1. General Provisions
1.1. This Personal Data Processing Policy (hereinafter — the PD Processing Policy) of Individual Entrepreneur Arkunov O.V. (hereinafter – the Operator), INN (Tax ID) 682000958919 located at the address: 15 Romashkovaya Street, Tambov, 392024, has been developed in accordance with the Constitution of the Russian Federation, the Labour Code of the Russian Federation, the Civil Code of the Russian Federation, Federal Law No. 149-FZ as of July 27, 2006 "On Information, Information Technologies and Information Protection", Federal Law No. 152-FZ as of 27 July 2006 "On Personal Data", Decree of the RF Government No. 1119 as of November 1, 2012 "On approval of requirements for protection of personal data at their processing in personal data information systems", other federal laws and regulatory legal acts.
1.2. The Policy has been developed taking into account the requirements of the Constitution of the Russian Federation, legislative and other regulatory legal acts of the Russian Federation in the field of personal data protection.
1.3. The PD Processing Policy is designed to protect the rights and freedoms of the subject of personal data at processing of his/her personal data (hereinafter referred to as - the PD).
1.4. The Policy provisions shall serve the basis for development of the local regulations governing the issues of processing the personal data of employees of Individual Entrepreneur Arkunov O.V. and other subjects of the personal data.
2. Purposes of personal data processing
Personal data shall be processed by the Operator for the following purposes:
1) Performing and fulfilling the functions, powers and duties assigned to the Operator by the legislation of the Russian Federation, in particular:
- Fulfillment of legislative requirements in the sphere of labour and taxation;
- Keeping current accounting and tax records, development, execution and timely submission of accounting, tax and statistical reports;
- Fulfillment of the legislation requirements on determining the procedure of processing and protection of personal data for citizens who are clients or contractors of Individual Entrepreneur Arkunov O.V. (hereinafter - subjects of personal data);
2) Exercising of the rights and legal interests of Individual Entrepreneur Arkunov O.V. within the framework of the activities provided by the Certificate and other local regulations of Individual Entrepreneur Arkunov O.V. or third parties or achieving other socially significant goals;
3) For other legal purposes.
3. Legal basis for personal data processing
The personal data processing is based on the following federal laws and regulations:
- Constitution of the Russian Federation;
- Labour Code of the Russian Federation;
- Federal Law No. 152-FZ as of July 27, 2006 "On Personal Data";
- Federal Law No. 149-FZ "On Information, Information Technology and Information Protection" as of July 27, 2006.
- Provisions on specific terms and conditions of personal data processing carried out without using automation facilities. Approved by Decree of the Government of the Russian Federation No. 687 as of September 15, 2008.
- Decree as of November 1, 2012 No. 1119 on the approval of requirements for personal data protection when processing them by personal data information systems.
- Order of the Federal Service for Technical and Export Control of Russia (FSTEC) No. 55, No. 86 of the Federal Security Bureau of Russia, No. 20 of Mininformsvyaz of Russia as of February 13, 2008 "On approval of the procedure for classification of personal data information systems";
- Order of the Federal Service for Technical and Export Control of Russia (FSTEC) No. 21 as of February 18, 2013 "On approval of the composition and content of organizational and technical measures to ensure the security of personal data when processing them in personal data information systems";
- Order of Roskomnadzor No. 996 as of September 5, 2013 "On approval of requirements and methods for depersonalization of personal data";
- Order of the Federal Tax Service No. MMV-7-3/611 as of November 17, 2010 "On approval of the form for information on physical persons' incomes and of recommendations for filling it out, of the format of information on physical persons' incomes in an electronic form and of handbooks".
- Other regulatory legal acts of the Russian Federation and regulatory documents of authorized state authorities.
4. List of actions with personal data
When PD processing, the Operator shall perform the following actions with such PD: collection, recording, systematization, accumulation, storage, refinement (updating, modification), extraction, depersonalization, blocking, deletion, destruction of personal data.
5. Composition of personal data being processed
5.1. The Operator shall treat the following subjects of personal data:
- The Operator's employees;
- The Operator's clients;
- The Operator's contractors;
- Individuals who have applied to the Operator in accordance with the procedure, stipulated by the Federal Law "On the procedure for consideration of applications of citizens of the Russian Federation".
5.2. Composition of the PD of each category of subjects listed in paragraph 5.1 of these Regulations shall be determined in accordance with regulatory documents listed in paragraph 3 of these Regulations, as well as regulatory documents of the Institution issued to ensure their execution.
5.3. In cases stipulated by the current legislation, the subject of personal data decides to provide his/her PD to the Operator and agrees to their processing freely, voluntarily and in their interest.
5.4. The Operator shall ensure the compliance of the content and volume of the PD processed with the stated processing purposes and, if necessary, shall take measures to eliminate their redundancy in relation to the stated processing purposes.
5.5. Individual Entrepreneur Arkunov O.V. does not process special categories of personal data related to race, nationality, political views, religious or philosophical beliefs, intimate life.
6. The personal data processing procedure
6.1. Personal data processing by Individual Entrepreneur Arkunov O.V. is carried out in the following ways:
- By means of application the non-automated personal data processing procedure.
7. Provision of personal data protection when they are being processed by the Operator
7.1. The Operator shall take measures necessary and sufficient to ensure that the obligations stipulated by Federal Law No. 152-FZ as of July 27, 2006 "On Personal Data" and the regulatory legal acts adopted in accordance with it are fulfilled. The Operator shall independently define structure and the list of the measures necessary and sufficient to ensure the fulfillment of the obligations provided for by Federal Law No. 152 as of July 27, 2006 "On Personal Data", Government Order No. 687 as of September 15, 2008 "On approving the Regulation on the specifics of personal data processing performed without the use of automation facilities", Government Order No. 1119 as of November 1, 2012 "On the approval of requirements for personal data protection when processing them by personal data information systems", Order of the FSTEC of Russia No. 21 as of February 18, 2013 "On approval of the composition and content of organizational and technical measures to ensure the security of personal data when processing them in personal data information systems" and other regulatory legal acts, unless otherwise provided by the federal laws. These measures include:
- Assignment of the Operator responsible for the organization of personal data processing;
- Publication by the Operator of documents defining the Operator's policy concerning personal data processing, local acts related to the personal data processing, as well as local acts establishing procedures aimed at preventing and detecting violations of the legislation of the Russian Federation and eliminating the consequences of such violations;
- Application of legal, organizational and technical measures to ensure the personal data protection;
- Implementation of internal control and (or) audit of compliance of personal data processing with the Federal Law "On Personal Data" and regulatory legal acts adopted in accordance with it, requirements for personal data protection, the Operator's policy concerning personal data processing, and local acts of the Operator;
- Determination of the assessment of damage that may be caused to subjects of personal data in case of violation of the Federal Law "On Personal Data", the ratio of the said damage to the measures taken by the Operator to ensure compliance with obligations under the Federal Law "On Personal Data";
- Familiarization of the Operator's employees directly carrying out the personal data processing with provisions of the legislation of the Russian Federation about the personal data, including requirements for protection of the personal data, the documents defining the policy of the Operator concerning processing of the personal data, local certificates concerning processing of the personal data, and (or) training of these employees.
7.2. When processing personal data, the Operator shall take the necessary legal, organizational and technical measures or ensure that they are taken to protect personal data from an unauthorized or accidental access to it, destruction, modification, blocking, copying, provision, distribution of personal data, as well as from other illegal acts attributed to personal data.
8. The right of the subject of personal data to access his/her personal data
8.1. The PD subject has the right to request the Operator to clarify his/her personal data, block or destroy them if the personal data is incomplete, outdated, inaccurate, illegally obtained or may be not necessary for the stated purpose of processing, as well as to take legal measures to protect their rights.
8.2. The information is provided to the subject of the personal data or his/her representative by the operator at the address or at reception of request of the subject of the personal data or his/her representative. The request shall contain the number of the basic document certifying the identity of the subject of the personal data or his/her representative, information on date of delivery of the specified document and the issuing authority, the data confirming participation of the subject of the personal data in relations with the Operator (contract number, date of conclusion of the contract, conditional verbal designation and (or) other information), or information otherwise confirming the processing of personal data by the Operator, the signature of the subject of personal data or his/her representative. The request can be sent in the form of an electronic document and signed with an electronic signature in accordance with the legislation of the Russian Federation.
8.3 The Operator has the right to refuse the subject of personal data to make a repeated request. Such refusal must be motivated. The Operator is obliged to provide the proofs of justification of any such refusal to fulfill the repeated request.
8.4 The subject of personal data has the right to receive the information relating to the processing of his/her personal data, including those containing:
- Confirmation of personal data processing by the Operator;
- Legal grounds and purposes of personal data processing;
- Goals and methods of personal data processing used by the Operator;
- Name and location of the Operator, information about persons (except for the Operator's employees) who have access to personal data or to whom personal data may be disclosed under the contract or agreement with the Operator or subject to the corresponding federal law;
- Processed personal data related to the respective subject of personal data, the source of their receipt, unless another procedure for submitting such data is provided for by federal law;
- Terms of processing of personal data, including the terms of their storage;
- The procedure of exercising by the subject of the personal data of the rights provided by the Federal Law "On Personal Data";
- The information on the carried out or on prospective transboundary transfer of the data;
- The name or surname, first name, patronymic and address of the person who processes personal data on behalf of the Operator, if the processing is or will be entrusted to such person.
8.5 If the subject of the personal data considers that the Operator carries out processing of his/her personal data with infringement of requirements of the Federal Law "On Personal Data" or otherwise violates his/her rights and freedoms, the subject of personal data has the right to appeal the actions or omissions of the Operator to the body authorized to protect the rights of subjects of the personal data, or in a judicial order.
8.6. The subject of personal data has the right to protect his/her rights and legal interests, including compensation for damages and (or) compensation for non-pecuniary damage in court.