PROTOTYPE DATA — For demonstration only. Not connected to production systems.

Prototype navigation only — switching does not authenticate across portals or change tenancy. Employer work uses employer sign-in; Operations staff use the Ops staff switcher.

Privacy & Data Protection

Data visible and withheld from authorised employers — based on current ERN privacy logic

← Legal & Governance
Amani Otieno
Prototype reference material — not production legal drafting.

Visible to authorised employers

Information an authorised employer may see when searching or viewing records

  • Employee identity (name, national ID or passport reference)
  • Past employment records with employer name and dates
  • Exit assessments and pillar ratings from former employers
  • Employer credibility score for past employers
  • Dispute status and resolution outcome
  • Serious-conduct flag category and status (not raw evidence)
  • Record consistency and evidence coverage indicators
  • Traffic-light record status (Green / Amber / Red / Blue-Grey)
  • Timeline events for completed employment periods

Hidden from authorised employers

Information withheld under current ERN privacy rules

  • Current employer identity while employment remains active elsewhere
  • Current employer name on active records viewed by other employers
  • Raw evidence file contents (contracts, payslips, letters)
  • Evidence document bodies and attachments
  • Unverified draft submissions not yet approved
  • Internal moderator notes and review commentary
  • National ID confirmation tokens used for report access

Current employer example

When Companyviews an employee currently employed elsewhere, the active employer's identity is withheld and shown as “Employer identity withheld”. This is a mandatory, server-owned policy (`CURRENT_EMPLOYER_VISIBILITY_POLICY` in `@/lib/employer-visibility-policy`) — it is not a configurable System Settings option.