GEOLOGICAL SURVEY OF FINLAND 1 (8) PRIVACY POLICY EU General Data Protection Regulation, articles 12 14

Similar documents
Privacy Policy Hafliger Films SpA

Haaga-Helia University of Applied Sciences Privacy Notice for JUSTUS publication data storage service

SCALA FUND ADVISORY PRIVACY POLICY

Haaga-Helia University of Applied Sciences Privacy Notice for Urkund Plagiarism Detection Software

Privacy Notice - Stora Enso s Customer and Sales Register. 1 Controller

Haaga-Helia University of Applied Sciences Privacy Notice for Student Welfare Services

PRIVACY POLICY (extended) Personal Data Act (523/1999) 10 and 24 EU General Data Protection Regulation 2016/679

PRIVACY NOTICE 1. Introduction

Rights of Individuals under the General Data Protection Regulation

Haaga-Helia University of Applied Sciences Privacy Notice for the Laura Recruitment Service

More detailed information, including the information about your rights is available below.

In compliance with the requirements of the EU General Data Protection Regulation (GDPR, Articles 13, 14 and 30)

2. Which personal data is processed by SF Studios and from which source does the personal data originate?

Integrity Notice. Fjärde AP-fonden (AP4)

POLICY. Art. 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016

Privacy Notice - Stora Enso s Supplier and Stakeholder Register. 1 Purpose

The legal basis for the data collection described above is user s consent in accordance with Article 6(1)(1)(a) of the GDPR.

ZENITO OY Client register

FIRSTBEAT TECHNOLOGIES OY DESCRIPTION OF PERSONAL DATA PROCESSING FOR PARTNERS - FIRSTBEAT LIFESTYLE ASSESSMENT

Haaga-Helia University of Applied Sciences Privacy Notice for Student Administration

Talenom Plc. Description of Data Protection and Descriptions of Registers

Privacy Statement for Use of the Certification Service of Swisscom (sales name: "All-in Signing Service")

Privacy Statement for Use of the Trust Service of Swisscom IT Services Finance S.E., Austria

PS Mailing Services Ltd Data Protection Policy May 2018

Information memorandum. SUNČANI HVAR d.d.

Data subject ( Customer or Data subject ): individual to whom personal data relates.

Contract Services Europe

Islam21c.com Data Protection and Privacy Policy

Diaconia University of Applied Sciences. Data protection officer Mari Nyrhinen

Tampere University of Technology Privacy Policy 1 (5) 18/06/2018

This privacy policy describes how Stockholm Design Lab Aktiebolag ( SDL ) processes personal data regarding our clients contact persons.

Name: Aho Terhi Title: ecommerce Manager. Phone: terhi.aho(at)finavia.fi Name: Närvänen Carita Title: Development Manager

COMPUTAMATRIX LIMITED T/A MATRICA Data Protection Policy September Table of Contents. 1. Scope, Purpose and Application to Employees 2

Wonde may collect personal information directly from You when You:

1 About GfK and the Survey What are personal data? Use of personal data How we share personal data... 3

Identity of the controller: CHARVAT CTS a.s., ID No.: , with the registered office at Okrinek 53, Podebrady, Czech Republic, Postcode

Data Subject Access Request Form (GDPR)

Privacy Notice For Ghana International Bank Plc customers

Privacy Policy Section A Section B Section C Section D

WE ARE COMMITTED TO PROTECTING YOUR PERSONAL DATA

Data Subject Access Request Form (GDPR)

POLICY. Art. 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016

PRIVACY POLICY FOR THE LIDC 2018 INTERNATIONAL CONGRESS

This Policy has been prepared with due regard to the General Data Protection Regulation (EU Regulation 2016/679) ( GDPR ).

PRIVACY NOTICE Olenex Sarl

Data Processing Policy

DISCLOSURE ON THE PROCESSING OF PERSONAL DATA LAST REVISION DATE: 25 MAY 2018

DISCLOSURE PURSUANT TO ART. 13 EU REGULATION No. 2016/679 (GDPR) Customers and prospects

Privacy Notice. 1. Name and contact details of the data controller

CEM Benchmarking Privacy Policy

Blue Alligator Company Privacy Notice (Last updated 21 May 2018)

1. Data Controller Metsäliitto Cooperative ( Metsä Wood ) registered address of the head office at Revontulenpuisto 2, Espoo, Finland

Data Processor Agreement

PRIVACY NOTICE (TIER 4)

INFORMATION TO BE GIVEN 2

I. Name and Address of the Controller

Privacy policy. Definitions and interpretation

EU GDPR & ISO Integrated Documentation Toolkit integrated-documentation-toolkit

INFORMATION NOTE ON DATA PROCESSING

Information leaflet about processing of personal data (

Link Exhibitions Privacy Policy

Online Ad-hoc Privacy Notice

Privacy Policy. In this data protection declaration, we use, inter alia, the following terms:

Latest version, please translate and adapt accordingly!

INFORMATIVE NOTICE ON PERSONAL DATA PROCESSING

Data Processing Agreement

- GDPR (General Data Protection Regulation) is the new Data Protection Regulation of the European Union;

PRIVACY POLICY PRIVACY POLICY

2.3 seconds. I accept these 50 pages of legalese I haven t read

INFORMATION TO BE GIVEN 2

Impacts of the GDPR in Afnic - Registrar relations: FAQ

NIPPON VALUE INVESTORS DATA PROTECTION POLICY

Privacy Policy. Data Controller - the entity that determines the purposes, conditions and means of the processing of personal data

Kährs Group s Privacy Policy

Data security statement Volunteers

Privacy Policy Inhouse Manager Ltd

PRIVACY POLICY OF THE WEB SITE

Brasenose College ICT Systems Privacy Notice (v1.2)

PRIVACY NOTICE STORM RECRUITMENT UNIT 11, 2 ND FLOOR CHARLESLAND CENTRE, GREYSTONES, CO. WICKLOW 1. INTRODUCTION

Part B of this Policy sets out the rights that all individuals have in relation to the collection and use of your personal information

PRIVACY STATEMENT FOR DATA COLLECTED FOR DATA COLLECTED VIA ON-LINE SURVEYS

Graff Search Limited ( Graff Search ) is a recruitment agency and recruitment business.

This Privacy Statement applies to data processing carried out by:

the processing of personal data relating to him or her.

GENERAL DATA PROTECTION REGULATION (GDPR)

Data Protection Policy

A. Sample Data Protection Statement in Accordance with the GDPR

Jefferies EMEA Privacy Notice

To make that choice, please click under privacy policy the checkbox (

UWTSD Group Data Protection Policy

Privacy Notices under #GDPR: Have you noticed my notice?

Within the meanings of applicable data protection law (in particular EU Regulation 2016/679, the GDPR ):

RECRUITMENT DATA PROTECTION NOTICE. AImotive Ltd.

GDPR RECRUITMENT POLICY

PRIVACY STATEMENT August 2018

SCHOOL SUPPLIERS. What schools should be asking!

All data subjects whose personal data is collected, in line with the requirements of the GDPR.

ACCOUNTING TECHNICIANS IRELAND DATA PROTECTION POLICY GENERAL DATA PROTECTION REGULATION

Privacy policy SIdP website EU 2016/679

Privacy Policy CARGOWAYS Logistik & Transport GmbH

Transcription:

1 (8) EU General Data Protection Regulation, articles 12 14 14 May 2018 GTK/151/00.19/2016 Juoni case management system Data controller Contact person in matters related to the register Contact details of the data protection officer Name of the register Geological Survey of Finland P.O. Box 96, FI-02151 Espoo, Finland Tel. +358 29 503 0000 gtk@gtk.fi Armi Helenius P.O. Box 96, FI-02151 Espoo, Finland Tel. +358 29 503 0000 tietosuojavastaava@gtk.fi Juoni case management system Data is mainly stored in electronic format. However, if contacting take place in paper format, data will be converted into electronic format by means of scanning and paper documents will be forwarded to the archives of the registry office. Purpose of and legal grounds for processing personal data if legal grounds are legitimate interests, define them Fulfilling the data controller s statutory obligations (article 6.1c), exercising the public authority belonging to the data controller (article 6.1e).

2 (8) Data content of the register and groups of personal data Cases processed by GTK, different processing stages and activities and documents. GTK s personnel: Name, contact information, organisation and profit centre or any other user group, title. Party outside GTK that has initiated the case or to which GTK sends document data: Name, contact information, organisation and profit centre or any other use group, title. Personal identity code or other identification of both parties, if its use is justified considering case management processes. Juoni also includes folder document management. In the targeted architecture for file-format data management at GTK, background material for management, operational planning and reporting has been set as the operating area of folders. Folders can be freely created in the system to collect document-type material that is closely linked with case management processes in Juoni. Personal data stored in these folders must be identified, and processing rules must be defined when creating folders.

3 (8) Storage period for personal data or, if this is not possible, criteria for defining the storage period Regular sources of data In the case management system, personal data is saved as part of the case management process in accordance with the Administrative Procedure Act. The storage period of personal data depends on the process or task to which the personal data is related. A record is a register for cases received to be processed by an authority or cases initiated by an authority. Personal data in record cards is stored permanently, because records are stored permanently. Documents attached to record cards are stored or destroyed following the storage period defined in the data control plan. Active Directory user management maintained by Valtori includes user data about GTK employees. In addition, GTK employees can edit their data and cases and documents they process. No regular source of data is available regarding parties outside GTK. Instead, personal data related to each case management process is saved manually in record cards.

4 (8) Recipients of personal data or groups of recipients Personal data stored in the case management system is processed by those GTK employees who have been provided, by means of record cards, with access rights to case-specific data and documents. Access rights are decided on by the responsible party and those designated employees whose data is included in basic information in record cards. In practice, the preparing party defines access rights. Recipients of data depend on the process, i.e. which employees are defined as responsible persons in each process, as defined in job descriptions. Triplan Oy, the supplier of the Juoni system and the service provider of TWEb, can access personal data to the extent permitted by GTK when it carries out specific activities in GTK s name. Information about the transfer of data to third countries and protection used (including information about the existence or nonexistence of the Commission s decision on the sufficiency of data protection), and opportunities to obtain a copy or information about content. No data is transferred from the case management system to third countries.

5 (8) Principles of register protection (manual material and electronic processing) Rights of data subjects Right to access personal data Right to have data rectified Right to have data erased The register is only processed in a secure technical environment provided by Valtori. Technical data protection methods provided by Triplan Oy are used in the register. Persons who process data in the system must process the data in accordance with permanent guidelines on case management within GTK and on the publicity and classification of GTK s material and documents. When an external party contacts GTK, a case management process starts in GTK s case management system. Regarding personal data generated in the system, GTK has a statutory

6 (8) right to restrict processing, right to object, right to transfer data from one system to another right to process and store. Data subjects cannot have their data erased, but they have the right to obtain an electronic or paper summary of the cases and documents in which they are mentioned. This data can be obtained in accordance with the provisions of the Act on the Openness of Government Activities. Any errors in personal data will be rectified so that any corrections will leave a trace in the case processing history, indicating what data was rectified, by whom, why and when. GTK has the right to transfer data later to a similar internal case management system within GTK, an internal archiving system or an external electronic archive of the Government.

7 (8) Right to file a complaint with the supervisory authority Data subjects have the right to file a complaint with the supervisory authority of the member state in which their permanent place of residence or business is or in which the suspected breach of the GDPR has taken place. If the data controller refuses the right of data subjects to access personal data or have the data rectified, data subjects have the right to file a complaint with the Finnish Data Protection Ombudsman. Office of the Data Protection Ombudsman Visiting address: Ratapihantie 9, 6th floor, 00520 Helsinki Postal address: P.O. Box 800, FI-00521 Helsinki, Finland Tel.: +358 29 56 66700 Fax: +358 29 56 66735 Email: tietosuoja@om.fi Is the provision of personal data a statutory or contractual requirement or a requirement needed to enter into an agreement? Do data subjects need to provide personal data? What are the consequences of any nonprovision of personal data? Statutory requirement. For GTK s employees and external parties, it is required that sufficient data about them in case management processes as required by processes or tasks. Mandatory personal data is indicated in the basic information tab of record cards, and it is collected systematically in all case management processes.

8 (8) Information about the existence of automated decision-making, including profiling, and significant information about the processing-related logic, at least in these cases, and the significance of specific processing and any consequences for data subjects No automated decision-making or profiling is used in the case management system.