operations:policy:privacy_regulations
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
operations:policy:privacy_regulations [2023-12-15 10:29] – mtersteeg | operations:policy:privacy_regulations [2024-07-02 07:35] (current) – hpoort | ||
---|---|---|---|
Line 3: | Line 3: | ||
The Privacy Regulations are a company-wide document that governs how FritsJurgens deals with GDPR-qualifying personal data. It is one of the policies governed by the [[: operations|Operations circle]]. | The Privacy Regulations are a company-wide document that governs how FritsJurgens deals with GDPR-qualifying personal data. It is one of the policies governed by the [[: operations|Operations circle]]. | ||
- | {{: | + | {{: |
---- | ---- | ||
- | FIXME | + | This policy is based on the General Data Protection Regulation (GDPR: [[https:// |
- | Naar dit reglement wordt verwezen vanuit: | + | This are the privacy regulations for the protection of personal privacy in the context of personal registration and apply to the services provided by FritsJurgens. |
- | - [[https:// | + | |
- | - Website (of op de website moet een variant komen met alleen het publieke gedeelte) | + | |
- | - Diverse wiki-pagina' | + | |
- | This policy is based on the General Data Protection Regulation (GDPR: [[https:// | + | Responsible publisher: FritsJurgens © 05-12-2023. All rights reserved. No part of this publication may be reproduced, stored in an automated database, or disclosed in any form or manner without prior written consent from the responsible publisher. |
- | + | ||
- | The Privacy Policy for the Protection of Personal Privacy in the Context of Personal Registration was held for services provided by FritsJurgens. | + | |
- | + | ||
- | Responsible publisher: FritsJurgens© December 5, 2023. All rights reserved. No part of this publication may be reproduced, stored in an automated database, or disclosed in any form or manner without prior written consent from the responsible publisher. | + | |
Line 25: | Line 18: | ||
In this policy, the following terms are defined: | In this policy, the following terms are defined: | ||
- | ^ Privacy | + | ^ Term ^ {{: |
- | ^ Data Subject | + | ^ Privacy |
- | ^ Data Controller | + | ^ FritsJurgens |
- | ^ Processor | + | ^ Data Subject |
- | ^ Processor Supervisor | + | ^ Data Controller |
- | ^ Recipient | + | ^ Processor |
- | ^ Personal Data | + | ^ Processor Supervisor |
- | ^ Health Data | + | ^ Recipient |
- | ^ Processing of Personal Data | + | ^ Personal Data | // |
- | ^ Consent | + | ^ Health Data | //health data// |
- | ^ Confidentiality | + | ^ Processing of Personal Data | // |
+ | ^ Consent | ||
+ | ^ Confidentiality | ||
- | ===== 2. Scope ===== | + | Throughout the policy, for some words, the Dutch translation is given in italics, to clarify. |
- | This policy applies to all paper and digital files, unwritten information within FritsJurgens, | + | ===== 2. Scope ===== |
- | FritsJurgens processes information in the following categories: | + | - This policy applies to all paper files, all digital files, and unwritten information within FritsJurgens, |
- | * Unordered List ItemFor Salary: Name, Address, Postal Code, Citizen Service Number, contact details | + | - FritsJurgens processes information in the following categories: |
- | * Unordered List ItemIn case of sick leave, Include name, address, postal code, citizen service number, salary, nature | + | * [[operations:policy: |
- | * Unordered List ItemFor Internal Communication: Name, position, business email address, business phone number, schedule, and tasks. | + | * for personel also date of birth and social security number (//burgerservicenummer, BSN//) |
+ | * [[operations: | ||
+ | * [[operations: | ||
+ | * [[operations: | ||
+ | - This policy applies within FritsJurgens | ||
+ | * [[operations: | ||
+ | * [[operations:policy: | ||
+ | * [[operations: | ||
+ | * [[operations: | ||
+ | * [[operations: | ||
- | FIXME opmaak FIXME | ||
- | For Business Activities: Dietary preferences and allergies. | ||
- | For Emergencies: | ||
- | Regarding employment, we share data with: | ||
- | Payroll administration (Mulderij & Partners): for payroll administration. They use the online payroll administration package Loket.nl. The payroll administration also provides the legally required information to the Tax Authorities. | + | ===== 3. Purpose |
- | Pension Fund (ASR): exclusively for the initial registration with them (you subsequently permit them to process and transmit your data to the payroll administration; | + | |
- | Possible Sick Leave Insurance (currently not applicable): | + | |
- | Occupational Health Service: The occupational health service has insight into the nature of sick leave. | + | |
- | Possible Absence Guidance (Alpina@Work): | + | |
- | Accountant (Afier): The accountant has access to and receives a copy of the entire administration, | + | |
- | For work-related activities, we share data with: | + | |
- | IT partner (MatenICT), software suppliers | + | - The purpose of collecting and processing personal data is to have the necessary information for conducting market analysis, sending newsletters |
- | Colleagues: All employees | + | - The data of potential customers |
- | Organizer | + | - Market analysis. |
- | Subcontractors and FritsJurgens seconded employees: considered external colleagues. The administration ensures that these external colleagues have access to the business contact details | + | - Sending newsletters |
- | Customers: only name, position, business email address, | + | - Referrals. |
- | Website: the name and position of the employee. | + | - The data of debtors (i.e. customers), |
- | Emergency contact involves the contact details | + | - Executing and communicating about provided orders. |
- | Regarding | + | - Invoicing |
- | We register: | + | - Discussing potential new orders. |
+ | - The data of creditors (i.e. suppliers and subcontractors), | ||
+ | - Executing | ||
+ | - Paying invoices and accounting for payments. | ||
+ | - Discussing deliveries or services. | ||
+ | - The data of employees are collected and processed for: | ||
+ | - Making and executing an employment | ||
+ | - Conducting payroll administration. | ||
+ | - Collaborating as colleagues. | ||
+ | - Being prepared for emergencies. | ||
+ | - The data of employee' | ||
+ | - Communicating in case of emergencies. | ||
+ | - Implementing ' | ||
- | Name, business contact details, inquiry, and role within the company we have contact with. | ||
- | All communication (emails, chats, phone notes). | ||
- | All other information these customers offer, including search behavior on our website and media expressions. | ||
- | Company data, including what we can find through data enrichment from publicly accessible internet sources. | ||
- | This policy applies within FritsJurgens and relates to the processing of personal data of: | ||
- | Employees, including interns. | ||
- | (Potential) customers and network contacts, such as the relationship with and data of other individuals in the personal network. | ||
- | Debtors, such as clients and budget managers. | ||
- | Suppliers, including subcontractors and other companies. | ||
- | 3. PURPOSE OF PERSONAL REGISTRATION | ||
- | The purpose of collecting and processing personal data is to have the necessary information for conducting market analysis, sending newsletters (if subscribed), | + | ===== 4. Representation |
- | The data of employees | + | The subject whose personal |
- | A. Making and executing an employment | + | * If younger than sixteen years: by their parent |
- | B. Conducting payroll administration. | + | * If under legal restrictions: |
- | C. Collaborating | + | |
- | D. Being prepared for emergencies. | + | |
- | The data of (potential) customers and network contacts are collected and processed for: | ||
- | A. Communicating in emergencies. | ||
- | B. Coordinating services with the individual' | ||
- | The data of debtors, or clients, are collected and processed for: | ||
- | A. Executing and communicating about provided orders. | ||
- | B. Invoicing and receiving payment. | ||
- | C. Discussing potential new orders. | ||
- | The data of creditors, or suppliers and subcontractors, | + | ===== 5. Responsibility |
- | A. Executing | + | |
- | B. Paying invoices and accounting for payments. | + | |
- | C. Discussing deliveries or services. | + | |
- | Responsibility | + | - The management is responsible |
- | The management is responsible for ensuring the proper processing and management of personal data and can be held liable for it, except in case of force majeure. | ||
- | 4. RIGHTS OF THE DATA SUBJECT | ||
- | When the data subject has given written | + | ===== 6. Access to data ===== |
- | The data subject has the right to withdraw their consent at any time. | + | |
- | The data subject has the right to data portability. | + | Access to the data is restricted to employees having certain roles grouped in so-called circles of accountability, |
- | The data subject has the right to be forgotten. | + | |
- | The data subject has the right to access. | + | ^ Role ^ Purpose |
- | The data subject has the right to rectification and supplementation. | + | | People & Culture recruiting |
- | 5. DATA RETENTION | + | | People & Culture contracting |
+ | | Hero' | ||
+ | | BD | responsible for regions | ||
+ | | Sales | responsible for sales | all data of customers | ||
+ | | Marketing | ||
+ | | Support | ||
+ | | Operations | ||
+ | |||
+ | |||
+ | ===== 7. Sharing data ===== | ||
+ | |||
+ | * Regarding employment, we share data with: | ||
+ | * Payroll administration // | ||
+ | * Pension Fund // | ||
+ | * Possible Sick Leave Insurance // | ||
+ | * Occupational Health Service // | ||
+ | * Possible Absence Guidance // | ||
+ | * Accountant ([[https:// | ||
+ | * For work-related activities, we share data with: | ||
+ | * IT partner ([[https:// | ||
+ | * Colleagues i.e. all employees and interns within FritsJurgens. Through the administration package, all employees have access to all colleagues' | ||
+ | * Organizer of company outings: name, dietary preferences, | ||
+ | * Subcontractors and FritsJurgens seconded employees: considered external colleagues. The administration ensures that these external colleagues have access to the business contact details of the employees they are dealing with. | ||
+ | * Customers: only name, position // | ||
+ | * Website: the name and function/ | ||
+ | * Emergency contact: This involves the contact details of one or more individuals who should be contacted in emergencies and with whom only the nature of the emergency is shared. | ||
+ | |||
+ | |||
+ | ===== 8. Processing special personal data ===== | ||
+ | |||
+ | This privacy regulation explicitly does **not** cover any personal data that is classed as ' | ||
+ | |||
+ | |||
+ | ===== 9. Rights of the data subject | ||
+ | |||
+ | FritsJurgens conforms to the legal requirements giving the data subject at least the following rights: | ||
+ | |||
+ | * When the data subject has given consent for the processing of their data, the management must be able to prove that this has consent has been given. | ||
+ | | ||
+ | | ||
+ | | ||
+ | | ||
+ | | ||
+ | |||
+ | |||
+ | ===== 10. Data protection | ||
+ | |||
+ | - FritsJurgens has the legal obligation to take both organisational measures (see below) and [[it: | ||
+ | - Paper files (i.e. contracts only) are kept under personal guard of the roles responsible for contracting, | ||
+ | - Digital files are stored on the [[it: | ||
+ | - Devices used to access Microsoft SharePoint are protected by at least password to the security standards set by our IT partner [[https:// | ||
+ | - Personal data is stored in the dedicated applications only (see the [[it: | ||
+ | - When sensitive personal data is to be sent, [[it: | ||
+ | - All online data is stored within the EU only. | ||
+ | - Whenever anyone within FritsJurgens finds out about breach of security or an actual breach, the [[it: | ||
+ | - Any breach in relation to personal data is registered in the data leak register of FritsJurgens. | ||
+ | |||
+ | |||
+ | ===== 11. Data retention | ||
Different documents have different retention periods: | Different documents have different retention periods: | ||
- | Destroying paper files: 2 years after departure. | + | | Destroying paper files | 1 day after the digital scan has been properly archived. | |
- | Destroying digital files: 5 years after release. | + | | Destroying digital files | FIXME | |
- | Destroying access logbook: 5 years after mutation date. | + | | Destroying access logbook |
- | Destroying email archive: 5 years after release. | + | | Destroying email archive |
- | Destroying digital calendars: 5 years after the end of the fiscal year. | + | | Destroying digital calendars |
- | Destroying paper day sheets: 2 years after the end of the fiscal year. | + | | Destroying personnel file |
- | Destroying time registration: | + | | Destroying payroll administration |
- | Destroying personnel file: 2 years after termination of employment. | + | | Destroying financial information (debtors) |
- | Destroying payroll administration: 7 years after the end of the fiscal year. | + | | Destroying list of destroyed files | 20 years after destruction. |
- | Destroying financial information (debtors): 7 years after the end of the fiscal year. | + | | Destroying digital backups |
- | Destroying list of destroyed files: 20 years after destruction. | + | | Destroying after approved destruction request |
- | Destroying digital backups: 5 years after backup date. | + | | Destroying job application letter and CV | 4 weeks after completion of the job application process, or one year for open applications. |
- | Destroying data in administration: | + | |
- | Destroying after approved destruction request: 3 months after the request. | + | |
- | Destroying job application letter and CV: 4 weeks after completion of the job application process, or one year for open applications. | + | |
- | 6. COMPLAINTS PROCEDURE | + | ===== 12. Complaints procedure |
+ | |||
+ | The data subject can file a complaint with the management about data processing. This can be done in writing via [[info@fritsjurgens.com]]. | ||
+ | |||
+ | |||
+ | ===== 13. Change log ===== | ||
+ | |||
+ | * Any future changes of this policy will be approved by the management and presented in a meeting for all employees. | ||
+ | * Changes become effective no sooner than four weeks after having been announced to all involved. | ||
+ | * This policy becomes effective per FIXME 01-01-2024 | ||
+ | * The policy is available on this wiki page or in print through the reception of FritsJurgens. | ||
- | The data subject can file a complaint with the management about data processing. This can be done in writing via info@fritsjurgens.com. | + | ==== 14. References |
+ | * These privacy regulations are referred to from: [[https:// | ||
+ | * A similar regulation is found on [[https:// | ||
+ | * Various wiki pages | ||
operations/policy/privacy_regulations.1702636180.txt.gz · Last modified: 2023-12-15 10:29 by mtersteeg