§ 1

The purpose of the Personal Data Protection Policy, hereinafter referred to as the “Policy”, in the enterprise Angelika Krupińska “Amanda” Trading Enterprise, ul. Kaliny 95/28, 41-506 Chorzów, is to achieve a method of processing information containing personal data that complies with the requirements of applicable legal acts.

§ 2

  1. Personal data protection is implemented through physical safeguards, organizational measures, system software, applications and users, proportionate and adequate to the risk of a breach of the security of personal data processed within the scope of the business activity conducted.
  2. The controller of personal data processed in the enterprise Angelika Krupińska “Amanda” Trading Enterprise, ul. Kaliny 95/28, 41-506 Chorzów, is Angelika Krupińska.

§ 3

  1. The safeguards applied in Angelika Krupińska “Amanda” Trading Enterprise are intended to ensure:
    1. data confidentiality – understood as a property ensuring that data is not made available to unauthorized persons;
    2. data integrity – understood as a property ensuring that personal data has not been altered or destroyed in an unauthorized manner;
    3. data accountability – understood as a property ensuring that a person’s actions can be attributed unambiguously only to that person;
    4. system integrity – understood as the inviolability of the system, the impossibility of any manipulation, whether intentional or accidental;
    5. information availability – understood as ensuring that authorized persons have access to information and related resources when needed;
    6. risk management – understood as the process of identifying, controlling and minimizing or eliminating security risks that may affect information systems used for processing personal data.
  2. The implementation of the above objectives should be guaranteed by the following assumptions:
    1. implementation of procedures defining the conduct of persons permitted to process personal data and their responsibility for the protection of such data.
    2. training users in the field of security and personal data protection.
    3. assigning users specific attributes enabling their identification (passwords, identifiers).
    4. taking necessary actions to eliminate weak links in the security system,
    5. periodic verification of users’ compliance with the implemented procedures for processing personal data.

§ 4

The terms used in the Policy shall be understood as follows:

  1. personal data controller – a natural or legal person, public authority, unit or other entity which, alone or jointly with others, determines the purposes and means of the processing of personal data,
  2. the Act – the Act of 10 May 2018 on the protection of personal data (Journal of Laws of 2018, item 1000)
  3. GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (OJ EU L No. 119, p. 1),
  4. personal data – any information relating to an identified or identifiable natural person,
  5. processing of data – an operation or set of operations performed on personal data in an automated or non-automated manner, such as collection, recording, storage, development, combination, transmission, alteration, disclosure and deletion, destruction, etc.,
  6. information system – a set of cooperating devices, programs, information processing procedures and software tools used for the processing of personal data,
  7. traditional system – a set of organizational procedures related to the mechanical processing of information, as well as equipment and fixed assets used for the processing of personal data on paper,
  8. data security in an information system – the implementation and operation of appropriate technical and organizational measures ensuring protection of data against unauthorized processing,
  9. recipient – a natural or legal person, public authority, unit or other entity to whom personal data is disclosed on the basis of, inter alia, a data processing agreement,
  10. third party – a natural or legal person, public authority, unit or entity other than the data subject, which, under the authorization of the personal data controller, may process personal data,
  11. user – a person authorized to process personal data,
  12. RCPD or register means the register of personal data processing activities. The register of activities constitutes Annex 1 to this Policy.

§ 5

  1. In Angelika Krupińska “Amanda” Trading Enterprise, personal data of customers, business partners, employees and job applicants are processed.
  2. This information is processed both in paper and electronic form.
  3. The Policy contains provisions regarding the implemented technical and organizational safeguards ensuring the protection of processed personal data.
  4. Other documents regulating the protection of personal data in Angelika Krupińska “Amanda” Trading Enterprise are:
    1. Register of personal data processing activities,
    2. Procedure for handling personal data breaches,
    3. Privacy Policy

§ 6

The Policy applies in particular to:

  1. personal data processed in the Microsoft Office system,
  2. all information concerning customer, employee, job applicant and business partner data
  3. recipients of personal data to whom personal data has been transferred for processing on the basis of data processing agreements
  4. information concerning the security of personal data, including in particular account names and passwords in personal data processing systems,
  5. other documents containing personal data.

§ 7

  1. The scope of personal data protection defined by the Policy and other related documents applies to:
    1. all existing, currently implemented or future information systems and paper-based systems in which protected personal data are processed,
    2. all locations – buildings and rooms in which protected information is or will be processed,
    3. all employees, interns and other persons having access to protected information.
  2. All persons having access to protected personal data are obliged to comply with the rules set out in the Policy and other related documents.

§ 8

  1. In Angelika Krupińska “Amanda” Trading Enterprise, personal data are processed with respect for the following principles:
    1. on the basis of a legal basis and in accordance with the law (lawfulness)
    2. fairly and honestly (fairness)
    3. in a transparent manner for the data subject (transparency)
    4. in specific purposes and not “in advance” (minimization)
    5. no more than necessary (adequacy)
    6. with due care for accuracy (accuracy)
    7. no longer than necessary (storage limitation)
    8. ensuring appropriate data security (security)

§ 9

Personal data are collected in the following sets:

  1. Civil-law contracts - paper documentation
  2. Contracts concluded with clients - paper documentation
  3. Employment contracts - paper documentation
  4. Client register - electronic form
  5. Archival documents - paper documentation
  6. Accounting documents - paper and electronic documentation

§ 10

  1. In particular, a breach of personal data protection shall be understood as:
    1. unauthorized access or attempted access to personal data or to the premises where they are located
    2. breach or attempted breach of data integrity, understood as any modifications, destruction or attempts thereof by unauthorized persons or authorized persons acting in bad faith or as an error in the actions of an authorized person (e.g. changing the content of data, loss of all or part of the data),
    3. breach or attempted breach of system integrity
    4. change or loss of data stored on backups,
    5. breach or attempted breach of data confidentiality,
    6. unauthorized access (a signal of illegal login or another symptom indicating an attempt or action related to illegal access to the system),
    7. making personal data available to unauthorized persons
    8. destruction, damage or any attempts of unauthorized interference with the IT system aimed at disrupting its operation or obtaining data contained in the system in an unauthorized manner or for purposes inconsistent with its intended use,
    9. any other state of the IT system or premises than that left by the user after finishing work.
    10. a breach of personal data protection shall also be understood as a break-in to the building or premises where personal data are processed, or attempts at such actions
  2. In the event of a breach being identified:
    1. the IT system security,
    2. the technical condition of devices,
    3. the content of the personal data set,
    4. the disclosure of the working method or the way the program operates,
    5. the quality of data transmission in the telecommunications network that may indicate a breach of the security of such data,
    6. other events that may affect the breach of personal data (e.g. flooding, fire, etc.), every person employed in data processing is obliged to immediately notify the Data Controller of this fact.
  3. Against a person who, in the event of a breach of IT system security or a justified presumption of such a breach, failed to take the action specified in this document, and in particular failed to notify the appropriate person in accordance with the specified rules, disciplinary or order proceedings shall be initiated.
  4. Cases of unjustified failure to perform the duties arising from this document may be treated as a serious breach of employee duties.

§ 11

Any person whose personal data are processed has the right to control the processing of their personal data, and in particular the right to:

  1. obtain comprehensive information whether their personal data are being processed and to receive information about the full name and registered office address of the data controller;
  2. obtain information about the purpose, scope and manner of processing personal data;
  3. obtain information as to when their personal data have been processed, and to have the content of such data provided in a generally understandable form;
  4. obtain information about the source from which the personal data concerning them originate;
  5. obtain information about the manner in which personal data are made available, and in particular information about the recipients or categories of recipients to whom such personal data are disclosed;
  6. request supplementation, updating, rectification of personal data, temporary or permanent suspension of their processing or their deletion, if they are incomplete, outdated, untrue or were collected in violation of

§ 12

Personal data are processed in the premises located at Kaliny 95/28 Street, 41-506 Chorzów.

§ 13

In order to increase the effectiveness of personal data protection, various safeguards have been combined in a way that enables the creation of several layers of protection.

  1. Organizational safeguards:
    1. a Personal Data Protection Policy has been developed and implemented,
    2. a procedure for handling a personal data protection breach has been created,
    3. the register of processing activities has been developed and is kept up to date (the template constitutes Appendix No. 1 to this Policy)
    4. persons employed in data processing have been familiarized with the regulations concerning personal data protection and with the security of the IT system,
    5. persons employed in personal data processing have been obliged to keep them confidential,
    6. personal data processing is carried out under conditions that protect the data against access by unauthorized persons,
    7. the presence of unauthorized persons in rooms where personal data are processed is permitted only in the presence of a person employed in personal data processing and under conditions ensuring data security,
    8. documents and information media containing personal data that are to be destroyed are neutralized using devices intended for this purpose or modified in such a way that their content cannot be reconstructed.
  2. Technical safeguards:
    1. the router has been secured by separating it from the public network using specialized firewall software,
    2. computer workstations have been equipped with individual antivirus protection,
    3. computers have been secured against use by persons not authorized to process personal data, by means of an individual user identifier,
    4. personal data transmitted electronically will be appropriately secured
  3. Physical protection measures:
    1. devices used for processing personal data are located in lockable rooms,
    2. documents and information media containing personal data are stored in lockable cabinets,
    3. only authorized employees and associates have access to the keys
    4. paper documents may be kept on desks only for the time necessary to perform official duties, and then must be put away in cabinets,
    5. computer monitors on which data are processed are positioned so that unauthorized persons cannot view the data,
    6. incorrect or outdated printouts and paper versions containing personal data or other protected information are destroyed using a shredder or by another mechanical means preventing their reconstruction.

§ 14

  1. Video surveillance is in operation on the premises of Angelika Krupińska “Amanda” Przedsiębiorstwo Handlowe.
  2. Data obtained from video surveillance are stored for a period no longer than 3 months from the date of recording.
  3. The monitored area is appropriately marked in accordance with Article 222 §§ 9 and 10 of the Labour Code.

§ 15

 

  1. The Policy has been developed on the basis of the requirements contained in:
    1. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (OJ EU L No. 119, p. 1),
    2. Act of 10 May 2018 on the protection of personal data (Journal of Laws of 2018, item 1000),
  2. The Policy is an internal document and may not be made available to unauthorized persons in any form.
  3. Users are obliged to familiarize themselves with the content of the Policy.
  4. The User is obliged to submit a statement that they have been acquainted with the GDPR provisions, the Personal Data Protection Act and the implementing regulations issued on its basis, with this Policy, and to undertake to comply with them.
  5. In matters not regulated in this Policy, the currently applicable legal provisions in the field of personal data protection shall apply.
  6. Users are obliged to strictly apply, when processing data, the provisions contained in this Policy. In the event of regulations different from those contained in this Policy appearing in other procedures applicable to the data controller, users are obliged to apply the more far-reaching provisions, the application of which will ensure a higher level of information protection.

Attachment:

  1. Template of the Record of Processing Activities