-
© 2023-2025 - Բոլոր իրավունքները պաշտպանված են:
The present policy of compliance with the requirements for personal data processing and protection (hereinafter referred to as the policy) is an internal and normative document defining the general provisions of the non-governmental organization, regulating the procedure and conditions of personal data processing by the organization and ensuring the protection of processed personal data, as well as the main means of compliance with the relevant requirements and the responsibility for them of the officials and competent persons of the organization:
Personal data – any information relating to a natural person, which allows or may allow to identify the person directly or indirectly.
Processing of personal data, regardless of the form and manner of implementation (including automation, use of any technical means or without them), any action or group of actions related to the collection, fixation, input, coordination, systematization, storage, use, transformation, recovery, transfer, rectification, blocking, destruction or performance of other actions related to the collection, fixation, input, systematization, storage, use, transformation, recovery, transfer, rectification, blocking, blocking, destruction or other actions related to the processing of personal data.
Data subject: citizens (natural persons), employees, service providers, partners who establish a contractual and/or other relationship with a non-governmental organization.
Database: a set of personal data systematized according to certain characteristics: Information system: a set of information technologies or technical means used to process personal data included in a database, in electronic or non-electronic form.
Personal data protection – a set of technical, organizational, organizational and technical measures aimed at protecting information related to the subject of personal data, determined on the basis of certain or similar information.
Publicly available personal data is information which, with the consent of the data subject or as a result of conscious actions aimed at making his/her personal data publicly available, becomes available to a certain or indefinite number of persons, as well as information stipulated by law as publicly available information.
Provision of personal data-actions aimed at disclosing personal data to a certain person or a certain circle of persons: Employees-staff members of the organization, fully or partially employed, regardless of their position in the organization.
1. To ensure the protection of processed personal data, the organization takes the necessary legal, organizational, technical protection measures in accordance with the regulatory requirements of the competent public authorities (regulatory bodies).
2 The requirements and rules for processing and protection of personal data shall be stipulated in the preparation of corporate documents related to all areas of the organization’s activities, including:
Personal data protection measures are developed in accordance with the possibilities of the RA legislation.
– the consent of the data subject to the processing of personal data in all cases provided for by law, especially in the case of transferring and receiving data by third parties.
Processing of personal data is carried out for the purpose of cooperation within the framework of concluded contracts, fulfillment of requirements of legislative acts, regulatory documents:
1 The processing of personal data is lawful if:
2. The consent of the data subject shall be deemed to have been obtained and the organization shall be entitled to process it when:
3. The data subject may give his or her consent in person or through a representative, if such authority is provided for in a power of attorney.
4. The consent of the data subject shall be given in writing or electronically with a verified electronic digital signature, or in the case of verbal consent, through credible actions that clearly indicate the data subject’s consent to the use of personal data.
5. Personal data may be processed without the data subject’s consent if the processing is expressly provided for by law.
6. The data subject has the right to receive information about the processing of his/her personal data, including information that will contain:
Information about personal data that became known to the non-governmental organization is confidential information and is protected by law. the organization can provide this information only to the granting organization, if necessary. The employees of the organization and other persons who have access to the processed personal data have signed an obligation of non-disclosure of confidential information, as well as have been warned about possible disciplinary, administrative, civil and criminal liability in case of violation of norms and requirements of the current legislation of the Republic of Armenia in the field of personal data processing.
1. This policy, as well as all amendments to it, shall be approved by the president of the non-governmental organization and shall enter into force in the non-governmental organization onecredit.am after publication on the website.
2. From the moment when further amendments to this Policy come into force, the previous versions of this Policy shall be deemed null and void.
3. If the provisions of this Policy contradict the legislation of the Republic of Armenia, the relevant provisions of the legislation of the Republic of Armenia shall apply.