User Tools

Site Tools


operations:policy:privacy_regulations

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
operations:policy:privacy_regulations [2023-12-15 15:38] – Formatting, corrections hpoortoperations:policy:privacy_regulations [2024-07-02 07:35] (current) hpoort
Line 9: Line 9:
 This policy is based on the General Data Protection Regulation (GDPR: [[https://autoriteitpersoonsgegevens.nl/over-de-autoriteit-persoonsgegevens|link)]], which took effect on 25-05-2018. This policy is based on the General Data Protection Regulation (GDPR: [[https://autoriteitpersoonsgegevens.nl/over-de-autoriteit-persoonsgegevens|link)]], which took effect on 25-05-2018.
  
-The Privacy Policy for the Protection of Personal Privacy in the Context of Personal Registration was held for services provided by FritsJurgens.+This are the privacy regulations for the protection of personal privacy in the context of personal registration and apply to the services provided by FritsJurgens.
  
 Responsible publisher: FritsJurgens © 05-12-2023. All rights reserved. No part of this publication may be reproduced, stored in an automated database, or disclosed in any form or manner without prior written consent from the responsible publisher. Responsible publisher: FritsJurgens © 05-12-2023. All rights reserved. No part of this publication may be reproduced, stored in an automated database, or disclosed in any form or manner without prior written consent from the responsible publisher.
  
  
-===== Definitions  =====+===== 1. Definitions  =====
  
 In this policy, the following terms are defined: In this policy, the following terms are defined:
Line 35: Line 35:
  
  
-===== Scope  =====+===== 2. Scope  =====
  
   - This policy applies to all paper files, all digital files, and unwritten information within FritsJurgens, as well as its associated data exchange and processing.   - This policy applies to all paper files, all digital files, and unwritten information within FritsJurgens, as well as its associated data exchange and processing.
-  - FritsJurgens processes information in the following categories +  - FritsJurgens processes information in the following categories: 
-    * For salaryName, Address, Postal Code, Citizen Service Number, contact details such as position/salary scale/salary, a copy of ID, and the signed tax declaration. +    * [[operations:policy:privacy_regulations:fields_per_category#personal_data|Personal data]] such as name, address and contact details 
-    * In case of sick leave: name, address, postal code, citizen service number, salary, nature of sick leave, and status of the reintegration progress. +      * for personel also date of birth and social security number (//burgerservicenummer, BSN//) 
-    * For internal communication: Name, function/position, business email address, business phone number, schedule, and tasks. +    [[operations:policy:privacy_regulations:fields_per_category#background_data|Background data]] such as work historyskillset and personal network 
-    * For company outings: Dietary preferences and allergies. +    [[operations:policy:privacy_regulations:fields_per_category#contract_data|Contract data]] such as employment contracts, permission forms, purchase and sales contractsand review reports 
-    * For emergencies: Emergency contact information. +    * [[operations:policy:privacy_regulations:fields_per_category#proces_data|Process data]] such as date of entry, software usage logscomplaints registrationreports of data breaches, incident reports 
-    * Regarding employment, we share data with: +  - This policy applies within FritsJurgens and relates to the processing of personal data of: 
-      * Payroll administration {{:flags:nl.png?20&nolink|}}//salarisadministratie// (Mulderij & Partners): for payroll administration. They use the online payroll administration package Loket.nl. The payroll administration also provides the legally required information to the Tax Authorities. +    [[operations:policy:privacy_regulations:fields_per_subject#accounts|Potential customers and network contacts]] (individuals associated with companies in their professional capacity only)
-      * Pension Fund {{:flags:nl.png?20&nolink|}}//pensioenfonds// (ASR): exclusively for the initial registration with them (you subsequently permit them to process and transmit your data to the payroll administration; they are the data processor for this). +    * [[operations:policy:privacy_regulations:fields_per_subject#customers|Contacts of actual customers]] and other debtors
-      Possible Sick Leave Insurance {{:flags:nl.png?20&nolink|}}//ziekteverzuimverzekering// (currently not applicable): This includes personal data such as Name, Address, Citizen Service Number {{:flags:nl.png?20&nolink|}}//BSN//, Salary, and sick leave percentage. +    [[operations:policy:privacy_regulations:fields_per_subject#vendors|Contacts of suppliers]], including subcontractors and other companies
-      Occupational Health Service {{:flags:nl.png?20&nolink|}}//arbodienst// (Alpina@Work)The occupational health service has insight into the nature of sick leave. +    [[operations:policy:privacy_regulations:fields_per_subject#employees|Employees]], including interns and indirectly hired workforce
-      * Possible Absence Guidance {{:flags:nl.png?20&nolink|}}//verzuimbegeleiding// (Alpina@Work): Communication with the absence guidance organization involves reintegration in case of prolonged illness. +    [[operations:policy:privacy_regulations:fields_per_subject#relations|Employee's relations]] such as emergency contact and family composition.
-      * Accountant (Afier): The accountant has access to and receives a copy of the entire administrationincluding the payroll administration. +
-    * For work-related activities, we share data with: +
-      * IT partner ([[https://MatenICT.nl|MatenICT]]), software suppliers (MicrosoftZohoHolaspirit): your name and business contact details. +
-      * Colleagues i.e. all employees and interns within FritsJurgens. Through the administration package, all employees have access to all colleagues' work schedules and business contact details. This includes name, position, business email address, business phone number, work schedule, and roles. +
-      * Organizer of company outings: name, dietary preferences, and allergies (if participating). +
-      * Subcontractors and FritsJurgens seconded employees: considered external colleagues. The administration ensures that these external colleagues have access to the business contact details of the employees they are dealing with. +
-      Customersonly name, position {{:flags:nl.png?20&nolink|}}//functietitel//, business email address, and work schedule. +
-      * Website: the name and function/position of the employee. +
-      * Emergency contact: This involves the contact details of one or more individuals who should be contacted in emergencies and with whom only the nature of the emergency is shared+
-    * Regarding data of potential customers and network contacts, we register: +
-      * Name, business contact details, inquiry, and role within the company we have contact with+
-      All communication (emails, chats, phone notes). +
-      * All other information these customers offer, including search behavior on our website and media expressions+
-      Company data, including what we can find through data enrichment from publicly accessible internet sources. +
-   +
-This policy applies within FritsJurgens and relates to the processing of personal data of: +
-  * Employees, including interns+
-  * (Potential) customers and network contacts, such as the relationship with and data of other individuals in the personal network+
-  Debtors, such as clients and budget managers. +
-  * Suppliers, including subcontractors and other companies.+
  
  
-===== Purpose  =====+===== 3. Purpose  =====
  
   - The purpose of collecting and processing personal data is to have the necessary information for conducting market analysis, sending newsletters (if subscribed), and managing personnel and the company's functioning.   - The purpose of collecting and processing personal data is to have the necessary information for conducting market analysis, sending newsletters (if subscribed), and managing personnel and the company's functioning.
-  - The data of employees are collected and processed for: +  - The data of potential customers and network contacts are collected and processed for: 
-    - Making and executing an employment or internship agreement. +    - Market analysis. 
-    - Conducting payroll administration. +    - Sending newsletters (if subscribed)
-    - Collaborating as colleagues. +    - Referrals.
-    - Being prepared for emergencies. +
-  - The data of (potentialcustomers and network contacts are collected and processed for: +
-    * FIXME  +
-    - Communicating in emergencies+
-    - Coordinating services with the individual's network.+
   - The data of debtors (i.e. customers), are collected and processed for:   - The data of debtors (i.e. customers), are collected and processed for:
     - Executing and communicating about provided orders.     - Executing and communicating about provided orders.
Line 92: Line 67:
     - Paying invoices and accounting for payments.     - Paying invoices and accounting for payments.
     - Discussing deliveries or services.     - Discussing deliveries or services.
 +  - The data of employees are collected and processed for:
 +    - Making and executing an employment or internship agreement.
 +    - Conducting payroll administration.
 +    - Collaborating as colleagues.
 +    - Being prepared for emergencies.
 +  - The data of employee's relations are collected and processed for:
 +    - Communicating in case of emergencies.
 +    - Implementing 'attentive employership' (e.g. Sinterklaas gifts, baby shower gifts).
 +
 +
 +
 +===== 4. Representation  =====
 +
 +The subject whose personal data are recorded may be represented:
 +  * If younger than sixteen years: by their parent or guardian (such as name and age of employee's children);
 +  * If under legal restrictions: by their official representative (curator, mentor, //bewindvoerder//).
 +
  
  
-===== Responsibility for management and liability  =====+===== 5. Responsibility for maintenance and liability  =====
  
   - The management is responsible for ensuring the proper processing and management of personal data and can be held liable for it, except in case of force majeure.   - The management is responsible for ensuring the proper processing and management of personal data and can be held liable for it, except in case of force majeure.
  
  
-===== Rights of the data subject  =====+===== 6. Access to data  =====
  
-  * When the data subject has given written consent for the processing of their data, the management must be able to prove that this has occurred.+Access to the data is restricted to employees having certain roles grouped in so-called circles of accountability, which roles makes the data processing essential: 
 + 
 +^ Role             ^ Purpose                      ^ Access 
 +| People & Culture recruiting   | responsible for recruitment  | all data of applicants, read skillsets of employees 
 +| People & Culture contracting  | responsible for contracting  | all data of employees 
 +| Hero'          | working in a team            | read role/name/schedule of employees 
 +| BD               | responsible for regions      | all data of contacts and customers 
 +| Sales            | responsible for sales        | all data of customers 
 +| Marketing        | responsible for marketing    | all data of contacts 
 +| Support          | support other roles          | all data managed by the roles requiring support 
 +| Operations       | ultimate responsibility      | all, if required only  | 
 + 
 + 
 +===== 7. Sharing data  ===== 
 + 
 +  * Regarding employment, we share data with: 
 +    * Payroll administration //salarisadministratie// ([[https://mulderijenpartners.nl/wp-content/uploads/Privacyverklaring.pdf|Mulderij & Partners]]): for payroll administration. They use the online payroll administration package [[https://www.loket.nl/privacy-statement/|Loket.nl]]. The payroll administration also provides the legally required information to the Tax Authorities. 
 +    * Pension Fund //pensioenfonds// ([[https://www.asrnederland.nl/privacyverklaring|ASR]]): exclusively for the initial registration with them (you subsequently permit them to process and transmit your data to the payroll administration; they are the data processor for this). 
 +    * Possible Sick Leave Insurance //ziekteverzuimverzekering// (currently not applicable): This includes personal data such as Name, Address, Citizen Service Number //BSN//, Salary, and sick leave percentage. 
 +    * Occupational Health Service //arbodienst// ([[https://www.alpinawork.nl/privacyreglement/|Alpina@Work]]): The occupational health service has insight into the nature of sick leave. 
 +    * Possible Absence Guidance //verzuimbegeleiding// ([[https://www.alpinawork.nl/privacyreglement/|Alpina@Work]]): Communication with the absence guidance organization involves reintegration in case of prolonged illness. 
 +    * Accountant ([[https://afier.com|Afier]]): The accountant has access to and receives a copy of the entire administration, including the payroll administration. 
 +  * For work-related activities, we share data with: 
 +    * IT partner ([[https://MatenICT.nl|MatenICT]]), software suppliers ([[https://privacy.microsoft.com/nl-nl/privacystatement|Microsoft]], [[https://www.zoho.com/privacy.html|Zoho]], [[https://www.holaspirit.com/privacy|Holaspirit]]): your name and business contact details. All data is hosted within the EU. 
 +    * Colleagues i.e. all employees and interns within FritsJurgens. Through the administration package, all employees have access to all colleagues' work schedules and business contact details. This includes name, position, business email address, business phone number, work schedule, and roles. 
 +    * Organizer of company outings: name, dietary preferences, and allergies (if participating). 
 +    * Subcontractors and FritsJurgens seconded employees: considered external colleagues. The administration ensures that these external colleagues have access to the business contact details of the employees they are dealing with. 
 +    * Customers: only name, position //functietitel//, business email address, and work schedule. 
 +    * Website: the name and function/position of the employee. 
 +    * Emergency contact: This involves the contact details of one or more individuals who should be contacted in emergencies and with whom only the nature of the emergency is shared. 
 + 
 + 
 +===== 8. Processing special personal data  ===== 
 + 
 +This privacy regulation explicitly does **not** cover any personal data that is classed as 'special'. This means that within FritsJurgens any data classed as such, such as medical data or information about religion or political preference, may not be handled in any way. 
 + 
 + 
 +===== 9. Rights of the data subject  ===== 
 + 
 +FritsJurgens conforms to the legal requirements giving the data subject at least the following rights: 
 + 
 +  * When the data subject has given consent for the processing of their data, the management must be able to prove that this has consent has been given.
   * The data subject has [[operations:policy:privacy_regulation:withdraw_consent|the right to withdraw their consent]] at any time.   * The data subject has [[operations:policy:privacy_regulation:withdraw_consent|the right to withdraw their consent]] at any time.
   * The data subject has [[operations:policy:privacy_regulation:port_personal_data|the right to data porting]].   * The data subject has [[operations:policy:privacy_regulation:port_personal_data|the right to data porting]].
Line 109: Line 142:
    
  
-===== Data retention  =====+===== 10. Data protection  ===== 
 + 
 +  - FritsJurgens has the legal obligation to take both organisational measures (see below) and [[it:policy:technical_data_protection|technical measures]] (see link). 
 +  - Paper files (i.e. contracts only) are kept under personal guard of the roles responsible for contracting, signage or administration, until they are scanned and digitally archived after which they are shredded. 
 +  - Digital files are stored on the [[it:software:sharepoint|Microsoft SharePoint]] environment only (including OneDrive local cache). 
 +  - Devices used to access Microsoft SharePoint are protected by at least password to the security standards set by our IT partner [[https://matenict.nl|MatenICT]]. 
 +  - Personal data is stored in the dedicated applications only (see the [[it:policy:it_where_to_save_documents|IT policy on where to save data]]), but name and function (only) of employees may end up in any of the [[it:software|software packages]] used throughout the organization. 
 +  - When sensitive personal data is to be sent, [[it:howto:sending_sensitive_data|appropriate protection measures]] should be taken. 
 +  - All online data is stored within the EU only. 
 +  - Whenever anyone within FritsJurgens finds out about breach of security or an actual breach, the [[it:policy:protocol_datalekken|Protocol data leaks]] is to be followed. 
 +  - Any breach in relation to personal data is registered in the data leak register of FritsJurgens. 
 + 
 + 
 +===== 11. Data retention  =====
  
 Different documents have different retention periods: Different documents have different retention periods:
  
-| Destroying paper files                         FIXME  |+| Destroying paper files                         1 day after the digital scan has been properly archived. |
 | Destroying digital files                       | FIXME  | | Destroying digital files                       | FIXME  |
 | Destroying access logbook                      | 5 years after mutation date.  | | Destroying access logbook                      | 5 years after mutation date.  |
Line 128: Line 174:
  
  
-===== Complaints procedure  =====+===== 12. Complaints procedure  =====
  
 The data subject can file a complaint with the management about data processing. This can be done in writing via [[info@fritsjurgens.com]]. The data subject can file a complaint with the management about data processing. This can be done in writing via [[info@fritsjurgens.com]].
  
  
-===== Change log  =====+===== 13. Change log  =====
  
   * Any future changes of this policy will be approved by the management and presented in a meeting for all employees.   * Any future changes of this policy will be approved by the management and presented in a meeting for all employees.
Line 141: Line 187:
  
  
-==== References  ====+==== 14. References  ====
  
   * These privacy regulations are referred to from: [[https://fritsjurgens.sharepoint.com/:w:/r/sites/support/_layouts/15/Doc.aspx?file=2023%20FritsJurgens%20-%20Toestemmingsverklaring%20personeel.docx|De toestemmingsverklaring personeel]]   * These privacy regulations are referred to from: [[https://fritsjurgens.sharepoint.com/:w:/r/sites/support/_layouts/15/Doc.aspx?file=2023%20FritsJurgens%20-%20Toestemmingsverklaring%20personeel.docx|De toestemmingsverklaring personeel]]
operations/policy/privacy_regulations.1702654696.txt.gz · Last modified: 2023-12-15 15:38 by hpoort

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki