Last updated:

saghysat.hu for visitors and registered users of the website

Download

Application of the Privacy Policy

Name of the organization: Sághy-Sat Kft
Registered office: 7754 Bóly, Ady Endre u. 9
Person responsible for the policy content: Ferenc Sághy
Effective date of the policy: 25.05.2018

This regulation establishes rules regarding the protection of natural persons with regard to the processing of personal data and the free movement of personal data. The provisions of this policy must be applied during specific data processing activities, as well as when issuing instructions and notices regulating data processing.

The obligation to employ (appoint) a Data Protection Officer applies to all public authorities or other bodies performing public duties (regardless of what data they process), as well as other organizations whose core activities involve the systematic, large-scale monitoring of individuals, or which process special categories of personal data on a large scale.

The organization employs a Data Protection Officer.

In the case of employing a Data Protection Officer:

Name: Ferenc Sághy
Position: Managing Director
Contact information: 69-368-162

Scope of the Policy

This policy remains valid until revoked; its scope extends to the organization's officers, employees, and the organization's Data Protection Officer.

Date: Bóly, 23.05.2018

Purpose of the Policy

The purpose of this policy is to harmonize the provisions of the organization's other internal regulations regarding data processing activities in order to protect the fundamental rights and freedoms of natural persons, and to ensure the proper processing of personal data.

In its activities, the organization intends to fully comply with the legal requirements for the processing of personal data, in particular the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council.

Furthermore, an important purpose of issuing this policy is that by understanding and complying with it, the organization's employees will be able to process the data of natural persons lawfully.

Key Terms and Definitions

GDPR (General Data Protection Regulation) is the new Data Protection Regulation of the European Union.

Data Controller: the natural or legal person, public authority, agency, or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;

Data Processing / Processing: any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction;

Data Processor: a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller;

Personal Data: any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person;

Third Party: a natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data;

Consent of the Data Subject: any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;

Restriction of Processing: the marking of stored personal data with the aim of limiting their processing in the future;

Pseudonymisation: the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person;

Filing System: any structured set of personal data which are accessible according to specific criteria, whether centralized, decentralized, or dispersed on a functional or geographical basis;

Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed;

Principles of Data Processing

Personal data must be processed lawfully, fairly, and in a transparent manner in relation to the data subject.

Personal data must be collected only for specified, explicit, and legitimate purposes.

The purpose of processing personal data must be adequate, relevant, and limited to what is necessary.

Personal data must be accurate and up to date. Inaccurate personal data must be erased without delay.

Personal data must be kept in a form which permits identification of data subjects for no longer than is necessary. Storage of personal data for longer periods may only occur if the data is stored solely for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes.

Personal data must be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures.

The principles of data protection must be applied to all information concerning an identified or identifiable natural person.

The organization's employee performing data processing carries disciplinary, financial, administrative, and criminal liability for the lawful handling of personal data. If the employee becomes aware that the personal data handled by them is incorrect, incomplete, or outdated, they are obliged to correct it or initiate its correction with the colleague responsible for data entry.

Processing of Personal Data

Since natural persons may be associated with online identifiers provided by their devices, applications, tools, and protocols, such as IP addresses and cookie identifiers, this data, when combined with other information, can be used to create profiles of natural persons and identify them.

Data processing may only take place if the data subject gives their voluntary, specific, informed, and unambiguous consent through a clear affirmative action, such as a written statement – including by electronic means – or an oral statement.

Consent to data processing is also constituted if the data subject ticks a relevant box while viewing the website. Silence, pre-ticked boxes, or inactivity do not constitute consent.

Consent is also constituted if a user makes relevant technical settings while using electronic services, or makes a statement or action that clearly indicates the data subject's consent to the processing of their personal data in that context.

Data concerning health includes personal data related to the physical or mental health of a data subject, which reveal information about their past, current, or future physical or mental health status. This includes the following:

  • registration for the purpose of health care services;
  • a number, symbol, or data assigned to a natural person to uniquely identify them for health purposes;
  • information derived from the testing or examination of a body part or bodily substance, including genetic data and biological samples;
  • information concerning a disease, disability, disease risk, medical history, clinical treatment, or the physiological or biomedical state of the data subject, regardless of its source, such as a physician or other health professional, a hospital, a medical device, or an in vitro diagnostic test.

Genetic data should be defined as personal data relating to the inherited or acquired genetic characteristics of a natural person, which result from the analysis of a biological sample from the natural person in question, in particular chromosomal analysis, or evaluation of deoxyribonucleic acid (DNA) or ribonucleic acid (RNA), or the examination of any other element enabling equivalent information to be obtained.

Children's personal data merit specific protection, as they may be less aware of the risks, consequences, and safeguards concerned, as well as their rights in relation to the processing of personal data. Such specific protection should apply in particular to the use of personal data of children for marketing purposes or for creating personality or user profiles.

Personal data must be processed in a manner that ensures an appropriate level of security and confidentiality, including for preventing unauthorized access to or use of personal data and the equipment used for the processing.

Every reasonable step must be taken to ensure that personal data that are inaccurate are rectified or deleted.

Lawfulness of Processing

Processing of personal data is lawful only if at least one of the following applies:

  • the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
  • processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
  • processing is necessary for compliance with a legal obligation to which the controller is subject;
  • processing is necessary in order to protect the vital interests of the data subject or of another natural person;
  • processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  • processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

In accordance with the above, data processing is considered lawful if it is necessary within the framework of a contract or an intention to enter into a contract.

If processing is carried out in compliance with a legal obligation to which the controller is subject, or if it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, the processing must have a legal basis in Union or Member State law.

Processing should be considered lawful where it is necessary to protect an interest which is essential for the life of the data subject or that of another natural person. Processing of personal data based on the vital interests of another natural person should in principle take place only where the processing cannot be manifestly based on another legal basis.

Some types of processing may serve both important grounds of public interest and the vital interests of the data subject as, for instance, when processing is necessary for humanitarian purposes, including monitoring epidemics and their spread, or in humanitarian emergencies, in particular in situations of natural and man-made disasters.

The legitimate interests of a controller, including those of a controller to which the personal data may be disclosed, or of a third party, may provide a legal basis for processing. Such legitimate interest could exist, for example, when there is a relevant and appropriate relationship between the data subject and the controller, such as situations where the data subject is a client or in the service of the controller.

The processing of personal data strictly necessary for the purposes of preventing fraud also constitutes a legitimate interest of the data controller concerned. The processing of personal data for direct marketing purposes may also be regarded as carried out for a legitimate interest.

To establish the existence of a legitimate interest, it must be carefully assessed, among other things, whether a data subject can reasonably expect at the time and in the context of the collection of the personal data that processing for that purpose may take place. The interests and fundamental rights of the data subject could override the interest of the data controller if personal data are processed in circumstances where data subjects do not reasonably expect further processing.

The processing of personal data to the extent strictly necessary and proportionate for the purpose of ensuring network and information security by public authorities, computer emergency response teams, network security incident response teams, operators of electronic communications networks and providers of services, as well as providers of security technologies, constitutes a legitimate interest of the data controller concerned.

The processing of personal data for purposes other than those for which the personal data were initially collected should be allowed only where the processing is compatible with the purposes for which the personal data were initially collected. In this case, no separate legal basis other than that which allowed the collection of the personal data is required.

The processing of personal data by authorities for the purpose of achieving the constitutional or international public law objectives of officially recognized religious organizations is considered to be based on public interest.

Consent of the Data Subject, Conditions

Where processing is based on consent, the controller must be able to demonstrate that the data subject has consented to the processing of his or her personal data.

If the data subject's consent is given in the context of a written declaration which also concerns other matters, the request for consent must be presented in a manner which is clearly distinguishable from the other matters.

The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent.

When assessing whether consent is freely given, utmost account shall be taken of the fact, among others, whether the performance of a contract, including the provision of services, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.

In relation to the offer of information society services directly to a child, the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorized by the holder of parental responsibility over the child.

Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited, unless the data subject has given explicit consent to the processing of those personal data for one or more specified purposes.

Processing of personal data relating to criminal convictions and offenses or related security measures shall be carried out only under the control of official authority.

Processing Not Requiring Identification

If the purposes for which a controller processes personal data do not or do no longer require the identification of a data subject by the controller, the controller shall not be obliged to maintain additional information.

Where the controller can demonstrate that it is not in a position to identify the data subject, the controller shall inform the data subject accordingly, if possible.

Information and Rights of the Data Subject

The principle of fair and transparent processing requires that the data subject be informed of the existence of the processing operation and its purposes.

Where personal data are collected from the data subject, the data subject must also be informed whether they are obliged to provide the personal data and of the consequences of failure to provide such data. This information may be supplemented with standardized icons in order to provide a highly visible, easily intelligible, and clearly legible general overview of the intended processing.

The information relating to the processing of personal data relating to the data subject must be provided to the data subject at the time when personal data are obtained, or, where the data are not obtained from the data subject but from another source, within a reasonable period, taking into account the circumstances of the case.

A data subject should have the right of access to personal data which have been collected concerning him or her, and to exercise that right easily and at reasonable intervals, in order to be aware of, and verify, the lawfulness of the processing. Every data subject should have the right to know in particular the purposes for which the personal data are processed, and, where possible, the period for which the personal data are processed.

A data subject should have the right to have personal data concerning him or her rectified and a 'right to be forgotten' where the retention of such data infringes this Regulation or Union or Member State law to which the controller is subject, or where data subjects have withdrawn their consent to processing.

Where personal data are processed for the purposes of direct marketing, the data subject should have the right to object at any time and free of charge to processing of personal data concerning him or her for such marketing.

Review of Personal Data

In order to ensure that personal data are not kept longer than necessary, time limits should be established by the controller for erasure or for a periodic review.

The periodic review period established by the head of the organization: 1 year.

Tasks of the Data Controller

The controller implements appropriate internal data protection policies to ensure lawful processing. This regulation covers the controller's scope of authority and responsibility.

The controller is obliged to implement appropriate and effective measures and be able to demonstrate that data processing activities comply with applicable laws.

This regulation must be adopted taking into account the nature, scope, context, and purposes of processing as well as the risks to the rights and freedoms of natural persons.

Taking into account the nature, scope, context, and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organizational measures. Based on this policy, it reviews other internal policies and updates them if necessary.

The controller or the processor maintains an appropriate record of processing activities under its responsibility. Each controller and processor is obliged to cooperate with the supervisory authority and make these records available on request for monitoring those processing operations.

Rights Related to Data Processing

Right to Request Information

Any person may request information through the provided contact details regarding what data the organization processes about them, on what legal basis, for what data processing purpose, from what source, and for how long. Upon request, information must be sent to the specified contact details without delay, but no later than within 30 days.

Right to Rectification

Any person may request the modification of any of their data through the provided contact details. Upon request, this must be acted upon without delay, but no later than within 30 days, and information must be sent to the specified contact details.

Right to Erasure

Any person may request the deletion of their data through the provided contact details. Upon request, this must be done without delay, but no later than within 30 days, and information must be sent to the specified contact details.

Right to Restriction / Blocking

Any person may request the blocking of their data through the provided contact details. The blocking lasts as long as the stated reason makes the storage of data necessary. Upon request, this must be done without delay, but no later than within 30 days, and information must be sent to the specified contact details.

Right to Object

Any person may object to data processing through the provided contact details. The objection must be examined within the shortest possible time from the submission of the request, but no later than within 15 days, a decision must be made regarding its validity, and information about the decision must be sent to the specified contact details.

Enforcement Possibilities Related to Data Processing

National Authority for Data Protection and Freedom of Information

Postal address: 1530 Budapest, Pf.: 5.
Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
Telephone: +36 (1) 391-1400
Fax: +36 (1) 391-1410
E-mail: ugyfelszolgalat@naih.hu
URL: https://naih.hu
Coordinates: N 47°30'56''; E 18°59'57''

In the event of a breach of their rights, the data subject may turn to a court against the controller. The court acts out of turn in the matter. The lawsuit may also be brought before the tribunal competent according to the data subject's place of residence or stay, at the choice of the data subject.

Tasks of the Organization for Appropriate Data Protection

Data protection awareness. Professional preparedness must be ensured to comply with the laws. Professional training of staff and familiarity with the policy are essential.

The purpose, criteria system, and concept of personal data processing must be reviewed. Lawful data processing and data handling must be ensured in accordance with the data protection and data processing rules.

Appropriate information for the person concerned by data processing. Attention must be paid to the fact that – if the data processing is based on the data subject's consent – in case of doubt, the controller must prove that the data subject's consent to the data processing was obtained.

The information provided to the data subject should be concise, easily accessible, and easy to understand, therefore it must be formulated and displayed in clear and plain language.

The requirement of transparent data processing is that the data subject receives information about the fact and purposes of data processing. Information must be considered and given before the start of data processing, and the right to information belongs to the data subject during data processing until its termination.

The main rights of the person concerned by data processing are as follows:

  • access to personal data concerning him or her;
  • rectification of personal data;
  • erasure of personal data;
  • restriction of processing of personal data;
  • objection to profiling and automated data processing;
  • the right to data portability.

The controller informs the data subject without undue delay, but at the latest within one month from the receipt of the request. If necessary, taking into account the complexity of the request and the number of requests, this deadline can be extended by a further two months. The obligation to provide information can be ensured by operating a secure online system through which the data subject can easily and quickly access the necessary information.

The data processing carried out by the organization must be reviewed, and the exercise of the right to informational self-determination must be ensured. At the request of the data subject, their data must be deleted without delay if the data subject withdraws the consent forming the basis of the data processing.

It must be unmistakably clear from the data subject's consent that the data subject agrees to the processing. If the data processing is based on the data subject's consent, in case of doubt, the controller must prove that the data subject consented to the data processing operation.

In the case of processing children's personal data, special attention must be paid to compliance with data processing rules. Processing of personal data in relation to the offer of information society services directly to a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorized by the holder of parental responsibility over the child.

In the event of unlawful handling or processing of personal data, a notification obligation arises towards the supervisory authority. The controller must notify the supervisory authority without undue delay – and, if possible, no later than 72 hours after having become aware of it – unless the personal data breach is unlikely to result in a risk to the rights of natural persons.

In certain cases, it may be justified for the controller to carry out a data protection impact assessment prior to data processing. During the impact assessment, it must be examined how the intended processing operations affect the protection of personal data. If a data protection impact assessment indicates that the processing would result in a high risk, the controller must consult the supervisory authority prior to processing.

In the event that the core activities consist of processing operations which, by their nature, scope, or purposes, require regular and systematic monitoring of data subjects on a large scale, a Data Protection Officer must be designated. The appointment of a Data Protection Officer aims to strengthen data security.

Data Security

Data must be protected by appropriate measures, particularly against unauthorized access, alteration, transmission, public disclosure, erasure or destruction, as well as accidental destruction and damage, and becoming inaccessible due to changes in the technology used.

In order to protect data files handled electronically in records, it must be ensured by an appropriate technical solution that data stored in records cannot be directly combined and attributed to the data subject.

When designing and applying data security, the current state of technology must be taken into account. Among several possible data processing solutions, the one providing a higher level of protection for personal data must be chosen, unless it would represent a disproportionate difficulty for the controller.

Data Protection Officer

The designation of a Data Protection Officer is mandatory based on the following criteria:

  • the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;
  • the core activities of the controller or the processor consist of processing operations which, by their nature, their scope, or their purposes, require regular and systematic monitoring of data subjects on a large scale;
  • the core activities of the controller or the processor consist of processing on a large scale of special categories of data and personal data relating to criminal convictions and offenses.

Where the designation of a Data Protection Officer is mandatory, the following rules apply:

The data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfill the tasks.

The data protection officer may be a staff member of the controller or processor, or fulfill the tasks on the basis of a service contract.

The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority.

Position of the Data Protection Officer

The controller shall ensure that the data protection officer is involved, properly and in a timely manner, in all issues which relate to the protection of personal data. It must be ensured that the resources necessary to maintain their expert knowledge are available.

The data protection officer shall not receive any instructions regarding the exercise of those tasks. He or she shall not be dismissed or penalized by the controller or the processor for performing his tasks. The data protection officer shall directly report to the highest management level of the controller or the processor.

Data subjects may contact the data protection officer with regard to all issues related to processing of their personal data and to the exercise of their rights.

The data protection officer shall be bound by secrecy or confidentiality concerns the performance of his or her tasks.

The data protection officer may fulfill other tasks and duties, provided that no conflict of interests arises.

Tasks of the Data Protection Officer

  • To inform and advise the controller or the processor and the employees who carry out processing;
  • to monitor compliance with this Regulation and with the internal policies of the controller or processor in relation to the protection of personal data;
  • to provide advice where requested as regards the data protection impact assessment and monitor its performance;
  • to cooperate with the supervisory authority.

Personal Data Breach

A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.

A personal data breach may, if not addressed in an appropriate and timely manner, result in physical, material, or non-material damage to natural persons such as loss of control over their personal data or limitation of their rights, discrimination, identity theft or fraud.

The personal data breach shall be notified to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.

The data subject shall be informed without undue delay if the personal data breach is likely to result in a high risk to the rights and freedoms of the natural person, in order to allow him or her to take the necessary precautions.

Processing for Administrative and Record-Keeping Purposes

The organization may also process personal data in cases belonging to its activities and for administrative and record-keeping purposes.

The basis for data processing is voluntary and definite consent based on appropriate information of the data subject. After detailed information – covering the purpose, legal basis, and duration of data processing as well as the rights of the data subject – the data subject must be warned about the voluntary nature of data processing. Consent to data processing must be recorded in writing.

Data processing for administrative and record-keeping purposes serves the following objectives:

  • processing of data of members and employees of the organization, which is based on a legal obligation;
  • processing of data of persons in an agency/contractual relationship with the organization for contact, settlement, and record-keeping purposes;
  • contact data of other organizations, institutions, and businesses in a business relationship with the organization, which may also be contact and identification data of natural persons.

Data processing according to the above is based on a legal obligation on the one hand, and on the other hand, the data subject has explicitly consented to the processing of their data (for example, for the purpose of an employment contract or registered as a partner on the website, etc.).

In the case of documents sent to the organization in written form – containing personal data – (for example, resume, job application, other submission, etc.), the consent of the data subject must be presumed. After the case is closed – in the absence of consent for further use – the documents must be destroyed. The fact of destruction must be recorded in a minutes.

In the case of data processing for administrative purposes, personal data appear exclusively in the documents and records of the given case. The processing of this data lasts until the discarding of the document forming the basis of the processing.

Data processing for administrative and record-keeping purposes – in order to ensure that the storage of personal data is limited to the necessary period – must be reviewed annually, and inaccurate personal data must be deleted without delay.

Compliance with the laws must also be ensured in the case of data processing for administrative and record-keeping purposes.

Data Processing for Other Purposes

If the organization intends to carry out data processing that is not included in this regulation, it must supplement its internal regulation accordingly in advance, or attach sub-rules corresponding to the new data processing purpose.

Other Documents Belonging to the Regulation

Documents and rules that contain, for example, the written statement consenting to data processing or, for example, in the case of websites, describe the mandatory data processing notice, must be linked to the data protection and data processing rules and handled together with them.

Legislation Forming the Basis of Data Processing

  • REGULATION (EU) 2016/679 OF THE EUROPEAN PARLAMENT AND OF THE COUNCIL (27 April 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
  • Act CXII of 2011 on the Right to Informational Self-Determination and on Freedom of Information.
  • Act LXVI of 1995 on Public Records, Public Archives, and the Protection of Private Archive Material.
  • Gov. Decree 335/2005 (XII. 29.) on the General Requirements for Document Management by Organs Performing Public Duties.
  • Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services.
  • Act C of 2003 on Electronic Communications.
The foreign language translation was performed with the help of artificial intelligence.