DATA PROTECTION POLICY

Similar documents
SCHNEIDER GROUP OOO POLICY OF THE COMPANY REGARDING TO THE PERSONAL DATA PROCESSING

LAW OF THE REPUBLIC OF ARMENIA ON PROTECTION OF PERSONAL DATA CHAPTER 1 GENERAL PROVISIONS

ACT of August 29, 1997 on the Protection of Personal Data

STATOIL BINDING CORPORATE RULES - PUBLIC DOCUMENT

Act CXII of on the Right of Informational Self-Determination and on Freedom of Information 1 CHAPTER I GENERAL PROVISIONS. 1.

Instructions on the processing of personal data in the election process

DIRECTIVE 95/46/EC OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL. of 24 October 1995

THE PROCESSING OF PERSONAL DATA (PROTECTION OF INDIVIDUALS) LAW 138 (I) 2001 PART I GENERAL PROVISIONS

PROTECTION OF PERSONAL INFORMATION ACT NO. 4 OF 2013

CONSULTATIVE COMMITTEE OF THE CONVENTION FOR THE PROTECTION OF INDIVIDUALS WITH REGARD TO AUTOMATIC PROCESSING OF PERSONAL DATA

SUBSIDIARY LEGISLATION DATA PROTECTION (PROCESSING OF PERSONAL DATA IN THE POLICE SECTOR) REGULATIONS

Personal Data Protection Act

THE DATA PROTECTION BILL (No. XIX of 2017) Explanatory Memorandum

The Act on Processing of Personal Data

RESTREINT UE/EU RESTRICTED

South Carolina Department of Motor Vehicles

Data Protection Policy. Malta Gaming Authority

DATA PROTECTION (JERSEY) LAW 2018

INFORMATION PROCESSING POLICIES INSIGHT CRIME DATABASES Preliminary Provisions

Patent Law of the Republic of Kazakhstan

Official Gazette No. 55 issued on 8 May Data Protection Act. of 14 March 2002

8557/16 SHO/ra 1 DGD 2

The NATIONAL CONGRESS decrees: CHAPTER I PRELIMINARY PROVISIONS

THE PERSONAL DATA (PROTECTION) BILL, 2013

Electronic Document and Electronic Signature Act Published SG 34/6 April 2001, effective 7 October 2001, amended SG 112/29 December 2001, effective 5

THE GENERAL ADMINISTRATIVE CODE OF GEORGIA

Regulations on Provision of Information to Shareholders of Public Joint Stock Company Oil company LUKOIL (new version)

General Data Protection Regulation

CHAPTER [INSERT] DATA PROTECTION BILL Acts [insert] ARRANGEMENT OF SECTIONS PART I PART II

Personal Data Protection Law

EUROPEAN COMMISSION DIRECTORATE-GENERAL JUSTICE. Directorate C: Fundamental rights and Union citizenship Unit C.3: Data protection

LAW OF GEORGIA GENERAL ADMINISTRATIVE CODE OF GEORGIA

SBERBANK OF RUSSIA. APPROVED BY: General Shareholders Meeting Minutes dated June 3, 2015 No. 28. REGULATIONS On the General Shareholders Meeting

VIETNAM LAWS ONLINE DATABASE License Agreement Multi-user (Special)

General Rules on the Processing of Personal Data SCHEDULE 1 DATA TRANSFER AGREEMENT (Data Controller to Data Controller transfers)...

MARITEC-X MARINE AND MARITIME RESEARCH, INNOVATION, TECHNOLOGY CENTRE OF EXCELLENCE. Consortium Agreement

Law on Associations and Foundations

Number 5 of Vehicle Registration Data (Automated Searching and Exchange) Act 2018

SCHEDULE 1 DATA TRANSFER AGREEMENT (Data Controller to Data Controller transfers)... 16

Decade of the Persons with Disabilities in Peru Year of Peru s economic and social consolidation

ELECTORAL CODE OF THE REPUBLIC OF ARMENIA PART ONE SECTION 1 GENERAL PROVISIONS CHAPTER 1 MAIN PROVISIONS

GUIDELINE FOR PROTECTION OF PERSONAL INFORMATION

AKTIVA sistem doo, Novi Sad

THE GENERAL ADMINISTRATIVE CODE OF GEORGIA

ASSEMBLEIA DA REPÚBLICA [PORTUGUESE PARLIAMENT]

Amended Act on the Protection of Personal Information (Tentative Translation)

BASECONE DATA PROCESSING AGREEMENT (BASECONE AS PROCESSOR)

NON-DISCLOSURE AGREEMENT

FEDERAL LAW 59-FZ of May 2, 2006 ON THE PROCEDURE FOR CONSIDERATION OF APPEALS BY CITIZENS OF THE RUSSIAN FEDERATION

ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION, ETC.

O R D E R OF THE MINISTER OF THE INTERIOR OF THE REPUBLIC OF LITHUANIA

Adopted by the State Duma of the Russian Federation on June 14, 2002 Endorsed by the Federation Council on July 10, 2002

FEDERAL LAW NO. 59-FZ OF MAY 2, 2006 ON THE PROCEDURE FOR HANDLING APPLICATIONS OF CITIZENS OF THE RUSSIAN FEDERATION

Coordinated text from 10 August 2011 Version applicable from 1 September 2011

PRIVACY POLICY. 1. OVERVIEW MEGT is committed to protecting privacy and will manage personal information in an open and transparent way.

Answers to Questionnaire: Romania

Last revised: 6 April 2018 By using the Agile Manager Website, you are agreeing to these Terms of Use.

CHAPTER I. Definitions

NOTICES ACCOMPANYING THE ELECTRONIC PROSPECTUS/INFORMATION MEMORANDUM/KNOWLEDGE PACK AND E-IPO APPLICATION FORMS FROM THE WEBSITE

Federal Act on Data Protection (FADP) Section 1: Aim, Scope and Definitions

Brussels, 16 May 2006 (Case ) 1. Procedure

DATA PROCESSING AGREEMENT. between [Customer] (the "Controller") and LINK Mobility (the "Processor")

B I L L. No. 30 An Act to amend The Freedom of Information and Protection of Privacy Act

BERMUDA COMPANIES AND LIMITED LIABILITY COMPANY (BENEFICIAL OWNERSHIP) AMENDMENT ACT : 41

Terms of Use Coach Me

RUSSIA Patent Law #3517-I of September 23, 1992, as amended by the federal law 22-FZ of February 7, 2003 ENTRY INTO FORCE: March 11, 2003

Policy To Protect Personal Information

BERMUDA COMPANIES AND LIMITED LIABILITY COMPANY (BENEFICIAL OWNERSHIP) AMENDMENT ACT : 41

Bulletin of Acts, Orders and Decrees of the Kingdom of the Netherlands

FUNDAMENTALS OF THE LEGISLATION OF THE RUSSIAN FEDERATION ON THE NOTARIATE NO OF FEBRUARY

REGISTRANT AGREEMENT Version 1.5

(3) (NAME OF APPLICANT) (4) (REGISTERED OR PRINCIPAL OFFICE LEGAL ADDRESS OF APPLICANT) (5)

5418/16 AV/NT/vm DGD 2

The High Contracting Parties to the present Treaty, Member States of the European Union,

The Civil Procedural Code of the Russian Federation (as amended on 4 December 2007) (the wording valid as of 1 February 2008)

EU GDPR - DATA PROCESSING ADDENDUM INSTRUCTIONS FOR CDNETWORKS CUSTOMERS

DATA PROTECTION (JERSEY) LAW 2005

GlobalSign Certificate Centre (GCC) Terms of Service Non US Version

Identity Documents Act

LIBRARY LICENSE AGREEMENT - DATABASE

the Commisslone Mazionale per le Sodeta e la Borsa in ItaJy and the Public Company Accounting Oversight Board In the United States

THE RUSSIAN FEDERATION FEDERAL LAW ON TECHNICAL REGULATION

SKILLSTAR 2018 NONPROFIT KFT. DATA PROTECTION POLICY

ACT, Inc. ( ACT ) and Customer agree as follows: Effective Date: August 8, 2017

Administrative and Penal Responsibility for Violations of Medical Device Marketing Regulations

Midwest Real Estate Data, LLC. MRED Participant Agreement 1 DEFINITIONS AND USAGE. MRED S OBLIGATIONS. PARTICIPANT ACKNOWLEDGMENTS.

Please contact the UOB Call Centre at (toll free if calls are made from within Singapore) if you need any assistance.

INTERNATIONAL CONVENTION ON MUTUAL ADMINISTRATIVE ASSISTANCE IN CUSTOMS MATTERS. Brussels 27 June, 2003

End User License Agreement

Canada: Canadian Human Rights Act

ACCESS AND PRIVACY POLICY

European College of Business and Management Data Protection Policy

AmCham EU Proposed Amendments on the General Data Protection Regulation

ELECTRONIC DATA PROTECTION ACT An Act to provide for protection to electronic data with regard to the processing of electronic data in Pakistan

January 2017 Eteach, Norwich House, Camberley, Surrey, GU15 3SY T:

Information leaflet about processing of personal data for Newsletter Recipients (hereinafter Data Subject)

Privacy policy. 1.1 We are committed to safeguarding the privacy of our website visitors.

General Contractual Terms and Conditions for the Sale of Standard Software of the company Engelmann Sensor GmbH

GWINNETT COUNTY GIS DATA LICENSE AGREEMENT

PROJET DE LOI ENTITLED. The Data Protection (Bailiwick of Guernsey) Law, 2017 ARRANGEMENT OF SECTIONS PART I PRELIMINARY

Transcription:

DATA PROTECTION POLICY Page 1 of 14

TABLE OF CONTENTS 1. GENERAL PROVISIONS 2. PRINCIPLES AND CONDITIONS OF PERSONAL DATA PROCESSING 2.1 Principles of Personal Data Processing 2.2 Conditions of Personal Data Processing 2.3 Personal Data Confidentiality 2.4 Publicly Available Personal Data Sources 2.5 Special Categories of Personal Data 2.6 Biometric Personal Data 2.7 Another Person to be Instructed to Process Personal Data 2.8 Cross-Border Personal Data Transfer 3. RIGHTS OF THE PERSONAL DATA SUBJECT 3.1 Consent of the Personal Data Subject to the Processing of Their Personal Data 3.2 Rights of Personal Data Subject 4. ENSURING PERSONAL DATA SECURITY 5. FINAL PROVISIONS Page 2 of 14

LIST OF TERMS AND DEFINITIONS Automated personal data processing Personal data processing by means of computer hardware and software. Personal data blocking Temporary termination of personal data processing (unless processing is necessary to clarify personal data). Personal Information System Personal data identification Personal data processing The totality of personal data contained in databases, and ensuring their processing with the use of information technologies and technical means. Actions whereby it is impossible to determine personal data attribution to a specific personal data subject without the use of additional information. Any action (operation) or set of actions (operations) performed using automation tools or without using such means with personal data including collection, recording, systematization, accumulation, storage, updating (updating, modification), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, and destruction of personal data. Operator A public authority, a municipal body, a legal entity or an individual, independently or jointly with other persons organizing and/or carrying out personal data processing, as well as defining the purposes of processing personal data, composition of personal data subject to processing, and actions (operations) performed with personal data. Page 3 of 14

Personal Information Any information relating to a directly or indirectly defined or determined individual (personal data subject). Provision of personal data Cross-border transfer of personal data Personal data dissemination Personal data destruction Actions aimed at disclosing personal data to a specific person or a certain circle of persons. Transfer of personal data to the territory of a foreign state to the authority of a foreign state, to a foreign physical or foreign legal entity. Actions aimed at the disclosure of personal data to an indeterminate circle of persons (transfer of personal data) or for acquaintance with personal data of an unlimited number of persons including the disclosure of personal data in the mass media, placement in information and telecommunications networks or provision of access to personal data, or otherwise. Actions whereby it is impossible to restore the contents of personal data in the information system of personal data and/or whereby material data carriers of personal data are destroyed. Page 4 of 14

1. GENERAL PROVISIONS The Personal Data Processing Policy in OOO VF Services (hereinafter referred to as the Policy ) has been developed in compliance with the Federal Law On Personal Data No. 152-FZ dated July 27, 2006 (hereinafter FZ 152). This Policy determines the procedure for processing personal data and controls to ensure the security of personal data in OOO VF Services (hereinafter referred to as the Company ) in order to protect the rights of subjects when processing their personal data. Page 5 of 14

2. PRINCIPLES AND CONDITIONS OF PERSONAL DATA PROCESSING 2.1 Principles of Personal Data Processing Personal data processing in the Company shall be performed based on the following principles: Legality and fair basis; Restrictions on personal data processing by the achievement of specific, pre-determined and legitimate purposes; Preventing personal data processing incompatible with the purposes of collecting personal data; Preventing merging of databases containing personal data processing which is performed for purposes incompatible with each other; Processing only those personal data that meet the objectives of their processing; Compliance of the content and volume of processed personal data with the stated processing objectives; Preventing personal data processing that is redundant in relation to the stated purposes of their processing; Ensuring the accuracy, adequacy and relevance of personal data in relation to the purposes of processing personal data; Destruction or depersonalization of personal data upon the achievement of the objectives of their processing, in the event of a loss of the need to achieve these goals or if the Company cannot eliminate the violations committed while processing personal data, unless otherwise provided by federal law. Page 6 of 14

2.2 Conditions of Personal Data Processing The Company processes personal data if at least one of the following conditions persists: Personal data processing is performed with the consent of the personal data subject to processing their personal data; Personal data processing is necessary to achieve the goals set forth in an international treaty of the Russian Federation or the law for the implementation and performance of functions, powers and duties imposed by the applicable laws of the Russian Federation on the operator; Personal data processing is necessary for the administration of justice, the execution of a judicial act, an act of another body or official subject to enforcement in compliance with the law of the Russian Federation on enforcement proceedings; Personal data processing is necessary for the performance of a contract to which the personal data subject or a beneficiary or guarantor is a party, as well as for the entering into a contract on the initiative of a personal data subject or a contract whereby the personal data subject will be a beneficiary or a guarantor; Personal data processing is necessary for the exercise of the rights and legitimate interests of the operator or third parties or for the achievement of socially significant purposes, provided that the rights and freedoms of the personal data subject are not thereby violated; Processing personal data, access of an unlimited circle of persons to which is provided by the personal data subject or at their request (hereinafter publicly available personal data); Processing personal data subject to publication or mandatory disclosure in compliance with federal law. Page 7 of 14

2.3 Personal Data Confidentiality The Company and other persons who have access to personal data shall not disclose to third parties or distribute personal data without the consent of the personal data subject, unless otherwise prescribed by a Federal law. 2.4 Publicly Available Personal Data Sources For the purpose of information support, the Company can create publicly available sources of personal data including directories and address books. In the public sources of personal data with the written consent of the personal data subject their data may include his/her last name, first name, patronymic, date, and place of birth, position, contact phone numbers, e-mail address and other personal data reported by the personal data subject. Information about the personal data subject shall be deleted at any time from the publicly available sources of personal data at the request of the personal data subject or by a court or other authorized government agency. 2.5 Special Categories of Personal Data Processing by the Company of special categories of personal data relating to race, nationality, political views, religious or philosophical beliefs, health status, intimate life shall be allowed in cases where: Personal data subject has given their consent in writing to the processing of their/her personal data; Personal data is made publicly available by the personal data subject; Personal data processing is performed in compliance with the applicable laws on state social assistance, labor legislation, the applicable laws of the Russian Federation on pensions for state pension provision, and on labor pensions; Personal data processing is necessary to protect the life, health or other vital interests of the personal data subject or the life, health or other vital interests of others and obtaining the consent of the personal data subject is impossible; Page 8 of 14

Personal data processing is performed for medical and preventive purposes, with a view to establishing a medical diagnosis, providing medical and medical and social services, provided that personal data processing is performed by a person professionally engaged in medical activities and required to maintain medical secrecy in compliance with the applicable laws of the Russian Federation; Personal data processing is necessary to establish or implement the rights of the personal data subject or third parties, as well as in connection with the implementation of justice. Personal data processing shall is performed in compliance with the applicable laws on compulsory types of insurance, with applicable insurance laws. Processing of special categories of personal data shall be immediately terminated if the reasons for their processing have been eliminated, unless otherwise provided by Federal law. Personal data processing on the criminal record may be performed by the Company only in cases and in the manner determined in compliance with the Federal laws. 2.6 Biometric Personal Data Information that are descriptive of the physiological and biological characteristics of a person whereby it is possible to establish their identity (biometric personal data) and used by the Company to establish the identity of the personal data subject may be processed by the Company only if there is consent in writing to the personal data subject. 2.7 Another Person to be Instructed to Process Personal Data The Company shall be entitled to entrust personal data processing to another person with the consent of the personal data subject, unless otherwise provided by the Federal law, based on a contract entered into with that person. A person engaged in the personal data processing on the Company s behalf shall be required to comply Page 9 of 14

with the principles and rules for personal data processing set forth by the Federal Law No. 152. 2.8 Cross-Border Personal Data Transfer The company shall ensure that the foreign state to which the transfer of personal data is intended is able and willing to provide adequate protection of the rights of subjects of personal data, prior to the commencement of such transfer. Cross-border transfer of personal data to the territory of foreign states that do not provide adequate protection of the rights of subjects of personal data may be performed in the following cases: Consent in writing of the personal data subject to the cross-border transfer of their personal data; Entering into a contract to which the personal data subject is a party; Protection of life, health, other vital interests of the personal data subject or other persons when it is impossible to obtain consent in writing to the personal data subject. Page 10 of 14

3. RIGHTS OF THE PERSONAL DATA SUBJECT 3.1 Consent of the Personal Data Subject to the Processing of Their Personal Data Personal data subject shall decide on the provision of their personal data and agrees to process thereof freely, by their will and in their interest. Consent to the personal data processing may be given by the personal data subject or their representative in any form that allows confirming the fact of its receipt, unless otherwise provided by the Federal law. The obligation to provide evidence of the consent of the personal data subject to the processing of their personal data or evidence of the grounds specified in FZ No. 152 shall be vested in the Company. 3.2 Rights of Personal Data Subject Personal data subject shall be empowered to obtain from the Company information concerning the processing of their personal data, unless such right is restricted in compliance with the Federal laws. The personal data subject shall be entitled to demand from the Company the specification of their personal data, blocking, or destruction thereof in the event that personal data is incomplete, outdated, inaccurate, illegally obtained or is not necessary for the stated purpose of processing, and also take adequate steps provided by applicable laws to protect their rights Personal data processing in order to promote goods, works, and services on the market by making direct contacts with a potential consumer by means of communication means, as well as for the purposes of political agitation is allowed only with the prior consent of the personal data subject. The said personal data processing is recognized as being performed without the prior consent of the personal data subject, unless the Company proves that such consent has been obtained prior thereto. Page 11 of 14

The company shall immediately cease, at the request of the personal data subject, the processing of their personal data for the above purposes. It is prohibited to make decisions based solely on the automated personal data processing that generate legal consequences with respect to the personal data subject or otherwise affect their rights and legitimate interests, with the exception of cases prescribed by the Federal laws or with the written consent of the personal data subject. If the personal data subject considers that the Company processes their personal data in violation of the requirements set forth by the Federal Law No. 152 or otherwise violates their rights and freedoms, the personal data subject shall be empowered to appeal against the actions or omission by the Company by filing a complaint with the Authorized body for the protection of the rights of subjects of personal data or judicial procedure. The personal data subject shall be empowered to protect their rights and legitimate interests including compensation for damages and/or compensation for non-pecuniary damage in court. Page 12 of 14

4. ENSURING PERSONAL DATA SECURITY Personal data security processed by the Company shall be ensured by the implementation of legal, organizational, and technical controls necessary to ensure the requirements of federal legislation in the field of personal data protection. To prevent unauthorized access to personal data, the Company applies the following organizational and technical measures: Appointment of officials responsible for organizing processing and ensuring the security of personal data; Restriction of the composition of persons having access to personal data; Getting to know of personal data subjects with the requirements of the applicable Federal laws and the Company s by-laws for the processing and protection of personal data; Organization of accounting, storage and circulation of information carriers; Definition of threats to the security of personal data during processing, formation of a threat model on their basis; Checking the readiness and efficiency of using information security tools; Differentiation of users' access to information resources and software and hardware information processing; Registration and recording of the users actions of personal data information systems; Use of antivirus and tools for restoring the protection of personal data; Application of firewalls and security analysis tools in necessary cases; Ensuring access control on the Company s territory, protection of premises with technical means of processing personal data. Page 13 of 14

5. FINAL PROVISIONS Other rights and obligations of the Company as an operator of personal data shall be determined by the applicable laws of the Russian Federation in the field of personal data. Officials of the Company who are guilty of violating the rules governing the processing and protection of personal data shall be subject to material, disciplinary, administrative, civil or criminal liability in compliance with the procedure established by the applicable Federal laws. Page 14 of 14