Personal data processing rules
PERSONAL DATA PROCESSING RULES AT UAB "GAUDRĖ"
CAHPTER I
GENERAL PROVISIONS
UAB "Gaudrė" (hereinafter - Company or Data Controller) personal data processing rules (hereinafter - Rules) regulate the purposes of personal data processing of natural persons (hereinafter - Data Subject), determine the procedure for implementing the rights of Data Subjects, the rights, duties and responsibilities of the Company's employees in processing personal data, establishes organizational and technical data protection measures, regulates the cases of using a personal data processor.
- These Rules are prepared based on:
- the Law on the Legal Protection of Personal Data of the Republic of Lithuania (hereinafter - ADTAĮ);
- the 2016 April 27 Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons in the processing of personal data and on the free movement of such data and which repeals Directive 95/46/EC (General Data Protection Regulation; hereinafter - GDPR);
- the 2008 directive of the Director of the State Data Protection Inspectorate. November 12 by order no. 1 T–71(1.12) "On approval of General requirements for organizational and technical personal data security measures";
- the basis of other legal acts related to the processing and protection of personal data.
- These Rules apply to:
- the Data Controller - UAB "Gaudrė", which processes personal data of customers automatically and manually;
- The requirements of these Rules are mandatory for all employees of UAB "Gaudrė" (hereinafter referred to as "Employees") who manage personal data in the Company or learn about it in the course of their duties;
- For data processors – legal or natural persons authorized by the data controller to process personal data.
- Data controller – UAB "Gaudrė", company code 120682381, registered office address: Ateities st. 10, Vilnius.
CHAPTER II
TERMS USED IN THE RULES
Company - UAB "Gaudrė", company code 120682381, registered office address: Ateities st. 10, Vilnius.
- Data subject - a natural person whose personal data is processed by Gaudrė UAB.
- Personal data (or Special personal data) – any information about an identified or identifiable natural person (data subject);
- Data processing - any operation or sequence of operations performed with personal data or sets of personal data by automated or non-automated means;
- Restriction of data processing – marking of stored personal data in order to limit their processing in the future;
- Data controller - a natural or legal person, public authority, agency or other institution, which alone or together with others determines the purposes and means of data processing;
- Data processor - a natural or legal person, public authority, agency or other institution that processes personal data on behalf of the data controller (employees of the company are not considered data processors);
- Recipient of data - natural or legal person, public authority, agency or other body to which personal data is disclosed, whether it is a third party or not. However, public authorities, which according to EU or LR law can receive personal data in the course of a specific investigation, are not considered data recipients;
- Third party - a natural or legal person, public authority, agency or other institution that is not a data subject, data controller, data processor;
- Consent of the data subject - any freely given, specific and unambiguous expression of the will of a duly informed data subject by means of a statement or unequivocal actions;
- Breach of personal data security – a security breach that results in the accidental or illegal destruction, loss, alteration, unauthorized disclosure, transmission, storage or other processing of personal data;
- The supervisory authority – an independent authority established by the state – is responsible for monitoring the application of the regulation in order to protect the basic rights and freedoms of natural persons in the processing of data and create more favorable conditions for the free movement of personal data in the Union;
- Data protection officer - a person who informs the data controller or data processor and data processing employees about their obligations, monitors compliance with the EU General Data Protection Regulation, other EU or national data protection provisions and the data controller or data processor's personal data protection policy , performs the functions of a contact person when addressing issues related to data processing to the supervisory authority.
CHAPTER III
LEGAL BASIS FOR PROCESSING PERSONAL DATA
- When processing personal data of Employees for administrative purposes, the Company relies on Article 6 GDPR as the basis for legal processing. 1 d. in point b in order to ensure the proper execution of employment contracts, in point c when certain personal data of Employees are required to be processed by legal acts, and health data is processed in accordance with Art. 9 GDPR. 2 d. on the basis of point b, so that the Company or the Employee can fulfill the obligations and exercise special rights in the field of labor and social security law.
- The Company processes the personal data of candidates for the purposes of job selection based on Article 6 GDPR. 1 d. point b, because these data are needed in order to take selection steps at the candidate's request before concluding an employment contract. In the event that the Company processes health data, this is done in accordance with Art. 9 GDPR. 2 d. on the basis of point g, because processing such data is necessary for reasons of important public interest, based on EU or national law.
- The company, when processing personal data to perform its functions, relies on Article 6 GDPR as the basis for legal processing. 1 d. point c when the Company must process certain data in order to fulfill the legal obligations applicable to it.
CHAPTER IV
BASIC PERSONAL DATA PROCESSING AND PROTECTION REQUIREMENTS
- Company employees, when performing their functions and processing personal data, must comply with the basic requirements for processing personal data:
- personal data is collected for the purposes defined in data activity records and then processed in ways consistent with these purposes;
- personal data is processed accurately, fairly and legally;
- personal data must be accurate and, if necessary for the processing of personal data, constantly updated; inaccurate or incomplete data must be corrected, supplemented, destroyed or their processing stopped;
- personal data must be identical, appropriate and only to the extent necessary for their collection and further processing;
- personal data is stored in such a form that the identity of data subjects can be determined for no longer than is necessary for the purposes for which these data were collected and processed;
- personal data is processed in accordance with the personal data processing principles set out in the Law on Legal Protection of Personal Data of the Republic of Lithuania, the EU General Data Protection Regulation and other legal acts regulating municipal activities.
- Personal data are collected in the Company only in accordance with the procedure established by legal acts, receiving them:
- directly from the data subject;
- when the data controller submits a request, which must specify the purpose of using personal data, the legal basis for providing and receiving it, and the scope of the requested personal data (in case of one-time collection of personal data).
- with the person's consent.
- The terms of personal data storage and the actions to be taken after the expiry of this term are determined by legal acts regulating the processing of personal data. Personal data is stored no longer than the purposes of data processing require. The specific storage terms of personal documents (data) are determined in the order approved by the Director of the Company. When personal data are no longer needed for the purposes of their processing, they are destroyed, except for those that must be transferred to the new archive of the State of Lithuania in cases established by law.
- The company ensures that all necessary information is provided to the data subject in a clear and understandable manner.
- In the cases and procedures established by legal acts, the Company may provide personal data processed by it to third parties to whom the Company is obliged to provide personal data by laws or other legal acts, according to the request of the data recipient (in the case of one-time provision) or the personal data provision agreement concluded between the Company and the data recipient ( in the case of multiple submissions).
- The data recipient's requests and data provision contracts must meet the requirements of Article 6 of the Law on Legal Protection of Personal Data of the Republic of Lithuania. When providing data in accordance with the data provision agreement, priority is given to automatic data provision, and when providing data at the request of the data recipient, priority is given to data provision by means of electronic communications.
CHAPTER V
SPECIAL PERSONAL DATA PROCESSING REQUIREMENTS
- The company implements the organizational and technical security measures specified in the rules to protect personal data from accidental or illegal destruction, alteration, disclosure, as well as from any other illegal processing.
- If the personal data of the data subjects changes and the data subjects are informed about it in writing, such a letter from the data subject is placed in the file, and the data is updated in automatic data files and databases, deleting irrelevant personal data and recording relevant data.
- Personnel, financial, accounting and reporting files, as well as other archival files and electronic files, when exchanging documents and files with the Company's employees or their powers, are transferred to the newly hired Company employee appointed to handle personal data by a transfer-acceptance act.
- When destroying documents whose storage term has expired, the Company's documents containing personal data and their copies must be destroyed in such a way that these documents cannot be reproduced and their contents cannot be recognized.
- Documents submitted by data subjects and their copies, financing, accounting and reporting, archival or other files containing personal data are stored in locked cabinets, safes or premises. Documents containing personal data must not be kept in a visible place accessible to everyone, where unauthorized persons could easily access them.
- Areas of the local network where personal data are stored must be protected by passwords for access to personal data or access rights to them must be restricted. Passwords for access to personal data are provided, changed and stored ensuring their confidentiality, are unique, consist of at least 8 characters, do not use personal information, are changed periodically at least once every 3 months, as well as in the event of certain circumstances (change of employee, when there is a threat of hacking, when there is a suspicion that the password has become known to third parties, etc.) and during the user's first login. The employee of the company must use personal data access passwords personally and not disclose them to third parties.
- Computer equipment must be protected from harmful software (installation of antivirus programs, updates, etc.).
CHAPTER VI
REQUIREMENTS FOR PERSONS PROCESSING PERSONAL DATA
- Access to personal data can be granted only to the employee of the Company who needs personal data to perform his functions.
- Only those actions that the Company's employee is authorized to perform with personal data can be performed. The employee of the company, who processes personal data of data subjects, must:
- comply with the basic requirements for processing personal data and security requirements established in the Law on Legal Protection of Personal Data of the Republic of Lithuania, these rules and other legal acts;
- to observe the principle of confidentiality and to keep secret any information related to personal data, which he became familiar with in the performance of his functions, unless such information is public in accordance with the provisions of applicable laws or other legal acts. The obligation to keep personal data confidential also applies after moving to another position or ending the civil service or employment relationship in the Company;
- to comply with the organizational and technical personal data security measures set out in these rules in order to prevent accidental or illegal destruction, alteration, disclosure of personal data, as well as any other illegal processing, to protect documents, data files and data stored in databases and to avoid making unnecessary copies;
- not to disclose, transfer or provide conditions for access to personal data by any means to any person who is not authorized to process personal data;
- immediately notify the direct manager and the data protection officer of any suspicious situation that may pose a threat to the security of personal data processed by the Company;
- to be interested in current affairs and problems of personal data protection, to raise the qualification of legal protection of personal data;
- comply with other requirements set out in the rules and legal acts governing the protection of personal data.
- Company employees performing personal data processing functions and having access to personal data processed by the Company must sign a confidentiality pledge in the established form, which is kept in the personal file of the Company employee.
- An employee of the company loses the right to process the subjects' personal data when his employment relationship with the company ends or when he is assigned to perform functions unrelated to data processing.
- The procedure for assessing the risk posed by the processing of personal data and the management of security violations, the actions of responding to these violations, the procedure for making backup copies of data, storing and restoring data from backup copies of data are determined by the data security regulations of the Company's information system.
CHAPTER VII SKYRIUS
IMPLEMENTATION OF THE RIGHTS OF THE DATA SUBJECT
- The data subject has the right to know (be informed) about the processing of his personal data.
- Entities are informed about the processing of personal data in writing, in electronic form (approved by the Head of the Company). At the request of the data subject, information may be provided verbally, but in all cases, information collected about a specific person is provided only after the data subject proves his identity.
- Information about the processing of personal data is provided to data subjects indicating that:
- personal data of data subjects is processed by the data controller - UAB "Gaudrė" (hereinafter - the Company), company code 120682381, registered office address: Ateities st. 10, Vilnius;
- personal data in the Company is processed manually in systematized files and/or automatically;
- The scope of personal data of data subjects processed in the company and the purposes of personal data processing are indicated in the records of personal data processing activities;
- personal data is provided to third parties only in the cases and procedures established by laws and other legal acts.
- The data subject, who has submitted a document confirming the identity of the person or in accordance with the procedure established by legal acts or electronic means of communication that allows the proper identification of the person, having confirmed his personal identity, has the right to familiarize himself with his data processed by the Company free of charge and to receive information from which sources and what his personal data collected, for what purpose it is processed, to which data recipients it is provided and has been provided in the last one year.
- The company, upon receiving the data subject's request, shall respond no later than within 30 (thirty) calendar days from the date of receipt of the data subject's request, whether the personal data of the data subject is being processed, and provide the requested data or indicate the reasons for refusing to fulfill such a request. At the request of the data subject, such data must be provided in writing.
- If the data subject, having familiarized himself with his personal data, determines that his personal data is incorrect, incomplete or inaccurate, and applies to the Company, the latter immediately checks the personal data and upon the written request of the data subject submitted in person, by mail or by means of electronic communications, immediately corrects incorrect, inaccurate, supplements incomplete personal data processed by the Company and/or suspends the processing of such personal data, except for storage, until incorrect, inaccurate, supplemented incomplete personal data is corrected or personal data is destroyed.
- If there are doubts about the correctness of the personal data provided by the data subject, the Company stops the processing of such data, checks and clarifies them. Such personal data can only be used to verify their correctness.
- The company immediately informs the data subject about the correction, destruction or suspension of personal data processing performed or not performed at his request. The company also immediately informs data recipients about corrected or destroyed personal data at the request of the data subject, suspension of personal data processing actions, except in cases where providing such information would be impossible or too difficult (due to a large number of data subjects, data period, unreasonably high costs). In such a case, the Company shall immediately notify the State Data Protection Inspectorate.
- The data subject, if he does not agree to the processing of his personal data, may submit a written notice of objection to the processing of personal data to the Company in person, by mail or by means of electronic communications. This right of the data subject is implemented before performing personal data processing actions, when personal data is intended to be processed in accordance with Article 5, Part 1, Clauses 5 and (or) 6 of the Law on Legal Protection of Personal Data of the Republic of Lithuania.
- In order to implement the data subject's right to object to the processing of his personal data, the company applies to the data subject in writing and sets a deadline during which the data subject has the right to express his objection.
- If the data subject's objection is legally justified, the Company immediately terminates the processing of personal data, except for cases established by legal acts, and informs the data recipients.
- If the data subject does not submit a written notice of objection to the processing of personal data by the deadline set by the Company, it is considered that the data subject has not exercised his right to object to the processing of his personal data.
- At the request of the data subject, the Company shall notify the data subject of the termination of his personal data processing actions or refusal to terminate the data processing actions.
- The company must create conditions for the data subject to exercise the rights established in this chapter, except for the cases established by law, when it is necessary to ensure:
- national security or defense;
- public order, prevention, investigation, detection or prosecution of criminal acts;
- important economic or financial interests of the state;
- prevention, investigation and determination of violations of official or professional ethics;
- protection of the rights and freedoms of the data subject or other persons.
- The data subject, in order to exercise the rights provided for in this section of the rules, submits a written request in which he must indicate his wish, name, address, and contact details. If the representative of the data subject applies for the implementation of the rights of the data subject, he must indicate his name, surname, place of residence, as well as the name, surname, place of residence of the person represented and attach a document confirming the representation.
- All requests submitted to the Company in writing, including in electronic form, must be signed by the data subject or his representative.
- The data subject's written request may be submitted in person, by mail or by means of electronic communications.
- Standardized data subjects' requests for access to data are received after they fill out the form of the Subjects' request for access to personal data approved by the Head of the Company. The specified form can be obtained by the data subject by contacting the Company's data protection officer, through the contacts indicated on the Company's website.
- Company employees cannot formally rely on non-compliance with the aforementioned form as a basis for refusing to accept a data subject's request or delaying its examination.
- Information may be provided to the data subject orally, depending on his request, by allowing access to the document, by providing a certificate, an extract of the document or a paper copy of the document, electronic media, audio, video or audio and video recording, access to the information file. If the form of information submission is not specified in the request, the Company provides it in the same form as the received request.
- If private information is sent to the data subject by mail, it is sent only by registered mail.
- Information is provided only in the state language.
- The Company's actions or inactions related to the implementation of the data subject's rights may be appealed to the State Data Protection Inspectorate, and in the case of possible illegal processing of personal data, the Company's actions or inactions may be appealed to the State Data Protection Inspectorate.
CHAPTER VIII
ACTIONS IN CASE OF BREACH OF PERSONAL DATA SECURITY
- The person whose data is processed, having noticed that an employee of the Company may have violated these rules or the provisions of the Law on Legal Protection of Personal Data of the Republic of Lithuania, must immediately inform the head of a specific department. The head of the department informs the Director of the Company about a possible violation by a civil servant or employee.
- In the event of a breach of personal data security, the data controller shall notify the supervisory authority without undue delay and, if possible, within no more than 72 hours after becoming aware of the breach of personal data security, unless the breach of personal data security should not endanger physical rights and freedoms of individuals. If the supervisory authority is not notified of a breach of personal data security within 72 hours, the reasons for the delay shall be attached to the notification.
- The data processor, upon learning of a breach of personal data security, notifies the data controller without undue delay. The notice must contain:
- the nature of the personal data security breach is described, including, if possible, the categories and approximate number of relevant data subjects, as well as the categories and approximate number of relevant personal data records;
- name and contact details of the data protection officer or other contact person who can provide more information;
- the likely consequences of a breach of personal data security are described;
- describes the measures taken or proposed to be taken by the data controller to eliminate the personal data security breach, including, where appropriate, measures to reduce its possible negative consequences.
- When it is not possible to provide information at the same time, the information may be provided in stages without further delay.
- The data controller shall document all personal data security breaches, including the facts related to the personal data security breach, its impact and corrective actions taken. Based on those documents, the supervisory authority must be able to verify compliance with this Article.
- Employees of the company who have violated the requirements of these rules shall be liable in accordance with the procedure established by the legal acts of the Republic of Lithuania.
CHAPTER IX
DATA PROTECTION OFFICER
- According to Art. 37 GDPR 1 part it is mandatory to have a data protection officer if the main activity of the data controller or data processor is the processing of special categories of data on a large scale or when the data is processed by a public authority or an institution other than the courts when they exercise their judicial functions.
- If a data protection officer is not mandatory in the Company, the data controller may appoint him by the decision of the Company manager, if he considers that a data protection officer is necessary in the Company. Considering the fact that the Company does not process personal data on a large scale, a data protection officer is not appointed in the Company.
CHAPTER X
FINAL PROVISIONS
- Personal data in the field of electronic communications is processed in accordance with the Law of the Republic of Lithuania on Electronic Communications, the Law of the Republic of Lithuania on the Legal Protection of Personal Data, the Law of the Republic of Lithuania on Cyber Security.
- The rights of the person whose data is processed are determined by the Law on Legal Protection of Personal Data of the Republic of Lithuania and the Civil Code of the Republic of Lithuania.
- Employees of the company are familiarized with these rules by signing.
- The head of the Company is responsible for the supervision and control of compliance with the rules.