To uphold its business reputation and ensure full compliance with the requirements of Federal Law No. 152-FZ of the Russian Federation and/or applicable foreign legislation regarding the processing and protection of personal data, Severstal Aviation Enterprise LLC considers it mandatory to adhere to the purposes, principles, and conditions governing the lawfulness of personal data processing. The Company also strives to adhere to best international practices regarding the processing and protection of personal data.
Policy Objective
To ensure the protection of the rights and freedoms of the individual (hereinafter referred to as the "Data Subject")—including the right to privacy and the confidentiality of personal and family life—during the processing of their personal data, in accordance with applicable legislation.
Principles of Personal Data Processing
- Respecting the rights of Data Subjects during the processing of their personal data.
- Processing personal data on a lawful and fair basis to achieve the stated processing objectives.
- Refraining from processing personal data that is irrelevant to the processing objectives, excessive in scope, or contained in databases with incompatible processing purposes.
- Ensuring the accuracy, sufficiency, and currency of personal data in relation to the processing objectives.
- Retaining personal data only for as long as required to achieve the processing objectives.
- Destroying or anonymizing personal data once the processing objectives have been achieved or are no longer relevant.
Conditions for Personal Data Processing
- Personal data processing is conducted in compliance with the principles and rules established by applicable legislation.
- The recording, systematization, accumulation, storage, updating, and retrieval of personal data belonging to citizens of the Russian Federation must be performed using databases located within the territory of the Russian Federation, unless otherwise provided by applicable legislation.
- Cross-border transfer of personal data is permitted provided the data was collected within the territory of the Russian Federation, in accordance with applicable legislation.
- Any persons (including directors, officers, employees, agents, representatives, or other intermediaries) who carry out assignments or provide services for or on behalf of the Company and who gain access to personal data undertake to maintain... ...confidentiality and not process them without a specific legal basis.
- Personal data processing is carried out subject to obtaining prior consent from the Data Subject for such processing or notifying the Data Subject of the processing of their personal data, or on other legal grounds provided for by the relevant applicable legislation.
Methods for achieving objectives
- Refraining from processing special categories of personal data where such processing is prohibited under applicable legislation.
- Ensuring the security of personal data within the information systems where processing takes place against current security threats, taking into account the potential harm to Data Subjects.
- Implementing a set of organizational and technical measures to ensure personal data security during processing in information systems as well as in non-automated processing.
- Systematically monitoring compliance of personal data processing activities with the requirements of applicable legislation.
- Conducting activities to inform and train personnel on the rules for processing and protecting personal data.
- Holding liable those responsible for violations of applicable legislation and the Company’s internal documents governing personal data processing procedures.