ĢƵ Allen Careers Privacy Notice

Last Updated: April 2025

1. Introduction and Definitions

This Privacy Notice explains how and why ĢƵ Allen Hamilton, Inc. and its subsidiaries and affiliates (collectively, “ĢƵ Allen,” “We,” or “Company”) collect and use Personal Information (or "PI") from Prospects and Applicants through Careers.ĢƵAllen.com (“Site” or “Careers website”), Workday, and other channels, such as events and social media. It also describes the rights you have with respect to your PI.

Prospects are individuals who may be interested in applying for a job at ĢƵ Allen.

Applicants are individuals who have applied for a job at ĢƵ Allen.

Personal Information (or “PI”) refers to information that can identify an individual, either on its own or when combined or associated with other information. PI includes Sensitive PI (or “SPI”) and Protected Health Information (or “PHI”).

SPI refers to certain categories of PI, such as:

  • Social Security numbers
  • government identification cards or numbers
  • citizenship or immigration status associated with a particular individual
  • financial information related to an individual’s financial account
  • precise geolocation
  • biometric or genetic data identifiable to an individual
  • medical information identifiable to an individual
  • criminal convictions or offenses identifiable to an individual
  • racial or ethnic origin identifiable to an individual
  • religious or philosophical beliefs identifiable to an individual
  • union membership identifiable to an individual
  • sex life or sexual orientation identifiable to an individual
  • contents of communications if obtained by someone who is not the intended recipient

PHI means individually identifiable health information created or received by a Covered Entity (for example, health plan, health care clearinghouse, or health care provider conducting electronic transactions) or Business Associate (for example, a service provider which must use, access, or create Protected Health Information to provide services to ĢƵ Allen).

2. Scope

We collect information from and about Prospects and Applicants in connection with employment opportunities at ĢƵ Allen. In general, the data we collect includes resumes or curriculum vitaes (CVs), identification documents, educational background, work history, employment information, and social profiles; some of this information may be sourced from third parties. For example, social profiles may include information from LinkedIn and other third parties that aggregate data to create social profiles.

We use your information to measure your qualifications based on education, experience, and skills for available positions at ĢƵ Allen. The information is shared with recruiters, hiring managers, and other persons involved in the recruitment process. ĢƵ Allen may collect further information from Applicants who are invited for an interview.

We also collect Sensitive Personal Information (or “SPI”) from Applicants during the recruitment and onboarding process as required by relevant employment laws, or when the Applicant consents and voluntarily provides the information, as permitted by applicable law.This information assists ĢƵ Allen in providing a diverse working environment and in providing benefits. In some cases, ĢƵ Allen is required by law to provide diversity information and may need to make an assessment without the help of the Applicant or employee. Notice is provided to the Applicant at the time of this data collection.

In addition, we collect SPI related to criminal background checks on Applicants after they receive an offer.

3. Your Rights in Relation to the Personal Information (or "PI") We Collect and Process About You

Depending on where you reside, you may have the following rights related to your PI:

  • right to request access to your PI stored by ĢƵ Allen
  • right to request that ĢƵ Allen amend, update, or correct your PI
  • right to request that ĢƵ Allen delete your PI
  • right to receive a copy of your PI
  • right to opt-out of marketing communications from ĢƵ Allen at any time
  • right to restrict or to object to the processing of you PI by ĢƵ Allen
  • right to withdraw consent if you have voluntarily provided PI or have consented to provide your PI
  • right to request access and/or opt-out of automated decision-making and right to appeal a decision related to automated decision-making
  • right to complain to a data protection authority

Note that these rights are not absolute. They are dependent upon, and subject to, certain conditions and exceptions under applicable laws and regulations. For more information on the rights that apply to you, based on the state in which you reside, please see the Privacy Statement for U.S. Residents. To exercise any of the above rights, please contact us at [email protected] or call 877-927-8278. In your request, please include the following:

  • the nature of the request – that is, the specific right you are asserting (see the Your Rights in Relation to the PI We Collect and Process About You section above)
  • the specific PI you seek to access, amend, delete, restrict, transmit to another company, or withdraw your consent to process– or if you wish to exercise one or more of these rights with respect to all of your PI.

For your protection and to mitigate the risk of fraud, we must verify your identity, in accordance with applicable law(s) and regulation(s), before processing your request. Thus, we will only respond to your request if we have enough information about you to verify your identity and your relationship to ĢƵ Allen (e.g., employee, former employee, client).

We will comply with your request as soon as reasonably practicable and within the timeframe set forth in applicable law(s) and regulation(s).

Please also note that we may need to retain certain information to comply with legal or regulatory obligations or to complete any transactions that you began prior to submitting your request. Residual PI may also remain in backup copies. Such residual PI will not be removed until the applicable retention period ends, per ĢƵ Allen’s records retention policy, unless otherwise required by law.

4. Minors

ĢƵ Allen does not direct this Site to individuals under the age of eighteen (18), and we do not knowingly collect, process, disclose, or share the Personal Information (or “PI”) of minors from this Site. If you are a minor and believe that you have provided PI, please ask your parent(s) or legal guardian(s) to notify us, and we will delete your PI.

5. Personal Information (or “PI”) We Collect and For What Purpose

By clicking on the links immediately below, you will be directed to certain portions of this policy, with a more detailed explanation of the information ĢƵ Allen collects and the purposes for collecting such information:

A.Information Submitted by Individuals

B.Information from Third Parties and Referrals

C.Information from Publicly Available Sources

D.Sensitive Personal Information (or "SPI")

E.Information that is Collected Automatically

F.Individuals Who Engage with Social Media Plug-ins

A. Information Submitted by Individuals

We collect Personal Information (or “PI”) that you provide voluntarily through our Site when you provide an online application by attaching your resume, completing the online form, and creating an account in Workday. We also collect PI from you when you register for a Talent Community to receive information about ĢƵ Allen career events and opportunities, as well as highlights about the work we do, the mission we serve, and the people who are at the heart of ĢƵ Allen. We may also collect PI from you when you attend events. We may store the PI collected at events to use for recruiting purposes.

If you submit any PI related to other people to us or to our service providers, you represent that you have the authority to do so and permit us to use the information in accordance with this Privacy Statement.

If you elect to opt-out of the Talent Community registration or out of receipt of ĢƵ Allen publications or marketing communications, your basic contact details will remain on our opt-out list.

PI that may be collected from registration in the Talent Community or at an event includes:

  • name
  • personal and business email address
  • phone number
  • country of residence
  • city
  • state
  • zip or postal code
  • clearance status
  • area of interest
  • job search activity level
  • resume
  • previous employment at ĢƵ Allen
  • any other PI that you voluntarily choose to provide us

Additional information that may be collected from Applicants includes:

  • employment history
  • education
  • photographs
  • biometric data related to face and voice
  • other information pertinent to the job application
  • any other PI that you voluntarily choose to provide us

Purposes for which ĢƵ Allen Processes the PI Provided by Prospects and Applicants

ĢƵ Allen collects and processes the PI of Prospects and Applicants for the following purposes:

  • general recruiting and employment purposes
  • for review by recruiters
  • to store for future career opportunities
  • to communicate about ĢƵ Allen career events and opportunities or other information about ĢƵ Allen’s mission
  • to hire and onboard Applicants
  • to review and match candidates to open positions, including using recruiting software and methods, including artificial intelligence functionality to supplement human reviews to train and optimize artificial intelligence tools

Legal Basis for Processing PI

  • explicit consent of the Prospect or Applicant related to information submitted
  • ĢƵ Allen’s legitimate interest in

o sourcing talent

o processing applications for ĢƵ Allen’s positions and roles

o hiring and onboarding

o carrying out pre-employment background screening

o developing, enhancing, and improving our recruiting methods

o complying with legal or regulatory requirements

o protecting the security of ĢƵ Allen personnel, buildings, and assets

B. Information from Third Parties and Referrals

ĢƵ Allen may receive your Personal Information (or “PI”) from a current ĢƵ Allen employee or a third party who refers you to a ĢƵ Allen job. ĢƵ Allen will use PI to match Prospects and Applicants to the requirements and qualifications stated in job postings. This process may be supported by technological applications, including artificial intelligence. ĢƵ Allen may also use this information to enhance and optimize recruiting methods.

Information collected through a referral may include:

  • name
  • email address
  • phone number
  • position title
  • employer
  • third-party profiles, such as LinkedIn
  • security clearance status
  • country, state, city
  • areas of interest
  • relationship with the person referring

ĢƵ Allen also uses third-party service providers for recruiting and hiring purposes, such as to conduct background investigations. These third parties may collect information from universities to verify degrees and education, and from law enforcement or public records to conduct a criminal background check. ĢƵ Allen also uses third parties for identity verification of applicants during onboarding, including through the use of facial recognition.

Legal Basis for Processing Information from Third Parties and Referrals

  • Explicit consent of the Candidate or Applicant who applies for jobs
  • ĢƵ Allen’s legitimate interest in

o sourcing talent

o carrying out pre-employment background screening

o complying with legal or regulatory requirements

o protecting the security of ĢƵ Allen personnel, buildings, and assets

C. Information from Publicly Available Sources

Social Media Sites and Job Boards

ĢƵ Allen uses various job boards, such as Indeed and Glassdoor, as well as social media platforms, such as Twitter or LinkedIn, for recruitment or marketing purposes, including targeting ĢƵ Allen articles to Prospects. We use these sources to provide easy access to relevant information about job opportunities and events, and to promote our services and brand. We also use job boards and social media to identify and recruit Prospects, including collecting Personal Information (or "PI") from social media platforms, such as LinkedIn.

ĢƵ Allen is responsible for the content it publishes using these platforms but does not have control over the platforms and the way they are administered. When using job boards and social media platforms, you must adhere to the terms of use and privacy policies imposed by the platform providers. If you would like to access this data or invoke your rights to the data, such as the right to correct or object to the processing of the data, you should contact the platform provider.

Some social media platforms provide ĢƵ Allen with data relevant to our pages that is aggregated or combined with similar data from other visitors to our social media sites, such as the number of “likes” triggered by our content or the amounts of posts, visitors to the sites, information downloaded, or links clicked.

Other Public Sources

ĢƵ Allen may also use other sources to identify and collect the PI of Prospects, such as public information from industry speakers and authors of white papers. ĢƵ Allen stores this PI and conducts automated screening with the PI and job opportunities for the purpose of recruiting.

More specifically, ĢƵ Allen may use the PI of Prospects obtained from public sources to identify roles that may be a good fit. The legal basis for processing this information is ĢƵ Allen’s legitimate interest in sourcing talent.

D. Sensitive Personal Information (or “SPI”)

We do not intend to collect SPI or Protected Health Information (or “PHI”) from Prospects and will only request the minimal SPI necessary to conduct background checks and onboarding of Applicants. Applicants consent to the use of the SPI for these purposes when they provide it to us for the purposes of onboarding and background checks.

We encourage you not to provide SPI in free text boxes or communications, but if you do, you acknowledge that you consent to our collection and processing of such SPI.

E. Information that is Collected Automatically

When you visit our website, we collect certain PI automatically from your device. For example, we may collect:

  • broad geographic location (e.g. country, city-level, or zip location)
  • company name
  • internet protocol (IP) address
  • pixel identifier (ID)
  • email address
    • how your device interacts with our site, including pages viewed, time you visited, current universal resource locator (URL), and links clicked
    • Our site also uses various social media plug-ins.

Purposes for Which ĢƵ Allen Processes the PI of Visitors to the Site

ĢƵ Allen collects and processes the PI of visitors to our website for the following purposes:

  • to administer and manage our site
  • to personalize and improve your browsing experience by displaying content and advertising that may be of particular interest to you
  • to provide news or information that may interest you through social media plug-ins on the Site
  • to analyze the data of visitors to our website and website traffic information
  • to determine your employer or organization with which you associate
  • to develop our business and services
  • to provide marketing communications and materials
  • general recruiting and employment purposes
  • to monitor and enforce compliance with applicable terms of use
  • to conduct quality and risk management reviews
  • to maintain security
  • to allow for event and webinar registration, management, and coordination
  • to allow content download

Note: If the Do Not Track setting or Global Privacy Control signal in your browser is enabled, marketing or targeting cookies will be disabled by default.

Legal Basis for Processing PI

  • Consent of the visitor based on interaction with our Cookie Banner, or configuration of the visitor’s browser settings as described above.
  • ĢƵ Allen’s legitimate interest in
    • effectively delivering information and services to you
    • developing and improving our site and user experience
    • marketing, growing, and protecting our business and services
F. Individuals Who Engage with Social Media Plug-ins

Social Media Plug-Ins

We may use social media plug-ins on our site that allow you to share information with your social network, view content, and provide you with relevant information. When you interact with these features, your internet browser will directly connect you to the relevant social network server to complete the action. The social media provider will know that the page with the plug-in on our site has been visited.

ĢƵ Allen or our service providers may also provide the social media provider with advertisements or marketing materials that they can deliver to individuals who viewed related content on our websites. The social media sites may also use the Personal Information (or "PI") collected in ways consistent with that provider’s notices and terms of use.

We have no control over the data collected by the social media providers through the use of the buttons. ĢƵ Allen does not know the type of data collected or how it is used.

Facebook plug-in

Our site may include plug-ins for Facebook. For an overview of the Facebook plug-ins, click . When you visit our site, a direct connection between your browser and the Facebook server is established via the plug-in. This enables Facebook to collect information from your IP address that you have visited our site. By clicking the Facebook “like button” while on the Facebook account, you will link the content of our site to your Facebook profile. For more information about the content of the data transmitted to Facebook or how Facebook uses the data, see Facebook’s privacy policy.

X plug-in

When you use Twitter and the “retweet” function, the websites you visit are connected to your Twitter account and made known to other users. If you are logged into X, data will also be transferred to X. For more information about the content of the data collected by X or how it is used, see X’s privacy policy.

Instagram plug-in

If you are logged into your Instagram account, you can click the Instagram button to link the content of our pages with your Instagram profile. For more information about the content of the data transmitted to Instagram or its use, see Instagram’s privacy policy.

YouTube

YouTube is operated by Google. If you visit one of our pages featuring a YouTube plug-in, the YouTube service collects information about which pages you have visited. If you are logged in to your YouTube account, YouTube allows you to associate your browsing behavior directly with your personal profile. For more information, see Google’s privacy policy.

LinkedIn

LinkedIn collects PI about your visits and interaction with our Site when you log in with LinkedIn through LinkedIn plug-ins, see LinkedIn privacy policy.

Social Media Tools

Google Maps

Our Site may use the Google Maps service via an application programming interface (API). Google Maps may process and/or save your IP address. ĢƵ Allen does not control the transfer of your data. For more information, see Google’s privacy policy.

Legal Basis for Processing and Sharing PI in Social Media Plug-Ins

ĢƵ Allen’s legitimate interest in:

  • promoting ĢƵ Allen services and brands
  • attracting, identifying, and sourcing talent
  • improving website experience and optimizing services
  • general recruiting and employment purposes

6. Communications with You

ĢƵ Allen may use the Personal Information (or “PI”) described above to communicate with you for recruitment-related purposes. We may reach out to you, based on your request and interactions with us, or our interest in you as a potential Prospect, to receive marketing or recruitment information and communications.

If we communicate with you via email, you have the option to opt out of further communications, or edit your preferences, with a convenient link in the footer of each email.

We only communicated with you via SMS (text messages) if you opt in to such communications. You will have the option to opt out easily by replying “STOP” at any time. Message and data rates may apply.

We will not share your email address or phone number with third parties for a use not described in this section. Please see the following section for additional information.

7. Sale and Sharing of Personal Information (or “PI”)

ĢƵ Allen does not sell PI collected from this Site for monetary consideration.

ĢƵ Allen does allow third parties to collect your browsing activity and certain other PI through automated technologies on our Site. These third parties may collect your PI when you are on this Site and may use your PI for purposes of advertising.

We may share the following PI with third parties through the use of cookies, pixels, and other online tools to improve our advertising by identifying your interests and information you might want to receive.

  • broad geographic location (e.g., country, city-level or zip location)
  • company name
  • internet protocol (IP) address
  • pixel identifier
  • device type
  • browser type
  • how your device interacts with our Site, including pages viewed, time you visited, current URL, and links clicked

You have the option to opt out of the sharing of your PI for advertising purposes by clicking on the Do Not Sell or Share My Personal Information link located in the footer of the Site. The link will take you to a notice which will explain how to effectuate your right to opt out. ĢƵ Allen will also recognize and treat an opt-out preference signal on your browser settings as a choice to opt out of the sharing of PI for targeted or contextual behavioral advertising.

Depending on where you are located, you can also opt out of the use of cookies and other online tools. For more information on how to exercise this option, you can visit our Cookie Policy, the cookie banner on this Site, and/or your browser’s settings and help menu. Please note that to the extent you access a Site across multiple devices or platforms or if you clear your browser settings, you may have to opt out again.

8. Retention

ĢƵ Allen retains Personal Information (or "PI") only as long as needed for the stated processing purpose. ĢƵ Allen’s record retention schedule provides the required retention periods for ĢƵ Allen records based on business and legal requirements, including the need to exercise and defend legal rights. ĢƵ Allen also maintains records for archiving and historical purposes in compliance with retention periods. If PI is not in a record subject to ĢƵ Allen’s retention schedule, ĢƵ Allen policy requires that the PI be deleted when no longer necessary for the stated processing purpose.

9. Transfers of Personal Information (or "PI")

ĢƵ Allen operates globally in several countries. If you would like a list of ĢƵ Allen affiliates and where they operate, please contact ĢƵ Allen at [email protected].

ĢƵ Allen centralizes various internal operations, including IT services, human resources, and finance/accounting functions in the United States. Client engagements in jurisdictions outside the United States often involve transfers of PI outside of the client’s or client’s jurisdiction. These transfers occur due to:

  • the need to access PI by ĢƵ Allen’s internal operations in the United States
  • the location of ĢƵ Allen employees working on the client engagement outside the client’s jurisdiction
  • the location of ĢƵ Allen vendors or subcontractors who are located outside of the client’s jurisdiction

This means that your PI may be transferred and processed outside of the country where you may be located. This includes transfers of PI from the European Economic Area (EEA) or the United Kingdom (UK) to countries with laws that the EEA, UK, or other jurisdictions have not deemed to provide an adequate level of protection for the processing of personal data.

ĢƵ Allen uses appropriate safeguards to protect the confidentiality, integrity, and availability of the PI transferred among ĢƵ Allen entities. For example, where PI is collected or obtained from individuals in the United Kingdom (UK) or European Economic Area (EEA), ĢƵ Allen has executed data transfer agreements that allow for global transfers within the ĢƵ Allen group of entities.

10. Disclosures of Personal Information (or “PI”) to Suppliers

ĢƵ Allen engages service providers to support our internal operations, including client contracts. We may disclose, and in some cases, transfer PI to our service providers and their affiliates and sub-processors (collectively, “Suppliers”). In other cases, Suppliers may collect and transfer PI on our behalf. For example, Suppliers may provide:

  • IT functions, such as information security, data storage, data analytics, business applications, and voicemail
  • recruitment functions, such as application management and recruitment communications/messaging
  • general operational support, such as enterprise management software, CRM software, archiving, and event management
  • accounting, finance, and billing support
  • compliance risk reviews and assessments, legal hold services, and legal case management
  • subcontractor services when we are engaged by a client when Suppliers provide services to ĢƵ Allen, they sometimes require access to PI. Thus, when engaging Suppliers, ĢƵ Allen requires them to contractually agree to comply with applicable privacy and data protection laws, including those related to information security and to the transfer of PI outside the jurisdiction from which it was collected. If you would like to know more about the Suppliers ĢƵ Allen engages, please contact ĢƵ Allen at [email protected].

11. Other Disclosures of Personal Information (or “PI”)

In addition to the other reasons set forth in this Privacy Statement, ĢƵ Allen might disclose PI about an individual:

  • when directed to do so by the relevant individual or with the individual’s consent
  • when the disclosure is consistent with the purposes described in this Privacy Statement
  • if and when required by applicable law, including applicable law outside the country where the PI was initially collected and/or where the individual resides
  • in connection with a reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of ĢƵ Allen’s business assets or stock (including in connection with any bankruptcy or similar proceeding)
  • to protect, exercise, and defend ĢƵ Allen’s legal claims, safety, or property
  • to comply with a regulatory or government inquiry, court order, or other legal obligation, including in a country different from where the PI was collected
  • to cooperate with a law enforcement inquiry or investigation

Note also that ĢƵ Allen is obligated to report certain activities or suspected criminal activity to relevant regulatory authorities and law enforcement entities. In these cases, recipients of the PI might include, for example:

  • law firms, tax advisors, or auditors
  • insurers
  • audit regulators
  • tax and customs, and excise authorities
  • regulatory bodies
  • credit reference/reporting agencies
  • courts, police, and law enforcement agencies
  • government departments and agencies
  • ĢƵ Allen Suppliers

ĢƵ Allen is sometimes legally prohibited from informing an individual about the disclosure either: 1) before the disclosure happens or 2) at any time.

12. De-identified Data

To the extent ĢƵ Allen intends to create de-identified data as defined by applicable law for the purposes of using the data in de-identified form, ĢƵ Allen policy requires that the data not be re-identified, except as permitted by applicable law.

13. Contact Us or a Relevant Government Agency

To ask a question, report an alleged violation of a privacy law or regulation, or compliment us, please contact us at [email protected]. You can also reach out to the privacy team at Office of the General Counsel, ĢƵ Allen Hamilton Inc., 8283 Greensboro Drive, McLean, Virginia 22102.

Depending on where you live, you might also have the right to submit a complaint to a national or state government agency, such as a Data Protection Authority or relevant Supervisory Authority in your country or your state Attorney General. For example, if you are in the European Economic Area (EEA), you may lodge a complaint with a Data Protection Authority for your country or region, or where an alleged infringement of applicable data protection law occurs.

14. Revisions to this Privacy Notice

We may change this Privacy Statement to reflect changes in our data collection and processing practices and/or applicable laws. Thus, we recommend checking here from time to time.