The Privacy Regulations are a company-wide document that governs how FritsJurgens deals with GDPR-qualifying personal data. It is one of the policies governed by the Operations circle.
Privacyreglement
This policy is based on the General Data Protection Regulation (GDPR: link), which took effect on 25-05-2018.
This are the privacy regulations for the protection of personal privacy in the context of personal registration and apply to the services provided by FritsJurgens.
Responsible publisher: FritsJurgens © 05-12-2023. All rights reserved. No part of this publication may be reproduced, stored in an automated database, or disclosed in any form or manner without prior written consent from the responsible publisher.
In this policy, the following terms are defined:
Term | ![]() | Definition |
---|---|---|
Privacy | privacy | The right of individuals to protect personal privacy concerning recording and providing personal data. |
FritsJurgens | FritsJurgens | Each of the companies under the FritsJurgens holding. |
Data Subject | betrokkene | The individual whose data is processed. This includes employees, network contacts, customers, debtors, and suppliers. |
Data Controller | verwerkingsverantwoordelijke | The entity determining the purpose of processing personal data; within FritsJurgens, this is the management. |
Processor | verwerker | The entity authorized to process personal data; within FritsJurgens, this includes the administration and employees, including hired external subcontractors. |
Processor Supervisor | bewerker | The entity processing personal data under the authority of the data controller. |
Recipient | ontvanger | Someone who receives personal data. |
Personal Data | persoonsgegevens | All information that can be traced back to an identified natural person. |
Health Data | health data | Personal data related to a person's physical or mental health, including healthcare data provided. |
Processing of Personal Data | verwerking van persoonsgegevens | Any action involving personal data, including but not limited to collecting, recording, organizing, storing, updating, modifying, retrieving, consulting, using, disseminating, or destroying data. |
Consent | toestemming | Demonstrable agreement of the data subject to the intended data processing, provided through signature, checkbox + signature on a consent form, data submission by the data subject who has previously consented to recorded data, or written consent such as email or WhatsApp message. |
Confidentiality | geheimhouding | Every employee of FritsJurgens who has access to the personal data of employees and customers is obliged to maintain confidentiality. This obligation also applies after termination of employment. |
Throughout the policy, for some words, the Dutch translation is given in italics, to clarify.
The subject whose personal data are recorded may be represented:
Access to the data is restricted to employees having certain roles grouped in so-called circles of accountability, which roles makes the data processing essential:
Role | Purpose | Access |
---|---|---|
People & Culture recruiting | responsible for recruitment | all data of applicants, read skillsets of employees |
People & Culture contracting | responsible for contracting | all data of employees |
Hero's | working in a team | read role/name/schedule of employees |
BD | responsible for regions | all data of contacts and customers |
Sales | responsible for sales | all data of customers |
Marketing | responsible for marketing | all data of contacts |
Support | support other roles | all data managed by the roles requiring support |
Operations | ultimate responsibility | all, if required only |
This privacy regulation explicitly does not cover any personal data that is classed as 'special'. This means that within FritsJurgens any data classed as such, such as medical data or information about religion or political preference, may not be handled in any way.
FritsJurgens conforms to the legal requirements giving the data subject at least the following rights:
Different documents have different retention periods:
Destroying paper files | 1 day after the digital scan has been properly archived. |
Destroying digital files | |
Destroying access logbook | 5 years after mutation date. |
Destroying email archive | |
Destroying digital calendars | 5 years after the end of the fiscal year. |
Destroying personnel file | 2 years after termination of employment. |
Destroying payroll administration | 7 years after the end of the fiscal year. |
Destroying financial information (debtors) | 7 years after the end of the fiscal year. |
Destroying list of destroyed files | 20 years after destruction. |
Destroying digital backups | 5 years after backup date. |
Destroying after approved destruction request | 3 months after the request. |
Destroying job application letter and CV | 4 weeks after completion of the job application process, or one year for open applications. |
The data subject can file a complaint with the management about data processing. This can be done in writing via info@fritsjurgens.com.