Regulation on the Processing and Protection of Personal Data in Personal Data Databases Owned by the Seller

Contents

  1. General Concepts and Scope of Application
  2. List of Personal Data Databases
  3. Purpose of Personal Data Processing
  4. Procedure for Processing Personal Data: Obtaining Consent, Informing About Rights, and Actions with the Personal Data of the Data Subject
  5. Location of the Personal Data Database
  6. Conditions for Disclosure of Information Contained in Personal Data to Third Parties
  7. Protection of Personal Data: Protection Methods, Responsible Person, Employees Directly Involved in Processing and/or Having Access to Personal Data in Connection with Their Official Duties, Retention Period of Personal Data
  8. Rights of the Data Subject
  9. Procedure for Handling Requests from the Data Subject
  10. State Registration of Personal Data Databases

1. General Concepts and Scope of Application

1.1. Definitions of Terms:

personal data database — a named collection of organized personal data in electronic form and/or in the form of personal data files;

responsible person — a designated person who organizes work related to the protection of personal data during their processing in accordance with the law;

owner of a personal data database — an individual or legal entity to whom the law or the consent of the data subject grants the right to process such data, who determines the purpose of processing personal data in this database, establishes the composition of such data and the procedures for their processing, unless otherwise provided by law;

State Register of Personal Data Databases — a unified state information system for the collection, accumulation and processing of information about registered personal data databases;

publicly available sources of personal data — directories, address books, registers, lists, catalogs and other systematized collections of publicly available information containing personal data, which are placed and published with the knowledge of the data subject. Social networks and internet resources where the data subject leaves their personal data are not considered publicly available sources of personal data (except where the data subject expressly indicates that the personal data has been posted for the purpose of its unrestricted dissemination and use);

consent of the data subject — any documented, voluntary expression of will by an individual regarding permission to process their personal data in accordance with the stated purpose of their processing;

depersonalization of personal data — removal of information that makes it possible to identify an individual;

processing of personal data — any action or set of actions performed wholly or partially in an information (automated) system and/or in personal data files that are related to the collection, registration, accumulation, storage, adaptation, modification, updating, use and dissemination (distribution, implementation, transfer), depersonalization and destruction of information about an individual;

personal data — information or a combination of information about an individual who is identified or can be specifically identified;

data processor — an individual or legal entity to whom the owner of the personal data database or the law has granted the right to process such data. An entity entrusted by the owner and/or processor of the personal data database to perform technical work with the personal data database without access to the content of the personal data is not considered a data processor;

data subject — an individual in relation to whom, in accordance with the law, personal data is processed;

third party — any person, except the data subject, owner or processor of the personal data database and the authorized state body responsible for personal data protection, to whom the owner or processor of the personal data database transfers personal data in accordance with the law;

special categories of data — personal data concerning racial or ethnic origin, political, religious or ideological beliefs, membership in political parties and trade unions, as well as data concerning health or sexual life.

1.2. This Regulation is mandatory for the responsible person and employees of the Seller who directly process and/or have access to personal data in connection with the performance of their official duties.

2. List of Personal Data Databases

2.1. The Seller owns the following personal data databases:

  • personal data database of counterparties.

3. Purpose of Personal Data Processing

3.1. The purpose of processing personal data in the system is to ensure the implementation of civil-law relations, the provision and receipt of goods and services, and the execution of payments for purchased goods and services in accordance with the Tax Code of Ukraine and the Law of Ukraine “On Accounting and Financial Reporting in Ukraine.”

4. Procedure for Processing Personal Data: Obtaining Consent, Informing About Rights, and Actions with the Personal Data of the Data Subject

4.1. The consent of the data subject shall constitute a voluntary expression of will by an individual granting permission to process their personal data in accordance with the stated purpose of its processing.

4.2. The consent of the data subject may be provided in the following forms:

  • a document on paper containing details that make it possible to identify the document and the individual;
  • an electronic document containing mandatory details that make it possible to identify the document and the individual. The voluntary expression of will by an individual to permit the processing of their personal data may appropriately be certified by the electronic signature of the data subject;
  • a mark on an electronic page of a document or in an electronic file processed in an information system on the basis of documented software and technical solutions.

4.3. The consent of the data subject to the processing of personal data is provided during the establishment of civil-law relations in accordance with applicable legislation.

4.4. Notification of the data subject about the inclusion of their personal data in the personal data database, their rights established by the Law of Ukraine “On Personal Data Protection,” the purpose of collecting the data, and the persons to whom their personal data is transferred shall be carried out during the establishment of civil-law relations in accordance with applicable legislation.

4.5. The processing of data concerning racial or ethnic origin, political, religious or ideological beliefs, membership in political parties and trade unions, as well as data concerning health or sexual life (special categories of data) is prohibited.

5. Location of the Personal Data Database

5.1. The personal data databases specified in Section 2 of this Regulation are located at the Seller’s address.

6. Conditions for Disclosure of Information Contained in Personal Data to Third Parties

6.1. The procedure for granting third parties access to personal data is determined by the terms of the consent of the data subject provided to the owner of the personal data for the processing of such data, or in accordance with the requirements of the law.

6.2. Access to personal data shall not be granted to a third party if such person refuses to assume obligations to ensure compliance with the requirements of the Law of Ukraine “On Personal Data Protection” or is unable to ensure such compliance.

6.3. A participant in relations involving personal data shall submit a request for access (hereinafter referred to as the “request”) to the owner of the personal data.

6.4. The request shall specify:

  • surname, first name and patronymic, place of residence (stay), and details of the identity document of the individual submitting the request (for an individual applicant);
  • name and location of the legal entity submitting the request, position, surname, first name and patronymic of the person certifying the request; confirmation that the content of the request corresponds to the authority of the legal entity (for a legal entity applicant);
  • surname, first name and patronymic, as well as other information making it possible to identify the individual whose personal data is being requested;
  • information about the personal data database in respect of which the request is submitted, or information about the owner or processor of such personal data database;
  • a list of the personal data being requested;
  • the purpose and/or legal grounds for the request.

6.5. The period for reviewing a request for the purpose of determining whether it can be satisfied may not exceed ten business days from the date of receipt. During this period, the owner of the personal data database shall notify the person submitting the request that the request will be satisfied or that the relevant personal data cannot be provided, indicating the grounds established by the relevant legal or regulatory act. The request shall be satisfied within thirty calendar days from the date of its receipt, unless otherwise provided by law.

6.6. Deferral of access to the personal data of third parties is permitted if the required data cannot be provided within thirty calendar days from the date the request is received. In such case, the total period for resolving the issues raised in the request may not exceed forty-five calendar days.

6.7. Notice of the deferral shall be provided to the third party that submitted the request in writing, together with an explanation of the procedure for appealing such decision.

6.8. The notice of deferral shall specify:

  • surname, first name and patronymic of the official;
  • date of dispatch of the notice;
  • reason for the deferral;
  • period within which the request will be satisfied.

6.9. Access to personal data may be refused if such access is prohibited by law.

6.10. The notice of refusal shall specify:

  • surname, first name and patronymic of the official refusing access;
  • date of dispatch of the notice;
  • reason for the refusal.

6.11. A decision to defer or refuse access to personal data may be appealed in court.

7. Protection of Personal Data: Protection Methods, Responsible Person, Employees Directly Involved in Processing and/or Having Access to Personal Data in Connection with Their Official Duties, Retention Period of Personal Data

7.1. The owner of the personal data database shall be equipped with system and software-technical means and communication facilities that prevent loss, theft, unauthorized destruction, alteration, falsification and copying of information and comply with international and national standards.

7.2. The responsible person organizes work related to the protection of personal data during its processing in accordance with the law. The responsible person shall be appointed by an order of the owner of the personal data database.

The duties of the responsible person regarding the organization of work related to the protection of personal data during its processing shall be specified in the job description.

7.3. The responsible person shall:

  • know the legislation of Ukraine in the field of personal data protection;
  • develop procedures for employees’ access to personal data in accordance with their professional, official or employment duties;
  • ensure that the employees of the owner of the personal data database comply with the requirements of Ukrainian legislation in the field of personal data protection and internal documents regulating the activities of the owner of the personal data database concerning the processing and protection of personal data in personal data databases;
  • develop a procedure for internal control over compliance with the requirements of Ukrainian legislation in the field of personal data protection and internal documents regulating the activities of the owner of the personal data database regarding the processing and protection of personal data, which shall, in particular, include provisions regarding the frequency of such control;
  • notify the owner of the personal data database of any violations by employees of the requirements of Ukrainian legislation in the field of personal data protection and internal documents regulating the activities of the owner of the personal data database concerning the processing and protection of personal data, no later than one business day from the moment such violations are discovered;
  • ensure the storage of documents confirming the consent of the data subject to the processing of their personal data and the notification of such data subject of their rights.

7.4. In order to perform their duties, the responsible person shall have the right to:

  • obtain necessary documents, including orders and other administrative documents issued by the owner of the personal data database, related to the processing of personal data;
  • make copies of received documents, including copies of files and any records stored in local computer networks and autonomous computer systems;
  • participate in discussions regarding the performance of their duties related to organizing work on the protection of personal data during its processing;
  • submit proposals for improving activities and methods of work for consideration, provide comments and options for eliminating deficiencies identified in the processing of personal data;
  • receive explanations concerning the processing of personal data;
  • sign and approve documents within the scope of their authority.

7.5. Employees who directly process personal data and/or have access to personal data in connection with the performance of their official (employment) duties shall comply with the requirements of Ukrainian legislation in the field of personal data protection and internal documents concerning the processing and protection of personal data in personal data databases.

7.6. Employees who have access to personal data, including those who process such data, shall not disclose, in any manner, personal data entrusted to them or made known to them in connection with the performance of their professional, official or employment duties. This obligation remains in force after termination of activities related to personal data, except in cases established by law.

7.7. Persons who have access to personal data, including those who process such data, shall be liable in accordance with Ukrainian legislation in the event of violation of the requirements of the Law of Ukraine “On Personal Data Protection.”

7.8. Personal data shall not be stored longer than necessary for the purpose for which such data is stored, but in any event not longer than the period for which such data is retained as specified in the data subject’s consent to the processing of such data.

8. Rights of the Data Subject

8.1. The data subject has the right to:

  • know the location of the personal data database containing their personal data, its purpose and name, location and/or place of residence (stay) of the owner or processor of such database, or authorize other persons to obtain this information on their behalf, except where otherwise established by law;
  • receive information about the conditions for access to personal data, including information about third parties to whom their personal data contained in the relevant database is transferred;
  • access their personal data contained in the relevant personal data database;
  • receive, no later than thirty calendar days from the date of receipt of the request, except as otherwise provided by law, a response as to whether their personal data is stored in the relevant personal data database, as well as obtain the content of their stored personal data;
  • submit a reasoned objection to the processing of their personal data by state authorities and local self-government bodies in the exercise of their powers provided by law;
  • submit a reasoned demand for the modification or destruction of their personal data by any owner or processor of the database if such data is processed unlawfully or is inaccurate;
  • protection of their personal data from unlawful processing and accidental loss, destruction or damage resulting from intentional concealment, failure to provide or untimely provision of such data, as well as protection against the provision of information that is inaccurate or damages the honor, dignity or business reputation of an individual;
  • apply to state authorities and local self-government bodies whose powers include protection of personal data regarding the protection of their rights concerning personal data;
  • use legal remedies in the event of violation of personal data protection legislation.

9. Procedure for Handling Requests from the Data Subject

9.1. The data subject has the right to receive any information concerning themselves from any participant in relations involving personal data without stating the purpose of the request, except in cases established by law.

9.2. The data subject’s access to their personal data shall be provided free of charge.

9.3. The data subject shall submit a request for access (hereinafter referred to as the “request”) to the owner of the personal data database.

The request shall specify:

  • surname, first name and patronymic, place of residence (stay), and details of the identity document of the data subject;
  • other information making it possible to identify the data subject;
  • information about the personal data database in respect of which the request is submitted, or information about the owner or processor of such database;
  • a list of the personal data being requested.

9.4. The period for reviewing a request for the purpose of determining whether it can be satisfied may not exceed ten business days from the date of receipt. During this period, the owner of the personal data database shall notify the data subject that the request will be satisfied or that the relevant personal data cannot be provided, indicating the grounds established by the relevant legal or regulatory act.

9.5. The request shall be satisfied within thirty calendar days from the date of its receipt, unless otherwise provided by law.

10. State Registration of Personal Data Databases

10.1. State registration of personal data databases is carried out in accordance with Article 9 of the Law of Ukraine “On Personal Data Protection.”