Regulations on the Processing and Protection of Personal Data in Personal Data Databases Owned by the Seller
Contents
- General concepts and scope of application
- List of personal data databases
- Purpose of personal data processing
- Procedure for processing personal data: obtaining consent, notification of rights, and actions regarding the subject’s personal data
- Location of the personal data database
- Conditions for disclosure of personal data to third parties
- Protection of personal data: protection methods, responsible person, employees directly involved in processing and/or having access to personal data due to their official duties, retention period of personal data
- Rights of the personal data subject
- Procedure for handling requests of the personal data subject
- State registration of personal data databases
1. General Concepts and Scope of Application
1.1. Definitions of Terms:
Personal data database — a named collection of organized personal data in electronic form and/or in the form of personal data files.
Responsible person — a designated person who organizes activities related to the protection of personal data during processing in accordance with the law.
Owner of the personal data database — an individual or legal entity granted the right by law or by consent of the personal data subject to process such data, who determines the purpose of processing personal data in the database, establishes the composition of such data and procedures for their processing unless otherwise provided by law.
State Register of Personal Data Databases — a unified state information system for collecting, storing, and processing information about registered personal data databases.
Publicly available sources of personal data — directories, address books, registers, lists, catalogs, and other systematized collections of open information containing personal data published with the knowledge of the personal data subject. Social networks and internet resources where personal data subjects leave their personal data are not considered publicly available sources, except where the subject explicitly states that the data is published for free distribution and use.
Consent of the personal data subject — any documented voluntary expression of will by an individual granting permission for the processing of their personal data according to the stated purpose of processing.
Depersonalization of personal data — removal of information that allows identification of an individual.
Processing of personal data — any action or set of actions carried out fully or partially in an information (automated) system and/or in personal data files related to collection, registration, accumulation, storage, adaptation, modification, renewal, use and dissemination (distribution, sale, transfer), depersonalization, destruction of information about an individual.
Personal data — information or a set of information about an individual who is identified or can be specifically identified.
Administrator of the personal data database — an individual or legal entity authorized by the owner of the database or by law to process such data. A person performing technical work with the database without access to the content of personal data is not considered an administrator.
Personal data subject — an individual whose personal data is processed in accordance with the law.
Third party — any person other than the personal data subject, the owner or administrator of the personal data database, and the authorized state body for personal data protection, to whom personal data is transferred in accordance with the law.
Special categories of data — personal data concerning racial or ethnic origin, political, religious or ideological beliefs, membership in political parties and trade unions, as well as data related to health or sexual life.
1.2.
These Regulations are mandatory for the responsible person and employees of the Seller who directly process and/or have access to personal data in connection with the performance of their official duties.
2. List of Personal Data Databases
2.1.
The Seller owns the following personal data databases:
- Database of counterparties’ personal data.
3. Purpose of Personal Data Processing
3.1.
The purpose of processing personal data in the system is to ensure the implementation of civil law relations, provision, receipt, and settlement of payments for purchased goods and services in accordance with the Tax Code of Ukraine and the Law of Ukraine “On Accounting and Financial Reporting in Ukraine”.
4. Procedure for Processing Personal Data
4.1.
Consent of the personal data subject must be a voluntary expression of will regarding permission to process their personal data according to the stated purpose of processing.
4.2.
Consent may be provided in the following forms:
- A paper document containing details enabling identification of the document and the individual;
- An electronic document containing mandatory details enabling identification of the document and the individual. The voluntary consent should preferably be certified by the electronic signature of the personal data subject;
- A mark on an electronic page of a document or in an electronic file processed in an information system based on documented software and technical solutions.
4.3.
Consent is provided during the establishment of civil law relations in accordance with applicable legislation.
4.4.
Notification of the personal data subject regarding inclusion of their data in the database, rights under the Law of Ukraine “On Personal Data Protection,” the purpose of data collection, and persons to whom the data is transferred is carried out during the establishment of civil law relations in accordance with applicable legislation.
4.5.
Processing of personal data concerning racial or ethnic origin, political, religious or ideological beliefs, membership in political parties and trade unions, as well as data related to health or sexual life (special categories of data) is prohibited.
5. Location of Personal Data Databases
5.1.
The personal data databases specified in Section 2 of these Regulations are located at the Seller’s address.
6. Conditions for Disclosure of Personal Data to Third Parties
6.1.
The procedure for access to personal data by third parties is determined by the consent conditions provided by the personal data subject or in accordance with legal requirements.
6.2.
Access is not granted if the third party refuses to undertake obligations ensuring compliance with the Law of Ukraine “On Personal Data Protection” or is unable to ensure such compliance.
6.3.
A subject of relations related to personal data submits a request for access to personal data to the owner of the database.
6.4.
The request must specify:
- Full name and residence details of the applicant;
- Details of the identity document;
- Information identifying the individual concerned;
- Information about the personal data database;
- List of requested personal data;
- Purpose and/or legal grounds for the request.
6.5.
The review period for a request shall not exceed ten working days from receipt. The request must be fulfilled within thirty calendar days unless otherwise provided by law.
6.6.
Postponement of access is allowed if the requested data cannot be provided within thirty calendar days. The total resolution period may not exceed forty-five calendar days.
6.7.
Notification of postponement is provided in writing with clarification of the appeal procedure.
6.8.
The postponement notice shall include:
- Name of the responsible official;
- Date of notification;
- Reason for postponement;
- Time period for fulfilling the request.
6.9.
Refusal of access is permitted if access is prohibited by law.
6.10.
The refusal notice shall include:
- Name of the responsible official;
- Date of notification;
- Reason for refusal.
6.11.
A decision to postpone or refuse access may be appealed in court.
7. Protection of Personal Data
7.1.
The owner of the personal data database is equipped with system and software-technical means and communication facilities preventing loss, theft, unauthorized destruction, distortion, forgery, and copying of information in compliance with international and national standards.
7.1.
The owner of the personal data database is equipped with system and software-technical means and communication facilities preventing loss, theft, unauthorized destruction, distortion, forgery, and copying of information in compliance with international and national standards.
7.2.
The responsible person organizes activities related to personal data protection during processing in accordance with the law and is appointed by order of the database owner.
7.3.
The responsible person is obliged to:
- Know Ukrainian legislation on personal data protection;
- Develop procedures for employee access to personal data;
- Ensure employees comply with personal data protection laws and internal regulations;
- Develop internal control procedures;
- Inform the database owner of violations within one working day;
- Ensure storage of documents confirming consent and notification of rights.
7.4.
The responsible person has the right to:
- Receive necessary documents and orders;
- Make copies of documents and files;
- Participate in discussions regarding data protection activities;
- Submit proposals for improvement;
- Receive explanations regarding data processing;
- Sign and approve documents within their competence.
-
7.5.
Employees processing or having access to personal data must comply with Ukrainian legislation and internal regulations.
7.6.
Employees with access to personal data must not disclose such data in any way, including after termination of employment, except as provided by law.
7.7.
Persons violating the Law of Ukraine “On Personal Data Protection” bear liability under Ukrainian law.
7.8.
Personal data shall not be stored longer than necessary for the purpose for which it is processed and in any case no longer than the retention period determined by the subject’s consent.
8. Rights of the Personal Data Subject
8.1.
The personal data subject has the right to:
- Know the location and purpose of the database containing their personal data;
- Receive information about conditions of access to personal data;
- Access their personal data;
- Receive confirmation whether their data is stored and obtain its content within thirty calendar days;
- Object to processing of personal data;
- Demand amendment or destruction of unlawful or inaccurate data;
- Protection from unlawful processing and accidental loss or destruction;
- Apply to state authorities and local self-government bodies regarding protection of rights;
- Use legal remedies in case of violation of personal data protection legislation.
-
9. Procedure for Handling Requests of the Personal Data Subject
9.1.
The personal data subject has the right to receive any information about themselves without stating the purpose of the request unless otherwise established by law.
9.2.
Access to personal data is free of charge.
9.3.
A request for access must contain:
- Full name and residence details;
- Identity document details;
- Information identifying the subject;
- Information about the database;
- List of requested personal data.
-
9.4.
The review period shall not exceed ten working days.
9.5.
The request shall be fulfilled within thirty calendar days unless otherwise provided by law.
-
10. State Registration of Personal Data Databases
10.1.
State registration of personal data databases is carried out in accordance with Article 9 of the Law of Ukraine “On Personal Data Protection”.