Regulation on the Processing and Protection of Personal Data in Personal Data Databases Owned by the Seller
Content
- State Registration of the Personal Data Database
- General Terms and Scope of Application
- List of Personal Data Databases
- Purpose of Processing Personal Data
- Procedure for Processing Personal Data: Obtaining Consent, Notification of Rights, and Actions with Personal Data of the Data Subject
- Location of the Personal Data Database
- Conditions for Disclosure of Personal Data to Third Parties
- Protection of Personal Data: Protection Methods, Responsible Person, Employees Directly Involved in Processing and/or Having Access to Personal Data in the Course of Their Duties, Duration of Personal Data Storage
- Rights of the Data Subject
- Procedure for Handling Requests from the Data Subject
1. General Terms and Scope of Application
1.1 Definitions:
- Personal Data Database – a named set of organized personal data in electronic form and/or as personal data card files.
- Responsible Person – an individual responsible for organizing activities related to the protection of personal data during its processing according to the law.
- Owner of the Personal Data Database – an individual or legal entity authorized by law or with the consent of the data subject to process such data, determining the purpose of processing, the content of the data, and the procedures for its processing unless otherwise specified by law.
- State Register of Personal Data Databases – a unified state information system for collecting, accumulating, and processing information on registered personal data databases.
- Public Sources of Personal Data – directories, address books, registries, lists, catalogs, and other structured collections of open information containing personal data, published with the data subject’s knowledge. Social networks and online resources where data subjects post their personal data are not considered public sources unless explicitly intended for free distribution and use.
- Consent of the Data Subject – any documented, voluntary declaration of an individual regarding the permission to process their personal data in accordance with the specified purpose.
- Anonymization of Personal Data – removal of information allowing identification of an individual.
- Processing of Personal Data – any operation or set of operations performed in a data (automated) system and/or in personal data files, including collection, registration, storage, adaptation, modification, updating, use, dissemination, anonymization, or destruction of information about an individual.
- Personal Data – information or set of information about an identified or identifiable individual.
- Manager of the Personal Data Database – an individual or legal entity to whom the owner or law grants the right to process personal data. An individual tasked only with technical maintenance without access to the content is not considered a manager.
- Data Subject – an individual whose personal data is processed according to the law.
- Third Party – any person other than the data subject, the owner, or the manager, or a state authority authorized for data protection, to whom the personal data owner or manager transfers data as per the law.
- Special Categories of Data – personal data related to race, ethnicity, political, religious, or philosophical beliefs, union membership, as well as data concerning health or sexual life.
1.2. This Regulation is mandatory for the responsible person and employees of the seller who are directly involved in processing and/or have access to personal data due to their official duties.
2. List of Personal Data Databases
2.1. The seller owns the following personal data databases:
- Personal data database of contractors.
3. Purpose of Processing Personal Data
3.1. The purpose of processing personal data is to ensure the implementation of civil-legal relations, provide, receive, and perform calculations for purchased goods and services according to the Tax Code of Ukraine and the Law of Ukraine “On Accounting and Financial Reporting in Ukraine.”
4. Procedure for Processing Personal Data: Obtaining Consent, Notification of Rights, and Actions with Personal Data of the Data Subject
4.1. Consent of the data subject must be a voluntary expression of the individual’s will to permit the processing of their personal data according to the defined purpose.
4.2. Consent of the data subject may be given in the following forms:
- A paper document with identifying details that allow for identification of the document and the individual.
- An electronic document containing mandatory identifying details, ideally with the data subject’s electronic signature.
- A mark on the electronic page of a document or file processed in an information system based on documented software solutions.
4.3. Consent is given during the establishment of civil-legal relations under current legislation.
4.4. The data subject is informed about the inclusion of their personal data in the database, their rights under the Law of Ukraine “On Personal Data Protection,” the purpose of data collection, and the persons to whom their data is transmitted at the time of establishing civil-legal relations according to current legislation.
4.5. Processing of special categories of data (race, ethnicity, political, religious beliefs, union membership, health, or sexual life) is prohibited.
5. Location of the Personal Data Database
5.1. The personal data databases listed in Section 2 of this Regulation are located at the seller’s address.
6. Conditions for Disclosure of Personal Data to Third Parties
6.1. Access to personal data by third parties is determined by the consent conditions of the data subject or as required by law.
6.2. Access is not granted if the third party refuses to ensure compliance with the Law of Ukraine “On Personal Data Protection” or is unable to do so.
6.3. A subject of relations involving personal data submits a request for access (hereinafter referred to as “request”) to the personal data owner.
6.4. The request should include:
- Full name, place of residence (location), and identification document details of the individual submitting the request (for an individual applicant).
- Name, location of the legal entity submitting the request, position, full name of the person certifying the request, confirmation that the request aligns with the legal entity’s powers (for a legal entity applicant).
- Full name and other details that allow identification of the individual to whom the request pertains.
- Information about the personal data database related to the request, or information about the owner or manager of this database.
- List of personal data being requested.
- Purpose and/or legal grounds for the request.
6.5. The time frame for reviewing a request cannot exceed ten working days from the date of its receipt. During this period, the personal data owner notifies the requesting party whether the request will be fulfilled or whether the relevant personal data cannot be provided, citing the grounds specified in the relevant legal act. The request must be fulfilled within thirty calendar days from the date of its receipt unless otherwise stipulated by law.
6.6. Postponement of access to personal data for third parties is allowed if the necessary data cannot be provided within thirty calendar days from the date of receipt of the request. In this case, the total term for addressing the issues raised in the request cannot exceed forty-five calendar days.
6.7. Notification of the postponement is provided to the third party who submitted the request in writing, with an explanation of the procedure for appealing this decision.
6.8. The postponement notice must include:
- The full name of the official.
- The date of notification.
- The reason for the postponement.
- The time frame within which the request will be fulfilled.
6.9. Access to personal data may be denied if access is prohibited by law.
6.10. The denial notice must include:
- The full name of the official denying access.
- The date of the notification.
- The reason for denial.
6.11. The decision to postpone or deny access to personal data may be appealed in court.
7. Protection of Personal Data: Protection Methods, Responsible Person, Employees Directly Involved in Processing and/or Having Access to Personal Data, Duration of Personal Data Storage
7.1. The personal data owner is equipped with systemic and technical means, as well as communication tools, to prevent loss, theft, unauthorized destruction, distortion, falsification, and copying of information, complying with international and national standards.
7.2. The responsible person organizes activities related to the protection of personal data during processing as required by law. The responsible person is appointed by an order of the personal data owner.
The responsibilities of the responsible person concerning the organization of work related to the protection of personal data during processing are outlined in their job description.
7.3. The responsible person is obliged to:
- Be knowledgeable about Ukrainian legislation on personal data protection.
- Develop procedures for employee access to personal data following their professional or official duties.
- Ensure that the owner’s employees comply with Ukrainian legislation on personal data protection and the internal documents regulating the owner’s activities concerning the processing and protection of personal data in the databases.
- Develop procedures for internal control over compliance with Ukrainian legislation on personal data protection and internal documents regulating the owner’s activities concerning the processing and protection of personal data. These procedures should specify the frequency of such control.
- Report to the personal data owner on any violations by employees of Ukrainian legislation on personal data protection and internal documents regulating the owner’s activities concerning the processing and protection of personal data within one working day from discovering such violations.
- Ensure the storage of documents confirming that the data subject has consented to the processing of their personal data and has been notified of their rights.
7.4. The responsible person has the right to:
- Obtain necessary documents, including orders and other directives issued by the personal data owner related to personal data processing.
- Make copies of received documents, including copies of files, and records stored in local computer networks and standalone computer systems.
- Participate in discussions of responsibilities related to organizing work on personal data protection during processing.
- Submit proposals for improving activities and refining work methods, providing comments and solutions to eliminate identified deficiencies in personal data processing.
- Receive explanations on personal data processing issues.
- Sign and review documents within their competence.
7.5. Employees directly involved in processing and/or having access to personal data as part of their official duties must adhere to Ukrainian legislation on personal data protection and internal documents regarding personal data processing and protection in databases.
7.6. Employees with access to personal data, including those involved in processing, are required not to disclose in any way personal data entrusted to them or that has become known to them in connection with their professional or official duties. This obligation remains after their involvement with personal data ceases, except as required by law.
7.7. Persons with access to personal data who violate the requirements of the Law of Ukraine “On Personal Data Protection” are liable under Ukrainian law.
7.8. Personal data should not be stored longer than necessary for the purposes for which it is collected and must comply with the retention period set by the data subject’s consent to process such data.
8. Rights of the Data Subject
8.1. The data subject has the right to:
- Know the location of the personal data database containing their data, its purpose and name, the location, and/or residence (location) of the owner or manager of this database, or delegate the receipt of this information to authorized persons, except as provided by law.
- Receive information on the conditions of access to their personal data, including information on third parties to whom their data contained in the database is transferred.
- Access their personal data in the database.
- Receive a response on whether their personal data is stored in the relevant database within thirty calendar days of the request, except as provided by law, and receive the content of the stored data.
- Submit a reasoned request objecting to the processing of their personal data by state authorities and local governments when performing their powers as provided by law.
- Submit a reasoned request for modification or destruction of their personal data by any owner or manager of the database if the data is processed unlawfully or is inaccurate.
- Protect their personal data from unlawful processing and accidental loss, destruction, or damage due to intentional concealment, withholding, or untimely provision, and protect against the provision of false or defamatory information about the individual’s honor, dignity, and business reputation.
- Contact state authorities and local governments on matters of protecting their rights concerning personal data.
- Use legal remedies in the event of a violation of personal data protection laws.
9. Procedure for Handling Requests from the Data Subject
9.1. The data subject has the right to receive any information about themselves from any subject of relations associated with personal data without specifying the purpose of the request, except as provided by law.
9.2. The data subject’s access to their data is free of charge.
9.3. The data subject submits a request for access (hereinafter referred to as “request”) to the personal data owner.
The request must include:
- Full name, place of residence (location), and identification document details of the data subject.
- Other information enabling identification of the data subject.
- Information about the personal data database related to the request or information about the owner or manager of this database.
- List of personal data requested.
9.4. The period for considering a request cannot exceed ten working days from the date of receipt. During this time, the personal data owner informs the data subject whether the request will be granted or if the requested personal data is unavailable, providing the grounds specified in the relevant regulatory act.
9.5. The request must be fulfilled within thirty calendar days from the date of its receipt unless otherwise provided by law.
10. State Registration of the Personal Data Database
10.1. State registration of personal data databases is carried out in accordance with Article 9 of the Law of Ukraine “On Personal Data Protection.”