1.1. This Personal Data Processing Policy (hereinafter referred to as the Policy) has been drawn up in accordance with paragraph 2 of Article 18.1 of the Federal Law "On Personal Data" No. 152–FZ of July 27, 2006, as well as other regulatory legal acts of the Russian Federation in the field of personal data protection and processing and applies to all personal data (hereinafter referred to as data) that an Organization (hereinafter referred to as the Operator, Company) may receive from a personal data subject who is a party to a civil law agreement, from an Internet user (hereinafter referred to as – The User) during the use of any of the sites, services, services, programs, products or services of the EAEU, as well as from the personal data subject who is in a relationship with the Operator regulated by labor law (hereinafter referred to as the Employee). 1.2. The Operator ensures the protection of the processed personal data from unauthorized access and disclosure, misuse or loss in accordance with the requirements of Federal Law No. 152-FZ of July 27, 2006 "On Personal Data".
1.3. The Operator has the right to make changes to this Policy. When making changes, the date of the last revision update is indicated in the Policy header. The new version of the Policy comes into force from the moment it is posted on the website, unless otherwise provided by the new version of the Policy.
Personal data is any information related directly or indirectly to a specific or identifiable natural person (personal data subject).
Personal data processing is any action (operation) or set of actions (operations) performed with or without the use of automation tools with personal data, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, destruction of personal data.
Automated personal data processing is the processing of personal data using computer technology.
The Personal Data Information System (ISPS) is a set of personal data contained in databases and information technologies and technical means that ensure their processing.
Personal data made publicly available by a personal data subject is personal data to which an unlimited number of persons have access provided by the personal data subject or at his request.
Blocking of personal data is the temporary termination of the processing of personal data (except in cases where the processing is necessary to clarify personal data).
Destruction of personal data – actions as a result of which it becomes impossible to restore the content of personal data in the personal data information system and (or) as a result of which the material carriers of personal data are destroyed.
Operator is an organization that independently or jointly with other persons organizes the processing of personal data, as well as determines the purposes of processing personal data to be processed, actions (operations) performed with personal data. The operator is the EAAU, located at: 119435, Moscow, Bolshaya Pirogovskaya str., 2, building 1;
3.1. Receiving personal data.
3.1.1. All personal data should be obtained from the subject himself. If the subject's personal data can only be obtained from a third party, then the subject must be notified of this or consent must be obtained from him.
3.1.2. The operator must inform the subject about the purposes, intended sources and methods of obtaining personal data, the nature of the personal data to be obtained, the list of actions with personal data, the period during which consent is valid, and the procedure for revoking it, as well as the consequences of the subject's refusal to give written consent to receive them.
3.1.3. Documents containing personal data are created by:
3.2. Processing of personal data.
3.2.1. Personal data is processed by:
3.2.2. Purposes of personal data processing:
3.2.3. Categories of subjects of personal data.
Personal data of the following personal data subjects is processed:
3.2.4. Personal data processed by the Operator:
3.2.5. Personal data is processed by:
3.3. Storage of personal data.
3.3.1. Personal data of subjects may be obtained, further processed and stored both on paper and electronically.
3.3.2. Personal data recorded on paper is stored in lockable cabinets or in lockable rooms with limited access rights.
3.3.3. Personal data of subjects processed using automation tools for different purposes are stored in different folders.
3.3.4. It is not allowed to store and post documents containing personal data in open electronic catalogs (file sharing sites) in ISPs.
3.3.5. Personal data is stored in a form that makes it possible to identify the subject of personal data for no longer than the purposes of their processing require, and they are subject to destruction upon achievement of the processing objectives or in case of loss of the need to achieve them.
3.4. Destruction of personal data.
3.4.1. The destruction of documents (media) containing personal data is carried out by burning, crushing (crushing), chemical decomposition, transformation into a shapeless mass or powder. Shredders may be used to destroy paper documents.
3.4.2. Personal data on electronic media is destroyed by erasing or formatting the media.
3.4.3. The fact of destruction of personal data is documented by the act of destruction of media.
3.5. Transfer of personal data.
3.5.1. The Operator transfers personal data to third parties in the following cases:
3.5.2. The list of persons to whom personal data is transferred.
4. Personal data protection
4.1. In accordance with the requirements of regulatory documents, the Operator has created a personal data protection system, consisting of subsystems of legal, organizational and technical protection.
4.2. The subsystem of legal protection is a complex of legal, organizational, administrative and regulatory documents that ensure the creation, functioning and improvement of the NWFPS.
4.3. The subsystem of organizational protection includes the organization of the management structure of the NWFPS, the licensing system, and information protection when working with employees, partners, and third parties.
4.4. The subsystem of technical protection includes a set of technical, software, hardware and software tools that ensure the protection of personal data.
4.4. The main personal data protection measures used by the Operator are:
4.5.1. Appointment of a person responsible for processing personal data, who organizes the processing of personal data, training and instruction, and internal control over compliance by the institution and its employees with personal data protection requirements.
4.5.2. Identification of current threats to the security of personal data during their processing in the ISPS and development of measures and measures to protect personal data.
4.5.3. Development of a personal data processing policy.
4.5.4. Establishment of rules for access to personal data processed in the ISPS, as well as ensuring registration and accounting of all actions performed with personal data in the ISPS.
4.5.5. Establishment of individual passwords for employees' access to the information system in accordance with their work responsibilities.
4.5.6. The use of information security tools that have passed the compliance assessment procedure in accordance with the established procedure.
4.5.7. Certified antivirus software with regularly updated databases.
4.5.8. Compliance with the conditions that ensure the safety of personal data and exclude unauthorized access to them.
4.5.9. Detection of unauthorized access to personal data and taking measures.
4.5.10. Recovery of personal data that has been modified or destroyed due to unauthorized access to it.
4.5.11. Training of the Operator's employees who directly process personal data in the provisions of the legislation of the Russian Federation on personal data, including requirements for personal data protection, documents defining the Operator's policy regarding personal data processing, and local acts on personal data processing.
4.5.12. Implementation of internal control and audit.
5. The basic rights of the personal data subject and the duties of the Operator
5.1. Basic rights of the personal data subject.
The subject has the right to access his personal data and the following information:
5.2. Duties of the Operator.
The operator must: