Budapest Makeup School
Privacy and Data Processing Notice
This is a courtesy English translation. The Hungarian version is the legally binding text; in case of any discrepancy, the Hungarian version prevails.
Bp. Smink és Maszkmester Oktató Szolgáltató és Kereskedelmi Kft. — in force from: 10 December 2018 until revoked. Below is the full text of the notice.
Download the notice (PDF, Hungarian)1. What is the purpose of this Notice, from when and until when is it in force, and what terms do we use?
1) The purpose of this Privacy and Data Processing Notice (the “Notice”) is to inform you, as the data subject: a) about compliance with REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL (GDPR — the “Regulation”) and with Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information (the “Privacy Act”). b) about ensuring the concrete implementation of the principles set out in Article 5 of the Regulation (lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, accountability). 2) The period of validity of the Notice is indicated on the cover page and in the footer of each page. The Data Controller reserves the right to amend the Notice at any time and to publish a new version on its website. When a new version enters into force, the previous version ceases to apply. 3) Terms and definitions used in the Notice Data subject (you): an identified or identifiable natural person (an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person); Personal data: any information relating to the data subject; Processing: any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction; Controller: the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data; Processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller; Third party: a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data; Personal data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
2. Who is the Data Controller, and who are the processors?
Name: Bp. Smink és Maszkmester Oktató Szolgáltató és Kereskedelmi Kft. Tax number: 14369708-2-42 Registered seat: 1083 Budapest, Illés u. 28-30. Building B, 7th floor, 705. E-mail address: info@budapestisminkiskola.com Website(s): http://budapestisminkiskola.com/
Name: Tárhely.Eu Kft. Registered seat: 1144 Budapest, Ormánság u 4. Tax number: 14571332-2-42 Website: https://tarhely.eu Activity performed: Web hosting, storage of personal data. Does it engage a further processor? NO.
Name: Robinia Hungary Kft. Tax number: 23571385-2-13 Registered seat: 2735 Dánszentmiklós, Dózsa György út 176. Represented by: Tamás Pásztory, managing director. Activity performed: Bookkeeping tasks performed in accordance with the legislation on taxation and accounting rules, using the data specified by law. Does it engage a further processor? NO.
Where required by its activity, and depending on urgency and availability, the Data Controller may also use the services of photo and video providers; in such cases it provides information about the identity of the processor on a case-by-case basis. Activity performed by them: taking photographs and video recordings.
3. Do we process special category personal data?
The Data Controller does not request or process special categories of personal data (i.e. personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation) — except for certain data required by law in the context of an employment relationship.
Any such data that comes to the Data Controller's attention in any way is not recorded by the Data Controller. If such data enters any system of the Data Controller without its knowledge, it will be deleted from the system without delay upon detection.
4. How do we assess the lawfulness of processing?
1) The Data Controller assesses the lawfulness of processing at every stage of its activity and processes only such data, and for as long, as it can justify by reference to a purpose and a legal basis. If the condition for a given legal basis ceases to exist, processing may continue only if the Data Controller can demonstrate another appropriate legal basis. 2) The legal bases for processing, in the order determined by the Data Controller: a) processing is necessary for the performance of a contract to which the data subject
is party; [Art. 6(1)(b)] b) processing is necessary for compliance with a legal obligation to which the controller
is subject; [Art. 6(1)(c)] c) processing is necessary for the purposes of the legitimate interests pursued by the
controller, supported by a balancing test; [Art. 6(1)(f)] d) the data subject has given consent to the processing of his or her personal data; [Art. 6(1)(a)] 3) As a general rule, the legal basis must be evidenced in writing; even where a legal basis arises from implied conduct, it must be examined whether this can be clearly proven afterwards. In case of doubt, and having regard to reasonableness and cost-effectiveness, efforts should be made to obtain written confirmation of processing based on implied conduct. 4) With respect to a party to an existing valid contract, the Data Controller continues to process the contracting party's data under Article 6(1)(b) of the Regulation, even after the Regulation's entry into force, until termination of the contract. 5) After termination of the contract, the Data Controller processes data only for as long as necessary to comply with a legal obligation applicable to it, or to assert its legitimate interest, and only for as long as this can be evidenced.
5. Processing necessary for the performance of a contract
This section details the conditions of processing necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into such a contract. [Article 6(1)(b) of the Regulation]
1) Purpose of processing: Providing the data subject with appropriate information and support, and maintaining contact in order to prepare (e.g. request for quote, providing a quote,
negotiation based on the quote, acceptance of the quote), maintain, perform and properly terminate the contract. 2) Legal basis: Where the request for information aims at concluding a contract, or relates to a question about its maintenance, its modification, or preparing its termination, the legal basis is the contract. Where the request for information relates to a purpose outside the contract, processing is based on voluntary consent. 3) Recipients / categories of recipients of the personal data: Employees of the Data Controller dealing with providing information, contract preparation and contract performance. 4) Scope and purpose of data processed: name – identification; e-mail address – contact, clarifying the request, providing information; phone number – contact, clarifying the request, providing information; content of the question/request – input data for the response. 5) Categories of data subjects: Any natural person who contacts the Data Controller and requests contract-related information/a quote from the Data Controller by providing personal data. 6) Duration of processing: For the duration of the contract, and thereafter, on the basis of the Data Controller's legitimate interest, until the limitation period for claims arising from the contract expires, and until expiry of the record-retention period under accounting rules. 7) Process of the data processing: a) the data subject contacts the Data Controller by a method of their choosing (in
person, by phone, by e-mail, or otherwise) requesting information/a quote. b) the Data Controller clarifies the request with the data subject as necessary. c) the Data Controller provides the requested information/quote in the manner in
which the request arrived, or as agreed with the data subject. d) upon acceptance of the quote, or by way of a written or implied contract, the
contractual relationship is established.
1) Purpose of processing: The Data Controller's cooperation with persons designated by its corporate partners, and general business contact with them. 2) Legal basis: Performance of obligations arising from the contract between the parties. 3) Recipients / categories of recipients of the personal data: Employees of the Data Controller involved in performing the contract. 4) Scope and purpose of data processed: name – identification; e-mail address – contact; phone number – contact. 5) Categories of data subjects: Any natural person designated by the corporate party contracting with the Data Controller as a representative, contact person, or person acting in the performance of the contract. 6) Duration of processing: For 5 years following termination of the contract or of the business relationship. 7) Process of the data processing: a) the parties designate, on each side, the persons acting as representative,
contact person and person acting in performance, as specified in the contract; b) the data subjects carry out the tasks assigned to them under the contract, cooperating
as necessary;
c) as necessary, the events of their cooperation are documented (memos,
minutes, records, etc.), and documents relevant to the performance of the contract are archived.
6. Processing necessary for compliance with a legal obligation
1) Purpose of processing: Managing documents (invoices, delivery notes, etc.) containing personal data of natural persons and of natural-person representatives of legal persons who come into contact with the Data Controller as customers/suppliers, in accordance with the applicable legislation in force from time to time. At the time this Policy enters into force, such legislation includes in particular:
• Act CL of 2017 on the Rules of Taxation, in particular Section 50; • Act CXXVII of 2007 on Value Added Tax, in particular Section 169; • Act C of 2000 on Accounting, in particular Section 167. 2) Legal basis: Compliance with a legal obligation applicable to the Data Controller. 3) Recipients / categories of recipients of the personal data: Employees of the Data Controller performing tax and accounting administration, and/or processors providing such services, the manager authorising payment, and the employee or processor performing related audits (e.g. internal auditor). 4) Scope and purpose of data processed: the data content prescribed by law, and the data of the documents and reporting forms mandatorily used to comply with it, for the purpose of complying with the legal obligation. 5) Categories of data subjects: Every customer and supplier who comes into contact with the Data Controller. 6) Duration of processing: 8 years following the economic event.
7. Processing necessary for the purposes of our legitimate interests
1) Purpose of processing: Selecting the successful candidate from among natural persons applying to job advertisements published by the Data Controller as an employer, informing both successful and unsuccessful candidates of the outcome, and the contact necessary for this. 2) Legal basis: Applying for a position is based on voluntary consent, but during the selection process the Data Controller, as an employer, is bound by Act CXXV of 2003 on
Equal Treatment and the Promotion of Equal Opportunities (the “Equal Treatment Act”), under which the employer must observe equal treatment in access to employment, in particular in public job advertisements, recruitment, and conditions of employment. 3) Recipients / categories of recipients of the personal data: Employees of the Data Controller engaged in recruitment and selection and/or a recruitment or headhunting firm occasionally engaged for this purpose, acting as a processor in that capacity, and the person exercising employer's rights at the Data Controller. 4) Scope and purpose of data processed: name – identification; CV (including the personal data contained therein) – identification, content assessed during selection; phone number – contact; interview minutes – identification, content assessed during selection; test results – content assessed during selection. 5) Categories of data subjects: Any natural person who applies to a job advertisement by sending their CV/cover letter. 6) Duration of processing: the Data Controller keeps documents related to the application and selection for 3 years from their creation, given that under Section 17 of the applicable Equal Treatment Act, official proceedings examining compliance with the equal treatment requirement may be initiated within one year of becoming aware of the infringement and within three years of its occurrence. Within this period the employer can only prove its compliance with the equal treatment requirement if it has the necessary documents in its possession. After 3 years the employer destroys the documents. 7) Process of the data processing: a) the data subject sends their application to the Data Controller, as employer, in the
manner indicated in the job advertisement; b) those responsible for selection carry out the selection according to the applicable
protocol; c) the manager exercising employer's rights decides on the selected person; d) the employer notifies both the selected and the rejected candidates of the closing
of the selection process and of the outcome relevant to them; e) if the employer wishes to continue processing the data of a rejected candidate for
the purposes of possible future employment, it must ask the data subject to make a statement to that effect. With such a statement, the data subject may be contacted later; without it, the data subject can only be considered in a selection process if they apply again to a new job advertisement. f) those performing the selection archive the documents created during the selection
process; g) should the National Authority for Data Protection and Freedom of Information or
an Equal Treatment authority make a request, the person exercising employer's rights and/or their legal representative retrieve the relevant documents from the archive and use them in the proceedings. h) after 3 years, the designated employee of the employer destroys the documents.
8. Processing based on the data subject's consent
1) The Data Controller provides customer-service-type activities in person, by phone, and by e-mail. If, in person or during a phone call, the data subject receives an adequate service for all their questions and their personal data is not recorded, no processing takes place. If the service can only be provided via a callback to the data subject or by providing information by e-mail, and the Data Controller records the data provided by the data subject in a paper-based or electronic call log (the “Call Log”), processing takes place, and is carried out by the Data Controller as described in this section. 2) Purpose of processing: Providing information to data subjects in person, by phone and by e-mail. 3) Legal basis: The data subject's consent. Consent is deemed to have been given if the data subject dictates the data necessary for a callback to the Data Controller themselves, or if they contact the Data Controller by e-mail. 4) Recipients / categories of recipients of the personal data: Employees of the Data Controller providing information. 5) Scope of data processed: name – identification; phone number – contact; e-mail address – contact; date, hour, minute – identification. 6) Categories of data subjects: Any natural person who contacts, by phone or e-mail, the Data Controller's employees performing customer-service activities. 7) Duration of processing: 3 months from the date of the response. 8) Process of the data processing: a) the data subject contacts the Data Controller in person, by phone or by e-mail; b) the employee performing customer-service activities listens to the
data subject, or interprets the e-mail received; c) the request is clarified with the data subject as necessary. d) either the answer is provided, or the data subject is offered a callback after the
matter has been looked into, in which case the optimal time of the callback is agreed; in the case of an e-mail, the expected time of the response is indicated; e) a question that cannot be answered immediately, or a phone call, results in the data
subject's data being recorded in the dedicated Call Log. f) the employee performing customer-service activities reviews the data recorded in
the Call Log every 3 months and deletes data from the record where the matter was closed without a complaint from the data subject.
1) Purpose of processing: The purpose of processing related to the sending of newsletters and/or advertising (direct marketing – DM – letters) is to provide the recipient with general or personalised information about news and the latest promotions appearing on the Data Controller's website (in
particular services and discounts offered only to those subscribed to the Newsletter), events, news, and notifications about changes to or discontinuation of services, in accordance with the applicable legislation in force. At the time this Policy enters into force, such legislation includes in particular Act XLVIII of 2008 on the Basic Conditions of and Certain Limitations to Business Advertising Activity, especially Section 6. 2) Legal basis: Subscribing to receive newsletters and/or DM letters is based on voluntary consent. 3) Recipients / categories of recipients of the personal data: Employees of the Data Controller performing customer-service and marketing activities, and IT, newsletter-sending and hosting processors. 4) Scope and purpose of data processed: name – identification; e-mail address – sending the newsletter. 5) Categories of data subjects: Any natural person who wants to receive regular updates about the Data Controller's news, promotions and discounts, and therefore subscribes to the newsletter and/or DM-letter service by providing their personal data. Confirmation of the subscription may be given by ticking a not-pre-ticked checkbox or so-called button. 6) Duration of processing: Until deletion at the data subject's request (unsubscription), or until the newsletter service is discontinued. 7) The data subject may unsubscribe from the newsletter/DM-letter at any time, a) via the “Unsubscribe” link at the bottom of electronic letters (immediate unsubscription),
or; b) by writing to info@budapestisminkiskola.com, preferably with the word UNSUBSCRIBE
in the subject line, or; c) by post, by sending an unsubscription request to Bp. Smink és Maszkmester Oktató
Szolgáltató és Kereskedelmi Kft., 1083 Budapest, Illés u. 28-30. Building B, 7th floor, 705. A data subject wishing to unsubscribe should be aware that only the method under point a) above results in immediate unsubscription; unsubscription under points b)-c) may take a few days to process, and it is not a breach of policy if the system still sends a newsletter to the data subject during that period. The Data Controller also notes that a newsletter sent at or near the same time as an immediate unsubscription request under point a) may technically cross paths with it; therefore receiving a newsletter after unsubscribing does not mean that the unsubscription request was disregarded.
1) Purpose of processing: Sharing content found on the Data Controller's website on social media platforms, raising awareness of it, and marketing. 2) Legal basis: Processing related to the Data Controller's profile(s) on social media platform(s) is based on voluntary consent. 3) Recipients / categories of recipients of the personal data: Employees of the Data Controller supporting social media marketing, and IT and hosting processors.
4) Scope and purpose of data processed: name – identification; profile photo used – identification; comment – expressing an opinion/comment; rating – expressing an opinion/sentiment; content of question/request – input data for the response. 5) Categories of data subjects: Any natural person who visits or follows the Data Controller's social media pages, reacts to content posted there (like/dislike), comments on it, or shares it, in whole or in part, among their own contacts. 6) Duration of processing: Until unsubscription, or until the Data Controller's social media page ceases operation. 7) The Data Controller does not process personal data published by visitors/commenters on its Facebook page. In the event of any unlawful or offensive content, the Data Controller is entitled to delete such content. Further information: https://www.facebook.com/legal/terms/update
1) Purpose of processing: facilitating financial performance by the data subject. 2) Legal basis: Providing data related to a bank transfer is based on voluntary consent. 3) Recipients / categories of recipients of the personal data: Employees of the Data Controller performing accounting tasks, and bookkeeping/accounting processors. 4) Scope and purpose of data processed: name (of the account holder) – identification; e-mail address (postal address) – needed to send the payment request and invoice; bank account number – identification; reference/note – identification; amount – needed for performance. 5) Categories of data subjects: Any natural person who wishes to pay by bank transfer. 6) Duration of processing: In accordance with the applicable accounting rules. 7) Process of the data processing: a) the Data Controller sends a payment request/invoice to the data subject's e-mail (postal) address. b) the data subject transfers the appropriate amount to the Data Controller's bank account. c) the Data Controller checks the transfer. d) the data related to the transfer is entered into the Data Controller's bookkeeping system,
to which only the Data Controller's employees performing accounting tasks, and the bookkeeper contractually engaged by the Data Controller, as processor in this respect, have access.
8) Purpose of processing: enabling complaints to be submitted, identifying the data subject and their complaint, recording the data mandatorily required by law, and the contact necessary to investigate and settle the complaint. 9) Legal basis: Submitting a complaint is based on voluntary consent, but with respect to the data processed in connection with a submitted complaint, processing is mandatory under Act CLV of 1997 on Consumer Protection (the “Consumer Protection Act”).
10) Recipients / categories of recipients of the personal data: Employees of the Data Controller handling complaints. 11) Scope and purpose of data processed: complaint identifier – identification; name – identification; date the complaint was received – identification; phone number – contact; time of the call – identification; personal data provided during the conversation – identification; billing/mailing/e-mail address – contact; product/service/conduct complained of – investigating the complaint; attached documents – investigating the complaint; reason for the complaint – investigating the complaint; the complaint itself – investigating the complaint. 12) Categories of data subjects: Any natural person who wishes to submit, verbally or in writing, a complaint about an ordered/used product or service, or about the Data Controller's conduct, activity or omission. 13) Duration of processing: the Data Controller is required to keep the minutes taken of the complaint and a copy of the response for 5 years from their creation, pursuant to Section 17/A(7) of the applicable Consumer Protection Act. 14) A complaint may be submitted a) to info@budapestisminkiskola.com, preferably with the word COMPLAINT in the
subject line, or b) by post to Bp. Smink és Maszkmester Oktató Szolgáltató és Kereskedelmi Kft.,
1083 Budapest, Illés u. 28-30. Building B, 7th floor, 705. Minutes must be taken of a complaint made in person, verbally. 15) In accordance with the Consumer Protection Act, the Data Controller must respond in writing to a written complaint on the merits within thirty days of receipt, or within a shorter period if required by law, and take action to communicate its response. The Data Controller must give reasons for rejecting a complaint. 16) Process of the data processing: a) the data subject communicates the complaint to the Data Controller in the manner of their choosing. b) in the case of a verbal complaint, the Data Controller takes minutes of the complaint. c) the Data Controller examines all circumstances of the complaint and, based on these, responds
within the applicable deadline. d) the Data Controller strives to settle the matter in a manner satisfactory to the
9. What should you know, as a visitor to our website, about the use of cookies?
1) Publicly available content on the Data Controller's website can be viewed without providing any personal data. The website automatically records the following data about visitors: the visitor's IP address, the time of the visit, and the subpages and content viewed on the website. The Data Controller uses this data exclusively for analysing the website and for verifying its secure operation. 2) Like the vast majority of other available websites, this website uses so-called “cookies”, which store information related to the use of the website.
These enable the use of Google Analytics services. The purpose of processing data stored in cookies is to improve the user experience and develop the website's online services. Cookies used on the website do not store information suitable for identifying a specific person. 3) Users may remove cookies placed on their computer during a visit to the website at any time from their own computer, or disable the use of cookies in their browser. Further information on this is available (also in Hungarian) at https://www.google.com/intl/hu/policies/privacy/partners/ and https://policies.google.com/technologies/cookies?hl=hu. 4) The website also contains so-called Facebook pixels, which allow Facebook to use cookies, tracking pixels and similar data-storage technologies to collect or receive data about the site, and to use this data to provide measurement services and display targeted advertisements to those who have previously visited the Data Controller's website. Website visitors may at any time decide that they do not want their data collected and used for ad targeting purposes. Further information on this is available (also in Hungarian) at https://www.facebook.com/about/privacy. 5) The Data Controller uses and stores questions, ideas, suggestions and comments submitted by e-mail via the website, typically through the “Write to me here!” link, for the purpose of developing its processes, products and services. Providing this data is voluntary; the Data Controller considers consent to processing for the above purposes to have been given by sending the e-mail. E-mails containing ideas, opinions and comments are kept by the Data Controller for at most 1 year; if the purpose of processing ceases earlier, the e-mail is deleted upon that occurring.
10. Who has access to the data?
1) The personal data provided by the data subject may be accessed by the Data Controller and by the Processors identified in Section 1 or in the description of the individual processing activities, in order to carry out their tasks. Processing of personal data is generally carried out by the Data Controller, or, for outsourced activities, by the processors. In such cases, the Data Controller transfers data to the processors, or they gain access to data by the nature of their activity. The Data Controller is responsible for the activities of the processors. 2) The attorney representing the Data Controller may also become aware of the data subject's personal data if court proceedings are initiated based on the data subject's submission. 3) The Data Controller transfers personal data to other state bodies only in exceptional cases, if a) under legislation and its internal policy on record-keeping, the Data Controller
transfers a case file containing the data subject's personal data to the Archives; b) court proceedings are initiated in a matter concerning the data subject, and it is
necessary to transfer documents containing the data subject's personal data to the court hearing the case; c) the police contact the Data Controller and request the transfer of documents
containing the data subject's personal data for the purposes of an investigation.
11. Do we act as a processor for another controller?
The Data Controller does not perform processor activities for any other controller.
12. What data-security measures do we take?
1) The Data Controller primarily stores personal data provided by the data subject on the servers of the processor(s) named at the beginning of this Privacy and Data Processing Notice, protected by standard security systems, partly on its own IT equipment, and in the case of paper records, properly locked away at its registered seat or premises. The Data Controller does not use any other party's services for storing personal data. 2) The Data Controller takes reasonably expected measures to protect personal data, among other things, against unauthorised access or unauthorised alteration. 3) To secure access to data stored electronically, in files, or in the cloud, the Data Controller implements strong password protection providing adequate security and updates it with sufficient frequency. 4) The Data Controller ensures that access to its systems is logged, and regularly analyses the log data. In the event of any sign of irregularity, the Data Controller takes the necessary preventive or incident-response measures. 5) The Data Controller ensures that passwords are tied to individual users of the devices and systems used, and regularly checks that they are used as prescribed. This includes, in particular, prohibiting the use of passwords by multiple users, storing passwords in a manner inaccessible to others, and making it technically impossible — or, failing that, prohibited — to disable password protection. 6) For electronic data handed over to its processor (e.g. Excel spreadsheets, Word documents, cloud-based databases, etc.), the Data Controller also uses the password-based document-protection options available for the given document, thereby ensuring that even if the document's data reaches an unauthorised person, it remains inaccessible to them. 7) In the case of data stored on paper, physical security must also be ensured, by creating lockable storage and securely keeping the keys. 8) Even while carrying out day-to-day activities, reasonable means must be used to ensure that data stored on paper cannot be seen by others (e.g. using a cover sheet, a folder, folding the document, etc.). 9) At the end of the working day, the Data Controller must allow sufficient time for documents created during the day to be placed in a locked location, inaccessible to unauthorised persons. The Data Controller regularly checks compliance with this. 10) The Data Controller ensures, through regular training, that the human factor necessary to establish and maintain data security remains at a high level. Training must cover keeping users' sense of responsibility high, and good practices must be established to make data security part of everyday routine. (E.g. a user may not leave a laptop or phone containing personal data in a vehicle,
may not leave them unattended, must lock them in a safe at a hotel, etc.) 11) Users are required to report to the Data Controller the slightest sign of abnormal operation they notice. 12) In its cooperation with the processor, the Data Controller and the processor mutually ensure that suitably trained and authorised persons, who know each other's contact details, are available to take the measures needed for data security, to prevent personal data breaches, and, should one occur, to take effective measures to mitigate its effects.
13. What do we do in the event of a personal data breach?
1) A personal data breach (a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed) must be prevented by every reasonable and available means. 2) If there is any sign of a personal data breach, the Data Controller investigates it without delay after becoming aware of it, and determines whether a personal data breach has actually occurred. 3) Even where an event does not qualify as a personal data breach — if a lesson can be drawn from it for safer future operation — what happened must be documented, and the Data Controller takes the necessary measures on that basis.
1) The Data Controller notifies a personal data breach to the supervisory authority competent under Article 55, without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where notification is not made within 72 hours, it must be accompanied by reasons for the delay. 2) The processor notifies the controller without undue delay after becoming aware of a personal data breach. 3) The notification of a personal data breach must at least: a) describe the nature of the personal data breach including, where possible, the categories
and approximate number of data subjects concerned, and the categories and approximate number of personal data records concerned; b) communicate the name and contact details of the data protection officer or other
contact point where more information can be obtained; c) describe the likely consequences of the personal data breach;
d) describe the measures taken or proposed to be taken by the controller to address
the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects. 4) Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay. 5) The controller documents any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation enables the supervisory authority to verify compliance with this Article.
1) When a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Data Controller communicates the personal data breach to the data subject without undue delay. 2) The communication to the data subject must describe in clear and plain language: a) the nature of the personal data breach, including, where possible, the categories of
data subjects and the approximate number of data subjects concerned, and the categories and approximate number of personal data records concerned; b) the name and contact details of the data protection officer or other contact point
where more information can be obtained; c) the likely consequences of the personal data breach;
d) the measures taken or proposed to be taken by the controller to address the
personal data breach, including, where appropriate, measures to mitigate its possible adverse effects. 3) The data subject need not be informed if any of the following conditions is met: a) the controller has implemented appropriate technical and organisational protection
measures, and those measures were applied to the personal data affected by the breach, in particular those that render the data unintelligible to any person who is not authorised to access it, such as encryption; b) the controller has taken subsequent measures which ensure that the high risk to
the rights and freedoms of data subjects is no longer likely to materialise; c) it would involve disproportionate effort. In such cases, there is instead a public
communication or similar measure whereby the data subjects are informed in an equally effective manner. 4) If the controller has not already communicated the personal data breach to the data subject, the supervisory authority, having considered the likelihood of the personal data breach resulting in a high risk, may require it to do so, or may decide that any of the conditions for exemption from notification are met.
14. What are your rights as a data subject?
1) The Data Controller provides the data subject with information about the processing of personal data, and any related notice, based on or by means of this Privacy and Data Processing Notice, prepared under the Data Controller's Privacy and Data Processing Policy, striving for it to be concise, transparent, intelligible, easily accessible, and expressed in clear and plain language. Any excerpt must reference the complete Privacy and Data Processing Notice document (either attached or made available via a link). 2) Information about a data subject may only be provided to that data subject. If the identity of the person requesting the information cannot be established beyond doubt as the data subject, the information must be refused. In such a case, the person acting on behalf of the Data Controller must take minutes accurately recording the facts, which may serve as a basic document in handling a potential complaint. 3) Identification must also be carried out in accordance with the principles of Article 5 of the Regulation (lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, accountability), and must be carried out according to the principle of necessity and proportionality. (For example: no further identification is required for a request arriving from the data subject's e-mail address on record with the Data Controller.) 4) Where the data subject makes the request by electronic means, the information shall be provided by electronic means where possible, unless otherwise requested by the data subject. 5) Information may also be provided orally at the data subject's request, provided that the identity of the data subject is proven by other means. 6) The Data Controller must inform the data subject of the actions taken on the request without undue delay and, in any event, within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of requests. The Data Controller shall inform the data subject of any such extension, together with the reasons for the delay, within one month of receipt of the request. 7) Where the controller does not take action on the request of the data subject, it shall inform the data subject without delay and at the latest within one month of receipt of the request of the reasons for not taking action, and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy. 8) The Data Controller communicates any rectification, erasure or restriction of processing to each recipient to whom the personal data has been disclosed, unless this proves impossible or involves disproportionate effort. The Data Controller shall inform the data subject about those recipients if the data subject requests this.
1) The Data Controller provides the data subject, at the time personal data is obtained from them, with the Privacy and Data Processing Notice document, which contains the information required under Articles 13 and 14 of the Regulation. 2) The Data Controller makes the Privacy and Data Processing Notice available in the footer of its website in a downloadable electronic format, and also displays it on paper in a location accessible to data subjects.
1) The data subject may, through the contact details of the Data Controller given in Section 1, request in writing information from the Data Controller as to whether it processes the data subject's personal data and, if so: a) for what processing purpose it is processed, b) which personal data is processed, c) to which recipients it has been or will be disclosed, d) for how long the Data Controller intends to store it, e) if not collected from the data subject: all information available as to its source,
f) whether it has been transferred to a third country or an international organisation and,
if so, with what safeguards (Article 46). 2) The information must also include information about the data subject's right to request from the controller rectification, erasure or restriction of processing of personal data concerning them, and to object to such processing, as well as the right to lodge a complaint with a supervisory authority. 3) The Data Controller provides the data subject with a copy of the personal data undergoing processing. For any further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs. Where the data subject makes the request by electronic means, the information shall be provided in a commonly used electronic format, unless otherwise requested by the data subject. The right to obtain a copy must not adversely affect the rights and freedoms of others.
The data subject has the right to obtain from the Data Controller, without undue delay, the rectification of inaccurate personal data concerning them. Taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.
1. The data subject may, through the contact details of the Data Controller given in Section 1, request in writing that the Data Controller erase their personal data where:
a) the personal data are no longer necessary in relation to the purposes for which they were
collected or otherwise processed; b) the data subject withdraws the consent on which the processing is based, and there
is no other legal ground for the processing; c) the data subject objects to the processing pursuant to Article 21(1) of the Regulation,
and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2); d) the personal data have been unlawfully processed; e) the personal data must be erased for compliance with a legal obligation under Union
or Member State law to which the controller is subject; f) the personal data have been collected in relation to the offer of information society
services referred to in Article 8(1). 2. Where the controller has made the personal data public and is obliged to erase it, the controller, taking account of available technology and the cost of implementation, takes reasonable steps, including technical measures, to inform other controllers processing the data that the data subject has requested erasure of any links to, or copies or replications of, that personal data. 3. The Data Controller may refuse erasure to the extent that processing is necessary for the establishment, exercise or defence of legal claims, or in the other cases referred to in Article 17(3) of the Regulation.
1. The data subject has the right to obtain from the Data Controller restriction of processing where one of the following applies: a) the accuracy of the personal data is contested by the data subject, for a period
enabling the controller to verify the accuracy of the personal data; b) the processing is unlawful and the data subject opposes the erasure of the personal
data and requests the restriction of their use instead; c) the Data Controller no longer needs the personal data for the purposes of processing,
but they are required by the data subject for the establishment, exercise or defence of legal claims; or d) the data subject has objected to processing pursuant to Article 21(1); in this case
the restriction applies for a period pending the verification whether the controller's legitimate grounds override those of the data subject. 2. Where processing has been restricted under paragraph 1, such personal data shall, with the exception of storage, only be processed with the data subject's consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State. 3. The Data Controller informs the data subject, at whose request processing has been restricted under paragraph 1, before the restriction is lifted.
1. The data subject has the right to receive the personal data concerning them, which they have provided to a controller, in a structured, commonly used and machine-readable format, and has the right to transmit that data to another controller without hindrance from the controller to which the personal data have been provided, where: a) the processing is based on the data subject's consent, or on a contract between
the data subject and the controller as contracting parties; and b) the processing is carried out by automated means. 2. In exercising the right to data portability, the data subject shall have the right to have the personal data transmitted directly from one controller to another, where technically feasible. 3. The exercise of the right to data portability shall not adversely affect the provisions on the right to erasure. This right shall not apply to processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. 4. The right to data portability must not adversely affect the rights and freedoms of others.
1. The data subject has the right to object, on grounds relating to their particular situation, at any time to the processing of personal data concerning them based on Article 6(1)(e) or (f), including profiling based on those provisions. In that case, the controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims. 2. Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to the processing of personal data concerning them for such marketing, which includes profiling to the extent that it is related to such direct marketing. 3. Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes. 4. At the latest at the time of the first communication with the data subject, the right referred to above shall be explicitly brought to their attention and shall be presented clearly and separately from any other information. 5. In the context of the use of information society services, and notwithstanding Directive 2002/58/EC, the data subject may exercise their right to object by automated means using technical specifications. 6. Where personal data are processed for scientific or historical research purposes or statistical purposes pursuant to Article 89(1), the data subject has the right to object, on grounds relating to their particular situation, to processing of personal data concerning them, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
1. The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. 2. Paragraph 1 shall not apply if the decision: a) is necessary for entering into, or performance of, a contract between the data
subject and the controller; b) is authorised by Union or Member State law to which the controller is subject
and which also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests; or c) is based on the data subject's explicit consent. 3. In the cases referred to in points (a) and (c) of paragraph 2, the Data Controller shall implement suitable measures to safeguard the data subject's rights, freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express their point of view and to contest the decision. 4. Decisions referred to in paragraph 2 shall not be based on special categories of personal data referred to in Article 9(1), unless point (a) or (g) of Article 9(2) applies and suitable measures to safeguard the data subject's rights, freedoms and legitimate interests are in place.
Union or Member State law to which the controller or processor is subject may restrict, by way of a legislative measure, the scope of the obligations and rights provided for in Articles 12 to 22 and 34, as well as Article 5 in so far as its provisions correspond to the rights and obligations provided for in Articles 12 to 22, where such a restriction respects the essence of fundamental rights and freedoms and is a necessary and proportionate measure in a democratic society to safeguard the objectives referred to in Article 23.
15. What can you do if you cannot properly exercise your rights described here?
1. The Data Controller strives to enable the data subject to exercise their rights related to data processing in accordance with the law and to settle every matter to their satisfaction. 2. If the data subject's objection, complaint or request concerning their personal data could not be settled satisfactorily with our Company, or if the data subject at any time believes that an infringement has occurred, or that there is a direct risk of one occurring, in connection with the processing of their personal data, they are entitled to lodge a complaint with the National Authority for Data Protection and Freedom of Information.
16. Where can you enforce your rights relating to data processing?
Contact details of the National Authority for Data Protection and Freedom of Information (NAIH)
Registered seat: 1125 Budapest, Szilágyi Erzsébet fasor 22/c. Postal address: 1530 Budapest, Pf. 5 Phone: +36 1 391 1400 Fax: +36 1 391 1410 E-mail: ugyfelszolgalat@naih.hu Website: naih.hu
In the event of unlawful data processing experienced by the data subject, they may bring a civil action against the Data Controller. Such proceedings fall within the jurisdiction of the regional court (törvényszék). The action may be brought — at the data subject's choice — before the regional court of their place of residence (a list of, and contact details for, the regional courts can be found at: http://birosag.hu/torvenyszekek).
