Services Projects Recommendations Contacts
Personal data processing policy

1. General provisions

1.1. The Personal Data Processing Policy of BM-ELECTRO LLC (hereinafter referred to as the Policy) defines the basic principles, goals, conditions and methods of personal data processing, lists of subjects and personal data processed in BM--ELECTRO LLC, functions of BM-ELECTRO LLC in the processing of personal data, and the rights of personal data subjects, as well as the personal data protection requirements implemented by BM-ELECTRO LLC.

1.2. The Policy has been developed taking into account the requirements of the Constitution of the Russian Federation, legislative and other regulatory legal acts of the Russian Federation in the field of personal data.

1.3. The provisions of the Policy serve as the basis for the development of local regulations governing the processing of personal data of employees of BM-ELECTRO LLC and other subjects of personal data in BM-ELECTRO LLC..

2. Legislative and other regulatory legal acts of the Russian Federation, in accordance with which the Personal Data Processing Policy is determined

2.1. The personal data processing policy at BM-ELECTRO LLC is determined in accordance with the following regulatory legal acts:

  • The Labor Code of the Russian Federation and other regulatory legal acts containing labor law norms;
  • Budget Code of the Russian Federation;
  • The Tax Code of the Russian Federation;
  • The Civil Code of the Russian Federation;
  • Federal Law No. 152-FZ of July 27, 2006 "On Personal Data";
  • Decree of the Government of the Russian Federation No. 1119 dated November 01, 2012 "On Approval of Requirements for the Protection of Personal Data during their Processing in Personal Data Information Systems";
  • FSTEC of Russia Order No. 21 dated February 18, 2013 "On Approval of the Composition and Content of Organizational and Technical Measures to Ensure the Security of Personal Data during their Processing in Personal Data Information Systems";
  • other regulatory legal acts of the Russian Federation and regulatory documents of authorized state authorities.

2.2. In order to implement the Policy provisions, BM-ELECTRO LLC develops relevant local regulations and other documents, including:

  • Regulations on the processing of personal data in BM-ELECTRO LLC;
  • The regulation on ensuring the security of personal data during their processing in the personal data information systems of BM-ELECTRO LLC;
  • The list of positions of BM-ELECTRO LLC, the replacement of which involves the processing of personal data, or access to personal data;
  • Regulations for the processing of personal data of BM-ELECTRO LLC;
  • Other local regulations and documents regulating the processing of personal data at BM-ELECTRO LLC.

2.3. The legal bases for the processing of personal data in BM-ELECTRO LLC are also federal laws and regulatory legal acts adopted on their basis governing relations related to the statutory activities of BM-ELECTRO LLC, the Charter of BM-ELECTRO LLC, civil law contracts, and consents to the processing of personal data..

3. Basic terms and definitions

Personal data -- any information relating directly or indirectly to a specific or identifiable natural person (personal data subject).

Personal data authorized by the personal data subject for dissemination -- personal data to which an unlimited number of persons have access by the personal data subject by giving consent to the processing of personal data authorized by the personal data subject for dissemination in accordance with the procedure provided for by the current legislation of the Russian Federation.

Information -- information (messages, data) regardless of the form of their presentation.

Operator -- a state body, municipal body, legal entity, or individual who independently or jointly with other persons organize and (or) process personal data, as well as determine the purposes of personal data processing, the composition of personal data to be processed, and actions (operations) performed with personal data.

Personal data processing is any action (operation) or set of actions (operations) performed with or without the use of automation tools with personal data, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, and destruction of personal data.

Automated personal data processing is the processing of personal data using computer technology.

Providing personal data is an action aimed at disclosing personal data to a certain person or a certain circle of people.

Dissemination of personal data -- actions aimed at disclosing personal data to an unspecified group of people.

Blocking of personal data is the temporary termination of the processing of personal data (except in cases where the processing is necessary to clarify personal data).

Destruction of personal data -- actions that make it impossible to restore the content of personal data in the personal data information system and/or as a result of which the material carriers of personal data are destroyed.

Depersonalization of personal data is an action that makes it impossible to determine whether personal data belongs to a specific personal data subject without using additional information.

Personal data information system -- a set of personal data contained in databases and information technologies and technical means that ensure their processing.

4. Principles and purposes of personal data processing

4.1. BM-ELECTRO LLC, being the operator of personal data, processes the personal data of employees of BM-ELECTRO LLC and other subjects of personal data who are not in an employment relationship with BM-ELECTRO LLC.

4.2. The processing of personal data in BM-ELECTRO LLC is carried out taking into account the need to ensure the protection of the rights and freedoms of employees of BM-ELECTRO LLC and other subjects of personal data, including the protection of the right to privacy, personal and family secrets, based on the following principles:

  • personal data is processed by BM-ELECTRO LLC on a lawful and fair basis;
  • The processing of personal data is limited to the achievement of specific, predetermined and legitimate purposes;
  • Processing of personal data incompatible with the purposes of personal data collection is not allowed;
  • It is not allowed to combine databases containing personal data, the processing of which is carried out for purposes incompatible with each other;
  • Only personal data that meets the purposes of their processing is subject to processing;
  • The content and volume of the processed personal data correspond to the stated purposes of processing. Redundancy of the processed personal data in relation to the stated purposes of their processing is not allowed.;
  • When processing personal data, the accuracy of personal data, their sufficiency, and, if necessary, their relevance to the purposes of personal data processing are ensured. BM-ELECTRO LLC takes the necessary measures or ensures that they are taken to delete or clarify incomplete or inaccurate personal data.;
  • personal data is stored in a form that makes it possible to identify the subject of personal data, no longer than the purposes of personal data processing require, unless the period of personal data storage is established by federal law, an agreement to which the personal data subject is a party, beneficiary or guarantor.;
  • The personal data being processed is destroyed or depersonalized upon achievement of the processing objectives or in case of loss of the need to achieve these objectives, unless otherwise provided by federal law.

4.3. Personal data is processed by BM-ELECTRO LLC for the purposes of:

  • ensuring compliance with the Constitution of the Russian Federation, legislative and other regulatory legal acts of the Russian Federation, and local regulations of BM-ELECTRO LLC;
  • performing the functions, powers and duties assigned by the legislation of the Russian Federation to BM-ELECTRO LLC as an employer and tax agent, including providing personal data to public authorities and institutions, the Social Insurance Fund of the Russian Federation, the Federal Compulsory Medical Insurance Fund, as well as other government agencies;
  • carrying out the activities of BM-ELECTRO LLC in accordance with the legislation and the Charter of BM-ELECTRO LLC;
  • regulation of labor relations with employees of BM-ELECTRO LLC (assistance in employment, training and promotion, ensuring personal safety, monitoring the quantity and quality of work performed, ensuring the safety of property and other purposes specified in the relevant local act of BM-ELECTRO LLC);
  • providing additional guarantees and compensations to employees of BM-ELECTRO LLC and their family members, including non-state pension provision, voluntary medical insurance, medical care and other types of social security;
  • Protecting the life, health or other vital interests of personal data subjects;
  • preparation, conclusion, execution and termination of contracts with counterparties;
  • provision of access and on-site modes at the facilities of BM-ELECTRO LLC;
  • formation of reference materials for the internal information support of the activities of BM-ELECTRO LLC;
  • execution of judicial acts, acts of other bodies or officials subject to execution in accordance with the legislation of the Russian Federation on enforcement proceedings;
  • exercising the rights and legitimate interests of BM-ELECTRO LLC in the framework of the activities provided for by the Charter and other local regulations of BM-ELECTRO LLC, or third parties, or achieving socially significant goals;
  • processing, reviewing submitted applications by users of the official website and providing a response by phone or e-mail.
  • for other legitimate purposes.

5. List of subjects of personal data

BM-ELECTRO LLC processes personal data of the following categories of subjects:

  • employees, including former ones;
  • candidates to fill vacant positions;
  • relatives of employees, including former;
  • counterparties (individuals), representatives and employees of legal entities under civil law contracts;
  • individuals indicated in the statements (consents, powers of attorney);
  • individuals who are visitors to BM-ELECTRO LLC;
  • site users..

6. List of personal data processed by BM-ELECTRO LLC

6.1. The list of personal data processed by BM-ELECTRO LLC is determined in accordance with the legislation of the Russian Federation and local regulations of BM-ELECTRO LLC, taking into account the purposes of personal data processing specified in Section 4 of the Policy.

6.2. The processing of personal data concerning the state of health is carried out in accordance with the legislation on state social assistance, labor legislation, pension legislation of the Russian Federation, or on the basis of the consent of the personal data subject.

6.3. The processing of special categories of personal data related to race, nationality, political views, religious or philosophical beliefs, and intimate life is allowed only in cases provided for by law.

6.4. The processing of personal data authorized by the personal data subject for dissemination is carried out at BM-ELECTRO LLC based on the consent of the personal data subject to distribute, in compliance with the prohibitions and conditions established by the subject of personal data, the processing of personal data.

7. Functions in the processing of personal data

BM-ELECTRO LLC when processing personal data:

  • takes measures necessary and sufficient to ensure compliance with the requirements of the legislation of the Russian Federation, the Regulations and local regulations of BM-ELECTRO LLC in the field of personal data;
  • takes legal, organizational and technical measures to protect personal data from unlawful or accidental access to them, destruction, modification, blocking, copying, provision, dissemination of personal data, as well as from other unlawful actions with respect to personal data;
  • appoints a person responsible for organizing the processing of personal data at BM-ELECTRO LLC;
  • Issues local regulations defining the policy and issues of personal data processing and protection at BM-ELECTRO LLC;
  • carries out familiarization of employees of BM-ELECTRO LLC, who directly process personal data, with the provisions of the legislation of the Russian Federation and local regulations of BM-ELECTRO LLC in the field of personal data, including requirements for personal data protection, and training of these employees;
  • publishes or otherwise provides unrestricted access to this Policy;
  • informs personal data subjects or their representatives in accordance with the established procedure about the availability of personal data related to the relevant subjects, provides an opportunity to get acquainted with these personal data when contacting and (or) receiving requests from these personal data subjects or their representatives, unless otherwise established by the legislation of the Russian Federation;
  • stops processing and destroys personal data in cases stipulated by the legislation of the Russian Federation in the field of personal data;
  • performs other actions stipulated by the legislation of the Russian Federation in the field of personal data.

8. Conditions of personal data processing

8.1 The processing of personal data in BM-ELECTRO LLC is carried out with the consent of the personal data subject to the processing of his personal data, unless otherwise provided by the legislation of the Russian Federation in the field of personal data.

8.2 BM-ELECTRO LLC does not disclose or distribute personal data to third parties without the consent of the personal data subject, unless otherwise provided by federal law.

8.3 BM-ELECTRO LLC has the right to entrust the processing of personal data to another person with the consent of the personal data subject on the basis of an agreement concluded with this person. The contract must contain a list of actions (operations) with personal data that will be performed by the person processing personal data, the purposes of processing, the obligation of such person to respect the confidentiality of personal data and ensure the security of personal data during processing, as well as requirements for the protection of processed personal data in accordance with Article 19 of the Federal Law "On Personal Data".

8.4 For the purposes of internal information support, BM-ELECTRO LLC may create reference books, address books and other sources in which, with the written consent of the personal data subject, unless otherwise provided by the legislation of the Russian Federation, his personal data may be included.

8.5 Access to personal data processed by BM-ELECTRO LLC is allowed only to employees holding positions included in the list of positions of BM-ELECTRO LLC, whose replacement involves the processing of personal data or access to personal data.

9. List of actions with personal data and methods of their processing

9.1. BM-ELECTRO LLC collects, records, systematizes, accumulates, stores, clarifies (updates, changes), extracts, uses, transfers (distributes, provides, accesses), depersonalizes, blocks, deletes and destroys personal data.

9.2. Personal data processing in BM-ELECTRO LLC is carried out in the following ways:

  • non - automated processing of personal data;
  • automated processing of personal data with or without transmission of the received information via information and telecommunication networks;
  • Mixed processing of personal data.

10. Rights of personal data subjects

Personal data subjects have the right to:

  • complete information about their personal data processed by BM-ELECTRO LLC;
  • access to their personal data, including the right to receive a copy of any record containing their personal data, except in cases provided for by federal law;
  • clarification of their personal data, their blocking or destruction if the personal data is incomplete, outdated, inaccurate, illegally obtained or is not necessary for the stated purpose of processing;
  • Revocation of consent to the processing of personal data;
  • Taking legal measures to protect their rights;
  • appeal against the actions or omissions of BM-ELECTRO LLC, carried out in violation of the requirements of the legislation of the Russian Federation in the field of personal data, to the authorized body for the protection of the rights of personal data subjects or to the court;
  • exercise of other rights provided for by law.

11. Measures taken by BM-ELECTRO LLC to ensure that the operator's duties are fulfilled when processing personal data

11.1. The measures necessary and sufficient to ensure that BM-ELECTRO LLC fulfills the operator's obligations provided for by the legislation of the Russian Federation in the field of personal data include:

  • appointment of the person responsible for the organization of personal data processing at BM-ELECTRO LLC;
  • adoption of local regulations and other documents in the field of personal data processing and protection;
  • organization of training and methodological work with employees of BM-ELECTRO LLC who hold positions included in the list of positions authorized for personal data processing;
  • obtaining the consent of personal data subjects to the processing of their personal data, except in cases provided for by the legislation of the Russian Federation;
  • separation of personal data processed without the use of automation tools from other information, in particular by fixing them on separate physical media of personal data, in special sections;
  • ensuring separate storage of personal data and their physical media, which are processed for different purposes and which contain different categories of personal data;
  • Ensuring the security of personal data when they are transmitted through open communication channels;
  • storage of material carriers of personal data in compliance with the conditions that ensure the safety of personal data and exclude unauthorized access to them;
  • implementation of internal control over the compliance of personal data processing with the Federal Law "On Personal Data" and regulatory legal acts adopted in accordance with it, requirements for personal data protection, this Policy, and local regulations of BM-ELECTRO LLC;
  • other measures provided for by the legislation of the Russian Federation in the field of personal data. Measures to ensure the security of personal data during their processing in personal data information systems are established in accordance with the local regulations of BM-ELECTRO LLC, which regulate the issues of ensuring the security of personal data during their processing in the personal data information systems of BM-ELECTRO LLC.».

12. Monitoring compliance with the legislation of the Russian Federation and local regulations of BM-ELECTRO LLC in the field of personal data, including requirements for personal data protection

12.1. Employees are monitored for compliance with the legislation of the Russian Federation and local regulations of BM-ELECTRO LLC in the field of personal data, including requirements for personal data protection, in order to verify the compliance of personal data processing at BM-ELECTRO LLC with the legislation of the Russian Federation and local regulations of BM-ELECTRO LLC in the field of personal data, including the requirements for personal data protection, as well as the measures taken, aimed at preventing and detecting violations of the legislation of the Russian Federation in the field of personal data, identifying possible channels of leakage and unauthorized access to personal data, and eliminating the consequences of such violations.

12.2. Internal control over compliance by employees of BM-ELECTRO LLC, the legislation of the Russian Federation and local regulations of BM-ELECTRO LLC in the field of personal data, including requirements for personal data protection, is carried out by the person responsible for organizing the processing of personal data at BM-ELECTRO LLC.

12.3. Internal control over the compliance of personal data processing with the Federal Law "On Personal Data" and regulatory legal acts adopted in accordance with it, requirements for personal data protection, this Policy, and local regulations of BM-ELECTRO LLC is carried out by the person responsible for organizing personal data processing at BM-ELECTRO LLC.

12.4. Personal responsibility for compliance with the requirements of the legislation of the Russian Federation and local regulations of BM-ELECTRO LLC in the field of personal data at BM-ELECTRO LLC, as well as for ensuring the confidentiality and security of personal data of BM-ELECTRO LLC, lies with the General Director of BM-ELECTRO LLC and persons responsible for those holding positions included in the list of positions authorized for processing personal data.

13. Final provisions

13.1. This Policy is approved by the General Director of BM-ELECTRO LLC, comes into force from the date of its approval and is valid until the adoption of a new one.

13.2. The original copy of this Policy is kept permanently, and in case of adoption of a new one -- for 3 years.

13.3. This Policy is posted on the official website of BM-ELECTRO LLC.