Data Protection Policy
Application of the Data Protection and Data Processing Regulation
Organization Name: | Dr. Johanics Gábor e.v. |
Organization Headquarters: | 3394 Egerszalók, Ady Endre út 80. |
Responsible Person for the Content of the Regulation: | Dr. Johanics Gábor |
Date of Enactment of the Regulation: | 2022. június 15. |
This regulation sets forth the rules for the protection of personal data and the free movement of personal data concerning individuals. The provisions contained in this regulation must be applied during specific data processing activities and when issuing instructions and notifications regarding data processing.
The obligation to designate a Data Protection Officer applies to all public authorities or other bodies performing public duties (regardless of the type of data they process), as well as to organizations whose main activity is the systematic, large-scale monitoring of individuals or those that process special categories of personal data on a large scale.
The organization does not employ a Data Protection Officer.
Scope of the Regulation
This regulation is valid until revoked and applies to the officials, employees, and the Data Protection Officer of the organization.
Date: June 15, 2022
Objective of the Regulation
The objective of this regulation is to harmonize the internal provisions of the organization with regard to data processing activities in order to protect the fundamental rights and freedoms of individuals, and to ensure the proper handling of personal data.
The organization is fully committed to complying with the legal requirements concerning personal data processing, particularly with the provisions of the European Parliament and Council Regulation (EU) 2016/679.
Another key purpose of issuing this regulation is to ensure that the employees of the organization are able to lawfully process personal data when they are familiar with and comply with this regulation.
A szervezet tevékenysége során teljes mértékben meg kíván felelni a személyes adatok kezelésére vonatkozó jogszabályi előírásoknak, különösen az Európai Parlament és a Tanács (EU) 2016/679 rendeletében foglaltaknak.
A szabályzat kiadásának fontos célja továbbá, hogy megismerésével és betartásával a szervezet alkalmazottai képesek legyenek a természetes személyek adatai kezelését jogszerűen végezni.
Essential Terms and Definitions
- GDPR (General Data Protection Regulation) is the new Data Protection Regulation of the European Union.
- Data Controller: A natural or legal person, public authority, agency, or any other body which determines the purposes and means of the processing of personal data, either alone or jointly with others; if the purposes and means of the processing are determined by Union or Member State law, the data controller or the criteria for its designation may also be specified by Union or Member State law.
- Data Processing: Any operation or set of operations performed on personal data or on sets of personal data, whether by automated or non-automated means, such as collection, recording, organization, structuring, storage, alteration or modification, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- Data Processor: A natural or legal person, public authority, agency, or any other body that processes personal data on behalf of the data controller.
- Personal Data: Any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, particularly by reference to an identifier such as a name, identification number, location data, online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- Third Party: A natural or legal person, public authority, agency, or any other body that is not the data subject, the data controller, the data processor, or those persons who, under the direct authority of the data controller or data processor, are authorized to process personal data.
- Consent of the Data Subject: The data subject’s voluntary, specific, informed, and unambiguous indication of their wishes, by a statement or a clear affirmative action, consenting to the processing of their personal data.
- Restriction of Processing: Marking stored personal data to limit its processing in the future.
- Pseudonymization: The processing of personal data in such a way that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separate and subject to technical and organizational measures to ensure that personal data is not attributed to an identified or identifiable individual.
- Filing System: Any structured set of personal data accessible according to specific criteria, whether centralized, decentralized, or functional or geographical in nature.
- Data Protection Incident: A security breach that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data that has been transmitted, stored, or otherwise processed.
Principles of Data Processing
Personal data must be processed lawfully, fairly, and transparently for the data subject.
- Collection of Personal Data: Personal data may only be collected for specified, legitimate, and clear purposes.
- Purpose Limitation: The purposes for processing personal data must be adequate, relevant, and limited to what is necessary for the processing.
- Accuracy: Personal data must be accurate and kept up to date. Any inaccurate personal data should be rectified without delay.
- Storage Limitation: Personal data should be stored in a form that allows identification of the data subject only for as long as necessary for the purposes of processing. Personal data can be stored for longer periods only if it is for archiving purposes in the public interest, scientific research, or statistical purposes.
- Security of Personal Data: Personal data should be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing, accidental loss, destruction, or damage, using appropriate technical or organizational measures.
- Applicability of Principles: These principles must be applied to all information concerning identified or identifiable natural persons.
Responsibilities and Accountability
The organization’s employee handling personal data is held accountable for its lawful processing. Employees have legal, disciplinary, compensation, regulatory, and criminal liability for the lawful handling of personal data. If an employee becomes aware that the personal data they are handling is incorrect, incomplete, or outdated, they must immediately correct or initiate the correction process through the relevant staff member responsible for data recording.
Personal Data Processing
Since natural persons can be identified through online identifiers provided by the devices, applications, tools, and protocols they use (such as IP addresses and cookie identifiers), these data can be combined with other information to create a profile of the individual and identify them.
- Consent Requirement: Data processing may only occur if the data subject gives clear and voluntary consent through a specific, informed, and unambiguous action, such as a written or oral statement (including electronic consent).
- Explicit Consent: Consent is also considered valid if the data subject checks a box during the visit to a website. Silence, pre-ticked boxes, or non-action does not constitute consent.
- Health Data: Health-related data includes any information regarding the past, present, or future physical or mental health of the data subject. This can include:
- Registration for healthcare services.
- Data used for individual identification for healthcare purposes.
- Information obtained from testing or examination of body parts, biological samples, or genetic data.
- Information related to the subject’s disease, disability, health risks, medical history, clinical treatment, or physiological state, regardless of the source.
- Genetic Data: This refers to personal data relating to the inherited or acquired genetic characteristics of a natural person, which is obtained from the biological sample analysis (e.g., chromosomal analysis, DNA, or RNA tests).
- Children’s Personal Data: Children’s data deserve special protection because they may be less aware of the risks, consequences, and guarantees related to personal data processing. This extra protection primarily applies to data used for marketing purposes or the creation of personal or user profiles.
- Security of Personal Data: Personal data must be processed in a way that ensures adequate security and confidentiality, preventing unauthorized access or unlawful use of personal data or the tools used for processing them.
Lawfulness of Data Processing
Personal data processing is lawful if at least one of the following conditions is met:
- Consent: The data subject has given explicit consent for the processing of personal data for one or more specific purposes.
- Contractual Necessity: The processing is necessary for the performance of a contract to which the data subject is a party or to take steps at the request of the data subject before entering into a contract.
- Legal Obligation: The processing is necessary for compliance with a legal obligation to which the data controller is subject.
- Vital Interests: The processing is necessary to protect the vital interests of the data subject or another individual.
- Public Task: The processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller.
- Legitimate Interest: The processing is necessary for the legitimate interests pursued by the data controller or a third party, except where such interests are overridden by the data subject’s rights and freedoms, especially where the data subject is a child.
Legitimate Interest as a Basis for Data Processing
Certain types of personal data processing can be based on the legitimate interests of the data controller or a third party. These interests must be balanced against the data subject’s fundamental rights and freedoms.
Examples of legitimate interests include:
- Fraud Prevention: Processing personal data for fraud prevention is considered to serve the legitimate interests of the data controller.
- Direct Marketing: Processing for direct marketing purposes is based on the legitimate interest of the data controller.
- Network and Information Security: Personal data processing for the purpose of ensuring network and information security is a legitimate interest, especially when it is necessary and proportionate to protect the integrity of the systems.
Secondary Use of Personal Data
Personal data may be processed for purposes other than the original purpose if such processing is compatible with the original purpose. This is permissible if:
- The new purpose is consistent with the original purpose.
- No new legal basis is required for processing.
In the case of data processing for public or religious purposes, such as by officially recognized religious organizations, this can be considered as being in the public interest.
Consent of the Data Subject, Terms and Conditions
- If data processing is based on consent, the data controller must be able to demonstrate that the data subject has consented to the processing of their personal data.
- If the data subject gives consent in a written statement that also covers other matters, the request for consent must be communicated in a way that clearly distinguishes it from these other matters.
- The data subject has the right to withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of data processing based on consent before its withdrawal. The data subject must be informed about this before giving consent. The withdrawal of consent must be made as easy as providing consent.
- In determining whether consent is voluntary, the data controller must consider whether, among other things, the processing of personal data, which is not necessary for the performance of the contract (including the provision of services), has been required as a condition for the performance of the contract.
- Personal data processing concerning services directly offered to children in the information society is lawful only if the child is at least 16 years old. In the case of a child under 16, personal data processing is lawful only if consent is given or authorized by the holder of parental responsibility for the child.
- The processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as genetic and biometric data intended to identify a natural person, health data, and personal data concerning a natural person’s sex life or sexual orientation, is prohibited unless the data subject has explicitly consented to the processing of these data for one or more specific purposes.
- The processing of personal data related to decisions regarding criminal liability and offenses, as well as associated security measures, can only take place within the scope of public authority data processing.
Data Processing Without Identification
If the purposes for which the data controller processes personal data no longer require the identification of the data subject, the data controller is not obliged to retain additional information.
If the data controller can prove that it is not in a position to identify the data subject, they must inform the data subject appropriately.
Information for the Data Subject, Rights
The principle of fairness and transparency in data processing requires that the data subject be informed about the fact and purposes of the processing.
If personal data is collected from the data subject, the data subject must be informed whether the provision of personal data is mandatory and what the consequences are of not providing the data. This information may be supplemented with standardized icons to ensure that the data subject receives clear, understandable, and easy-to-read general information about the intended processing.
The data subject must be informed about personal data processing at the time of collection, or if the data is not collected from the data subject but from another source, the information must be provided within a reasonable time considering the circumstances.
The data subject has the right to access the personal data collected about them, and to exercise this right in a simple and timely manner to verify and ensure the lawfulness of the data processing. Every data subject must have the right to know the purposes of the processing and, where possible, the duration for which the personal data will be processed.
The data subject has the right to request the deletion of their personal data if the original purpose for which the data was collected is no longer relevant, or if the data subject withdraws their consent for data processing.
If personal data is processed for direct marketing purposes, the data subject must have the right to object at any time to the processing of their personal data for such purposes, free of charge.
Review of Personal Data
To ensure that personal data is stored only for as long as necessary, the data controller must establish retention or review deadlines.
The periodic review deadline set by the organization’s leader: 1 year.
Responsibilities of the Data Controller
The data controller must apply appropriate internal data protection rules to ensure lawful data processing. This regulation covers the scope and responsibility of the data controller.
The data controller is obligated to take appropriate and effective measures and must be able to demonstrate that data processing activities comply with applicable laws.
This regulation must be adopted in consideration of the nature, scope, circumstances, and purposes of the data processing, as well as the risks to the rights and freedoms of natural persons.
The data controller must implement appropriate technical and organizational measures based on a risk assessment regarding the processing of personal data. Based on this regulation, internal policies must be reviewed and updated as necessary.
The data controller or the data processor must maintain records of the data processing activities they conduct under their authority. Every data controller and data processor is required to cooperate with the supervisory authority and make these records available upon request for the inspection of data processing operations.
Rights Related to Data Processing
Right to Information
Anyone may request information about which data the organization is processing, on what legal basis, for what purposes, from which source, and for how long. A response must be provided promptly, but no later than 30 days from the request.
Right to Rectification
Anyone may request the correction of their data. The data controller must act promptly, but no later than 30 days from the request, and send a response to the provided contact information.
Right to Deletion
Anyone may request the deletion of their data. The data controller must promptly comply with this request, but no later than 30 days from the request, and send a response to the provided contact information.
Right to Restriction
Anyone may request the restriction of their data. This restriction lasts until the reason for retaining the data is no longer necessary. The data controller must promptly comply with this request, but no later than 30 days from the request, and send a response to the provided contact information.
Right to Object
Anyone may object to the processing of their data. The objection must be examined as soon as possible but no later than 15 days from the submission of the request. A decision must be made on the grounds of the objection and communicated to the requester.
Enforcement of Data Processing Rights
National Authority for Data Protection and Freedom of Information
Mailing address: 1363 Budapest, P.O. Box 9
Address: 1055 Budapest, Falk Miksa Street 9-11
Phone: +36 (1) 391-1400
Fax: +36 (1) 391-1410
Email: ugyfelszolgalat@naih.hu
Data Protection Officer
The designation of a Data Protection Officer (DPO) is mandatory based on the following criteria:
- Data processing is carried out by public authorities or other bodies performing public tasks, except for courts acting in their judicial capacity;
- The main activities of the data controller or processor involve data processing operations that, due to their nature, scope, or purposes, require the regular and systematic large-scale monitoring of data subjects;
- The main activities of the data controller or processor concern the processing of personal data related to decisions about criminal liability and criminal offenses, and the large-scale processing of related data.
If the designation of a DPO is mandatory, the following rules apply:
- The DPO must be appointed based on professional competence, particularly expert-level knowledge of data protection law and practices, as well as the ability to perform data processing tasks.
- The DPO may be an employee of the data controller or processor, but they can also fulfill their duties under a service contract.
- The data controller or processor must publicly disclose the DPO’s name and contact information, and this information must be communicated to the supervisory authority.
The Status of the Data Protection Officer
The data controller must ensure that the DPO is involved in all matters relating to the protection of personal data in a timely and proper manner. The data controller must also provide the necessary resources for the DPO to maintain their expert-level knowledge.
The DPO may not accept instructions from anyone regarding the performance of their tasks. The data controller or processor cannot dismiss the DPO or impose any sanctions on them concerning their duties. The DPO is directly accountable to the highest management of the data controller or processor.
Data subjects can contact the DPO regarding any issues related to the processing of their personal data and the exercise of their rights.
The DPO is bound by confidentiality obligations or other duties regarding the confidential handling of data in relation to their tasks.
The DPO may perform other tasks, but there should be no conflict of interest with their data protection responsibilities.
DPO’s Duties
- Provide information and professional advice to the data controller or processor and employees involved in data processing.
- Ensure compliance with the internal rules regarding personal data protection of the data controller or processor.
- Offer professional advice regarding data protection impact assessments (DPIA) upon request and monitor the completion of these assessments.
- Cooperate with the supervisory authority.
Data Protection Incident
A data protection incident is a security breach that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to personal data transmitted, stored, or otherwise processed.
A data protection incident, if not addressed adequately and promptly, may result in physical, material, or immaterial damages to individuals, including the loss of control over their personal data or restrictions on their rights, discrimination, identity theft, or misuse of identity.
A data protection incident must be reported to the relevant supervisory authority without undue delay, and no later than 72 hours, unless it can be demonstrated, in accordance with the principle of accountability, that the incident is unlikely to result in risks to the rights and freedoms of individuals.
The data subject must be informed without delay if the data protection incident is likely to result in a high risk to their rights and freedoms, so that they can take the necessary
Az adatvédelmi tisztviselő a feladatai ellátásával kapcsolatban utasításokat senkitől nem fogadhat el. Az adatkezelő vagy az adatfeldolgozó az adatvédelmi tisztviselőt feladatai ellátásával összefüggésben nem bocsáthatja el és szankcióval sem sújthatja. Az adatvédelmi tisztviselő közvetlenül az adatkezelő vagy az adatfeldolgozó legfelső vezetésének tartozik felelősséggel.
Az érintettek a személyes adataik kezeléséhez és jogaik gyakorlásához kapcsolódó valamennyi kérdésben az adatvédelmi tisztviselőhöz fordulhatnak.
Az adatvédelmi tisztviselőt feladatai teljesítésével kapcsolatban titoktartási kötelezettség vagy az adatok bizalmas kezelésére vonatkozó kötelezettség köti.
Az adatvédelmi tisztviselő más feladatokat is elláthat, de a feladatokkal kapcsolatban összeférhetetlenség ne álljon fenn.
Administrative and Record Keeping Data Processing
The organization may process personal data for administrative and record-keeping purposes as part of its activities.
The processing is based on voluntary and explicit consent given by the data subject, following proper information on the purpose, legal basis, and duration of the processing, as well as the data subject’s rights. After providing this information, the data subject must be reminded that providing personal data is voluntary. Consent must be recorded in writing.
The personal data processed for administrative and record-keeping purposes serves the following goals:
- The processing of data for members and employees, based on legal obligations.
- The processing of data for individuals working under a contractual relationship with the organization, for communication, billing, and record-keeping purposes.
- The processing of contact and identification details of representatives of other organizations, institutions, and businesses with which the organization has a business relationship.
The processing of such data is either based on legal obligations or the explicit consent of the data subject (e.g., for an employment contract or registration as a partner on a website).
In cases where documents containing personal data (e.g., resumes, job applications, other submissions) are sent to the organization, consent from the data subject is presumed. After the matter is concluded and without further consent for use, these documents must be destroyed, and the destruction must be documented.
For administrative purposes, personal data will only be included in relevant files or records related to the matter at hand. Data processing will continue only until the document or record related to the matter is destroyed.
Administrative and record-keeping data processing must be reviewed annually to ensure personal data is retained only for the necessary period, and any inaccurate data must be promptly deleted.
The organization must ensure compliance with the relevant legal regulations in relation to such data processing.
Data Processing for Other Purposes
If the organization intends to carry out data processing for a purpose not mentioned in this policy, it must appropriately amend its internal regulations and add specific sub-regulations aligned with the new purpose of processing.
Az adatvédelmi incidens megfelelő és kellő idejű intézkedés hiányában fizikai, vagyoni vagy nem vagyoni károkat okozhat a természetes személyeknek, többek között a személyes adataik feletti rendelkezés elvesztését vagy a jogaik korlátozását, a hátrányos megkülönböztetést, a személyazonosság-lopást vagy a személyazonossággal való visszaélést.
Az adatvédelmi incidenst indokolatlan késedelem nélkül, legkésőbb 72 órán belül be kell jelenteni az illetékes felügyeleti hatóságnál, kivéve, ha az elszámoltathatóság elvével összhangban bizonyítani lehet, hogy az adatvédelmi incidens valószínűleg nem jár kockázattal a természetes személyek jogaira és szabadságaira nézve.
Az érintett személyt késedelem nélkül tájékoztatni kell, ha az adatvédelmi incidens valószínűsíthetően magas kockázattal jár a természetes személy jogaira és szabadságára nézve, annak érdekében, hogy megtehesse a szükséges óvintézkedéseket.
Other Documents Related to the Regulation
The data protection and data processing policy must include and manage documents and regulations that cover, for example, written declarations of consent for data processing or, in the case of websites, mandatory data processing notices.
Laws Governing Data Processing
- Regulation (EU) 2016/679 of the European Parliament and the Council (April 27, 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, GDPR).
- Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information.
- Act LXVI of 1995 on the Protection of Public Documents, National Archives, and Private Archives.
- Government Decree 335/2005 (XII. 29.) on the General Requirements for Document Management by Public Authorities.
- Act CVIII of 2001 on Electronic Commerce Services and Certain Issues of Information Society Services.
- Act C of 2003 on Electronic Communications.