Regulation on the Processing and Protection of Personal Data in Personal Data Databases Owned by the Seller
Contents
- General terms and scope
- List of personal data databases
- Purpose of personal data processing
- Procedure for personal data processing: obtaining consent, informing about rights, and actions performed with the personal data of the data subject
- Location of the personal data database
- Conditions for disclosure of personal data to third parties
- Personal data protection: protection methods, responsible person, employees who directly process and/or have access to personal data in connection with their official duties, and personal data retention period
- Rights of the personal data subject
- Procedure for handling requests from the personal data subject
- State registration of the personal data database
1. General Terms and Scope
1.1. Definitions:
personal data database — a named set of organized personal data in electronic form and/or in the form of personal data files (card indexes);
responsible person — a designated person who organizes work related to the protection of personal data during processing, in accordance with the law;
owner of a personal data database — an individual or legal entity that, by law or with the consent of the personal data subject, is granted the right to process such data, and that approves the purpose of personal data processing in such database, determines the composition of the data and the procedures for processing, unless otherwise established by law;
State Register of Personal Data Databases — a unified state information system for collecting, accumulating, and processing information about registered personal data databases;
publicly available sources of personal data — directories, address books, registers, lists, catalogues, and other systematized compilations of open information containing personal data that are placed and published with the knowledge of the personal data subject. Social networks and internet resources in which the personal data subject leaves their personal data are not considered publicly available sources (except where the personal data subject explicitly states that the personal data are published for free distribution and use);
consent of the personal data subject — any documented, voluntary expression of will by an individual to grant permission for the processing of their personal data in accordance with the stated purpose of such processing;
depersonalization of personal data — removal of information that makes it possible to identify a person;
processing of personal data — any action or set of actions performed wholly or partially in an information (automated) system and/or in personal data files that relates to collection, registration, accumulation, storage, adaptation, modification, updating, use, and dissemination (distribution, sale, transfer), depersonalization, or destruction of information about an individual;
personal data — information or a set of information about an individual who is identified or can be specifically identified;
processor of a personal data database — an individual or legal entity that is granted, by the owner of the personal data database or by law, the right to process such data. A person entrusted by the owner and/or processor to perform technical work with a personal data database without access to the content of personal data is not considered a processor of the personal data database;
personal data subject — an individual whose personal data are processed in accordance with the law;
third party — any person other than the personal data subject, the owner or processor of the personal data database, and the authorized state body for personal data protection, to whom the owner or processor transfers personal data in accordance with the law;
special categories of data — personal data revealing racial or ethnic origin, political, religious, or philosophical beliefs, membership in political parties or trade unions, as well as data concerning health or sex life.
1.2. This Regulation is mandatory for the responsible person and the Seller’s employees who directly process and/or have access to personal data in connection with the performance of their official duties.
2. List of Personal Data Databases
2.1. The Seller owns the following personal data databases:
- contractor personal data database.
3. Purpose of Personal Data Processing
3.1. The purpose of personal data processing within the system is to ensure the implementation of civil-law relations, provision and receipt of services, and execution of payments for purchased goods and services in accordance with the Tax Code of Ukraine and the Law of Ukraine “On Accounting and Financial Reporting in Ukraine.”
4. Procedure for Personal Data Processing: Obtaining Consent, Informing About Rights, and Actions Performed with the Personal Data of the Data Subject
4.1. Consent of the personal data subject must be a voluntary expression of will by an individual to grant permission for the processing of their personal data in accordance with the stated purpose of such processing.
4.2. Consent of the personal data subject may be provided in the following forms:
- a paper document containing details that make it possible to identify the document and the individual;
- an electronic document containing mandatory details that make it possible to identify the document and the individual. It is advisable to certify the voluntary expression of will by the personal data subject with an electronic signature;
- a mark (tick/confirmation) on an electronic document page or in an electronic file processed in an information system based on documented software and technical solutions.
4.3. Consent of the personal data subject is provided when establishing civil-law relations in accordance with applicable law.
4.4. Notification of the personal data subject about inclusion of their personal data in a personal data database, the rights defined by the Law of Ukraine “On Personal Data Protection,” the purpose of data collection, and persons to whom their personal data are transferred is carried out when establishing civil-law relations in accordance with applicable law.
4.5. Processing of personal data revealing racial or ethnic origin, political, religious, or philosophical beliefs, membership in political parties or trade unions, as well as data concerning health or sex life (special categories of data) is prohibited.
5. Location of the Personal Data Database
5.1. The personal data databases specified in Section 2 of this Regulation are located at the Seller’s address.
6. Conditions for Disclosure of Personal Data to Third Parties
6.1. The procedure for providing third parties with access to personal data is determined by the terms of the personal data subject’s consent granted to the personal data owner for processing, or in accordance with the requirements of the law.
6.2. Access to personal data is not granted to a third party if such party refuses to assume obligations to comply with the Law of Ukraine “On Personal Data Protection” or is unable to ensure such compliance.
6.3. A subject of relations involving personal data submits a request for access (hereinafter — the “request”) to the personal data owner.
6.4. The request shall specify:
- surname, first name and patronymic, place of residence (stay), and details of the identity document of the individual submitting the request (for an individual applicant);
- name and location of the legal entity submitting the request, position, surname, first name and patronymic of the person certifying the request; confirmation that the request content corresponds to the authority of the legal entity (for a legal entity applicant);
- surname, first name and patronymic, as well as other information enabling identification of the individual to whom the request relates;
- information about the personal data database to which the request relates, or information about the owner/processor of that database;
- the list of personal data requested;
- the purpose and/or legal grounds for the request.
6.5. The period for reviewing the request for the possibility of satisfaction shall not exceed ten (10) working days from the date of receipt. Within this period, the owner of the personal data database informs the requesting party whether the request will be satisfied or whether the relevant personal data may not be provided, indicating the grounds established by the applicable legal act. The request shall be satisfied within thirty (30) calendar days from the date of receipt, unless otherwise provided by law.
6.6. Deferral of access to personal data for third parties is permitted if the required data cannot be provided within thirty (30) calendar days from the date of receipt of the request. In this case, the total period for resolving the issues raised in the request shall not exceed forty-five (45) calendar days.
6.7. Notice of deferral shall be provided to the requesting third party in writing, with an explanation of the procedure for appealing such decision.
6.8. The deferral notice shall specify:
- surname, first name and patronymic of the official;
- date the notice is sent;
- reason for deferral;
- time period within which the request will be satisfied.
6.9. Refusal to grant access to personal data is permitted if such access is prohibited by law.
6.10. The refusal notice shall specify:
- surname, first name and patronymic of the official refusing access;
- date the notice is sent;
- reason for refusal.
6.11. A decision to defer or refuse access to personal data may be appealed in court.
7. Personal Data Protection: Protection Methods, Responsible Person, Employees Who Directly Process and/or Have Access to Personal Data, and Personal Data Retention Period
7.1. The owner of the personal data database is equipped with system and software/technical tools and communications means that prevent loss, theft, unauthorized destruction, distortion, falsification, or copying of information and meet international and national standards.
7.2. The responsible person organizes work related to the protection of personal data during processing in accordance with the law. The responsible person is appointed by an order of the owner of the personal data database.
The duties of the responsible person regarding organization of personal data protection during processing are set out in the job description.
7.3. The responsible person shall:
- be familiar with Ukrainian legislation in the field of personal data protection;
- develop procedures for employee access to personal data according to their professional, official, or employment duties;
- ensure that employees of the owner of the personal data database comply with Ukrainian legislation on personal data protection and internal documents regulating processing and protection of personal data in personal data databases;
- develop an internal control procedure for compliance with Ukrainian personal data protection legislation and internal documents regulating processing and protection of personal data, including provisions on the frequency of such control;
- notify the owner of the personal data database about violations by employees of Ukrainian personal data protection legislation and internal documents regulating processing and protection of personal data no later than one (1) working day from the moment such violation is discovered;
- ensure retention of documents confirming the personal data subject’s consent to processing and notification of the personal data subject about their rights.
7.4. For the purpose of performing their duties, the responsible person has the right to:
- receive necessary documents, including orders and other administrative documents issued by the owner of the personal data database related to personal data processing;
- make copies of received documents, including file copies and any records stored in local networks and standalone computer systems;
- participate in discussions related to performance of duties regarding personal data protection during processing;
- submit proposals for improvement of activities and work methods, comments, and options for eliminating identified deficiencies in the process of personal data processing;
- obtain explanations on personal data processing matters;
- sign and endorse documents within their competence.
7.5. Employees who directly process and/or have access to personal data in connection with their official (employment) duties must comply with Ukrainian personal data protection legislation and internal documents regulating processing and protection of personal data in personal data databases.
7.6. Employees with access to personal data, including those who process such data, must not disclose in any manner personal data entrusted to them or made known to them in connection with the performance of professional, official, or employment duties. This obligation remains in force after termination of their activities related to personal data, except in cases established by law.
7.7. Persons who have access to personal data, including those who process such data, shall be liable under Ukrainian law in case of violation of the Law of Ukraine “On Personal Data Protection.”
7.8. Personal data shall not be retained longer than necessary for the purpose for which they are stored, and in any case not longer than the retention period determined by the personal data subject’s consent to processing.
8. Rights of the Personal Data Subject
8.1. The personal data subject has the right to:
- know the location of the personal data database containing their personal data, its purpose and name, and the name and location and/or place of residence (stay) of the owner or processor of such database, or to authorize representatives to obtain such information, except as provided by law;
- receive information about the conditions for granting access to personal data, including information about third parties to whom their personal data contained in the relevant database are transferred;
- access their personal data contained in the relevant personal data database;
- receive, no later than thirty (30) calendar days from the date of receipt of the request (except as provided by law), a response indicating whether their personal data are stored in the relevant personal data database, and to receive the content of their stored personal data;
- submit a reasoned request objecting to the processing of their personal data by state authorities and local self-government bodies while exercising their statutory powers;
- submit a reasoned request to amend or destroy their personal data by any owner or processor of such database if the data are processed unlawfully or are inaccurate;
- protection of their personal data from unlawful processing and accidental loss or destruction, damage due to intentional concealment, non-provision, or untimely provision, as well as protection from providing information that is inaccurate or that discredits the honor, dignity, or business reputation of an individual;
- apply to state authorities and local self-government bodies empowered to ensure personal data protection regarding protection of their rights related to personal data;
- use legal remedies in case of violation of personal data protection legislation.
9. Procedure for Handling Requests from the Personal Data Subject
9.1. The personal data subject has the right to obtain any information about themselves from any subject of relations involving personal data without stating the purpose of the request, except as provided by law.
9.2. Access by the personal data subject to information about themselves is provided free of charge.
9.3. The personal data subject submits a request for access (hereinafter — the “request”) to the owner of the personal data database.
The request shall specify:
- surname, first name and patronymic, place of residence (stay), and details of the identity document of the personal data subject;
- other information enabling identification of the personal data subject;
- information about the personal data database to which the request relates, or information about the owner/processor of the database;
- the list of personal data requested.
9.4. The period for reviewing the request for the possibility of satisfaction shall not exceed ten (10) working days from the date of receipt. Within this period, the owner of the personal data database informs the personal data subject whether the request will be satisfied or whether the relevant personal data may not be provided, indicating the grounds established by the applicable legal act.
9.5. The request shall be satisfied within thirty (30) calendar days from the date of receipt, unless otherwise provided by law.
10. State Registration of the Personal Data Database
10.1. State registration of personal data databases is carried out in accordance with Article 9 of the Law of Ukraine “On Personal Data Protection”.