UAB „Own Leasing“

PERSONAL DATA PROCESSING RULES

1.

GENERAL PROVISIONS AND DEFINITIONS

1.1

The personal data processing rules of UAB “Own Leasing” (the “Company”) (the “Rules”) set out the requirements for the processing of personal data (as defined in these Rules) within the Company (including the processing of personal data of customers, employees, suppliers and partners), as well as the technical and organisational measures implemented by the Company to protect personal data against accidental or unlawful destruction, alteration or disclosure, and against any other unlawful processing.

1.2

These Rules have been prepared in accordance with the EU General Data Protection Regulation, which entered into force on 25 May 2018 (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC) (the “Regulation”), the Law on Legal Protection of Personal Data of the Republic of Lithuania (the “Law”), and other legislation governing the protection and processing of personal data.

1.3

In these Rules and their annexes, terms written with an initial capital letter shall have the meanings set out below:

Personal Data (Data)

means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

Personal Data Breach

means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed;

Responsible Employee

means an Employee of the Company appointed by the head of the Company to be responsible for the protection of Personal Data, ensuring: (i) implementation of the Regulation as set out in these Rules, and (ii) management of Data security and risks in accordance with these Rules. Where a Data Protection Officer has been appointed, that person shall also be regarded as the Responsible Employee;

Company

has the meaning given to it in clause 1.1 of these Rules;

Employee

means a natural person who has entered into an employment or other similar agreement with the Company;

Data Protection Officer

means an Employee of the Company or another person providing services under a service agreement, appointed to monitor and oversee the implementation of the Regulation within the Company;

Data Subject

means a living natural person whose Personal Data is processed by the Company;

Data Subject's Consent

means any freely given, specific, informed and unambiguous indication of the Data Subject's wishes, given by a duly informed Data Subject either by a statement or by a clear affirmative action, signifying agreement to the processing of Data relating to them;

Data Processing

means any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;

Data Processor

means a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Data Controller;

Data Controller

means a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data;

Law

has the meaning given to it in clause 1.2 of these Rules;

Supervisory Authority

means the State Data Protection Inspectorate or another supervisory authority responsible for overseeing the implementation of legislation governing the protection of Data;

Profiling

means any form of automated processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements. This term is linked to the Data Subject's right to object to Profiling and the right to be informed about the use of Profiling, its significance and its envisaged consequences for the Data Subject;

Regulation

has the meaning given to it in clause 1.2 of these Rules;

Special categories of personal data

means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation;

Rules

has the meaning given to it in clause 1.1 of these Rules;

Third Party

means a natural or legal person, public authority, agency or other body other than the Data Subject, the Data Controller, the Data Processor, or a person who, under the direct authority of the Data Controller or Data Processor, is authorised to process Personal Data.

1.4

Other terms used in these Rules shall be understood as defined in the Regulation, the Law and other legislation.

2.

RESPONSIBILITIES UNDER THE REGULATION

2.1

For the purposes of the Regulation, the Company is considered a Data Controller. In individual cases of Data Processing, the Company may also act as a Data Processor.

2.2

The Company's management, including all persons performing managerial and/or supervisory functions, is responsible for promoting and developing good information governance practices within the Company and for making decisions relating to the proper implementation of the Regulation.

2.3

The proper implementation of the Regulation within the Company is overseen and monitored by the Responsible Employee.

2.4

All Employees of the Company who process Personal Data within their assigned competence are responsible for compliance with Data protection legislation. The obligation to maintain the confidentiality of Personal Data continues even after the employment relationship with the Company ends.

2.5

The above responsibility includes:

  • implementation of the Regulation, as set out in these Rules;
  • ensuring Data security and managing risks in accordance with these Rules.

2.6

Employees must promptly notify the Responsible Employee of any suspicious situation that may pose a threat to Data security.

2.7

Employees must ensure that all Personal Data they provide to the Company is accurate and up to date.

2.8

An Employee who breaches the requirements of the Regulation, the Law or other legislation governing the protection of personal data shall be held liable in accordance with the procedure established by the legislation of the Republic of Lithuania.

2.9

Where necessary, the Company organises training for Employees on personal data protection matters, to help Employees perform their duties in accordance with the Regulation, the Law and other legislation governing the protection of personal data.

3.

DATA PROTECTION OFFICER

3.1

Where such a need is identified, the Company shall appoint a Data Protection Officer, who may be an Employee of the Company or a person providing Data Protection Officer services under a service agreement. Where a Data Protection Officer has been appointed, that person shall also be regarded as the Responsible Employee.

3.2

The Company appoints the Data Protection Officer having regard to their expert knowledge of Data protection law and practice, professional qualities, and ability to perform the functions assigned to the Data Protection Officer.

3.3

The Company ensures the guarantees afforded to the Data Protection Officer under the Regulation.

3.4

The Data Protection Officer performs the tasks set out in the Regulation and in these Rules and reports directly to the head of the Company.

3.5

A dedicated email address is created for the Data Protection Officer's functions and for communicating with this person, and its address is publicly published on the Company's website.

3.6

The Company notifies the Supervisory Authority of the appointment of the Data Protection Officer.

3.7

In order to prevent the accidental or unlawful destruction, alteration or disclosure of Personal Data, or any other unlawful Data Processing, Employees of the Company who process Personal Data or organise its processing must consult the Data Protection Officer and obtain their opinion in the following cases:

  • before changing existing or launching new Personal Data processing processes;
  • when improving existing or implementing new systems or programs related to Personal Data processing;
  • when carrying out a data protection impact assessment;
  • when preparing internal legal acts related to Personal Data processing;
  • when preparing new or amending existing agreements for the provision or processing of Personal Data;
  • when deciding on the provision of Personal Data to Third Parties, if such provision is not provided for in a Personal Data provision agreement and is not regulated by legislation.

4.

DATA PROCESSING PRINCIPLES

Data is processed within the Company in accordance with the Data Processing principles set out in Article 5 of the Regulation. The Company's internal policies and processes are prepared and implemented in a manner that ensures compliance with these principles.

Data must be processed lawfully, fairly and transparently

4.1

Lawfulness means that, before Personal Data processing begins, a legal basis for the Data Processing must be established in all cases.

4.2

Fairness means that the Data Controller must provide Data Subjects with relevant information about the processing of their Data. This obligation applies both where the Data is obtained directly from the Data Subject and where it is obtained from other sources.

4.3

Transparency means that Data Subjects must be provided with comprehensive information about the processing of their Data. The specific information that must be provided is set out in Articles 12–14 of the Regulation. The information must be provided in an intelligible and easily accessible form, using clear and plain language.

Data is collected for specified, explicit and legitimate purposes

4.4

Data collected for the original purposes shall not be further processed in a manner incompatible with those purposes; further processing for archiving purposes in the public interest, for scientific or historical research purposes, or for statistical purposes is not considered incompatible with the original purposes.

Data must be adequate, relevant and limited to what is necessary for the purposes

4.5

The Company ensures that it does not process Data that is not necessary to achieve the purposes for which the Data was collected.

4.6

All Data collection forms (both electronic and physical) must include information about fair Data Processing or a reference to the privacy notice. Forms must be agreed with the Responsible Employee.

4.7

The Responsible Employee regularly reviews Data collection procedures to ensure that they remain adequate, relevant and not excessive.

Data must be accurate and kept up to date

4.8

Every reasonable step must be taken to ensure that Personal Data that is inaccurate or incorrect, having regard to the purposes for which it is processed, is erased or rectified without delay.

4.9

The Responsible Employee must ensure that all Employees are properly trained and understand the importance of collecting accurate Data and maintaining such accuracy.

4.10

The Data Subject is also responsible for maintaining the accuracy of their Data provided to the Company.

4.11

The Responsible Employee regularly reviews the retention periods of the Data processed and identifies Data that is no longer necessary for the purposes for which it was collected. Such Data is securely erased (destroyed).

4.12

The Responsible Employee or another authorised person must respond to Data Subjects' requests for rectification of their Data no later than within one (1) month. In the case of complex requests, this period may be extended by a further two (2) months. If the Company refuses to rectify Personal Data, the Responsible Employee or another authorised person must inform the Data Subject of the reasons for the refusal and of the possibility of lodging a complaint with the Supervisory Authority.

Data must be kept in a form which permits identification of Data Subjects for no longer than is necessary

4.13

Where Personal Data is stored after the end of its active processing, the Company implements appropriate technical and organisational measures (including, depending on the case, data minimisation, encryption and/or pseudonymisation), which help protect the identity of the Data Subject in the event of a Personal Data Breach.

4.14

Personal Data will be stored for no longer than provided for in the records of Data Processing activities and only for as long as is necessary to achieve the purposes for which such Data is processed.

Data must be processed in a manner that ensures appropriate Data security through the use of appropriate technical or organisational measures

4.15

Where necessary (including where the scope or nature of the Data processed changes), the Responsible Employee carries out a risk assessment, taking into account all Data management and processing operations carried out by the Company.

4.16

Data security measures within the Company are implemented having regard to the nature of the Data processed and the risk posed by its processing, the extent of potential harm to individuals (for example, Employees, customers) in the event of a Personal Data Breach, and the impact that a Personal Data Breach would have on the Company itself, including potential reputational damage.

4.17

When determining appropriate technical security measures, the following are, among other things, assessed and, where necessary, implemented:

  • password protection;
  • automatic locking of inactive screens;
  • the need for anti-virus software and firewalls;
  • the granting of differentiated access rights depending on the functions performed by the relevant person (role-based access);
  • protection of local and wide area networks;
  • the use of Data protection-enhancing measures (such as pseudonymisation and anonymisation).

4.18

When determining appropriate organisational security measures, the following are, among other things, taken into account (and, where necessary, implemented):

  • the level of training of the Company's Employees;
  • measures for assessing the reliability of Employees;
  • the inclusion of Data protection provisions in agreements with Employees;
  • the establishment of disciplinary measures for breaches of Data protection requirements;
  • monitoring of Employees' compliance with applicable security standards;
  • restriction of physical access to electronic and physical records;
  • implementation of a “clean desk” policy in the workplace;
  • storage of Data kept in physical form in fire-resistant, lockable storage facilities;
  • restriction of the use of Employees' personal equipment in the workplace;
  • adoption of clear rules on the use of passwords;
  • regular backing up of Data and storage of backups in a different location;
  • imposing contractual obligations on Data Processors that process Data on behalf of the Company.

4.19

The technical and organisational security measures implemented by the Company are also set out and described in other internal documents and procedures of the Company, including the Information Security Policy.

The Data Controller must be able to demonstrate compliance with the principles of the Regulation (accountability)

4.20

The Company may demonstrate compliance of Data Processing with the data protection principles on the basis of: adopted personal data processing rules, internal policy provisions on data security, implemented technical and organisational security measures, as well as other measures implemented by the Company (such as data protection by design, data protection impact assessments, Personal Data Breach notification procedures, etc.).

5.

RIGHTS OF DATA SUBJECTS

5.1

Data Subjects have the following rights in relation to the processing of their Data:

  • the right to contact the Company to obtain access to their Data processed by the Company;
  • the right to object to Data Processing (including Profiling) carried out to pursue the Company's legitimate interests;
  • the right to object to Data Processing (including Profiling) for direct marketing purposes;
  • the right to be informed of the logic involved in, as well as the significance and envisaged consequences of, automated decision-making, where such decision-making will significantly affect them or may produce legal effects;
  • the right to require that decisions significantly affecting them are not based solely on automated processing;
  • the right to apply to a court for compensation in the event of a breach of the Regulation;
  • the right to require the rectification or erasure of Data, or the restriction of its processing;
  • the right to lodge a complaint with the Supervisory Authority;
  • the right to receive Personal Data concerning the Data Subject in a structured, commonly used and machine-readable format, and the right to transmit that Data to another Data Controller;
  • the right to withdraw their consent.

5.2

The Company ensures the exercise of these rights in accordance with the procedure for handling Data Subjects' requests and complaints (which is attached as an annex to these Rules).

6.

CONSENT OF THE DATA SUBJECT

6.1

The Company only regards “consent” as a freely given, specific, informed and unambiguous indication of the Data Subject's wishes, given by a statement or by a clear affirmative action, by which they agree to the processing of Personal Data relating to them. The Data Subject has the right to withdraw their consent at any time.

6.2

Consent cannot be inferred from the Data Subject's inaction (including failure to respond to a request, failure to object to pre-ticked boxes (options), etc.). The Company must be able to demonstrate that consent to Data Processing was obtained.

6.3

The Company presents the request for consent separately from other terms and conditions. Giving consent may not be made a condition of the provision of services.

6.4

The processing of special categories of personal data requires the Data Subject's explicit consent. This requirement does not apply where such Data is processed on other lawful grounds.

6.5

The Company generally obtains Data Subjects' consent to the processing of their Data using standard consent forms (for example, tick boxes (options) for direct marketing).

Consent-obtaining procedure

6.6

In order to comply with the requirements applicable to obtaining consent, the Company:

  • in every case, before the Data Subject gives consent, provides the Data Subject with a privacy notice, which helps ensure that the duty to inform is properly fulfilled and that the Data Subject is informed of their rights relating to Data Processing;
  • can demonstrate that the Data Subject's consent to the processing of their Personal Data for one or more purposes was obtained;
  • in the case of processing special categories of personal data, can demonstrate that the Data Subject's explicit consent was obtained;
  • can demonstrate that the request for consent was presented to the Data Subject separately from other terms and conditions;
  • can demonstrate that, before giving consent, the Data Subject was informed of the right to withdraw it;
  • can demonstrate that the Data Subject's Data Processing is limited to what is provided for in the Data Subject's consent.
Consent-withdrawal procedure

6.7

Withdrawal of consent means an unambiguous expression of the Data Subject's wishes (by statement or active conduct) indicating their wish to withdraw the consent given to the Company regarding the processing of their Data.

6.8

Withdrawal of consent does not affect the lawfulness of Data Processing based on consent carried out before the withdrawal, nor Data Processing based on other legal grounds. Where consent was given for all Data Processing activities carried out for a specific purpose, its withdrawal shall be regarded as a withdrawal of consent for all such Data Processing activities.

6.9

It must be as easy to withdraw consent as it is to give it.

6.10

In order to comply with the requirements applicable to the withdrawal of consent, the Company:

  • documents the fact that the Data Subject has withdrawn the consent given;
  • where Data was processed for different purposes, can demonstrate that the Data Subject withdrew consent for each of the purposes for which separate consents were given;
  • suspends the Data Processing activities that were carried out on the basis of the Data Subject's consent.

7.

DATA SECURITY

7.1

The technical and organisational measures implemented within the Company ensure a level of Data security appropriate to the nature of the Data held and processed by the Company and to the risks posed by its processing.

7.2

All Employees must ensure that any Data processed by the Company for which such Employees are responsible is reliably stored and is not, under any circumstances, accessible to Third Parties, except where such Third Parties are authorised to receive the information and are obliged to keep it confidential.

7.3

Any Personal Data will be accessible only to those persons (Employees, Data Processors) who require it, and access shall be granted in accordance with the Company's internal procedures and policies. All Personal Data will be subject to security measures consistent with market standards and will be kept:

  • in lockable premises with controlled access; and/or
  • in lockable storage (cabinets, drawers); and/or
  • in the case of Data in electronic form, protected by passwords consistent with good Data security practice.

7.4

The Company takes measures to ensure that the screens of the Company's Employees' computers are visible only to authorised Employees. Before using computers, Employees must familiarise themselves with the Company's internal procedures governing information security.

7.5

Data stored in physical form may not be left unattended where it could be accessed by Employees or other persons who do not have the right of access to it. In the absence of clear authorisation, Data stored in physical form may only be kept on the Company's premises. Once such Data is no longer needed for the Company's day-to-day operations, it must be archived.

7.6

Personal Data that is no longer needed (and does not need to be retained) is erased or otherwise destroyed in accordance with good practice for the secure destruction of Data.

7.7

Processing Data outside the Company's premises inevitably carries a higher risk of theft, other loss or damage to the Data. Accordingly, Employees must obtain separate authorisation to process Personal Data outside the Company's premises.

7.8

The specific measures implemented by the Company to ensure the security of Personal Data are set out in the Information Security Policy and other internal documents of the Company.

8.

ENGAGEMENT OF DATA PROCESSORS

8.1

The Company enters into agreements only with service providers (Data Processors) that can ensure the implementation of sufficient technical, physical and organisational security measures, consistent with the Company's requirements, in respect of all Personal Data disclosed by the Company.

8.2

All agreements entered into by the Company are regularly reviewed in order to identify those agreements under which Personal Data is processed.

8.3

The Company (as Data Controller) ensures that all necessary arrangements with service providers (Data Processors) regarding Data security are set out in written agreements that provide for appropriate Data security measures.

8.4

Data Processors operating outside the European Economic Area are engaged only where the requirements set out in Part 12 of these Rules are complied with.

8.5

All agreements with Data Processors must grant the Company the right to regularly carry out audits and inspections of service providers, to assess the adequacy of the security measures applied by the Data Processor to the Data Processing activities it carries out.

8.6

Data Processors may engage other Data Processors only with the Company's prior consent and only where such Data Processors assume the same level of Data security obligations as the original service provider (Data Processor).

9.

DISCLOSURE OF DATA

9.1

Where there is a legal basis for doing so, the Company provides Data to its recipients – Third Parties and Data Processors.

9.2

Personal Data is provided to Data Processors in accordance with the terms set out in the personal data processing agreements concluded with them.

9.3

Where the Company provides Data to Third Parties, this is done only after assessing the purposes of the Personal Data Processing, the legal grounds for provision and receipt, the terms and procedure, and the scope of the Personal Data to be provided.

9.4

The Company may transfer personal data to other companies within the Company's group, provided that the requirements set out in the Regulation, the Law and other legislation governing the protection and processing of personal data are complied with.

9.5

The Company ensures that Personal Data is not disclosed to unauthorised Third Parties, including family members, friends, or state institutions or bodies. All Employees must exercise particular caution before disclosing any Personal Data to a Third Party.

9.6

Where questions arise regarding the lawfulness of disclosing Data, Employees must consult the Responsible Employee.

10.

DATA PROTECTION BY DESIGN AND BY DEFAULT

10.1

Both when determining the means of Data Processing and at the time of the Data Processing itself, the Company implements appropriate technical and organisational measures designed to ensure compliance with the Data protection principles.

10.2

The Company implements these technical and organisational measures having regard to the state of the art, the cost of implementation, and the nature, scope, context and purposes of the Data Processing, as well as the risks of varying likelihood and severity that the Data Processing poses to the rights and freedoms of natural persons.

10.3

Data protection by design means that every new application or system that uses Personal Data must be designed with the protection of such Data in mind. Privacy must be taken into account throughout the entire lifecycle of the application or system.

10.4

In order to implement the principle of data protection by design, the following aspects are assessed in each specific case:

  • limitation of the amount of Data;
  • control options;
  • transparency;
  • the implementation of user-friendly systems;
  • ensuring the confidentiality and quality of Data;
  • pseudonymisation;
  • ensuring anonymity;
  • ensuring the ability to improve existing and implement new security measures;
  • appropriate training and information of Employees;
  • the carrying out of internal audits and reviews of the Rules;
  • restriction of the use of Data.

10.5

Data protection by default requires that the strictest privacy settings be applied to a given application or system as soon as that application or system becomes accessible to Data Subjects.

10.6

In order to implement the principle of data protection by default, the following is taken into account in each specific case:

  • by default, only Data that is necessary for the specific Data Processing purpose is processed;
  • technological measures must be designed in a way that avoids unnecessary Data Processing;
  • default settings must favour Data protection (the highest level of privacy is assumed);
  • functions that are not necessary must be configurable.

10.7

These measures are aimed at effectively implementing Data protection principles, such as the principle of data minimisation, and at integrating the necessary security measures into Data Processing so that it complies with the requirements of the Regulation and ensures the rights of Data Subjects.

10.8

The objectives described in this Part are also pursued when carrying out a data protection impact assessment.

11.

DATA STORAGE AND DESTRUCTION

11.1

The Company will not store Data in a form that permits identification of Data Subjects for longer than is necessary for the purposes for which such Data is processed.

11.2

The Company may store Data for longer periods where it is processed solely for archiving purposes in the public interest, for scientific or historical research purposes, or for statistical purposes, and where appropriate technical and organisational measures are applied to protect the rights and freedoms of Data Subjects.

11.3

The retention period for each category of Data, or the criteria for determining it, are set out in the records of Data Processing activities.

11.4

Any destruction of Data will be carried out in accordance with good practice for the secure destruction of Data (that is, in a manner that properly ensures Data security).

11.5

Personal Data stored in electronic form is destroyed by deleting it in a manner that prevents its recovery.

11.6

Paper documents containing Personal Data are shredded, and the resulting waste is safely disposed of.

12.

TRANSFER OF DATA TO THIRD COUNTRIES

12.1

Personal Data may be transferred to a third country (that is, a country outside the European Economic Area) or to an international organisation where its legal framework has been recognised by the European Commission as ensuring an adequate level of protection of Personal Data (an adequacy decision).

12.2

Personal Data may also be transferred to third countries or international organisations where one or more of the following appropriate safeguards have been applied:

  • binding corporate rules;
  • standard contractual clauses for Data protection adopted by the European Commission;
  • standard contractual clauses for Data protection adopted by the Supervisory Authority and approved by the European Commission, or contractual clauses recognised by the Supervisory Authority;
  • an approved code of conduct governing international Data transfers;
  • certification, seals and/or marks that can be used to demonstrate that the Data Processor or Data Controller complies with the established Data protection measures.

12.3

The appropriate safeguards referred to above are set out in detail in the Regulation.

12.4

In the absence of an adequacy decision (clause 12.1) and appropriate safeguards (clause 12.2), the Company transfers Personal Data to a third country or international organisation only where one of the following conditions is met, and subject to the other restrictions set out in the Regulation:

  • the Data Subject has explicitly consented to the proposed transfer, after having been informed of the possible risks of such a transfer for the Data Subject due to the absence of an adequacy decision and appropriate safeguards;
  • the transfer is necessary for the performance of a contract between the Data Subject and the Data Controller, or for the implementation of pre-contractual measures taken at the Data Subject's request;
  • the transfer is necessary for the conclusion or performance of a contract concluded in the interests of the Data Subject between the Data Controller and another natural or legal person;
  • the transfer is necessary for the establishment, exercise or defence of legal claims.

13.

RECORDS OF DATA PROCESSING ACTIVITIES

13.1

Information about the Personal Data processed by the Company is set out in the records of Data Processing activities.

13.2

The Company's records of Data Processing activities, in its capacity as Data Controller, set out:

  • the name and contact details of the Data Controller;
  • the name, or the first and last name, and contact details of the Data Protection Officer (if appointed);
  • the business function (department) and/or the Employee or unit of the Company responsible for the Data Processing;
  • the legal basis for the Data Processing;
  • the purposes of the Data Processing;
  • the name and contact details of the joint Data Controller (where applicable);
  • the categories of Data Subjects;
  • the categories of Personal Data processed;
  • the categories of recipients of Personal Data (including recipients of Data in third countries and international organisations) to whom the Personal Data has been or will be disclosed;
  • where applicable, transfers of Data to a third country or an international organisation, identifying that third country or international organisation, and, in the case of transfers referred to in the second subparagraph of Article 49(1) of the Regulation, the documentation of appropriate safeguards;
  • the time limits for the Processing (retention) of Personal Data;
  • a general description of the security measures applied;
  • other necessary information.

13.3

Where the Company acts as a Data Processor for other Data Controllers, the Company's records of Data Processing activities, in its capacity as Data Processor, set out:

  • the name and contact details of the Data Processor;
  • the name, or the first and last name, and contact details of the Data Protection Officer (if appointed);
  • information about the Data Controller on whose behalf Personal Data is processed, and its representatives;
  • the categories of Personal Data processed on behalf of the Data Controller;
  • where applicable, transfers of Data to a third country or an international organisation, identifying that third country or international organisation, and, in the case of transfers referred to in the second subparagraph of Article 49(1) of the Regulation, the documentation of appropriate safeguards;
  • a general description of the security measures applied;
  • other necessary information.

13.4

The records of Data Processing activities are maintained in Excel format.

13.5

The records of Data Processing activities are maintained by the Responsible Employee, in coordination with the persons responsible for Data Processing carried out for specific purposes.

13.6

The information contained in the records of Data Processing activities is checked and updated whenever the Data Processing or the implemented Data security measures change, but no less frequently than once per calendar year. When updating the records of Data Processing activities, a new version is prepared and the update date is indicated.

13.7

When reviewing the records of Data Processing activities, the Responsible Employee takes into account the results of data protection impact assessments, Data protection and security audits, and other reviews carried out within the Company.

13.8

At the request of the Supervisory Authority, the records of Data Processing activities are provided to the Supervisory Authority.

13.9

The records of Data Processing activities are provided to the Supervisory Authority by the Responsible Employee.

14.

DATA PROTECTION IMPACT ASSESSMENT

14.1

The Company is aware of the risks associated with the processing of the relevant categories of Data.

14.2

The Company carries out assessments of the level of risk to natural persons associated with Data Processing. Data protection impact assessments may be carried out both in respect of Data Processing within the Company and in respect of Data Processing carried out by Data Processors on the Company's behalf.

14.3

The Company seeks to manage the risks identified during such risk assessments in order to reduce the likelihood of adverse consequences for natural persons.

14.4

Where, due to the type of Data Processing (in particular where new technologies are used) and having regard to the nature, scope, context and purposes of the Data Processing, there is a likelihood of a high risk to the rights and freedoms of Data Subjects, the Company will, before beginning the Processing, carry out a data protection impact assessment of the intended Data Processing operations. A single assessment may be carried out to address a set of similar Data Processing operations that present similarly high risks.

14.5

Where it becomes apparent that there are risks that could give rise to a high risk of harm, the Supervisory Authority is consulted before the Company begins such Data Processing operations.

14.6

The Company will take appropriate measures to reduce the level of risk associated with Data Processing to an acceptable level, having regard to the requirements of these Rules and of the Regulation.

14.7

The data protection impact assessment procedure is attached as an annex to these Rules.

15.

FINAL PROVISIONS

15.1

On the initiative of the Responsible Employee or other Employees of the Company, these Rules are reviewed and amended following significant organisational, systemic or other changes to Personal Data Processing and/or operations, or following changes to the requirements of legislation governing the protection of personal data, but no less frequently than once per calendar year.

15.2

These Rules take effect on the date of their approval and may only be revoked, amended and/or supplemented by order of the head of the Company. Amendments and/or supplements to the Rules take effect on the day following the date of their adoption.

15.3

The Company ensures that Employees are informed of amendments and/or supplements to the Rules in a timely manner.

15.4

All Employees must be familiarised with these Rules against signature.