Information on personal data processing

Size: px
Start display at page:

Download "Information on personal data processing"

Transcription

1 In this information memorandum, we would like to provide you with a clear and comprehensive overview of the manner in which we process your personal data, their categories, extent and purposes for which they are processed, of the source from which the personal data are obtained, and on the persons to whom your personal data are transferred. You will also find here information on your rights concerning the personal data processing. This information is intended for: applicants for employment; current employees and members of organs of the Institute of Molecular Genetics of the ASCR, v. v. i.; former employees and members of organs of the Institute of Molecular Genetics of the ASCR, v. v. i.. For better clarity of the text, all the above-mentioned groups are further referred to as Employee. In this text, you will particularly find answers to the following questions: 1. Who is the controller of your personal data? 2. What data on your person are processed by IMG? 3. Why are your personal data processed by IMG? 4. For what purposes does IMG process your personal data? 5. In what manners does IMG process your personal data? 6. What rights can you apply in association with processing your personal data at IMG? 7. For how long does IMG process your personal data? 8. To whom does IMG allow access to your personal data? 1. Who is the controller of your personal data? The controller of your personal data is: Institute of Molecular Genetics of the ASCR, v. v. i. Vídeňská 1083, Prague 4, , Czech Republic In this text further referred to as IMG You can address your suggestions or questions related to the processing of your personal data: in printed form to the address: Institute of Molecular Genetics of the ASCR, v. v. i. Vídeňská 1083, Prague 4, , Czech Republic; 1

2 by to: via IMG data box (5h4nxm4) 2. What data on your person are processed by IMG? Data provided during the staff recruitment Identification data name, surname, degree(s), date of birth, permanent address; Contact data phone number, address, address for correspondence; Information on your immigration status when relevant; CV and motivation letter data concerning your education, work experience, skills, and motivation for working at IMG; Work references recommendation from previous employers, including data originating from their verification; Data originating from interviews notes and findings from discussions in person or by phone with you; Data originating from tests results and findings from tests, if you underwent some during the recruitment process; Information that you have voluntarily decided to share with IMG during the recruitment process the extent of this set of personal data will be very individual because it depends on the personal data you decide to provide to IMG. Data processed on employees In addition to the above-mentioned data, they represent: Identification data surname at birth, previous surname, place of birth, family status, nationality, ID card number; Contact data permanent address, address for correspondence; Data needed for processing the wage agenda and compulsory deductions birth registration number (healthcare ID No. for foreigners), bank account No., bank code and bank name for sending the wages; name, surname and birth registration number of your spouse/registered partner; names, surname and birth registration numbers of your children; information on whether you claim a tax allowance (including copies of the birth certificates of your children and confirmation of the other spouse that he/she does not claim the tax allowance; for adult children certificate of study); information on disability (of what degree, when relevant), age pension, or holder of disability certificate including the date of claiming it; data on wages; data on leaves of absence; data on travel allowances/expenses; records on the use of work mobile phone, when allocated; records on movements of a service car if you use it; Data on attendance, performance, and possible disciplinary proceedings; Penal Register extracts; 2

3 Data on completed trainings; Data collected by security systems records from the camera system in the corridors and in the IMG building surroundings, records on your movements in the building; Data concerning your use of the entrusted IT equipment logs; Data that you decide to share voluntarily; Photos in case you grant us your consent to their processing or acquisition; Health records results of compulsory occupational health checks. 3. Why are your personal data processed by IMG? What legal bases for personal data processing does IMG use? IMG may process your data solely for purposes having an appropriate legal basis. In view of the position of IMG as an employer and of the purposes for which it processes your personal data in relation to this position, the only legal bases for processing personal data are the following: if it is necessary for fulfilment of a contract concluded with you or for adopting measures preceding conclusion of this contract at your request; if it is necessary for fulfilment of our legal duty; for protecting our rights and legally protected interests; based on your consent. For processing your personal data, your consent is only needed in cases that IMG does not have another legal basis for the particular purpose of their processing. The purposes for which IMG processes personal data may be divided into four main areas: fulfilment of contracts, service to employees, management of risks and provision of security including fulfilment of legal duties of IMG as an employer, internal administration including development and improvement of services. Do you have to provide your personal data to IMG? Provision of personal data is always voluntary. However, in case you refuse to provide your personal data needed for purposes that have a legal basis for processing other than your consent, it won t be possible for you to become our employee because provision of your personal data for these purposes is a prerequisite for concluding a contract with IMG. In case you give your consent to personal data processing, the provision of personal data for the purposes defined in the particular consent is always your decision. When considering provision of a consent to processing personal data for internal communication, we would like to point out that its provision is not a prerequisite for concluding a contract nor for the continuation of the labour-law relationship. In any case and at any time you have the right to withdraw your consent free of charge. The withdrawal of consent shall not affect the lawfulness of processing based on the consent before its withdrawal. 3

4 How does IMG get your personal data? IMG processes personal data that: you have provided to IMG by yourself; are generated within the framework of your working activities for IMG; are obtained from the third parties entitled to handle these data and transfer them to IMG based on fulfilment of particular conditions (e.g., during the recruitment process from external HR agencies). 4. For what purposes does IMG process your personal data? Purpose of processing: recruitment of staff for new or liberated positions More detailed description: we actively search for people who could be new IMG employees. Concerning our future colleagues, we need to assess whether they possess the education, experience, skills and personal qualifications needed for the particular position. We may receive your CV and additional data based on your consent provided to an HR agency from this HR agency. In case you were not successful in a competition for a particular position and you give us your consent to preserve your data for the case that another position, potentially interesting for you, will open, we will retain your CV and potentially other additional relevant information provided by you. Consent given by you Purpose of processing: preparation of employment contract, its potential changes during the employment More detailed description: the employment relationship is based on an employment contract, which must be concluded in written form. The employment contract includes all our mutual rights and duties. During the employment relationship, there may be situations when changes are needed in the contract. Fulfilment of a contract that you have concluded with us Purpose of processing: wage accounting, including compulsory deductions and concurrences and travel compensations 4

5 More detailed description: you are not entitled to your wages just based on your contract that we have concluded with each other, but also even based on the law. In case that, for some reasons, there is an executable decision on deductions from you wage (e.g., for reasons of a distraint for your property), we shall be bound to process your personal data to comply with this decision. o Act on Income Tax o Act on Healthcare Insurance o Act on Insurance for Public Healthcare Insurance o Act on Social Security o Act on Health Insurance o Civil Procedure Act Purpose of processing: records of attendance More detailed description: the arrivals and departures of employees are recorded. Purpose of processing: records of leaves of absence More detailed description: in accord with valid regulations, we have to record the spent leaves of absence. Fulfilment of a legal duty Fulfilment of contracts that you have concluded with us Purpose of processing: registry of allocated property More detailed description: in accord with valid regulations, we have to record the registry of property allocated to employees, and these data are maintained in a structured electronic database. Purpose of processing: accounting and tax agenda 5

6 More detailed description: We are also bound to keep accounts and pay taxes. Therefore, we process your personal data to a required extent in order to fulfil this duty. o Accounting Act o Act on Income Tax Purpose of processing: to ensure internal and external electronic communication More detailed description: all IMG employees are provided with an address in These boxes are intended solely for communication related to the employment activities. Purpose of processing: administration of training and courses More detailed description: IMG supports individual and qualification development of its employees, among other by enabling their participation in a wide range of courses and workshops. In some cases the participation in a course or training may even represent a legal requirement. o Act on Fire Protection Purpose of processing: occupational health checks More detailed description: occupational health checks to the extent and at intervals defined by legal regulations represent a measure serving for protection of the employees health. o Act on Specific Health Services o Act on Public Health Protection o Directive on Occupational Health Services Purpose of processing: administration of employment benefits 6

7 More detailed description: IMG offers its employees a wide range of benefits. During their administration, personal data are processed. These administrative activities e.g. include calculation of the number of lunch vouchers to which the employee is entitled for the given month or records of other spent benefits. Fulfilment of contracts that you have concluded with us Purpose of processing: administration of service mobile phones and/or cars More detailed description: employees who have been allocated service mobile phone have been instructed during its receipt that they only may use it for working matters. Service cars are equipped with a GPS unit monitoring their movement. Purpose of processing: litigious agenda: determination, execution, or defence of our legal claims, including collection of claims More detailed description: in case of conflict that is not solved by mutual agreement and is presented to the court or the appropriate supervisory organ, we shall use your personal data to the required extent for protection of our rights. We may also use your personal data for the purposes of collection of our claims. Purpose of processing: internal and external audit More detailed description: We are bound to let an independent external auditor verify our final accounts. During their work, external auditors may have access to personal data. o Accounting Act Purpose of processing: to provide security More detailed description: for the purpose of ensuring security of property and data protection, a system of cameras have been installed in selected locations. The camera system does not violate the right to privacy and dignity of employees. In order to ensure security of the IMG property and data protection, a system of administration of access rights and monitoring of employees movements in the building has been implemented. 7

8 In association with utilization of IT equipment and information systems by the employees, logs are collected. 5. In what manners does IMG process your personal data? Personal data processing is done both manually and in an automated way in electronic information systems, both in electronic and printed form, always with high technical, organizational and personal security in accord with legal requirements. Personal data are under permanent physical, electronic, as well as procedural control. 6. What rights can you apply in association with processing your personal data at IMG? You can ask us for the information on processing your personal data, in which we have to disclose, without undue delay: the purpose of processing; processed personal data or their categories, including all available information on their source; recipients, or categories of recipients; nature of the automated processing, when the data are used for deciding on the rights of the data subject. For providing this information, we are entitled to require an adequate fee not exceeding the costs needed for providing the information. Application for explanation / elimination of illegal state If you believe or find out that we process your personal data at variance with protection of your private and personal life or contrary to law, you are entitled to request an explanation and/or prompt us to remove the illegal state, i.e., to blocking, correcting, complementing, or eliminating the personal data. In case of violation of our duties, you can also address your suggestions to the Office for Personal Data Protection ( Úřad pro ochranu osobních údajů, ÚOOÚ ), residing at the address Pplk. Sochora 27, Prague 7, Czech Republic, phone No (exchange). ÚOOÚ operates the website: at which you can find more information on the possible help by ÚOOÚ. 8

9 Withdrawal of consent You can withdraw your consent to processing personal data at any time. The withdrawal of consent shall not affect the lawfulness of processing based on the consent before its withdrawal. Also, the withdrawal of consent has no effect on our contractual relationship. How can you apply the above-mentioned rights? Contact us via some of the above-mentioned contacts. 7. For how long does IMG process your personal data? On principle, we process your personal data only during your employment at IMG. After termination of your employment, only those documents, i.e., personal data, are preserved the preservation of which is based on a justified interest (or protection of our interests in case of conflict), for the duration of 10 years after termination of your employment at IMG, and/or those documents, i.e., personal data, that we are bound to preserve based on our legal regulations (in some cases, therefore, up to 30 years). In case you were not successful in applying for employment at IMG and you did not give us your consent to processing your personal data for the case of a potential future free position that might be interesting for you, your personal data are eliminated immediately after the end of the open competition for the current position. The personal data that we process based on your consent are processed for the period for which you have given us your consent, or until the moment you withdraw your consent. In accord with the principle of data minimization, in all cases we only process those personal data that we necessarily need for the particular purpose and preserve them only for the indispensable time. When this period elapses, the personal data are erased, i.e., anonymized. 8. To whom does IMG allow access to your personal data? Generally speaking, the recipient of personal data represents any subject to whom the access to personal data is provided. According to the situation, the recipient of personal data may thus represent another personal data controller (defining by itself the purposes and means of processing these personal data) or personal data processor (processing personal data for the personal data controller). On principle, IMG does not share your personal data with other controllers of personal data, unless such data transfer were given by a duty or claim based on a legal regulation, or a justified interest, or in case you gave your consent to such data transfer. 9

10 Your consent is not needed for sharing personal data with personal data processors. With every subject that could become processor of the personal data we control within the framework of his/her activities, we shall conclude a written contract on processing personal data, and this personal data processor is entitled to handle these data to the extent indispensable for fulfilment of his/her task, for the purposes of fulfilment of his/her task and for the agreed period. Suppliers Some of our activities may include third subjects our suppliers. Depending on the nature of the particular activity, your personal data may be processed by this supplier in a position of processor or controller of personal data. Organs of state administration, execution of decisions Based on legal regulations, in certain circumstances we may be bound to share your personal data with third parties (e.g., distrainers, healthcare agencies, labour offices, organs of social security, insolvency practitioners) without your consent for the purposes of fulfilment of their duties and, when relevant, execution of decision. Publication of data on IMG employees On principle, we do not publish data on IMG employees, unless: a) we are bound to it based on legal regulations; or b) we have obtained your consent to this publication. 10