Information on Data Protection
The following Data Protection Information has been prepared on the basis of the Data Management Regulations of EMKI-cert Kft. with ID ME6100_v1.0, which entered into force on 30.07.2022.
Data Protection Information
The Data Protection Information has been prepared taking into account the requirements of the relevant EU and national legislation, which are:
• Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Regulation (EC) No 95/46 Data Protection Regulation / GDPR)
• 2011 CXII. Act on the Right to Information Self-Determination and Freedom of Information
Terms used in this document:
Interested party: a natural person who can be identified or identifiable on the basis of any information, directly or indirectly identifiable, in particular an identifier such as name, identification number, location data, online identifier or a natural, physiological, genetic, intellectual, economic, cultural or social identifier. identified by one or more factors
Personal data: any information about the data subject
Consent: a voluntary, clear and well-informed statement of the will of the data subject, by which the data subject indicates, by means of a statement or other conduct unequivocally expressing his or her will, that he or she consents to the processing of personal data concerning him or her
Data controller: a natural or legal person or an organization without legal personality who -within the framework set by law or a binding act of the European Union-determines individually or together with others the purpose of data processing and makes and implements decisions on data processing (including the means used)
Data management: any operation or total operation carried out on the data, irrespective of the procedure used, in particular their collection, recording, systematisation, storage, alteration, use, interrogation, transmission, disclosure, coordination or linking, blocking, erasure and destroying, and prevent further use of the data, take photographs, sounds or images, and record physical characteristics that identify the person (e.g. fingerprints, palm prints, DNA samples, iris images)
Data transfer: making the data available to a specific third party
Disclosure: making the data available to anyone
Data erasure: making the data unrecognizable in such a way that it is no longer possible to recover it
Data set: the totality of the data managed in one register
Data protection incident: a breach of data security which results in the accidental or unlawful destruction, loss, alteration, unauthorized transfer or disclosure of personal data transmitted, stored or results in unauthorized access to them.
Data breach: a breach of data security that results in, or unauthorised access to, or unauthorised access to, the accidental or unlawful destruction, destruction, destruction, unauthorised transmission or disclosure of personal data transmitted, stored or otherwise processed
EMKI-cert Kft. has prepared its regulations in accordance with the above legal regulations and complies with the provisions thereof in connection with the processing of personal data of natural persons, as it is committed to the protection of personal data. EMKI-cert Kft. does not collect or manage any special, genetic, health or biometric data during its activities.
EMKI-cert Kft. handles the data in a lawful and fair and transparent manner in accordance with Article 5 of the GDPR Regulation. EMKI-cert Kft. Collects the data, limited to the necessary scope for a specific purpose, only for a specific, clear and lawful purpose. It is a basic principle is that EMKI-cert Kft. stores the data for a limited time, accurately and up-to-date. In view of the sensitive and confidential nature of personal data, EMKI-cert Kft. makes every effort to ensure the proper security of the data.
EMKI-cert Kft. does not send unsolicited letters (newsletter, advertising, direct marketing materials) to its clients, their representatives or other organizations, unless a given person explicitly consents to providing a newsletter to EMKI-cert Kft. or inform you of any other offers (training, etc.). EMKI-cert Kft. pays special attention to the fact that personal data is handled and stored only to the extent and for the time necessary to carry out its certification and training activities. EMKI-cert Kft. qualifies as a data controller in accordance with the above legislation. In case of data protection issues, you can contact the managing director available at the central telephone number or e-mail address of EMKI-cert Kft.
The measures of EMKI-cert Kft. have been designed in accordance with the above principles
-the requirements for the processing of personal data, in particular the principles of data processing and the effective enforcement of data subjects’ rights in a reasonably accessible manner, taking into account the current state of science and technology and the costs of implementing the measures, and
-are suitable and adequate to ensure that, by default, only such and as much personal data are processed to the extent and for the duration necessary for the purpose of data processing, and that personal data processed by EMKI-cert Kft. cannot become publicly available without the express will of the data subject
EMKI-cert Kft. is not obliged to employ a data protection officer based ont he regulatory requirements, however, it continuously monitors the provisions of the legislation in order to react immediately if the obligation arises.
EMKI-cert Kft. obtains and handles personal data from clients and interested parties from the following sources during its activities:
- data of the contact persons of the clients and contracting authorities provided on a voluntary basis in connection with the certification and educational activities: name, position, e-mail address, telephone number of the contact person;
- details of the participants in the training provided on a voluntary basis in connection with the educational activity: name, place of work, telephone number and / or e-mail address of the participant;
- voluntary information from interested parties on other issues: name, contact information (e-mail address and / or telephone number).
We would like to inform our clients that the precondition for concluding a certification or service contract is the provision of the minimum personal data indicated above, as in the absence of this EMKI-cert Kft. is not in a position to enter into a contract with the client.
EMKI-cert Kft. does not collect, manage or retain other personal data in addition to the minimum set of data specified above, either tomorrow or in any other way.
EMKI-cert Kft. only transmits data to an official supervisory authority (eg market surveillance, accreditation, designating body), if it is obliged to do so by order or decision. EMKI-cert Kft. carries out data processing only to the extent necessary, for which the managing director or an employee appointed by him for this task is responsible. EMKI-cert Kft. Does not disclose personal data in any form and for any reason.
Method of handling personal data, retention period:
Personal data related to certification and educational activities (data necessary for conducting and organizing audit activities)
Handled on a paper basis: On the Request for Quotation, on audit documents
Electronically handled: On audit documents
Retention period: 5 years after the certification cycle
Personal data of participants in training (data required for organizing education, issuing certificates)
Handled on a paper basis: Application form for education, certificate
Electronically handled: Electronic version of certificates
Retention period: 5 years
Personal data of interested parties
Paper-based: Postal correspondence
Electronically handled: Electronic mail
Retention period: 5 years
If any incident occurs in connection with the data management of EMKI-cert Kft. the Managing Director of EMKI-cert Kft. reports this immediately, but not later than wihin 72 hours ont he NAIH’s regularized interface (https://www.naih.hu/adatvedelmi-incidensbejelent--rendszer.html), unless it is probable that the rights of the party concerned will not be jeopardized. If based on the classification of the incident, it is likely to pose a high risk to the interested parties EMKI-cert Kft. shall immediately notify the interested users. The information shall include the nature of the data protection incident, the name and contact details of the Managing Director as contact person, the likely consequences of the data protection incident and the measures taken or planned to deal with the data protection incident.
EMKI-cert Kft. provides all the means for the data subjects (whose personal data it handles) to control their personal data and their use. Therefore, EMKI-cert Kft. provides the following rights to the interested parties:
- right to prior information (to be informed of the facts relating to the processing prior to the start of the processing)
- right of access (at the request of the data controller to make personal data and information related to their processing available)
- right to rectification (at the request of the data controller to correct or clarify his / her personal data)
- the right to restrict data processing (at the request of data controller to restrict the processing of personal data)
- right to erasure (delete your personal data at the request of the data controller)
- right to data portability (e.g. initiating the transfer of certification to another certification body), if requested by the party concerned
- right to object to the processing of your data.
You can submit an application to enforce the rights of the interested party at the e-mail address info@emki-cert.hu which EMKI-cert Kft. assess as soon as possible but within a maximum of 25 days and also notified the individual of its decision in electronic form. EMKI-cert Kft. retains the related e-mail as a record.
If EMKI-cert Kft. rejects the data subject's request to correct, delete or restrict the processing of personal data managed by EMKI-cert Kft., it shall immediately inform the data subject in writing of the fact of the rejection and its legal and factual reasons and the data subject’s rights and how to enforce them under the Act CXII of 2011 on Informational and Freedom of Information.
Supervisory authority regarding legal compliance:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: H-1055 Budapest, Falk Miksa str. 9-11., Hungary
Web: www.naih.hu
E-mail: ugyfelszolgalat@naih.hu
Phone: +36 1 391-1400
- MUNKAVÉDELEM
- KÖRNYEZETVÉDELEM
- ADR
