Privacy
Information on data management
Information and contact details of the data controller:
His full name
Toldy Consult Kft.
Headquarters
1074 Budapest, Rejtő Jenő u. 2nd floor 7.
Location
6100 Kiskunfélegyháza, outskirts E5, main road 108 km.
Company registration number
01-09-376796
Your tax number
11377816-2-42
Location of data management
6100 Kiskunfélegyháza, outskirts E5, main road 108 km.
Contact information of the data controller
company@toldyconsult.hu +36 30 367 1677
The data controller acknowledges the content of this legal notice as binding. The purpose of this Data Management Notice is to inform customers, partners, and principals about the management of their personal data. The data manager handles personal data exclusively in accordance with the provisions of the applicable laws and strictly in compliance with the provisions of the data management and data protection provisions, taking into account the principles of legality, fair procedure and transparency, purposefulness, data economy, accuracy, and limited storage capacity.
The data controller takes all technical and organizational measures to ensure that the personal data of its partners is secure, according to the European Parliament and Council (EU) 2016/679. handle it in the manner prescribed by its regulation.
In accordance with the above, the data controller developed its everyday activities, developed its regulations, records, document samples, and information sheets.
The data protection guidelines arising in connection with the data management of the data controller are continuously available at the data controller's headquarters and website. The data manager reserves the right to change this information at any time. Of course, you will notify your audience of any changes in good time.
The data manager is committed to protecting the personal data of its customers and partners, and considers it of utmost importance to respect the client's right to self-determination of information. The data manager treats personal data confidentially and takes all security, technical and organizational measures that guarantee data security. The data controller describes its data management practices below.
The personal, material and temporal scope of the Data Management Notice
The personal scope of this Data Management Notice covers the data controller, as well as the natural persons whose data is included in the data processing covered by this Notice, as well as the persons whose rights or legitimate interests are affected by the data processing.
The material scope of the Notice covers all data processing arising in the course of the data controller's business, other commercial and service activities. Personal data management related to other activities of the data manager are regulated in a separate Data Management Information Sheet and the Data Management Regulations of the data manager.
This Notice enters into force on the day of approval and is valid indefinitely until further notice.
Concepts
concerned:
any specific natural person identified or - directly or indirectly - identifiable on the basis of personal data;
affected consent:
the voluntary, specific, and clear declaration of the data subject's will based on adequate information, by which the data subject indicates through a statement or an act clearly expressing the confirmation that he/she consents to the processing of personal data concerning him/her;
personal data:
the data that can be linked to the offense - in particular the name and identification mark of the data subject, as well as information characteristic of one or more physical, physiological, mental, economic, cultural or social identities - as well as the conclusion that can be drawn about the data subject;
data protection incident:
a breach of security that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data transmitted, stored or otherwise handled.
restriction of data management:
marking stored personal data for the purpose of restricting their future processing;
profiling:
any form of automated processing of personal data in which personal data is used to evaluate certain personal characteristics of a natural person, in particular to analyze or predict characteristics related to work performance, economic situation, health, personal preferences, interests, reliability, behavior, location or movement;
alias:
the processing of personal data in such a way that, without the use of additional information, it is no longer possible to establish which specific natural person the personal data refers to, provided that such additional information is stored separately and technical and organizational measures are taken to ensure that this personal data cannot be linked to identified or identifiable natural persons;
registration system:
the file of personal data in any way - centralized, decentralized or divided according to functional or geographical aspects - which is accessible based on specific criteria;
addressee:
the natural or legal person, public authority, agency or any other body to whom the personal data is communicated, regardless of whether it is a third party. Public authorities that have access to personal data in accordance with EU or member state law in the context of an individual investigation are not considered recipients; the handling of said data by these public authorities must comply with the applicable data protection rules in accordance with the purposes of the data management;
protest:
the statement of the data subject, with which he objects to the processing of his personal data and requests the termination of the data processing and the deletion of the processed data;
data controller:
the natural or legal person or organization without legal personality who, independently or jointly with others, determines the purpose of data management, makes and implements decisions regarding data management (including the device used), or has them implemented by the data processor it has commissioned
data management:
regardless of the procedure used, any operation or set of operations performed on the data, including, in particular, collection, recording, recording, organization, storage, change, use, query, transmission, disclosure, coordination or connection, locking, deletion and destruction, as well as preventing the further use of the data, taking photographs, audio or video recordings, physical characteristics suitable for identifying the person (for example, fingerprints or palm prints, DNA sample, iris image) recording;
data transmission:
making the data available to specific third parties;
Disclosure:
making the data available to anyone;
delete data:
rendering the data unrecognizable in such a way that their recovery is no longer possible;
data designation:
providing the data with an identification mark for the purpose of distinguishing it;
data lock:
providing the data with an identification mark for the purpose of limiting its further processing for a definitive or specified time;
data destruction:
physical destruction of the data carrier containing the data;
data processing:
performing technical tasks related to data management operations, regardless of the method and tool used to perform the operations, as well as the place of application, provided that the technical task is performed on the data;
data processor:
the natural or legal person or organization without legal personality who processes the data on the basis of the contract concluded with the data controller - including the conclusion of a contract based on the provisions of the law;
third person:
a natural or legal person, or an organization without legal personality, who is not the same as the data subject, data controller or data processor;
third country:
any non-EEA state.
Lawful data management by the data controller
Personal data will be processed by the data controller only in the following cases:
1. if the data subject has given his consent to the processing of his personal data for one or more specific purposes,
2. data management is necessary for the performance of a contract in which the data subject is one of the parties,
3. data management is necessary to fulfill the legal obligation of the data controller,
4. data processing is necessary to protect the vital interests of the data subject or another natural person,
5. data management is necessary to enforce the legitimate interests of the data controller or a third party.
The data controller examines the legality of data management in every phase of its activity, and only processes data for which it can prove its purpose and legal basis. In the event that a condition of a legal basis ceases, data processing can only be continued if the data controller can prove another suitable legal basis.
According to the main rule, the method of proving the legal grounds is in writing, even in the case of a legal basis created by suggestive conduct, it must be examined whether it can be clearly proved afterwards. In case of doubt, with regard to the aspects of reasonableness and economy, efforts should be made to confirm in writing the data management created by referring behavior.
In the case of data processing based on consent, the data subject gives his written consent to the processing of his personal data. Consent is not formally binding, but subsequent verifiability requires paper or electronic written consent.
Data processing based on the fulfillment of a legal obligation is independent of the data subject's consent, as data processing is defined by law.
Regardless of the mandatory nature of the data processing, the data subject must be informed before the data processing begins that the data processing is mandatory and cannot be avoided, and the data subject must be given clear and detailed information about all significant facts related to the processing of his data before the data processing begins.
According to the GDPR (General Data Protection Regulation), it is also possible to process personal data if the data processing is necessary for the performance of a contract in which the individual concerned is one of the parties, or the data processing or data collection is necessary to take steps at the request of the data subject prior to the conclusion of the contract. The data controller may process personal data for the purpose of concluding, fulfilling, or terminating the contract with the legal basis of performance of the contract.
Management of personal data by the data controller
Engineering consulting and fuel retail activities are at the disposal of its customers. The data manager comes into contact with the personal data of natural persons during the performance of these activities. It carries out the following data management activities:
The services and appointments available at the data controller can be obtained by telephone and via the website (www……………………..). When logging in, the data controller asks for the customer's name and phone number. The personal data is processed by the data manager in order to order the appropriate appointment with the client and ensure contact in the event of a change of appointment. The legal basis for the processing of personal data obtained in this way is the creation of a contract (Article 6 (1) point b) of the General Data Protection Regulation. If the data subject does not use the data manager's services at the scheduled time, the data manager will delete the personal data immediately, but no later than within 3 working days. The contractual relationship between the parties is actually established during the training session. The legal basis for the processing of personal data is the fulfillment of contractual obligations (Article 6 (1) point b) of the General Data Protection Regulation), and then the fulfillment of the obligations stipulated in the law during the issuance of the invoice (Article 6 (1) point c) of the General Data Protection Regulation). The invoice contains the name, address, and possibly tax number of the person concerned. The invoice is issued by the data controller with this legal basis in order to fulfill the legal obligation. Regarding the preservation of the personal data included in the account, the data manager acts in accordance with the provisions of the law and stores them for 8 years.
The contractual partners of the data controller can be both natural persons and legal entities. The conclusion of the contract is preceded by a request for an offer, in the form of a message received by telephone or e-mail, or by using the form on the website of the data controller (www………………..hu). The legal basis for the processing of personal data is the creation of a contract (Article 6 (1) point b) of the General Data Protection Regulation. If the data subject orders the offered service and accepts the General Terms and Conditions of the data controller, a contractual relationship is established between the parties. When the contracts are concluded, the data controller acquires additional personal data of individuals (partners and contacts). The legal basis for data management is the fulfillment of the contractual obligation (Article 6 (1) point b) of the General Data Protection Regulation), in the case of the contact person of the legal entity, the consent of the data subject (Article 6 (1) point a) of the General Data Protection Regulation). The data controller issues an invoice for the consideration for the services it provides. The invoice contains the name, address, and possibly tax number of the person concerned. Issuing the invoice is the legal obligation of the data controller. The legal basis for handling the personal data included in the account is therefore the fulfillment of a legal obligation (Article 6 (1) point c) of the General Data Protection Regulation). Regarding the preservation of the personal data included in the account, the data manager acts in accordance with the provisions of the law and stores them for 8 years.
In the course of performing its duties, the data controller manages the e-mail addresses and telephone numbers of its partners and principals, to fulfill its contractual obligations (Article 6 (1) point b) of the General Data Protection Regulation), or pursuant to their individual consent (Article 6 (1) point a) of the General Data Protection Regulation).
In the course of its work, the data controller may enter into a contractual relationship with subcontractors, suppliers and service providers, which also provides a basis for the management of personal data. In this case, the legal basis for the processing of personal data (in the case of an individual or sole trader) is the fulfillment of the contractual obligation (Article 6 (1) point b) of the General Data Protection Regulation), the express, informed consent of the person concerned in relation to the personal data of the contact person of the legal entity (Article 6 (1) point a) of the General Data Protection Regulation).
On the website, the site visitor has the opportunity to contact the data controller and book an appointment. The name, e-mail address and telephone number of the interested party must be entered on the form. The purpose of handling personal data is to contact the website visitor and the person interested in the services of the data manager. If the service is not ordered after the contact, the personal data of the interested party will be deleted immediately, but no later than within 3 working days. The data controller processes personal data with this legal basis in order to conclude the contract (Article 6 (1) point b) of the General Data Protection Regulation). By booking the appointment, the data subject declares that he has read the Data Management Information of the data controller and has taken note of its contents.
On the website of the data controller, it is possible to subscribe to the newsletter by entering an e-mail address. When subscribing to the newsletter, the data subject declares that he has read the information contained in the Data Management Information of the data controller, as well as whether he gives his consent to the processing of his personal data for marketing purposes. The data subject is entitled to the rights described in the Data Management Notice and has the opportunity to exercise these rights in the manner and places described therein. Accordingly, the legal basis for the processing of personal data during the sending of the newsletter is the express and written consent of the subscriber based on adequate information (General Data Protection Regulation Article 6 (1) point a)).
The data controller also operates social media pages for marketing purposes in order to present its activities and services. The data of the followers of the pages is also processed here. The legal basis for data management is the consent of the data subject (Article 6 (1) point a) of the General Data Protection Regulation.
During the handling of complaints related to the activity of the data controller, the purpose of data handling is to enable the communication of the complaint, to identify the person concerned and his complaint, as well as to record the data that must be recorded according to law, as well as to investigate the complaint and maintain contact related to its settlement. In the event of a complaint, the administration, and thus the handling of personal data - CLV of 1997 on consumer protection. by law - mandatory. Pursuant to this, the legal basis for the processing of personal data is the fulfillment of the obligation written in the law (General Data Protection Regulation Article 6 (1) point c)).
The data controller keeps a data management record of the above-mentioned data management. The register also contains the deadlines for deleting personal data. The register forms an appendix to this Data Management Information.
Data processors
If the data management is carried out by someone else on behalf of the data controller, the data controller can only use data processors that provide adequate guarantees for compliance with the requirements of the General Data Protection Regulation, or implement appropriate technical and organizational measures that ensure the protection of the rights of the data subjects.
The data controller hereby declares that, in the course of his work, he only contacts data processors who have a suitable guarantee of compliance with the GDPR regulation and the implementation of appropriate technical and organizational measures ensuring the protection of the rights of the data subjects. The relevant declarations of the data processors are available.
The contracted data processing and data management partners manage the personal data of the partners solely on the basis of the instructions given by the data manager (except for the application of legal requirements), assuming an obligation of confidentiality.
By reading and taking note of this Data Management Information, the affected parties accept that the data controller will forward their personal data to the data processors and joint data controllers listed below.
Data processor is the accounting firm employed by the data controller:
ZÉTA-DÓ Könyvelő és Dótácsadó Kft.
6000 Kecskemét, Vágó u 2-4.
Regarding the issuance of invoices, the data controller's partner:
KBOSS.hu Kft.
1031 Budapest, Záhony utca 7.
The company providing the hosting of the website of the data controller is also considered a data processor:
…………………………………………………………………………..
Due to the use of the Google Analytics service used by the website of the data controller, the data processor:
Google Ireland Limited
Gordon House, Barrow Street, Dublin 4, Ireland
The server of the data controller's mail system is also a data processor:
Google Ireland Limited
Gordon House, Barrow Street, Dublin 4, Ireland
Due to the use of the Facebook page and group, as well as the social plug-ins built into the website, data processing and joint data management partner:
Facebook Ireland Ltd.
4 Grand Canal Square, Grand Canal Harbour, Dublin 2 Ireland
Visitor data management on the company's website
Cookies are short data files placed on the user's computer by the visited website. The purpose of the cookie is to make the given information communication and Internet service easier and more convenient. There are many types, but they can generally be classified into two large groups. One is the temporary cookie, which the website places on the user's device only during a specific session (e.g. during the security identification of internet banking), the other type is the permanent cookie (e.g. language setting of a website), which remains on the computer until the user deletes it. Based on the guidelines of the European Commission, cookies [unless they are absolutely necessary for the use of the given service] can only be placed on the user's device with the user's permission.
In the case of cookies that do not require the user's consent, information must be provided during the first visit to the website. It is not necessary for the full text of the information regarding cookies to appear on the website, it is sufficient if the website operators briefly summarize the essence of the information and refer to the availability of the full information via a link.
In the case of cookies that require consent, the information can also be linked to the first visit to the website, in the event that the data management associated with the use of cookies already begins with the visit to the page. If the application of the cookie is related to the use of a function specifically requested by the user, then the information may also appear in connection with the use of this function. In this case too, it is not necessary for the full text of the information about cookies to appear on the website, a short summary of the essence of the information and a reference to the availability of the full information through a link are sufficient.
The visitor must be informed about the use of cookies on the website in the data management information sheet. With this information, the Company ensures that the visitor can learn, before using the information society-related services of the website and at any time during the use, which types of data the Company manages for which data management purposes, including the management of data that cannot be directly linked to the user.
Community guidelines / Data management on the Company's Facebook page
The Company maintains a Facebook page for the purpose of introducing and promoting its products and services.
A question on the Company's Facebook page is not considered an officially submitted complaint.
(The Company does not manage personal data published by visitors on the Company's Facebook page.
Visitors are governed by Facebook's Privacy and Terms of Service. In case of publication of illegal or offensive content, the Company may exclude the person concerned from membership or delete his/her comments without prior notice.
The Company is not responsible for data content and comments posted by Facebook users that violate the law. The Company is not responsible for any errors, malfunctions or problems arising from changes to the operation of the system resulting from the operation of Facebook.
Data management related to the operation of the entry system
Access rights to the website can be purchased on the website of the data controller.
The fulfillment of the data management contract handles the following data as a legal title: buyer's basic data, which must be entered for the purchase: email, name, address, , in the case of a company: company name, Tax number, data registering the success of the transaction: transaction ID, service provider status, time, internal transaction data, in the case of an invoice, account identifier, Access code. Data of purchased products: Product name, product sku, net, gross quantity.
Recipients of personal data: the company's employees performing tasks related to customer service, employees performing accounting and taxation tasks, and data processors, as well as employees of the company operating the online payment system.
Duration of processing personal data: 5 years after the termination of the contract.
The data subject must be informed before the start of data management that the data management is based on the legal title of the performance of the contract, this information can also be provided in the contract.
Data management related to the organization of a prize draw
If the company organizes a prize draw (§ 23 of Act XXXIV of 1991), it may process the name, address, telephone number, e-mail address, and online ID of the natural person concerned based on their consent. Participation in the game is voluntary. Data management consent can be requested with the content of the data request form according to Annex No. 1 of these regulations.
The purpose of handling personal data is to determine and notify the winner of a prize draw, and to send the prize. Legal basis for data management: the consent of the data subject.
Recipients of personal data and categories of recipients: employees of the Company performing tasks related to customer service, employees of the Company's IT service provider providing server services as data processors, employees of the courier service.
Duration of storage of personal data: until the end of the gift list.
Data management for direct marketing purposes
If a separate law does not provide otherwise, advertising by the method of directly contacting a natural person as the recipient of the advertisement (direct acquisition of business), especially by electronic mail or other equivalent means of individual communication - Act XLVIII of 2008. with the exception defined by law - it can only be disclosed if the recipient of the advertisement clearly and specifically consented to it in advance.
The range of personal data that can be processed by the Company for the purpose of advertising recipient inquiries: the natural person's name, address, telephone number, e-mail address, online identifier.
The purpose of processing personal data is to carry out direct marketing activities related to the Company's activities, i.e. regular or periodic sending of advertising publications, newsletters, current offers in printed (postal) or electronic form (e-mail) to the contact details provided during registration.
Legal basis for data management: the consent of the data subject.
Recipients of personal data and categories of recipients: employees of the Company performing tasks related to customer service, employees of the Company's IT service provider providing server services as data processors, employees of the Post Office in the case of postal delivery.
Duration of storage of personal data: until consent is revoked.
The data request form according to Annex 1 of these regulations can be used for consent to data management for direct marketing purposes.
The contact form used on the website
On the data manager's website, the visitor can contact the data manager. You can use the contact form to indicate your interest in the data controller's services. The visitor's name, e-mail address, and telephone number must be entered on the contact form. By filling out the form, the data subject declares that he has read the data controller's Data Management Information. The personal data provided for such a purpose is processed by the data controller solely for the purpose of establishing the connection. After the contact, the data controller will delete the personal data of the interested party immediately, but no later than within 3 working days. Data management is carried out in order to create a contract with this legal basis (Article 6 (1) point b) of the General Data Protection Regulation.
In connection with the use of the customer contact data sheet on the website of the data controller, the data subject declares that he has reached the age of 16. A person under the age of 16 may not contact the data controller on the customer contact data sheet, given that, based on Article 8 (1) of the GDPR, the consent of their legal representative is required for the validity of their legal declaration containing their consent to data management. The data controller has no way to check the consenting person's age and eligibility, so the data subject guarantees that the data provided is true.
Newsletters
On the website of the data controller, visitors can also subscribe to a newsletter. When subscribing to the newsletter, the visitor declares that he has read the data controller's Privacy Policy, as well as whether he consents to the processing of his personal data for marketing purposes (for the purpose of sending a newsletter). The data subject is entitled to the rights described in the Data Management Notice and has the opportunity to exercise these rights in the manner and places described therein. Accordingly, the legal basis for the processing of personal data during the sending of the newsletter is the express and written consent of the subscriber (General Data Protection Regulation Article 6 (1) point a)).
The purpose of data management related to sending the newsletter is to provide the recipient with full general or personalized information about the news, latest events and news appearing on the website, in accordance with the relevant and effective legislation. Signing up for the newsletter and/or DM mailing is based on voluntary consent, the data controller naturally gives the data subject the option to withdraw their consent and unsubscribe from the newsletter at any time.
In relation to subscribing to the newsletter on the website of the data controller, the data subject declares that he has reached the age of 16. Persons under the age of 16 may not subscribe to the newsletter, given that, based on Article 8 (1) of the GDPR, the consent of their legal representative is required for the validity of their legal declaration containing their consent to data processing. The data controller has no way to check the consenting person's age and eligibility, so the data subject guarantees that the data provided is true.
Data security measures
For the security of personal data, the company is obliged to take the technical and organizational measures and establish the procedural rules necessary to implement the Regulation and Infotv.
The Data Controller uses appropriate measures to protect the data against accidental or unlawful destruction, loss, alteration, damage, unauthorized disclosure or unauthorized access.
The company classifies and manages personal data as confidential data. It imposes a confidentiality obligation on employees regarding the handling of personal data, to which the stipulation according to Annex No. 10 must be applied. Access to personal data is restricted by the enterprise by specifying authorization levels.
The company protects IT systems with a firewall and virus protection.
The company performs electronic data processing and registration using a computer program that meets the requirements of data security. The program ensures that only those persons who need it in order to perform their duties have access to the data under controlled conditions.
During the automated processing of personal data, the data controller and the data processor ensure with additional measures:
a) preventing unauthorized data entry;
b) preventing the use of automatic data processing systems by unauthorized persons using data transmission equipment;
c) the verifiability and ascertainability of which bodies the personal data have been or may be transmitted using data transmission equipment;
d) the verifiability and ascertainability of which personal data was entered into the automatic data processing systems, when and by whom;
e) the restoreability of the installed systems in the event of a malfunction and
f) that a report is prepared on errors occurring during automated processing.
In order to protect personal data, the company ensures the control of incoming and outgoing electronic communications.
Only the competent administrators can access the work in progress and the documents being processed, and the documents containing personnel, wage and labor and other personal data must be kept securely locked away.
Adequate physical protection of the data and the devices and documents carrying them must be ensured.
Rights and Remedies
Right to prior information
The data subject has the right to receive information about the facts and information related to data processing before the data processing begins.
The data subject's right of access
The data subject is entitled to receive feedback from the Data Controller as to whether his personal data is being processed, and if such data processing is underway, he is entitled to access the personal data and related information specified in the Regulation.
Right to rectification
The data subject has the right to request that the Data Controller correct inaccurate personal data relating to him without undue delay. Taking into account the purpose of the data management, the data subject is entitled to request the completion of incomplete personal data - among other things, by means of a supplementary statement.
The right to erasure ("the right to be forgotten")
1. The data subject has the right to request that the Data Controller delete the personal data concerning him without undue delay, and the Data Controller is obliged to delete the personal data concerning the data subject without undue delay if one of the reasons specified in the Order exists.
The right to restrict data processing
The data subject has the right to request that the Data Controller restricts data processing if the conditions specified in the regulation are met.
Notification obligation related to the correction or deletion of personal data or the limitation of data management
The Data Controller informs all recipients of all corrections, deletions or data management restrictions to whom or to whom the personal data was communicated, unless this proves to be impossible or requires a disproportionately large effort. At the request of the data subject, the Data Controller informs about these recipients.
The right to data portability
Under the conditions set out in the Regulation, the data subject is entitled to receive the personal data concerning him/her provided to a Data Controller in a segmented, widely used, machine-readable format, and is also entitled to forward this data to another Data Controller without being hindered by the Data Controller to whom the personal data was provided.
The right to protest
The data subject has the right to object to his personal data at any time for reasons related to his own situation under point e) of Article 6 (1) of the Regulation (data processing is in the public interest or necessary for the execution of a task carried out in the context of the exercise of public authority vested in the Data Controller) or point f) (data processing is necessary to enforce the legitimate interests of the Data Controller or a third party.
Automated decision-making in individual cases, including profiling
The data subject has the right not to be covered by the scope of a decision based solely on automated data management - including profiling - that would have legal effects on him or affect him to a similar extent.
Restrictions
The EU or Member State law applicable to the Data Controller or data processor may limit the provisions of Articles 12-22 through legislative measures. Article and Article 34, as well as Articles 12-22. in accordance with the rights and obligations defined in Article
Remedies
If you notice data processing that violates your rights, it is advisable to send your comments to the head of the company before starting legal proceedings, as this will allow the Data Controller to restore the legal status by itself.
In case of unlawful data processing you have experienced, you can initiate a civil lawsuit in court. Adjudication of the lawsuit falls within the jurisdiction of the court. The lawsuit - according to your choice, can also be initiated before the court of your place of residence. You can view the list of courts and their contact information via the following link: http://birosag.hu/torvenyszekek
In case of illegal data processing, you can initiate an investigation at the supervisory authority (NAIH), whose contact details are as follows:
President of the National Data Protection and Freedom of Information Authority (NAIH):
Dr. Attila Péterfalvi
NAIH's mailing address: 1363 Budapest, Pf. 9.
address: 1055 Budapest, Falk Miksa u. 9-11
phone number: +36 1 391 1400
fax: +36 1 391 1410
Website: http://www.naih.hu
email address: ugyfelszolgalat@naih.hu
Data protection incident
Data protection incident: a breach of security that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure or unauthorized access to personal data transmitted, stored or otherwise handled.
The most frequently reported incidents can be, for example: the loss of a flash drive, laptop or mobile phone, unsafe storage of personal data (e.g. payment papers thrown in the trash); unsafe transmission of data, unauthorized copying and transmission of patient-client and customer-partner lists, attacks against servers, website hacking.
The prevention and management of data protection incidents and compliance with the relevant legal regulations are the responsibility of the company manager.
Accesses and access attempts must be logged on the IT systems and analyzed continuously.
If the employees of the data controller who are entitled to control detect a data protection incident during the performance of their duties, they must immediately notify the manager of the Service Provider.
The employees of the data controller are obliged to report to the head of the company or to the employer's rights practitioner if they notice a data protection incident or an incident indicating it.
A data protection incident can be reported to the company's central e-mail address and telephone number, where employees, contracting partners, and stakeholders can report the underlying incidents and security weaknesses.
In the event of a data protection incident being reported, the head of the company - if necessary with the involvement of the IT and operations manager - will immediately examine the report, during which the incident must be identified and a decision must be made as to whether it is a real incident or a false alarm. It must be examined and determined:
- the time and place of the incident,
- the description, circumstances and effects of the incident,
- the scope and number of data compromised during the incident,
- the range of persons affected by the compromised data,
- a description of the measures taken to prevent the incident,
- a description of the measures taken to prevent, eliminate and reduce the damage.
In the event of a data protection incident, the affected systems, persons, and data must be delimited, separated, and evidence supporting the occurrence of the incident must be collected and preserved. After that, you can begin to repair the damage and restore legal operation.
A record of data protection incidents must be kept, which includes:
- the range of personal data concerned,
- the scope and number of those affected by the data protection incident,
- the date of the data protection incident,
- the circumstances and effects of the data protection incident,
- the measures taken to remedy the data protection incident,
- other data specified in the legislation prescribing data management.
Data relating to data protection incidents in the register must be kept for 5 years. The details of the incidents are contained in the "Registry of Data Protection Incidents".
Data protection incidents likely to pose a risk to the rights and freedoms of natural persons are reported by the data controller to the competent supervisory authority on the basis of Article 33 (1) of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR).
The GDPR requires the data controller to report the data protection incident to the competent supervisory authority without undue delay and, if possible, no later than 72 hours after becoming aware of the data protection incident.
The National Data Protection and Freedom of Information Authority (hereinafter: NAIH) has prepared the NAIH Incident Reporting System, a unified online interface available at the link below, for the purpose of fulfilling the notification obligation electronically, in view of the minimum content elements of the data protection incident notification found in Article 33 (3) of the GDPR.
http://www.naih.hu/adatvedelmi-incidensbejelento-rendszer.html
For data controllers who wish to report a data protection incident on paper, the NAIH provides a notification form available at the link.
