Now no activity is complete withoutinformation. Each organization stores information about employees, partners, and customers. Unauthorized access to them leads to their loss or change, which adversely affects the activities of the firm. The goals of processing personal data in organizations are the same, as it is fixed by law. This is described in the article.
Each person can read information aboutanother citizen, both in the performance of work duties, and in non-working communication, while browsing the Internet, reading the newspaper. Such collection of information is not considered processing. This is just an introduction to the information.
If personal information is specifically collectedfor use, storage, it will be the processing of personal data. This process is observed in educational institutions and hospitals. Information is recorded, entered into the database, classified for use in lawful purposes. If the information is collected by a writer, a journalist, he can use it for creative purposes.
Personal information is processed in 2 ways:
The second option involves processingperformed with the participation of a citizen. If this happens without automation, then the data must be separated from the rest of the information. This is done using a mark, for example, in the margins of the blanks. It is forbidden to place personal information on a single carrier, if it is known that the purposes of processing personal data are incompatible.
If personal information of citizens belong to differentcategories, it is necessary for each type to use an individual carrier. Which systems can be classified as automated, and which are not? The following facts reveal this:
Automated processing is performed withusing computational tools. Processing refers to all actions that are performed on the data provided. This process includes the collection, fixation, use, destruction.
The objectives of the processing of personal data in the organization are the same. Information is needed for:
Каждая цель обработки персональных данных в The organization is obligatory for execution because it is enshrined in law. That is why all institutions require information about employees, customers, partners. The purposes of personal data processing allow you to conduct business in a legal way.
The head should receive the following information about his employees:
When processing information of employees, HR specialists should follow several rules:
Purposes of processing personal data according to Law No. 152mandatory for every employer. Based on Art. 22, the head can take actions with the personal information of employees without notifying Roskomnadzor.
It is important to know not only the goals of collecting and processing personal data, but also the principles. They are listed in Art. 5 ch. 2 FZ №152:
The goals of processing personal data of an employee are achieved using the conditions specified in art. 6 ch. 2:
There are several exceptions when permission of the subject is not required. This happens when:
To protect a person from unwanteduse of information about him requires his consent to the processing of personal data. The purpose of the treatment must be legal, and in other cases it is prohibited to do so. Consent is provided with a job, a bank account and other important transactions.
Единой формы разрешения нет.It is made up in free form on the form used by the enterprise. The period during which the permit is valid is indicated in the document itself. It also indicates the purpose of processing personal data in the organization.
The specialist responsible for obtaining,processing, storage of personal information, appoints the director of the institution. It also identifies individuals who are open to access information. The document must be issued by order. Usually they are responsible for processing information:
Based on Federal Law No. 152, an employee performingthe collection and processing of personal data is the operator. He is the head. The objectives of the processing of personal data in an educational institution are the same as in organizations.
Keeping records with personal information aboutworkers carried in refractory cabinets or safes. The keys to them should be the director of the personnel department. If he is absent, then the deputy manages it. If it is necessary to transfer personal information of an employee, a staff member should remember the following rules:
An exception is considered to be circumstances relating to the question of the performance by employees of their duties.
If employees have violated the collection procedure,processing, issuing information, they are subject to disciplinary and criminal liability under the law. In Art. 5 of the Federal Law states that personal information collected for processing by automated principles or other means must be made in such a way that it is possible to establish a data subject.
The definition of the subject can not be longerwhat is required for processing. If it is done, then some time personal data cannot be destroyed. Personal data of employees are stored in the institution for 75 years. Thus, each company must comply with the rules for storing and processing information.