operations:policy:privacy_regulations
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
operations:policy:privacy_regulations [2023-12-14 11:30] – ↷ Links adapted because of a move operation hpoort | operations:policy:privacy_regulations [2024-07-02 07:35] (current) – hpoort | ||
---|---|---|---|
Line 1: | Line 1: | ||
====== Privacy Regulations | ====== Privacy Regulations | ||
- | The Privacy Regulations are a company wide document that governs how FritsJurgens deals with GDPR-qualifying personal data. It is one of the policies governed by the [[: | + | The Privacy Regulations are a company-wide document that governs how FritsJurgens deals with GDPR-qualifying personal data. It is one of the policies governed by the [[: operations|Operations circle]]. |
- | {{: | + | {{: |
---- | ---- | ||
- | FIXME | + | This policy is based on the General Data Protection Regulation (GDPR: [[https:// |
- | Naar dit reglement wordt verwezen vanuit: | + | This are the privacy regulations for the protection of personal privacy in the context of personal registration and apply to the services provided by FritsJurgens. |
- | - [[https:// | + | |
- | - Website (of op de website moet een variant komen met alleen het publieke gedeelte) | + | |
- | - Diverse wiki-pagina' | + | |
- | Wat moet hier in komen te staan: | + | Responsible publisher: FritsJurgens |
- | * Volgens de samenvatting: | + | |
- | * Alle medewerkers van FritsJurgens | + | |
- | * Alle medewerkers van FritsJurgens zijn tot geheimhouding verplicht, ook na beëindiging van het dienstverband bij FritsJurgens. | + | |
- | * Dat gegevens alleen geregistreerd, | + | |
- | * Welke persoonsgegevens geregistreerd worden en welke gegevens met andere partijen gedeeld mogen worden. | + | |
- | * Dit laatste moet een volledige opsomming zijn, met naam en toenaam van de externe partijen | + | |
- | * Betreffende gegevens van medewerkers | + | |
- | * We registeren: | + | |
- | * Voor salaris: NAW, Burgerservicenummer, | + | |
- | * In geval van ziekteverzuim: | + | |
- | * Voor de interne communicatie: | + | |
- | * Voor bedrijfsactiviteiten: | + | |
- | * Voor noodgevallen: | + | |
- | * In verband met dienstverband delen we gegevens met: | + | |
- | * Salarisadministratie (Mulderij & Partners): voor de salarisadministratie. Zij gebruiken het online-salarisadministratiepakket Loket.nl. De salarisadministratie geeft de wettelijk vereiste gegevens ook door aan de Belastingdienst. | + | |
- | * Pensioenfonds (ASR): uitsluitend voor de initiële aanmelding bij hen (jijzelf geeft hen daarna de toestemming om je gegevens te verwerken en door te geven aan de salarisadministratie; | + | |
- | * Evt. Ziekteverzuimverzekeraar (deze hebben we nu niet): Dit betreft persoonsgegevens zoals NAW, BSN, Salaris en ziekteverzuimpercentage. | + | |
- | * Arbodienst: De arbodienst krijgt inzage | + | |
- | * Evt. Verzuimbegeleiding (Alpina@Work): | + | |
- | * Accountant (Afier): De accountant heeft inzage in en krijgt een kopie van de gehele boekhouding waar o.a. de salarisadministratie deel van is. | + | |
- | * In verband met de werkzaamheden delen we gegevens met: | + | |
- | * IT-partner (MatenICT), softwareleveranciers (Microsoft, Zoho, < | + | |
- | * Collega' | + | |
- | * Organisator bedrijfsuitjes: | + | |
- | * Onderaannemers en bij FritsJurgens gedetacheerden: | + | |
- | * Klanten: uitsluitend naam, functie, zakelijk mailadres en werkrooster. | + | |
- | * Website: de naam en functie van de medewerker. | + | |
- | * Noodcontact: | + | |
- | * Betreffende gegevens van potentiële klanten en netwerkcontacten: | + | |
- | * We registreren: | + | |
- | * Naam, zakelijke contactgegevens, | + | |
- | * Alle communicatie (e-mails, chats, telefoonnotities) | + | |
- | * Alle overige informatie die we door deze klanten zelf aangeboden krijgen, inclusief zoekgedrag op onze website en media-uitingen | + | |
- | * Bedrijfsgegevens inclusief dat wat we door dataverrijking vanuit publiekelijk toegankelijke internetbronnen kunnen vinden | + | |
- | * FIXME | + | |
- | * We gebruiken: | + | |
- | * Deze gegevens voor marktanalyse | + | |
- | * Nieuwsbrieven alleen indien aangemeld | + | |
- | * FIXME | + | |
- | * We delen: | + | |
- | * Naam, zakelijke contactgegevens en vraag met de dealer in de regio of het toepassingsgebied van de klant (na toestemming) | + | |
- | * FIXME | + | |
- | * Betreffende gegevens van werkelijke klanten: | + | |
- | * Naam, adres en zakelijke contactgegevens | + | |
- | * Van bedrijven: BTW-nummer indien in EU, betalingsgegevens, | + | |
- | * FIXME | + | |
+ | |||
+ | ===== 1. Definitions | ||
+ | |||
+ | In this policy, the following terms are defined: | ||
+ | |||
+ | ^ Term ^ {{: | ||
+ | ^ Privacy | ||
+ | ^ FritsJurgens | ||
+ | ^ Data Subject | ||
+ | ^ Data Controller | ||
+ | ^ Processor | ||
+ | ^ Processor Supervisor | ||
+ | ^ Recipient | ||
+ | ^ Personal Data | // | ||
+ | ^ Health Data | //health data// | ||
+ | ^ Processing of Personal Data | // | ||
+ | ^ Consent | ||
+ | ^ Confidentiality | ||
+ | |||
+ | Throughout the policy, for some words, the Dutch translation is given in italics, to clarify. | ||
+ | |||
+ | |||
+ | ===== 2. Scope ===== | ||
+ | |||
+ | - This policy applies to all paper files, all digital files, and unwritten information within FritsJurgens, | ||
+ | - FritsJurgens processes information in the following categories: | ||
+ | * [[operations: | ||
+ | * for personel also date of birth and social security number (// | ||
+ | * [[operations: | ||
+ | * [[operations: | ||
+ | * [[operations: | ||
+ | - This policy applies within FritsJurgens and relates to the processing of personal data of: | ||
+ | * [[operations: | ||
+ | * [[operations: | ||
+ | * [[operations: | ||
+ | * [[operations: | ||
+ | * [[operations: | ||
+ | |||
+ | |||
+ | ===== 3. Purpose | ||
+ | |||
+ | - The purpose of collecting and processing personal data is to have the necessary information for conducting market analysis, sending newsletters (if subscribed), | ||
+ | - The data of potential customers and network contacts are collected and processed for: | ||
+ | - Market analysis. | ||
+ | - Sending newsletters (if subscribed). | ||
+ | - Referrals. | ||
+ | - The data of debtors (i.e. customers), are collected and processed for: | ||
+ | - Executing and communicating about provided orders. | ||
+ | - Invoicing and receiving payment. | ||
+ | - Discussing potential new orders. | ||
+ | - The data of creditors (i.e. suppliers and subcontractors), | ||
+ | - Executing and communicating about provided orders. | ||
+ | - Paying invoices and accounting for payments. | ||
+ | - Discussing deliveries or services. | ||
+ | - The data of employees are collected and processed for: | ||
+ | - Making and executing an employment or internship agreement. | ||
+ | - Conducting payroll administration. | ||
+ | - Collaborating as colleagues. | ||
+ | - Being prepared for emergencies. | ||
+ | - The data of employee' | ||
+ | - Communicating in case of emergencies. | ||
+ | - Implementing ' | ||
+ | |||
+ | |||
+ | |||
+ | ===== 4. Representation | ||
+ | |||
+ | The subject whose personal data are recorded may be represented: | ||
+ | * If younger than sixteen years: by their parent or guardian (such as name and age of employee' | ||
+ | * If under legal restrictions: | ||
+ | |||
+ | |||
+ | |||
+ | ===== 5. Responsibility for maintenance and liability | ||
+ | |||
+ | - The management is responsible for ensuring the proper processing and management of personal data and can be held liable for it, except in case of force majeure. | ||
+ | |||
+ | |||
+ | ===== 6. Access to data ===== | ||
+ | |||
+ | Access to the data is restricted to employees having certain roles grouped in so-called circles of accountability, | ||
+ | |||
+ | ^ Role ^ Purpose | ||
+ | | People & Culture recruiting | ||
+ | | People & Culture contracting | ||
+ | | Hero' | ||
+ | | BD | responsible for regions | ||
+ | | Sales | responsible for sales | all data of customers | ||
+ | | Marketing | ||
+ | | Support | ||
+ | | Operations | ||
+ | |||
+ | |||
+ | ===== 7. Sharing data ===== | ||
+ | |||
+ | * Regarding employment, we share data with: | ||
+ | * Payroll administration // | ||
+ | * Pension Fund // | ||
+ | * Possible Sick Leave Insurance // | ||
+ | * Occupational Health Service // | ||
+ | * Possible Absence Guidance // | ||
+ | * Accountant ([[https:// | ||
+ | * For work-related activities, we share data with: | ||
+ | * IT partner ([[https:// | ||
+ | * Colleagues i.e. all employees and interns within FritsJurgens. Through the administration package, all employees have access to all colleagues' | ||
+ | * Organizer of company outings: name, dietary preferences, | ||
+ | * Subcontractors and FritsJurgens seconded employees: considered external colleagues. The administration ensures that these external colleagues have access to the business contact details of the employees they are dealing with. | ||
+ | * Customers: only name, position // | ||
+ | * Website: the name and function/ | ||
+ | * Emergency contact: This involves the contact details of one or more individuals who should be contacted in emergencies and with whom only the nature of the emergency is shared. | ||
+ | |||
+ | |||
+ | ===== 8. Processing special personal data ===== | ||
+ | |||
+ | This privacy regulation explicitly does **not** cover any personal data that is classed as ' | ||
+ | |||
+ | |||
+ | ===== 9. Rights of the data subject | ||
+ | |||
+ | FritsJurgens conforms to the legal requirements giving the data subject at least the following rights: | ||
+ | |||
+ | * When the data subject has given consent for the processing of their data, the management must be able to prove that this has consent has been given. | ||
+ | * The data subject has [[operations: | ||
+ | * The data subject has [[operations: | ||
+ | * The data subject has [[operations: | ||
+ | * The data subject has [[operations: | ||
+ | * The data subject has [[operations: | ||
+ | |||
+ | |||
+ | ===== 10. Data protection | ||
+ | |||
+ | - FritsJurgens has the legal obligation to take both organisational measures (see below) and [[it: | ||
+ | - Paper files (i.e. contracts only) are kept under personal guard of the roles responsible for contracting, | ||
+ | - Digital files are stored on the [[it: | ||
+ | - Devices used to access Microsoft SharePoint are protected by at least password to the security standards set by our IT partner [[https:// | ||
+ | - Personal data is stored in the dedicated applications only (see the [[it: | ||
+ | - When sensitive personal data is to be sent, [[it: | ||
+ | - All online data is stored within the EU only. | ||
+ | - Whenever anyone within FritsJurgens finds out about breach of security or an actual breach, the [[it: | ||
+ | - Any breach in relation to personal data is registered in the data leak register of FritsJurgens. | ||
+ | |||
+ | |||
+ | ===== 11. Data retention | ||
+ | |||
+ | Different documents have different retention periods: | ||
+ | |||
+ | | Destroying paper files | 1 day after the digital scan has been properly archived. | | ||
+ | | Destroying digital files | FIXME | | ||
+ | | Destroying access logbook | ||
+ | | Destroying email archive | ||
+ | | Destroying digital calendars | ||
+ | | Destroying personnel file | 2 years after termination of employment. | ||
+ | | Destroying payroll administration | ||
+ | | Destroying financial information (debtors) | ||
+ | | Destroying list of destroyed files | 20 years after destruction. | ||
+ | | Destroying digital backups | ||
+ | | Destroying after approved destruction request | ||
+ | | Destroying job application letter and CV | 4 weeks after completion of the job application process, or one year for open applications. | ||
+ | |||
+ | |||
+ | |||
+ | ===== 12. Complaints procedure | ||
+ | |||
+ | The data subject can file a complaint with the management about data processing. This can be done in writing via [[info@fritsjurgens.com]]. | ||
+ | |||
+ | |||
+ | ===== 13. Change log ===== | ||
+ | |||
+ | * Any future changes of this policy will be approved by the management and presented in a meeting for all employees. | ||
+ | * Changes become effective no sooner than four weeks after having been announced to all involved. | ||
+ | * This policy becomes effective per FIXME 01-01-2024 | ||
+ | * The policy is available on this wiki page or in print through the reception of FritsJurgens. | ||
+ | |||
+ | |||
+ | ==== 14. References | ||
+ | |||
+ | * These privacy regulations are referred to from: [[https:// | ||
+ | * A similar regulation is found on [[https:// | ||
+ | * Various wiki pages | ||
operations/policy/privacy_regulations.1702553436.txt.gz · Last modified: 2023-12-14 11:30 by hpoort