Skip to content
🌞 SUMMER SALE VÉGE:
🌞🏖️👙🌊 25% minden képre + 20% minden második képre 🌊🏖️👙🌞

Data protection

TABLE OF CONTENTS

INTRODUCTION

CHAPTER I – DESIGNATION OF THE DATA CONTROLLER

CHAPTER II – DESIGNATION OF DATA PROCESSORS

  • Our company's IT service provider:
  • Our company's accounting service provider:
  • Postal services, delivery, parcel delivery:

CHAPTER III – EMPLOYMENT-RELATED DATA PROCESSING

  • Labor and personnel records
  • Data processing related to aptitude tests
  • Management of data of employees applying for employment, applications, CVs
  • Data processing related to checking the use of an email account
  • Data management related to computer, laptop, tablet verification
  • Data processing related to monitoring internet use at work
  • Data processing related to monitoring the use of company mobile phones
  • Data processing related to the use of GPS navigation systems
  • Data processing related to workplace entry and exit
  • Data processing related to workplace camera surveillance

CHAPTER IV – DATA PROCESSING RELATED TO A CONTRACT

  • Management of data of contracting partners – registration of customers and suppliers
  • Contact details of natural person representatives of legal entity clients, buyers, suppliers
  • Recording customer service calls
  • Visitor data management on the Company's website
  • Information about the use of cookies
  • Registration on the Company's website
  • Data processing related to newsletter service
  • Community Guidelines / Data Management on the Company's Facebook Page
  • Data processing in the Company's webshop
  • Data processing related to the organization of a prize draw
  • Data processing for direct marketing purposes

CHAPTER V – DATA PROCESSING BASED ON LEGAL OBLIGATIONS

  • Data processing for the purpose of fulfilling tax and accounting obligations
  • Payer data management
  • Data processing for the purpose of fulfilling anti-money laundering obligations

CHAPTER VI – SUMMARY INFORMATION ON THE RIGHTS OF THE DATA SUBJECT

CHAPTER VII – DETAILED INFORMATION ON THE RIGHTS OF THE DATA SUBJECT

CHAPTER VIII – SUBMISSION OF THE DATA SUBJECT’S REQUEST, MEASURES OF THE DATA CONTROLLER


INTRODUCTION

REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Regulation 95/46/EC (hereinafter referred to as the Regulation) requires that the Data Controller shall take appropriate measures to provide the data subject with any information relating to the processing of personal data in a concise, transparent, intelligible and easily accessible form, in clear and plain language, and that the Data Controller shall facilitate the exercise of the data subject's rights.

The obligation of prior information of the data subject is also prescribed by Act CXII of 2011 on the right to informational self-determination and freedom of information.

We comply with this legal obligation by providing the information below.

The information must be published on the company's website or sent to the person concerned upon request.

CHAPTER I

NAME OF THE DATA CONTROLLER

The publisher of this information, which is also the Data Controller:

  • Company name: The Art Bridge Ltd.
  • Registered office: 2089 Telki Nyúl u. 8.
  • Company registration number: 13-09-230273
  • Tax number: 26198020-1-13
  • Representative: Eszter Zborai, managing director
  • Phone number: +36 20 253 8945
  • Email address: info@artbridge.hu
  • Website: www.artbridge.hu

(hereinafter referred to as: Company)

CHAPTER II

DESIGNATION OF DATA PROCESSORS

Data processor: the natural or legal person, public authority, agency or any other body which processes personal data on behalf of the data controller; (Article 4, point 8 of the Regulation). The use of a data processor does not require the prior consent of the data subject, but it is necessary to inform him/her. Accordingly, we provide the following information:

Our company's IT service provider

Our company uses a data processor to maintain and manage its website, who provides IT services (hosting, platform operation) and, within this framework, processes the personal data provided on the website for the duration of our contract with it. Along with the operations performed by it, the personal data is stored on the server.

The name of this data processor is as follows:

Company name: Shopify International Ltd.
Headquarters: 2nd Floor, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland
Company registration number: 560826
Tax number: IE3452302HH
Website: www.shopify.com

Shopify provides the IT platform and hosting services for the Artbridge web store.

Our company's accounting service provider

To fulfill its tax and accounting obligations, our Company uses an external service provider under an accounting service provider contract, who also processes the personal data of natural persons in a contractual or payer relationship with our Company, for the purpose of fulfilling the tax and accounting obligations of our Company.

The name of this data processor is as follows:

  • Company name: T+T Tax Ltd.
    Headquarters: 1142 Budapest, Queen Erzsébet Street 62.
  • Company registration number:
  • Tax number: 12779091-2-42
  • Representative: Theresia Bagó
  • Phone number: +36 30 383 9439

Postal services, delivery, parcel delivery

These data processors receive the personal data necessary for the delivery of the ordered product from our Company (name, address, telephone number of the data subject) and use this to deliver the product.

These service providers:

  • Company name: GLS Hungary Ltd.
  • Registered office: 2351 Alsónémedi Europe Street 2.
  • Company registration number: 13-09-111755
  • Tax number: 12369410-2-44
  • Email: info@gls-hungary.com
  • Web: www.gls.hu

CHAPTER III

EMPLOYMENT-RELATED DATA PROCESSING

Labor and personnel records

(1) Only such data may be requested from employees and recorded, and only such medical fitness examinations may be performed for the job, which are necessary for the establishment, maintenance and termination of employment, or for the provision of social welfare benefits, and which do not violate the personal rights of the employee.

(2) The Company processes the following data of employees for the purpose of establishing, fulfilling or terminating an employment relationship in order to enforce the legitimate interests of the employer (Article 6 (1) paragraph f) of the Regulation):

  • name
  • birth name
  • date of birth
  • mother's name
  • address
  • nationality
  • tax identification number
  • Social Security number
  • pensioner registration number (in the case of a retired employee)
  • phone number
  • email address
  • ID card number
  • number of official ID card proving address
  • bank account number
  • online ID (if applicable)
  • start and end date of work
  • job title
  • a copy of a document certifying your educational qualifications and professional qualifications
  • photo resume
  • passport number in the case of a foreign employee
  • the name of the document proving your employment eligibility

(3) The employer processes data relating to illness and trade union membership only for the purpose of fulfilling the rights or obligations specified in the Labor Code.

(4) Recipients of personal data: the employer's manager, the person exercising employer authority, the Company's employees and data processors performing labor-related tasks.

(5) Only the personal data of management employees may be transferred to the owners of the Company.

(6) Duration of storage of personal data: 3 years after termination of employment.

(7) Before starting data processing, the data subject must be informed that the data processing is based on the Labor Code and the enforcement of the employer's legitimate interests.

Management of data of employees applying for employment, applications, CVs

(1) The scope of personal data that can be processed: the natural person's name, date and place of birth, mother's name, address, qualification data, photo, telephone number, e-mail address, employer's note on the applicant (if any).

(2) The purpose of processing personal data is: application, evaluation of the application, conclusion of an employment contract with the selected person. The data subject must be informed if the employer has not selected him/her for the given position.

(3) Legal basis for data processing: consent of the data subject.

(4) Recipients of personal data and categories of recipients: managers and employees performing labor duties authorized to exercise employer rights at the Company.

(5) Duration of storage of personal data: Until the application or tender is assessed. The personal data of applicants who are not selected must be deleted. The data of those who have withdrawn their application or tender must also be deleted.

(6) The employer may only retain applications based on the express, unambiguous and voluntary consent of the data subject, provided that their retention is necessary to achieve the purpose of the data processing in accordance with the law. This consent must be requested from the applicants after the conclusion of the recruitment procedure.

CHAPTER IV

DATA PROCESSING RELATED TO A CONTRACT

Management of data of contracting partners – registration of customers and suppliers

(1) The Company processes the name, birth name, date of birth, mother's name, address, tax identification number, tax number, entrepreneur's or primary producer's ID number, ID number, address, registered office, location, telephone number, e-mail address, website address, bank account number, customer number (customer number, order number), online identifier (list of customers, suppliers, regular purchase lists) of the natural person who has entered into a contract with it for the purpose of concluding, fulfilling, terminating the contract, and providing a contractual discount, for the purpose of fulfilling the contract. This data processing is considered lawful even if the data processing is necessary to take steps at the request of the data subject prior to concluding the contract. The recipients of the personal data are: the Company's employees performing customer service-related tasks, employees performing accounting and tax tasks, and data processors. Duration of personal data processing: 5 years after the termination of the contract.

(2) Before the commencement of data processing, the data subject must be informed that the data processing is based on the legal basis of the performance of the contract; this information may also be provided in the contract.

(3) The data subject must be informed about the transfer of his or her personal data to the data processor.

Contact details of natural person representatives of legal entity clients, buyers, suppliers

(1) The scope of personal data that can be processed: the name, address, telephone number, e-mail address, online identifier of the natural person.

(2) The purpose of the processing of personal data: performance of the contract concluded with the Company's legal entity partner, business relations, legal basis: the consent of the data subject.

(3) Recipients of personal data and categories of recipients: employees of the Company performing customer service-related tasks.

(4) Duration of storage of personal data: 5 years after the business relationship or the representative status of the data subject.

Visitor data management on the Company's website

(1) Cookies are short data files that are placed on the user's computer by the website you visit. The purpose of a cookie is to make the given infocommunication and internet service easier and more convenient. There are many types of cookies, but they can generally be classified into two large groups. One is a temporary cookie, which the website places on the user's device only during a given session (e.g. during the security identification of an internet banking session), the other type is a permanent cookie (e.g. the language setting of a website), which remains on the computer until the user deletes it. According to the European Commission's guidelines, cookies [unless they are absolutely necessary for the use of the given service] can only be placed on the user's device with the user's permission.

(2) In the case of cookies that do not require the user's consent, information must be provided during the first visit to the website. It is not necessary for the full text of the information on cookies to appear on the website; it is sufficient for the website operators to briefly summarize the essence of the information and provide a link to the full information.

(3) In the case of cookies requiring consent, the information may also be related to the first visit to the website if the data processing associated with the use of cookies begins with the visit to the website. If the use of the cookie is related to the use of a function expressly requested by the user, the information may also be displayed in connection with the use of this function. In this case, it is not necessary for the full text of the information on cookies to be displayed on the website; a short summary of the essence of the information and a link to the availability of the full information are sufficient.

Information about the use of cookies

(1) In accordance with general Internet practice, our Company also uses cookies on its website. A cookie is a small file containing a series of characters that is placed on the visitor's computer when they visit a website. When they visit the given website again, the cookie allows the website to recognize the visitor's browser. Cookies can store user settings (e.g. chosen language) and other information. Among other things, they collect information about the visitor and their device, remember the visitor's individual settings, and can be used, for example, when using online shopping carts. Cookies generally make the website easier to use, help the website to provide users with a real web experience and an effective source of information, and also ensure that the website operator can monitor the operation of the website, prevent abuse, and provide the services provided on the website without interruption and at an appropriate level.

(2) Our company's website records and processes the following data about the visitor and the device they are browsing on when using the website:

  • the IP address used by the visitor,
  • browser type,
  • characteristics of the operating system of the device used for browsing (set language),
  • date of visit,
  • the (sub)page, function or service visited.

(3) Accepting or allowing the use of cookies is not mandatory. You can reset your browser settings to refuse all cookies or to indicate when a cookie is being sent. Most browsers automatically accept cookies by default, but these can usually be changed to prevent automatic acceptance and offer you the option each time.

You can find information about cookie settings for the most popular browsers at the links below.

• Google Chrome: https://support.google.com/accounts/answer/61416?hl=en

• Firefox: https://support.mozilla.org/hu/kb/sutik-engedelyezese-es-tiltasa-amit-weboldak-haszn

• Microsoft Internet Explorer 11: http://windows.microsoft.com/hu-hu/internet-explorer/delete-manage-cookies#ie=ie-11

• Microsoft Internet Explorer 10: http://windows.microsoft.com/hu-hu/internet-explorer/delete-manage-cookies#ie=ie-10-win-7

• Microsoft Internet Explorer 9: http://windows.microsoft.com/hu-hu/internet-explorer/delete-manage-cookies#ie=ie-9

• Microsoft Internet Explorer 8: http://windows.microsoft.com/hu-hu/internet-explorer/delete-manage-cookies#ie=ie-8

• Microsoft Edge: http://windows.microsoft.com/hu-hu/windows-10/edge-privacy-faq

• Safari: https://support.apple.com/hu-hu/HT201265

However, please note that certain website features or services may not function properly without cookies.

(4) The cookies used on the website are not capable of identifying the user by themselves.

( 5) Cookies used on our company's website:

Technically essential session cookies

These cookies are necessary to enable visitors to browse the website, to use its functions smoothly and to the full extent, and to use the services available through the website, including, among other things, to remember the actions taken by the visitor on the given pages during a visit. The duration of data processing of these cookies applies only to the visitor's current visit, and this type of cookie is automatically deleted from your computer when the session ends or the browser is closed.

The data handled:

The legal basis for this data processing is Section 13/A (3) of Act CVIII of 2001 on certain issues of electronic commerce services and information society services (Elkertv.).

The purpose of data management is to ensure the proper functioning of the website.

Cookies requiring consent:

These enable the Company to remember the user's choices regarding the website. The visitor may prohibit this data processing at any time before and during the use of the service. These data cannot be linked to the user's identification data and cannot be transferred to a third party without the user's consent.

2.1. Cookies that facilitate use:

The legal basis for data processing is the visitor's consent.

The purpose of data processing is: Increasing the efficiency of the service, enhancing the user experience, and making the website more convenient to use.

The duration of data management is 6 months.

2.2. Performance cookies:

Google Analytics cookies – you can find out more about this here:

https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage

Google AdWords cookies – you can find out more about this here:

https://support.google.com/adwords/answer/2407785?hl=en

Community Guidelines / Data Management on the Company's Facebook Page

  • 1) The Company maintains a Facebook page to introduce and promote its products and services.
  • 2) A question posted on the Company's Facebook page does not constitute an officially submitted complaint.
  • 3) The Company does not process personal data published by visitors on the Company's Facebook page.
  • 4) Visitors are subject to Facebook's Privacy and Terms of Service.
  • 5) In the event of the publication of illegal or offensive content, the Company may exclude the person concerned from membership or delete their comment without prior notice.
  • 6) The Company is not responsible for any illegal content or comments posted by Facebook users. The Company is not responsible for any errors, malfunctions or problems arising from changes to the operation of Facebook.

CHAPTER V

DATA PROCESSING BASED ON LEGAL OBLIGATIONS

Data processing for the purpose of fulfilling tax and accounting obligations

(1) The Company processes the data specified in the law of the natural persons entering into business relations with it as buyers and suppliers in order to fulfill legal obligations and tax and accounting obligations prescribed by law (accounting, taxation). The processed data are, in particular, pursuant to Sections 169 and 202 of Act CXXVII of 2017 on Value Added Tax: tax number, name, address, tax status; pursuant to Section 167 of Act C of 2000 on Accounting: name, address, designation of the person or organization ordering the economic transaction, the person issuing the order and the person certifying the execution of the order, and, depending on the organization, the signature of the auditor; the signature of the recipient on the stock movement documents and cash management documents, the signature of the payer on the counter-receipts; pursuant to Section CXVII of 1995 on Personal Income Tax: according to the law: entrepreneur ID number, primary producer ID number, tax identification number.

(2) The storage period of personal data is 8 years after the termination of the legal relationship that gave rise to the legal basis.

(3) Recipients of personal data: employees and data processors of the Company performing tax, accounting, payroll and social security tasks.

Payer data management

(2) The Company processes the personal data of those data subjects – employees, their family members, employees, recipients of other benefits – prescribed in tax laws, with whom its payers (2017:CL. Act on the Taxation System (Art.) 7.§ 31.) are in a relationship, for the purpose of fulfilling legal obligations and for the purpose of fulfilling tax and contribution obligations prescribed by law (assessment of tax, tax advance, contributions, payroll accounting, social security administration). The scope of the processed data is determined by Art. 50.§, specifically highlighting: the natural person's personal identification data (including the previous name and title), gender, citizenship, tax identification number of the natural person, social security identification number (TAJ number). If tax laws provide for legal consequences, the Company may process data related to employees' health (Szja tv. § 40) and trade union membership (Szja § 47(2) b./) for the purpose of fulfilling tax and contribution obligations (payroll accounting, social security administration).

(2) The storage period of personal data is 8 years after the termination of the legal relationship that gave rise to the legal basis.

(3) Recipients of personal data: employees and data processors of the Company performing tax, payroll and social security (payer) tasks.

Data processing for the purpose of fulfilling anti-money laundering obligations

(1) The Company processes the data of its clients, their representatives and beneficial owners, as specified in Act LIII of 2017 on the Prevention and Prevention of Money Laundering and the Financing of Terrorism (Pmt.), in order to fulfil its legal obligation and to prevent and combat money laundering and terrorist financing: a) natural person a) family name and first name, b) family name and first name at birth, c) citizenship, d) place and date of birth, e) mother's birth name, f) address, or in the absence thereof, place of residence, g) type and number of identification document; number of official ID card proving address, copy of the documents presented. (§ 7).

(2) Recipients of personal data: the Company's employees performing customer service-related tasks, the Company's manager and the Company's designated person pursuant to the Personal Data Protection Act.

(3) The period of storage of personal data: 8 years from the termination of the business relationship or the fulfillment of the transaction order. (Pmt. § 56(2))

CHAPTER VI

SUMMARY INFORMATION ON THE RIGHTS OF THE DATA SUBJECT

In this chapter, for the sake of clarity and transparency, we briefly summarize the rights of the data subject, detailed information on the exercise of which is provided in the following chapter.

Right to prior information

The data subject has the right to be informed about the facts and information related to data processing before the start of data processing.

(Articles 13-14 of the Regulation)

We will provide information about the detailed rules in the next chapter.

The data subject's right of access

The data subject has the right to receive feedback from the Data Controller as to whether his or her personal data is being processed and, if such processing is taking place, has the right to access the personal data and related information as specified in the Regulation.

(Article 15 of the Regulation).

We will provide information about the detailed rules in the next chapter.

The right to rectification

The data subject shall have the right to obtain from the Controller, at his/her request, the rectification of inaccurate personal data concerning him/her without undue delay. Taking into account the purpose of the processing, the data subject shall have the right to request the completion of incomplete personal data, including by means of a supplementary statement.

(Article 16 of the Regulation).

The right to erasure (“the right to be forgotten”)

The data subject has the right to request that the Data Controller erase personal data concerning him or her without undue delay, and the Data Controller is obliged to erase personal data concerning the data subject without undue delay if one of the reasons specified in the Regulation applies.

(Article 17 of the Regulation)

We will provide information about the detailed rules in the next chapter.

Right to restriction of data processing

The data subject has the right to request that the Data Controller restrict data processing if the conditions specified in the order are met.

(Article 18 of the Regulation)

We will provide information about the detailed rules in the next chapter.

Notification obligation related to the rectification or erasure of personal data or the restriction of data processing

The Data Controller shall inform all recipients to whom the personal data have been disclosed of any rectification, erasure or restriction of processing, unless this proves impossible or involves a disproportionate effort. Upon request, the Data Controller shall inform the data subject of these recipients.

(Article 19 of the Regulation)

The right to data portability

Under the conditions set out in the Regulation, the data subject has the right to receive the personal data concerning him or her, which he or she has provided to a Data Controller, in a structured, commonly used and machine-readable format, and has the right to transmit these data to another Data Controller without hindrance from the Data Controller to whom the personal data have been provided.

(Article 20 of the Regulation)

We will provide information about the detailed rules in the next chapter.

The right to protest

The data subject has the right to object at any time, on grounds relating to his or her particular situation, to the processing of personal data concerning him or her based on point (e) of Article 6(1) of the Regulation (processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller) or point (f) of Article 6(1) of the Regulation (processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party).

(Article 21 of the Regulation)

We will provide information about the detailed rules in the next chapter.

Automated decision-making in individual cases, including profiling

The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.

(Article 22 of the Regulation)

We will provide information about the detailed rules in the next chapter.

Restrictions

Union or Member State law applicable to the controller or processor may restrict, by means of legislative measures, the rights and obligations set out in Articles 12 to 22 and Article 34 and in accordance with Articles 12 to 22.

(Article 23 of the Regulation)

We will provide information about the detailed rules in the next chapter.

Informing the data subject about the data protection incident

If the data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Controller shall inform the data subject about the data breach without undue delay.

(Article 34 of the Regulation)

We will provide information about the detailed rules in the next chapter.

Right to lodge a complaint with a supervisory authority (right to a judicial remedy)

The data subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement, if the data subject considers that the processing of personal data concerning him or her infringes the Regulation.

(Article 77 of the Regulation)

We will provide information about the detailed rules in the next chapter.

Right to an effective judicial remedy against the supervisory authority

Every natural and legal person has the right to an effective judicial remedy against a legally binding decision of a supervisory authority concerning him or her, or if the supervisory authority does not deal with the complaint or does not inform the data subject within three months of the procedural developments or the outcome of the complaint submitted.

(Article 78 of the Regulation)

We will provide information about the detailed rules in the next chapter.

Right to an effective judicial remedy against the controller or processor

Every data subject shall have the right to an effective judicial remedy if he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data not in accordance with this Regulation.

(Article 79 of the Regulation)

We will provide information about the detailed rules in the next chapter.

CHAPTER VII

DETAILED INFORMATION ON THE RIGHTS OF THE DATA SUBJECT

Right to prior information

The data subject has the right to be informed about the facts and information related to data processing before the start of data processing.

A) Information to be provided when personal data are collected from the data subject

Where personal data relating to the data subject are collected from the data subject, the controller shall provide the data subject with all of the following information at the time the personal data are obtained:

a) the identity and contact details of the controller and, if any, the controller's representative; b) the contact details of the data protection officer, if any;

c) the purpose of the intended processing of personal data and the legal basis for the processing;

d) Article 6(1) of the Regulation

f) (legitimate interest), the legitimate interests of the data controller or a third party;

(e) where applicable, the recipients of the personal data and the categories of recipients, if any;

(f) where applicable, the fact that the controller intends to transfer the personal data to a third country or to an international organisation, the existence or absence of an adequacy decision by the Commission or, in the case of transfers referred to in Article 46, Article 47 or the second subparagraph of Article 49(1) of the Regulation, an indication of the appropriate and suitable safeguards and a reference to the means of obtaining a copy of them or their availability. In addition to the information referred to in point 1, the controller shall, at the time of obtaining the personal data, provide the data subject with the following additional information in order to ensure fair and transparent processing:

a) the period for which the personal data will be stored or, if this is not possible, the criteria for determining this period;

b) the right of the data subject to request from the controller access to, rectification, erasure or restriction of processing of personal data concerning him or her, and to object to the processing of such personal data, as well as the right of the data subject to data portability;

c) in the case of processing based on Article 6(1)(a) (the data subject's consent) or Article 9(2)(a) (the data subject's consent) of the Regulation, the right to withdraw consent at any time, without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal;

d) the right to lodge a complaint with the supervisory authority;

e) whether the provision of personal data is based on a legal or contractual obligation or is a prerequisite for concluding a contract, and whether the data subject is obliged to provide the personal data, as well as the possible consequences of failure to provide the data;

f) the fact of automated decision-making referred to in Article 22(1) and (4) of the Regulation, including profiling, and at least in those cases, intelligible information about the logic involved and the significance and foreseeable consequences of such processing for the data subject. Where the controller intends to process personal data for purposes other than those for which they were collected, the controller shall, prior to the further processing, inform the data subject of that purpose and of any relevant additional information referred to in paragraph 2. Points 1 to 3 shall not apply if and to the extent that the data subject already has the information.

(Article 13 of the Regulation)

B) Information to be provided if the personal data were not obtained from the data subject

If the personal data were not obtained from the data subject, the controller shall provide the data subject with the following information:

a) the identity and contact details of the data controller and, if any, the data controller's representative;

b) contact details of the data protection officer, if any;

c) the purpose of the intended processing of personal data and the legal basis for the processing;

(d) the categories of personal data concerned;

e) the recipients of the personal data and the categories of recipients, if any;

(f) where applicable, the fact that the controller intends to transfer the personal data to a recipient in a third country or to an international organisation, the existence or absence of an adequacy decision by the Commission or, in the case of transfers referred to in Articles 46, 47 or the second subparagraph of Article 49(1) of the Regulation, an indication of the appropriate and suitable safeguards and a reference to the means of obtaining a copy of them or their accessibility. In addition to the information referred to in point 1, the controller shall provide the data subject with the following additional information necessary to ensure fair and transparent processing for the data subject:

a) the period for which the personal data will be stored or, if this is not possible, the criteria for determining this period;

b) if the processing is based on Article 6(1)(f) of the Regulation (legitimate interest), the legitimate interests of the controller or a third party;

c) the right of the data subject to request from the controller access to, rectification, erasure or restriction of processing of personal data concerning him or her, and to object to the processing of personal data, as well as the right of the data subject to data portability;

d) in the case of processing based on Article 6(1)(a) (the data subject's consent) or Article 9(2)(a) (the data subject's consent) of the Regulation, the right to withdraw consent at any time, without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal;

(e) the right to lodge a complaint with a supervisory authority;

(f) the source of the personal data and, where applicable, whether the data originate from publicly available sources; and

g) the fact of automated decision-making referred to in Article 22(1) and (4) of the Regulation, including profiling, and at least in those cases, intelligible information about the logic involved and the significance and foreseeable consequences of such processing for the data subject. The controller shall provide the information referred to in points 1 and 2 as follows:

a) taking into account the specific circumstances of the processing of personal data, within a reasonable period of time from the date of obtaining the personal data, but no later than one month;

b) if the personal data are used for the purpose of communicating with the data subject, at least upon initial contact with the data subject; or

c) if the data are expected to be disclosed to other recipients, at the latest when the personal data are disclosed for the first time. If the controller intends to process the personal data for a purpose other than that for which they were collected, he shall inform the data subject of that purpose and of any relevant additional information referred to in point 2 before the further processing. Points 1 to 5 shall not apply if and to the extent that:

(a) the data subject already has the information;

(b) providing the information in question proves impossible or would involve a disproportionate effort, in particular for archiving purposes in the public interest, scientific and historical research purposes or statistical purposes, in the case of processing carried out subject to the conditions and safeguards referred to in Article 89(1) of the Regulation, or where the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously jeopardise the achievement of the purposes of such processing. In such cases, the controller shall take appropriate measures to safeguard the rights, freedoms and legitimate interests of the data subject, including making the information publicly available;

(c) the collection or disclosure of the data is expressly required by Union or Member State law applicable to the controller, which provides for appropriate measures to safeguard the legitimate interests of the data subject; or

(d) personal data must remain confidential pursuant to an obligation of professional secrecy laid down in Union or Member State law, including a statutory obligation of confidentiality.

(Article 14 of the Regulation)

The data subject's right of access

The data subject has the right to receive feedback from the Data Controller as to whether his or her personal data is being processed and, if such processing is taking place, he or she has the right to access the personal data and the following information:

a) the purposes of data processing;

(b) the categories of personal data concerned;

(c) the recipients or categories of recipients to whom the personal data have been or will be disclosed, including in particular recipients in third countries or international organisations;

(d) where applicable, the planned period for which the personal data will be stored or, if this is not possible, the criteria for determining this period;

e) the right of the data subject to request from the Data Controller the rectification, erasure or restriction of processing of personal data concerning him or her, and to object to the processing of such personal data;

(f) the right to lodge a complaint with a supervisory authority;

g) if the data were not collected from the data subject, all available information on their source;

h) the fact of automated decision-making referred to in Article 22(1) and (4) of the Regulation, including profiling, and at least in these cases, intelligible information on the logic involved and the significance and foreseeable consequences of such processing for the data subject.

Where personal data are transferred to a third country or to an international organisation, the data subject shall have the right to be informed of the appropriate safeguards relating to the transfer in accordance with Article 46 of the Regulation. The Controller shall provide the data subject with a copy of the personal data which are the subject of the processing. For further copies requested by the data subject, the Controller may charge a reasonable fee based on the administrative costs. If the data subject has submitted the request electronically, the information shall be provided in a commonly used electronic format, unless the data subject otherwise requests. The right to request a copy shall not adversely affect the rights and freedoms of others.

(Article 15 of the Regulation)

The right to erasure (“the right to be forgotten”)

The data subject has the right to request that the Data Controller erase personal data concerning him or her without undue delay, and the Data Controller is obliged to erase personal data concerning the data subject without undue delay if one of the following reasons applies:

a) the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;

b) the data subject withdraws his or her consent which was the basis for the processing pursuant to point (a) of Article 1(1) or point (a) of Article 9(2) of the Regulation and there is no other legal basis for the processing;

c) the data subject objects to the processing of his or her data on the basis of Article 21(1) of the Regulation and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing on the basis of Article 21(2);

d) the personal data have been processed unlawfully;

e) the personal data must be erased for compliance with a legal obligation under Union or Member State law applicable to the Controller;

f) the personal data were collected in connection with the provision of information society services referred to in Article 8(1) of the Regulation.

Where the Controller has made the personal data public and is obliged to erase them pursuant to point 1 above, the Controller, taking into account available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform the Controllers processing the data that the data subject has requested erasure by them of links to, or copies or replications of, the personal data concerned.

Points 1 and 2 do not apply if the processing is necessary:

a) for the purpose of exercising the right to freedom of expression and information;

b) for the purpose of fulfilling an obligation to process personal data under Union or Member State law applicable to the Controller, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;

c) on grounds of public interest in the field of public health, in accordance with Article 2(h) and (i) and Article 9(3) of the Regulation;

d) for archiving purposes in the public interest, scientific and historical research purposes or statistical purposes in accordance with Article 1(1) of the Regulation, where the right referred to in point 1 would likely render impossible or seriously jeopardise such processing; or

e) for the establishment, exercise or defense of legal claims.

(Article 17 of the Regulation)

Right to restriction of data processing

The data subject has the right to request that the Data Controller restrict data processing if one of the following applies:

a) the data subject disputes the accuracy of the personal data, in which case the restriction shall apply for a period of time enabling the Data Controller to verify the accuracy of the personal data;

b) the processing is unlawful and the data subject opposes the erasure of the data and instead requests the restriction of their use;

c) the Data Controller no longer needs the personal data for the purposes of data processing, but the data subject requires them for the establishment, exercise or defense of legal claims; or

d) the data subject has objected to the processing pursuant to Article 21(1) of the Regulation; in such a case, the restriction shall apply for a period of time until it is determined whether the legitimate grounds of the Controller override those of the data subject.

If processing is restricted pursuant to point 1, such personal data may, with the exception of storage, only be processed with the consent of the data subject, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for important public interests of the Union or of a Member State. The Controller shall inform the data subject at whose request the processing has been restricted pursuant to point 1 in advance of the lifting of the restriction on processing.

(Article 18 of the Regulation)

The right to data portability

The data subject has the right to receive the personal data concerning him or her, which he or she has provided to a Data Controller, in a structured, commonly used and machine-readable format and has the right to transmit those data to another Data Controller without hindrance from the Data Controller to whom the personal data have been provided, if:

a) the processing is based on consent pursuant to point (a) of Article 6(1) or point (a) of Article 9(2) of the Regulation, or on a contract pursuant to point (b) of Article 6(1) of the Regulation; and

b) the data processing is carried out in an automated manner.

    In exercising the right to data portability pursuant to point 1, the data subject shall have the right to request the direct transmission of personal data between controllers, where technically feasible. The exercise of this right shall be without prejudice to Article 17 of the Regulation. The said right shall not apply where the processing is carried out in the public interest or is necessary for the performance of a task carried out in the exercise of official authority vested in the controller. The right referred to in point 1 shall not adversely affect the rights and freedoms of others.

    (Article 20 of the Regulation)

    The right to protest

    The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her based on point (e) of Article 6(1) of the Regulation (processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller) or point (f) of Article 6(1) of the Regulation (processing is necessary for the exercise of the legitimate interests of the Controller or of a third party), including profiling based on those provisions. In such a case, the Controller shall no longer process the personal data unless the Controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims. Where the processing of personal data is carried out for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such purposes, including profiling, where it is related to direct marketing. If the data subject objects to the processing of personal data for direct marketing purposes, the personal data shall no longer be processed for these purposes. The right referred to in points 1 and 2 shall be expressly brought to the data subject's attention at the latest when the data subject is first contacted and the information on this shall be displayed clearly and separately from all other information. In connection with the use of information society services and by way of derogation from Directive 2002/58/EC, the data subject may also exercise the right to object by automated means based on technical specifications. Where personal data are processed for scientific and historical research purposes or for statistical purposes in accordance with Article 89(1) of the Regulation, the data subject shall have the right to object, on grounds relating to his or her particular situation, to processing of personal data concerning him or her, unless the processing is necessary for the performance of a task carried out for reasons of public interest.

    (Article 21 of the Regulation)

    Automated decision-making in individual cases, including profiling

    The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her. Point 1 shall not apply where the decision:

    • a) necessary for the conclusion or performance of a contract between the data subject and the Data Controller;
    • b) it is permitted by Union or Member State law applicable to the Controller, which also lays down suitable measures to safeguard the rights and freedoms and legitimate interests of the data subject; or
    • c) based on the explicit consent of the data subject

    In the cases referred to in points (a) and (c) of point 2, the Controller shall implement suitable measures to safeguard the rights, freedoms and legitimate interests of the data subject, including at least the right of the data subject to obtain human intervention on the part of the Controller, to express his or her point of view and to object to the decision. The decisions referred to in point 2 shall not be based on special categories of personal data referred to in Article 9(1) of the Regulation, unless point (a) or (g) of Article 9(2) applies and suitable measures are taken to safeguard the rights, freedoms and legitimate interests of the data subject.

    (Article 22 of the Regulation)

    Restrictions

    Union or Member State law applicable to the controller or processor may, by means of legislative measures, restrict the scope of the rights and obligations set out in Article 5 of the Regulation in respect of the provisions set out in Articles 12 22 and 34 and in accordance with the rights and obligations set out in Articles 12 to 22, provided that the restriction respects the essence of the fundamental rights and freedoms and is a necessary and proportionate measure in a democratic society to protect:

    • a) national security;
    • b) national defense;
    • (c) public safety;
    • (d) the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security;
    • (e) other important objectives of general public interest of the Union or of a Member State, in particular the important economic or financial interests of the Union or of a Member State, including monetary, budgetary and taxation matters, public health and social security;
    • (f) the protection of judicial independence and judicial proceedings;
    • g) in the case of regulated professions, the prevention, investigation, detection and conduct of proceedings related to ethical violations;
    • h) in the cases referred to in points a)–e) and g) – even occasionally – control, investigation or regulatory activities related to the performance of public authority tasks;
    • (i) the protection of the data subject or the rights and freedoms of others;
    • j) enforcement of civil claims.
    • (k) The legislative measures referred to in point 1 shall, where appropriate, contain detailed provisions on at least:
    • l) the purposes of data processing or the categories of data processing,
    • m) categories of personal data,
    • n) the scope of the restrictions introduced,
    • o) guarantees aimed at preventing misuse or unauthorized access or transmission,
    • p) to define the Data Controller or to define the categories of Data Controllers,
    • q) the duration of data storage and the applicable safeguards, taking into account the nature, scope and purposes of the data processing or categories of data processing,
    • r) the risks to the rights and freedoms of data subjects, and
    • s) the right of data subjects to be informed about the restriction, unless this may adversely affect the purpose of the restriction.

    (Article 23 of the Regulation)

    Informing the data subject about the data protection incident

    Where the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Controller shall inform the data subject of the personal data breach without undue delay. The information provided to the data subject referred to in point 1 shall describe the nature of the personal data breach in a clear and intelligible manner and shall include at least the information and measures referred to in points (b), (c) and (d) of Article 33(3) of the Regulation. The data subject shall not be required to be informed as referred to in point 1 if any of the following conditions are met:

    a) the Data Controller has implemented appropriate technical and organizational protection measures and these measures have been applied to the data affected by the data protection incident, in particular measures – such as the use of encryption – that make the data unintelligible to persons not authorized to access the personal data;

    b) the Data Controller has taken additional measures following the data protection incident to ensure that the high risk to the rights and freedoms of the data subject referred to in point 1 is no longer likely to materialise;

    (c) the provision of information would involve a disproportionate effort. In such cases, the data subjects shall be informed by means of publicly available information or a similar measure shall be taken which ensures that the data subjects are informed in a similarly effective manner.

    If the Data Controller has not yet notified the data subject of the data breach, the supervisory authority, after considering whether the data breach is likely to involve a high risk, may order the data subject to be informed or may determine that one of the conditions referred to in point 3 is met.

    (Article 34 of the Regulation)

    Right to lodge a complaint with a supervisory authority

    Without prejudice to other administrative or judicial remedies, each data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement, if the data subject considers that the processing of personal data concerning him or her infringes this Regulation. The supervisory authority to which the complaint has been lodged shall inform the customer of the progress of the procedure relating to the complaint and its outcome, including the fact that the customer has the right to a judicial remedy pursuant to Article 78 of the Regulation.

    (Article 77 of the Regulation)

    Right to an effective judicial remedy against the supervisory authority

    Without prejudice to other administrative or non-judicial remedies, every natural or legal person shall have the right to an effective judicial remedy against a legally binding decision of a supervisory authority concerning him or her. Without prejudice to other administrative or non-judicial remedies, every data subject shall have the right to an effective judicial remedy where the supervisory authority competent under Article 55 or 56 of the Regulation does not deal with a complaint or does not inform the data subject within three months of the progress of the procedure or the outcome of a complaint lodged under Article 77. Proceedings against a supervisory authority shall be brought before the courts of the Member State in which the supervisory authority is established. Where proceedings are brought against a decision of a supervisory authority on which the Board has previously issued an opinion or taken a decision under the consistency mechanism, the supervisory authority shall be obliged to send that opinion or decision to the court.

    (Article 78 of the Regulation)

    Right to an effective judicial remedy against the controller or processor

    Without prejudice to any available administrative or non-judicial remedies, including the right to lodge a complaint with a supervisory authority pursuant to Article 77 of the Regulation, each data subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of personal data concerning him or her not being in accordance with this Regulation. Proceedings against a controller or processor shall be brought before the courts of the Member State in which the controller or processor is established. Such proceedings may also be brought before the courts of the Member State in which the data subject has his or her habitual residence, unless the controller or processor is a public authority of a Member State acting in its official capacity.

    (Article 79 of the Regulation)

    CHAPTER VIII

    SUBMISSION OF THE DATA SUBJECT'S REQUEST, MEASURES OF THE DATA CONTROLLER

    The Controller shall inform the data subject without undue delay, but in any case within one month of receipt of the request, of the measures taken in response to the request to exercise his or her rights. If necessary, taking into account the complexity of the request and the number of requests, this deadline may be extended by a further two months. The Controller shall inform the data subject of the extension of the deadline, indicating the reasons for the delay, within one month of receipt of the request. If the data subject submitted the request electronically, the information shall be provided electronically, if possible, unless the data subject requests otherwise. If the Data Controller does not take action in response to the data subject's request, it shall inform the data subject without undue delay, but at the latest within one month of receipt of the request, of the reasons for not taking action and of the fact that the data subject may lodge a complaint with a supervisory authority and exercise his or her right to a judicial remedy. The Data Controller shall provide the information pursuant to Articles 13 and 14 of the Regulation and the information on the data subject's rights (Articles 15-22 and 34 of the Regulation) and the action taken free of charge. If the data subject's request is manifestly unfounded or excessive, in particular because of its repetitive nature, the Data Controller shall, taking into account the administrative costs involved in providing the requested information or communication or in taking the requested action:

    a) may charge a fee of HUF 6,350, or

    b) may refuse to take action on the request.

    The Data Controller shall bear the burden of proving that the request is clearly unfounded or excessive.

    If the Data Controller has reasonable doubts regarding the identity of the natural person submitting the request, it may request the provision of additional information necessary to confirm the identity of the data subject.

    Válassz keretszínt!