Organisational directive for the processing and protection of personal data under Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and Act No. 18/2018 Coll. on the Protection of Personal Data.
Euro Service Business spol. s r.o.
Registered office: Banská Bystrica, Tr. Hr. Králové 13
Company ID (IČO): 44550197
Office for Personal Data Protection of the Slovak Republic
Hraničná 12, 820 07 Bratislava 27
Tel: 02/ 32 31 3214 · E-mail: statny.dozor@pdp.gov.sk
Pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter „GDPR") and pursuant to Act No. 18/2018 Coll. of 29 November 2017 on the Protection of Personal Data and on Amendments to Certain Acts (hereinafter „the Data Protection Act"), this directive contains the technical and organisational measures our company has undertaken to comply with, since under Article 24 GDPR it is responsible — taking into account the nature, scope, context and purposes of processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons — for ensuring and being able to demonstrate that processing is carried out in accordance with the GDPR.
In this step, our company decided to define which personal data it processes so that it can analyse the processing of personal data and ensure compliance with the GDPR. We define individual categories of personal data as separate filing systems (IS).
IS Customers: Legal entity: company name, company billing address, Company ID (IČO), Tax ID (DIČ), VAT ID (IČ DPH), registered office address, first and last name of the contact person, job position of the contact person, phone number, email address, fax, website, cookies. Purpose of processing: issuing a tax document, contact with the customer, performance of the contract, delivery of goods, delivery of services, complaints.
IS Marketing: First name, last name, phone number, email address, cookies. Purpose: sending marketing and promotional emails, the contact form, contact via social media.
Our company will comply with the following principles of personal data processing:
Personal data will be processed lawfully, fairly and in a transparent manner in relation to the data subject ('lawfulness, fairness and transparency').
Our company has undertaken to process data only in a lawful manner so as not to infringe the fundamental rights of the data subject. Processing of personal data by our company will be lawful by ensuring it is based on at least one of the following legal grounds:
The legal basis for the individual filing systems (IS) is as follows:
IS Customers: Legal basis – Article 6(1)(c) GDPR – processing of personal data (first name, last name, title, street and number, postal code, city) is necessary under a specific regulation or an international treaty binding on the Slovak Republic, in particular under Act No. 222/2004 Coll. on Value Added Tax. Legal basis – Article 6(1)(b) GDPR – processing of personal data is necessary for the performance of the contract.
IS Marketing: Legal basis – Article 6(1)(a) GDPR – the data subject has given consent to the processing of their personal data for at least one specific purpose.
Our company will collect personal data only for specified, explicit and legitimate purposes, and will not process it further in a manner incompatible with those purposes. Our company informs the data subject of the purpose of processing personal data before processing begins. In the section Mapping of personal data, we have set out the purposes of processing for each IS, and we will process personal data only for the purposes stated there.
Our company will process personal data in a manner that is adequate, relevant and limited to what is necessary for the purposes for which it is processed. To ensure data minimisation, our company has decided to analyse whether the data processed is adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.
IS Customers: All processed data is necessary. It is processed for the purposes of issuing a tax document, contact with the customer and performance of the contract.
IS Marketing: All processed data is necessary.
Our company will process personal data so that it is accurate and, where necessary, kept up to date, and will take reasonable and effective steps to ensure that personal data which is inaccurate, having regard to the purposes for which it is processed, is erased or rectified without delay. To ensure the principle of accuracy, our company's written consent to the processing of personal data includes the following wording: „The data subject is obliged to provide true and up-to-date personal data. In the event of a change in personal data, the data subject is obliged to notify the controller of the change without delay."
Our company will keep personal data in a form which permits identification of the data subject for no longer than is necessary for the purpose for which the personal data is processed.
Personal data at our company will be processed in a manner that ensures appropriate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, erasure or damage, using appropriate technical or organisational measures.
Personal data stored in electronic documents: Our company uses Microsoft Defender antivirus software and a Microsoft firewall. Internet connection: Orange Slovensko.
Personal data stored in paper (printed) form: Physical documents are kept in folders and binders, which protects them from damage. Binders with physical documents are stored in a cabinet and in a locked office, ensuring that only authorised persons can access these documents. Physical documents are destroyed using a shredder.
Our company is responsible for compliance with the basic principles of personal data processing and for the conformity of processing with those principles, and is obliged to demonstrate this compliance at the request of the Office. Our company has reviewed its written consents to the processing of personal data to ensure they meet GDPR requirements.
The company will ensure the following conditions are met when a data subject gives consent:
Our company has reviewed its written consents to the processing of personal data to ensure they meet GDPR requirements.
Under the GDPR, it is prohibited to process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and to process genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation. This prohibition does not apply where one of the conditions set out in Article 9(2)(a)–(j) GDPR applies.
Our company processes data concerning health on the basis of Article 9(2)(b) GDPR – processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law.
The rights of the data subject are set out in Chapter 3 GDPR, and our company undertakes to comply with them. These include, in particular, the following rights:
When processing personal data, our company will provide the data subject with the following information:
If personal data has not been obtained from the data subject, our company will provide the data subject with all the information set out in point 6.1 of this directive, as well as the source from which the personal data originates and, where applicable, information as to whether it comes from publicly accessible sources, within a reasonable period, and no later than within one month. Our company will not provide the data subject with this information in the cases set out in Article 14(5) GDPR, in particular where:
The data subject has the right to obtain from the controller confirmation as to whether personal data concerning them is being processed and, if so, the right to access that personal data.
The data subject has the right to have the controller rectify inaccurate personal data concerning them without undue delay, and to have incomplete personal data completed, including by means of providing a supplementary statement.
The data subject has the right to obtain from the controller the erasure of personal data concerning them without undue delay, and the controller is obliged to erase such data without undue delay where one of the following grounds applies:
The data subject has the right to obtain restriction of processing from the controller in any of the following cases:
Under Article 19 GDPR, the controller will communicate any rectification, erasure or restriction of processing to each recipient to whom the personal data was disclosed, unless this proves impossible or involves disproportionate effort; the controller will inform the data subject about those recipients if requested.
The data subject has the right to receive the personal data concerning them, which they provided to the controller, in a structured, commonly used and machine-readable format, and the right to transmit that data to another controller, where processing is based on consent or on a contract and is carried out by automated means. Where technically feasible, the data subject has the right to have the data transmitted directly from one controller to another.
The data subject has the right to object, at any time, on grounds relating to their particular situation, to the processing of personal data carried out on the basis of legitimate or public interest, including profiling based on those provisions.
The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
As controller, our company undertakes to comply with the following general obligations:
Our company undertakes to implement, prior to processing and throughout the processing of personal data, data protection by design, consisting of the adoption of appropriate technical and organisational measures, such as pseudonymisation, to effectively implement appropriate safeguards for the protection of personal data and to comply with the GDPR. In doing so, it takes into account the state of the art, the cost of implementation, the nature, scope, context and purpose of processing, and the risks that processing poses to the rights of the data subject.
Our company undertakes to implement data protection by default, consisting of appropriate measures to ensure that only personal data necessary for the specific purpose is processed, limiting the amount of data collected, the extent of its processing, its storage period and accessibility. It will ensure that personal data is not, by default, made accessible without the individual's intervention to an indefinite number of natural persons.
A processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller. Our company, as controller, does not currently use any processors.
Our company, as controller, maintains records of processing activities and will make them available to the supervisory authority upon request. These records contain:
Our company, as processor, maintains records of processing activities and will make them available to the supervisory authority upon request. These records contain:
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, our company will implement appropriate technical and organisational measures to ensure a level of security appropriate to that risk.
Authorisation to process personal data (Article 32(4) GDPR): Our company will take steps to ensure that any natural person acting under the authority of the controller or the processor who has access to personal data processes that data only on our instructions, unless required to do so by Union or Member State law.
In the event of a personal data breach, our company will, without undue delay and, where feasible, no later than 72 hours after becoming aware of it, notify the breach to the supervisory authority. Where notification is not made within 72 hours, it will be accompanied by reasons for the delay. The notification will contain at least:
Our company will document every personal data breach, including the facts relating to it, its effects and the remedial action taken. Where a breach is likely to result in a high risk to the rights and freedoms of natural persons, our company will also notify the data subject without undue delay.
Where a type of processing, in particular using new technologies and taking into account the nature, scope, context and purposes of processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller will, prior to processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. This is required in particular in cases of:
Our company's processing activities do not include the cases set out above; therefore, a data protection impact assessment is not required.
The controller is obliged to appoint a data protection officer where:
As our company does not meet any of the above conditions, it does not appoint a data protection officer.
The transfer of personal data which is processed or intended for processing after transfer to a third country or international organisation may only take place if the controller and processor comply with the applicable conditions, including conditions for onward transfer from that third country or international organisation to another third country or international organisation. The Office for Personal Data Protection publishes on its website a list of third countries, territories, specified sectors within a third country, and international organisations for which an adequate level of protection is ensured, available at dataprotection.gov.sk. Our company will regularly monitor this list and, when transferring personal data to countries outside this list, will proceed in accordance with Chapter 4 GDPR.
Our company is obliged to maintain confidentiality regarding the personal data it processes. This duty of confidentiality continues even after the processing of personal data has ended. Our company is also obliged to bind, by a duty of confidentiality, natural persons who come into contact with personal data at the controller or processor. This duty of confidentiality must continue even after the termination of the employment, civil service, service, or similar working relationship of that natural person.