DATA PROTECTION POLICY
Document ID: ZOP 1.0
Version: 1
Publication Date: 01. 07. 2023.
Next Revision Date: if necessary
Document Owner: Data Protection Officer of the Organization
ETERNIUM d.o.o., Ružići 25/i, 51213 Jurdani
INTRODUCTION
The organization ETERNIUM d.o.o. respects the privacy of its users, business partners, clients, and associates, and bases its operations on mutual trust and transparency. An important factor in building trust is the protection of personal data. One of the best practices for personal data protection is defined by the Regulation (EU) 2016/679 of the European Parliament and Council of 27.4.2016 (hereinafter referred to as the Regulation). The Regulation defines the rights of individuals, i.e., data owners, and accordingly the obligations of the Organization ETERNIUM d.o.o. as the data controller and as the data processor.
The Personal Data Protection Regulation from 2016 (hereinafter referred to as the Regulation) replaces the Directive on Personal Data Protection 95/46/EC from 1995 and substitutes the laws of individual member states created in accordance with the aforementioned Directive. The main purpose of adopting the Regulation is to protect the rights and freedoms of natural persons and to limit the processing of personal data of individuals without their knowledge. It describes the ways in which organizations, including the Organization ETERNIUM d.o.o., must collect, process, and store personal data. The rules defined by the Regulation must be applied regardless of whether the data is collected and stored in electronic form, on paper, or on other media. To comply with the Law, the Organization ETERNIUM d.o.o. must collect and use data fairly, securely store it, and ensure that it is not unlawfully disclosed.
The Regulation applies to all partially or fully automated processes of personal data processing, as well as to the processing of other personal data (e.g., in paper form) that are an integral part of the organization.
Territorially, the Regulation applies to all data controllers and processors established in the European Union (EU) who process personal data for the needs of the controller and/or processor. In addition, the Regulation also applies to all data controllers outside the EU whose processing of personal data enables the offering of goods and services and/or monitoring the behavior of personal data owners within the EU.
This Policy regulates the principles and rules that the Organization ETERNIUM d.o.o. and all associates, contractual partners, and other natural and legal persons working on behalf of the Organization ETERNIUM d.o.o. must adhere to when collecting, processing, and storing all categories of personal data, in order to meet the high standards aligned with existing legal provisions.
Reasons for the Existence of this Policy
- Compliance with the standards defined by this Policy ensures the alignment of the collection, processing, and storage of personal data with applicable
- Law and Regulation
- The rights of employees, service users, and other partners of the Organization ETERNIUM d.o.o. are protected
- The methods of storage, processing, and safeguarding of individuals' data are transparently defined
- The Policy protects against the risk of unlawful distribution of entrusted data
Key Terms
Headquarters – The main headquarters of the data controller in the EU is the place where the data controller makes key decisions regarding the purpose and means of processing personal data. The main headquarters of the data processor in the EU is its administrative headquarters. If the data controller is registered outside the EU, they must appoint a representative within the EU. Their powers and responsibilities must allow them to act on behalf of the data controller, including all types of communication with supervisory authorities.
Personal data – All data relating to an identified or identifiable individual (data subject); an identifiable individual is a person who can be identified directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or by reference to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that individual.
Special category of personal data – Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a person's sex life or sexual orientation.
Data controller – A natural or legal person, public authority, agency, or other body that alone or jointly with others determines the purposes and means of processing personal data. If the purposes and means of processing are determined by EU law or the law of a member state, the criteria for appointing a data controller may be specifically defined by EU law or specific member state law.
Data processor – A natural or legal person, public authority, agency, or other body that processes personal data on behalf of the data controller.
Data owner – Any living individual whose data is subject to some form of processing by an organization.
Processing – Any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment, combination, restriction, erasure, or destruction.
Profiling – Any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to an individual, in particular to analyze or predict aspects concerning work performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements of that individual.
Personal data breach – A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed.
Consent – In the context of the Regulation and this Policy, Consent represents any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them or personal data of individuals they represent.
Child – The Regulation defines a Child as any person under the age of 16. Depending on the laws of individual member states, the age limit that ensures the status of a child may be at least 16 years. Processing of a child's personal data is only permitted if parental or guardian consent is obtained. The data controller must make reasonable efforts to verify that consent is given by the holder of parental responsibility over the child.
Third party – A natural or legal person, public authority, agency, or other body that is not the data subject, the data controller, the data processor, or persons authorized to process personal data under the direct authority of the data controller or the data processor.
Storage system – Any structured set of personal data which is accessible according to specific criteria, whether centralized, decentralized, or dispersed on a functional or geographical basis.
Risks
This Policy helps protect against real security risks related to the protection of personal data, including
a. Confidentiality breach (data is processed inappropriately)
b. Inability to choose the method of data processing (all individuals should be free to choose how the organization ETERNIUM d.o.o. uses data related to them)
c. Reputation damage to the company (loss of reputation in the event of a successful hacking attack)
POLICY STATEMENT
Scope of the policy
The rules described in this Policy apply to
- The organization ETERNIUM d.o.o.
- All employees of the organization ETERNIUM d.o.o.
- All associates, clients, contractual partners, and other natural and legal persons acting on behalf of the organization ETERNIUM d.o.o.
The rules apply to all data that the organization ETERNIUM d.o.o. possesses regarding identifiable individuals. This may include:
- Names of individuals
- Addresses
- Email addresses
- Phone numbers
- Salary information
- Information about the number of children
- Information about the number of dependents and all other data related to the individual
Statement
Organization ETERNIUM d.o.o., Ružići 25/i, 51213 Jurdani, all employees of Organization ETERNIUM d.o.o. and individuals and legal entities working for and on behalf of Organization ETERNIUM d.o.o., commit to comply with all relevant EU laws and the laws of member states relating to personal data and the rights and freedoms of individuals arising from the aforementioned laws, whose information is collected and processed in accordance with the General Data Protection Regulation.
Compliance with the Regulation is described in this Policy, other relevant policies, and related procedures and processes.
The Regulation and this Policy apply to all activities involving the processing of personal data including data about users of goods and services, clients, employees, suppliers, and other partners, as well as all other personal data that Organization ETERNIUM d.o.o. processes from any source.
Organization ETERNIUM d.o.o. has defined standards that describe the level of protection of an individual's privacy and their personal data, which are in line with the EU Regulation on the protection of personal data.
The Data Protection Officer is responsible for the annual audit of the personal data processing records in the context of any changes in the activities of Organization ETERNIUM d.o.o. and all additional requirements established by the data protection impact assessment. This record and the data protection impact assessment must be available upon request from the supervisory authority.
The rules described in this Policy apply to all employees of Organization ETERNIUM d.o.o. and third parties, individuals or legal entities working for or on behalf of Organization ETERNIUM d.o.o. such as external collaborators, contractual partners, etc. Any violation of the Regulation or the rules described in this Policy will be resolved in accordance with the disciplinary policy of Organization ETERNIUM d.o.o. and may constitute a criminal offense that will be reported to the relevant authorities. The disciplinary policy of the organization in the event of a violation of the Regulation and/or the rules described in this policy includes extraordinary termination of employment in the case that the violation is committed by an employee of Organization ETERNIUM d.o.o., or termination of business cooperation in the case that the violation is committed by individuals or legal entities working for or on behalf of Organization ETERNIUM d.o.o. such as external collaborators, contractual partners, etc. Likewise, any potential financial penalties arising from violations of the Regulations, which are a direct consequence of irresponsible behavior by employees of Organization ETERNIUM d.o.o. or their external collaborators, contractual partners, etc., must be compensated to Organization ETERNIUM d.o.o.
It is expected that a partner or any third party working on behalf of, at the request of, or for Organization ETERNIUM d.o.o. and who may have access to personal data, reads, understands, and complies with the rules described in this Policy. No third party may access personal data processed by Organization ETERNIUM d.o.o. without a previously concluded confidentiality agreement that defines the obligations of third parties, in accordance with the obligations undertaken and to which Organization ETERNIUM d.o.o. is committed regarding the protection of personal data. The confidentiality agreement grants responsible persons of Organization ETERNIUM d.o.o. the right to conduct an audit of compliance with the confidentiality agreement.
Organization ETERNIUM d.o.o. in the role of processor, will process data at the request of the data controller or client solely in accordance with the rules defined by the Regulation, the law of the respective member state, and this Policy. Organization ETERNIUM d.o.o. will enable each data controller on whose behalf it processes personal data, an audit of compliance with the confidentiality agreement.
RESPONSIBILITIES AND ROLES IN ACCORDANCE WITH THE REGULATION
Data Controller and Processor
The main activity of the organization ETERNIUM d.o.o. is mediation in real estate business, and the mediation services are provided to contractual clients (principals). By concluding a mediation agreement, the organization ETERNIUM d.o.o. takes on the role of data processor. By assuming the role of data processor, the organization ETERNIUM d.o.o. takes on all obligations and responsibilities of the data processor towards the principal (data controller), as defined by the General Data Protection Regulation, the law of the member state, and the obligations defined by this Policy, and commits to carry out any processing related to the principal's business exclusively at their request, as defined in the business cooperation agreement.
In addition to the role of data processor, the organization ETERNIUM d.o.o. is also the data controller as defined by the Regulation. The management and other persons assigned a managerial or supervisory function in the organization ETERNIUM d.o.o. are responsible for developing and promoting good information management practices within the organization ETERNIUM d.o.o.
Data Protection Officer
To further strengthen the security of personal data it processes, the organization ETERNIUM d.o.o. has appointed a data protection officer in accordance with the requirements defined by the Regulation.
The job description of the Data Protection Officer is defined in a document titled Obligations of the Data Protection Officer, while the responsibilities are defined in a separate document titled Responsibilities of the organization ETERNIUM d.o.o. related to the protection of personal data. The Data Protection Officer should be accountable to the management of the organization ETERNIUM d.o.o. for ensuring compliance with legal regulations on the protection of personal data.
The Data Protection Officer, whom the management of the organization ETERNIUM d.o.o. considers suitably qualified, is appointed to take responsibility for the daily compliance of the organization ETERNIUM d.o.o. with this Policy, particularly with the Regulation, in the segment of personal data processing carried out within the organization ETERNIUM d.o.o..
The Data Protection Officer has specific responsibilities related to certain procedures such as the Procedure for Data Subject Requests for Access to Personal Data. They are also obliged to provide all relevant information and answers to questions from employees of the organization ETERNIUM d.o.o. related to this Policy and the Regulation.
Compliance with personal data protection laws is the responsibility of all employees of the organization ETERNIUM d.o.o. and of individuals and legal entities working for and on behalf of the organization ETERNIUM d.o.o., who process personal data.
Employees of the organization ETERNIUM d.o.o. are responsible for ensuring accurate and up-to-date information about themselves and are obliged to report any changes so that employee data remains accurate and up-to-date.
DATA PROTECTION PRINCIPLES OF ETERNIUM d.o.o.
Any processing of personal data must be carried out in accordance with the data protection principles at least as stated in Article 5 of the Regulation. The rules and procedures that define the processing of personal data in the organization ETERNIUM d.o.o. have been created to ensure compliance with the principles of the Regulation and this Policy.
The organization ETERNIUM d.o.o. as the data processor
The organization ETERNIUM d.o.o. in accordance with the contractual obligations assumed with the client, takes on the role of data processor. The data processor and any person acting under the authority of the data processor who has access to personal data shall not process such data unless requested by the client, unless required by Union law or the law of a member state. By entering into the contract, the organization ETERNIUM d.o.o. has assumed obligations as a data processor, as follows:
1.1.1. The organization ETERNIUM d.o.o. guarantees through this policy and other related policies the implementation of appropriate technical and organizational measures in such a way that the processing of entrusted data is in accordance with the requirements of the Regulation and ensures the protection of the rights of data subjects.
1.1.2. The organization ETERNIUM d.o.o. shall not engage another data processor without prior specific or general written consent from the client. In the case of general written consent, the organization ETERNIUM d.o.o. will inform the client of all planned changes regarding the addition or replacement of other data processors to enable the client to raise objections to such changes.
1.1.3. The processing carried out by the organization ETERNIUM d.o.o. is governed by a contract or other legal act in accordance with Union law or the law of a member state. By the contract or other legal act, the organization ETERNIUM d.o.o. commits to the client, specifying the subject and duration of processing, the nature and purpose of processing, the type of personal data and category of data subjects, as well as the obligations and rights of the client. This contract or other legal act particularly stipulates that the organization ETERNIUM d.o.o.:
processes personal data only according to the recorded instructions of the client, including with regard to transfers of personal data to a third country or an international organization, unless required by Union law or the law of the member state to which the data processor is subject; in that case, the organization ETERNIUM d.o.o. will inform the client of that legal requirement prior to processing, unless such notification is prohibited by law for important reasons of public interest;
ensures that persons authorized to process personal data have committed to confidentiality or are subject to legal obligations of confidentiality;
takes all necessary measures in accordance with Article 32 of the Regulation;
respects the conditions set out in paragraphs 2 and 4 of Article 28 of the Regulation for engaging another data processor;
taking into account the nature of the processing, the organization ETERNIUM d.o.o. will assist the client through appropriate technical and organizational measures, as far as possible, to fulfill the client's obligation to respond to requests for the exercise of the rights of data subjects established in Chapter III of the Regulation;
assists the client in ensuring compliance with obligations under Articles 32 to 36 of the Regulation, taking into account the nature of the processing and the information available to the organization ETERNIUM d.o.o.;
at the choice of the controller, deletes or returns to the client all personal data after the completion of the services related to processing and deletes existing copies unless there is an obligation to retain personal data under Union law or the law of the member state;
makes available to the client all information necessary to demonstrate compliance with the obligations set out in Article 28 of the Regulation and which enable audits, including inspections, carried out by the client or another auditor authorized by the client, and contributes to them;
with regard to the previous points, the organization ETERNIUM d.o.o. shall immediately inform the client if, in its opinion, a particular instruction violates the Regulation or other provisions of Union or member state data protection law.
1.1.4. If the organization ETERNIUM d.o.o. engages another data processor to carry out specific processing activities on behalf of the client, the same data protection obligations as those specified in the contract or other legal act between the organization ETERNIUM d.o.o. and the client from the previous point, shall be imposed on that other data processor by contract or other legal act in accordance with Union law or the law of a member state, particularly the obligation to provide sufficient guarantees for the implementation of appropriate technical and organizational measures in such a way that the processing meets the requirements of the Regulation. If that other data processor fails to fulfill data protection obligations, the organization ETERNIUM d.o.o. remains fully responsible to the client for the fulfillment of the obligations of that other data processor.
1.1.5. The contract or other legal act referred to in points 3 and 4 of this paragraph must be in written form, including electronic form.
1.1.6. The organization ETERNIUM d.o.o. and the representative of the organization ETERNIUM d.o.o. maintain a record of all categories of processing activities carried out for the data controller, which includes:
the name and contact details of one or more data processors and each data controller on behalf of which the data processor acts and, if applicable, the representative of the data controller or data processor and the data protection officer;
the categories of processing carried out on behalf of each data controller;
if applicable, the transfer of personal data to a third country or international organization, including identifying that third country or international organization and, in the case of transfers under Article 49(1)(h), documentation of appropriate safeguards; if possible, a general description of the technical and organizational security measures referred to in Article 32(1).
1.1.7. The organization ETERNIUM d.o.o. shall not review and determine the lawfulness of the processing of personal data required by the client or any other data controller. It shall not restrict such processing, but shall inform the client or another data controller at whose request it acts of any observed irregularities. Nevertheless, if the organization ETERNIUM d.o.o. assesses that the requested processing could in any way negatively affect its integrity and publicity and, ultimately, the financial stability of the organization ETERNIUM d.o.o., it will oppose the requested processing. It will inform the client or another data controller of any possible negative consequences for the organization and for the client or another data controller.
ETERNIUM d.o.o. as the data controller
Personal data may only be collected when the purpose of collection is specific, explicit, and legitimate.
Data obtained for a specific purpose must not be used for any other purpose. The privacy protection procedure of ETERNIUM d.o.o. is described in the Privacy Procedures document.
Personal data must be:
processed lawfully, fairly, and transparently in relation to the data subject ("lawfulness, fairness, and transparency");
collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes; further processing for archiving purposes in the public interest, for scientific or historical research, or for statistical purposes, in accordance with Article 89, paragraph 1, is not considered incompatible with the original purposes ("purpose limitation");
adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed ("data minimization");
accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that is inaccurate, considering the purposes for which it is processed, is erased or rectified without delay ("accuracy");
Processing under applicable law implies identifying the legal basis before processing the personal data itself. Processing is lawful only if and to the extent that at least one of the following applies:
the data subject has given consent to the processing of their personal data for one or more specific purposes;
processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract;
processing is necessary for compliance with a legal obligation to which the data controller is subject;
processing is necessary to protect the vital interests of the data subject or another natural person;
processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller;
processing is necessary for the purposes of legitimate interests pursued by the data controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, especially if the data subject is a child.
Fair processing implies that the data controller has ensured the availability of all necessary information to the data subject. This particularly applies to situations where data is collected directly from the data subject.
Transparent processing implies providing all relevant information to the data subject as described in Articles 12, 13, and 14 of the Regulation. Information must be provided in a clear and understandable form, using clear and plain language.
All data processed by ETERNIUM d.o.o. is handled in accordance with the procedure described in the Privacy Procedures and Privacy Notice documents.
The minimum amount of information that must be provided to the data subject is as follows:
The identity and contact details of the data controller
Contact details of the Data Protection Officer
The purposes of processing for which personal data is used as well as the legal basis for processing
The period for which the personal data will be stored or, if that is not possible, the criteria used to determine that period
The existence of the data subject's rights to request access to personal data and rectification or erasure of personal data or restriction of processing concerning the data subject or the right to object to such processing and the right to data portability
The existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
The right to lodge a complaint with a supervisory authority
Information on whether the provision of personal data is a statutory or contractual requirement or a requirement necessary to enter into a contract and whether the data subject is obliged to provide personal data and the possible consequences of failing to provide such data.
Information on the existence of automated data processing, including profiling, and at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
Personal data must be adequate for the purpose, relevant, and limited in accordance with the necessary frameworks for processing.
According to defined obligations, the responsibility of the data protection officer is to ensure that the Organization ETERNIUM d.o.o. does not collect data that is not necessarily required to fulfill the purpose for which it was collected.
All forms for collecting personal data (electronic or paper) must include a statement on fair processing or a link to a privacy statement approved by the Data Protection Officer.
To ensure adequacy, relevance, and to avoid excessive data collection, the data protection officer annually reviews all methods of collecting personal data.
Personal data must be accurate and up to date, and inaccurate data must be deleted without delay.
Data stored by the data controller must be regularly updated. They must not be kept if they are not accurate and up to date.
The data protection officer must ensure training for employees of the Organization ETERNIUM d.o.o. so that they are properly trained and can understand the importance of collecting and storing only accurate data.
The responsibility of the data subject is to ensure accurate and up-to-date data for the Organization ETERNIUM d.o.o. If there is a formal record form for data collection, it will include a statement that the data provided in it is accurate as of the date of filling out the form.
Employees of the Organization ETERNIUM d.o.o. should notify responsible persons of any changes in circumstances to enable the updating of personal data. It is the responsibility of the Organization ETERNIUM d.o.o. to record any notifications of changes in circumstances that affect the accuracy and up-to-date record.
The responsibility of the Data Protection Officer is to ensure appropriate procedures and policies to ensure the accuracy and up-to-date nature of personal data, taking into account the volume of collected data, the speed at which the volume of data may change, and other relevant factors.
At least once a year, the Data Protection Officer will review the dates until which specific personal data may be stored. Data that no longer needs to be stored must be deleted, destroyed, or anonymized in accordance with the defined Procedure for secure disposal of data storage media.
The Data Protection Officer is responsible for responding to requests from Data Subjects within no longer than 30 days. The deadline may be extended for an additional two months for complex requests. If the responsible persons of the Organization ETERNIUM d.o.o. decide not to respond to the request of the data subject, the data protection officer must provide an explanation for the non-action to the data subject and inform them of their right to appeal to the supervisory authority and the possibility of seeking legal remedy.
Personal data must be stored in a form that can identify the data owner only as long as necessary to carry out the required processing, i.e., to achieve the purpose for which the personal data was collected.
When personal data is stored longer than the period necessary for its processing or after the purpose has been fulfilled, such data will be stored in a form that cannot easily be linked to the data owner.
Personal data is stored as described in the Procedure for storing personal data. After the expiration of the prescribed storage period for personal data, it must be properly destroyed as described in the aforementioned Procedure for storing personal data.
Any storage of personal data longer than that specified in the Procedure for storing personal data must be approved by the Data Protection Officer as described in the relevant procedure. In this case, the reason for such action must be clearly established and must not fall outside the framework of the applicable Personal Data Protection Act. Approval must be in written form.
Personal data must be processed securely. The Data Protection Officer will conduct a risk assessment procedure taking into account all circumstances that affect data processing and the security of data processing in the organization ETERNIUM d.o.o.
When determining the appropriateness of the processing of personal data, the Data Protection Officer must take into account the extent of potential harm that could affect individuals in the event of a security breach, as a result of any security lapse, along with the direct or indirect impact on the reputation of the organization and the trust of users, suppliers, and other stakeholders.
In assessing appropriate technical measures, the Data Protection Officer considers the following:
Password protection policy (described in the document Information Infrastructure Security Policy)
Automatic locking of equipment in idle mode
Limiting the use of USB and other media (described in the documents Information Infrastructure Security Policy, Access Policy and Data Access Rights, and Data Storage Media Management)
Installed antivirus protection and firewall (described in the document Information Infrastructure Security Policy)
Access rights based on roles, including those rights granted to temporary staff and visitors (described in the document Information Infrastructure Security Policy and Access Policy and Data Access Rights)
Encryption of devices leaving the organization's premises (laptops) (described in the document Information Infrastructure Security Policy)
Network system security (described in the document Information Infrastructure Security Policy)
Additional data protection options such as pseudonymization and anonymization where applicable
Enhancing security standards in line with technological development
RIGHTS OF THE DATA SUBJECT
Availability of information
The availability of information ensures that individuals become aware that their data is being processed and understand:
How the data is used
How they can exercise their rights
The data subject has the following rights regarding the processing of data related to them:
The data subject has the right to request access to the data being processed about them from the data controller
Object to the processing of personal data related to them and processing that may cause harm to the data subject.
Prevent the processing of personal data related to them that is processed for marketing purposes
Be informed about the methods and algorithms if it involves automated data processing
Seek compensation for damages through legal means if caused
Take actions that result in the correction, deletion, or destruction of inaccurate personal data or data for which consent for processing has been denied, where there is no other legal basis for processing
Request an assessment from the supervisory authority regarding a breach of any provisions of the Regulation
Request the transfer of data to other data controllers
Stop any automated profiling, if consent has not been given for it
For the purpose of exercising the rights of the data subject:
The data subject may request access to personal data in the manner described in the Procedure for Requests for Access to Personal Data. The procedure describes how the Organization ETERNIUM d.o.o. will ensure a response to the request of the data subject that meets the requirements of the Regulation.
The data subject has the right to appeal to the Organization ETERNIUM d.o.o. regarding the processing of their personal data and the management of the request to exercise their rights in accordance with the prescribed Procedure in the event of a complaint
CONSENT
The organization ETERNIUM d.o.o. considers that Consent represents any voluntarily given, specific, informative, and unequivocal statement by which the respondent, the owner of personal data, consents to the processing of their personal data or the personal data of individuals they represent. Consent can be withdrawn at any time in a roughly simple manner in which it was given.
For the organization ETERNIUM d.o.o., giving Consent means that the respondent is fully informed about the intended processing of personal data. Any Consent obtained under duress or based on a misconception is invalid and cannot serve as a basis for processing the respondent's personal data.
Obtaining Consent from the respondent requires active communication between both parties (data controller and respondent). By not responding to the posed inquiry from the respondent, Consent cannot be valid, i.e., consent cannot be assumed. The data controller must be able to demonstrate that consent for the processing of personal data has been obtained.
When it comes to special data, consent must be in written form, as described in the document titled Procedure for Obtaining Consent. If there is an alternative legitimate basis for processing personal data, giving consent is not mandatory or does not have to be given in written form.
In most cases, consent for the processing of personal and special data is part of standard forms, i.e., written documents that are an integral part of the documentation and which the respondent (user, business partner) signs in accordance with defined internal procedures.
The respondent has the right to withdraw consent for the processing of their personal data at any time. The procedure for withdrawing consent for the withdrawal of personal data is described in the document titled Procedure for Withdrawing Consent.
DATA SECURITY
All employees of ETERNIUM d.o.o. and other individuals working for and on behalf of ETERNIUM d.o.o. are responsible for the security of all personal data that ETERNIUM d.o.o. possesses and processes. They must keep the data in a secure location that does not allow the disclosure of personal data to third parties unless explicitly permitted to receive the data under a prior confidentiality agreement. In such cases, the third party agrees to the terms of this Policy and confirms that it meets the security conditions described in the General Regulation.
All personal data is accessible only to those individuals who need it to fulfill their business tasks, and access may only be granted in accordance with the Access Control Policy and the IT Infrastructure Security Policy. In terms of security, ETERNIUM d.o.o. treats personal data with the utmost care. For this reason, all personal data must be stored:
In a locked room with controlled access
In a locked drawer or cabinet
If it concerns digital data, it must be password-protected in accordance with the accepted IT Infrastructure Security Policy
Stored on computer media that is encrypted according to the described procedure called Data Storage Media Management.
Computer monitors must not be visible to third parties, except for authorized individuals from the organization. All employees are required to sign an Acceptable Use Agreement for equipment before being granted access to any type of information in the possession of the organization.
Written records must not be left in areas accessible to unauthorized persons and must not be removed from the secure area without explicit written approval. At the moment when written records are no longer needed for business tasks, they must be disposed of in accordance with prescribed procedures.
Personal data may only be deleted or moved in accordance with the accepted Record Retention Procedure. Written records that are retained until the retention date prescribed by the relevant policy must be destroyed or disposed of as confidential data. Hard drives of computers that are no longer in use must be destroyed as described in the Data Storage Media Management procedure.
Processing personal data outside of ETERNIUM d.o.o. represents a potentially greater risk of loss, theft, or destruction of personal data. Employees of ETERNIUM d.o.o. and other individuals working for and on behalf of ETERNIUM d.o.o. must obtain special authorization for such processing of personal data.
DATA DISCLOSURE
In certain circumstances, the Regulation allows for the disclosure of personal data to agencies and government bodies enforcing the law, without the consent of the data owner/subject. In such circumstances, ETERNIUM d.o.o. will disclose the requested data. However, the responsible person of the company will ensure that the request is legitimate by seeking assistance from legal advisors or supervisory bodies in the field of personal data protection before disclosing the data.
ETERNIUM d.o.o. must ensure that personal data is not disclosed to unauthorized third parties, including family members, friends, government bodies, and, in certain circumstances, the police. All employees must be familiar with the procedure to follow if they are asked to disclose personal data to a third party.
All requests for the provision of personal data must be accompanied by appropriate documentation, and any disclosure must be specifically approved by the Data Protection Officer.
DATA RETENTION AND DISPOSAL
The organization ETERNIUM d.o.o. must not retain personal data that can identify an individual longer than necessary for the purpose for which the data was collected.
The organization ETERNIUM d.o.o. may retain data for a longer period than the period prescribed by law or accepted policy if the data is processed for the purpose of public interest, scientific and historical research, or for statistical purposes. In such cases, it is essential to implement appropriate technical and organizational measures to protect the rights and freedoms of the data subjects.
The retention period for data from each separate category of personal data is defined by the Record Retention Procedure along with the criteria that determine the retention periods, including all legal obligations that the organization ETERNIUM d.o.o. must adhere to.
Personal data entrusted for processing to the organization ETERNIUM d.o.o. is processed appropriately to remain secure, thereby protecting the rights and freedoms of the data subjects. Any disposal of personal data is carried out in accordance with the accepted secure disposal procedure described in the Data Storage Media Management procedure.
DATA TRANSFER TO THIRD COUNTRIES
Any transfer of data from the European Economic Area to third countries is unlawful if there is no adequate level of protection for the fundamental rights of the data subjects.
The European Commission assesses third countries, territories, and/or specific sectors within third countries to determine whether there is an adequate level of protection for the rights and freedoms of individuals. In the case of transfers of personal data to countries that meet security criteria, no authorization from the supervisory authority is required for the transfer of personal data to those countries/territories.
A country that is a member of the European Economic Area, although not an EU country, meets the required conditions.
The organization ETERNIUM d.o.o. may adopt its own rules for the transfer of personal data to third countries. In that case, the rules must be reported to the competent supervisory authority, which will issue an opinion and either approve or reject the rules.
If none of the previously mentioned conditions are met, the transfer of data to third countries or international organizations can only be made under one of the following conditions:
The data subject has explicitly consented to the proposed transfer after being informed of the possible risks of such transfer.
The transfer is necessary for the fulfillment of contractual obligations between the data subject and the data controller/processor or for the implementation of pre-contractual measures taken at the request of the data subject.
The transfer is necessary for the conclusion or execution of a contract concluded in the interest of the data subject between the data controller/processor and another natural or legal person.
The transfer is necessary due to public interest.
The transfer is necessary for the fulfillment of legal purposes.
The transfer is necessary to protect the vital interests of the data subject or other persons when the data subject is unable to give consent.
OWNERSHIP AND APPROVAL OF THE DOCUMENT
The owner of this document is the data protection officer of the organization
ETERNIUM d.o.o. The document owner must review this Policy in accordance with the previously mentioned requirements. The current version of this document is available to all employees of the organization ETERNIUM d.o.o. at the business address Ružići 25/i, 51213 Jurdani and is publicly published on the organization's website https://eternium.hr
The policy was approved by the management of the organization ETERNIUM d.o.o. on 01.07.2023.
Date: 01.07.2023. Approved by: Mauro Slavić
