In order to maintain its business reputation and ensure compliance with the norms of Federal Law No. 152-FZ (hereinafter referred to as the Legislation), Severstal Aviation Company LLC considers it mandatory to comply with the goals, principles and conditions of the legality of personal data processing.
The purpose of the Policy
Ensuring the protection of human rights and freedoms (hereinafter referred to as the Subject) when processing his personal data in accordance with applicable law, including the protection of the rights to privacy, personal and family secrets.
Principles of personal data processing
- Respect for the rights of subjects when processing their personal data.
- Processing of personal data on a lawful and fair basis to achieve the purposes of their processing.
- Preventing the processing of personal data that do not meet the processing objectives, are redundant, or are contained in databases whose processing objectives are incompatible.
- Ensuring the accuracy, sufficiency and relevance of personal data during their processing in relation to the purposes of their processing.
- The storage of personal data is not longer than the purposes of personal data processing require.
- Destruction or depersonalization of personal data upon achievement of the purposes of processing or in case of loss of the need to achieve these goals.
Personal data processing conditions
- The processing of personal data is carried out in compliance with the principles and rules provided for by applicable Law.
- Recording, systematization, accumulation, storage, clarification, extraction of personal data of citizens of the Russian Federation when collecting personal data are carried out using databases located on the territory of the Russian Federation, unless otherwise provided by applicable Law.
- Cross-border transfer of personal data is allowed provided they are collected on the territory of the Russian Federation, in accordance with applicable law.
- Any persons who perform assignments or provide services for or on behalf of the Company and who have access to personal data are obligated to maintain confidentiality and not process them without a specific legal basis.
Ways to achieve goals
- Refusal to process special categories of personal data, the processing of which, according to applicable Law, is prohibited.
- Ensuring the security of information systems in which personal data is processed from the effects of current security threats, taking into account the assessment of harm to subjects.
- The application of a set of organizational and technical measures to ensure the security of personal data during their processing in information systems, as well as without the use of automation tools.
- Systematic monitoring of the compliance of personal data processing with the requirements of applicable Legislation.
- Carrying out activities to inform and train staff on the rules of personal data processing and protection.
- Bringing perpetrators to justice for violating applicable Laws and internal documents of the Company governing the processing of personal data