Regulation on the processing and protection of personal data in the personal databases owned by the seller

 

Contents

  1. General concepts and scope of application
  2. List of personal databases
  3. Purpose of processing personal data
  4. Procedure for processing personal data: obtaining consent, notification of rights and of actions with the personal data of the personal data subject
  5. Location of the personal database
  6. Conditions for disclosing information about personal data to third parties
  7. Protection of personal data: methods of protection, the responsible person, the employees who directly carry out the processing of and/or have access to personal data in connection with the performance of their official duties, the personal data retention period
  8. Rights of the personal data subject
  9. Procedure for handling requests from the personal data subject
  10. State registration of the personal database

 

1. General concepts and scope of application

1.1. Definitions of terms:

personal database means a named set of ordered personal data in electronic form and/or in the form of personal data card files;

responsible person means a designated person who organises the work connected with the protection of personal data during their processing, in accordance with the law;

owner of a personal database means a natural or legal person who, by law or with the consent of the personal data subject, has been granted the right to process such data, who approves the purpose of processing personal data in that database and establishes the composition of such data and the procedures for their processing, unless otherwise provided by law;

State Register of Personal Databases means the unified state information system for the collection, accumulation and processing of information about registered personal databases;

publicly available sources of personal data means directories, address books, registers, lists, catalogues and other systematised collections of open information that contain personal data placed and published with the knowledge of the personal data subject. Social networks and internet resources in which the personal data subject leaves their personal data are not deemed publicly available sources of personal data (except where the personal data subject has expressly stated that the personal data are placed for the purpose of their free dissemination and use);

consent of the personal data subject means any documented, voluntary expression of will by a natural person granting permission to process their personal data in accordance with the stated purpose of such processing;

depersonalisation of personal data means the removal of information that makes it possible to identify a person;

processing of personal data means any action or set of actions carried out in whole or in part in an information (automated) system and/or in personal data card files, connected with the collection, registration, accumulation, storage, adaptation, alteration, renewal, use and dissemination (distribution, sale, transfer), depersonalisation or destruction of information about a natural person;

personal data means information or a set of information about a natural person who is identified or may be specifically identified;

administrator of a personal database means a natural or legal person who has been granted the right to process such data by the owner of the personal database or by law. A person entrusted by the owner and/or the administrator of a personal database with performing work of a technical nature with the personal database without access to the content of the personal data is not an administrator of the personal database;

personal data subject means a natural person in respect of whom the processing of their personal data is carried out in accordance with the law;

third party means any person, other than the personal data subject, the owner or administrator of the personal database and the authorised state body for the protection of personal data, to whom the owner or administrator of the personal database transfers personal data in accordance with the law;

special categories of data means personal data on racial or ethnic origin, political, religious or ideological beliefs, membership of political parties and trade unions, and also data concerning health or sexual life.

1.2. This Regulation is binding on the responsible person and on the employees of the seller who directly carry out the processing of and/or have access to personal data in connection with the performance of their official duties.

 

2. List of personal databases

2.1. The seller is the owner of the following personal databases:

  • the personal database of counterparties.

 

3. Purpose of processing personal data

3.1. The purpose of processing personal data in the system is to ensure the implementation of civil-law relations, the provision and receipt of goods and services and the settlement of payments for the goods and services purchased, in accordance with the Tax Code of Ukraine and the Law of Ukraine "On Accounting and Financial Reporting in Ukraine".

 

4. Procedure for processing personal data: obtaining consent, notification of rights and of actions with the personal data of the personal data subject

4.1. The consent of the personal data subject must be a voluntary expression of will by a natural person granting permission to process their personal data in accordance with the stated purpose of such processing.

4.2. The consent of the personal data subject may be given in the following forms:

  • a paper document bearing details that make it possible to identify that document and the natural person;
  • an electronic document, which must contain the mandatory details that make it possible to identify that document and the natural person. It is advisable that the voluntary expression of will by a natural person granting permission to process their personal data be certified by the electronic signature of the personal data subject;
  • a mark on the electronic page of a document or in an electronic file processed in an information system on the basis of documented software and hardware solutions.

4.3. The consent of the personal data subject is given at the time when civil-law relations are formalised in accordance with the applicable legislation.

4.4. The personal data subject is notified of the inclusion of their personal data in the personal database, of the rights established by the Law of Ukraine "On Personal Data Protection", of the purpose of the data collection and of the persons to whom their personal data are transferred, at the time when civil-law relations are formalised in accordance with the applicable legislation.

4.5. The processing of personal data on racial or ethnic origin, political, religious or ideological beliefs, membership of political parties and trade unions, and also of data concerning health or sexual life (special categories of data), is prohibited.

 

5. Location of the personal database

5.1. The personal databases specified in Section 2 of this Regulation are located at the address of the seller.

 

6. Conditions for disclosing information about personal data to third parties

6.1. The procedure for the access of third parties to personal data is determined by the terms of the consent of the personal data subject given to the owner of the personal data for the processing of those data, or in accordance with the requirements of the law.

6.2. Access to personal data is not granted to a third party if that party refuses to undertake obligations to ensure compliance with the requirements of the Law of Ukraine "On Personal Data Protection" or is unable to ensure such compliance.

6.3. A party to relations connected with personal data submits a request for access (hereinafter referred to as the request) to personal data to the owner of the personal data.

6.4. The request shall specify:

  • the surname, first name and patronymic, place of residence (place of stay) and the details of the document identifying the natural person submitting the request (for a natural person as the applicant);
  • the name and location of the legal person submitting the request, the position, surname, first name and patronymic of the person certifying the request, and confirmation that the content of the request corresponds to the powers of the legal person (for a legal person as the applicant);
  • the surname, first name and patronymic, and also other information making it possible to identify the natural person in respect of whom the request is made;
  • information about the personal database in respect of which the request is submitted, or information about the owner or administrator of that personal database;
  • the list of the personal data requested;
  • the purpose of and/or the legal grounds for the request.

6.5. The period for examining the request with a view to granting it may not exceed ten working days from the date of its receipt. Within that period the owner of the personal database shall inform the person submitting the request that the request will be granted or that the personal data concerned are not subject to disclosure, stating the ground established by the relevant regulatory act. The request is granted within thirty calendar days from the date of its receipt, unless otherwise provided by law.

6.6. Access to personal data by third parties may be deferred where the data required cannot be provided within thirty calendar days from the date of receipt of the request. In that case the overall period for resolving the matters raised in the request may not exceed forty-five calendar days.

6.7. Notice of the deferral is communicated to the third party that submitted the request in writing, with an explanation of the procedure for appealing against such a decision.

6.8. The notice of deferral shall specify:

  • the surname, first name and patronymic of the official;
  • the date on which the notice was sent;
  • the reason for the deferral;
  • the period within which the request will be granted.

6.9. Access to personal data may be refused where access to them is prohibited by law.

6.10. The notice of refusal shall specify:

  • the surname, first name and patronymic of the official refusing access;
  • the date on which the notice was sent;
  • the reason for the refusal.

6.11. A decision to defer or to refuse access to personal data may be appealed against in court.

 

7. Protection of personal data: methods of protection, the responsible person, the employees who directly carry out the processing of and/or have access to personal data in connection with the performance of their official duties, the personal data retention period

7.1. The owner of the personal database is equipped with system, software and hardware facilities and communication facilities that prevent losses, theft, unauthorised destruction, distortion, falsification and copying of information and that meet the requirements of international and national standards.

7.2. The responsible person organises the work connected with the protection of personal data during their processing, in accordance with the law. The responsible person is designated by an order of the owner of the personal database.

The duties of the responsible person regarding the organisation of the work connected with the protection of personal data during their processing are set out in the job description.

7.3. The responsible person is obliged:

  • to know the legislation of Ukraine in the field of personal data protection;
  • to develop procedures for employees' access to personal data in accordance with their professional, official or labour duties;
  • to ensure that the employees of the owner of the personal database comply with the requirements of the legislation of Ukraine in the field of personal data protection and with the internal documents governing the activity of the owner of the personal database in respect of the processing and protection of personal data in personal databases;
  • to develop a procedure for internal control over compliance with the requirements of the legislation of Ukraine in the field of personal data protection and with the internal documents governing the activity of the owner of the personal database in respect of the processing and protection of personal data in personal databases, which shall, in particular, contain rules on how often such control is exercised;
  • to inform the owner of the personal database of any breach by employees of the requirements of the legislation of Ukraine in the field of personal data protection and of the internal documents governing the activity of the owner of the personal database in respect of the processing and protection of personal data in personal databases, no later than one working day from the moment such breaches are discovered;
  • to ensure the storage of the documents confirming that the personal data subject has given consent to the processing of their personal data and that the said subject has been notified of their rights.

7.4. In order to perform their duties, the responsible person has the right:

  • to receive the necessary documents, including orders and other administrative documents issued by the owner of the personal database that relate to the processing of personal data;
  • to make copies of the documents received, including copies of files and of any records stored in local computer networks and standalone computer systems;
  • to take part in the discussion of the duties they perform in organising the work connected with the protection of personal data during their processing;
  • to submit proposals for improving the activity and refining the working methods, and to put forward comments and options for eliminating the shortcomings identified in the course of processing personal data;
  • to obtain explanations on matters relating to the processing of personal data;
  • to sign and endorse documents within the limits of their competence.

7.5. Employees who directly carry out the processing of and/or have access to personal data in connection with the performance of their official (labour) duties are obliged to comply with the requirements of the legislation of Ukraine in the field of personal data protection and with the internal documents on the processing and protection of personal data in personal databases.

7.6. Employees who have access to personal data, including those who process them, are obliged not to disclose in any way the personal data entrusted to them or that became known to them in connection with the performance of their professional, official or labour duties. This obligation remains in force after they cease the activity connected with personal data, except in the cases established by law.

7.7. Persons who have access to personal data, including those who process them, bear liability under the legislation of Ukraine if they breach the requirements of the Law of Ukraine "On Personal Data Protection".

7.8. Personal data must not be stored longer than is necessary for the purpose for which such data are stored, and in any event no longer than the data retention period determined by the consent of the personal data subject to the processing of those data.

 

8. Rights of the personal data subject

8.1. The personal data subject has the right:

  • to know the location of the personal database that contains their personal data, its purpose and name, the location and/or place of residence (stay) of the owner or administrator of that database, or to give a corresponding instruction to persons authorised by them to obtain that information, except in the cases established by law;
  • to receive information about the conditions on which access to personal data is granted, in particular information about the third parties to whom their personal data contained in the relevant personal database are transferred;
  • to have access to their personal data contained in the relevant personal database;
  • to receive, no later than thirty calendar days from the date of receipt of the request, except in the cases provided for by law, an answer as to whether their personal data are stored in the relevant personal database, and also to receive the content of their personal data that are stored;
  • to lodge a reasoned objection to the processing of their personal data by state authorities and local self-government bodies in the exercise of their powers provided for by law;
  • to lodge a reasoned demand for the alteration or destruction of their personal data by any owner or administrator of that database if those data are processed unlawfully or are inaccurate;
  • to have their personal data protected against unlawful processing and against accidental loss, destruction or damage caused by deliberate concealment, failure to provide or untimely provision of the data, and also to be protected against the provision of information that is inaccurate or that discredits the honour, dignity and business reputation of a natural person;
  • to apply, on matters concerning the protection of their rights in respect of personal data, to state authorities and local self-government bodies whose powers include the protection of personal data;
  • to apply legal remedies in the event of a breach of the legislation on the protection of personal data.

 

9. Procedure for handling requests from the personal data subject

9.1. The personal data subject has the right to obtain any information about themselves from any party to relations connected with personal data, without stating the purpose of the request, except in the cases established by law.

9.2. Access by the personal data subject to the data about themselves is provided free of charge.

9.3. The personal data subject submits a request for access (hereinafter referred to as the request) to personal data to the owner of the personal database.

The request shall specify:

  • the surname, first name and patronymic, place of residence (place of stay) and the details of the document identifying the personal data subject;
  • other information making it possible to identify the personal data subject;
  • information about the personal database in respect of which the request is submitted, or information about the owner or administrator of that database;
  • the list of the personal data requested.

9.4. The period for examining the request with a view to granting it may not exceed ten working days from the date of its receipt. Within that period the owner of the personal database shall inform the personal data subject that the request will be granted or that the personal data concerned are not subject to disclosure, stating the ground established by the relevant regulatory act.

9.5. The request is granted within thirty calendar days from the date of its receipt, unless otherwise provided by law.

 

10. State registration of the personal database

10.1. State registration of personal databases is carried out in accordance with Article 9 of the Law of Ukraine "On Personal Data Protection".