KRONOS WORLDWIDE, INC. SAFE HARBOR PRIVACY POLICY Effective December 1, 2009 Amended and Restated as of July 20, 2012

Similar documents
Policy Name: McKesson s Imaging and Workflow Solutions and Enterprise Information Solutions U.S. - EU Safe Harbor Privacy Policy ( Policy )

Data Privacy Policy for Employees and Employee Candidates in the European Union

ECOLAB INC. PRIVACY POLICY STATEMENT PERSONAL DATA

K Y Ä N I P R I V A C Y P O L I C Y EEA

CANDIDATE DATA PROTECTION STANDARDS

GDPR Annotated Privacy Statement

General Optical Council. Data Protection Policy

Recruitment Privacy Notice Italy

General Personal Data Protection Policy

Privacy and Data Protection Policy

Recruitment Privacy Notice London

Recruitment Privacy Notice France

Subway Group. Prospective Employees Privacy Notice

LAST UPDATED June 11, 2018 DATA PROTECTION POLICY. International Foundation for Electoral Systems

Global Privacy Policy

DATA PROTECTION POLICY VERSION 1.0

ECOSERVICES, LLC BINDING CORPORATE RULES

GDPR: What Every MSP Needs to Know

WEWORK PRIVACY POLICY FOR PEOPLE DATA

Wroxton College c/o Data Protection Officer s Office Wroxton, Nr. Banbury Oxfordshire OX15 6PX England

GDPR DATA PROCESSING NOTICE FOR FS1 RECRUITMENT UK LTD FOR APPLICANTS AND WORKERS

LIFE STYLE CARE PLC. Privacy Statement for Employees. August 2018

DATA PROTECTION POLICY

Recruitment Privacy Notice Cleary Gottlieb Frankfurt & Cologne Offices

SCHOOLS DATA PROTECTION POLICY. Guidance Notes for Schools

GARMIN LTD. Audit Committee Charter. (Amended and Restated as of July 25, 2014)

HYDRASUN LTD RECRUITMENT PRIVACY NOTICE

You can contact St. John s Office of General Counsel with any questions about this notice, our data collection practices, or your rights:

Search Consultancy Limited Privacy Notice

DATA PROTECTION POLICY

Data Protection Policy

GDPR P4 Privacy Policy Statement & Guidance for Employees and External Providers

Syntel Human Resources Privacy Statement

Brasenose College Data Protection Policy Statement v1.2

THE COMPETITION AND CONSUMER PROTECTION COMMISSION JOB APPLICANT PRIVACY NOTICE 1. INTRODUCTION... 2

WORLEYPARSONS RECRUITMENT PRIVACY NOTICE

Applicant Privacy Notice Date: June 1, 2018

DELL BANK INTERNATIONAL D.A.C DATA PROTECTION STATEMENT - USE OF PERSONAL DATA 1

Salesforce s Processor Binding Corporate Rules. for the. Processing of Personal Data

Celgene General Privacy Policy

APPLICANT PRIVACY POLICY

TG Therapeutics, Inc. Audit Committee Charter

Recruitment Privacy Notice

The Data Controller for all personal data stored and processed by Horiba MIRA Ltd is:

RAW MARKETING DATA PROTECTION POLICY

Training Manual. DATA PROTECTION ACT 2018 (DPA18) Incorporating General Data Protection Regulations (GDPR) Data Protection Officer is Mike Bandurak

RSD Technology Limited - Data protection policy: RSD Technology Limited ( the Company )

SPRINT CORPORATION AUDIT COMMITTEE CHARTER

Depending on the circumstances, we may collect, store, and use the following categories of personal information about you:

We reserve the right to update this privacy notice at any time. Please check our website from time to time for any changes we may make.

Stanford University Offline Privacy Notice

TimePlan Education Group Ltd ( the Company ) Data Protection. Date: April Version: 001. Contents

EEA General Data Protection Regulation Privacy Notice - University of Rochester Applicants and Current Employees Located in the EEA

Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents

Recruiting Privacy Statement

P Drive_GDPR_Data Protection Policy_May18_V1. Skills Direct Ltd ( the Company ) Data protection. Date: 21 st May Version: Version 1.

MODA HEALTH CODE OF CONDUCT

Data Protection Policy Approved by: COG Approved: 9 August 2017 Review date: August 2019 Version: Statement of Intent

CV, résumé, cover letter, previous work experience and education information;

Audit Committee Charter

Data Protection Policy

VICTORY CAPITAL HOLDINGS, INC. CORPORATE GOVERNANCE GUIDELINES

WILLIS TOWERS WATSON APPLICANT PRIVACY NOTICE

DEPARTMENT OF PUBLIC WORKS MANAGEMENT MANUAL ADOPTED BY THE BOARD OF PUBLIC WORKS, CITY OF LOS ANGELES. June 20, 2007 PERSONNEL DIRECTIVE NO.

BrightPath Early Leaning Inc. Audit Committee Charter

General Data Privacy Regulation: It s Coming Are You Ready?

GROUPON, INC. CORPORATE GOVERNANCE GUIDELINES

AUDIT COMMITTEE CHARTER

VMS Software Ltd- Data Protection Privacy Policy

Ernst & Young Data Protection Binding Corporate Rules Programme

GROUP DATA PROTECTION POLICY

PRIVACY NOTICE FOR JOB APPLICANTS

PRYSMIAN GROUP ETHICAL CODE

STARWOOD HOTELS & RESORTS WORLDWIDE, INC. CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS

Personal data: By Personal data we understand all information about identified or identifiable natural ( data subject ) according to GDPR

CORPORATE GOVERNANCE GUIDELINES

REX ENERGY CORPORATION CORPORATE GOVERNANCE GUIDELINES

WORKDAY, INC. CORPORATE GOVERNANCE GUIDELINES (September 6, 2018)

AUDIT COMMITTEE CHARTER. Specifically, the Audit Committee is responsible for overseeing that:

Data Protection Employee Privacy Notice

BOARD GUIDELINES ON SIGNIFICANT CORPORATE GOVERNANCE ISSUES

GDPR Policy of Lovedaycare Nursery

DATA PROTECTION POLICY

Privacy Statement About this privacy policy Who are we and how to contact us

Board Policy Manual July 29, 2014

Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018

Stolle Europe Introduction Important information and who we are Controller and contact information Complaints

Employee Privacy Statement

GDPR Webinar 1: Overview of Preparing for the GDPR. T-Minus 441 Days (March 9, 2017) Presenter: Peter Blenkinsop.

2 INFORMATION ACCESS, SHARING, STORAGE & RETENTION

Swansea University Recruitment Privacy Policy

DATA PROTECTION POLICY 2016

HUGO BOSS Social Standards

Verisk Analytics, Inc. Code of Business Conduct and Ethics As Amended June 5, 2018

Tourettes Action Data Protection Policy

EUROPEAN UNION PRIVACY NOTICE

SOP MRS HR Applicant Privacy Notice

Human Resources. Data Protection Policy IMS HRD 012. Version: 1.00

NATIONAL VISION HOLDINGS, INC. CORPORATE GOVERNANCE GUIDELINES

The Audit Committee of the Supervisory Board of CB&I

Transcription:

. SAFE HARBOR PRIVACY POLICY Amended and Restated as of July 20, 2012 I. OBJECTIVES The objective of this policy is to comply with applicable laws and regulations and document the processes and procedures of Kronos for the protection of Kronos employee s Personal Information and to define Kronos policy for data protection under the Safe Harbor Privacy Principles. II. DEFINITIONS Agent - any person or third-party that collects or uses Personal Information or Sensitive Personal Information under the instructions of, and solely for, Kronos or to whom Kronos discloses Personal Information or Sensitive Personal Information for use on Kronos behalf. EEA - the European Economic Area, which includes, among other members, the members of the EU and Norway. EU - the European Union. HR Offices - the local Human Resource administrative office for each respective employee. Kronos Kronos Worldwide, Inc., its successors, subsidiaries, affiliates, divisions and groups. Kronos Network all data processing, information and/or communication systems maintained by Kronos in the U.S. and the EEA. Personal Information data or information relating to an identified or identifiable individual who can be identified, directly or indirectly, by reference to an identification number or to one or more factors specific to his or her physical, physiological, mental, economic, cultural or social identity. Privacy Officer - the individual responsible for the internal audit of processes and procedures to safeguard Personal Information and Sensitive Personal Information and responsible for ensuring that transfers are consistent with applicable laws and regulations. Privacy Offices locations where questions or comments regarding this policy may be submitted. Privacy Offices are identified in the Contact Information section of this policy. Safe Harbor Privacy Principles the U.S.-EU Safe Harbor Privacy Principles and related frequently asked questions published by the U.S. Department of Commerce. Sensitive Personal Information Personal Information that reveals medical or health conditions, race, ethnic origin, political opinions, religious or philosophical beliefs, trade union membership or sexual preference or practices. For each jurisdiction in the EEA for which w:\teams\team_legal\working\kronos worldwide\policies\data privacy\kro-eu-data-privacy-security-policy-120720-fin.docx Page 1 of 5.

Kronos employs individuals, Sensitive Personal Information shall include all other Personal Information about such individuals deemed sensitive by applicable laws and regulations of such jurisdiction. In addition, Kronos will treat as Sensitive Personal Information any information received from its EEA operations or a third-party about an individual where the EEA operation or the third-party treats and identifies the information as Sensitive Personal Information. U.S. the United States of America. III. RESPONSIBILITIES The U.S. Department of Commerce and the European Commission have agreed on the Safe Harbor Principles to enable U.S. companies to satisfy the requirements under EU law that adequate protection will be given to Personal Information transferred between the EU and the U.S. The EEA also has recognized the Safe Harbor Principles as providing adequate data protection (OJ L 45, 15.2.2001, p.47). Consistent with its commitment to protect personal privacy, Kronos adheres to the Safe Harbor Principles. IV. SAFE HARBOR PRIVACY POLICY General Kronos respects individual privacy and values the confidence of its employees, business partners and others. Kronos strives to collect, use and disclose Personal Information in a manner consistent with the laws of the countries in which it does business. This policy sets forth the privacy principles that Kronos follows with respect to Personal Information about its EEA employees transferred to the U.S. in any format including electronic, verbal or paper. Privacy Principles Notice The privacy principles in this policy are based upon the Safe Harbor Principles. Kronos collects and uses Personal Information about individuals solely for Kronos business purposes, including decisions related to employment, promotion, payment of compensation, extension of employee benefits, performance assessment and other similar business purposes common to business and understood by employees. Beyond these purposes, where Kronos collects Personal Information directly from individuals, it will inform the individuals about further purposes for which it collects and uses Personal Information about them. When required by applicable law or regulation or law enforcement agencies, Kronos will provide notice to employees before disclosure of Personal Information for a purpose other than that for which it was originally collected or to a non-agent third-party. Some examples of non- Agent third-parties include, but are not limited to, trade unions that represent Kronos employees, government authorities that require information and other third-parties that have not contracted with Kronos for services. w:\teams\team_legal\working\kronos worldwide\policies\data privacy\kro-eu-data-privacy-security-policy-120720-fin.docx Page 2 of 5.

Choice Kronos will offer individuals the opportunity to refuse to permit a transfer of Personal Information when and if their Personal Information is (a) to be used for a purpose other than the purpose for which it was originally collected or subsequently authorized or (b) to be disclosed to a non-agent third-party. In the case of Sensitive Personal Information, employees have the right to make a free and affirmative (or explicit) choice before a transfer is made to a non-agent thirdparty or for a use incompatible with previously stated purposes. Data Integrity Kronos will use Personal Information only in ways that are in compliance with applicable laws and regulations and compatible with the purposes for which it was collected or subsequently authorized by the individual. As required by applicable laws and regulations, Kronos will take reasonable steps to ensure that Personal Information is accurate, complete and current (to the extent that the individual keeps Kronos updated on such information) and is relevant to its intended use. In this vein, employees will have the responsibility to update Kronos about their Personal Information from time-to-time. Kronos has appointed the Benefits Manager of Kronos (US), Inc. as the Privacy Officer for the U.S. who has the responsibility to monitor compliance with the Safe Harbor Principles. The Vice President, General Counsel in Europe will serve as the Privacy Officer for the EEA, and the HR Offices will serve as the contact point for employees to bring forth any questions or concerns. Transfers Outside Kronos Network If Kronos transfers data outside the Kronos Network, it will obtain assurances from its third-party Agents that they will safeguard Personal Information in accordance with this policy. Examples of appropriate assurances that may be provided by third-party Agents include: a contract that obligates the third-party Agent to provide at least the same level of protection as is required by the relevant Safe Harbor Principles; the Agent is subject to the EU Directive 95/46/EC (the EU Data Protection Directive); or the Agent has self-certified to the U.S. Department of Commerce its adherence to the Safe Harbor Principles in accordance with the guidance provided by the U.S. Department of Commerce. Where Kronos has knowledge that an Agent is using or disclosing Personal Information in a manner contrary to this policy, Kronos will take reasonable steps to stop the use or disclosure of such information. Access and Correction Upon request, Kronos will grant individuals reasonable access to Personal Information that it holds about them. In addition, Kronos will take reasonable steps to permit individuals to correct, amend, or delete information that is demonstrated to be inaccurate or incomplete. Any individual that reviews Personal Information and believes it is inaccurate or incomplete, may w:\teams\team_legal\working\kronos worldwide\policies\data privacy\kro-eu-data-privacy-security-policy-120720-fin.docx Page 3 of 5.

submit a written request to the Privacy Officer in Europe to identify items needing correction. For this purpose, an email or other electronic request via Kronos systems is acceptable. The Privacy Officer will be responsible for reviewing requests for data correction and ensuring the data on file is accurate and complete based on facts presented. Security Kronos will take reasonable precautions to protect Personal Information in its possession from loss, misuse and unauthorized access, disclosure, alteration and destruction. Training Kronos will provide the appropriate training on data protection to any staff member who will have access to Personal Information or Sensitive Personal Information as part of his or her job duties. Such training will, to the extent needed by the staff member, educate him or her on the applicable requirements related to data privacy use, protection, storage and destruction of Personal Information and Sensitive Personal Information. Enforcement Kronos will conduct a compliance audit of its relevant privacy practices on an annual basis. The audit will be conducted by the U.S. and European Privacy Officers, or their designees, and is designed to verify adherence to this policy. Any employee that Kronos determines is in violation of this policy will be subject to disciplinary action up to and including termination of employment. Dispute Resolution Any questions or concerns regarding the use or disclosure of Personal Information should be directed to the Privacy Office, attention European Vice President, General Counsel, at the address given below. Any individual having a question or concern about Personal Information or Sensitive Personal Information must submit a written request providing sufficient details of the issue to the applicable HR Office to allow for an effective evaluation of the issue. The Human Resources staff will investigate and attempt to resolve complaints and disputes regarding use and disclosure of Personal Information in accordance with the principles contained in this policy. For complaints that cannot be resolved between Kronos and the complainant, Kronos has agreed to participate in the dispute resolution procedures of the home country of the employee and to utilize the panel established by the European data protection authorities to resolve disputes pursuant to the Safe Harbor Principles. V. LIMITATION ON APPLICATION OF PRINCIPLES Adherence by Kronos to these Safe Harbor Principles may be limited (a) to the extent required to respond to a legal or ethical obligation (for example, a national security requirement); and (b) to the extent expressly permitted or required by an applicable law or regulation. w:\teams\team_legal\working\kronos worldwide\policies\data privacy\kro-eu-data-privacy-security-policy-120720-fin.docx Page 4 of 5.

VI. DATA PRIVACY AND TECHNOLOGY Kronos views the internet and the use of other technologies as valuable tools for communicating and interacting with consumers, employees, healthcare professionals, business partners and others. Kronos recognizes the importance of maintaining the privacy of information collected online and has created specific policies and procedures governing the treatment of Personal Information and Sensitive Personal Information collected through web sites that it operates. Each employee shall utilize Kronos information technology systems and data on such systems as required by Kronos Electronic Data Policy, this policy and any other applicable Kronos policy. With respect to Personal Information or Sensitive Personal Information that is transferred from the EEA to the U.S., this policy incorporates any applicable future additional or amended safe harbor principles published by the U.S. Department of Commerce regarding requirements and standards with respect to personal data exchanges from the EEA to the U.S. VII. CONTACT INFORMATION Questions or comments regarding this policy should be submitted to the applicable Kronos Privacy Office in writing by mail as follows: Kronos Privacy Office (Europe) Kronos Privacy Office (United States) Kronos International, Inc. Kronos (US), Inc. Vice President, General Counsel Benefits Manager Peschstrasse 5 5430 LBJ Freeway, Suite 1700 D-51373 Leverkusen Germany Dallas, Texas 75240 VIII. CHANGES TO DATA PRIVACY POLICY This policy may be amended from time to time, consistent with the requirements of the Safe Harbor Principles. A notice will be posted on the Kronos intranet and/or bulletin boards at Kronos worksites for 60 days whenever this policy is changed in a material way. IX. AFFIRMATIVE STATEMENT OF COMPLIANCE Kronos complies with the Safe Harbor Principles regarding the collection, use and retention of Personal Information from EEA member countries. Kronos has certified that it adheres to the Safe Harbor Privacy Principles of notice, choice, onward transfer, security, data integrity, access and enforcement. To learn more about the Safe Harbor program, and to view the Kronos certification, please visit www.export.gov/safeharbor. w:\teams\team_legal\working\kronos worldwide\policies\data privacy\kro-eu-data-privacy-security-policy-120720-fin.docx Page 5 of 5.