Privacy Policy for processing information containing personal data
JSC «Krasny Pishchevik»
REGULATION 16-11/10 No. 3
Bobruisk
On the procedure for ensuring confidentiality when processing information containing personal data
CHAPTER 1. GENERAL PROVISIONS
This Regulation establishes the security methods applied at JSC «Krasny Pishchevik» (hereinafter referred to as the Company, Operator) when processing personal data, which includes any action or set of actions performed with personal data, including collection, systematization, storage, modification, use, depersonalization, blocking, distribution, provision, and deletion of personal data.
For the purposes of this Regulation, terms and definitions are used in accordance with the Operator’s Policy «Regarding the processing of personal data», the Regulation «On the procedure for processing and protection of personal data», and other local acts of the Company aimed at protecting personal data.
The requirement to ensure confidentiality when processing personal data means that Company officials authorized to process personal data, and other persons who have gained access to personal data, are strictly required not to allow their distribution without the consent of the personal data subject or the existence of another legal basis.
Ensuring the confidentiality of personal data is not required in the case of:
- depersonalization of personal data (actions resulting in the impossibility of determining the affiliation of personal data to a specific personal data subject without the use of additional information);
- publicly available personal data (personal data disclosed by the personal data subject themselves, or with their consent, or disclosed in accordance with the requirements of legislative acts).
Lists of personal data and persons responsible for the storage and processing of personal data are approved by order of the Company’s Director. Processing and storage of confidential data by persons not specified in the order is prohibited.
In order to ensure compliance with confidentiality and security requirements when processing personal data, the Company provides officials working with personal data with the necessary conditions to fulfill these requirements:
- familiarizes employees under signature with the requirements of the Operator’s Policy «Regarding the processing of personal data of JSC «Krasny Pishchevik», the Regulation «On the procedure for processing and protection of personal data», this Regulation, job descriptions, and other local acts of the Company in the field of ensuring confidentiality and security of personal data;
- provides storage facilities for documents, means for accessing information resources (keys, passwords, etc.);
- trains on the rules for operating information security tools;
- conducts other necessary measures.
Company officials working with personal data are prohibited from disclosing them orally or in writing to anyone, unless required by official necessity. After the preparation and transfer of a document, draft files and document versions are transferred by the employee who prepared them to marked media intended for storing personal data. Without the approval of the head of the structural unit and the personal data protection specialist, the creation and storage of databases (card files, file archives, etc.) containing confidential data is prohibited.
Company officials working with personal data are required to use information about personal data exclusively for purposes related to the performance of their job duties.
Upon termination of the performance of job functions related to the processing of personal data, all information media containing personal data (originals and copies of documents, machine-readable and paper media, etc.) that were at the disposal of the official in connection with the performance of job duties must be handed over by the employee to their immediate supervisor.
Transfer of personal data to third parties is permitted only in cases established by the legislation of the Republic of Belarus, the Operator’s Policy «Regarding the processing of personal data», the Regulation «On the procedure for processing and protection of personal data», this Regulation, job descriptions, and other local legal acts of the Company in the field of ensuring confidentiality and security of personal data.
In cases where the transfer of personal data to third parties is not related to the performance of a duty provided for by legislative acts, the corresponding transfer is carried out by the Company official responsible for processing personal data exclusively on the basis of a written or oral instruction from the head of the structural unit, in coordination with the personal data protection specialist. The transfer of information and documents containing personal data is formalized by drawing up an act in the established form. The official who provided personal data to third parties sends a written notification to the personal data subject about the fact of the transfer of their data to third parties.
Transfer of personal data by phone, fax, or email is prohibited, except in cases established by legislation and local acts in force in the Company. Responses to requests from citizens and organizations are provided in a volume that allows for not disclosing personal data in the responses, except for data contained in the applicant’s materials or published in publicly available sources.
Company officials working with personal data are required to immediately inform their immediate supervisor and/or the personal data protection specialist about all facts known to them regarding unauthorized access or attempts to gain access to personal data by third parties, loss or shortage of information media containing personal data, identification cards, passes, safe (storage) keys, personal seals, electronic keys, and other facts that may lead to unauthorized access to personal data, as well as about the causes and conditions of possible leakage of this information.
Officials performing the processing of personal data are subject to disciplinary, administrative, civil, or criminal liability in accordance with the legislation of the Republic of Belarus for failure to comply with the requirements of confidentiality and protection of personal data.
CHAPTER 2. PROCEDURE FOR ENSURING SECURITY WHEN PROCESSING PERSONAL DATA WITHOUT THE USE OF AUTOMATION TOOLS
Processing of personal data, including that contained in a personal data information system or extracted from such a system, is considered to be carried out without the use of automation tools (non-automated) if such processing is carried out with the direct participation of a person.
The head of the structural unit processing personal data without the use of automation tools:
- determines the storage locations for personal data (material media);
- monitors the presence of conditions in the structural unit that ensure the safety of personal data and exclude unauthorized access to them;
- informs persons processing personal data without the use of automation tools about the list of processed personal data, as well as about the features and rules for carrying out such processing;
- organizes separate, i.e., preventing mixing, storage of material media of personal data (documents, disks, floppy disks, USB flash drives, etc.), the processing of which is carried out for different purposes.
The list of persons having access to personal data processed by non-automated means is established by order of the Company’s Director.
When recording personal data on material media, it is not allowed to record personal data on one material medium if the purposes of processing are obviously incompatible. For the processing of different categories of personal data carried out without the use of automation tools, a separate material medium must be used for each category of personal data.
In case of incompatibility of processing purposes, the head of the structural unit must ensure separate processing of personal data.
Destruction or depersonalization of a part of personal data, if permitted by the material medium, must be carried out in a way that excludes further processing of this personal data while maintaining the possibility of processing other data recorded on the material medium (deletion, blacking out).
Clarification of personal data when processing them without the use of automation tools is carried out by updating or changing the data on the material medium.
CHAPTER 3. PROCEDURE FOR ENSURING SECURITY WHEN PROCESSING PERSONAL DATA USING AUTOMATION TOOLS
Processing of personal data using automation tools means performing actions (operations) with such data using computing objects in the Company’s computer network (hereinafter — KSO). The security of personal data during their processing in the KSO is ensured by a personal data protection system, which includes organizational measures and information security tools, as well as information technologies used in the KSO. Technical and software information security tools must meet the requirements established in accordance with the legislation of the Republic of Belarus to ensure information protection. Information security tools used in the KSO undergo a conformity assessment procedure in the established manner.
Admission of persons to the processing of personal data using automation tools is carried out on the basis of an order from the Company’s Director, provided that access passwords to the individual accounts of these persons are ensured. Work with personal data contained in the KSO is carried out in accordance with the Company’s local acts, which the employee whose job duties include processing personal data familiarizes themselves with under signature.
Work with personal data in the KSO must be organized in such a way as to ensure the safety of personal data media and information security tools, and to exclude the possibility of unauthorized persons being in these premises without control.
Computers and/or electronic folders containing files with personal data must be protected for each user by individual access passwords that meet the requirements of the Company’s local acts.
Sending personal data without the use of special security tools over public communication networks, including the Internet, is prohibited.
When processing personal data in the KSO, users must ensure:
- use of designated sections (directories) of information media built into technical equipment or removable marked media;
- prevention of physical impact on technical equipment for automated processing of personal data, which could disrupt their functioning;
- constant use of antivirus software to detect infected files and immediate restoration of personal data modified or destroyed as a result of unauthorized access to them;
- prevention of unauthorized removal from premises, installation, connection of equipment, as well as deletion, installation, or configuration of software.
When processing personal data in the KSO, the production automated control system bureau must ensure:
- training of persons using information security tools applied in the KSO on the rules for working with them;
- accounting for persons authorized to work with personal data in the KSO, access rights, and passwords;
- accounting for the information security tools used, as well as operational and technical documentation for them;
- control over compliance with the conditions for using information security tools provided for by operational and technical documentation;
- description of the personal data protection system.
Specific requirements for the protection of personal data in individual automated systems of the Company are determined by instructions for their use and operation, approved in the established manner.
CHAPTER 4. PROCEDURE FOR ACCOUNTING, STORAGE, AND HANDLING OF REMOVABLE PERSONAL DATA MEDIA, HARD COPIES, AND THEIR DISPOSAL
All removable media (disks, floppy disks, USB flash drives, etc.) containing personal data that are in storage and circulation in the Company are subject to accounting. Each removable medium with personal data recorded on it must have a label indicating its unique inventory number.
Accounting and issuance of removable media on which personal data processing is intended are carried out by employees of the production automated control system bureau. Company employees receive an accounted removable medium from an authorized employee for a specific period to perform work. Upon receipt, corresponding entries are made in the log of personal accounting of removable personal data media (hereinafter — the accounting log), which is maintained in the production automated control system bureau. Upon completion of the work, the user returns the removable medium to the authorized employee for storage, which is recorded in the accounting log.
When working with removable media containing personal data, it is prohibited to:
- store removable media with personal data together with open information media, on desktops, or leave them unattended or transfer them to other persons for storage;
- remove removable media with personal data from office premises for work at home, in hotels, etc.
When sending or transferring personal data to recipients, only the data intended for the recipients is recorded on the removable media. Sending personal data to recipients on removable media is carried out in the manner established for official-use documents. Removal of removable personal data media for direct transfer to a recipient is carried out only with the written permission of the head of the Company’s structural unit, in coordination with the personal data protection specialist.
Facts of loss of removable media containing personal data or disclosure of the information contained therein must be immediately reported to the personal data protection specialist. An act is drawn up for lost media. Corresponding notes are made in the accounting logs.
CHAPTER 5. FINAL PROVISIONS
All employees of the Company’s structural units and persons performing work under contracts and agreements who have a relationship to the processing of personal data of Company employees must be familiarized with this Regulation under signature in the Log of access to personal data processing. The person responsible for the briefing is the personal data protection specialist.
