- DEFINITIONS
“GDPR”, “Regulation” – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing the Directive 95/46/CE (General Data Protection Regulation, in English General Data Protection Regulation);
“personal data” – any information regarding an identified or identifiable natural person (“data subject”); an identifiable natural person is a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more many specific elements, specific to his physical, physiological, genetic, psychological, economic, cultural or social identity;
“processing” – means any operation or set of operations performed on personal data or sets of personal data, with or without the use of automated means, such as collection, recording, organization, structuring, storage, adaptation or modification , extract, consult, use, disclose by transmission, disseminate or otherwise make available, align or combine, restrict, delete or destroy;
“operator” – means the natural or legal person, public authority, agency or other body that, alone or together with others, determines the purposes and means of personal data processing; when the purposes and means of processing are established by Union law or domestic law, the operator or the specific criteria for its designation may be provided for in Union law or domestic law;
“person authorized by the operator” – means the natural or legal person, public authority, agency or other body that processes personal data on behalf of the operator;
“recipient” – means the natural or legal person, public authority, agency or other body to whom (to whom) personal data is disclosed, whether or not it is a third party. However, the public authorities to whom personal data may be communicated within a
certain inquiries in accordance with Union or national law are not considered recipients; the processing of this data by the respective public authorities complies with the applicable data protection rules, in accordance with the purposes of the processing;
“third party” – means a natural or legal person, public authority, agency or body other than the data subject, the operator, the person authorized by the operator and the persons who, under the direct authority of the operator or the person authorized by the operator, are authorized to process data personal;
“consent” – of the data subject means any manifestation of the data subject’s free, specific, informed and unambiguous will by which he accepts, through a statement or an unequivocal action, that the personal data concerning him be processed;
“breach of personal data security” – means a breach of security that leads, accidentally or unlawfully, to the destruction, loss, alteration, or unauthorized disclosure of personal data transmitted, stored or otherwise processed, or to unauthorized access to them;
“representative” – means a natural or legal person established in the Union, designated in writing by the controller or the person authorized by the controller, who represents the controller or the authorized person with regard to their respective obligations under the GDPR;
“mandatory corporate rules” – means the personal data protection policies that must be followed by a controller or a person authorized by the controller established in the territory of a Member State, in relation to transfers or sets of transfers of personal data personally to an operator or a person authorized by the operator in one or more third countries within a group of enterprises or a group of enterprises involved in a joint economic activity;
“supervisory authority” – means an independent public authority established by a Member State;
“DPO” – data protection officer (in English, data protection officer);
“DPIA” – data protection impact assessment (in English, data-protection impact assessment, DPIA);
“Supervisory Authority” – the National Supervisory Authority for the Processing of Personal Data (ANSPDCP).
PURPOSE AND SCOPE
2.1. THE GOAL
This procedure documents the requirements regarding the preparation of the document called “Data Processing Record Register” (Annex 1).
2.2. APLICATION DOMAIN
This procedure applies to all organizational structures of SC TRIPLAST SRL. This procedure will be considered as having a general character and will apply to all processing carried out by the Operator.
If it is found that there are certain matters for which this procedure does not provide adequate guidance, Employees must immediately seek advice from the Data Protection Officer (DPO), if appointed, or the legal representative of the Operator.
2.3. REFERENCE DOCUMENTS
– GDPR
– Internal regulation
– Internal procedures
GENERAL RULES
3.1. GENERAL. The SC TRIPLAST SRL operator will prepare a table (preferably in excel format), in which it will list each line of business (e.g. “activity” carried out within each business process) together with the information related to collection, storage, use, transfer and destruction of critical data content for each department.
IMPORTANT: The operator will go through the points below for each type of document that contains personal data.
3.2. TYPE/NAME OF DOCUMENTS FOR PERSONAL DATA COLLECTION
The SC TRIPLAST SRL operator will identify the type/name of the documents for the collection of personal data, the categories of data from the Data Classification Scheme will be selected.
3.3. DATA CATEGORIES
The SC TRIPLAST SRL operator will select the categories of personal data. In order to identify the categories of personal data collected, the Data Classification Scheme will be considered.
3.4. DATA TYPE
The SC TRIPLAST SRL operator will select the type of personal data. In order to identify the type of personal data collected, the Data Classification Scheme will be considered.
3.5. DATA SOURCE
The SC TRIPLAST SRL operator will select where the personal data comes from (eg input source)? Tick ”X” the data input source (multiple options are possible).
☐ Clients (PF or PJ)
☐ Employees
☐ Third parties (suppliers, partners, service providers)
3.6. DATA COLLECTION METHOD
The SC TRIPLAST SRL operator will select the method of collecting personal data. Tick with an “X” the support type of data collection (multiple options are possible).
☐ Physical (Paper Support)
☐ Post/Courier
☐ Fax
☐ Web portal
☐ Online form
☐ USB Drive
☐ Hard drive
☐ CDs/DVDs
☐ FTP server
☐ Social Media
☐ Call Center
3.7. NEXT TRANSFER LOCATION
The SC TRIPLAST SRL operator will select the location of the transfer of personal data. Tick ”X” the data transfer location (multiple options are possible).
☐ Offices (Files)
☐ Email Server
☐ IT applications (name of applications used)
☐ Databases
☐ Electronic Files
☐ Mobile phones
3.8. STORAGE LOCATION
The SC TRIPLAST SRL operator will select the storage location of personal data. Tick ”X” the data storage location (multiple options are possible).
☐ Offices (Files)
☐ Email Server
☐ IT applications (name of applications used)
☐ Generic System/Server
☐ Electronic Files
☐ Databases
☐ Web server
☐ Electronic Archive (back-up)
☐ Cloud
3.9. DATA USE (Internal)
The SC TRIPLAST SRL operator will select the method of using personal data. Tick with an “X” the method of use (multiple options are possible).
☐ Department
☐ Internal transfer to another department
☐ How many employees have access to personal data?
3.10. DATA TRANSFER (External)
The SC TRIPLAST SRL operator will select the method of transfer of personal data. Tick with “X” the method of transfer (several options are possible).
☐ Authorities
☐ Third parties (suppliers, partners, service providers)
☐ Cross-border (in the EU/EEA or outside the EU/EEA)
3.11. DATA RETENTION AND ARCHIVING
The SC TRIPLAST SRL operator will select the data retention/storage location. “X” the data retention/storage location (multiple options are possible).
☐ Offices (Archive)
☐ Email Server
☐ IT applications (name of applications used)
☐ Generic System/Server
☐ Electronic Files
☐ Databases
☐ Web server
☐ Electronic archiving (back-up)
☐ Cloud
3.12. STORAGE/RETENTION PERIOD
The SC TRIPLAST SRL operator will complete the storage/retention period for each basis of personal data processing.
☐ Consent
☐ Legal obligation
☐ Contractual obligation
☐ Public interest
☐ Public authorities
☐ Protecting vital interests
☐ Legitimate interest
3.13. DESTRUCTION/DELETION
The SC TRIPLAST SRL operator will complete the method of destruction/deletion of personal data. Tick with an “X” the method of data deletion/destruction (multiple options are possible).
☐ Trash can
☐ Paper shredder
☐ Delete computer systems

