Privacy Policy
SUBJECT
Art. 1. (1) These Rules (the Rules) set out the manner in which MILLER PRO Ltd, with UIC 204645018 (the Company) collects, records, organises, structures, stores, adapts or modifies, retrieves, consults, uses, discloses by transmission, dissemination or otherwise makes available, arranges or combines, restricts, erases, destroys or otherwise processes personal data for the purposes of its activities.
(2) Depending on the specific situation, the Company may process data in its capacity as controller or processor.
(3) The Rules have been drawn up in accordance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
Art. 2. These RULES govern:
(1) The principles, procedures and mechanisms for the processing of personal data;
(2) The procedures for notifying the supervisory authority in the event of a security breach;
(3) The procedures for the administration of requests for access to data, rectification of processed data, objections and withdrawal of consents, as well as for the administration of requests for the exercise of other rights that data subjects have by law;
(4) Persons who process personal data and their obligations;
(5) The rules for the transfer of personal data to third parties in Bulgaria and abroad;
(6) The necessary technical and organisational measures to protect personal data from unlawful processing and in the event of incidents such as accidental or unlawful destruction, loss, unlawful access, alteration or dissemination;
(7) The technical means used in the processing of personal data.
DEFINITIONS
Art. 3. For the purposes of these Regulations, the terms used shall have the following meanings:
LPPD – Personal Data Protection Act.
CPDP – Commission for the Protection of Personal Data.
GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
Data Protection Officer – a natural person or organisation designated in accordance with the requirements of Article 37 et seq. On ORZD.
[or – if the appointment of a data protection officer is optional – the following may be included:
Data Protection Officer – a person who is an employee of the company or performs functions on whose behalf the duties relating to the protection and processing of personal data regulated in these rules are assigned.
The principal activities of the controller or processor shall not consist of processing operations which, by their nature, scope and/or purposes, require regular and systematic large-scale monitoring of data subjects, or large-scale processing of special categories of data and personal data. with convictions and offences. In view of this circumstance, the Company has no obligation to appoint a data protection officer and the Company should not be deemed to have appointed such a person or that the person responsible for the personal data has the obligations and should meet the requirements of a person within the meaning of Art. 37 et seq. From ORZD.]
Data controller – a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data. In these rules, “controller” means the Company.
Processor – a person or organisation which, on the basis of a contract, processes personal data provided by the Company for the agreed purposes.
Data Protection Notices – separate notices containing information provided to data subjects at the point at which the Company collects information about them. These notices may be general (for example, addressed to employees or notices on the organisation’s website) or related to processing for a specific purpose.
Data processing – any activity involving the use of personal data. This includes: receiving, recording, storing, performing an operation or series of operations on data, such as organising, editing, recovering, using, making available, deleting or destroying. Processing also includes the transfer of personal data to third parties.
Pseudo-identification – replacing information that directly or indirectly identifies an individual with one or more identifiers (‘pseudonyms’) so that the individual cannot be identified without access to additional information, which should be kept separate and confidential.
Consent – any freely given, specific, informed and unambiguous indication of the data subject’s wishes by a statement or a clear affirmative action consenting to the processing of personal data relating to him or her.
DATA SUBJECTS AND CATEGORIES OF PERSONAL DATA
Art. 4. (1) The Company shall collect and process personal data necessary for the exercise of its rights and obligations as an employer, supplier of goods and services and contractor, subject to the requirements of the applicable law. Personal data processed by the Company are grouped in registers of processing activities containing rules for processing personal data relating to:
employees and contractors under civil contracts;
job applicants;
customers;
service providers.
(2) The following personal data is collected for persons employed by the Company under employment or civil law relationships and for job applicants:
(a) Identification: name; SSN (date of birth), permanent and/or current address, telephone, ID card or passport details;
b) Education and training: data relating to education, work experience, professional and personal qualifications and skills;
(c) Health data: health status, TEC decisions, medical certificates, sick notes and any supporting documents;
d) Other data: criminal record certificate, where its presentation is required by a legal act, and other data the processing of which is necessary for the performance of the Company’s rights and obligations as an employer.
(3) With respect to natural persons, customers of the Company, personal data is collected which is necessary for the performance of the Company’s legal obligations as a provider of goods and services, as follows:
Name; SSN (date of birth), permanent and/or current address, telephone number, ID card or passport details and e-mail address.
(4) With regard to natural persons who are service providers to the company, personal data necessary for the conclusion and performance of contracts for the provision of services to the company by external providers shall be stored as follows:
name, SSN (date of birth), permanent and/or current address, telephone number, ID card or passport details; email.
(5) The Company processes sensitive data only insofar as this is necessary for the performance of its specific rights and obligations in the field of employment and social security law.
PURPOSES AND PRINCIPLES OF THE PROCESSING OF PERSONAL DATA
Art. 5. The purposes of the processing of personal data are:
(1) human resources management, payment of wages and the performance of the employer’s related obligations to withhold and pay employees’ health and social security contributions, taxes, and other rights and obligations of the Company as an employer;
(2) managing the Company’s customer relationships and providing goods and services;
(3) entering into and performing contracts with suppliers for the provision of goods and services to the Company.
Art. 6. Personal data shall be processed lawfully, fairly and transparently in accordance with the following principles:
(1) The data subject shall be informed in advance of the processing of his or her personal data;
(2) Personal data shall be collected for specified, explicit and legitimate purposes and shall not be further processed in a manner incompatible with those purposes;
(3) The personal data must be relevant to the purposes for which they are collected;
(4) The personal data must be accurate and, if necessary, kept up to date;
(5) Personal data shall be erased or rectified where it is found to be inaccurate or not relevant to the purposes for which it is processed;
(6) Personal data shall be kept in a form which permits identification of the natural persons concerned for no longer than is necessary for the purposes for which the data are processed.
Art. 7. For processing to be lawful, at least one of the following conditions must be met:
(1) The data subject has given his or her consent;
(2) The processing is necessary for the performance of a contract to which the data subject is a party or for taking steps at the request of the data subject before entering into a contract;
(3) The processing is necessary for compliance with a legal obligation to which the controller is subject;
(4) The processing is necessary to protect the vital interests of the data subject or of another natural person;
(5) The processing is necessary for the performance of a task carried out in the public interest;
(6) The processing is necessary for the purposes of the legitimate interests of the controller, except where the interests or fundamental rights and freedoms of the data subject override those interests. The purposes for which personal data are processed on this basis must be described in the applicable data protection notices.
AGREEMENT
Art. 8. (1) The data subject shall consent to the processing if he or she expressly and unambiguously so consents, by means of a statement or other confirmatory act. If consent to processing is given by means of a document which governs other matters, it shall be required separately from consent to other matters.
(2) Data subjects must be able to easily withdraw their consent to processing at any time, and the withdrawal must be complied with promptly. If there is no other condition for the lawfulness of the processing, it should be terminated by the withdrawal of consent.
(3) Declarations of consent shall be retained by the company for as long as processing activities are carried out on this basis, in order to comply with the principle of accountability.
PERSONAL DATA PROCESSING PROCEDURES
Procedure for the processing of personal data relating to persons employed by the company under an employment or civil law relationship, as well as job applicants
Art. 9. (1) Personal data relating to persons employed under an employment or civil law relationship in the Company, as well as to job applicants, shall be collected during and in connection with recruitment. The data of each employee of the Company shall be stored in personnel files, and some data may be stored or processed on technical media. Data from competitions and interviews are stored on technical and/or paper media as required.
(2) Personal files shall be stored in special locked cabinets which shall be located in the office of the person responsible for personal data. Job applicants’ data which are stored on paper shall be stored in special cabinets in the office of the person responsible for personal data. Access to the office shall be restricted to persons authorised to process personal data, and a special procedure shall be established for entering the premises by means of a key, magnetic card or other appropriate means and/or device.
(3) Persons authorised to process personal data shall take all organisational and technical measures for the storage and protection of personal files and folders containing information, including restricting access to them to outsiders and unauthorised employees.
(4) Employee files and the data of job applicants shall not be taken outside the company’s premises.
Procedure for processing personal data relating to customers and suppliers of goods and/or services
Art. 10. (1) Personal data relating to customers shall be collected when a request is made for the provision of goods or services or when a contract is concluded with a customer of the Company.
(2) Personal data relating to suppliers of goods and/or services are collected when a contract is concluded with the supplier concerned, and personal data are usually contained in the text of the contracts themselves.
(3) Personal data is stored electronically and on paper (signed copies of the concluded contracts), which are classified in separate files. The files shall be kept in lockable cabinets in the office of the person responsible for personal data. Electronic data shall be stored in databases.
DOCUMENTATION OF THE PROCESSING OF PERSONAL DATA
Art. 11. (1) The Company shall document the personal data processing activities in accordance with the principle of reporting.
(2) The documentation shall be sufficient to demonstrate compliance with the principles of lawful processing of personal data.
(3) Data processing related to the transmission of data to processors established in the country or abroad; the storage of data on servers owned by third parties; the archiving or deletion of data; the introduction of pseudonymisation, as well as any other processing whose parameters are different from those described in these rules, shall be documented by establishing protocols that contain the following information:
(a) the purposes of the processing;
(b) the categories of personal data and the categories of data subjects;
(c) the categories of recipients to whom the personal data have been or will be disclosed, including recipients in third countries;
(d) the transfer of personal data to a third country;
(e) where possible, the time limits provided for erasure of the different categories of data;
(f) a general description of the technical and organisational security measures.
(4) The records shall be drawn up by the persons carrying out the processing concerned in accordance with the instructions of the person responsible for the personal data.
(5) The set of all protocols containing the above-described information constitutes a record of processing activities pursuant to Article 30 of the GDPR.
DATA PROTECTION MEASURES
Technical measures
Art. 12. (1) All premises where personal data are stored and processed must have access control. Possible technical means of access control are:
security of the premises;
magnetic card and/or key recognition devices;
a policy of allowing outsiders onto company premises only when accompanied by company staff.
(2) The company’s premises must be reliably secured by fire safety measures in accordance with Bulgarian legislation.
Measures to protect documents
Art. 13. (1) The Company shall establish procedures for processing personal data, regulating access to data, destruction procedures and retention periods as detailed in these Rules. Pseudonymisation may be provided for certain categories of data upon proposal of the person responsible for the personal data.
(2) Reproduction and distribution of documents or files containing personal data shall be carried out only by authorised staff in case of necessity.
Personal protection measures
Art. 14. (1) Before occupying the relevant position, persons who carry out the protection and processing of personal data shall:
undertake not to disclose the personal data to which they have access;
familiarise themselves with the legal framework, internal rules and policies of the company regarding the protection of personal data;
undergo training on how to respond to data security events;
have been briefed on the dangers associated with the personal data processed by the company;
undertake not to share critical information with each other or with outsiders except in accordance with the procedure set out in these Rules.
(2) All employees shall receive training upon commencement of employment on how to respond to data security incidents, as well as training on the company’s obligations relating to the processing of personal data and the data protection measures to be taken during employment. . Periodic follow-up training and drills are conducted for staff to ensure knowledge of the regulations, potential data security risks and mitigation measures.
Measures to protect automated information systems and cryptographic protection
Art. (1) Access to the operating system containing files containing personal data shall be restricted to persons whose official duties or specifically assigned task require such access. Access shall be by means of a password.
(2) Electronic databases shall be protected by logical means of protection, such as an antivirus program which is updated automatically, firewalls, etc.
(3) Back-up of personal data on technical media is carried out periodically in order to preserve the information.
Art. 16. (1) The protection of electronic data against unlawful access, damage, loss or destruction, whether intentionally committed by a person or in the event of technical malfunctions, accidents, accidents, disasters, etc., shall be ensured by
the introduction of passwords for computers that provide access to personal data and files containing personal data;
antivirus programs, checking for illegally installed software;
periodic database integrity checks and updating of system information, data access system maintenance;
periodic back-up of data on technical media, maintenance of paper information (backup copies).
(2) The person responsible for personal data shall periodically report to the management of the company on the measures taken to ensure the level of security in the processing of personal data.
SECURITY BREACHES
Art. 17. (1) Persons who have detected signs of a data breach shall immediately report it to the person responsible for the personal data, providing him with all available information.
(2) The person responsible for personal data shall immediately carry out an investigation of the report, attempting to establish whether a breach of security has occurred and which data are affected.
(3) The person responsible for the personal data shall immediately report to the partners in the Company the available information on the security breach, including information on the nature of the incident, the time of its detection, the type of damage, the measures taken at the time and the measures to be taken in advance.
(4) In consultation with the management of the Company, the person responsible for the personal data shall take measures to prevent or mitigate the effects of the breach and the possibilities for data recovery.
(5) In case of urgency, where coordination with management would delay the response and cause great harm, the person responsible for personal data may, at his or her discretion, take measures to prevent or mitigate the effects of the security breach. In such a case, the data controller shall immediately inform the management of the measures taken and implement the instructions received.
Art. 18. (1) In the event that the security breach poses a probable risk to the rights and freedoms of the individuals whose data is affected, and after approval by the management of the company, the Person in charge of personal data shall arrange for the notification of the CPD.
(2) Notification to the CPD shall be made without undue delay and, where practicable, not later than 72 hours after the initial knowledge of the breach.
(3) The notification to the CPDP must contain the following information:
(a) a description of the security breach; the categories and approximate number of data subjects affected; and the categories and approximate number of personal data records affected;
(b) the name and contact details of the data controller;
(c) a description of the possible consequences of the security breach;
(d) a description of the measures taken or proposed to address the security breach, including measures to mitigate the adverse effects.
(4) Where the personal data breach is likely to pose a high risk to the rights and freedoms of natural persons, the data controller shall, without undue delay and in accordance with applicable law, notify the natural persons concerned.
Art. 19. (1) The Company shall keep a security breach register containing the following information:
(a) the date on which the breach was detected;
(b) a description of the breach – the source, type and scope of the relevant data, the cause of the breach (if applicable);
(c) a description of the notifications made: notification to the CPC and to the affected persons, if any;
(d) the measures taken to prevent and mitigate negative consequences for data subjects and the Company;
(e) the measures taken to limit the possibility of further security breaches.
(2) The register shall be kept in electronic format by the person responsible for the personal data.
DISCLOSURE OF PERSONAL DATA TO THIRD PARTIES
Art. 20. (1) Where necessary, the company may provide personal data to third parties acting as a processor of personal data on the basis of an express contract.
(2) In the case of providing the data of employees, customers or suppliers of goods and/or services to a processor, the Company shall:
(a) require sufficient guarantees from the processor to comply with legal requirements and good practices for the processing and protection of personal data;
(b) enter into a written agreement or other legal instrument having identical effect which governs the obligations of the processor and meets the requirements of Article 28 of Regulation (EU) 2016/679;
(c) inform the natural persons whose data will be provided to the processor.
(3) The processing of personal data by non-EU/EEA processors is only permissible where:
(a) the European Commission has adopted a decision confirming that the country where the transfer takes place ensures an adequate level of protection of the rights and freedoms of data subjects;
(b) appropriate safeguards are in place – such as binding corporate rules (BCRs), standard contractual clauses approved by the European Commission, an approved code of conduct or a certification mechanism;
(c) the data subject has given his or her explicit consent to the transfer, having been informed of the possible risks, or
(d) the transfer is necessary for one of the purposes listed in the GDPR, including the performance of a contract with the data subject, the protection of the public interest, the establishment and defence of legal disputes, the protection of the vital interests of the data subject in cases where the data subject is physically or legally incapable of giving consent.
DATA PROTECTION IMPACT ASSESSMENT
Art. 21. (1) An impact assessment shall be carried out where required by applicable law and in view of the risk to natural persons and the nature of the processing of personal data carried out by the Company. The impact assessment shall be carried out for high-risk processing activities.
(2) An impact assessment is required for any implementation of a key system or change to a business program that involves the processing of personal data, including:
the initial introduction of new technologies or the switch to new technologies;
automated processing, including profiling or automated decision-making;
large-scale processing of sensitive personal data;
large-scale, systematic surveillance of a public area.
(3) A record of the assessment shall be made and shall be made available upon request to the CPPO.
DESTRUCTION OF DATA
Art. 22. (1) Destruction of personal data shall be carried out by the Company or by a person expressly authorized, without prejudice to the rights of the persons to whom the data subject to destruction relate, in accordance with the provisions of the relevant regulations.
(2) The information in the records shall be destroyed once the purposes of the processing have been achieved and the need for storage no longer exists.
(3) The destruction of data on paper shall be carried out by shredding or incineration. Electronic data shall be erased from the electronic database in a manner that does not allow the information to be recovered.
PERSONS RESPONSIBLE FOR THE COLLECTION, PROCESSING AND STORAGE OF PERSONAL DATA AND FOR ACCESS TO PERSONAL DATA.
Art. 23. The person in charge of personal data and the persons who process personal data on behalf of the company shall be natural persons with the necessary competence and shall be appointed by an appropriate written act, including these rules.
Art. 24. The person in charge of personal data:
shall assist the Company and the persons processing personal data in the performance of their obligations to protect personal data by ensuring the implementation and maintenance of the necessary technical and organizational measures and means to implement data protection;
ensuring the proper functioning of the aforementioned protection systems;
supervise the entire data collection and processing process;
fulfil all data breach reporting and management obligations;
periodically request information from processors in relation to the collection, access and processing of personal data;
promptly notify the Company of any irregularities identified in connection with the performance of its duties;
destroy data on paper and technical media in accordance with the law and the conditions set out in these Rules;
re-authorise natural or legal persons with a written data protection act.
Article 25 (1) The collection, processing, storage and protection of personal data shall be carried out only by persons who are expressly instructed to do so and whose official duties or specifically assigned task so require.
(2) When commissioning activities requiring the processing of personal data from the Company’s records, service providers shall comply with the applicable legal requirements concerning the processing of personal data and the procedures referred to in Article 19 of these Rules.
(3) Access to personal data may also be granted to the relevant state authorities – court, investigation, prosecution, audit bodies, etc. The aforementioned persons may request the data in a timely manner in connection with the exercise of their powers.
RIGHTS OF DATA SUBJECTS
Article 26 (1) Every person shall have the right to request access to his or her personal data, including the right to request confirmation as to whether data relating to him or her are being processed, to be informed of the purposes of such processing, of the categories of data and of the recipients of the data, and of the purposes of any processing of personal data relating to him or her.
(2) The right of access shall be exercised by means of a request by the individual concerned, received at the address of the registered office of the Company or by official e-mail.
(3) Any individual shall have the right to request the erasure, rectification or blocking of his or her personal data, the processing of which does not comply with the requirements of the law.
(4) Any individual has the right to object in writing to the processing and/or disclosure to third parties of his or her personal data without the necessary legal grounds.
(5) The Company shall, within two weeks of receipt of the request referred to in the preceding paragraphs, notify the applicant whether there are legal grounds for granting the request. If the Company finds that there are legal grounds for granting the request, it shall inform the person of the procedure by which he may exercise his right.
(6) Data subjects shall also have the right to:
withdraw their consent to processing at any time;
object to the use of their personal data for direct marketing purposes;
request information about the basis on which their personal data have been provided for processing by a processor outside the EU/EEA;
object to a decision taken entirely on the basis of automated processing, including profiling;
be informed of a breach of data protection which may result in a high risk to their rights and freedoms;
lodge a complaint with the regulatory authority;
in some cases, obtain or request that their personal data be transferred to a third party in a structured, commonly used, machine-readable format (right to data portability).
CHANGES TO INTERNAL RULES
Art. 27. The Company may modify these Rules at any time. Any changes must be communicated immediately to the persons concerned.
These Rules are adopted and come into force on the date of their signature.
Sofia, 1 January 2024.
Andrea Bertin
Manager of MILLER PRO Ltd.