Regulations on the processing and protection of personal data in personal data bases owned by the seller

 

Content

General concepts and scope
List of personal data bases
Purpose of personal data processing
Procedure for processing personal data: obtaining consent, notification of rights and actions with personal data of the subject of personal data
The location of the personal database
Terms of disclosure of information about personal data to third parties
Protection of personal data: methods of protection, responsible person, employees who directly process and/or have access to personal data in connection with the performance of their official duties, term of personal data storage
Rights of the subject of personal data
Procedure for handling requests of the subject of personal data
State registration of the personal data base


1. General concepts and scope

1.1. Definition of terms:

personal data base - a named set of ordered personal data in electronic form and/or in the form of personal data files;

responsible person - a designated person who organizes work related to the protection of personal data during their processing, in accordance with the law;

the owner of a personal data base is a natural or legal person who is granted the right to process this data by law or with the consent of the subject of personal data, who approves the purpose of processing personal data in this database, establishes the composition of this data and the procedures for its processing, unless otherwise determined by law;

The State Register of Personal Data Bases is a unified state information system for collecting, accumulating and processing information on registered personal data bases;

publicly available sources of personal data - directories, address books, registers, lists, catalogs, other systematic collections of open information, which contain personal data, placed and published by a known subject of personal data. Social networks and Internet resources in which the subject of personal data leaves their personal data are not considered publicly available sources of personal data (unless the subject of personal data expressly states that the personal data is posted for the purpose of their free distribution and use);

consent of the subject of personal data - any documented, voluntary expression of will of a natural person regarding the granting of permission for the processing of his personal data in accordance with the formulated purpose of their processing;

depersonalization of personal data - removal of personally identifiable information;

processing of personal data - any action or set of actions performed in whole or in part in an information (automated) system and/or in personal data files, which are related to the collection, registration, accumulation, storage, adaptation, change, renewal, use and dissemination (distribution, implementation, transfer), depersonalization, destruction of information about a natural person;

personal data - information or a set of information about a natural person who is identified or can be specifically identified;

the controller of the personal data base is a natural or legal person who is authorized by the owner of the personal data base or by law to process this data. A person who is instructed by the owner and/or manager of the personal database to carry out technical work with the personal database without access to the content of personal data is not a personal database administrator;

subject of personal data - a natural person, in relation to whom, in accordance with the law, his or her personal data is processed;

third party - any person, with the exception of the subject of personal data, the owner or manager of the personal data base and the authorized state body for personal data protection issues, to whom the owner or manager of the personal data base transfers personal data in accordance with the law;

special categories of data - personal data about racial or ethnic origin, political, religious or ideological beliefs, membership in political parties and trade unions, as well as data related to health or sex life.

1.2. This Regulation is mandatory for the responsible person and the seller's employees who directly process and/or have access to personal data in connection with the performance of their official duties.

 

2. List of personal data bases

2.1. The seller is the owner of the following personal data bases:

database of personal data of counterparties.


3. Purpose of personal data processing

3.1. The purpose of processing personal data in the system is to ensure the implementation of civil legal relations, providing, receiving and making payments for purchased goods and services in accordance with the Tax Code of Ukraine, the Law of Ukraine "On Accounting and Financial Reporting in Ukraine".

 

4. The procedure for processing personal data: obtaining consent, notification of rights and actions with personal data of the subject of personal data