Personal data processing policy
1. General Provisions
1.1.This Personal Data Processing Policy (hereinafter referred to as the “Policy”) defines the principles, purposes, conditions, and methods of personal data processing, the categories of personal data subjects, the scope of personal data processed, the rights and obligations of personal data subjects, as well as the rights and obligations of **LIMITED LIABILITY COMPANY “CENTER FOR SUPPORT OF MEDICAL DEVICE MANUFACTURERS”** (hereinafter referred to as the “Organization” or the “Operator”), and the measures aimed at ensuring the security of personal data within the Organization.
1.2.This Policy has been developed in compliance with paragraph 2, part 1, article 18.1 of Federal Law No. 152-FZ dated July 27, 2006 “On Personal Data” (hereinafter referred to as the “Personal Data Law”) for the purpose of ensuring protection of the rights and freedoms of individuals and citizens in the processing of their personal data.
1.3.This Policy serves as the basis for the development of local regulatory acts governing the issues of protection and processing of personal data of the Organization’s employees and other personal data subjects.
1.4.This Policy is intended for review and strict compliance by all employees of the Organization and shall also be communicated to persons having contractual, civil-law, and other relations with the Organization.
1.5.This Policy applies to all relations concerning personal data processing arising in the Organization both before and after approval of this Policy.
1.6.In compliance with part 2 of article 18.1 of the Personal Data Law, this Policy shall be published in publicly accessible form on the Organization’s website on the Internet.
2. Terms and Definitions
Personal Data – Any information relating directly or indirectly to an identified or identifiable individual (personal data subject).
Personal Data Operator (Operator) – LIMITED LIABILITY COMPANY “CENTER FOR SUPPORT OF MEDICAL DEVICE MANUFACTURERS”**, independently or jointly with other persons organizing and/or carrying out personal data processing, as well as determining the purposes of personal data processing, the composition of personal data to be processed, and the actions (operations) performed with personal data.
Personal Data Subject – An individual who can be directly or indirectly identified by means of personal data.
Personal Data Permitted for Dissemination – Personal data to which an unlimited number of persons have been granted access by the personal data subject through consent to the processing of personal data permitted for dissemination.
Consent to Personal Data Processing – A written or electronic document confirming the voluntary decision of the personal data subject to provide personal data to the Operator in the amount, under the conditions, and for the purposes defined by this Policy and agreements concluded between the personal data subject and the Operator.
Personal Data Processing – Any action (operation) or set of actions (operations) performed with personal data, with or without automation tools, including collection, recording, systematization, accumulation, storage, updating (modification), retrieval, use, transfer (dissemination, provision, access), depersonalization, blocking, deletion, and destruction of personal data.
Automated Personal Data Processing – Processing of personal data using computer technology.
Provision of Personal Data – Actions aimed at disclosing personal data to a specific person or a specific group of persons.
Dissemination of Personal Data – Actions aimed at disclosing personal data to an indefinite number of persons.
Blocking of Personal Data – Temporary suspension of personal data processing, except where processing is necessary for clarification of personal data.
Destruction of Personal Data – Actions resulting in the impossibility of restoring the content of personal data in a personal data information system and/or resulting in the destruction of tangible media containing personal data.
Depersonalization of Personal Data – Actions resulting in the impossibility of determining, without additional information, the принадлежность of personal data to a specific personal data subject.
Cross-Border Transfer of Personal Data – Transfer of personal data to the territory of a foreign state, to a foreign public authority, foreign individual, or foreign legal entity.
Personal Data Information System – A set of personal data contained in databases and the information technologies and technical means ensuring their processing.
Personal Data Protection – Activities aimed at preventing leakage of personal data and protecting personal data from unauthorized and accidental access or impact.
3. Principles and Purposes of Personal Data Processing
3.1.When processing personal data, the Operator adheres to the following principles:
– personal data shall be processed in accordance with the requirements of the legislation of the Russian Federation;
– personal data shall be processed with the consent of personal data subjects, unless otherwise provided by the legislation of the Russian Federation;
– personal data processing shall be limited to the achievement of specific, predetermined, and lawful purposes;
– personal data incompatible with the purposes of collection shall not be processed;
– only personal data relevant to the purposes of processing shall be processed;
– the content and volume of personal data processed shall correspond to the stated purposes of processing;
– processed personal data shall not be excessive in relation to the stated purposes;
– personal data shall be accurate, sufficient, and, where necessary, up to date;
– personal data shall be destroyed or depersonalized upon achievement of the purposes of processing unless otherwise required by law;
– databases containing personal data processed for incompatible purposes shall not be merged.
3.2.The Operator processes personal data for the following purposes:
– ensuring compliance with the Constitution of the Russian Federation, federal laws, and other legal acts;
– carrying out activities in accordance with the Charter of the Organization, including conclusion and performance of agreements with counterparties;
– recruitment and personnel selection;
– personnel administration;
– accounting and bookkeeping;
– assistance in employment, performance of employment duties, education, ensuring employee safety, quality control of work performed, and protection of property;
– submission of statutory reports to public authorities;
– implementation of civil-law relations
4. LEGAL GROUNDS FOR PERSONAL DATA PROCESSING. RIGHTS AND OBLIGATIONS OF THE OPERATOR AND PERSONAL DATA SUBJECT
4.1. Legal Grounds
The legal grounds for personal data processing by the Operator shall include the aggregate of regulatory legal acts, including but not limited to:
– the Constitution of the Russian Federation;
– the Civil Code of the Russian Federation;
– the Labor Code of the Russian Federation;
– the Tax Code of the Russian Federation;
– Federal Law No. 152-FZ dated July 27, 2006 “On Personal Data”;
– Federal Law No. 149-FZ dated July 27, 2006 “On Information, Information Technologies and Information Protection”;
– Resolution of the Government of the Russian Federation No. 687 dated September 15, 2008;
– Resolution of the Government of the Russian Federation No. 1119 dated November 1, 2012;
– Resolution of the Government of the Russian Federation No. 211 dated March 21, 2012;
– Resolution of the Government of the Russian Federation No. 512 dated July 6, 2008;
– Order of Roskomnadzor No. 179 dated October 28, 2022;
– other regulatory legal acts governing the Operator’s activities.
4.2. Additional Legal Grounds
Personal data processing is also carried out on the basis of:
– the Charter of the Organization;
– agreements concluded with personal data subjects;
– consent of personal data subjects.
4.3. Rights and Obligations
4.3.1. Operator Rights
The Operator shall have the right to:
– independently determine necessary and sufficient measures for compliance with legal requirements;
– entrust personal data processing to third parties subject to the consent of the data subject and contractual arrangements;
– continue processing without consent where permitted by law.
4.3.2. Operator Obligations
The Operator shall be obliged to:
– organize personal data processing in compliance with applicable law;
– respond to requests of personal data subjects;
– provide information to supervisory authorities upon request within statutory deadlines;
– cooperate with state systems for cybersecurity incident detection and response where applicable.
4.3.3. Rights of Personal Data Subjects
Personal data subjects shall have the right to:
– obtain information regarding processing of their personal data;
– request rectification, blocking, or destruction of inaccurate or unlawfully processed data;
– provide or withdraw consent;
– appeal unlawful actions to supervisory authorities or courts.
5. CATEGORIES OF PERSONAL DATA SUBJECTS, METHODS OF PROCESSING, AND DATA COMPOSITION
5.1. Categories of Data Subjects
The Operator processes personal data of:
– employees and former employees;
– job applicants;
– individuals engaged under civil law contracts;
– interns;
– authorized representatives.
5.2. Methods of Processing
Processing may be:
– non-automated;
– automated;
– mixed.
5.3. Scope of Personal Data
The scope includes any information directly or indirectly identifying a data subject, determined in accordance with applicable law and processing purposes.
5.4. Biometric Data
Biometric personal data shall be processed strictly in accordance with legal requirements.
5.5. Health Data
Health-related data shall be processed in accordance with labor and pension legislation.
5.6. Special Categories
The Operator does not process personal data relating to race, nationality, political views, religious beliefs, or private life.
6. PROCEDURE AND CONDITIONS FOR PERSONAL DATA PROCESSING
6.1. General Requirements
Processing is carried out in compliance with legal principles and requirements.
6.2. Purpose Limitation
Processing is limited to lawful and predefined purposes.
6.3. Access Control
Only authorized employees who have signed confidentiality obligations may process personal data.
6.4. Post-Employment Obligations
Employees must cease processing personal data upon termination of employment.
6.5. Storage
Personal data shall be stored only as long as necessary for processing purposes and must be destroyed or anonymized thereafter unless otherwise required by law.
6.6. Data Localization
Databases used for personal data processing shall be located within the Russian Federation.
6.7. Termination of Processing
Processing shall cease upon:
– achievement of processing purposes;
– expiration or withdrawal of consent;
– detection of unlawful processing.
6.8. Third-Party Processing
Processing may be entrusted to third parties under contractual arrangements.
6.9. Disclosure
Personal data may be disclosed to authorized state bodies where required by law.
6.10. Confidentiality
Personal data shall not be disclosed or disseminated without consent, except as required by law.
6.11. Withdrawal of Dissemination Consent
Dissemination must cease upon request of the data subject.
6.12. Cross-Border Transfer
Cross-border transfer of personal data is not carried out.
6.13. Compliance Measures
The Operator shall implement measures necessary to comply with legal requirements.
6.14. Data Security
The Operator shall take legal, organizational, and technical measures to protect personal data.
6.15. Legal Consequences of Refusal
Data subjects shall be informed of consequences of refusal or withdrawal of consent.
7. REQUESTS OF PERSONAL DATA SUBJECTS
7.1. Access Requests
The Operator shall provide requested information unless restricted by law.
Requests must include identification and verification details.
7.2. Repeated Requests
Repeated requests may be submitted no earlier than 30 days unless otherwise provided.
7.3. Early Requests
Earlier requests must be justified.
7.4. Corrections and Deletion
Corrections or deletion shall be made within 7 business days upon confirmation.
7.5. Data Accuracy
The Operator must ensure data accuracy and remove blocking where applicable.
7.6. Termination of Processing
Processing must cease:
– upon detection of violations (within 3 business days);
– upon consent withdrawal;
– upon achievement of processing purposes (within 30 days, or data must be blocked and destroyed within 6 months).
8. PERSONAL DATA PROTECTION MEASURES
The Operator shall implement:
– appointment of responsible personnel;
– risk assessment procedures;
– internal regulatory acts;
– employee training;
– access control mechanisms;
– secure storage systems;
– logging and monitoring;
– backup and recovery;
– physical security measures;
– technical protection tools;
– antivirus solutions;
– certified information security systems;
– internal audits and ongoing monitoring.
The Operator continuously improves data protection systems.
9. LIABILITY
Violations of personal data legislation shall entail liability in accordance with the laws of the Russian Federation.
Employees and officials may bear disciplinary, administrative, or other liability.
Managers are personally responsible for ensuring proper access control.
10. USE OF COOKIES
The website uses cookies to:
– ensure proper functionality;
– analyze user behavior;
– improve services.
Cookies may store user preferences and anonymized data.
Third-party analytics tools may be used.
Users consent to cookies by using the website.
Users may disable cookies via browser settings, which may affect functionality.
11. FINAL PROVISIONS
This Policy shall enter into force upon approval and remain valid indefinitely.
All amendments shall be approved by the General Director of the Organization.