Skip to content
Reviewing legal documents

Personal Data Protection Policy

GDPR = General Data Protection Regulation

JANUARY/2024Български

Introduction

Solarpro Technology AD, hereinafter referred to as the Company, has adopted this Personal Data Protection Policy, including the applicable procedures, operational documents, registers and lists, hereinafter collectively referred to as the Policy, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, hereinafter referred to as the Regulation, and the Bulgarian Personal Data Protection Act.

The Policy has been adopted taking into account:

  • the likelihood and severity of the risks to the rights and freedoms of the natural people whose personal data are processed;
  • the necessary and appropriate technical and organisational measures;
  • the state of technological development and the reasonable cost of implementing safeguards, having regard to the nature, scope, context and purposes of the processing of personal data.

The Policy is based on the following principles:

  • lawfulness and fairness in the processing of personal data;
  • transparency – all information must be provided in a concise, comprehensible and easily accessible form, using clear and unambiguous language;
  • purpose limitation – personal data must be collected only for purposes that are genuinely necessary for the Company’s activities;
  • data minimisation – the personal data collected must be limited to what is necessary for the Company’s activities;
  • accuracy and currency of the personal data processed;
  • access to personal data limited to the minimum necessary;
  • controlled and traceable access to personal data;
  • storage for the minimum period necessary;
  • secure and reliable storage;
  • accountability in demonstrating compliance with the Regulation.

The Policy is governed by the following rights of natural people:

  • the right to be informed about the purposes for which their personal data are processed;
  • the right of access to personal data;
  • the right to rectification;
  • the right to erasure (the “right to be forgotten”);
  • the right to restriction of processing;
  • the right to be informed of any action taken in response to a request for rectification, erasure or restriction of processing;
  • the right to data portability;
  • the right to object to the processing of personal data;
  • the right not to be subject to a decision based solely on automated processing, including profiling.

1. Key Terms

PERSONAL DATA
PROCESSING OF PERSONAL DATA
PERSONAL DATA REGISTER
DATA CONTROLLER
DATA PROCESSOR
RECIPIENT OF PERSONAL DATA
CONSENT OF THE DATA SUBJECT
PERSONAL DATA BREACH
DATA CONCERNING HEALTH
SPECIAL CATEGORIES OF (SENSITIVE) PERSONAL DATA
PROFILING

2. Principles Relating to the Processing of Personal Data

  • 1
    Compliance with the provisions of the Regulation.
  • 2
    Personal data shall be collected and processed lawfully and fairly.
  • 3
    Personal data shall be processed in a transparent manner.
  • 4
    Personal data shall be collected and processed only for specified purposes.
  • 5
    Personal data that are not necessary for the Company’s activities shall not be collected or processed.
  • 6
    Personal data already collected shall be processed for other purposes only with the consent of the individuals concerned.
  • 7
    Only the minimum amount of personal data necessary for processing shall be collected.
  • 8
    Personal data undergoing processing shall be accurate and kept up to date.
  • 9
    Personal data shall be processed by the minimum number of persons necessary.
  • 10
    Personal data shall be retained for no longer than is necessary. Personal data relating to employees that are not subject to a statutory retention requirement shall be retained for up to five (5) years following the termination of the employment relationship.

3. Rules for the Processing of Personal Data

  • 1
    Personal data shall be processed using the necessary levels of security and appropriate safeguards.
  • 2
    Access to personal data shall be controlled and traceable.
  • 3
    Personal data shall be processed with the necessary accountability to demonstrate compliance with the Regulation.
  • 4
    The rights of the natural persons whose personal data are processed shall be respected.
  • 5
    Personal data shall be processed only in the manner specified by the Controller.
  • 6
    Every personal data breach shall be documented.
  • 7
    All persons processing personal data shall undertake to maintain confidentiality.
  • 8
    All employees and contractual partners with access to personal data shall be accountable for their handling of such data.
  • 9
    Any breach of the rules governing the processing of personal data shall be subject to disciplinary or other applicable sanctions.

4. Video Surveillance

Video surveillance is conducted on the Company’s premises.

The purposes of video surveillance are:

  • monitoring compliance with working hours;
  • ensuring the traceability of work processes;
  • ensuring safety in the performance of employment duties;
  • protecting the Controller’s property and assets.

5. Personal Data Processed

In its capacity as Data Controller, the Company processes the personal data of:

  • persons holding management positions;
  • employees;
  • the Company’s contractual partners;
  • suppliers.

The personal data processed are obtained:

  • from persons holding management positions within the Company;
  • directly from the data subjects;
  • through an intermediary or duly authorised representative;
  • from a government institution.

6. Special Categories of (“Sensitive”) Personal Data Processed

The following categories of sensitive personal data are processed:

  • data concerning employees’ health, including decisions issued by the Territorial Expert Medical Commission (TELK) and medical certificates;
  • data relating to criminal convictions and offences contained in criminal record certificates.

7. Purposes of Personal Data Processing

The Company processes personal data for the following purposes:

  • entering into, performing and terminating employment contracts, as well as calculating employees’ salaries and benefits;
  • providing services to contractual partners;
  • entering into agreements with suppliers and contractual partners;
  • reissuing electronic penalty notices in accordance with Bulgarian legislation;
  • preparing contracts, annexes, powers of attorney and agreements for the purchase and sale of movable and immovable property;
  • receiving documents from, or serving documents on, a government institution or another authority in connection with Bulgarian legislation;
  • ensuring compliance with occupational health and safety requirements under the Bulgarian Health and Safety at Work Act;
  • submitting visa applications and supporting documents in connection with the Company’s activities outside Bulgaria;
  • monitoring compliance with working hours;
  • ensuring the traceability of work processes;
  • ensuring safety in the performance of employment duties;
  • protecting the Controller’s property and assets.

8. Recipients of Personal Data

Personal data may be disclosed to the following recipients:

  • the National Revenue Agency, in connection with the calculation of employees’ salaries;
  • the National Social Security Institute, in connection with the calculation of employee benefits and compensation;
  • an insurance company, for the purpose of obtaining mandatory occupational accident insurance for certain categories of employees;
  • an occupational health service provider, in connection with the obligation to maintain up-to-date information concerning employees’ health status and to conduct periodic medical examinations;
  • the General Labour Inspectorate Executive Agency, the National Social Security Institute and the Ministry of Interior, in connection with occupational accidents;
  • the Ministry of Interior, in connection with the disclosure of information contained in CCTV footage;
  • other national or municipal authorities and/or institutions, in connection with statutory obligations owed to them or lawful requests made by them for information containing personal data;
  • contractors or subcontractors, where necessary for the performance of contractual obligations.

9. IMPORTANT

If you have any questions concerning:

  • the processing of personal data by the Company;
  • the submission of a complaint or report concerning the processing of personal data;
  • obtaining further information about the General Data Protection Regulation,

please send your enquiries to:

gdpr@solarpro.bg

Please act responsibly, diligently and in good faith when handling personal data in the workplace.

THANK YOU!