GDPR – The general procedure for monitoring the employee

  • Home
  • GDPR – The general procedure for monitoring the employee

3.7. Informing the data subject at the request of the Supervisory Authority. The person responsible for analyzing the request received from the Supervisory Authority regarding the information of the data subjects is: DPO.

Within the company, information is sent regarding the violation of the security of personal data by the following means:

  • email
  • other ways.

The persons concerned will be informed in the following situations:

if the violation is likely to generate a high risk (the threshold for informing the data subjects is higher than that for notifying the ANSPDCP) for the rights and freedoms of the data subjects, directly and without undue delay;
the seriousness of the possible or actual impact of a violation on the persons concerned, as well as the probability of its materialization is high.

To the extent that the decision is not to inform the persons concerned, the ANSPDCP must be notified, if it cannot be demonstrated that the violation is not likely to generate a risk for rights and freedoms. In any case, documentation of the decision-making process must be kept in accordance with the requirements of the accountability principle.

The information to the data subjects will describe, in clear and simple language, the nature of the personal data security breach and will include the following information:

the name and contact details of the DPO or another point of contact where more information can be obtained;
description of the likely consequences of the personal data security breach;
description of the measures taken or proposed to be taken to remedy the problem of the personal data security breach, including, as appropriate, the measures taken to mitigate any negative effects.

For the transmission of the Information to the data subjects, the model provided [Information to the data subject regarding the data security breach] will be used.

Informing the data subject is not necessary if:

a) adequate technical and organizational protection measures have been implemented in the case of personal data affected by the security breach;
b) measures have been taken to ensure that the high risk for the rights and freedoms of the persons concerned is no longer likely to materialize;
c) would require a disproportionate effort, in which case public information will be provided or a similar measure will be taken by which the persons concerned are informed in an effective way.

The person responsible for transmitting the information to the data subject is the DPO. The deadline for sending the information is 72 hours. If this deadline is exceeded, good reasons for the delay must be provided.

3.8. Persons authorized by the operator. If the company uses one or more authorized persons and they suffer a security breach, they must inform the operator without undue delay as soon as they discover the breach in order to take steps to deal with the breach and fulfill their breach reporting obligations according to the GDPR. The requirements regarding the reporting of violations must be detailed in the contract concluded with the authorized person, according to art. 28 GDPR.

3.9. Taxes. Within SC TRIPLAST SRL, the information provided to the data subject and any communication are provided free of charge. If requests from a data subject are manifestly unfounded or excessive (in particular due to their repetitive nature, we will proceed to:

a) charging a fee in the amount of 2,000 lei, taking into account the administrative costs for providing the information or communication or for taking the requested measures;
b) refusal to comply with the request.

3.10. Signature. All documents drawn up regarding the reporting and treatment of security incidents to be sent outside the SC TRIPLAST SRL company will be signed by the CEO.

3.11. Close. Before the security incident review is closed, it will be investigated whether the breach was the result of human error or a systemic problem, and measures will be considered to prevent recurrence – either through better processes, additional training or other corrective measures.

After their resolution, all documents regarding the reporting and handling of security incidents are grouped according to the nomenclature and handed over to the archive within 10 years. Submission to the archive is based on inventories (opis) drawn up in three copies (one copy for the person submitting, one copy for the archive file and one copy for the department record file).

“mandatory corporate rules” – means the personal data protection policies that must be followed by a controller or a person authorized by the controller established in the territory of a Member State, in relation to transfers or sets of transfers of personal data personally to an operator or a person authorized by the operator in one or more third countries within a group of enterprises or a group of enterprises involved in a joint economic activity;

“supervisory authority” – means an independent public authority established by a Member State;

“DPO” – data protection officer (in English, data protection officer);

“DPIA” – data protection impact assessment (in English, data-protection impact assessment, DPIA).

 

PURPOSE AND SCOPE

 

2.1. THE GOAL

2.1.1. This procedure documents the GDPR requirements regarding the monitoring of employees at work. The SC TRIPLAST SRL operator carries out the monitoring under the conditions provided by the legislation in force and to protect the employees, as well as to protect their own interests or those of their clients.

2.1.2. This procedure describes the activities carried out regarding the monitoring of employees, namely maintaining the balance between the legitimate interests of the Operator and the reasonable expectations of employees regarding private life, considering the risks posed by new technologies.

 

2.2. APLICATION DOMAIN

2.2.1. This procedure applies to all organizational structures of SC TRIPLAST SRL.

 

2.3. REFERENCE DOCUMENTS

  • GDPR
  • Internal regulation
  • Internal procedures

 

GENERAL RULES REGARDING MONITORING

 

3.1. Fundamental principles provided by the GDPR

 

Monitoring of employees at work, as well as any kind of processing of personal data, is carried out by the Operator in compliance with the principles set out in art. 5 of the Regulation:

  • personal data must be processed legally, fairly and transparently;
  • personal data must be processed for specific, explicit and legitimate purposes;
  • personal data must be adequate, relevant and not excessive;
  • personal data must be accurate and up-to-date;
  • personal data must be kept for a period that does not exceed the period necessary for processing for the identified purpose;
  • personal data must be processed in a way that ensures their adequate security.

 

3.2. Transparency of processing

The operator SC TRIPLAST SRL effectively communicates to its employees any type of monitoring that takes place, the purposes and circumstances of this monitoring, as well as the possibilities for employees to prevent the recording of their personal data through monitoring technologies. Policies and rules regarding legitimate monitoring must be clear and easily accessible.

 

3.3. Proportionality and minimization of personal data

The operator SC TRIPLAST SRL ensures that the processing of personal data at the workplace constitutes a proportional reaction to the risks faced as an employer.

The operator minimizes the information recorded as a result of permanent monitoring. The operator takes organizational measures so that employees have the possibility to temporarily deactivate the location tracking function, if there are circumstances that justify this.

The operator takes into account the principle of data minimization when deciding to use new technologies. The information is stored for the minimum necessary period, with the indication of the retention period. Whenever there is information that is no longer needed, it would be removed.

 

TYPES OF MONITORING

 

4.1. Monitoring of electronic communications

Electronic communications monitoring refers to the monitoring of telephone, fax, e-mail, voicemail, Internet access and other forms of electronic communication.

The operator SC TRIPLAST SRL considers the following measures to ensure a legal and fair processing of personal data, respectively:

  • clearly setting out the circumstances under which employees may or may not use the employer’s telephone systems (including mobile phones), e-mail system and Internet access for private communications;
  • establishing the degree and type of private use employees are allowed, for example for restrictions on international phone calls or limits on the size and/or type of email attachments they can send or receive;
  • in the case of internet access, clearly detailing any restrictions on material that can be viewed or copied, for example material containing racist or pornographic terminology;
  • establishing clear rules for the private use of communication devices when used from home or remotely, for example the use of facilities that allow external calls to be made on company networks;
  • explaining the purposes for which the monitoring is carried out, the extent of the monitoring and the means used;
  • detailing how this procedure is applied and the sanctions that exist for violating it.

The Operator shall ensure that, where the monitoring involves the monitoring/interception of a communication, it is carried out in accordance with the legal provisions.

The operator will consider carrying out a personal data protection impact assessment if any monitoring of electronic communications cannot be limited to what is necessary to ensure the security of the system and if it can be automated.

The operator will ensure that persons making or receiving calls are aware of any monitoring and the purpose justifying it, unless this is obvious.

Employees of the Operator are aware of the extent to which the employer receives information about the use of telephone lines in their homes or about mobile phones provided for personal use, for which the company pays in part or in full.

Whenever possible, the Operator will take measures to avoid opening emails, especially those that clearly indicate they are private or personal.

4.2. Video and audio monitoring

 

For the Operator, video surveillance will be carried out mainly for the following purposes:

a) preventing and combating the commission of crimes;
b) supervising road traffic and finding violations of road traffic rules;
c) ensuring the guarding and protection of persons, goods and valuables, buildings and public utility facilities, as well as the fences affected by them;
d) the fulfillment of public interest measures or the exercise of public authority prerogatives;
e) the realization of legitimate interests, provided that the rights and fundamental freedoms or the interest of the concerned persons are not prejudiced.

Video surveillance will be carried out in places and spaces open or intended for the public, including on public access ways from the public or private domain, under the conditions provided by law. Video surveillance cameras will be installed in visible places.

The operator SC TRIPLAST SRL will not carry out the following activities:

  • the use of hidden video surveillance means, except for situations provided by law;
  • the processing of personal data by means of video surveillance in spaces where it is necessary to ensure the privacy of people, such as: fitting rooms, changing rooms, shower cabins, toilets and other similar locations;
  • the processing of personal data by means of video surveillance, exclusively in relation to racial or ethnic origin, political, religious or philosophical beliefs, trade union membership, health status and sex life, except in cases expressly provided by law;
  • the processing of employees’ personal data by means of video surveillance inside the offices where they carry out their work, except for situations expressly provided by law.

The operator SC TRIPLAST SRL is aware that the processing of employees’ personal data by means of video surveillance is allowed for the fulfillment of express legal obligations or on the basis of a legitimate interest, respecting the rights of employees, especially their prior information. In the situation where there is no legal obligation or the Operator cannot justify a legitimate interest, the processing of employees’ personal data by means of video surveillance can only be carried out on the basis of their express and freely expressed consent, respecting the rights of individuals employees, especially their prior information.

 

The operator will monitor the employee’s activity without his prior consent and information in the following situations:

  • when the employer could untimely intervene in the employee’s activity and monitor him if the employer’s or other employees’ property is endangered or if it concerns the security of some people or property; if the possibility of theft is suspected (in the case of cashiers and, in general, managers); if the intention to produce scraps is suspected; in such situations, as a protective measure, the employer must ensure the presence of witnesses;
  • when the employer cedes its rights, accepting, for example, that employees can use IT means for personal purposes for a certain period during the working day; when the employer decides to suspend the monitoring for a certain period; if the employee has expressly mentioned that certain data from the computer are of private, personal interest, they cannot be controlled by the employer (accessed, monitored); in the same way, the control of an employee’s file can only be carried out with the prior condition of warning and in the actual presence of that employee.

 

4.3. Monitoring in the vehicle

The operator may use devices that can record or transmit information such as the location of a vehicle, the distance it has traveled and information about the user’s driving habits. The monitoring of vehicle movements, where the vehicle is assigned to a specific driver and information about the vehicle’s performance can therefore be linked to a specific person, falls within the scope of personal data protection legislation.

If the Operator has a legal obligation to monitor the use of the vehicles, even if it is used for private purposes, for example by installing a tachograph on a truck, then the legal obligations take precedence.

4.4. Monitoring of employees in case of disciplinary investigations

The operator SC TRIPLAST SRL will take the following measures in relation to the disciplinary investigation of employees:

  • managers will ensure that the access rights of data subjects apply even if the response to a request may have an impact on a disciplinary investigation or complaint or on future proceedings, unless the response could potentially prejudice a criminal investigation;
  • persons involved in the investigation of disciplinary matters or potential grievances will ensure that they do not have to gather information in violation of the law;
  • the records used in the course of disciplinary proceedings are of a sufficiently good quality to support any conclusion arising from them;
  • records of any type used in disciplinary investigations must be kept secure.

The Operator ensures that employee information will not be accessed and used unless it may have relevance to a disciplinary investigation or complaint if the access or use would be incompatible with the purpose(s) for which you obtained it or disproportionate to the seriousness of the matter being investigated .

 

4.5. Monitoring equal opportunities

Information about an employee’s ethnic origin, disability, religion or sexual orientation is special personal data.

The operator ensures that the equal opportunity monitoring of these characteristics satisfies the processing conditions of these personal data provided in the provisions of art. 9 para. (2) of the GDPR.

The Operator will only use information that identifies employees individually when it is necessary to carry out meaningful equal opportunity monitoring. If possible, the collected information will be kept in an anonymous form.

 

4.6. Monitoring information from third parties

The operator attaches particular importance when processing information held by third parties, such as credit or electoral roll information. The same importance is given to information obtained and held by employers outside the scope of the employment relationship, such as when a bank monitors employees’ bank accounts.

An employee’s financial statements will not be monitored unless there are strong grounds to conclude that financial difficulties would represent a significant risk to the Operator. If employees are monitored using information held by a banking entity, they must be aware of the purpose of this use.

 

4.7. Monitoring of employees through medical services

The operator respects the obligation to ensure the access of employees to the medical service of occupational medicine. The occupational medicine medical service can be an autonomous service organized by the employer or a service provided by an employers’ association. The duration of the work performed by the occupational medicine doctor is calculated according to the number of employees of the employer, according to the law.

The main tasks of the occupational medicine physician consist of:

a) prevention of work accidents and occupational diseases;
b) the effective supervision of hygiene and health conditions at work;
c) ensuring the medical control of employees both upon employment and during the execution of the individual employment contract.

In order to carry out his duties, the occupational medicine doctor can propose to the employer to change the workplace or the type of work of some employees, determined by their state of health. Every year, the occupational medicine physician establishes an activity program for improving the work environment from the point of view of occupational health for each employer. The elements of the program are specific for each employer and are subject to the approval of the occupational health and safety committee.

No products in the cart.