POLICY
regarding the processing of personal data
in the open joint-stock company “Beresteysky baker”
Annex 1
to order dated November 15, 2021 No. 462
“On approval of local legal acts of OJSC “Beresteisky baker”
CHAPTER 1
GENERAL PROVISIONS
1.1. The personal data processing policy at Beresteysky Baker OJSC (hereinafter referred to as the Policy) defines the basic principles, goals, conditions and methods of processing personal data, lists of subjects and personal data processed at Beresteysky Baker OJSC, the rights of personal data subjects, as well as those implemented in JSC “Beresteisky baker” requirements for the protection of personal data.
1.2. The policy was developed taking into account the requirements of the Constitution of the Republic of Belarus, legislative and other regulatory legal acts of the Republic of Belarus in the field of personal data
1.3. The provisions of the Policy serve as the basis for the development of local legal acts regulating the processing of personal data at Beresteysky Baker OJSC.
CHAPTER 2
LEGISLATIVE AND OTHER REGULATIVE LEGAL ACTS OF THE REPUBLIC OF BELARUS, IN ACCORDANCE WITH WHICH THE POLICY FOR PROCESSING PERSONAL DATA AT JSC “BERERSTEI BAKER” is DETERMINED
2.1. The policy for processing personal data at Beresteysky Baker OJSC is determined in accordance with the following regulatory legal acts:
Constitution of the Republic of Belarus;
Labor Code of the Republic of Belarus;
Law of the Republic of Belarus dated 05/07/2021 No. 99-3 “On the protection of personal data”;
Law of the Republic of Belarus dated July 21, 2008 No. 418-3 “On the Population Register”; Law of the Republic of Belarus dated November 10, 2008 No. 455-3 “On information, informatization and information protection”;
Other regulatory legal acts of the Republic of Belarus.
CHAPTER 3
MAIN TERMS AND DEFINITIONS USED IN LOCAL REGULATIONS OF JSC “BERESTEYSKY BAKER” REGULATING ISSUES OF PROCESSING PERSONAL DATA.
In the texts of the Policy, local regulations of Beresteysky Baker OJSC, the terms and definitions used are used in the meanings applied in the current legislation of the Republic of Belarus.
CHAPTER 4
PRINCIPLES AND OBJECTIVES OF PROCESSING PERSONAL DATA
4.1. OJSC “Beresteysky Baker”, being a personal data operator, processes personal data of employees of OJSC “Beresteysky Baker” and other subjects of personal data who are not in labor relations with OJSC “Beresteysky Baker”.
4.2. The processing of personal data at Beresteysky Baker OJSC is carried out taking into account the need to ensure the protection of the rights and freedoms of personal data subjects, including the protection of the right to privacy, personal and family secrets, based on the following principles:
– processing of personal data is carried out at OJSC “Beresteisky Baker” on a legal basis;
– the processing of personal data is limited to the achievement of specific, predetermined and legitimate purposes;
– processing of personal data that is incompatible with the purposes of collecting personal data is not permitted;
– it is not allowed to combine databases containing personal data, the processing of which is carried out for purposes that are incompatible with each other;
– only personal data that meets the purposes of their processing are subject to processing;
– the content and volume of personal data correspond to the stated purposes of processing. The personal data processed is not redundant in relation to the stated purposes of processing;
– when processing personal data, the accuracy of personal data, their sufficiency, and, if necessary,
relevance in relation to the stated purposes of their processing;
– storage of personal data is carried out in a form that makes it possible to determine the subject of personal data no longer than required by the purposes of processing personal data, unless a different period for storing personal data is established by law or contract. Personal data is subject to destruction upon achievement of the purposes of processing or in the event of the loss of the need to achieve these purposes, unless otherwise provided by law;
4.3. Personal data is processed at Beresteysky Baker OJSC for the purposes of:
– ensuring compliance with the Constitution of the Republic of Belarus, legislative and regulatory legal acts of the Republic of Belarus, local legal acts of Beresteysky Baker OJSC;
– ensuring the implementation of labor, civil law, accounting, tax relations, conclusion and execution of labor, civil law contracts, including public ones;
– implementation of the functions, powers and responsibilities assigned by the legislation of the Republic of Belarus to OJSC “Beresteisky Baker”, including the provision of personal data to government authorities, to the Social Protection Fund of the Ministry of Labor and Social Protection of the Republic of Belarus, andalso to other government bodies;
– regulation of labor relations with the Company’s employees (assistance in employment, training and promotion, ensuring personal safety, monitoring labor discipline, quantity and quality of work performed, labor protection, ensuring the safety of property, implementation of the terms of the collective agreement);
– implementation of the Company’s social policy in the field of housing relations, cultural and sports activities, provision of vouchers to health and sanatorium-resort institutions, medical care, insurance, food, provision of places in preschool educational institutions;
– protection of life, health or other vital interests of personal data subjects;
– preparation, conclusion, execution and termination of contracts with counterparties;
– ensuring access and intra-facility regimes at the facilities of OJSC “Beresteisky Baker”;
– formation of reference materials for internal information support of the activities of OJSC “Beresteisky Baker”;
– execution of judicial acts, acts of other bodies or officials subject to execution in accordance with the legislation of the Republic of Belarus on enforcement proceedings;
– for other lawful purposes.
CHAPTER 5
LIST OF PERSONAL DATA AND LIST OF SUBJECTS, WHOSE PERSONAL DATA IS PROCESSED AT JSC “BERESTEYSKY BAKER”
5.1. The list of personal data processed at Beresteysky Baker OJSC is determined in accordance with the legislation of the Republic of Belarus and local legal acts, taking into account the purposes of processing personal data specified in Chapter 4 of the Policy
5.2. OJSC “Beresteisky Baker” processes personal data of the following categories of subjects:
Employees of Beresteysky Baker OJSC, including employees of separate divisions (branches) of Beresteysky Baker OJSC;
Other subjects of personal data (to ensure the implementation of the processing purposes specified in Chapter 4 of the Policy).
CHAPTER 6
FUNCTIONS OF JSC “BERESTEYSKY BAKER” WHEN PROCESSING PERSONAL DATA
6.1. OJSC “Beresteisky Baker” when processing personal data:
– takes measures necessary and sufficient to ensure compliance with the requirements of the legislation of the Republic of Belarus and local legal acts of the Company in the field of personal data;
– takes legal, organizational and technical measures to protect personal data from unauthorized or accidental access, destruction, modification, blocking, copying, provision, distribution of personal data, as well as from other unlawful actions in relation to personal data;
– appoints persons responsible for implementing internal control over the processing of personal data of Beresteysky Baker OJSC;
– issues local legal acts that define the policy and issues of processing and protection of personal data at Beresteysky Baker OJSC;
– familiarizes employees of Beresteysky Baker OJSC, who have permission to process personal data, with the provisions of the legislation of the Republic of Belarus and local legal acts in the field of personal data, including requirements for the protection of personal data, and trains these employees;
– publishes or otherwise provides unrestricted access to this Policy;
– informs in the prescribed manner to the subjects of personal data or their representatives information about the availability of personal data relating to the relevant subjects, provides the opportunity to familiarize themselves with this personal data when contacting and (or) receiving requests from the specified subjects of personal data or their representatives, unless otherwise provided by law The Republic of Belarus;
-stops processing and destroys personal data in cases provided for by the legislation of the Republic of Belarus in the field of personal data;
– performs other actions provided for by the legislation of the Republic of Belarus in the field of personal data.
CHAPTER 7
TERMS AND PROCEDURES FOR PROCESSING PERSONAL DATA
IN OJSC “BERESTEYSKY BAKER”
7.1. The processing of personal data at Beresteysky Baker OJSC is carried out with the consent of the subject of personal data to the processing of his personal data, unless otherwise provided by the legislation of the Republic of Belarus in the field of personal data.
7.2. Without the consent of the subject of personal data, Beresteysky Baker OJSC does not disclose or distribute personal data to third parties, unless otherwise provided by the legislation of the Republic of Belarus.
7.3. OJSC “Beresteisky Baker” has the right to entrust the processing of personal data on its behalf or in its interests to an authorized person on the basis of an agreement concluded with this person. The contract must contain:
purposes of processingpersonal data;
a list of actions that will be performed with personal data by an authorized person;
obligations to maintain the confidentiality of personal data; measures to ensure the protection of personal data in accordance with Art. 17 of the Law on the Protection of Personal Data.
The authorized person is not required to obtain the consent of the subject of personal data. If the processing of personal data on behalf of Beresteysky Baker OJSC requires obtaining the consent of the subject of personal data, such consent is obtained by Beresteysky Baker OJSC.
7.4. For the purpose of internal information support, Beresteysky Baker OJSC may create internal reference materials, which, with the written consent of the subject of personal data, unless otherwise provided by the legislation of the Republic of Belarus, may include his last name, first name, patronymic, place of work, position, year and place birth, address, subscriber number, email address, other personal data provided by the subject of personal data.
7.5. Processing of personal data at Beresteysky Baker OJSC is carried out in the following ways:
using automation tools;
without the use of automation tools, if this provides search for personal data and (or) access to it according to certain criteria (card files, lists, databases, journals, etc.).,
CHAPTER 8
RIGHTS OF PERSONAL DATA SUBJECTS
8.1. Personal data subjects have the right to:
•revocation of the consent of the subject of personal data;
•obtaining information about the provision of their personal data to third parties;
•obtaining information regarding the processing of personal data and changing personal data;
•request to stop processing personal data and (or) delete it;
• appealing actions (inaction) and decisions of the operator related to the processing of personal data.
CHAPTER 9
MEASURES TAKEN BY JSC “BERESTEIY BAKER” TO ENSURE THE FULFILLMENT OF THE OPERATOR'S OBLIGATIONS WHEN PROCESSING PERSONAL DATA
9.1. Measures necessary and sufficient to ensure that Beresteysky Baker OJSC fulfills the obligations of the operator provided for by the legislation of the Republic of Belarus in the field of personal data include:
– providing personal data subjects with the necessary information before obtaining their consent to the processing of personal data;
– explaining to personal data subjects their rights related to the processing of personal data;
– obtaining written consents of personal data subjects for the processing of their personal data, except for cases provided for by the legislation of the Republic of Belarus;
– appointment of persons responsible for internal control over the processing of personal data;
– familiarization of employees who have access and directly process personal data at Beresteysky Baker OJSC with the provisions of the legislation on personal data;
– establishing the procedure for access to personal data, including those processed in the information resource (system);
– implementation of technical and cryptographic protection of personal data at Beresteysky Baker OJSC in the manner established by the Operational Analytical Center under the President of the Republic of Belarus, in accordance with the classification of information resources (systems) containing personal data;
– ensuring unlimited access, including using the global computer network Internet, to documents defining the policy of Beresteysky Baker OJSC regarding the processing of personal data, before such processing begins;
– termination of processing of personal data if there are no grounds for their processing;
– immediate notification of the authorized body for the protection of the rights of personal data subjects about violations of personal data protection systems;
– changing, blocking, deleting inaccurate or illegally obtained personal data;
– limiting the processing of personal data to the achievement of specific, pre-declared legitimate purposes;
– storage of personal data in the form,
allowing identification of subjects of personal data, no longer than required by the stated purposes of processing personal data.
9.2. Measures to ensure the security of personal data during their processing in personal data information systems are established in accordance with local legal acts regulating the issues of ensuring the security of personal data during their processing in the personal data information systems of Beresteysky Baker OJSC.
CHAPTER 10
MONITORING COMPLIANCE WITH THE LEGISLATION OF THE REPUBLIC OF BELARUS AND LOCAL LEGAL ACTS OF JSC “BERESTEYSKY BAKER” IN THE FIELD OF PERSONAL DATA, INCLUDING REQUIREMENTS FOR THE PROTECTION OF PERSONAL DATA
10.1. Monitoring compliance at OJSC “Beresteisky Baker”» legislation of the Republic of Belarus and local legal acts of Beresteysky Baker OJSC in the field of personal data, including requirements for the protection of personal data, is carried out in order to verify the compliance of the processing of personal data in the structural divisions of Beresteysky Baker OJSC with the legislation of the Republic of Belarus and local legal acts OJSC “Beresteisky Baker” in the field of personal data, including requirements for the protection of personal data, as well as measures taken aimed at preventing and identifying violations of the legislation of the Republic of Belarus in the field of personal data, identifying possible channels of leakage and unauthorized access to personal data, eliminating consequences of such violations.
10.2. Internal control over compliance at Beresteysky Baker OJSC, in separate divisions (branches), with the legislation of the Republic of Belarus and local legal acts of Beresteysky Baker OJSC in the field of personal data, including requirements for the protection of personal data, is carried out by persons responsible for the implementation internal control over the processing of personal data at Beresteysky Baker OJSC.
The current version of the Policy is constantly available at: https://pinskhleb.by/privacy.