Employment Claims, Complaints and Disclosures Information; Sensitive Personal Information.

Business Transformation

We process personal information for restructures, redundancies, change programmes and corporate transactions that affect employment.

Categories of personal information: Staff Related Information; Data Related to Your Engagement with the Company; Recruitment Information; Regulatory Information; Vetting Information; Remuneration and Benefits Information; Leave Information; HR Processes Information; Monitoring Information; Employment Claims, Complaints and Disclosures Information; Sensitive Personal Information.

Business Protection

We monitor systems, devices and activity to protect the business, ensure compliance with law and company policy, support staff safety, investigate security concerns and inform disciplinary procedures. These activities to protect our business from external and internal threats, and help us comply with industry security requirements laid down by governments in jurisdictions where we operate.

Categories of personal information: Staff Related Information; Business Information; Data Related to Your Engagement with the Company; Vetting Information; Leave Information; HR Processes Information; Monitoring Information; Employment Claims, Complaints and Disclosures Information; Sensitive Personal Information.

CCTV

We use video cameras for safety, security, incident investigation and policy compliance across sites and events.

Categories of personal information: Image; Audio; Vehicle Information.

Project Lists and Insider Lists

We maintain Project Lists and Insider Lists to comply with market abuse regulations and protect business value.

Categories of personal information: Staff Related Information; Data Related to Your Engagement with the Company.

Information Technology

We administer IT systems, manage access, provide support, enforce policies, test systems, monitor security and migrate data.

Categories of personal information: Staff Related Information; Data Related to Your Engagement with the Company; Recruitment Information; Regulatory Information; Vetting Information; Remuneration and Benefits Information; Leave Information; HR Processes Information; Monitoring Information; Employment Claims, Complaints and Disclosures Information; Sensitive Personal Information.

Legal and Regulatory

We use personal information to enforce or defend legal claims, comply with legal obligations, respond to authorities and manage intellectual property.

Categories of personal information: All categories of personal information held, including Sensitive Personal Information.

Company Accounts

We process personal information to open and administer accounts for authorised signatories and manage business credit card accounts.

Categories of personal information: Staff Related Information; Data Related to Your Engagement with the Company; Financial Information; signature.

Legal Compliance Registers and Records

We maintain registers of legal risks and records of incidents, accidents and compliance matters.

Categories of personal information: All categories of personal information held, including Sensitive Personal Information.

Insurance

We process personal information to manage insurance policies, claims and associated risk activities.

Security Clearance

We process identity and clearance information to manage access to classified materials and meetings.

Categories of personal information: Identity Information; Security Clearance Information.