I.
Basic provisions
1. The subject of this Directive is the regulation of the protection and handling of personal data in activities carried out by authorised persons of the employer, which is the company ELLMAN, s.r.o., Muškátová 732/23,
Lozorno 900 55, IČO: 35 949 309 (hereinafter the “Controller”).
2. For the purposes of this Directive, an authorised person means an employee of the Controller who handles the personal data of data subjects in the course of their work (hereinafter the “Authorised Person”).
II.
General obligations
1. Personal data must be adequately secured in all cases in which it is handled within the organisation.
2. An authorised person may handle personal data only if this is necessary for the performance of their work or on the basis of an individual written authorisation from the Controller.
3. An authorised person is obliged to maintain confidentiality about the personal data they come into contact with in the course of their work or activities arising from their authorisation.
4. The duty of confidentiality continues even after the termination of the authorised person’s employment.
5. An authorised person may handle only such personal data as is necessary for the performance of their work or activities arising from their authorisation.
6. An authorised person may carry out only those operations with personal data that are necessary for the performance of their work or activities arising from their authorisation.
7. An authorised person must not obtain information relating to personal data beyond the scope of their work or authorisation.
8. An authorised person is obliged to ensure that no leak of the personal data processed and no breach of the security of processing operations occurs in the course of their work or activities arising from their authorisation.
9. It is prohibited to state the birth number (personal identification number) in contracts concluded with a natural person.
10. It is prohibited to publish photographs and other activities from work on private social media profiles.
11. An authorised person is obliged to save photographs taken on private devices to the Controller’s device designated for this purpose and to remove (delete) them from their private device without delay.
III.
Obtaining personal data
1. The Controller’s personal data is stored and backed up in its own database with external storage.
2. An authorised person accesses the database through individual software available on every company computer of the Controller.
3. Each authorised person has their own user name and password required to access the Controller’s software, and the database provides them only with the personal data of data subjects within the scope of their work or authorisation.
4. If an authorised person needs access to personal data to a greater extent than is available to them in the database, they are obliged to request individual written consent from the Controller to obtain such data on the basis of a request.
5. The Controller grants written consent upon request, and only to the extent necessary to fulfil the purpose of the authorised person.
6. The authorised person then submits the written consent to the head of the IT department, who provides them with personal data only within the scope of the consent granted by the Controller.
7. An authorised person must not provide the personal data obtained to other persons.
8. An authorised person must not provide their access credentials for the Controller’s software to other persons.
9. An authorised person must not use the Controller’s software for their own purposes.
IV.
Use of the internet
1. The use of internet services by authorised persons is intended for the performance of work tasks.
2. The use of the internet must take into account the confidentiality of the information transmitted.
3. When accessing the internet, an authorised person is obliged to observe the following principles:
a. use internet access primarily in accordance with their job description/function,
b. follow the alerts of the antivirus program,
c. not connect to unknown websites with unverified content unless this is necessary for the performance of work tasks/functions,
d. not use passwords that are used to access internal information systems to access public internet services.
V.
Electronic mail
- Electronic mail is used for internal and external communication.
- An authorised person is obliged to send bulk e-mails using hidden e-mail addresses (blind copy) so that individual recipients do not become aware of the e-mail addresses of the other data subjects – recipients.
- It is prohibited to send the personal data of data subjects in unprotected e-mails or in an unprotected attachment. Attachments must be password-protected. The password must be sent through a different communication channel, e.g. by SMS or by telephone. If this is not possible, the password must be sent in a separate e-mail.
- If the employment or other relationship with an authorised person ends, the Controller shall terminate the use of that authorised person’s e-mail address within 30 days of the end of the relationship.
VI.
Personnel security
- When an employment or other relationship ends (e.g. the end of the function of an executive director), the authorised person (employee, executive director, etc.) is obliged to hand over their work agenda, including files, all assigned inventory items, borrowed books and keys.
- All authorised persons must be instructed in the basic security principles before they gain access to the Controller’s information system and the purposes of processing. The instruction is given by the responsible person. Proof of the instruction is kept in the employee’s personal file.
- An authorised person may be assigned a technical device (e.g. a work mobile phone or laptop), the receipt of which the authorised person confirms on a confirmation of receipt of the device. When returning the device, the authorised person has the right to request a confirmation of its return.
VII.
Physical security
1. Information technology (computers, laptops, etc.) must be located in lockable premises. The room in which the information technology is located must be locked every time the authorised person leaves. After finishing work, the authorised person is obliged to:
a. switch off the personal computer or log out of it,
b. lock cabinets containing materials with personal data (if the cabinets are lockable).
VIII.
Management of keys and access cards
- On taking up employment/office, an authorised person is assigned one key to the door of the
room in which they will perform their work/function.
2. An authorised person is obliged to report any loss of an office key by e-mail without delay
to their superior and to the responsible person.
3. The person to whom the keys were assigned is responsible for them. An authorised person is obliged to
hand these keys over to their superior when their employment or other relationship ends.
IX.
Other measures
1. Every time an authorised person (employee, executive director) leaves a room in which no other authorised person remains, they are obliged to lock the room and take the key with them.
2. Before leaving the room, an authorised person is obliged to check that the windows in their room are closed.
3. An authorised person must not change the settings of the antivirus program or switch off the resident antivirus program without the consent of the head of the IT department.
4. An authorised person is obliged to report any suspicious or unusual behaviour of the computer, or any malfunction, to the head of the IT department immediately.
5. An authorised person must not install computer programs on their own initiative, whether from storage media or from the internet. They may install programs only with the consent of their superior after prior consultation with the head of the IT department.
6. Each authorised person must be assigned a password with which they authenticate themselves and which they keep secret. An authorised person must not disclose the password with which they authenticate themselves. The password must not be written down and kept in a visible or easily accessible place. An authorised person is responsible for the unauthorised disclosure of their password to another person and, consequently, for its misuse and any damage caused.
7. An authorised person must not allow an unauthorised person to work with the computer.
8. If several persons work on one computer, an authorised person must log in with their own user name and password after the authorised person who previously worked on that computer has logged out.
X.
Security breach
1. If a personal data security breach occurs, the authorised person is obliged to inform their superior and the head of the IT department of this fact without delay.
2. The authorised person is obliged to interrupt their activity and must not perform any actions that could increase the risk to the security of personal data.
3. The authorised person is obliged to draw up a record stating all details, including:
a. which personal data is concerned,
b. when they learned of the security breach,
c. what security breach occurred,
d. how they learned of the breach,
e. what steps they took.
4. The authorised person hands the record over to the head of the IT department.
5. The head of the IT department notifies the Controller of the nature and extent of the security breach without delay after learning of it.
6. The head of the IT department is obliged to make every effort to prevent any further security breaches in the processing of personal data and to remove the problems that have arisen as quickly as possible.
7. The authorised person may resume their work only after the consent of the head of the IT department, who confirms that the performance of the work does not pose a risk to the security of personal data.
8. The head of the IT department is obliged to draw up a record containing:
a. the type of personal data whose protection was breached,
b. the origin and form of the breach,
c. the extent of the breach and the estimated level of risk,
d. the measures taken to remedy the situation,
e. the measures taken to ensure the security of personal data.
9. The head of the IT department hands over their record and the authorised person’s record to the Controller.
XI.
Processing of submissions from data subjects
1. Requests and objections from data subjects are processed by the person designated to do so (hereinafter the “responsible person”).
2. After receiving a request, objection or complaint from a data subject (hereinafter a “submission”), the responsible person informs the data subject of its receipt and the next steps.
3. The responsible person is obliged to evaluate a data subject’s submission within 30 days of the date of its receipt at the latest.
4. If the evaluation of a submission requires more time, the responsible person is obliged to contact the Controller and to inform the data subjects accordingly.
5. After evaluating the submission, the responsible person is obliged to inform the data subjects properly within the period set out above.
XII.
Working from home
- When working from home, work devices (laptops and desktops) must be used
- If this is not possible, when working from home on one’s own devices, only antivirus programs and cloud solutions recommended by the employer may be used, and automatic updates of the programs used must be enabled.
- When working from home, work must be done with an active VPN (Virtual Private Network) or another secure application approved by the employer.
- It is prohibited to open documents or programs containing personal data or other sensitive data without an active VPN.
- Devices (laptops or desktops) used when working from home must not be left unlocked in the absence of the authorised person (even when leaving the device for a short time, the device must be put into sleep mode).
- When working from home, the approved password system must be observed and the device used for work must be locked during periods of absence.
- Only approved cloud solutions and communication applications may be used for storing documents containing personal data online and for sending documents containing personal data.
- When working from home, do not use private e-mail addresses or telephone numbers (where possible).
- When working from home, it is prohibited to use publicly available means of communication (WhatsApp, Facebook, etc.) to communicate or to send or hand over documents containing personal data.
- It is prohibited to work with devices through which personal data is processed in publicly accessible places, and the general security measures concerning the protection of devices against theft or the copying of their content must be observed (in particular, these devices must not be left unattended in the presence of a stranger or, if they are carried through publicly accessible places, e.g. in the boot of a car).
- In the event of any security incidents, the authorised person is obliged to contact the employer and the responsible person without delay.
XIII.
Common, transitional and final provisions
1. This Directive enters into force on 1 October 2021
2. This Directive is binding on all authorised persons of the Controller.
Lozorno, 1 June 2025
