DATA PROCESSING NOTICE

The LG TECHNOLOGIES Limited Liability Company (registered office: 2161 Csomád, Levente utca 14. A. building, company registration number: 13-09-231888, tax number: 24376004-2-13, statistical number: 24376004-3314-113-15, registration body: Budapest Regional Court Commercial Court, hereinafter referred to as: Company or Entrepreneur or Enterprise) by publishing this data processing policy, we comply with Regulation 2016/679 of the European Parliament and of the Council (hereinafter referred to as: GDPR) obligation prescribed by.

I. NAME OF THE DATA CONTROLLER

The LG TECHNOLOGIES Limited Liability Company informs the data subject that it is considered a data controller in relation to the processing of certain of his/her personal data. The data controller's details are as follows:

Name: LG TECHNOLOGIES Limited Liability Company

Registered office: 2161 Csomád, Levente Street 14.

Tax number: 24376004-2-13

Company registration number: 13-09-231888

Court ordering registration: Budapest District Court Commercial Court

Phone: +36 70 563 0493

E-mail: info@lgtechnologies.hu

Representative: Károly Lengyel, Managing Director

II. DEFINITIONS (Based on the relevant provisions of the GDPR)

the)
personal data: any information relating to an identified or identifiable natural person („data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, a number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person
b)
data processing: any operation or set of operations which is performed on personal data or data files, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
c)
restriction of data processing: marking stored personal data with the aim of restricting their future processing
d)
registration system: a file of personal data structured in any way – centralized, decentralized or according to functional or geographical aspects – which is accessible based on specific criteria
e)
data controller: the natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of the processing are determined by Union or Member State law, the controller or the specific criteria for the designation of the controller may also be determined by Union or Member State law
f)
data processor: the natural or legal person, public authority, agency or any other body which processes personal data on behalf of the data controller
g)
recipient: the natural or legal person, public authority, agency or any other body to which personal data are disclosed, whether or not a third party. Public authorities which have access to personal data in the context of a specific investigation in accordance with Union or Member State law shall not be considered recipients; the processing of such data by such public authorities shall be in accordance with the applicable data protection rules in accordance with the purposes of the processing.
h)
third party: a natural or legal person, public authority, agency or any other body other than the data subject, the controller, the processor or the persons who, under the direct control of the controller or processor, are authorised to process personal data
i)
consent of the data subject: any freely given, specific, adequately informed and unambiguous indication of the data subject's wishes by which the data subject, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data concerning him or her.
j)
data breach: a breach of security that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data transmitted, stored, or otherwise processed

III. NAME OF THE DATA PROCESSOR

The LG TECHNOLOGIES Limited Liability Company uses a data processor for the operation and maintenance of its website, the use of IT solutions, the performance of accounting and payroll tasks, and auditing purposes. The LG TECHNOLOGIES Limited Liability Company Data of data processors used by:

1.
Accountant

Company name: Tower Interconsult Ltd.

Headquarters: 134 Budapest, Váci Street 45. Building G., 7th floor.

Company registration number: 01-09-995297

Tax number: 24200943-2-41

Activity: 6920'08 - Accounting, auditing and tax expert activities

2.
Website operator

Company name: Websupport Hungary Ltd.

Headquarters: 1119 Budapest, Fehérvári Street 97-99.

Company registration number: 01-09-381419

Tax number: 25138205-2-43

Activity: 6311'08 - Data processing, web hosting services

IV. GENERAL DATA PROCESSING RULES

the)
Personal data may be accessed by LG Technologies Kft. employees with access rights related to the relevant data processing purpose, in particular employees performing administrative tasks, or persons and organizations performing data processing activities for LG Technologies Kft. under a contract, to the extent determined by LG Technologies Kft. and to the extent necessary for the performance of their activities, as well as by the law firm providing legal representation and legal services to LG Technologies, lawyers and their employees.
b)
The data processing activity set out in this policy is directed at the personal data of natural persons and, in addition to the natural persons affected by the data processing, its scope extends to LG Technologies Ltd.
c)
The CEO of LG Technologies Kft. ensures that all employees and senior officers of LG Technologies Kft. comply with the provisions of the GDPR and this policy.
d)
LG Technologies Ltd. stores the personal data it processes at its headquarters or in a database in electronic form, and certain data on paper-based documents, while complying with legal requirements regarding data security.

V. LG TECHNOLOGIES KFT. ACTIVITIES AS A DATA PROCESSOR

the)
Data processing related to the performance of contracts

LG Technologies Ltd. processes the personal data of natural persons contracting with it and natural persons employed by legal entities necessary for the performance of the contract for the period necessary for the performance of the contract. The legal basis for data processing by LG Technologies Ltd. is the performance of the contract (GDPR Article 6 (1) b)) and the User's consent (GDPR Article 6 (1) a)), the purpose of data processing is to maintain contact with the contracting natural person, enforce the claims arising from the contract, and fulfill the obligations arising from the contract.

The personal data processed may include: natural person identification data (name, birth name, place and time of birth, mother's name, address), telephone number, e-mail address, tax number, bank account number, social security number, identity document number.

LG Technologies Ltd. processes the personal data of natural persons contracting with it for the period specified by the legal provisions requiring the retention of the contract.

b)
Processing of data necessary for the performance of contracts

The main activity of LG Technologies Ltd. is the construction, maintenance, installation of air conditioning and other equipment, as well as other construction works. LG Technologies Ltd. transfers the name, mother's name, place and date of birth, telephone number, e-mail address and residential address of the natural persons contracting with it to its employees and subcontractors if this is necessary for the performance of the contract, the purpose of the data management is to maintain contact with the customers, the duration of the data management is the duration of the contract.

c)
Data processing during the employment relationship

LG Technologies Ltd. processes the personal data of its employees included in the employment register. These are the following: name; mother's name; home address and place of residence, as well as notification address; contact details (telephone number, e-mail address); social security number, tax identification number, type and number of personal identification document; amount of wages; name of the account-keeping financial institution and account number; amount and title of withholdings and deductions from wages, as well as the account number of the person entitled to the deductions and withholdings; names and social security numbers of children and dependents; name and contact details of the next of kin to be notified.

The purpose of data processing is: to fulfill obligations arising from the employment relationship and exercise rights arising from the employment relationship, to establish and terminate the employment relationship.

Duration of data management: 8 years after the employment relationship and termination of the employment relationship, or, if longer, the period specified in the legislation.

Legal basis for data processing: legitimate interest of the employer, fulfillment of a legal obligation, fulfillment of the employment contract. The employee must be informed of the legal basis and purpose of data processing before data processing begins.

d)
Data processing necessary to fulfill accounting obligations

LG Technologies Kft. processes the data necessary for the fulfillment of these legal obligations of those natural persons in a contractual relationship with it, against whom LG Technologies Kft. is subject to obligations prescribed by the legal provisions relating to accounting. The purpose of data processing is to determine the mandatory data content of the invoice, issue the invoice, and perform accounting tasks related to invoicing. Scope of the processed data: LG Technologies Kft. processes the names of the persons concerned, their registered residential and notification addresses, their electronic mailing addresses, their tax identification numbers (tax numbers) and the data related to their payment accounts (account number, account management institution data). Employees of LG Technologies Kft. who perform invoicing and related accounting activities as part of their job duties are entitled to learn about the processed personal data. LG Technologies Kft. is entitled to process the personal data recorded in the course of fulfilling the legal obligation specified above for 8 years from the termination of the contract (business relationship).

k)
Data processing related to the fulfillment of tax and contribution obligations

LG Technologies Kft., in accordance with the legal provisions determining the taxation regime, files an electronic return on a monthly basis, by the twelfth day of the month following the month in question, on all taxes, contributions and mandatory data related to payments and benefits made to natural persons resulting in tax and/or social security obligations.

Data management may be carried out by employees of LG Technologies Kft. performing payroll activities as a job task or by business companies and sole proprietors entrusted with these tasks. LG Technologies Kft. processes data processed in connection with the fulfillment of tax and contribution obligations for the period prescribed by the legal provisions determining the taxation system.

VI. LEGAL BASIS FOR DATA PROCESSING

the)
The data subject's consent

The lawfulness of the processing of personal data must be based on the consent of the data subject or on some other legitimate basis established by law.

In the case of data processing based on the data subject's consent, the data subject may provide their consent to the processing of their personal data in the following form:

the)
in writing, in the form of a declaration giving consent to the processing of personal data,
b)
electronically, by explicit conduct on the LG Technologies Kft. website, by ticking a checkbox, or by making relevant technical settings when using information society services, as well as any other statement or action that clearly indicates the data subject's consent to the planned processing of his or her personal data in the given context.

Silence, a pre-ticked box, or inaction does not constitute consent.

Consent covers all data processing activities carried out for the same purpose or purposes.

If the data processing serves several purposes at the same time, consent must be given for all the purposes of data processing. If the data subject gives his consent following an electronic request, the request must be clear and concise and must not unnecessarily hinder the use of the service for which consent is requested.

The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. The withdrawal of consent shall be made as easy as the granting of consent.

b)
Contract fulfillment

Data processing is considered lawful if it is necessary for the performance of a contract to which the data subject is a party, or if it is necessary to take steps at the data subject's request prior to entering into a contract.

The consent given by the data subject to the processing of personal data that is not necessary for the performance of the contract cannot be a condition for concluding a contract.

c)
Compliance with a legal obligation to which the controller is subject or to protect the vital interests of the data subject or another natural person

The legal basis for data processing is determined by law in the event of compliance with a legal obligation, so the consent of the data subject is not required for the processing of their personal data.

The data controller is obliged to inform the data subject about the purpose, legal basis, duration of data processing, the identity of the data controller, as well as their rights and legal remedies.

The data controller is entitled to process the data set necessary for the fulfillment of a legal obligation to which it is subject, after the withdrawal of the data subject's consent.

d)
The performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller, the enforcement of the legitimate interests of the data controller or a third party.

The legitimate interests of the controller, including the controller to whom the personal data may be disclosed, or of a third party may constitute a legal basis for processing, provided that the interests, fundamental rights and freedoms of the data subject are not overridden by them, taking into account the reasonable expectations of the data subject based on the relationship between the data subject and the controller. Such legitimate interests may exist, for example, where there is a relevant and appropriate relationship between the data subject and the controller, for example where the data subject is a client or employee of the controller.

In order to determine the existence of a legitimate interest, it is necessary to carefully examine, among other things, whether the data subject can reasonably expect, at the time and in the context of the collection of personal data, that data processing may take place for the given purpose.

The interests and fundamental rights of the data subject may override the interests of the controller if personal data are processed in circumstances in which the data subject does not expect further processing.

VII. RIGHTS OF THE DATA SUBJECT RELATING TO THE PROCESSING OF THEIR DATA

the)
LG Technologies Ltd. provides the following brief information about the rights of the data subject:

The data subject has the right to:

for information before starting data processing,

to receive feedback from the data controller as to whether or not personal data concerning you is being processed, and if such processing is taking place, you have the right to access the personal data and the following information:,

request the correction or deletion of your data, and receive notification from the data controller that this has occurred,

request restriction of data processing, receive notification from the data controller that this has occurred,

data portability,

to object if your personal data is processed for purposes of public interest or with reference to the legitimate interests of the data controller.

be exempt from automated decision-making, including profiling,

to file a complaint with the supervisory authority. The data subject may exercise his/her right to file a complaint at the following contact details:

National Data Protection and Freedom of Information Authority,

address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c.,

Phone: +36 (1) 391-1400; Fax: +36 (1) 391-1410.,

www.naih.hu;

e-mail: ugyfelszolgalat@naih.hu

to an effective judicial remedy against the supervisory authority,

to an effective judicial remedy against the data controller or processor,

to inform about the data protection incident. b) Detailed information provided on the rights of the data subject

Right to information

(1)
The data subject has the right to receive information related to data processing prior to the commencement of activities aimed at processing his or her data.
(2)
Information to be provided:

the identity and contact details of the data controller and, if any, the data controller's representative;

contact details of the data protection officer, if any;

the purpose of the intended processing of personal data and the legal basis for the processing;

in the case of data processing based on point (f) of Article 6(1) of the Regulation, the legitimate interests of the controller or a third party;

where applicable, the recipients of the personal data and the categories of recipients, if any;

where applicable, the fact that the controller intends to transfer the personal data to a third country or to an international organisation, the existence or absence of an adequacy decision by the Commission, or, in the case of transfers referred to in Article 46, Article 47 or the second subparagraph of Article 49(1) of the Regulation, an indication of the appropriate and suitable safeguards and a reference to the means of obtaining a copy of them or their availability.

(3)
In addition to the information referred to in paragraph 1, the controller shall, at the time of obtaining the personal data, inform the data subject of the following additional information in order to ensure fair and transparent data processing:

the duration of storage of personal data or, if this is not possible, the criteria for determining this duration;

the right of the data subject to request from the controller access to, rectification, erasure or restriction of processing of personal data concerning him or her, and to object to the processing of such personal data, as well as the right of the data subject to data portability;

in the case of processing based on Article 6(1)(a) or Article 9(2)(a) of the Regulation, the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;

the right to lodge a complaint with a supervisory authority; whether the provision of personal data is based on a legal or contractual obligation or is a prerequisite for entering into a contract, and whether the data subject is obliged to provide the personal data, as well as the possible consequences of failure to provide the data;

the fact of automated decision-making referred to in Article 22(1) and (4) of the Regulation, including profiling, and at least in these cases, intelligible information on the logic involved and the significance and foreseeable consequences of such processing for the data subject.

(4)
Where the controller intends to process personal data for purposes other than those for which they were collected, the controller shall, prior to the further processing, inform the data subject of that other purpose and of any relevant additional information referred to in paragraph (2).
(5)
Paragraphs (1) to (3) shall not apply if and to the extent that:

the data subject already has the information;

providing the information in question proves impossible or would involve a disproportionate effort, in particular for archiving purposes in the public interest, scientific and historical research purposes or statistical purposes, in the case of processing carried out subject to the conditions and safeguards referred to in Article 89(1), or where the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously jeopardise the achievement of the purposes of such processing. In such cases, the controller shall take appropriate measures to safeguard the rights and freedoms and legitimate interests of the data subject, including making the information publicly available;

the collection or disclosure of the data is expressly required by Union or Member State law applicable to the controller, which provides for appropriate measures to safeguard the legitimate interests of the data subject; or

personal data must remain confidential pursuant to an obligation of professional secrecy laid down in Union or Member State law, including a statutory obligation of confidentiality.

The data subject's right of access

(1)
The data subject has the right to receive feedback from the data controller as to whether his or her personal data is being processed and, if such processing is taking place, he or she has the right to access the personal data and the following information:

the purposes of data processing;

the categories of personal data concerned; the recipients or categories of recipients to whom the personal data have been or will be disclosed, including in particular recipients in third countries or international organisations;

where applicable, the planned period for which the personal data will be stored or, if this is not possible, the criteria for determining this period;

the right of the data subject to request from the controller the rectification, erasure or restriction of processing of personal data concerning him or her and to object to the processing of such personal data;

the right to lodge a complaint with a supervisory authority;

if the data were not collected from the data subject, all available information regarding their source;

the fact of automated decision-making referred to in Article 22(1) and (4) of the Regulation, including profiling, and at least in these cases, intelligible information on the logic involved and the significance and foreseeable consequences of such processing for the data subject.

(2)
Where personal data are transferred to a third country or to an international organisation, the data subject shall have the right to be informed of the appropriate safeguards for the transfer in accordance with Article 46.
(3)
The controller shall provide the data subject with a copy of the personal data subject to processing. For further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs. If the data subject has submitted the request electronically, the information shall be provided in a commonly used electronic format, unless the data subject requests otherwise.

The data subject's right to rectification and erasure

The right to rectification

(1)
The data subject shall have the right to obtain from the controller, at his or her request, the rectification of inaccurate personal data concerning him or her without undue delay. Taking into account the purpose of the processing, the data subject shall have the right to request the completion of incomplete personal data, including by means of a supplementary statement.

The right to erasure („the right to be forgotten”)

(1)
The data subject has the right to request that the data controller erase personal data concerning him or her without undue delay, and the data controller is obliged to erase personal data concerning the data subject without undue delay if one of the following reasons applies:

the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;

the data subject withdraws his or her consent which was the basis for the processing pursuant to Article 6(1)(a) of the Regulation (consent to the processing of personal data) or Article 9(2)(a) of the Regulation (granting explicit consent) and there is no other legal basis for the processing;

the data subject objects to the processing of his or her data pursuant to Article 21(1) of the Regulation (right to object) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2) of the Regulation (objection to the processing of personal data for commercial purposes);

the personal data has been processed unlawfully;

the personal data must be erased for compliance with a legal obligation under Union or Member State law to which the controller is subject;

the personal data were collected in connection with the provision of information society services referred to in Article 8(1).

(2)
Where the controller has made personal data public and is obliged to erase them at the request of the data subject, the controller, taking into account available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform the controllers processing the data that the data subject has requested the erasure of links to, or copies or replications of, the personal data concerned.
(3)
Paragraphs (1) and (2) shall not apply if the processing is necessary:

for the purpose of exercising the right to freedom of expression and information;

for compliance with an obligation to process personal data under Union or Member State law to which the controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

on grounds of public interest in the field of public health in accordance with Article 9(2)(h) and (i) of the Regulation and Article 9(3) of the Regulation;

for archiving purposes in the public interest, scientific and historical research purposes or statistical purposes in accordance with Article 89(1) of the Regulation, where the right referred to in paragraph 1 would likely render impossible or seriously jeopardise such processing; or

to assert, enforce or defend legal claims.

Right to restriction of data processing

(1)
The data subject has the right to request that the data controller restrict data processing if one of the following applies:

the data subject disputes the accuracy of the personal data, in which case the restriction shall apply for a period of time enabling the controller to verify the accuracy of the personal data;

the processing is unlawful and the data subject opposes the erasure of the data and instead requests the restriction of their use;

the controller no longer needs the personal data for the purposes of processing, but the data subject requires them for the establishment, exercise or defence of legal claims; or

the data subject has objected to the processing pursuant to Article 21(1) of the Regulation; in this case, the restriction shall apply for a period of time until it is determined whether the legitimate grounds of the controller override those of the data subject.

(2)
Where processing is restricted pursuant to paragraph 1, such personal data may, with the exception of storage, only be processed with the data subject's consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for important reasons of public interest of the Union or of a Member State.
(3)
The data controller shall inform the data subject, at whose request data processing has been restricted pursuant to paragraph (1), in advance of the lifting of the restriction on data processing.

Notification obligation related to the rectification or erasure of personal data or the restriction of data processing

(1)
The data controller shall inform all recipients to whom the personal data have been disclosed of the rectification, erasure or restriction of processing, unless this proves impossible or involves a disproportionate effort.
(2)
The data controller will inform the data subject about these recipients upon request.

The right to data portability

(1)
The data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format and shall have the right to transmit those data to another controller without hindrance from the controller to whom the personal data have been provided, where:

the processing is based on consent pursuant to Article 6(1)(a) of the Regulation (the data subject's consent to the processing of personal data) or Article 9(2)(a) of the Regulation (the data subject's explicit consent to the processing) or on a contract pursuant to Article 6(1)(b); and

data processing is carried out in an automated manner.

(2)
When exercising the right to data portability pursuant to paragraph (1), the data subject shall have the right to request the direct transmission of personal data between data controllers, where technically feasible.
(3)
The exercise of the right referred to in paragraph 1 of this Article shall be without prejudice to Article 17 of the Regulation. That right shall not apply where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
(4)
The right referred to in paragraph 1 shall not adversely affect the rights and freedoms of others.

The right to protest

(1)
The data subject shall have the right, on grounds relating to his or her particular situation, to object at any time to processing of personal data concerning him or her carried out in the public interest or in the exercise of official authority vested in him or her, or to processing necessary for the purposes of the legitimate interests pursued by the controller or by a third party (processing based on point (e) or (f) of Article 6(1) of the Regulation), including profiling based on those provisions. In such a case, the controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.
(2)
If personal data are processed for direct marketing purposes, the data subject has the right to object at any time to processing of personal data concerning him or her for such purposes, including profiling, where it is related to direct marketing.
(3)
If the data subject objects to the processing of personal data for direct marketing purposes, the personal data may no longer be processed for this purpose.
(4)
The right referred to in paragraphs (1) and (2) shall be expressly brought to the attention of the data subject at the latest during the first contact with him/her, and the information relating to it shall be displayed clearly and separately from all other information.
(5)
In connection with the use of information society services and by way of derogation from Directive 2002/58/EC, the data subject may also exercise the right to object by automated means based on technical specifications.
(6)
Where personal data are processed for scientific and historical research purposes or for statistical purposes pursuant to Article 89(1) of the Regulation, the data subject shall have the right to object, on grounds relating to his or her particular situation, to processing of personal data concerning him or her, unless the processing is necessary for the performance of a task carried out for reasons of public interest.

Right to be exempt from automated decision-making

(1)
The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
(2)
Paragraph (1) shall not apply if the decision:

necessary for the conclusion or performance of a contract between the data subject and the data controller;

is permitted by Union or Member State law applicable to the controller and which also lays down suitable measures to safeguard the rights and freedoms and legitimate interests of the data subject; or

based on the explicit consent of the data subject.

(3)
In the cases referred to in points (a) and (c) of paragraph 2, the controller shall take suitable measures to safeguard the rights, freedoms and legitimate interests of the data subject, including at least the right of the data subject to obtain human intervention on the part of the controller, to express his or her point of view and to object to the decision.
(4)
The decisions referred to in paragraph 2 shall not be based on special categories of personal data referred to in Article 9(1) of the Regulation, unless point (a) or (g) of Article 9(2) applies and suitable measures have been taken to safeguard the rights, freedoms and legitimate interests of the data subject.

The data subject's right to complain and seek legal redress

Right to lodge a complaint with a supervisory authority

(1)
The data subject has the right to lodge a complaint with the supervisory authority pursuant to Article 77 of the Regulation if, in the opinion of the data subject, the processing of personal data concerning him or her infringes this Regulation.
(2)
The data subject may exercise his/her right to file a complaint at the following contact details:

National Data Protection and Freedom of Information Authority Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c Phone: +36 (1) 391-1400; Fax: +36 (1) 391-1410 www: www.naih.hu e-mail: ugyfelszolgalat@naih.hu

(3)
The supervisory authority to which the complaint has been submitted is obliged to inform the customer about the procedural developments related to the complaint and its outcome, including the fact that the customer has the right to a judicial remedy pursuant to Article 78 of the Regulation.

Right to an effective judicial remedy against the supervisory authority

(1)
Without prejudice to other administrative or non-judicial remedies, every natural and legal person has the right to an effective judicial remedy against a legally binding decision of a supervisory authority concerning him or her.
(2)
Without prejudice to other administrative or non-judicial remedies, each data subject shall have the right to an effective judicial remedy if the competent supervisory authority does not deal with the complaint or does not inform the data subject of the procedural developments or the outcome of a complaint lodged pursuant to Article 77 of the Regulation within three months.
(3)
Proceedings against a supervisory authority shall be brought before the courts of the Member State in which the supervisory authority is established.
(4)
If proceedings are brought against a decision of the supervisory authority in relation to which the Board has previously issued an opinion or taken a decision under the consistency mechanism, the supervisory authority shall be obliged to send this opinion or decision to the court.

Right to an effective judicial remedy against the controller and the processor

(1)
Without prejudice to any available administrative or non-judicial remedies, including the right to lodge a complaint with a supervisory authority under Article 77, each data subject shall have the right to an effective judicial remedy if he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of personal data concerning him or her not being in accordance with this Regulation.
(2)
Proceedings against a controller or processor shall be brought before the courts of the Member State in which the controller or processor is established. Such proceedings may also be brought before the courts of the Member State in which the data subject has his habitual residence, unless the controller or processor is a public authority of a Member State acting in the exercise of its official authority.
c)
Restrictions
(1)
Union or Member State law applicable to the controller or processor may, by means of legislative measures, restrict the scope of the rights and obligations set out in Article 5 in respect of its provisions in accordance with Articles 12 to 22 and Article 34 and the rights and obligations set out in Articles 12 to 22, provided that the restriction respects the essence of the fundamental rights and freedoms and is a necessary and proportionate measure in a democratic society to protect:

national security;

national defense;

public safety;

the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security; other important objectives of general public interest of the Union or of a Member State, in particular the important economic or financial interests of the Union or of a Member State, including monetary, budgetary and taxation matters, public health and social security;

the protection of judicial independence and judicial proceedings;

in the case of regulated professions, the prevention, investigation, detection and conduct of proceedings related to ethical violations;

in the cases referred to in points a)–e) and g) – even occasionally – control, investigation or regulatory activities related to the performance of public authority tasks;

the protection of the data subject or the rights and freedoms of others;

enforcement of civil law claims.

(2)
The legislative measures referred to in paragraph 1 shall, where appropriate, contain detailed provisions on at least:

the purposes of data processing or categories of data processing,

categories of personal data,

the scope of the restrictions introduced,

guarantees to prevent misuse or unauthorized access or transmission,

to identify the data controller or to identify categories of data controllers,

the duration of data storage and the applicable safeguards, taking into account the nature, scope and purposes of the data processing or categories of data processing,

the risks to the rights and freedoms of data subjects, and

the right of data subjects to be informed about the restriction, unless this may adversely affect the purpose of the restriction.

d)
Information about a data breach
(1)
If the data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall inform the data subject of the data breach without undue delay.
(2)
The information provided to the data subject referred to in paragraph 1 shall describe in a clear and comprehensible manner the nature of the data protection incident and shall include at least the name and contact details of the data protection officer or other contact person who can provide further information, the likely consequences of the data protection incident, the measures taken or planned by the controller to remedy the data protection incident, including, where applicable, measures to mitigate any adverse consequences resulting from the data protection incident.
(3)
The data subject shall not be required to be informed as referred to in paragraph 1 if any of the following conditions are met:

the controller has implemented appropriate technical and organisational protection measures and these measures have been applied to the data affected by the data breach, in particular measures – such as the use of encryption – that make the data unintelligible to persons not authorised to access the personal data;

the controller has taken further measures following the data protection incident to ensure that the high risk to the rights and freedoms of the data subject referred to in paragraph (1) is no longer likely to materialise;

information would require a disproportionate effort. In such cases, the data subjects should be informed by means of publicly published information or a similar measure should be taken to ensure that the data subjects are informed in a similarly effective manner.

(4)
If the controller has not yet notified the data subject of the personal data breach, the supervisory authority may, after considering whether the personal data breach is likely to involve a high risk, order the data subject to be informed or determine that one of the conditions referred to in paragraph (3) is met.

VIII. PROCEDURE TO BE APPLIED IN CASE OF A DATA SUBJECT'S REQUEST

(1)
LG Technologies Kft. facilitates the exercise of the data subject's rights and may not refuse to fulfill the data subject's request to exercise his or her rights as set out in this data protection notice, unless it proves that it is unable to identify the data subject.
(2)
LG Technologies Kft. shall inform the data subject of the measures taken in response to the request without undue delay, but in any case within one month of receipt of the request. If necessary, taking into account the complexity of the request and the number of requests, this deadline may be extended by a further two months. The data controller shall inform the data subject of the extension of the deadline within one month of receipt of the request, indicating the reasons for the delay.
(3)
If the data subject has submitted the request electronically, the information shall be provided electronically, if possible, unless the data subject requests otherwise.
(4)
If LG Technologies Kft. does not take action following the data subject's request, it shall inform the data subject without delay, but no later than one month from receipt of the request, of the reasons for the failure to take action and of the fact that the data subject may file a complaint with the supervisory authority and exercise his/her right to a judicial remedy.
(5)
LG Technologies Ltd. provides the data subject with the following information and measures free of charge: feedback on the processing of personal data, access to the processed data, correction, completion, deletion of data, restriction of data processing, data portability, objection to data processing, information about the data protection incident.
(6)
If the data subject's request is clearly unfounded or excessive – in particular due to its repetitive nature – the data controller may, taking into account the administrative costs of providing the requested information or communication or taking the requested action: charge a fee of HUF 5,000 or refuse to take action based on the request.
(7)
The burden of proving that the request is clearly unfounded or excessive shall be on the data controller.
(8)
Without prejudice to Article 11 of the Regulation, where the controller has reasonable doubts as to the identity of the natural person making a request pursuant to Articles 15 to 21 of the Regulation, he may request the provision of further information necessary to confirm the identity of the data subject.

IX. PROCEDURE TO BE APPLIED IN THE EVENT OF A DATA PROTECTION INCIDENT

(1)
A data breach, within the meaning of the Regulation, is a breach of security that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data transmitted, stored, or otherwise processed.
(2)
A data protection incident is the loss or theft of a device (laptop, mobile phone) containing personal data, as well as the loss or inaccessibility of the code used to decrypt a file encrypted by the data controller, infection by a ransomware virus that makes the data managed by the data controller inaccessible until the ransom is paid, an attack on the IT system, the publication of an email or address list containing personal data sent in error, etc.
(3)
In the event of a data breach, a representative of LG Technologies Kft. will immediately conduct an investigation to identify the data breach and determine its possible consequences. The necessary measures must be taken to prevent damage.
(4)
You shall notify the personal data breach to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of the personal data breach, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. If the notification is not made within 72 hours, it shall be accompanied by reasons justifying the delay.
(5)
The data processor shall notify the data controller of the data protection incident without undue delay after becoming aware of it.
(6)
The notification referred to in paragraph 3 shall include at least:

the nature of the data breach must be described, including, where possible, the categories and approximate number of data subjects and the categories and approximate number of data affected by the breach;

közölni kell az adatvédelmi tisztviselő vagy a további tájékoztatást nyújtó egyéb kapcsolattartó nevét és elérhetőségeit;

ismertetni kell az adatvédelmi incidensből eredő, valószínűsíthető következményeket;

ismertetni kell az adatkezelő által az adatvédelmi incidens orvoslására tett vagy tervezett intézkedéseket, beleértve adott esetben az adatvédelmi incidensből eredő esetleges hátrányos következmények enyhítését célzó intézkedéseket.

(7)
Ha és amennyiben nem lehetséges az információkat egyidejűleg közölni, azok további indokolatlan késedelem nélkül később részletekben is közölhetők.
(8)
Az adatkezelő nyilvántartja az adatvédelmi incidenseket, feltüntetve az adatvédelmi incidenshez kapcsolódó tényeket, annak hatásait és az orvoslására tett intézkedéseket. E nyilvántartás lehetővé teszi, hogy a felügyeleti hatóság ellenőrizze a Rendelet 33. cikkében foglalt követelményeknek való megfelelést.

X.    AZ ADATBIZTONSÁGRA VONATKOZÓ RENDELKEZÉSEK

the)
Az adatbiztonság megvalósításának elvei
(1)
Az LG Technologies Kft. személyes adatot csak a jelen szabályzatban rögzített tevékenységekkel összhangban, az adatkezelés célja szerint kezel.
(2)
Az LG Technologies Kft. az adatok biztonságáról gondoskodik, e körben kötelezettséget vállal arra, hogy megteszi mindazon technikai és szervezési intézkedéseket, amelyek elengedhetetlenül szükségesek az adatbiztonságra vonatkozó jogszabályok, adat- és titokvédelmi szabályok érvényre juttatásához.
(3)
Az LG Technologies Kft. által végrehajtandó technikai és szervezési intézkedések a következőkre irányulnak:

a személyes adatok kezelésére használt rendszerek és szolgáltatások folyamatos bizalmas jellegének biztosítása, integritása, rendelkezésre állása és ellenálló képességének fennállása;

fizikai vagy műszaki incidens esetén az arra való képesség, hogy a személyes adatokhoz való hozzáférést és az adatok rendelkezésre állását kellő időben vissza lehet állítani;

az adatkezelés biztonságának garantálására hozott technikai és szervezési intézkedések hatékonyságának rendszeres tesztelésére, felmérésére és értékelésére szolgáló eljárás alkalmazása,

(4)
A biztonság megfelelő szintjének meghatározásakor kifejezetten figyelembe kell venni az adatkezelésből eredő olyan kockázatokat, amelyek különösen a továbbított, tárolt vagy más módon kezelt személyes adatok véletlen vagy jogellenes megsemmisítéséből, elvesztéséből, megváltoztatásából, jogosulatlan nyilvánosságra hozatalából vagy az azokhoz való jogosulatlan hozzáférésből erednek.
(5)
Az LG Technologies Kft. az adatokat megfelelő intézkedésekkel védi a jogosulatlan hozzáférés, megváltoztatás, továbbítás, nyilvánosságra hozatal, törlés vagy megsemmisítés, valamint a véletlen megsemmisülés és sérülés, továbbá az alkalmazott technika megváltozásából fakadó hozzáférhetetlenné válás ellen.
(6)
Az LG Technologies Kft. az általa kezelt adatokat az irányadó jogszabályoknak megfelelően tartja nyilván, biztosítva, hogy az adatokat csak azok a munkavállalók, és egyéb Az LG Technologies Kft. érdekkörében eljáró személyek ismerhessék meg, akiknek erre munkakörük, feladatuk ellátása érdekében szükségük van.
(7)
Az LG Technologies Kft. az egyes adatkezelési tevékenység során megadott személyes adatokat más adatoktól elkülönítetten tárolja, azzal, hogy – összhangban a fenti rendelkezéssel – az elkülönített adatállományokat kizárólag a megfelelő hozzáférési jogosultsággal rendelkező munkavállalók ismerhetik meg.
(8)
Az LG Technologies Kft. azon munkavállalóinak enged hozzáférést személyes adatokhoz, akik a kezelt személyes adatkörök tekintetében szóbeli vagy írásbeli titoktartási nyilatkozat tételével vetették alá magukat az adatbiztonsági szabályok megtartásával kapcsolatos kötelezettségnek.
(9)
Az LG Technologies Kft. az adatok biztonságát szolgáló intézkedések meghatározásakor és alkalmazásakor tekintettel van a technika mindenkori fejlettségére, több lehetséges adatkezelési megoldás esetén a személyes adatok magasabb szintű védelmét biztosító megoldást választja, kivéve, ha az aránytalan nehézséget jelentene.
b)
Az LG Technologies Kft. informatikai nyilvántartásainak védelme
(1)
Az LG Technologies Kft. az informatikai nyilvántartásai tekintetében az adatbiztonság megvalósulásához a következő szükséges intézkedéseket foganatosítja:

Ellátja az általa kezelt adatállományokat számítógépes vírusok elleni állandó védelemmel (valós idejű vírusvédelmi szoftvert alkalmaz).

Gondoskodik az informatikai rendszer hardvereszközeinek fizikai védelméről, beleértve az elemi károk elleni védelmet.

Gondoskodik az informatikai rendszer jogosulatlan hozzáférés elleni védelméről, mind a szoftver-, mind a hardvereszközök tekintetében.

Megteszi mindazokat az intézkedéseket, amelyek az adatállományok helyreállításához szükségesek, a biztonsági másolatok elkülönített, biztonságos kezelését végrehajtja.

Az LG Technologies Kft. papíralapú nyilvántartásainak védelme

(1)
Az LG Technologies Kft. a papíralapú nyilvántartások védelme érdekében megteszi a szükséges intézkedéseket különösen a fizikai biztonság, illetve tűzvédelem tekintetében.
(2)
Az LG Technologies Kft. vezetője, munkavállalói és egyéb, Az LG Technologies Kft. érdekében eljáró személyek az általuk használt vagy birtokukban lévő, személyes adatokat is tartalmazó adathordozókat, függetlenül az adatok rögzítésének módjától, kötelesek biztonságosan őrizni, és védeni a jogosulatlan hozzáférés, megváltoztatás, továbbítás, nyilvánosságra hozatal, törlés vagy megsemmisítés, valamint a véletlen megsemmisülés és sérülés ellen.
(3)
Az LG Technologies Kft. irodájához kulcsot csak Az LG Technologies Kft. vezetője, munkavállalói és egyéb, Az LG Technologies Kft. érdekében eljáró személyek részére ad.

XI.    AZ ADATFELDOLGOZÁSSAL KAPCSOLATOS SZABÁLYOK

(1)
Az adatfeldolgozónak a személyes adatok feldolgozásával kapcsolatos jogait és kötelezettségeit törvény, valamint az adatkezelésre vonatkozó külön törvények keretei között az adatkezelő határozza meg.
(2)
Az adatfeldolgozó részére az adatkezelési műveletek tárgyában adott utasítások jogszerűségéért Az LG Technologies Kft. felel.
(3)
Az LG Technologies Kft. kötelezettsége az érintettek számára az adatfeldolgozó személyéről, az adatfeldolgozás helyéről való tájékoztatás megadása.
(4)
Az LG Technologies Kft. az adatfeldolgozónak további adatfeldolgozó igénybevételére felhatalmazást nem ad.

Csomád, 2024.11.04.