Regulations on the processing and protection of personal data in personal data databases owned by the seller
Contents
1.1. Definition of terms:
personal database - a named set of organized personal data in electronic form and/or in the form of personal data files;
responsible person - a designated person who organizes work related to the protection of personal data during their processing, in accordance with the law;
personal database owner - a natural or legal person who, by law or with the consent of the personal data subject, is granted the right to process these data, who approves the purpose of processing personal data in this database, establishes the composition of these data and the procedures for their processing, unless otherwise specified by law;
State Register of Personal Databases - a single state information system for collecting, accumulating and processing information on registered personal database;
publicly available sources of personal data - directories, address books, registers, lists, catalogs, other systematized collections of open information containing personal data, posted and published with the consent of the personal data subject. Social networks and Internet resources in which the personal data subject leaves their personal data are not considered publicly available sources of personal data (except for cases where the personal data subject explicitly states that the personal data is posted for the purpose of their free distribution and use);
consent of the personal data subject - any documented, voluntary expression of will of an individual to grant permission for the processing of their personal data in accordance with the formulated purpose of their processing;
depersonalization of personal data - removal of information that allows identifying a person;
personal data processing - any action or set of actions performed in whole or in part in an information (automated) system and/or in personal data filing systems, which are related to the collection, registration, accumulation, storage, adaptation, modification, updating, use and dissemination (dissemination, sale, transfer), depersonalization, destruction of information about an individual;
personal data - information or a set of information about an individual who is identified or can be specifically identified;
personal data database administrator - an individual or legal entity who is granted the right to process this data by the owner of the personal data database or by law. A person who is entrusted by the owner and/or the owner of the personal data database to carry out technical work with the personal data database without access to the content of the personal data is not a personal data database administrator;
personal data subject - a natural person in respect of whom, in accordance with the law, his/her personal data is processed;
third party - any person, except for the personal data subject, the owner or manager of the personal data base and the authorized state body for personal data protection, to whom the owner or manager of the personal data base transfers personal data in accordance with the law;
special categories of data - personal data about racial or ethnic origin, political, religious or ideological beliefs, membership in political parties and trade unions, as well as data concerning health or sexual life.
1.2. This Regulation is mandatory for application by the responsible person and employees of the seller who directly process and/or have access to personal data in connection with the performance of their official duties.
2.1. The Seller is the owner of the following personal data bases:
3.1. The purpose of personal data processing in the system is to ensure the implementation of civil legal relations, the provision, receipt and payment for purchased goods and services in accordance with the Tax Code of Ukraine, the Law of Ukraine "On Accounting and Financial Reporting in Ukraine".
4.1. Consent of the personal data subject
The consent of the individual to the processing of his/her personal data in accordance with the stated purpose of their processing must be voluntary.
4.2. The consent of the personal data subject may be provided in the following forms:
4.3. The consent of the personal data subject is provided during the registration of civil legal relations in accordance with the current legislation.
4.4. Notification of the subject of personal data about the inclusion of his personal data in the personal data base, the rights defined by the Law of Ukraine "On the Protection of Personal Data", the purpose of data collection and the persons to whom his personal data is transferred is carried out during the registration of civil legal relations in accordance with current legislation.
4.5. Processing of personal data about racial or ethnic origin, political, religious or ideological beliefs, membership in political parties and trade unions, as well as data relating to health or sexual life (special categories of data) is prohibited.
5.1. The personal data bases specified in Section 2 of these Regulations are located at the address of the seller.
6.1. The procedure for access to personal data of third parties is determined by the terms of the consent of the subject of personal data provided to the personal data controller to process this data, or in accordance with the requirements of the law.
6.2. Access to personal data is not granted to a third party if the specified person refuses to assume obligations to ensure compliance with the requirements of the Law of Ukraine "On Personal Data Protection" or is unable to provide them.
6.3. The subject of relations related to personal data submits a request for access (hereinafter referred to as the request) to personal data to the owner of personal data.
6.4. The request shall indicate:
6.5. The term for examining a request for its satisfaction may not exceed ten working days from the date of its receipt. During this term, the owner of the personal data base shall notify the person submitting the request that the request will be satisfied or the relevant personal data shall not be provided, indicating the grounds specified in the relevant regulatory legal act. The request shall be satisfied within thirty calendar days from the date of its receipt, unless otherwise provided by law.
6.6. Postponement of access to personal data of third parties is allowed if the necessary data cannot be provided within thirty calendar days from the date of receipt of the request. In this case, the total term for resolving the issues raised in the request cannot exceed forty-five calendar days.
6.7. The notification of the postponement is brought to the attention of the third party who submitted the request in writing with an explanation of the procedure for appealing such a decision.
6.8. The notification of the postponement shall indicate:
6.9. Denial of access to personal data is allowed if access to them is prohibited by law.
6.10. The notification of the refusal shall indicate:
6.11. The decision to postpone or refuse access to personal data may be appealed to the court.
7.1. The owner of the personal data base is equipped with system and software
amno-technical means and means of communication that prevent loss, theft, unauthorized destruction, distortion, forgery, copying of information and meet the requirements of international and national standards.
7.2. The responsible person organizes work related to the protection of personal data during their processing, in accordance with the law. The responsible person is determined by the order of the Owner of the personal data base.
The responsibilities of the responsible person regarding the organization of work related to the protection of personal data during their processing are specified in the job description.
7.3. The responsible person is obliged to:
7.4. In order to fulfill his duties, the responsible person has the right to:
7.5. Employees who directly process and/or have access to personal data in connection with the performance of their official (labor) duties are obliged to comply with the requirements of the legislation of Ukraine in the field of personal data protection and internal documents regarding the processing and protection of personal data in personal data databases.
7.6. Employees who have access to personal data, including processing them, are obliged to prevent the disclosure in any way of personal data that was entrusted to them or that became known in connection with the performance of professional, official or labor duties. Such an obligation is valid after the termination of their activities related to personal data, except for cases established by law.
7.7. Persons who have access to personal data, including processing them, in case of violation of the requirements of the Law of Ukraine "On Personal Data Protection" are liable in accordance with the legislation of Ukraine.
7.8. Personal data shall not be stored for longer than is necessary for the purpose for which such data are stored, but in any case not longer than the data storage period specified in the consent of the personal data subject to the processing of such data.
8.1. The personal data subject has the right to:
nor in the relevant personal data base, as well as to receive the content of his/her personal data that is stored;
9.1. The personal data subject has the right to receive any information about himself from any subject of relations related to personal data, without specifying the purpose of the request, except for cases established by law.
9.2. The personal data subject's access to data about himself is free of charge.
9.3. The personal data subject submits a request for access (hereinafter referred to as the request) to personal data to the owner of the personal data base.
The request shall indicate:
9.4. The term for examining a request for its satisfaction may not exceed ten working days from the date of its receipt. During this term, the owner of the personal data base shall notify the subject of personal data that the request will be satisfied or the relevant personal data shall not be provided, indicating the grounds specified in the relevant regulatory legal act.
9.5. The request shall be satisfied within thirty calendar days from the date of its receipt, unless otherwise provided by law.
10.1. State registration of personal data bases shall be carried out in accordance with Article 9 of the Law of Ukraine “On Personal Data Protection”.