operations:policy:privacy_regulations
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
operations:policy:privacy_regulations [2023-12-15 15:38] – Formatting, corrections hpoort | operations:policy:privacy_regulations [2024-07-02 07:35] (current) – hpoort | ||
---|---|---|---|
Line 9: | Line 9: | ||
This policy is based on the General Data Protection Regulation (GDPR: [[https:// | This policy is based on the General Data Protection Regulation (GDPR: [[https:// | ||
- | The Privacy Policy | + | This are the privacy regulations |
Responsible publisher: FritsJurgens © 05-12-2023. All rights reserved. No part of this publication may be reproduced, stored in an automated database, or disclosed in any form or manner without prior written consent from the responsible publisher. | Responsible publisher: FritsJurgens © 05-12-2023. All rights reserved. No part of this publication may be reproduced, stored in an automated database, or disclosed in any form or manner without prior written consent from the responsible publisher. | ||
- | ===== Definitions | + | ===== 1. Definitions |
In this policy, the following terms are defined: | In this policy, the following terms are defined: | ||
Line 35: | Line 35: | ||
- | ===== Scope ===== | + | ===== 2. Scope ===== |
- This policy applies to all paper files, all digital files, and unwritten information within FritsJurgens, | - This policy applies to all paper files, all digital files, and unwritten information within FritsJurgens, | ||
- | - FritsJurgens processes information in the following categories | + | - FritsJurgens processes information in the following categories: |
- | * For salary: Name, Address, Postal Code, Citizen Service Number, contact details | + | * [[operations:policy: |
- | * In case of sick leave: | + | * for personel |
- | * For internal communication: | + | * [[operations:policy:privacy_regulations: |
- | * For company outings: Dietary preferences and allergies. | + | * [[operations:policy:privacy_regulations:fields_per_category# |
- | * For emergencies: | + | * [[operations:policy: |
- | * Regarding employment, we share data with: | + | - This policy applies |
- | * Payroll administration {{: | + | * [[operations:policy:privacy_regulations:fields_per_subject# |
- | * Pension Fund {{: | + | * [[operations: |
- | * Possible Sick Leave Insurance {{:flags:nl.png? | + | * [[operations: |
- | * Occupational Health Service {{:flags:nl.png? | + | * [[operations: |
- | * Possible Absence Guidance {{: | + | * [[operations: |
- | * Accountant (Afier): The accountant has access to and receives a copy of the entire administration, including the payroll administration. | + | |
- | * For work-related activities, we share data with: | + | |
- | * IT partner ([[https:// | + | |
- | * Colleagues i.e. all employees and interns | + | |
- | * Organizer of company outings: name, dietary preferences, | + | |
- | * Subcontractors and FritsJurgens seconded employees: considered external colleagues. The administration ensures that these external colleagues have access | + | |
- | * Customers: only name, position {{:flags:nl.png? | + | |
- | * Website: the name and function/ | + | |
- | * Emergency contact: This involves the contact details of one or more individuals | + | |
- | * Regarding data of potential | + | |
- | * Name, business contact details, inquiry, and role within the company we have contact with. | + | |
- | * All communication (emails, chats, phone notes). | + | |
- | * All other information these customers offer, including | + | |
- | * Company data, including what we can find through data enrichment from publicly accessible internet sources. | + | |
- | + | ||
- | This policy | + | |
- | * Employees, including interns. | + | |
- | * (Potential) customers | + | |
- | * Debtors, | + | |
- | * Suppliers, including subcontractors and other companies. | + | |
- | ===== Purpose | + | ===== 3. Purpose |
- The purpose of collecting and processing personal data is to have the necessary information for conducting market analysis, sending newsletters (if subscribed), | - The purpose of collecting and processing personal data is to have the necessary information for conducting market analysis, sending newsletters (if subscribed), | ||
- | - The data of employees are collected and processed for: | + | - The data of potential customers and network contacts are collected and processed for: |
- | - Making and executing an employment or internship agreement. | + | |
- | - Conducting payroll administration. | + | - Sending newsletters (if subscribed). |
- | - Collaborating as colleagues. | + | - Referrals. |
- | - Being prepared for emergencies. | + | |
- | - The data of (potential) customers and network contacts are collected and processed for: | + | |
- | | + | |
- | - Communicating in emergencies. | + | |
- | - Coordinating services with the individual' | + | |
- The data of debtors (i.e. customers), are collected and processed for: | - The data of debtors (i.e. customers), are collected and processed for: | ||
- Executing and communicating about provided orders. | - Executing and communicating about provided orders. | ||
Line 92: | Line 67: | ||
- Paying invoices and accounting for payments. | - Paying invoices and accounting for payments. | ||
- Discussing deliveries or services. | - Discussing deliveries or services. | ||
+ | - The data of employees are collected and processed for: | ||
+ | - Making and executing an employment or internship agreement. | ||
+ | - Conducting payroll administration. | ||
+ | - Collaborating as colleagues. | ||
+ | - Being prepared for emergencies. | ||
+ | - The data of employee' | ||
+ | - Communicating in case of emergencies. | ||
+ | - Implementing ' | ||
+ | |||
+ | |||
+ | |||
+ | ===== 4. Representation | ||
+ | |||
+ | The subject whose personal data are recorded may be represented: | ||
+ | * If younger than sixteen years: by their parent or guardian (such as name and age of employee' | ||
+ | * If under legal restrictions: | ||
+ | |||
- | ===== Responsibility for management | + | ===== 5. Responsibility for maintenance |
- The management is responsible for ensuring the proper processing and management of personal data and can be held liable for it, except in case of force majeure. | - The management is responsible for ensuring the proper processing and management of personal data and can be held liable for it, except in case of force majeure. | ||
- | ===== Rights of the data subject | + | ===== 6. Access to data ===== |
- | * When the data subject has given written | + | Access to the data is restricted to employees having certain roles grouped in so-called circles of accountability, |
+ | |||
+ | ^ Role ^ Purpose | ||
+ | | People & Culture recruiting | ||
+ | | People & Culture contracting | ||
+ | | Hero' | ||
+ | | BD | responsible for regions | ||
+ | | Sales | responsible for sales | all data of customers | ||
+ | | Marketing | ||
+ | | Support | ||
+ | | Operations | ||
+ | |||
+ | |||
+ | ===== 7. Sharing data ===== | ||
+ | |||
+ | * Regarding employment, we share data with: | ||
+ | * Payroll administration // | ||
+ | * Pension Fund // | ||
+ | * Possible Sick Leave Insurance // | ||
+ | * Occupational Health Service // | ||
+ | * Possible Absence Guidance // | ||
+ | * Accountant ([[https:// | ||
+ | * For work-related activities, we share data with: | ||
+ | * IT partner ([[https:// | ||
+ | * Colleagues i.e. all employees and interns within FritsJurgens. Through the administration package, all employees have access to all colleagues' | ||
+ | * Organizer of company outings: name, dietary preferences, | ||
+ | * Subcontractors and FritsJurgens seconded employees: considered external colleagues. The administration ensures that these external colleagues have access to the business contact details of the employees they are dealing with. | ||
+ | * Customers: only name, position // | ||
+ | * Website: the name and function/ | ||
+ | * Emergency contact: This involves the contact details of one or more individuals who should be contacted in emergencies and with whom only the nature of the emergency is shared. | ||
+ | |||
+ | |||
+ | ===== 8. Processing special personal data ===== | ||
+ | |||
+ | This privacy regulation explicitly does **not** cover any personal data that is classed as ' | ||
+ | |||
+ | |||
+ | ===== 9. Rights of the data subject | ||
+ | |||
+ | FritsJurgens conforms to the legal requirements giving the data subject at least the following rights: | ||
+ | |||
+ | | ||
* The data subject has [[operations: | * The data subject has [[operations: | ||
* The data subject has [[operations: | * The data subject has [[operations: | ||
Line 109: | Line 142: | ||
- | ===== Data retention | + | ===== 10. Data protection |
+ | |||
+ | - FritsJurgens has the legal obligation to take both organisational measures (see below) and [[it: | ||
+ | - Paper files (i.e. contracts only) are kept under personal guard of the roles responsible for contracting, | ||
+ | - Digital files are stored on the [[it: | ||
+ | - Devices used to access Microsoft SharePoint are protected by at least password to the security standards set by our IT partner [[https:// | ||
+ | - Personal data is stored in the dedicated applications only (see the [[it: | ||
+ | - When sensitive personal data is to be sent, [[it: | ||
+ | - All online data is stored within the EU only. | ||
+ | - Whenever anyone within FritsJurgens finds out about breach of security or an actual breach, the [[it: | ||
+ | - Any breach in relation to personal data is registered in the data leak register of FritsJurgens. | ||
+ | |||
+ | |||
+ | ===== 11. Data retention | ||
Different documents have different retention periods: | Different documents have different retention periods: | ||
- | | Destroying paper files | + | | Destroying paper files |
| Destroying digital files | FIXME | | | Destroying digital files | FIXME | | ||
| Destroying access logbook | | Destroying access logbook | ||
Line 128: | Line 174: | ||
- | ===== Complaints procedure | + | ===== 12. Complaints procedure |
The data subject can file a complaint with the management about data processing. This can be done in writing via [[info@fritsjurgens.com]]. | The data subject can file a complaint with the management about data processing. This can be done in writing via [[info@fritsjurgens.com]]. | ||
- | ===== Change log ===== | + | ===== 13. Change log ===== |
* Any future changes of this policy will be approved by the management and presented in a meeting for all employees. | * Any future changes of this policy will be approved by the management and presented in a meeting for all employees. | ||
Line 141: | Line 187: | ||
- | ==== References | + | ==== 14. References |
* These privacy regulations are referred to from: [[https:// | * These privacy regulations are referred to from: [[https:// |
operations/policy/privacy_regulations.1702654696.txt.gz · Last modified: 2023-12-15 15:38 by hpoort