0% found this document useful (0 votes)
18 views8 pages

Data Protection

The Data Protection/Privacy Policy outlines the company's commitment to data protection and security for all stakeholders, emphasizing the importance of personal rights and privacy in business relationships. It establishes strict guidelines for processing personal data, compliance with national laws, and the responsibilities of employees and management regarding data handling. The policy also details the rights of data subjects, data processing principles, and the procedures for reporting incidents and ensuring compliance.

Uploaded by

yogeshkadolkar
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
18 views8 pages

Data Protection

The Data Protection/Privacy Policy outlines the company's commitment to data protection and security for all stakeholders, emphasizing the importance of personal rights and privacy in business relationships. It establishes strict guidelines for processing personal data, compliance with national laws, and the responsibilities of employees and management regarding data handling. The policy also details the rights of data subjects, data processing principles, and the procedures for reporting incidents and ensuring compliance.

Uploaded by

yogeshkadolkar
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

DATA PROTECTION/PRIVACY POLICY

In the information age, we offer Management Staff, Factory Employees, customers, Suppliers the means to be always
connected everywhere. This requires data to be collected and processed. When storing and transmitting data, we must ensure a
high level of data protection and data security. That goes for information pertaining to our customers, prospects, business partners
and employees because data protection is people protection.
Our top priority is to ensure universally applicable, worldwide standards for handling personal data for us, protecting the personal
rights and privacy of each and every individual is the foundation of trust in our business relationships.
Our Corporate Data Protection Policy lays out strict requirements for processing personal data pertaining to customers, prospects,
business partners and employees. The policy sets a globally applicable data protection and security standard for our company and
regulates the sharing of information. We have established data protection principles among them transparency, data economy and
data security-as our guideline.
1 AIM OF THE DATA PROTECTION POLICY
As part of its social responsibility, we committed to international compliance with data protection laws. Basic principles on data
protection. Ensuring data protection is the foundation of trustworthy business relationships and the reputation of the company as
an attractive employer. The Data Protection Policy provides one of the necessary framework conditions for cross-border data
transmission.
[Link] AND AMENDMENT OF THE DATA PROTECTION POLICY 2
This Data Protection Policy applies to all companies and their employees. The Data Protection Policy
extends to all processing of personal data. This Data Protection Policy applies equally to data of legal
entities. Anonym zed data, e.g. for statistical evaluations or studies, is not subject to this Data Protection
Policy. Additional data protection policies can be created in agreement with the Authorised Person of the
Company, Data Protection only if required by applicable national laws. This Data Protection Policy can be
amended in coordination with the Authorised Person of the Company, Data Protection under the defined
procedure for amending policies Amendments that have a major impact on compliance with the Data Protection Policy must be
reported annually to the data protection authorities that issue approval for this Data Protection Policy as Binding Corporate Rules

3 APPLICATIONS OF NATIONAL LAWS

This Data Protection Policy comprises the internationally accepted data privacy principles without replacing the existing national
laws. It supplements the national data privacy lews. The relevant national law will take precedence in the event that it conflicts
with this Data Protection Policy, or it has stricter requirements than this Policy. The content of this Data Protection Policy must also
be observed in the absence of corresponding national legislations. The reporting requirements for data processing under national
laws must be observed. Each company is responsible for compliance with this Data Protection Policy and the legal obligations. In
the event of conflicts between national legislation and the Data Protection Policy Company will work with the relevant company to
find a practical solution that meets the purpose of the Data Protection Policy.
PRINCIPLES FOR PROCESSING PERSONAL DATA
Fairness and lawfulness when processing personal data, the individual rights of the data subjects must be protected. Personal
data must be collected and processed in a legal and fair manner.
Restriction to a specific purpose Personal data can be processed only for the purpose that was defined before the data was
collected. Subsequent changes to the purpose are only possible to a limited extent and require substantiation.
Transparency The data subject must be informed of how his/her data is being handled. In general, personal data must be
collected directly from the individual concerned. When the data is collected, the data subject must either be aware of, or
informed of
 The identity of the Data Controller.
 The purpose of data processing.
 Third parties or categories of third parties to whom the data might be transmitted.
Data reduction and data economy before processing personal data, you must determine whether and to what extent the
processing of personal data is necessary in order to achieve the purpose for which it is undertaken.
Deletion Personal data that is no longer needed after the expiration of legal or business process-related periods must be
deleted.
Factual accuracy; up-to-datedness of data Personal data on file must be correct, complete, and if necessary, kept up to date.
Suitable steps must be taken to ensure that inaccurate or incomplete data are deleted, corrected, supplemented or updated.
Confidentiality and data security Personal data is subject to data secrecy. It must be treated as confidential on a personal
level and secured with suitable organizational and technical measures to prevent unauthorized access, illegal processing or
distribution, as well as accidental loss, modification or destruction.

5 RELIABLIABILITY OF DATA PROCESSING


Collecting, processing and using personal data is permitted only under the following legal bases. One of these legal bases is
also required if the purpose of collecting, processing and using the personal data is to be changed from the original purpose.
CUSTOMER AND PARTNER DATA
Data processing for a contractual relationship Personal data of the relevant prospects, customers and partners can be
processed in order to establish, execute and terminate a contract. Prior to a contract - during the contract initiation phase -
personal data can be processed to prepare bids or purchase orders or to fulfil other requests of the prospect that relate to
contract conclusion. Prospects can be contacted during the contract. Data processing for advertising purposes if the data
subject contacts a company to request information data processing to meet this request is permitted. Data processing for
advertising purposes if the data subject contacts a company to request information (e.g. request to receive information
material about a product), data processing to meet this request is permitted. Personal data can be processed for advertising
purposes or market and opinion research, provided that this is consistent with the purpose for which the data was originally
collected. The data subject shall be informed that providing data for this purpose is voluntary, it can no longer be used for
these purposes and must be blocked from use for these purposes.
Consent to data processing Data can be processed following consent by the data subject. Before giving consent, the data
subject must be informed in accordance with Data Protection Policy. The declaration of consent must be obtained in writing
or electronically for the purposes of documentation. In some circumstances, such as telephone conversations, consent can
be given verbally. The granting of consent must be documented.
Data processing pursuant to legal authorization. The processing of personal data is also permitted if national legislation
requests, requires or allows this.
Data processing pursuant to legitimate interest Personal data can also be processed if it is necessary for a legitimate interest
of the company.
Processing of highly sensitive data highly sensitive personal data can be processed only if the law requires this or the data
subject has given express consent.
EMPLOYEE DATA
Data processing for the employment relationship in employment relationships, personal data can be processed if needed to
initiate, carry out and terminate the employment agreement. When initiating an employment relationship, the applicants'
personal data can be processed. If the candidate is rejected, his/her data must be deleted. Consent is also needed to use the
data for further application processes or before sharing the application with other Group companies There must be legal
authorization to process personal data that is related to the employment relationship but was not originally part of
performance of the employment agreement. This can include legal requirements, collective regulations with employee
representatives, consent of the employee, or the legitimate interest of the company.
Collective agreements on data processing if a data processing activity exceeds the purposes of fulfilling a contract, it may be
permissible if authorized through a collective agreement. Collective agreements are pay scale agreements or agreements
between employers and employee representatives, within the scope allowed under the relevant employment law. The
agreements must cover the specific purpose of the intended data processing activity, and must be drawn up within the
parameters of national data protection legislation. The declaration of consent must be obtained in writing or electronically
for the purposes of documentation.
Personal data may not be processed based on a legitimate interest if, in individual cases, there is evidence that the interests
of the employee merit protection. Before data is processed, it must be determined whether there are interests that merit
protection.
Control measures that require processing of employee data can be taken only if there is a legal obligation to do so or there is
a legitimate reason.
The legitimate interest of the company and any interests of the employee meriting protection must be identified and
documented before any measures are taken.
Moreover, any additional requirements under national law (eg. rights of co-determination for the employee representatives
and information rights of the data subjects) must be taken into account. Automated decisions of personal data are processed
automatically as part of the employment relationship, and specific personal details are evaluated.
This automatic processing cannot be the sole basis for decisions that would have negative consequences or significant
problems for the affected employee.
The data subject must also be informed of the facts and results of automated individual decisions
and the possibility to respond.
Telecommunications and internet Telephone equipment, e-mail addresses, intranet and internet along with internal social
networks are provided by the company primarily for work-related assignments.
They are a tool and a company resource.
They can be used within the applicable legal regulations and internal company policies.
In the event of authorized use for private purposes, the laws on secrecy of telecommunications and the relevant national
telecommunication laws must be observed if applicable.
TRANSMISSION OF PERSONAL DATA
Transmission of personal data to recipients outside or Inside the company is subject to the authorization requirements for
processing personal data.
The data recipient must be required to use the data only for the defined purposes.
In the event that data is transmitted to a recipient outside the company to a third country.
This country must agree to maintain a data protection level equivalent to this Data Protection Policy.
This does not apply if transmission is based on a legal obligation.
In the alternative, the laws of the domiciliary country of the Group Company can acknowledge the purpose of data
transmission based on the legal obligation of a third country. If data is transmitted by a third party to a company, it must be
ensured that the data can be used for the intended purpose.

CONTRACT DATA PROCESSING


Data processing on Behalf means that a provider is hired to process personal data, without being assigned responsibility for
the related business process.
In these cases, an agreement on Data Processing on Behalf must be concluded with external providers and among companies
within the company.
The client retains full responsibility for correct performance of data processing.
The provider can process personal data only as per the instructions from the client.
When Issuing the order, the following requirements must be complied with, the department placing the order must ensure
that they are met.
The provider must be chosen based on its ability to cover the required technical and
organizational protective measures.
The order must be placed in writing. The instructions on data processing and the responsibilities of the client and provider
must be documented.
Before data processing begins, the client must be confident that the provider will comply with the duties.
A provider can document its compliance with data security requirements in particular by presenting suitable certification.
Depending on the risk of data processing, the reviews must be repeated on a regular basis during the term of the contract
Acknowledgment of binding corporate rules of the provider to create a suitable level of data protection by the responsible
supervisory authorities for data protection.
RIGHTS OF THE DATA SUBJECT

Every data subject has the following rights. Their assertion is to be handled immediately by the responsible unit and cannot
pose any disadvantage to the data subject.
The data subject may request information on which personal data relating to him/her has been stored, how the data was
collected, and for what purpose.
If there are further rights to view the employer's documents (e.g. personnel file) for the employment relationship under the
relevant employment laws, these will remain unaffected.
If personal data is transmitted to third parties, information must be given about the identity of the recipient or the categories
of recipients. If personal data is incorrect or incomplete, the data subject can demand that it be corrected or supplemented.
The data subject can object to the processing of his or her data for purposes of advertising or market/opinion research. The
data must be blocked from these types of use.
The data subject may request his/her data to be deleted if the processing of such data has no legal basis, or if the legal basis
has ceased to apply.
The same applies if the purpose behind the data processing has lapsed or ceased to be applicable for other reasons. Existing
retention periods and conflicting interests meriting protection must be observed.
The data subject generally has a right to object to his/her data being processed, and this must be taken into account if the
protection of his/her interests takes precedence over the interest of the data controller owing to a particular personal
situation.
If a company that has agreed to comply with the Data Protection Policy does not observe the requirements and violates the
party's rights.
CONFIDENTIALLY OF PROCESSING
Personal data is subject to data secrecy. Any unauthorized collection, processing, or use of such data by employees is
prohibited. Any data processing undertaken by an employee that he/she has not been authorized to carry out as part of
his/her legitimate duties is unauthorized.
The "need to know" principle applies. Employees may have access to personal information only as is appropriate for the type
and scope of the task in question. This requires a careful breakdown and separation, as well as implementation, of roles and
responsibilities. Employees are forbidden to use personal data for private or commercial purposes, to disclose it to
unauthorized persons, or to make it available in any other way. Supervisors must inform their employees at the start of the
employment relationship about the obligation to protect data secrecy. This obligation shall remain in force even after
employment has ended.
PROCESSING SECURITY
Personal data must be safeguarded from unauthorized access and unlawful processing or disclosure, as well as accidental
loss, modification or destruction.
This applies regardless of whether data is processed electronically or in paper form.
Before the introduction of new methods of data processing, particularly new IT systems, technical and organizational
measures to protect personal data must be defined and implemented.
These measures must be based on the state of the art, the risks of processing, and the need to protect the data. In particular,
the responsible department can consult with its Information Security Officer and data protection coordinator.
The technical and organizational measures for protecting personal data are part of Corporate Information Security
management and must be adjusted continuously to the technical developments and organizational changes.

DATA PROTECTION CONTROL


Compliance with the Data Protection Policy and the applicable data protection taws is checked regularly with data protection
audits and other controls. The performance of these controls is the responsibility of the Chief Officer Corporate Data
Protection, the data protection coordinators, and other company unite with audit rights or external auditors hired.
On request, the results of data protection controls will be made available to the responsible data protection authority.
The responsible data protection authority can perform its own controls of compliance with the regulations of this Policy, as
permitted under national law

DATA PROTECTION INCIDENTS


All employees must inform their supervisor, data protection coordinator or the Authorised Person Data Protection
immediately about cases of violations against this Data Protection Policy of other regulations on the protection of personal
data. The manager responsible for the function of the unit is required to inform the responsible data protection coordinator
or the Authorised Person Data Protection immediately about data protection incidents. In cases of
 improper transmission of personal data to third parties,
 improper access by third parties to personal data, or
 loss of personal data
the required company reports must be made immediately so that any reporting duties under national law can be complied
with.

RESPONSIBILITIES AND SANCTIONS


The executive bodies of the Group companies are responsible for data processing in their area of responsibility. Therefore,
they are required to ensure that the legal requirements and those contained in the Data Protection Policy, for data protection
are met. measures are in place
Management staff is responsible for ensuring that organizational, HR, and technical measures are in place so that any data
processing is carried out in accordance with data protection.
Compliance with these requirements is the responsibility of the relevant employees.
If official agencies perform data protection controls, the Authorised Person Data Protection must be informed immediately.
The data protection coordinators are the contact persons on site for data protection.
They can perform checks and must familiarize the employees with the content of the data protection policies.
The relevant management is required to assist the Authorised Person Data Protection and the data protection coordinators
with their efforts.
The departments responsible for business processes and projects must inform the data protection coordinators in good time
about new processing of personal data.
For data processing plans that may pose special risks to the individual rights of the data subjects, the
Authorised Person Data Protection must be informed before processing begins.
This applies in particular to extremely sensitive personal data.
The managers must ensure that their employees are sufficiently trained in data protection.
Improper processing of personal data, or other violations of the data protection laws, can be criminally prosecuted in many
countries and result in claims for compensation of damage.
Violations for which individual employees are responsible can lead to sanctions under employment law.
AUTHORISED PERSON DATA PROTECTION

The Authorised Person Data Protection, being internally independent of professional orders, works towards the compliance
with national and international data protection regulations.
He is responsible for the Data Protection Policy, and supervises its compliance.
The Authorised Person Data Protection is appointed by the company that are legally obligated to appoint
data protection officer will appoint the Authorised Person Data Protection.
Specific exceptions have to be agreed upon with the Authorised Person Data Protection.
The data protection coordinators shall promptly inform the Authorised Person Data Protection of any data protection risks.
Any data subject may approach the Authorised Person Data Protection, or the relevant data protection coordinator, at any
time to raise concerns, ask questions, request information or make complaints relating to data protection or data security
issues.
If requested, concerns and complaints will be handled confidentially. Policy for data protection, the Authorised Person Data
Protection must be consulted immediately.
Decisions made by the Authorised Person Data Protection to remedy data protection breaches must be
upheld by the management of the company in question.
Inquiries by supervisory authorities must always be reported to the Authorised Person Data Protection.

DEFINITIONS
Data is anonym zed if personal identity can never be traced by anyone, or if the personal identity could be recreated only
with an unreasonable amount of time, expense and labour.
 Consent is the voluntary, legally binding agreement to data processing.
 Data protection incidents are all events where there is justified suspicion that personal data is being illegally
captured, collected, modified, copied, transmitted or used. This can pertain to actions by third parties or employees.
 Data subject under this Data Protection Policy is any natural person whose data can be processed. In some
countries, legal entities can be data subjects as well.
 Highly sensitive data is data about racial and ethnic origin, political opinions, religious or philosophical beliefs, union
membership or the health and sexual life of the data subject. Under national law, further data categories can be
considered highly sensitive or the content of the data categories can be structured differently.
Moreover, data that relates to a crime can often be processed only under special requirements under national law.
 Personal data is all information about certain or definable natural persons. A person is definable for instance if the
personal relationship can be determined using a combination of information with even incidental additional
knowledge.
 Processing personal data means any process, with or without the use of automated systems, to collect, store,
organize, retain, modify, query, use, forward, transmit, disseminate or combine and compare data. This also includes
disposing of, deleting and blocking data and data storage media.
 Processing personal data is required if the permitted purpose or justified interest could not be achieved without the
personal data, or only with exceptionally high expense.
 Transmission is all disclosure of protected data by the responsible entity to third parties.

You might also like