The General Data Protection Regulation (GDPR) aims to protect the rights of individuals about whom data is obtained, stored, processed, or supplied and requires that organisations take appropriate security measures against unauthorised access, alteration, disclosure, or destruction of Personal Data.
GDPR requires reporting of actual or suspected data breaches, and our procedure for dealing with breaches is set out below.
For the purposes of this Data Breach Policy, “we”, “us”, “Company” and “our” refer to Everdust OÜ, company number 16927064, having its registered address at Harju maakond, Tallinn, Kesklinna linnaosa, Narva mnt 5, 10117, as the Controller of your Personal Data, and "you", “User”, "your" refer to you as to a Data Subject.
The terms and headings used in this Data Breach Policy but not defined have similar meanings to those in the Privacy Policy.
What is a Data Breach?
A Data Breach is a security breach that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or Processed (the “Data Breach”).
Examples of a Data Breach could include the following (but are not exhaustive):
Data Breach Response Team
In case of a Data Breach, the Director, Kyrylo Zhankevych of the Company shall urgently form the Data Breach response team, which will handle the Data Breach, notify the appropriate persons, and mitigate its risks (the “Data Breach Response Team”).
А Data Breach Response Team must be а multi-disciplinary team headed by the Director, Kyrylo Zhankevych and comprised of knowledgeable and skilled specialists in the IT department or outsourced professionals, if necessary. The team must ensure that all employees and engaged contractors/processors adhere to this Data Breach Policy and provide an immediate, effective, and skillful response to any suspected/alleged or actual personal data breaches affecting the Company and Data Subjects.
The members of the Data Breach Response Team must be prepared to respond to а suspected/alleged or actual Data Breaches. The Data Breach Response Team shall perform all the responsibilities mentioned in this Data Breach Policy.
The duties of the Data Breach Response Team are:
The Data Breach Response Team shall perform its duties until all the necessary measures required by this Data Breach Policy are taken.
Notification to Data Protection Authority
The Company shall inform the Data Protection Authority about the Data Breach without undue delay and, where possible, not later than 72 hours after becoming aware of the Data Breach.
The Data Protection Authority shall be determined by the residence of the Data Subjects whose information was involved in the Data Breach. If the Data Breach concerns the Personal Data of Data Subjects from multiple countries, the Company shall inform all Data Protection Authorities.
Annex 1 contains all the necessary contact information of the EU Data Protection Authority. If the Data Breach concerns Data Subjects from other than the EU countries, the Response Team shall ask a competent privacy specialist for advice.
The notification to the Data Protection Authority shall contain at least the following information:
Notifications to Data Subjects
If a Data Breach may lead to a violation of the Data Subject’s rights and freedoms or has a high risk of this, the Company shall immediately inform this Data Subject of the fact of the Data Breach and report the following information:
Notification to the Data Subjects should be carried out by email or, where email is impossible to use, by other available means of communication.
We do not have to send the notification to the Data Subject if any of the following conditions are met:
If we apply one of the exemptions, we must document the circumstances, reason for not informing, and actions taken to meet one of the exemptions.
Communication with Third Parties
In case the Company processes the Personal Data on behalf of any Third Party, and the Data Breach occurs, the Company shall also notify this Third Party about it within 72 hours. The same rule applies to activities, in which Third Parties share personal data with the Company, and Data Breach has occurred. The conduction of such notification does not exempt the Company from the duty to conduct the Data Breach response procedure.
In case of receiving a notification about the Data Breach from Third Parties, the Director, Kyrylo Zhankevych of the Company shall:
Miscellaneous
This Data Breach Policy is valid from the Effective date.
The Company may change the Data Breach Policy from time to time. The new version will be valid from the Effective date changes.
The Data Breach Policy is construed in accordance with the Estonian legislation.
Approved by: | |
---|---|
Signature | |
Director | Kyrylo Zhankevych |
Effective Date | 17.04.2024 |