Privacy information for Employee verification connector(EVC)
Safe and secure employment and income verification.
Data is shared under the terms of the General Data Protection Regulations (GDPR), Experian and Equifax are authorised and regulated by the Financial Conduct Authority.
Data is encrypted using 256 bit encryption.
It's safe
• Since pay evidence is sourced directly from the employer, no payslips or sensitive information gets lost in the post or emails.
• The automation of the processes removes the need for manual processing of data.
• Reduces the potential for fraud as information is verified at source.
The employee needs to provide consent for each financial application submitted.
It's secure
• Information passed via secure API (an encrypted link), rather than email or post.
• Employees are in total control of who they share their data with as consent is provided during the application process.
Data
-
Data is securely stored within the IRIS Microsoft Azure Cloud environment.
-
Only used for IRIS employee verification purposes for Experian and Equifax.
-
The data is secured using the highest Microsoft Azure security levels within the IRIS infrastructure.
-
Encrypted using 256 bit encryption.
-
Employers can opt-in or out a company.
-
Depending on the kind of financial product applied for, the period of earnings to be verified can be between 3 and 12 months of previous earnings.
-
Privacy & Data protection policy | Terms and conditions | Data processing terms
Data used for verification | ||
Surname | Employment Leaver Date | Date of Birth |
National Insurance Number | Pay Currency | Payroll ID |
Gross Basic Annual Salary | Post Code | Year to Date Gross Income |
Employer Name | Year to Date Net Income | Employment Start Date |
Pay Date | Most Recent Hire Date | Pay Frequency |
Employment Type | Base Pay Rate Description | Base Pay Rate |
Common questions about privacy
We have partnered with Experian and Equifax for employees whose payrolls are processed by IRIS Payroll software for instant verification of income and employment status. Find out more.
Provide privacy notice to their employees. Find out more about on the employee fact sheet.
Consult their clients
-
Opt-out any clients that have not authorised processing for this purpose, before processing the client’s payroll using IRIS software enabled for EVC (see opt-out process per IRIS software product release notes and EVC details.
Additional information for customers who use IRIS desktop payroll products
-
IRIS will extract employee data from your product for storage in the [IRIS EVC Cloud] so that it is available to employees that wish to use the service for verification.
-
If you do not want this to happen you must opt-out before processing payroll in the EVC enabled IRIS software product that you use
Opt-out of the service before processing payroll see the product release notes/help and EVC details.
The following information is important for employers to provide their employees with privacy notice information (required by Articles 13 & 14 of the General Data Protection Regulation)
The employer
Payroll bureau where applicable
IRIS Software/relevant IRIS legal entity
Experian and Equifax (when authorised by individual employee using the service]
Data storage in EVC cloud is based on the employer’s legitimate interest in providing this service to their employees. Employers can consult ICO guidance on the legitimate interest.
IRIS as data processor takes its instruction from the T&Cs/Data processing agreement with our customers, which authorises data processing. However IRIS customers can withdraw this instruction specific to EVC by opting out, which will result in no employee data being extracted for this service.
The employee information is derived from payroll data in IRIS payroll software that is submitted to HMRC via RTI per payroll processing period.
EVC employee information is held by IRIS and queried per application by Experian and Equifax when an Employee consents to this being accessed.
IRIS , Experian and Equifax (when authorised by individual employees on a case by case basis)