-
Purpose of this Agreement
As part of the GYA membership selection process, GYA Members and Alumni may be given access to personal data submitted by applicants. This data is provided solely for the purpose of assessing applications and supporting the official membership review process.
This Agreement sets out the obligations of reviewers regarding confidentiality, secure handling, limited use, and deletion of applicant personal data in accordance with applicable data protection requirements, including the General Data Protection Regulation, GDPR.
-
Scope
This Agreement applies to all GYA Members and Alumni who receive, access, download, view, discuss, or otherwise handle personal data of applicants during the membership review process.
Applicant personal data may include, but is not limited to:
- Name and contact details
- CVs, academic history, publications, and professional background
- Motivation letters or application statements
- Demographic information, where applicable
- References, evaluations, or reviewer comments
- Any other information contained in the application materials
-
Permitted Use of Applicant Data
Reviewers may use applicant personal data only for the following purpose:
To assess, evaluate, compare, and discuss membership applications as part of the official GYA membership selection process.
Reviewers must not use applicant personal data for any other purpose, including but not limited to:
- Personal, academic, commercial, or institutional purposes
- Contacting applicants independently, unless expressly authorised by GYA
- Adding applicants to mailing lists, networks, databases, or contact lists
- Sharing applicant information with third parties
- Using applicant data for research, publication, teaching, or analysis outside the selection process
-
Confidentiality Obligations
Reviewers agree to treat all applicant personal data and application materials as strictly confidential.
Reviewers must:
- Access applicant data only when necessary for the review process
- Keep application materials confidential at all times
- Not disclose, forward, copy, publish, discuss, or distribute applicant data to unauthorised persons
- Discuss applicant data only within authorised GYA review channels and meetings
- Take reasonable steps to prevent accidental disclosure or unauthorised access
These confidentiality obligations continue after the membership review process has ended.
-
Storage and Saving of Applicant Data
Reviewers should avoid downloading, saving, printing, copying, or storing applicant personal data locally unless strictly necessary for the review process.
Where temporary storage is necessary, reviewers must ensure that:
- Files are stored securely
- Devices are protected by password, PIN, biometric access, or equivalent security measures
- Files are not stored in unsecured personal cloud services, shared drives, or public folders
- Files are not accessible to family members, colleagues, students, assistants, or other unauthorised persons
- Printed copies, if any, are kept secure and not left unattended
Reviewers must not create independent databases, spreadsheets, archives, or collections of applicant data unless expressly authorised by GYA.
-
Deletion and Return of Data
Once the membership review process is completed, or earlier if requested by GYA, reviewers must delete or securely destroy all applicant personal data in their possession.
This includes:
- Downloaded application files
- CVs and supporting documents
- Local copies on computers, tablets, phones, or external drives
- Email attachments or emails as such including data of applicants of any kind
- Notes containing identifiable applicant information
- Printed copies
- Files stored in cloud storage or backup folders, where reasonably accessible
- Any temporary working documents created during the review process
Reviewers must not retain applicant personal data after the review process has ended unless GYA has given explicit written permission.
If requested, reviewers must confirm deletion to GYA in writing.
Suggested confirmation wording
I confirm that I have deleted or securely destroyed all applicant personal data and application materials received or created by me in connection with the GYA membership review process, except where retention has been expressly authorised by GYA in writing.
-
Security Measures
Reviewers must handle applicant personal data with appropriate care and security.
At a minimum, reviewers should:
- Use secure, password-protected devices
- Avoid accessing applicant data on public or shared computers
- Avoid using unsecured public Wi-Fi where possible
- Keep operating systems and software reasonably up to date
- Use secure GYA-approved platforms or channels where provided
- Log out of review systems after use
- Avoid forwarding application materials by email unless specifically authorised
- Report suspected unauthorised access, loss, or disclosure immediately
-
Data Breach or Accidental Disclosure
Reviewers must notify GYA immediately if they become aware of any actual or suspected data breach involving applicant personal data.
This includes, for example:
- Sending applicant data to the wrong person
- Losing a device containing applicant data
- Accidental public sharing of files
- Unauthorised access to application materials
- Theft, hacking, malware, or compromise of an account or device
- Inability to delete data due to technical or access issues
Notification should be sent to:
GYA contact: Beate Wagner, Managing Director
The notification should include, where known:
- What happened
- What data may be affected
- Which applicants may be involved
- When the incident occurred or was discovered
- What immediate steps have been taken
Reviewers must not contact affected applicants directly unless instructed by GYA.
-
International Access and Transfers
GYA Members and Alumni may be located in different countries. Reviewers acknowledge that accessing applicant data from outside the European Economic Area may constitute international access to personal data.
Reviewers agree to handle applicant data only in accordance with this Agreement and any additional instructions provided by GYA.
Reviewers must not transfer applicant data to another country, organisation, institution, platform, or individual unless authorised by GYA.
-
Use of External Tools, AI Systems, or Third-Party Platforms
Reviewers must not upload, copy, paste, process, summarise, analyse, or translate applicant personal data using external tools or third-party platforms unless expressly authorised by GYA.
This includes, but is not limited to:
- Generative AI tools
- Translation tools
- File conversion services
- Cloud storage platforms
- External scoring or analysis tools
- Personal or institutional document management systems
If a reviewer requires accessibility support, translation, or technical assistance, they should contact GYA for guidance before using any external service.
-
Reviewer Notes and Evaluation Comments
Reviewer notes and evaluation comments may themselves contain personal data. Reviewers must ensure that such notes are:
- Relevant to the membership assessment
- Respectful and professional
- Limited to what is necessary
- Submitted only through authorised GYA channels
- Deleted from personal devices or records after completion of the process
Reviewers should avoid including unnecessary sensitive information or subjective comments that are not relevant to the assessment criteria.
-
Compliance with GYA Instructions
Reviewers agree to follow all instructions provided by GYA regarding the handling, review, storage, discussion, return, and deletion of applicant data.
If a reviewer is unsure whether a particular action is permitted, they should contact GYA before proceeding.
-
Duration of Obligations
The obligations regarding confidentiality, non-disclosure, restricted use, and secure handling continue after the review process has ended.
The obligation to delete or destroy applicant personal data applies immediately after completion of the review process, or earlier if instructed by GYA.
-
Acknowledgement and Agreement
By signing this Agreement, the reviewer confirms that they:
- Have read and understood this Agreement
- Will use applicant personal data only for the GYA membership review process
- Will keep applicant personal data confidential
- Will not save, copy, share, or retain applicant data except as strictly necessary and authorised
- Will delete or securely destroy applicant data once the process is complete
- Will notify GYA immediately of any suspected or actual data breach
- Will comply with GYA’s instructions and applicable data protection requirements