Privacy Notice - GENERAL DATA PROTECTION POLICY
AIESEC in India
Data Protection Policy
Last Updated: 5th May 2019
1. Introduction
1.1. General Statement
We are required to process relevant personal data regarding members/employees, volunteers, applicants, alumni and customers as part of our operations: thus, we shall take all reasonable steps to do so in accordance with this policy. It is important that personal data is processed lawfully and appropriately, in accordance with the requirements of the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and abiding by the appropriate local/national laws regarding privacy.
Personal data is any information relating to an identified or identifiable individual, such as members/employees, volunteers, applicants, alumni, customers and anyone else with whom we do business. Personal data is an important and valuable asset, and the way we handle this data should demonstrate respect, promote trust and avoid security incidents. In many cases, there are laws that govern how we collect, use and dispose of personal data: for these reasons, we must follow the law and the internal policies/guidelines for handling personal data.
We respect the confidentiality of personal data, in both paper and electronic form: information shall not be used/disclosed improperly and/or used by someone who is not authorised to do so. Furthermore, we are committed to protecting and respecting the privacy of our stakeholders, because we respect the trust that is being placed in us to use personal information appropriately and responsibly: therefore, we have to take our data protection duties seriously.
1.2. About this Policy
This policy and any other documents referred to in it clarify the basis on which we will deal with any personal data we collect and/or process: thus, this policy is applicable to every data processing activity carried out by us. Please note that this policy is not part of the agreement/contract signed by our members/employees, so it can be amended at any time and its provisions shall be respected by all those who participate in our processing activities.
Every director, member/employee, contractor and third party – including the ones related to the local committees – working for or acting on behalf of AIESEC in India, including AIESEC in Ahmedabad, AIESEC in Bangalore, AIESEC in Baroda, AIESEC in Bhubaneswar, AIESEC in Chandigarh, AIESEC in Chennai, AIESEC in Dehradun, AIESEC in Delhi IIT, AIESEC in Delhi University, AIESEC in Hyderabad, IIT ISM Dhanbad, AIESEC in IIT KGP, AIESEC in Indore, AIESEC in Jaipur, AIESEC in Jalandhar, AIESEC in Jodhpur, AIESEC in Kolkata, AIESEC in Ludhiana, AIESEC in M.AH.E, AIESEC in Mumbai, AIESEC in Nagpur, AIESEC in Nashik, AIESEC in Navi Mumbai, AIESEC in NIT Trichy, AIESEC in NMIMS Shirpur, AIESEC in Patiala, AIESEC in Pune, AIESEC in Shillong, AIESEC in South Mumbai, AIESEC in Surat, AIESEC in Visakhapatnam, and AIESEC in VIT must be aware of and follow this policy.
Our Data Protection Officer is responsible for ensuring compliance with the data protection requirements and with this policy (*please refer to point 5., “Data Protection Officer”). Any questions about the operation of this policy and/or any concerns that this policy is not being followed should be referred to the Data Protection Officer.
1.3. Main Definitions
Expressions mentioned in this policy shall have the same meaning provided by the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and the appropriate laws. For basic understanding of this policy, the main concepts are:
- Personal data (whether stored electronically or paper based) means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
- Right to access | You have the right to access your own personal data and the right to receive
relevant information regarding the processing of your personal data. Thus, you can ask us for a
copy of the personal data we hold about you so that you can know if and what kind of personal
data is being processed, why it is being processed and who is processing it, being able to enforce
yourrights. You can contact us so as to exercise this Right.
- Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
- Special categories of personal data is an expression which refers to sensitive categories of personal data, such as the ones regarding a person’s racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, sexual orientation or sexual life. In general, it is forbidden to process sensitive personal data; in case it is processed, conditions must be met. Please note that data about criminal offences or convictions are another “special” category and we do not process such data.
2. Data Processing Principles
Anyone processing personal data must ensure that activities respect the provisions of the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679), ensuring that data is:
- processed lawfully, fairly and in a transparent manner in relation to the data subject;
- processed for specific, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes;
- adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (“data minimisation”);
- accurate and, where necessary, kept up-to-date;
- not kept for longer than necessary for the intended purposes;
- processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
Lastly, we must be able to demonstrate compliance with all the principles mentioned above – and, of course, respect the rights of the data subjects. In this way, we must keep a register of data processing activities, which must be updated periodically and reflect/regulate the way we use personal data.
2.1. Lawfulness, Fairness and Transparency
Processing must be done fairly and without adversely affecting the rights of the individual: thus, in accordance with the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679), we will only process personal data where it is in line with a lawful ground – which, according to the relevant provisions of the Article 6 (1) of such regulation, are:
- the data subject has given consent to the processing of his/her personal data for one or more specific purposes;
- processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
- processing is necessary for compliance with a legal obligation to which the controller is subject;
- processing is necessary in order to protect the vital interests of the data subject or of another natural person;
- processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
Please note that when sensitive personal data is being processed, additional conditions must be met. Furthermore, all processing activities must be recorded in the appropriate register.
2.1.1. Consent
Whenever consent is the lawful basis for processing, it must be:
- recorded, so that we can demonstrate that the data subject has consented to the processing of his/her personal data;
- given in a free, specific, explicit, informed and unambiguous manner. If consent is given in the context of a written declaration which also concerns other matters, the request for consent must be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language;
- easy to be revoked at any time.
If communications (including direct marketing) are sent to individuals based on their consent, the option for the individual to revoke consent must be clearly available and systems should be in place to ensure such revocation is reflected effectively.
2.2. Purpose Limitation
We may collect and process the personal data we receive directly from a data subject (for example, when he/she completes forms and/or sends information via mail, phone or email) and data we receive from other sources (including, for example, location data, business partners, payment/delivery services and others).
We will only process personal data for specific purposes or for any other purposes specifically permitted by the data protection laws. We must notify the purposes to the data subject when we first collect the data (in case data was provided directly to us) or as soon as practicable (where data was received from a third party).
2.2.1. Information to Individuals
Whenever we process personal data relating to an individual, we will inform the data subject about:
- the purpose(s) for which we intend to process that personal data, as well as the legal basis for the processing;
- where we rely upon the legitimate interests of the business to process personal data, the legitimate interests pursued;
- the recipients or categories of recipients of the personal data, if any;
- the fact that we intend to transfer personal data to a country or international organisation outside the European Union/European Economic Area and the appropriate and suitable safeguards in place;
- the existence of each of the rights of the data subject and their respective explanation, paying special attention to:
- the right to request from us (*considering that we are the “data controller”) access to and rectification or erasure of personal data or restriction of processing;
- the right to object to processing and the right to data portability.
- information about the period that the information will be stored or the criteria used to determine that period;
- the right to withdraw consent at any time (if consent was given) without affecting the lawfulness of the processing before the consent was withdrawn. This right must be indicated at the moment the consent of the data subject is requested and/or in the appropriate privacy notice;
- the right to lodge a complaint with the appropriate supervisory authority;
- the existence of automated decision-making (including profiling) and meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the individual;
- our identity and contact details (*considering that we are the “data controller”), of our Data Protection Officer and, where applicable, of our representative.
Data subjects shall also be able to understand how to exercise their rights: in order to comply with these points (from the details regarding information to the enforcement of the rights), we shall have in place a easily accessible privacy notice.
Regarding the deadlines for providing such information, it is important to consider the source of the personal data and remind that:
- if personal data was obtained directly from the individual, we must inform him/her about the points mentioned above at the time when data is obtained. In addition, he/she must also be provided with the following:
- whether the provision of the personal data is a statutory or contractual requirement/obligation, or a requirement necessary to enter into a contract, as well as whether the individual is obliged to provide the personal data and any possible consequences of failing to provide the data.
- if personal data was obtained from other sources, we must provide him/her with this information as soon as practicable, but within one month of obtaining it. The individual must also be provided with:
- the types or categories of personal data which are to be processed;
- the source the personal data originates from and whether it came from publicly accessible sources.
2.3. Data Minimisation
We must process data in an adequate, relevant and non-excessive manner: thus, we will only collect personal data to the extent that it is required for the specific purpose(s) notified to the data subject.
2.4. Accuracy
We will ensure that personal data we hold is accurate and kept up-to-date.
In order to comply with such principle, we will check the accuracy of any personal data at the point of collection and at regular intervals subsequently, taking all reasonable steps to destroy/correct inaccurate or out-of-date data and giving individuals the opportunity to enforce their right to rectify data concerning them.
2.5. Storage Limitation
We will not keep personal data longer than is necessary for the purpose(s) for which it was collected. We will take all reasonable steps to erase/anonymise or archive from our systems all data which is no longer required, following our internal retention policies.
2.6. Integrity and Confidentiality
We must process data in accordance with the rights of the data subjects and in a manner that ensures security, integrity and confidentiality, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical and organisational measures.
Personal data shall not be transferred to people/organisations situated in countries without adequate protection safeguards or in situations which do not meet the appropriate circumstances mentioned in the Articles 44–49 of the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679). Please note that the individual must be informed of the transfer.
2.6.1. Data Security
We will take appropriate security measures against unlawful or unauthorised processing of personal data, and against the accidental or unlawful destruction, damage, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed.
We will put in place technical and organisational measures to maintain the security of all personal data under our responsibility, during the whole flow. In this way, personal data will only be transferred to data processors if they agree to comply with the procedures and policies and/or if they put in place adequate measures.
Our processing activities will be guided by the concepts of confidentiality and integrity of the personal data, as specified below:
- confidentiality, applying measures which guarantee that data is protected against unauthorised or accidental use or disclosure – and, therefore, accessed only by people who are authorised to use the data and who are needed for the achievement of the purposes;
- integrity, applying measures which guarantee that data is protected against unauthorised or accidental loss, destruction or alteration and guaranteeing that it is accurate and suitable for the purpose(s).
Our security procedures include:
- secure offices and workplaces, guaranteeing that the files are stored in buildings which count on appropriate safeguards (such as locks, security systems, etc.) and on furniture which allows extra protection (e.g.: locked drawers, etc). Personal information is always considered confidential and should be kept in a secure place where unauthorised people cannot see it;
- data minimisation, requesting only the appropriate data for our purpose(s);
- internal policies/guidelines which consider the principles/rights in the development of future projects and in the assessment of current practices;
- equipment safety, making regular backups, installing anti-virus softwares in platforms/devices and inserting passwords in every system/platform/device. Furthermore, members/employees must ensure that confidential information is not shown to passers-by and that they log off from systems/platforms/devices whenever they are left unattended;
- usage of modern and secure softwares which are kept-up-to-date;
- review and update of data which is out-of-date, taking every opportunity to ensure data is up-to-date;
- storage of data in as few places as necessary, without creating unnecessary additional data sets;
- methods of disposal, such as shredding papers and/or anonymising/erasing virtual data whenever it must be destroyed;
Our staff should also pay attention to further guidelines:
- the only people able to access the data covered by the policy shall be those who need it for their work and for the achievement of the purpose(s) informed to the data subject;
- data shall not be shared – formally or informally – to individuals outside our organisation except where it is necessary to do so i
Leave a Reply
Be the First to Comment!