SKILLSTAR 2018 NONPROFIT KFT. DATA PROTECTION POLICY

Similar documents
Information leaflet about processing of personal data for Newsletter Recipients (hereinafter Data Subject)

PROCEDURE RIGHTS OF THE DATA SUBJECT PURSUANT TO THE ARTICLES 15 TO 23 OF THE REGULATION 679/2016

closer look at Rights & remedies

Declaration on the protection of personal data in the company TAJMAC ZPS, a.s.

Charter on personal data

Art. I Right to Access to Personal Data

(1) General information

16 March Purpose & Introduction

DATA PROTECTION (JERSEY) LAW 2018

Privacy Notice 1. CONTROLLER S NAME AND DATA

DIRECTIVE 95/46/EC OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL. of 24 October 1995

1. Processing of personal data legal basis, purpose and scope Legal basis fulfillment of statutory legal requirements

Data Protection Policy. Malta Gaming Authority

Act CXII of on the Right of Informational Self-Determination and on Freedom of Information 1 CHAPTER I GENERAL PROVISIONS. 1.

Privacy policy. 1.1 We are committed to safeguarding the privacy of our website visitors.

The Act on Processing of Personal Data

PROJET DE LOI ENTITLED. The Data Protection (Bailiwick of Guernsey) Law, 2017 ARRANGEMENT OF SECTIONS PART I PRELIMINARY

General Data Protection Regulation

European Data Protection Supervisor Your personal information and the EU administration: What are your rights?

BASECONE DATA PROCESSING AGREEMENT (BASECONE AS PROCESSOR)

REGULATION (EU) 2016/679 General Data Protection Regulation

Information about the Processing of Personal Data (Article 13, 14 GDPR)

COMP Article 1. Article 1 Subject matter and objectives

EQUILOR BEFEKTETÉSI ZRT. S PRELIMINARY INFORMATION ON DATA PROTECTION

Aalto Summer continuing education

DATA PROCESSING AGREEMENT. between [Customer] (the "Controller") and LINK Mobility (the "Processor")

THE DATA PROTECTION BILL (No. XIX of 2017) Explanatory Memorandum

DATA PROCESSING AGREEMENT

STATOIL BINDING CORPORATE RULES - PUBLIC DOCUMENT

Personal Data Protection Act

***I DRAFT REPORT. EN United in diversity EN 2012/0010(COD)

PERSONAL DATA PROCESSING AGREEMENT

PRIVACY POLICY STATEMENT ON THE PROCESSING OF PERSONAL AND SENSITIVE DATA OF THE CUSTOMERS WITHIN THE MEANING OF ARTICLE 13 AND FF. OF REGULATION (EU)

REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April on the protection of natural persons

5418/16 AV/NT/vm DGD 2

Data Protection Bill [HL]

THE GDPR AND DFIR THE IMPACT OF THE EU GENERAL DATA PROTECTION REGULATION ON DIGITAL FORENSICS AND INCIDENT RESPONSE

International Privacy Laws: Those New EU Data Protection Regulations Do Apply to You!

A Legal Overview of the Data Protection Act By: Mrs D. Madhub Data Protection Commissioner

General Rules on the Processing of Personal Data SCHEDULE 1 DATA TRANSFER AGREEMENT (Data Controller to Data Controller transfers)...

Data Protection Bill [HL]

SCHEDULE 1 DATA TRANSFER AGREEMENT (Data Controller to Data Controller transfers)... 16

An Bille um Chosaint Sonraí, 2018 Data Protection Bill 2018

An Bille um Chosaint Sonraí, 2018 Data Protection Bill 2018

Data Processing Addendum

Law Enforcement processing (Part 3 of the DPA 2018)

THE PROCESSING OF PERSONAL DATA (PROTECTION OF INDIVIDUALS) LAW 138 (I) 2001 PART I GENERAL PROVISIONS

the Commisslone Mazionale per le Sodeta e la Borsa in ItaJy and the Public Company Accounting Oversight Board In the United States

DATA PROTECTION (JERSEY) LAW 2005

The Ministry of Technology, Communication and Innovation and The Data Protection Office. Workshop On DATA PROTECTION ACT 2017

Data Protection Act 1998

OTrack Data Processing Terms

LAW OF THE REPUBLIC OF ARMENIA ON PROTECTION OF PERSONAL DATA CHAPTER 1 GENERAL PROVISIONS

Telekom Austria Group Standard Data Processing Agreement

ARTICLE 29 DATA PROTECTION WORKING PARTY

9091/17 VH/np 1 DGD 2C

Application for a visa for a long stay in Belgium This application form is free

PROTECTION OF PERSONAL INFORMATION ACT NO. 4 OF 2013

RESTREINT UE/EU RESTRICTED

GDPR. EU General Data Protection Regulation. ebook Version 1.2

Act CVIII of on certain issues of electronic commerce services and information society services 1

Individual Rights (Data Privacy) Policy

Adequacy Referential (updated)

STATUTORY INSTRUMENT 2002 NO THE ELECTRONIC COMMERCE (EC DIRECTIVE) REGULATIONS Statutory Instruments No. 2013

PRIVACY POLICY. 1. OVERVIEW MEGT is committed to protecting privacy and will manage personal information in an open and transparent way.

Port Glasgow St Andrew s Data Protection Policy

The NATIONAL CONGRESS decrees: CHAPTER I PRELIMINARY PROVISIONS

The European Union General Data Protection Regulation (GDPR) Barmak Nassirian, Federal Director Thursday, February 22, 2018

DECISION no. 52 of 31 st May 2012 on the processing of personal data using video surveillance means

Mannofield Parish Church. Registered Scottish Charity No: SC (the Congregation ) Data Protection Policy

8557/16 SHO/ra 1 DGD 2

Data Protection Policy

Consolidated text PROJET DE LOI ENTITLED. The Data Protection (Bailiwick of Guernsey) Law, 2001 [CONSOLIDATED TEXT] NOTE

Coordinated text from 10 August 2011 Version applicable from 1 September 2011

SSLI \6.0 v1.0

PE-CONS 71/1/15 REV 1 EN

ELECTRONIC DATA PROTECTION ACT An Act to provide for protection to electronic data with regard to the processing of electronic data in Pakistan

DATA PROTECTION LAWS OF THE WORLD. Romania

Fragomen Privacy Notice

Principles and Rules for Processing Personal Data

Consolidated text PROJET DE LOI ENTITLED. The Data Protection (Bailiwick of Guernsey) Law, 2001 * [CONSOLIDATED TEXT] NOTE

DATA PROTECTION (AMENDMENT) REGULATIONS Amendments to the Data Protection Regulations Insertion of new sections...

Schools Subject Access Request Procedures

SUBSIDIARY LEGISLATION DATA PROTECTION (PROCESSING OF PERSONAL DATA IN THE POLICE SECTOR) REGULATIONS

Terms of Business

CHAPTER [INSERT] DATA PROTECTION BILL Acts [insert] ARRANGEMENT OF SECTIONS PART I PART II

Date recieved Recieved by (name) Authority (stamp) Personal ID / Udl.nr. Previous surnames / family names (if applicable)

ASSEMBLEIA DA REPÚBLICA [PORTUGUESE PARLIAMENT]

6153/1/18 REV 1 VH/np 1 DGD2

Official Gazette No. 55 issued on 8 May Data Protection Act. of 14 March 2002

PERSONAL DATA PROTECTION POLICY OF GOPET

General Part of the Economic Activities Code Act 1

AGREEMENT FOR ACCESS, WHICH MAY RESULT IN PERSONAL DATA PROCESSING

DATA PROTECTION LAWS OF THE WORLD. Ireland

EDPS Opinion on the proposal for a recast of Brussels IIa Regulation

Case C-553/07. College van burgemeester en wethouders van Rotterdam. M.E.E. Rijkeboer. (Reference for a preliminary ruling from the Raad van State)

DATA PROTECTION LAWS OF THE WORLD. Ukraine

Data Processing Addendum

Terms and Conditions GDPR Ready Data

Access to Personal Information Procedure

Transcription:

SKILLSTAR 2018 NONPROFIT KFT. DATA PROTECTION POLICY 1. OBJECT AND THE SCOPE OF THE POLICY 1.1. Object of the policy The General Data Protection Regulation, which entered into force on 25 th May 2018, official title Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC) (hereinafter referred to as "GDPR") established uniform rules for the protection of natural persons' data directly applicable throughout the European Union (and in certain cases beyond). GDPR establishes obligations primarily for persons who handle data for natural persons for specific purposes. The purpose of this policy is to provide a brief, comprehensible explanation on the details of the processing and data protection practices - which are based on the GDPR and the Act nr. CXII. of 2011 on informational selfdetermination and freedom of information (hereinafter referred to as "Privacy Act") - followed by the SkillStar 2018 Európai Szakmunkásverseny Szervező Nonprofit Korlátolt Felelősségű Társaság (registered seat: 1054 Budapest, Szabadság tér 7, registration authority: Company Registry Court of Budapest, Hungary; registration number: 01-09-271952, hereinafter referred to as "SkillStar"), and, in this context, inform the data subject on their rights under the abovementioned legislation. 1.2. Scope of the policy This policy was prepared and published by SkillStar on the web site www.euroskills2018.com (hereinafter referred to as "Website"), maintained and operated by them. This policy shall be applied for all data processing by SkillStar, which affects a natural person. 1.3. Processing not affected by the policy Regarding the fact that GDPR only regulates the processing of personal data of natural persons, the provisions of this policy does not apply to SkillStar s processing of data which relate to a non-natural person. SkillStar considers the contact details of a nonnatural partner with a business relationship, including any contact information provided by the company or such person (e.g. phone number, email address not suitable for identifying a natural person, etc.) as data mentioned in this article. 2. PROCESSING DEFINITIONS AND PRINCIPLES 2.1. Definitions The main terms used in this policy shall be interpreted as follows (according to GDPR definitions): - data subject means any natural person identified or identifiable on any processed data; a person may be identified if the identification is possible related to the processed data (in particular an identification data, such as name, number, positioning data, online identity or physical, physiological, genetic, intellectual, economic, cultural or social identity of one or more factor) in direct or indirect way; 1

- personal data means any information concerning the data subject; - controller means the person who manages the purposes and tools of the processing of personal data, alone or jointly with others; - processor means other person who is processing personal data on behalf of the controller; - processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means (such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction); - consent of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her; - recipient means a natural or legal person, to which the personal data are disclosed; - personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed. 2.2. Cases of the processing SkillStar processes the data of natural person only in accordance with the GDPR and the domestic legislation on data protection for a specific purpose, in the case of an appropriate legal basis. The time, mode and extent of the processing shall be in accordance with the purpose set out above. 2.3. Methods of the processing SkillStar processes and stores personal data primarily on its own assets or self-controlled devices. SkillStar s employees are authorized to process or to access the data stored on such devices only if the processing or knowledge of the data in question is necessary to perform their duties. SkillStar uses services of processor(s) in cases of the following services: (i) (ii) keeping records of labour relationships, payroll calculation; provision of legal services; (iii) provision of hotel accommodation; (iv) providing a travel organization service; (v) provision of security guard and security services related to property leasing; (vi) providing postal and mail delivery service; (vii) provision of cloud based data storage services. 2.4. Transfer data to countries outside the European Union SkillStar does not transfer data relating to natural persons to countries outside the European Union. 2

2.5. Processing of particularly sensitive personal data SkillStar does not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data uniquely identifying a natural person, data concerning health or data concerning sex or sexual orientation. If any data subject still provides such data, SkillStar promptly deletes it. The only exceptions to the foregoing is when SkillStar according to reasons related to health status, social security, social or similar benefits or services or any obligation related to any of them concerning a natural person having a legal relationship with SkillStar, is obliged to process such data, but in this cases SkillStar shall ensure that such data are properly protected and stored and subsequently removed for the time indicated in the relevant legislation. 2.6. Processing personal data relating to children SkillStar processes personal data relating to a person who is below the age of 16 only in the cases specified in this policy. 3. CASES OF PROCESSING OF DATA 3.1. Processing of data related to labour contract SkillStar processes the following data in connection with labour contracts signed with its employees: - scope of the processed data: name, birth name, date and place of birth, mother s birth name, residence, tax number, social insurance number, bank account number, phone number, marital status, child s name, child s date of birth, birth name of the child s mother, child s residence, child s tax number, type of the document of qualification, the issuing institution of the document of qualification, date of the document of professional skills, retired (yes/no), starting date of retirement, pension fund number; - purpose of the processing: the identification of the person and the bank account number is necessary for performance of the labour contract, and for providing information based on Act nr. CL of 2017 on the order of taxation and the Act nr. LXXX. of 1997 on the eligibility for social security benefits and private pensions and the funding of these services, related to the labour contract, and also for the payment of the wages; - basis for the processing: processing is necessary for the performance of a contract to which the data subject is party and for compliance with a legal obligation to which the controller is subject [GDPR, point b) and c) of paragraph (1) of Article 6]; - duration of the processing: 5 th December 2028, after this date 5 (five) years from the date of termination of the contract; processors carrying out accounting or legal activity for SkillStar. 3.2. Processing of data related to data subject applying for job advertisement SkillStar processes the following data of data subjects applying for the job advertisements of the company: - scope of the processed data: name, birth name, date and place of birth, mother s birth name, phone number, e-mail address, residence, and all the data provided by the applier in the CV (qualification, professional experience, languages, interests, etc.); 3

- purpose of the processing: identification of the appliers and examination of their suitability (qualification, professional competence), making possible to reach unsuccessful applicants if a similar position becomes available; - basis for the processing: consent of the data subject [GDPR, point a) of paragraph (1) of Article 6]; - duration of processing: 1 (one) year from the submission of the CV; - persons entitled for processing and recipients: managers and employees of SkillStar. 3.3. Processing of data related to other contracts concluded with natural persons SkillStar processes the following data in connection with other contracts (personal service contracts, work contracts, etc.) signed with natural persons: - scope of the processed data: name, birth name, date and place of birth, mother s name, residence/seat, tax number, social insurance number, bank account number, full time employment relationship s nature, employer s name, retired (yes/no), beginning date of retirement, pension fund number; - purpose of the processing: the identification of the person and the bank account number is necessary for performance of the contract, and for providing information based on Act nr. CL of 2017 on the order of taxation and the Act nr. LXXX. of 1997 on the eligibility for social security benefits and private pensions and the funding of these services, related to the labour contract, and also for the payment of the wages; - basis for the processing: processing is necessary for the performance of a contract to which the data subject is party and for compliance with a legal obligation to which the controller is subject [GDPR, point b) and c) of paragraph (1) of Article 6]; - duration of the processing: 5 th December 2028, after this date 5 (five) years from the date of termination of the contract; processors carrying out accounting or legal activity for SkillStar. 3.4. Processing of data of natural persons mentioned in contracts concluded with legal persons SkillStar processes the following data in case of natural persons mentioned in contracts concluded with legal persons (e.g. administrators, contact persons): - scope of the processed data: name, phone number, e-mail address; - purpose of the processing: identification of the natural person acting on behalf of a legal persons is necessary for the performance of the contract; - basis for the processing: processing is necessary for the performance of a contract to which the data subject is party [GDPR, point b) of paragraph (1) of Article 6]; - duration of the processing: 5 th December 2028, after this date 5 (five) years from the date of termination of the contract; processors carrying out accounting or legal activity for SkillStar. 4

3.5. Processing of data of active participants (competitors, competition experts, volunteers, etc.) of international competition of professions EuroSkills 2018 Budapest and any event related thereto SkillStar processes the following data related to active participants concerning organization of international competition of professions EuroSkills 2018 Budapest: - scope of the processed data: name, date of birth, phone number, e-mail address, data related to food intolerance, data related to allergy, image; - purpose of the processing: registration, identification of the participants, and carrying out of travel and accommodation services, - basis for the processing: consent of the data subject [GDPR, point a) of paragraph (1) of Article 6]; - method of the processing: digital documentation; - duration of the processing: 30 th September 2019; processors providing travel, accommodation, guard or security services, international organization having the rights of the competition. 3.6. Processing of data of participants of international competition of professions EuroSkills 2018 Budapest, participating in frames of school community service SkillStar processes the following data related to participants concerning organization of international competition of professions EuroSkills 2018 Budapest, participating in frames of school community service: - scope of the processed data: name, date of birth, residence, mother s birth name, data related to food intolerance, data related to allergy, parent s/caretaker s name, parent s/caretaker s residence, parent s/caretaker s phone number; - purpose of the processing: registration and identification of persons participating in frames of school community service, issuing certificate to them; - basis for the processing: consent of the data subject [GDPR, point a) of paragraph (1) of Article 6]; - duration of the processing: 30 th September 2019, after this date 1 (one) year from the performance of school community service; processors providing guard and security services. 3.7. Processing of data of active participants (competitors, competition experts, volunteers, etc.) of international competition of professions EuroSkills 2018 Budapest and any event related thereto SkillStar processes the following data related to active participants concerning organization of international competition of professions EuroSkills 2018 Budapest: - scope of the processed data: name, date of birth, phone number, e-mail address; - purpose of the processing: registration and identification of the participants; - basis for the processing: consent of the data subject [GDPR, point a) of paragraph (1) of Article 6]; 5

- method of processing: digital documentation; - duration of processing: 30 th November 2018; processors providing guard and security services. 4. THE RIGHTS OF THE DATA SUBJECT 4.1. Right of information The data subject shall have the right to be informed in case SkillStar processes personal data relating to him or her. The information shall contain the following: - the identity and the contact of the controller; - the purposes and the legal basics of the processing; - the envisaged duration of the processing; - information on other rights of the data subject contained in this chapter; - information on opportunity of withdrawal of consent, when the legal basis of the processing is the consent of the data subject; - the name of the supervisory authority which is competent pursuant to the processing operation. The information shall contain the source of the data, where personal data obtained from another source. 4.2. Right of access The data subject shall have the right to obtain from SkillStar confirmation as to whether or not personal data concerning him or her are being processed, and, where that in the case, access to the personal data and the following information: - the purposes of the processing; - the categories of personal data concerned; - people to whom the personal data have been disclosed or will be disclosed; - envisaged duration of the processing; - the source of the data, where the personal data are not collected from the data subject. The information shall contain further details concerning the other rights mentioned in this chapter and the name of the supervisory authority which is competent pursuant to the processing operation. 4.3. Right to rectification The data subject shall have the right to obtain from SkillStar the rectification of inaccurate personal data concerning him or her. 4.4. Right of erasure The data subject shall have the right to ask SkillStar to erase personal data relating to him or her in the following cases: 6

- personal data are no longer necessary in relation to the purposes which they were processed; - the data subject withdraws his or her consent and the processing has no other legal grounds; - the data subject objects to the processing and there are no overriding legitimate grounds; - the personal data have been unlawfully processed; - the personal data have to be erased for compliance with a legal obligation in law to which the controller is subject. 4.5. Right to restriction The data subject shall have the right to obtain from SkillStar restriction of the processing of the personal data relating to him or her where the following applies: - the accuracy of the personal data is contested by the data subject (for a period enabling to verify the accuracy of the personal data); - the processing is unlawful and the data subject opposes the erasure of the personal data; - the controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims; - the data subject has objected to processing (pending the verification whether the legitimate grounds of the controller override those of the data subject). 4.6. Right to data portability The data subject shall have the right to receive the personal data concerning him or her in a structured, commonly-used and machine-readable form and have the right to transmit those data to another controller without hindrance from SkillStar. 4.7. Right to object The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her, which is necessary for the purposes of legitimate interests pursued by the SkillStar or by a third party, SkillStar shall no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims. 4.8. Right to compensation The data subject who has suffered damage as a result of an infringement of law or this policy shall have the right to receive compensation from SkillStar. 4.9. Law enforcement The data subject shall have the right to give a notice of the claims regarding to points 4.1-4.7. of this chapter (to SkillStar or the data protection officer mentioned in this policy) in person, in writing or by e-mail. The data subject shall proof his or her identity first to be entitled to exercise the legal claim. After the proof of the identity the personal contact is no longer necessary, the communication can continue via other means and contacts (e.g. postal address, phone number, e-mail) given by the identified data subject. The 7

information shall be in a concise, transparent, intelligible and easily accessible form. The compensation can be enforced in the form as mentioned above or with a law-suite in a judicial procedure. 5. PROTECTION OF THE PROCESSED DATA 5.1. Measures of protection SkillStar makes efforts to use the highest safety methods in relation to data which processed and stored by itself or SkillStar s controllers. At the same time details of these methods couldn t be mentioned in this policy regarding there nature and the purposes of them. If any problem occurs relating to any of the safety methods, SkillStar shall immediately start making steps in order to solve the problem and to make the safety method better or to change the method for a more suitable one to reach a higher safety level without undue delay. 5.2. Personal data breach In the case of a personal data breach relating to the processed personal data, SkillStar shall, without undue delay, but not later than 72 hours after having become aware of it, notify the competent supervisory authority about the personal data breach. The notification shall describe the nature of the personal data breach, the categories of data subjects concerned, the categories of personal data records concerned, communicate the name and contact details of the data protection officer, describe the likely consequences of the personal data breach and measures taken or proposed to be taken to address the personal data breach. When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, and the risk cannot be removed or the consequences cannot be avoided, SkillStar shall communicate to the data subject without undue delay. The communication shall describe in clear and plain language the nature of the personal data breach and contain measures taken or proposed to be taken to address the personal data breach. 6. MISCELLANEOUS 6.1. Place(s) of activity The main place of activity of SkillStar is Hungary (Budapest). 6.2. Data protection officer Data protection officer can be contacted with questions, comments, complaints and any other claims concerning this policy or the processing of data by SkillStar via each of the following contacts: name: dr. Krisztián Tóta status: in-house lawyer, Hungarian Chamber of Commerce and Industry postal address: Hungary 1054, Budapest Szabadság tér 7. phone number: +36 1 474-5194 e-mail: tota.krisztian@mkik.hu 6.3. Supervisory authority Where the processing of data by SkillStar infriges the rights or legitimate interests of a natural person, the data subject shall have the right to file a complaint to Hungarian National Authority for Data Protection and Freedom of Information (registered seat: 1125 8

Budapest, Szilágyi Erzsébet fasor 22/C.; postal address: 1530 Budapest, Pf. 5.; phone number: +36 1 391-1400; fax: +36 1 391-1410; e-mail: ugyfelszolgalat@naih.hu). 6.4. Entry into force, amendment This policy shall apply from the date of its publication on the Website below. SkillStar reserves the right to amend this policy unilaterally and without explanation, in which case the amendment shall apply from the date of the publication of the amended policy on the Website. Budapest, 25 th May 2018 9