McKinsey & Company Recruitment Privacy Notice

Effective date 15th February 2021.

McKinsey & Company Inc., and its subsidiaries and affiliates (“McKinsey”, “us” or “we”), understand that your privacy is important to you. McKinsey subsidiaries and affiliates may process your personal data in our capacity as data controllers. We are committed to respecting your privacy and protecting your personal data, which is any information that is capable of identifying you as an individual person. This Recruitment Privacy Notice (“Privacy Notice”) describes how we handle and protect your personal data in connection with McKinsey’s recruiting processes and programs.

This Privacy Notice only applies to the personal data of job applicants, potential candidates for employment or partnership, and those who participate in our recruiting programs and events. This personal data is submitted directly to McKinsey through the online application process and follow-up communications and/or through alternative channels (e.g., via professional recruiting firms). McKinsey may also collect and process your personal data should we engage in due diligence related to a potential corporate acquisition of your current employer (e.g., if you are part of the senior leadership team of a target company). This Privacy Notice does not apply to our employees, contractors or clients, or to other personal data that McKinsey collects for other purposes.

We will process your personal data in accordance with this Privacy Notice, unless such processing conflicts with the requirements of applicable law, in which case, applicable law will prevail.

By submitting your personal data to us, you acknowledge that:

  • You have read and understood this Privacy Notice and agree to the use of your personal data as set out herein.
  • Your personal data may be transferred and processed worldwide, including in countries that may not be deemed to provide the same level of data protection as your home country, for the purposes and in the manner specified in this Privacy Notice.
  • You are not required to provide any requested information to us, but your failure to do so may result in not being able to continue your candidacy for the job for which you have applied.
  • All of your representations are true and correct to the best of your knowledge and belief, and you have not knowingly omitted any related information of an adverse nature. Providing any inaccurate information may make you ineligible for employment.
  • This Privacy Notice does not form part of any contract of employment offered to candidates hired by McKinsey.

Personal data we collect

The types of personal data that we request from you and the ways that we process it are determined by the requirements of the country in which the role you apply for is located, and not the country in which you reside. Should you apply to more than one location or should the role to which you apply be available in more than one country, the types of personal data we request from you and the ways that we process it are determined by the requirements of all the countries in which the position is located.

We usually collect personal data directly from you when you apply for a role with us, such as your name, address, contact information, photographs and videos, work and educational history, achievements, identity documents, and test results. If you receive an offer from us, we may then conduct a background check and, to the extent permitted by applicable law, we may also collect data related to criminal offences and proceedings. We also collect similar personal data about you from third parties, such as professional recruiting firms, your references, prior employers, McKinsey employees with whom you have interviewed or who recommended your candidacy, and, to the extent permitted by applicable law, employment background check providers. We may also collect personal data about you online to the extent that you have chosen to make this information publicly available. For example, we may find your profile on professional social media websites (such as LinkedIn), and contact you about suitable roles.

Sensitive personal data is a subset of personal data that includes ethnicity, health, trade union membership, philosophical beliefs, sexual orientation, and other categories as prescribed by law. We may collect sensitive personal data about a candidate to the extent permitted to do so by applicable laws (e.g., U.S. equal opportunity laws) and to support our efforts to create an inclusive and diverse work environment. We may also collect sensitive personal data to the extent that a candidate chooses, without being asked, to voluntarily disclose it during the recruiting process.

Use of your personal data

We collect and use your personal data for legitimate human resources and business management reasons, including:

  • identifying and evaluating candidates for potential employment, as well as for future roles that may become available;
  • maintaining records in relation to recruiting and hiring;
  • ensuring compliance with legal requirements;
  • fostering our diversity and inclusion programs and practices;
  • conducting criminal history checks to the extent permitted by applicable law, and if you receive an offer from us;
  • protecting our legal rights to the extent authorized or permitted by law; or
  • emergency situations where the health or safety of one or more individuals may be endangered.

We may also use your personal data for McKinsey analytics purposes, including in aggregated/pseudonymized form, to improve our recruitment and hiring process and augment our ability to attract successful candidates.

Legal basis for processing your personal data

Our processing of your personal data for the purposes mentioned above is based:

  • in part, on our legitimate business interest in evaluating your application to manage our relationship with you, to ensure that we recruit appropriate employees, and to evaluate and maintain the efficacy of our recruiting process more generally;
  • in part, on our performing contractual and precontractual measures relating to our potential employment relationship with you;
  • in part, on our complying with applicable law with regard to personal data necessary to satisfy our legal or regulatory obligations;
  • in part, on your consent, if we offer you the opportunity to participate in our optional recruiting programs or if we collect sensitive personal data, to the extent permitted by applicable law.

Background screening

If you receive an offer from us, we may conduct a background check on you or instruct a third party to do so on our behalf. Background screening will only be done where permitted by law applicable to the location where the position is located and to the extent necessary and proportionate to the role that you are being offered. A background check will only involve criminal background data to the extent permitted in your specific jurisdiction. Our legal basis for background screening is our need to perform precontractual measures related to establishing our employment relationship. If background screening is required for your application, you may be contacted by a third-party background screening service provider to request authorization for the release of your information, and at that time you will be provided with further information about the process and what personal data it might involve.

Data recipients and international data transfers

Your personal data may be accessed by recruiters and interviewers working in the country where the position for which you are applying is based, as well as by recruiters and interviewers working in different countries within the McKinsey global organization. Individuals performing administrative functions and IT personnel within McKinsey may also have limited access to your personal data to the extent necessary to perform their jobs. In some countries, you may have fewer rights under local law than you do in your country of residence, but we have put in place legal mechanisms designed to ensure adequate data protection for your personal data when it is processed by McKinsey subsidiaries and affiliates within the McKinsey global organization and by McKinsey’s service providers, including the transfer of your personal data to countries other than the one in which you reside.

We use third-party service providers to provide a recruiting software system. We also share your personal data with other third-party service providers that may assist us in identifying and recruiting talent, administering and evaluating pre-employment screening and testing, and improving our recruiting practices.

We maintain processes designed to help ensure that any processing of personal data by third party service providers is consistent with this Privacy Notice and protects the confidentiality, availability, and integrity of your personal data in compliance with applicable law. Where required by law, we put in place additional legal mechanisms designed to help ensure adequate data protection of your personal data in a third country. If you would like more information about these legal mechanisms, which may include the EU’s Standard Contractual Clauses, please contact us at the address provided at the end of this Privacy Notice.

In addition, we may disclose or transfer your personal data in the event of a re-organization, merger, sale, joint venture, assignment, or other transfer or disposition of all or any portion of our business.

Automated sorting of applicants

In certain jurisdictions, we may use data analytics and algorithms to help us review the large quantities of candidates and application data that we receive. These algorithms help us prioritize the application review process and sort candidates on the basis of characteristics that suggest strengths and capabilities necessary to perform the relevant role. The algorithms are designed to analyze the candidate’s application data and compare it to our historical data on previously successful and unsuccessful candidates.

The automated results are always considered in tandem with, and not in lieu of, human judgement. We evaluate each individual candidate on their own merits. Certain roles may require specific prerequisites or skills (for example, fluency in a certain language, particular professional qualifications or certifications, or number of years in a similar role). Applications that do not meet those requirements may be automatically rejected.

Data retention

If you accept an offer of employment with us, any relevant personal data collected during your pre-employment period will become part of your personnel records and will be retained in accordance with specific country requirements and with the privacy notice applicable to McKinsey employees, which will be provided during the on-boarding process.

If we do not employ you, we may nevertheless continue to retain and use your personal data for a period of time (which may vary depending on the country) for system administration purposes, to consider you for potential future roles, and to perform research. Thereafter, we retain a minimal amount of your personal data to record your recruiting activity with us.

We may want to remain in contact with you and consider you for future employment opportunities. In such an event, we will seek your consent to include you in one of our recruiting programs that provides you ways to further learn about and stay in touch McKinsey, either prior to or after you formally apply for a job opportunity. Participation in these recruiting programs is entirely optional.

If you join a recruiting retention program, we retain your personal data for a period of time specific to that program, but if you wish to withdraw at any time, please contact us at keep-in-touch@mckinsey.com. For candidates in Germany, please contact us at karriere@mckinsey.com.

Security

We use generally accepted standards of technical and operational security to protect personal data. Only authorized personnel of McKinsey and of our third-party service providers are permitted to access personal data, and these employees and third party service providers are required to treat this information as confidential. Despite these precautions, we cannot guarantee that unauthorized persons will not obtain access to your personal data.

Your rights

We take reasonable steps that are designed to keep your personal data accurate, complete, and up-to-date for the purposes for which it is collected and used. We also have implemented measures that are designed to help ensure that our processing of your personal data complies with this Privacy Notice and applicable law.

In accordance with applicable law, you may have one or more of the following rights:

  • a right to request a copy of the personal data that we hold about you and details of how we use that information;
  • a right to amend or rectify your personal data if any of the information held about you is incorrect or out of date;
  • a right to portability of your personal data;
  • a right to request erasure of your personal data;
  • a right to demand that we cease the processing of your personal data or that we restrict the processing of your personal data;
  • a right to withdraw your consent to the processing of your personal data, to the extent our processing relies on your consent as the lawful basis for processing. This right may not apply if there are other legal justifications to continue processing or we need to retain certain personal data where required or permitted under applicable law; and/or
  • a right to provide us with instructions as to the processing of your personal data in case of death.

In addition, and where granted by applicable law, you may have the right to lodge a complaint with a competent data protection authority.

If you would like to make a request to access, review, correct, delete or port the personal data we have collected about you, to assert a right with regard to your personal data, or to discuss how we process your personal data, please complete this form. If you are unable to access this form for any reason, you may contact us using the information at the end of this Privacy Notice.

To help protect your privacy and security, we will take reasonable steps to verify your identity before granting you access to your personal data. We will make reasonable attempts to promptly investigate, comply with, or otherwise respond to your requests as may be required by applicable law. Depending upon the circumstances and the request, we may not be permitted to provide access to personal data or otherwise fully comply with your request; for example, where producing your information may reveal the identity of someone else. We reserve the right to charge an appropriate fee for complying with your request where allowed by applicable law, and/or to deny your requests where, in the Firm’s discretion, they may be unfounded, excessive, or otherwise unacceptable under applicable law.

Social Media Tools

Our application process allows you to provide us with relevant personal data from information you have on third-party websites (such as LinkedIn, Google Drive and Dropbox). If you choose to incorporate your personal data from third-party websites, , it will be used in accordance with this Privacy Notice.

Cookies and other tracking technologies

We may use first party and third-party cookies, web beacons, pixels, clear gifs, and other similar technologies (collectively “Cookies and Other Tracking Technologies”) to identify you and your interests, to remember your preferences, and to track your use of our websites. We also use Cookies and Other Tracking Technologies to control access to certain content on our websites, to protect the websites, and to process any requests that you make of us.

Some of our online recruiting activities are hosted by third parties. When you access sites operated by these third parties, they may, consistent with our Cookie Policy, place their own Cookies or Other Tracking Technologies on your device. You can learn more about our use of Cookies and other tracking technologies by reading our Privacy Policy and Cookie Policy.

For candidates from other countries

Availability of the Recruitment Privacy Notice in Other Languages:

  • Arabic
  • Chinese (Simplified)
  • Chinese (Traditional)
  • English
  • French (Canada)
  • French (France)
  • Korean
  • Polish
  • Portuguese (Brazil)
  • Portuguese (Portugal)
  • Russian
  • Spanish (Spain)
  • Spanish (Latin America)

CONTACT

If you have any questions about this Privacy Notice or if you would like to communicate with any of our Data Protection Officers or the Data Privacy Team, please contact us at:

McKinsey & Company
Legal Department
711 Third Avenue
New York, NY 10017
212-446-7000
privacy@mckinsey.com

McKinsey reserves the right to modify this Privacy Notice. We will post any changes to our Privacy Notice on this page. Please check this page regularly to keep up-to-date.