Welcome to G-P Privacy & Security Center
G-P’s rigorous security, privacy, compliance, and transparency standards let you focus on your business with confidence.

Transparency.

Control.

Security.
Privacy resources.
At G-P, we take the privacy and security of our Customers’ and Professionals’ data seriously. Explore the links below for more information on G-P’s thorough approach to privacy and data protection.
Privacy statements.
At G-P, we value, protect, and defend privacy. We believe in transparency, so that people and organizations can control their data and have meaningful choices in how it is used.
Sub-processor list.
Where G-P acts as a processor in providing you with products or services, we may engage third party sub-processors to assist us. A list of our sub-processors is available for your review.
Cookies.
In order to provide you with more relevant offers and optimize your experience on our website, we use different types of cookies and advertising technologies. Learn about how we engage you and update your preferences.
Your Privacy & Security questions, answered.
These frequently asked questions are designed to assist you in understanding G-P’s approach to privacy and security.
How does G-P collect personal data?
G-P collects personal data:
Directly from you when you access various parts of our Services, including when you communicate with us via email or other channels;
From other sources, for instance, including your company and your company’s third parties who may send us your personal data on your or your Company’s behalf; and
From the network of websites and applications accessible through or utilized by our Services and our company, including third party suppliers (e.g. recruiting agencies) and our G-P related companies, affiliates, subsidiaries, partners and subcontractors. This includes personal data we collect automatically through our websites and applications, for instance by using cookies and similar technologies.
How does G-P protect Customers’ personal data?
G-P employs appropriate technical and organizational security measures to ensure a level of security appropriate to the risk and to protect personal data against loss, unauthorized access, disclosure, alteration, and destruction, and against other forms of unlawful or abusive treatment. To learn more and access to G-P security and compliance posture, please reference our
How does G-P meet its obligations under data protection laws?
G-P has a comprehensive global privacy program which includes policies, procedures, standards, and controls focusing on compliance with global data protection laws, including GDPR. This program is managed and monitored by a global privacy and data protection team. G-P’s comprehensive program includes policies, procedures, standards, and controls around:
Data Governance;
Data Mapping;
Incident Response;
International Data Transfers;
Notice and Consent;
Privacy Impact Assessment (and DPIAs);
Privacy By Design and Default;
Third Party Management;
Security of Data;
Recordkeeping;
Confidentiality; and
Training and Awareness of our team members.
G-P’s Privacy Policy explains how and why G-P collects, uses, stores, and discloses personal data / information from individuals who interact with us. You may consult it here
Is G-P a Data Controller or a Data Processor?
G-P is both a data controller and a data processor.
G-P collects and uses the Professional’s human resources data during the course the employment relationship. With regard to that information, G-P is a data controller. In the context of the employment relationship with the Professionals, G-P is not a processor on behalf of the Customer. To the extent Customers also collect and use the Professional’s personal data for the Customer’s own purposes, Customers are also data controllers with independent privacy obligations. Therefore, the exchange / sharing of Professionals’ Personal data between G-P and the Customer is under an independent Controller-to-Controller relationship.
On the other hand, through our SaaS-based platform (“G-P Platform”), we help Customers to find, hire, onboard, pay, and manage team members, quickly and compliantly, to expand growth opportunities for everyone, everywhere – without the hassle of setting up local subsidiaries or branch offices. By providing Customers with access to G-P Platform, G-P is a data processor for any personal data uploaded to the G-P Platform by Customer concerning the authorized users of the G-P Platform appointed by the Customer. G-P processes the account related date belonging to such authorized users of the GP Platform.
Those relationships between Customer and G-P are addressed in G-P Data Protection Addendum incorporated in the Master Agreement executed between the parties.
Does G-P transfer personal data across borders?
G-P disrupted the rules of international business by enabling organizations to hire anyone, anywhere in the world within minutes. Therefore, transferring personal data internationally is necessary for the provision of our Services. When sharing with or disclosing personal data to other parties, including to G-P’s related companies, affiliates, subsidiaries, partners and subcontractors who provide Services, personal data may be transferred to countries with data protection laws providing a lower standard of protection for your personal data than your country.
We will transfer your personal data in compliance with applicable data protection laws, including having adequate mechanisms in place to protect your personal data when it is transferred internationally (e.g. Standard Contractual Clauses, data processing agreements).
Is G-P obliged to provide or give access to personal data to third parties on the basis of national laws?
G-P protects the privacy of its Customers and Professionals and G-P not voluntarily provide third party. G-P has never received a request under U.S. surveillance laws to provide personal data to the U.S. government.
How does G-P manage and monitor its AI technologies safely and compliantly?
G-P has achieved ISO/IEC 42001 certification, the world’s most rigorous standard dedicated to Artificial Intelligence Management Systems (AIMS). This independently audited framework validates G-P's ability to responsibly develop, deploy and monitor AI technologies.
Comprehensive Risk Mitigation: Continuous identification and evaluation of AI-specific operational and security risks.
Data Governance & Integrity: Establishing strict parameters for AI data provenance and quality, ensuring data utilized by AI models is handled ethically and in alignment with global privacy principles.
Algorithmic Transparency: Ensuring AI system deployment features clear traceability and logging, allowing for meaningful human oversight and accountability.
Systemic Accountability: Establishing clear corporate governance and institutional responsibility for all AI outputs and lifecycles.
Does G-P give Professionals a privacy notice?
Yes, G-P issues a Privacy Notice to Professionals at the time their data is collected.
This means that:
When using Recruit services a candidate privacy notice is issued at the start of the selection process; and
An employee privacy notice is provided to all Professionals at the start of the engagement.
Our privacy notice ensures that Professionals are aware of the way their personal data is processed, helping them understand what data is being collected, why and how it’s being used, with whom will be shared, how it is secured and how long it will be kept.
How does G-P use cookies?
When you visit our websites, we may use cookies or similar technologies to deliver a more personalized experience. Cookies help us better understand your interests, tell us which parts of our website you’ve visited, and show how you’re interacting with our online ads and web searches. For more information on our cookies settings, and how to manage your preferences, visit our COOKIES SETTINGS in our website.





