Regulation on the Processing and Protection of Personal Data in Personal Data Databases Owned by the Seller

Contents

  1. General concepts and scope of application
  2. List of personal data databases
  3. Purpose of personal data processing
  4. Procedure for personal data processing: obtaining consent, notification of rights, and actions involving personal data of the personal data subject
  5. Location of the personal data database
  6. Conditions for disclosure of personal data to third parties
  7. Personal data protection: protection methods, responsible person, employees who directly process and/or have access to personal data in connection with their official duties, and personal data storage period
  8. Rights of the personal data subject
  9. Procedure for handling requests from the personal data subject
  10. State registration of the personal data database

1. General concepts and scope of application

1.1. Definition of terms:

personal data database — a named set of organized personal data in electronic form and/or in the form of personal data card files;

responsible person — a designated person who organizes work related to the protection of personal data during its processing in accordance with the law;

owner of the personal data database — an individual or legal entity that, by law or with the consent of the personal data subject, has been granted the right to process such data, determines the purpose of personal data processing in this database, establishes the composition of such data and the procedures for its processing, unless otherwise provided by law;

State Register of Personal Data Databases — a unified state information system for collecting, accumulating, and processing information about registered personal data databases;

publicly available sources of personal data — directories, address books, registers, lists, catalogues, and other systematized collections of open information containing personal data published with the knowledge of the personal data subject;

consent of the personal data subject — any documented voluntary expression of will by an individual granting permission to process their personal data in accordance with the stated purpose of processing;

depersonalization of personal data — removal of information that makes it possible to identify a person;

processing of personal data — any action or set of actions performed fully or partially in an information system and/or in personal data card files, related to the collection, registration, accumulation, storage, adaptation, modification, updating, use and distribution, depersonalization, or destruction of information about an individual;

personal data — information or a set of information about an individual who is identified or can be specifically identified;

processor of the personal data database — an individual or legal entity authorized by the owner of the personal data database or by law to process such data;

personal data subject — an individual whose personal data is processed in accordance with the law;

third party — any person other than the personal data subject, the owner or processor of the personal data database, and the authorized state body for personal data protection;

special categories of data — personal data concerning racial or ethnic origin, political, religious or philosophical beliefs, membership in political parties and trade unions, as well as data concerning health or sex life.

1.2. This Regulation is mandatory for the responsible person and the Seller’s employees who directly process and/or have access to personal data in connection with the performance of their official duties.

2. List of personal data databases

2.1. The Seller owns the following personal data databases:

  • database of contractors’ personal data.

3. Purpose of personal data processing

3.1. The purpose of personal data processing in the system is to ensure the implementation of civil law relations, provision, receipt, and settlement for purchased goods and services in accordance with the Tax Code of Ukraine and the Law of Ukraine «On Accounting and Financial Reporting in Ukraine».

4. Procedure for personal data processing

4.1. The consent of the personal data subject must be a voluntary expression of will by an individual to grant permission for the processing of their personal data in accordance with the stated purpose of such processing.

4.2. Consent of the personal data subject may be provided in the following forms:

  • a paper document with details that make it possible to identify the document and the individual;
  • an electronic document containing mandatory details that make it possible to identify the document and the individual;
  • a mark on an electronic document page or in an electronic file processed in an information system.

4.3. Consent of the personal data subject is provided during the establishment of civil law relations in accordance with current legislation.

4.4. Notification of the personal data subject about the inclusion of their personal data in the personal data database, the rights defined by the Law of Ukraine «On Personal Data Protection», the purpose of data collection, and the persons to whom their personal data is transferred is carried out during the establishment of civil law relations in accordance with current legislation.

4.5. Processing of personal data concerning racial or ethnic origin, political, religious or philosophical beliefs, membership in political parties and trade unions, as well as data concerning health or sex life, is prohibited.

5. Location of the personal data database

5.1. The personal data databases specified in Section 2 of this Regulation are located at the Seller’s address.

6. Conditions for disclosure of personal data to third parties

6.1. The procedure for third-party access to personal data is determined by the terms of the consent of the personal data subject provided to the personal data owner for processing such data, or in accordance with legal requirements.

6.2. Access to personal data is not provided to a third party if such person refuses to undertake obligations to ensure compliance with the requirements of the Law of Ukraine «On Personal Data Protection» or is unable to ensure such compliance.

6.3. A subject of relations connected with personal data submits a request for access to personal data to the personal data owner.

6.4. The request shall indicate:

  • surname, first name and patronymic, place of residence, and details of the identity document of the person submitting the request;
  • name and location of the legal entity submitting the request;
  • information that makes it possible to identify the individual in respect of whom the request is made;
  • information about the personal data database;
  • list of personal data requested;
  • purpose and/or legal grounds for the request.

6.5. The period for reviewing the request may not exceed ten business days from the date of its receipt. The request is satisfied within thirty calendar days from the date of its receipt, unless otherwise provided by law.

6.6. Deferral of access to personal data of third parties is allowed if the required data cannot be provided within thirty calendar days. The total period for resolving the matters raised in the request may not exceed forty-five calendar days.

6.7. Notice of deferral shall be provided to the third party who submitted the request in written form with an explanation of the appeal procedure.

6.8. The notice of deferral shall indicate:

  • surname, first name and patronymic of the official;
  • date of sending the notice;
  • reason for deferral;
  • period within which the request will be satisfied.

6.9. Refusal of access to personal data is permitted if access is prohibited by law.

6.10. The notice of refusal shall indicate:

  • surname, first name and patronymic of the official refusing access;
  • date of sending the notice;
  • reason for refusal.

6.11. A decision to defer or refuse access to personal data may be appealed in court.

7. Personal data protection

7.1. The owner of the personal data database is equipped with system, software, technical, and communication tools that prevent loss, theft, unauthorized destruction, distortion, falsification, and copying of information and comply with international and national standards.

7.2. The responsible person organizes work related to personal data protection during its processing in accordance with the law.

7.3. The responsible person is obliged to:

  • know the legislation of Ukraine in the field of personal data protection;
  • develop procedures for employee access to personal data;
  • ensure that employees comply with Ukrainian legislation requirements;
  • develop internal control procedures;
  • report violations no later than one business day from the moment they are detected;
  • ensure storage of documents confirming the consent of the personal data subject.

7.4. For the purpose of performing their duties, the responsible person has the right to:

  • receive necessary documents;
  • make copies of received documents;
  • participate in discussions regarding their duties;
  • submit proposals for improving activities;
  • receive explanations regarding personal data processing;
  • sign and endorse documents within their competence.

7.5. Employees who directly process and/or have access to personal data must comply with the requirements of Ukrainian legislation.

7.6. Employees who have access to personal data must not disclose personal data in any way.

7.7. Persons who have access to personal data and violate the requirements of the Law of Ukraine «On Personal Data Protection» shall be liable in accordance with Ukrainian legislation.

7.8. Personal data must not be stored longer than necessary for the purpose for which such data is stored.

8. Rights of the personal data subject

8.1. The personal data subject has the right to:

  • know the location of the personal data database;
  • receive information about the conditions for accessing personal data;
  • access their personal data;
  • receive a response as to whether their personal data is stored;
  • submit a reasoned objection to the processing of their personal data;
  • submit a request to change or destroy their personal data;
  • protect their personal data from unlawful processing;
  • apply to the relevant authorities regarding the protection of their rights;
  • use legal remedies in case of violation of personal data protection legislation.

9. Procedure for handling requests from the personal data subject

9.1. The personal data subject has the right to receive any information about themselves without stating the purpose of the request, except in cases established by law.

9.2. Access of the personal data subject to data about themselves is free of charge.

9.3. The personal data subject submits a request for access to personal data to the owner of the personal data database.

The request shall indicate:

  • surname, first name and patronymic, place of residence, and identity document details;
  • other information that makes it possible to identify the person;
  • information about the personal data database;
  • list of personal data requested.

9.4. The period for reviewing the request may not exceed ten business days from the date of its receipt.

9.5. The request is satisfied within thirty calendar days from the date of its receipt, unless otherwise provided by law.

10. State registration of the personal data database

10.1. State registration of personal data databases is carried out in accordance with Article 9 of the Law of Ukraine «On Personal Data Protection».